The long-awaited proposed changes to the HIPAA Privacy Rules have finally been released by the Department of Health and Human Services (HHS).
A joint statement issued today by the HHS and the Office of Civil Rights (OCR) says that the proposed regulations “would expand individuals’ rights to access their information and restrict certain disclosures of protected health information to health plans, extend the applicability of certain of the Privacy and Security Rules’ requirements to the business associates of covered entities, establish new limitations on the use and disclosure of protected health information for marketing and fundraising purposes, and prohibit the sale of protected health information without patient authorization. In addition, the proposed rule is designed to strengthen and expand OCR’s ability to enforce HIPAA’s Privacy and Security provisions. This rulemaking will strengthen the privacy and security of health information, and is an integral piece of the Administration’s efforts to broaden the use of health information technology in health care today. We urge consumers, providers, and other stakeholders to read these proposals and offer comments during the 60-day comment period, which will officially open on July 14, 2010. Information about posting comments will be available at http://www.regulations.gov.”
The 234 pages of proposed regulations can be found at Notice of Proposed Rulemaking to Implement HITECH Act Modifications and we are in the process of reviewing these regulations to provide our readers with further information.
Showing posts with label electronic health records. Show all posts
Showing posts with label electronic health records. Show all posts
Thursday, July 8, 2010
Monday, April 26, 2010
Proposed HITECH Regulations Out in May?
Buried in a part of today's Federal Register was the publication of the Department of Health and Human Services' regulatory agenda. The agenda presents a forecast of expected HHS rulemaking activities and suggests that in May of this year HHS will issue the long-awaited proposed rules to modify the HIPAA Privacy, Security, and Enforcement Rules as necessary to implement the privacy, security, and certain enforcement provisions of the HITECH Act (see our earlier blog posts).
The Department is also scheduled to issue a final rule in May of this year, addressing the certification standards and implementation criteria for electronic health record technology.
The Department is also scheduled to issue a final rule in May of this year, addressing the certification standards and implementation criteria for electronic health record technology.
Labels:
business associate,
electronic health records,
HHS,
HIPAA,
HITECH Act
Friday, April 9, 2010
Privacy and Security Bits and Bytes
Our Friday afternoon feature --
Virginia Adds Medical Information Breach Law - The Commonwealth of Virginia has amended its data breach notification law to include breaches of medical information. For the text of the amendment, link here. Even if the data is encrypted, the law requires notice if the breach involved a person with access to the encryption key. The law requires notice to affected individuals (residents of Virginia) as well as Virginia's Office of Attorney General. The Attorney General can bring an action for violations of the law and impose civil penalties up to $150,000 per breach (or a series of similar breaches of a similar nature that are discovered in a single investigation). The law does not apply to persons or entities that must report the breach under the HITECH Act.
“Data Security – It’s a Responsibility, Not an Option” – interesting point of view from InfoSecIsland.
FTC Complaint Focuses on Tracking, Profiling of Consumers. -- Yesterday, the Center for Digital Democracy, the US Public Interest Research Group, and the World Privacy Forum filed a complaint with the FTC regarding two emerging trends in online advertising that they say pose growing threats to consumer privacy: auctioning of individual Internet users for targeted advertising opportunities and the combination of online and offline data about Internet users. The complaint describes what the group feels is a growing trend in online behavioral advertising that involves the real-time sale and trade of the right to target individual users with online ads through the use of data compiled about users via their Web surfing habits. The groups have asked the FTC to investigate the data and advertising exchanges operated by Google, Microsoft and Yahoo, as well as several firms that support the auctioning and data collection/targeting system, including AppNexus, BlueKai and Rubicon Project. Furthermore, the group has asked the FTC to require the firms involved in real-time online tracking and auction bidding to allow consumers to opt-in to participate in such activities; require firms to update their privacy policies so consumers are aware of these activities; and ensure consumers are compensated for the use of their data. Stay tuned.
Large UK Data Breach Penalty Takes Effect -- As we warned you in this space last month, this week marks the effective date of the new, substantially higher fines in the UK for data loss. Reports are that up to 65 percent of workers are unaware of the new penalties – which can quickly hit £500K for large scale breaches. If you’re operating in the UK, check out Data loss fines hit £500K from today • The Register or ICO vows to impose heavy fines for major data breaches - 07 Apr 2010 - Computing.
And Finally --
This item from Wired Magazine proves yet again that identity theft is not limited to computer hacking or interception of electronic messages. A 74-count indictment unsealed yesterday in Arizona details charges that a group of sophisticated identity thieves managed to steal millions of dollars by filing bogus tax returns using the names and Social Security numbers of other people, many of them deceased.
