Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Tuesday, March 5, 2013

Department of Health and Human Services Introduces HIPAA Omnibus Rule


By George F. Indest III, J.D., M.P.A., LL.M., Board Certified by The Florida Bar in Health Law, and Lance O. Leider, J.D., The Health Law Firm

With the popularity of electronic health records (EHRs), social media and everything in between, the U.S. Department of Health and Human Services (HHS) has released stronger rules and protections governing patient privacy. On January 17, 2013, the HHS announced the omnibus rule to strengthen the privacy and security protection established under the Health Insurance Portability and Accountability Act (HIPAA) of 1996.

Click here to read the entire 563-page rule.
Now, I can’t say that I’ve had enough free time to read the entire document yet, but I can tell you about the major parts of the omnibus rule, and what it means for healthcare providers.


Protecting a Patient's Information During Data Exchanges.
HHS is expanding the government’s jurisdiction over healthcare providers, health plans and other entities that process health insurance claims to include their contractors and subcontractors with whom providers share protected health information. As the industry embraces new care delivery models, including accountable care organizations (ACOs) and integrated delivery systems, data is exchanged between physicians, hospitals and additional providers to improve care and reduce costs. This all has to be done while keeping patient data safe. According to the HHS, some of the largest breaches involve business associates and not the covered entities themselves.

The government is committed to doing more HIPAA compliance audits and collecting more fines.  The fines the government collects will help to fund the audit process. Because of this rule, we will see audits of business associates and their subcontractors, not just covered entities.

Under the new rule, penalties have been increased for noncompliance based on the level of negligence with a maximum penalty of $1.5 million per violation.


Don’t Land on the Office for Civil Rights’ “Wall of Shame.”
The changes also improve the Health Information Technology for Economic and Clinical Health (HITECH) breach notification requirements by making it clear when breaches must be reported to the Office for Civil Rights (OCR), according to the HHS.

Once reported to the OCR, the breaches are then placed on what is commonly known in the healthcare industry as the “Wall of Shame.” It’s a comprehensive list of privacy breaches each affecting more than 500 people. We’re currently working on a “Wall of Shame” blog, so more on that later.


Take Notes of New Regulations Regarding Patient Information in Marketing.
One part of the final rule also sets new regulations for how patient information can be used for marketing and fundraising. It ensures that such information cannot be sold without a patient’s permission. According to an article in Fierce Healthcare, this provision is a huge win for patient advocates and privacy groups who blast hospitals for mining patient data to target affluent or privately insured patients. Hospitals using health and demographic data from patients’ records to target advertising could be in hot water.

Click here to read the entire Fierce Healthcare article.


If You are Unsure of Your Policies and Procedures, Get a HIPAA Risk Assessment.

Since the HIPAA laws have changed, you need to edit your privacy forms and procedures. Many health providers simply don't have the time to re-review their policies and revise documents. A HIPAA risk assessment is a thorough review and analysis of areas where you may have risk of violating the HIPAA laws.  Federal regulations require that covered entities have this assessment done. A HIPAA risk assessment can significantly reduce, if not entirely eliminate, your exposure to regulatory and litigation sanctions.

When the OCR auditor comes to visit your office to check for HIPAA compliance, they will ask for your risk assessment. Do you have one? Does your staff know who your HIPAA compliance officer is? Call an experienced health law attorney to complete a risk assessment of your practice today. To learn more on HIPAA risk assessments, click here to read a blog we wrote.


Update Notice of Privacy Practices.
Healthcare providers, now is the time to revise your Notice of Privacy. The final rule will be effective on March 26, 2013. Covered entities and their business associates will have until September 21, 2013, to comply.


Contact a Health Law Attorney Experienced in Defending HIPAA Complaints and Violations.
The attorneys of The Health Law Firm represent physicians, medical groups, nursing homes, home health agencies, pharmacies, hospitals and other healthcare providers and institutions in investigating and defending alleged HIPAA complaints and violations and in preparing Corrective Action Plans (CAPs).

For more information about HIPAA violations, electronic health records or corrective action plans (CAPs) please visit our website at www.TheHealthLawFirm.com or call (407) 331-6620 or (850) 439-1001.


What Do You Think?
What do you think about the new HIPAA rules? Do you think these updates were necessary? Do you think it will be difficult for health professionals to comply? Please leave any thoughtful comments below.


Sources:
HHS Press Office. “New Rule Protects Patient Privacy, Secures Health Information.” U.S. Department of Health and Human Services. (January 17, 2013). From: http://www.hhs.gov/news/press/2013pres/01/20130117b.html
Struck, Kathleen. “HIPAA Rules Fortify Patient Privacy.” MedPage Today. (January 21, 2013). From: http://www.medpagetoday.com/PracticeManagement/InformationTechnology/36940
Conn, Joseph. “New Rule: Hospital, Physician Partners Face Penalties for Privacy Leaks.” Modern Healthcare. (January 17, 2013). From: http://www.modernhealthcare.com/article/20130117/NEWS/301179957/new-rule-hospital-physician-partners-face-penalties-for-privacy&utm_source=home&utm_medium=web&utm_campaign=most-popular-box
Caramenico, Alicia. “New HIPAA Rule a Delicate Balance Between Privacy, Sharing.” Fierce Healthcare. (January 18, 2013). From: http://www.fiercehealthcare.com/story/new-hipaa-rule-delicate-balance-between-privacy-sharing/2013-01-18


About the Authors: George F. Indest III, J.D., M.P.A., LL.M., is Board Certified by The Florida Bar in Health Law.  He is the President and Managing Partner of The Health Law Firm, which has a national practice.  Its main office is in the Orlando, Florida, area.  www.TheHealthLawFirm.com  The Health Law Firm, 1101 Douglas Ave., Altamonte Springs, FL 32714, Phone: (407) 331-6620.
 
