The top 10 HIPAA violations by Covered Entities and Business Associates include the following:
- Snooping on healthcare records;
- Failure to perform risk analysis;
- Failure to manage security risks;
- Failure to enter into a HIPAA compliant BAA once again is your Business Associate Agreement;
- Insufficient ePHI access controls;
- Failure to use encryption to safeguard portable devices;
- Failure to issue breach notification;
- Impermissible disclosure of PHI;
- Improper disposal of PHI after the retention period has expired;
- Denying patients access to health records.