HIPAA's Right of Access: Compliance Challenges, OCR Enforcement, and Best Practices

Course Details
- smart_display Format
On-Demand
- signal_cellular_alt Difficulty Level
- work Practice Area
Health
- event Date
Wednesday, June 22, 2022
- schedule Time
1:00 p.m. ET./10:00 a.m. PT
- timer Program Length
90 minutes
-
This 90-minute webinar is eligible in most states for 1.5 CLE credits.
This CLE course will guide healthcare counsel on HIPAA's right of access. The panel will discuss defining the designated record set and evaluate common scenarios in which liability may arise. The panel will also discuss the U.S. Department of Health and Human Services Office for Civil Rights (OCR's) right of access enforcement efforts. The panel will offer best practices for compliance.
Faculty

Ms. Klein is a leading practitioner on privacy and data protection matters, with a special emphasis on the health and life sciences sectors. She has been recognized by The Legal 500 US in the cyber law (including privacy and data protection) category from 2019 through 2022. She has focused on privacy and data protection law for more than 20 years. Ms. Klein assists clients with issues arising under state and federal privacy, security and data breach notification laws and regulations. These include the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH), Section 5 of the Federal Trade Commission (FTC) Act, the FTC Health Breach Notification Rule (HBNR) and myriad state privacy, security and breach notification laws, including the California Consumer Privacy Act (CCPA) and California Confidentiality of Medical Information Act (CMIA). Ms. Klein has examined privacy and data protection issues arising in a broad array of settings, ranging from hospitals to professional sports, including medical device and pharmaceutical companies, developers of health-related apps, and leading-edge technology companies.

Ms. Montague represents a variety of health care providers, digital health companies, senior living facilities, nonprofit trade associations, life sciences companies, and vendors of health care providers. She is a Certified Information Privacy Professional/United States (CIPP/US), the preeminent credential in the field of privacy. Ms. Montague assists health care providers and business associates of all types in complying with the requirements of HIPAA and the HITECH Act, from the development of policies and workforce training to analysis and notification of breaches to guidance through Office for Civil Rights investigations. She also advises vendors initiating arrangements with health care entities on whether their business triggers HIPAA. Beyond HIPAA, Ms. Montague counsels health care providers on compliance with other federal and state health information confidentiality requirements, as well as cybersecurity best practices.
Description
In March 2022, OCR announced the resolution of three investigations related to HIPAA right of access compliance. The announcement, along with recent statements from the OCR director, emphasizes the ongoing focus by OCR on its Right of Access Initiative.
The HIPAA Privacy Rule generally requires HIPAA covered entities to provide individuals, upon request, with access to protected health information (PHI) about them maintained by/for the covered entity in "designated record sets." However, the HIPAA right of access may not apply to all PHI, as it is limited to information contained in the designated record set. Complying with the HIPAA access requirement, along with access requirements under other applicable laws, can be challenging for many entities.
Listen as our authoritative panel of healthcare attorneys examines HIPAA's right of access requirements. The panel will discuss compliance challenges and evaluate common scenarios that may give rise to liability. The panel will offer practical guidance for ensuring compliance with HIPAA's right of access requirements.
Outline
- HIPAA basics and the right of access
- HIPAA Right of Access Initiative
- Common scenarios in which liability may arise
- Intersection with the interoperability rule
- Applicable state law
- Record retention
- Best practices
Benefits
The panel will review these and other relevant issues:
- What compliance challenges are covered entities facing today with respect to the HIPAA right to access?
- What steps should covered entities take to define designated record sets and otherwise ensure compliance with access requirements?
- Under its Right of Access Initiative, what actions has OCR taken to enforce the requirements?
Unlimited access to premium CLE courses:
- Annual access
- Available live and on-demand
- Best for attorneys and legal professionals
Unlimited access to premium CPE courses.:
- Annual access
- Available live and on-demand
- Best for CPAs and tax professionals
Unlimited access to premium CLE, CPE, Professional Skills and Practice-Ready courses.:
- Annual access
- Available live and on-demand
- Best for legal, accounting, and tax professionals
Related Courses

The ACA and the New Administration: CMS Proposed Rule Impacting Marketplace Eligibility and Other Notable Actions
Tuesday, April 22, 2025
1:00 p.m. ET./10:00 a.m. PT

Healthcare Speaker Programs and AKS Compliance: Regulatory Update, Lessons Learned From Recent Settlements
Tuesday, May 27, 2025
1:00 p.m. ET./10:00 a.m. PT

HIPAA and Beyond: Health Information Privacy Updates
Tuesday, May 27, 2025
1:00 p.m. ET./10:00 a.m. PT
Recommended Resources
Navigating Modern Legal Challenges: A Comprehensive Guide
- Business & Professional Skills
- Career Advancement