Virginia Adds Medical Information Breach Law - The Commonwealth of Virginia has amended its data breach notification law to include breaches of medical information. For the text of the amendment, link here. Even if the data is encrypted, the law requires notice if the breach involved a person with access to the encryption key. The law requires notice to affected individuals (residents of Virginia) as well as Virginia's Office of Attorney General. The Attorney General can bring an action for violations of the law and impose civil penalties up to $150,000 per breach (or a series of similar breaches of a similar nature that are discovered in a single investigation). The law does not apply to persons or entities that must report the breach under the HITECH Act.
“Data Security – It’s a Responsibility, Not an Option” – interesting point of view from InfoSecIsland.
FTC Complaint Focuses on Tracking, Profiling of Consumers. -- Yesterday, the Center for Digital Democracy, the US Public Interest Research Group, and the World Privacy Forum filed a complaint with the FTC regarding two emerging trends in online advertising that they say pose growing threats to consumer privacy: auctioning of individual Internet users for targeted advertising opportunities and the combination of online and offline data about Internet users. The complaint describes what the group feels is a growing trend in online behavioral advertising that involves the real-time sale and trade of the right to target individual users with online ads through the use of data compiled about users via their Web surfing habits. The groups have asked the FTC to investigate the data and advertising exchanges operated by Google, Microsoft and Yahoo, as well as several firms that support the auctioning and data collection/targeting system, including AppNexus, BlueKai and Rubicon Project. Furthermore, the group has asked the FTC to require the firms involved in real-time online tracking and auction bidding to allow consumers to opt-in to participate in such activities; require firms to update their privacy policies so consumers are aware of these activities; and ensure consumers are compensated for the use of their data. Stay tuned.
Large UK Data Breach Penalty Takes Effect -- As we warned you in this space last month, this week marks the effective date of the new, substantially higher fines in the UK for data loss. Reports are that up to 65 percent of workers are unaware of the new penalties – which can quickly hit £500K for large scale breaches. If you’re operating in the UK, check out Data loss fines hit £500K from today • The Register or ICO vows to impose heavy fines for major data breaches - 07 Apr 2010 - Computing.
And Finally --
This item from Wired Magazine proves yet again that identity theft is not limited to computer hacking or interception of electronic messages. A 74-count indictment unsealed yesterday in Arizona details charges that a group of sophisticated identity thieves managed to steal millions of dollars by filing bogus tax returns using the names and Social Security numbers of other people, many of them deceased.
Friday, March 26, 2010
HHS Announces Delay in Enforcement of HITECH Rules as Applied to Business Associates
As we have discussed before, HHS’s Office of Civil Rights has let it be known that a proposed rule implementing the HITECH Act’s privacy and security provisions as they apply to business associate liability is in the works. The proposed rule will also deal with new limitations on the sale of protected health information, marketing, and fundraising communications, and stronger individual rights to access electronic medical records, among other things. According to the Office of Civil Rights, the proposed rule “will provide specific information regarding the expected date of compliance and enforcement of these new requirements.”
We take this to mean that enforcement of these particular HITECH Act provisions will be delayed.
For more information, see the Mintz Levin Health Law and Employee Benefits Alert just published.
We take this to mean that enforcement of these particular HITECH Act provisions will be delayed.
For more information, see the Mintz Levin Health Law and Employee Benefits Alert just published.
Thursday, January 28, 2010
Data Privacy Day Tip #2 - HITECH Act
Written by Dianne Bourque
Effective February 17, 2010, significant new compliance obligations will be imposed on business associates through the HITECH provisions of the American Recovery and Reinvestment Act of 2009 ("ARRA"). Business associates (or organizations that use or disclose protected health information on behalf of covered entities subject to HIPAA) will be directly liable for compliance with certain provisions of the HIPAA Privacy Rule and the HIPAA Security Standards, and may be audited by the Department of Health and Human Services ("HHS"). They will also be subject to increased civil and criminal penalties for non-compliance.
DATA PRIVACY DAY REMINDER: Time to update business associate agreements to reflect HITECH's new breach-notice provisions and other requirements. Business associates must also--at a minimum--(i) undertake and complete a security risk assessment, (ii) prepare and adopt written security policies and procedures, and (iii) conduct workforce training in their policies and procedures.
Link to blog post for more information:
Privacy and Security Information - Privacy MATTERS: Federal Breach Notification Rules -- NEXT WEEK. Are you ready?
Effective February 17, 2010, significant new compliance obligations will be imposed on business associates through the HITECH provisions of the American Recovery and Reinvestment Act of 2009 ("ARRA"). Business associates (or organizations that use or disclose protected health information on behalf of covered entities subject to HIPAA) will be directly liable for compliance with certain provisions of the HIPAA Privacy Rule and the HIPAA Security Standards, and may be audited by the Department of Health and Human Services ("HHS"). They will also be subject to increased civil and criminal penalties for non-compliance.
DATA PRIVACY DAY REMINDER: Time to update business associate agreements to reflect HITECH's new breach-notice provisions and other requirements. Business associates must also--at a minimum--(i) undertake and complete a security risk assessment, (ii) prepare and adopt written security policies and procedures, and (iii) conduct workforce training in their policies and procedures.
