Compliance Update: HIPAA Right of Access Initiative Announces 13th Investigation

The Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) announces its

thirteenth settlement of an enforcement action in its HIPAA Right of Access Initiative. OCR announced this initiative as an enforcement priority in 2019 to support individuals' right to timely access their health records at a reasonable cost under the HIPAA Privacy Rule.



Peter Wrobel, M.D., P.C., doing business as Elite Primary Care ("Elite"), has agreed to take corrective actions and pay $36,000 to settle a potential violation of the HIPAA Privacy Rule's right of access standard. Elite provides primary care health services in Georgia.


In April 2019, OCR received a complaint alleging that Elite failed to respond to a patient's request for access to his medical records. In May 2019, OCR provided technical assistance to Elite on the HIPAA right of access requirements and closed the complaint. In October 2019, OCR received a second complaint alleging that Elite still had not provided the patient with access to his medical records. OCR initiated an investigation and determined that Elite's failure to provide the requested medical records was a potential violation of the HIPAA right of access standard. As a result of OCR's investigation, the patient received a copy of his medical record in May 2020.


"OCR created the Right of Access Initiative to address the many instances where patients have not been given timely access to their medical records. Health care providers, large and small, must ensure that individuals get timely access to their health records, and for a reasonable cost-based fee," said OCR Director Roger Severino.


In addition to the monetary settlement, Elite will undertake a corrective action plan that includes two years of monitoring. A copy of the resolution agreement and corrective action plan may be found at https://www.hhs.gov/sites/default/files/elite-racap.pdf.


What can I do to ensure this doesn’t happen to me or my organization?

At Live Compliance, we make checking off your compliance requirements extremely simple.

  • Reliable and Effective Compliance

  • Completely online, our role-based courses make training easy for remote or in-office employees.

  • Contact-free, accurate Security Risk Assessments are conducted remotely. All devices are thoroughly analyzed regardless of location.

  • Policies and Procedures curated to fit your organization ensuring employees are updated on all Workstation Use and Security Safeguards in the office, or out. Update in real time.

  • Electronic, prepared document sending and signing to employees and business associates.

Don’t risk your company’s future, especially when we are offering a free Organization Assessment to help determine your company’s status. Call us at (980) 999-1585, or email me, Jim Johnson at Jim@LiveCompliance.com or visit www.LiveCompliance.com

The information in this article was provided by hhs.gov

Read the full article here