Lobbying Affiliate: MML&K Government Solutions
{ Banner Image }

Healthcare Law Blog

Comprehensive Healthcare law services.
It's kind of our bag.

Contact Us

250 Character(s) Remaining
Type the following characters: tango, tango, romeo, papa

* Indicates a required field.

Categories

McBrayer Blogs

Related Blogs

Showing 3 posts tagged HIPAA.

When HIPAA Says Yes but Part 2 Says No, Part One: What SUD Providers Must Know When Responding to a Subpoena

Posted In Part 2

Part 2 increases protections for SUD patient records because of the stigma and legal consequences associated with substance use treatment. Protecting patient records serves an important public health interest, because weakening confidentiality discourages patient participation in treatment. Federal courts have enforced Part 2 to protect patients. The increased privacy protection for substance use treatment was originally intended to prevent prosecution of patients in active treatment programs, and it still does. While Part 2 is not a new regulation, it did undergo major changes when the 2024 Final Rule was adopted on April 16, 2024 (with a two-year implementation period). Enforcement for the updated Part 2 rules began on February 16, 2026, when the HHS Office for Civil Rights (“OCR”) launched a civil enforcement program and began accepting complaints alleging Part 2 violations and breach notification violations.

Substance use disorder (“SUD”) treatment providers face increasing scrutiny from Medicaid fraud and control units and other government agencies that regularly use subpoenas as an early investigation tool. The United States Department of Health and Human Services (“HHS”) Office of Inspector General (“OIG”) Work Plan also targets SUD providers and focuses on billing accuracy, regulatory compliance, patient monitoring, and other provider-related issues. Because SUD treatment is now provided in such a wide range of settings — including rural health clinics, physician practices, federally qualified health centers, primary care centers, behavioral health providers, hospitals, and independent treatment programs — these providers are targets for heightened oversight but are also subject to complex federal privacy laws that mandate extra protection for the private health information of SUD patients. SUD providers should actively manage these regulatory risks. Although a subpoena may feel urgent and intimidating, federal privacy law strictly limits what SUD providers may disclose, even when the request comes from law enforcement or a state agency. SUD providers must understand and comply with their privacy obligations when responding to the first-line investigative tool, the subpoena. More >

New Resident Legal Issues

Leaving medical school and entering residency is a daunting transition in the career of a new physician, presenting a new set of legal rules and requirements, including employment contracts and malpractice liabilities. We recommend familiarizing yourself with your program’s relevant manuals and policies and seeking legal advice when necessary. More >

Healthcare Entities: How is Your Cyber Security?

In an evolving world of cyber terrorism where individuals such as Edward Snowden grab headlines by stealing national secrets, it should come as no surprise that protected healthcare information (“PHI”) kept by providers has become a “target rich environment” for foreign governments and individual hackers alike. In addition to threats from outside entities, healthcare providers must also realize and appreciate that state and federal regulatory and statutory requirements govern the creation, maintenance and protection of PHI, including through but not limited to the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and the Health Information Technology for Economic and Clinical Health (“HITECH”) Act.  Failure to abide by these complex and stringent rules can lead to significant penalties.  More >

Lexington, KYLouisville, KYFrankfort, KYFrankfort, KY: MML&K Government Solutions