Link to blog post for more information:
Privacy and Security Information - Privacy MATTERS: Federal Breach Notification Rules -- NEXT WEEK. Are you ready?
Monday, January 4, 2010
New Regulations Propose a Definition of 'Meaningful Use'
Written by Dianne
On December 30, 2009, the Centers for Medicare & Medicare Services (CMS) and the Office of the National Coordinator for Health Information Technology (ONC) issued interim final rules necessary to implement electronic health record (EHR) incentive programs enacted under the American Recovery and Reinvestment Act of 2009. The ONC rule sets initial standards, implementation specifications, and certification criteria for EHR technology. The CMS rule provides a long-awaited definition of the concept of “meaningful use” of EHR technology. Both regulations are open to public comment.
The ONC Rule
The ONC rule calls for the industry to standardize the way in which EHR information is exchanged between organizations, and sets forth criteria required for an EHR technology to be certified. These standards will support meaningful use and data exchange among providers who must use certified EHR technology to qualify for Medicare and Medicaid incentives.
The proposed rule relies heavily on existing standards for the interoperability of health information technologies, including those established and/or promoted by Health Level 7, Inc. (HL7), the National Institute of Standards and Technology (NIST), and Integrating the Healthcare Enterprise (IHE). The standards also rely on existing classification and nomenclature systems including SNOMED CT, ICD-9 and 10, X12, LOINC, NCPDP, and RxNorm.
ONC’s interim final rule may be viewed at http://www.federalregister.gov/inspection.aspx#special.. There is a 60 day comment period.
The CMS Rule
CMS’ proposed regulation defines and specifies how to demonstrate 'meaningful use' of EHR technology, which is a prerequisite for receiving incentive payments. The rule also outlines proposed payment methodologies for the Medicare and Medicaid EHR incentive programs.
The proposed criteria for meaningful use focus on electronically capturing health information in a coded format, using that information to track key clinical conditions, communicating that information for care coordination purposes, and initiating the reporting of clinical quality measures and public health information.
The criteria are based on a series of specific objectives, each of which is tied to a proposed measure that all eligible professionals and hospitals must meet in order to demonstrate that they are meaningful users of certified EHR technology. For Stage 1, which begins in 2011, CMS proposes 25 objectives/measures for eligible professionals and 23 objectives/measures for eligible hospitals that must be met to be deemed a meaningful EHR user.
CMS’ proposed rule may be viewed at http://www.cms.hhs.gov/Recovery/11_HealthIT.asp. There is a 60 day comment period.
On December 30, 2009, the Centers for Medicare & Medicare Services (CMS) and the Office of the National Coordinator for Health Information Technology (ONC) issued interim final rules necessary to implement electronic health record (EHR) incentive programs enacted under the American Recovery and Reinvestment Act of 2009. The ONC rule sets initial standards, implementation specifications, and certification criteria for EHR technology. The CMS rule provides a long-awaited definition of the concept of “meaningful use” of EHR technology. Both regulations are open to public comment.
The ONC Rule
The ONC rule calls for the industry to standardize the way in which EHR information is exchanged between organizations, and sets forth criteria required for an EHR technology to be certified. These standards will support meaningful use and data exchange among providers who must use certified EHR technology to qualify for Medicare and Medicaid incentives.
The proposed rule relies heavily on existing standards for the interoperability of health information technologies, including those established and/or promoted by Health Level 7, Inc. (HL7), the National Institute of Standards and Technology (NIST), and Integrating the Healthcare Enterprise (IHE). The standards also rely on existing classification and nomenclature systems including SNOMED CT, ICD-9 and 10, X12, LOINC, NCPDP, and RxNorm.
ONC’s interim final rule may be viewed at http://www.federalregister.gov/inspection.aspx#special.. There is a 60 day comment period.
The CMS Rule
CMS’ proposed regulation defines and specifies how to demonstrate 'meaningful use' of EHR technology, which is a prerequisite for receiving incentive payments. The rule also outlines proposed payment methodologies for the Medicare and Medicaid EHR incentive programs.
The proposed criteria for meaningful use focus on electronically capturing health information in a coded format, using that information to track key clinical conditions, communicating that information for care coordination purposes, and initiating the reporting of clinical quality measures and public health information.
The criteria are based on a series of specific objectives, each of which is tied to a proposed measure that all eligible professionals and hospitals must meet in order to demonstrate that they are meaningful users of certified EHR technology. For Stage 1, which begins in 2011, CMS proposes 25 objectives/measures for eligible professionals and 23 objectives/measures for eligible hospitals that must be met to be deemed a meaningful EHR user.
CMS’ proposed rule may be viewed at http://www.cms.hhs.gov/Recovery/11_HealthIT.asp. There is a 60 day comment period.
Subscribe to:
Posts (Atom)