HIPAA Final Rule: Security Standards, General Rules & Administrative Safeguard Modifications

February 5, 2013.  Today, we cover the modifications to Security Standards:  General Rules, and Administrative Safeguards in the HIPAA Security Rule, as modified by the Final Rule:  Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules under the Health Information Technology for Economic and Clinical Health Act [HITECH Act] and the Genetic Information Nondiscrimination Act; Other Modifications of the HIPAA Rules, which was published in the Federal Register on January 25, 2013.  The effective date of the Final Rule is March 26, 2013, and covered entities and business associates must comply by September 23, 2013. Security Standards:  General Rules.  The five General Rules govern how the administrative, physical,…

READ MORE

ONC Publishes Stage 2 EHR Technology Certification Criteria NPRM

On March 7, 2012, the Office of the National Coordinator for Health Information Technology (ONC) of the Department of Health and Human Services (HHS) published in the Federal Register its notice of proposed rule making (NPRM) entitled Health Information Technology:  Standards, Implementation Specifications, and Certification Criteria for Electronic Health Record [EHR] Technology, 2014 Edition; Revisions to the Permanent Certification Program for Health Information Technology [pp. 13832-13885].  Comments to HHS may be made until 5 PM on May 7, 2012. The summary of the NPRM is included here: “Under section 3004 of the Public Health Service Act, the Secretary of Health and Human Services is proposing to revise the initial set…

READ MORE

IFR for HIPAA EFT Standard to be Published in Federal Register January 10, 2012

HIPAA.com discussed in its preceding posting this Interim Final Rule (IFR) for “adoption of standards and operating rules for Electronic Funds Transfers (EFT) and operating rules for remittance advice…”, as required by the Patient Protection and Affordable Care Act of 2010 (Public Law 111-148).  [124 STAT. 153] The Office of Management and Budget (OMB) completed its regulatory review on January 3, 2012, and the IFR is available for pre-publication review prior to January 10, 2012, when it will be published in the Federal Register.  The title of the IFR is: Administrative Simplification:  Adoption of Standards for Health Care Electronic Funds Transfers (EFTs) and Remittance Advice. The Summary in the pre-publication…

READ MORE

IFR for EFT at OMB

The Centers for Medicare & Medicaid Services (CMS) of the Department of Health and Human Services (HHS) has sent to the Office of Management and Budget (OMB) its Interim Final Rule (IFR) for “adoption of standards and operating rules for Electronic Funds Transfers (EFT) and operating rules for remittance advice….” Following the December 15 receipt and subsequent review of the IFR by OMB, the IFR is expected to be published in the Federal Register before January 1, 2012, as required by the Affordable Care Act of 2010 (Public Law 111-148). [124 STAT. 153] The legal authority for the IFR is Section 1104 (Administrative Simplification) of the Affordable Care Act.  Section 1104…

READ MORE

HHS Extends Life of Temporary EHR Technology Certification Program

The Office of the National Coordinator for Health Information Technology (ONC) of the Department of Health and Human Services (HHS) published a notice in the Thursday, November 3, 2011, Federal Register that extends the life of the “temporary certification program for health information technology” beyond its expected sunset date of December 31, 2011, to at least summer 2012.  “We believe that the sunset of the temporary certification programs [ONC-Authorized Testing and Certification Bodies (ATCBs)] should be tied to the effective date of the final rule that we intend to issue in summer 2012, which is expected to adopt new and revised standards, implementation specifications, and certification criteria for EHR technology in…

READ MORE

OMB Completes Review of Final Rules for EHR Incentive Program and for Initial Certification Criteria

On Friday, July 9, 2010, the Office of Management and Budget (OMB) completed review of the two Final Rules:  Health Information Technology:  Initial Set of Standards, Implementation Specifications, and Certification Criteria for Electronic Health Record (RIN:  0991-AB58) and Electronic Health Record (EHR) Incentive Program (RIN: 0938-AP78).  RIN means Regulatory Identification Number, used to track a regulatory action through its development.  These rules are on a fast track, follow on the heels of the June 24 Final Rule:  Establishment of the Temporary Certification Program for Health Information Technology (75 Federal Register 36157-36209), and are expected to be available for prepublication inspection at the Federal Register imminently.  For additional information and updates,…

READ MORE

Final Rules for EHR Incentives and Certification Criteria at OMB for Review

The Office of Management and Budget (OMB) received in early July for Executive Order (EO) 12866 Regulatory Planning and Review two Final Rules relating to electronic health record (EHR) incentives and certification criteria required under the Health Information Technology for Economic and Clinical Health Act (HITECH Act) that was enacted on February 17, 2009 as part of the American Recovery and Reinvestment Act of 2009. On Friday, July 2, 2010, OMB received from the Office of the Secretary at the Department of Health and Human Services (HHS) for review Health Information Technology:  Initial Set of Standards, Implementation Specifications, and Certification Criteria for Electronic Health Record Technology; Final Rule.  The Interim Final…

READ MORE

HHS Publishes Proposed Rule for Electronic Health Record Incentive Program

HHS published today in the Federal Register:  “Medicare and Medicaid Programs–Electronic Health Record Incentive Program; Proposed Rule.”  75 FR 1844-2011.  Comments on this Notice of Proposed Rulemaking (NPRM) may be submitted to HHS no later than March 15, 2010.  Here is the Summary from the NPRM: “This proposed rule would implement the provisions of the American Recovery and Reinvestment Act of 2009 (ARRA)(Public Law 111-5) that provide incentive payments to eligible professionals (EPs) and eligible hospitals participating in Medicare and Medicaid programs that adopt and meaningfully use certified electronic health record (EHR) technology.  The proposed rule would specify the initial criteria an EP and eligible hospital must meet in order…

READ MORE

HHS Publishes EHR Standards, Implementation Specifications and Certification Criteria IFR

HHS published today in the Federal Register:  “Health Information Technology: Initial Set of Standards, Implementation Specifications, and Certification Criteria for Electronic Health Record Technology”  75 FR 2013-2047.  This Interim Final Rule (IFR) is effective February 2, 2010.  Comments on the IFR may be submitted to HHS no later than March 15, 2010.  Here is the Summary from the IFR: “The Department of Health and Human Services (HHS) is issuing this interim final rule with a request for comments to adopt an initial set of standards, implementation specifications, and certification criteria, as required by section 3004(b)(1) of the Public Health Service Act.  This interim final rule represents the first step in…

READ MORE

Exploring HIPAA and HITECH Act Definitions: Part 16

From now through early December, HIPAA.com is providing a run through of HIPAA transaction & code set, privacy, and security definitions, along with relevant HITECH Act definitions pertaining to breach notification, securing of protected health information, and electronic health record (EHR) standards development and adoption. These definitions are key to understanding the referenced HIPAA and HITECH Act enabling regulations that are effective now and that will require compliance by covered entities and business associates now or in the months ahead, as indicated in HIPAA.com’s timeline. Each posting will contain three definitions, with a date reference to the Federal Register, Code of Federal Regulations (CFR), or statute, as appropriate. Exploring HIPAA…

READ MORE