Contact Us
Categories
- Part 2
- Data Privacy
- Department of Health and Human Services' Office of Civil Rights
- Medical Malpractice
- Medical Cannabis
- Workplace health
- Workplace Violence
- Assisted Living Facilities
- EMTALA
- FDA
- Reproductive Rights
- Roe v. Wade
- SCOTUS
- COVID-19
- Prescription Drugs
- Telemedicine
- Medical Spas
- Code Enforcement
- Corporate
- Employee Contracts
- Non-Compete Agreement
- United States Department of Justice ("DOJ")
- Compliance
- HIPAA
- Kentucky Board of Nursing
- Managed Care Organizations (“MCOs”)
- Anti-Kickback Statute
- False Claims Act
- KASPER
- Kentucky’s Department for Medicaid Services
- Medicaid
- Mental Health Care
- Office for Civil Rights ("OCR")
- Office of Inspector General of the United States Department of Health and Human Services (OIG)
- Primary Care Physicians ("PCPs")
- Qui Tam
- Stark Laws
- Accountable Care Organizations (“ACO”)
- Affordable Care Act
- APRNs
- Centers for Medicare & Medicaid Services (“CMS”)
- Charitable Hospitals
- Data Breach
- Electronic Protected Health Information (ePHI)
- Federally Qualified Health Centers (“FQHCs”)
- Health Information Technology for Economic and Clinical Health Act (HITECH Act)
- Health Insurance Portability and Accountability Act of 1996 (HIPAA)
- Health Professional Shortage Area ("HPSA")
- Hospitals
- HPSA
- HRSA
- Kentucky Board of Medical Licensure
- Medicare
- Mid-Level Practitioners
- Patient Protection and Affordable Care Act (“ACA”)
- Pharmacists
- Physician Assistants
- Rural Health Centers (“RHCs”)
- Rural Health Clinic
- Telehealth
- Business Associate Agreements
- Fraud
- Part D
- Appeal
- Compliance Programs
- Electronic Health Records (“EHR")
- ERISA
- Hospice
- Overpayments
- Advanced Practice Registered Nurses
- Business Associates
- Denied Claims
- Division of Regulated Child Care
- Employee Agreement
- Fair Labor Standards Act (FLSA)
- Licensed practical nurses (LPN)
- Licensure Requirements
- Nurse practitioners (NP)
- Part A
- Part B
- Personal Health Information
- Personal Service Entities
- Physician Payments
- Qualified Health Plan ("QHP")
- Registered nurses (RN)
- Abuse and Waste
- Occupational Safety and Health Administration (“OSHA”)
- Patient Autonomy
- Department of Health and Human Services (HHS)
- Health Insurance
- Healthcare Regulation
- Health Care Law
McBrayer Blogs
Showing 3 posts tagged HIPAA.
When HIPAA Says Yes but Part 2 Says No, Part One: What SUD Providers Must Know When Responding to a Subpoena
Part 2 increases protections for SUD patient records because of the stigma and legal consequences associated with substance use treatment. Protecting patient records serves an important public health interest, because weakening confidentiality discourages patient participation in treatment. Federal courts have enforced Part 2 to protect patients. The increased privacy protection for substance use treatment was originally intended to prevent prosecution of patients in active treatment programs, and it still does. While Part 2 is not a new regulation, it did undergo major changes when the 2024 Final Rule was adopted on April 16, 2024 (with a two-year implementation period). Enforcement for the updated Part 2 rules began on February 16, 2026, when the HHS Office for Civil Rights (“OCR”) launched a civil enforcement program and began accepting complaints alleging Part 2 violations and breach notification violations.
Substance use disorder (“SUD”) treatment providers face increasing scrutiny from Medicaid fraud and control units and other government agencies that regularly use subpoenas as an early investigation tool. The United States Department of Health and Human Services (“HHS”) Office of Inspector General (“OIG”) Work Plan also targets SUD providers and focuses on billing accuracy, regulatory compliance, patient monitoring, and other provider-related issues. Because SUD treatment is now provided in such a wide range of settings — including rural health clinics, physician practices, federally qualified health centers, primary care centers, behavioral health providers, hospitals, and independent treatment programs — these providers are targets for heightened oversight but are also subject to complex federal privacy laws that mandate extra protection for the private health information of SUD patients. SUD providers should actively manage these regulatory risks. Although a subpoena may feel urgent and intimidating, federal privacy law strictly limits what SUD providers may disclose, even when the request comes from law enforcement or a state agency. SUD providers must understand and comply with their privacy obligations when responding to the first-line investigative tool, the subpoena. More >
New Resident Legal Issues
Leaving medical school and entering residency is a daunting transition in the career of a new physician, presenting a new set of legal rules and requirements, including employment contracts and malpractice liabilities. We recommend familiarizing yourself with your program’s relevant manuals and policies and seeking legal advice when necessary. More >
Healthcare Entities: How is Your Cyber Security?
In an evolving world of cyber terrorism where individuals such as Edward Snowden grab headlines by stealing national secrets, it should come as no surprise that protected healthcare information (“PHI”) kept by providers has become a “target rich environment” for foreign governments and individual hackers alike. In addition to threats from outside entities, healthcare providers must also realize and appreciate that state and federal regulatory and statutory requirements govern the creation, maintenance and protection of PHI, including through but not limited to the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and the Health Information Technology for Economic and Clinical Health (“HITECH”) Act. Failure to abide by these complex and stringent rules can lead to significant penalties. More >

