Lexology October 3, 2019
On October 2, 2019, the Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) announced that a Texas dental practice (“Practice”) will settle potential violations of the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) by paying a civil penalty of $10,000 and adopting a corrective action plan.
A patient of the Practice filed a complaint with OCR regarding the Practice’s response to a social media review posted by the patient. Specifically, the Practice disclosed the patient’s last name, treatment plan, insurance and cost information for the patient. During the course of its investigation, OCR reviewed the Practice’s Yelp review page. OCR subsequently discovered other responses from the Practice that were also impermissible disclosures under HIPAA....