Lance O. Leider is an attorney with The Health Law Firm, which has a national practice. Its main office is in the Orlando, Florida, area. www.TheHealthLawFirm.com  The Health Law Firm, 1101 Douglas Avenue, Altamonte Springs, Florida 32714, Phone:  (407) 331-6620.

 
"The Health Law Firm" is a registered fictitious business name of George F. Indest III, P.A. - The Health Law Firm, a Florida professional service corporation, since 1999.

Copyright © 1996-2012 The Health Law Firm. All rights reserved.

Monday, May 14, 2012

Internet Calendar Postings at the Center of Alleged HIPAA Privacy Violation Settlement

By George F. Indest III, J.D., M.P.A., LL.M., Board Certified by The Florida Bar in Health Law

A physician group has reached a settlement with the United States Department of Health and Human Services (HHS) Office for Civil Rights (OCR) over alleged Health Insurance Portability and Accountability Act of 1996 (HIPAA) violations. The settlement was reached on April 17, 2012. It requires Phoenix Cardiac Surgery (PCS) to pay OCR $100,000. PCS is also required enter into a one-year corrective action plan (CAP). The Resolution Agreement and Corrective Action Plan can be viewed here.

HIPAA Complaint Resulted from Internet Calendar Postings.
OCR's investigation of PCS was launched after a complaint was received in 2009. Click here to view a HIPAA complaint that you can file online. The complaint alleged that PSC disclosed protected health information (PHI) on patients on the Internet. After investigating the complaint, the OCR alleged that PCS violated the HIPAA privacy and security rules.

According to the OCR, PCS posted clinical and surgical appointments on a publicly accessible, Internet calendar. The OCR also alleged that PCS employees e-mailed protected health information to their personal e-mail accounts. Furthermore, PCS allegedly did not have adequate administrative, physical and technical safeguards in place to protect patient data. The OCR alleged that PCS did not appoint a security officer as required by HIPAA or perform an accurate and thorough risk assessment, also required by HIPAA. The CAP required by the settlement will require PCS to implement policies to ensure full compliance with HIPAA's privacy and security rules.

Are You In Compliance with HIPAA?


The Health Insurance Portability and Accountability Act of 1996, sometimes referred to as the Kennedy-Kassenbaum Act, was enacted into law as Public Law (P.L.) 104-191, 110 Stat. 1936. Among its many different provisions, it included basic minimums to ensure the privacy of personal medical information. Its main privacy provisions are codified in federal law in different sections of the U.S. Code.

Health Providers Must be Cautious When Working With Electronic Health Information.
This case provides a good example of the downside of information technology (IT). While electronic health information assists in increasing accessibility and efficiency, it can also increase a practice's risk of violating HIPAA's Privacy Rule and Security Rule. All medical practices that utilize electronic health information need to ensure that they have effective IT security, education, policies and procedures in place to protect themselves from HIPAA's violations.

Contact a Health Law Attorney Experienced in Defending HIPAA Complaints and Violations.

The attorneys of The Health Law Firm represent physicians, medical groups, nursing homes, home health agencies, pharmacies, hospitals and other healthcare providers and institutions in investigating and defending alleged HIPAA complaints and violations and in preparing Corrective Action Plans (CAPs).

For more information about HIPAA violations, electronic health records or corrective action plans (CAPs) please visit our website at http://www.thehealthlawfirm.com/ or call (407) 331-6620 or (850) 439-1001.

Sources Include:

HHS Press Office. "HHS Settles Case with Phoenix Cardiac Surgery for Lack of HIPAA Safeguards." U.S. Department of Health and Human Services. (Apr. 17, 2012). Press Release. From http://www.hhs.gov/news/press/2012pres/04/20120417a.html

Lewis, Nicole. "Online Calendar Mistakes Cost Doctors Group $100,000." Information Week. (Apr. 23, 2012). From http://www.informationweek.com/news/healthcare/security-privacy/232900727

Sterling, Robyn. "HHS Settlement for Lack of HIPAA Safeguards." Proskauer Privacy Law Blog. (Apr. 25, 2012). From http://www.jdsupra.com/post/documentViewer.aspx?fid=e548966a-d7eb-4f47-a0af-de15db487dbb/

About the Author: George F. Indest III, J.D., M.P.A., LL.M., is Board Certified by The Florida Bar in Health Law. He is the President and Managing Partner of The Health Law Firm, which has a national practice. Its main office is in the Orlando, Florida, area. http://www.thehealthlawfirm.com/ The Health Law Firm, 1101 Douglas Ave., Altamonte Springs, FL 32714, Phone: (407) 331-6620.