Under the Health Information Technology for Economic and Clinical Health Act (HITECH Act), enacted as part of the American Recovery and Reinvestment Act of 2009, covered entities are required to report to the Secretary of the U.S. Department of Health and Human Services (HHS) any privacy or security breach affecting 500 or more individuals within 60 days of discovery of the breach by the covered entity or its business associate. The HHS Office for Civil Rights (OCR), which is responsible for privacy and security enforcement under the Health Insurance Portability and Accountability Act (HIPAA) and HITECH Act provisions that strengthened privacy and security enforcement, is required to post those breaches on…
Categories American Recovery and Reinvestment Act, Enforcement, Health IT and HITECH, HIPAA Law, Privacy, SecurityLeave a commentNearly 8.3 Million Individuals Impacted by 249 Privacy and Security Breaches Reported by HHS; More Training on Safeguarding PHI Required
Under the Health Information Technology for Economic and Clinical Health Act (HITECH Act), enacted as part of the American Recovery and Reinvestment Act of 2009, covered entities are required to report to the Secretary of the U.S. Department of Health and Human Services (HHS) any privacy or security breach affecting 500 or more individuals within 60 days of discovery of the breach by the covered entity or its business associate. The HHS Office for Civil Rights (OCR), which is responsible for privacy and security enforcement under the Health Insurance Portability and Accountability Act (HIPAA) and HITECH Act provisions that strengthened privacy and security enforcement, is required to post those breaches…
Categories American Recovery and Reinvestment Act, Enforcement, Health IT and HITECH, HIPAA Law, Privacy, SecurityLeave a commentPermanent HIT Certification Final Rule Published by ONC in Federal Register
January 7, 2011. The Department of Health and Human Services (HHS) Office of the National Coordinator for Health Information Technology (ONC) published today in the Federal Register the final rule for Establishment of the Permanent Certification Program for Health Information Technology (HIT), available online. This regulation is effective on February 7, 2011. According to the January 3, 2011, HHS News Release, “[t]he temporary certification program, established through a final rule published on June 24, 2010, will continue in effect until it sunsets on December 31, 2011, or at a later date when the processes necessary for the permanent certification program to operate are completed. ONC expects to stand-up the programmatic…
Categories Health IT and HITECH, Meaningful UseLeave a commentHealthcare Providers Receive FTC Red Flags Exemption from Congress
HIPAA.com has covered the provisions of the Federal Trade Commission (FTC) Red Flags Rule in earlier postings. Congressional action now exempts healthcare providers from compliance with the provisions of the Red Flags Rule. On Tuesday, December 7, the House by voice vote joined the Senate in passage of S.3987, the Red Flag Program Clarification Act of 2010. On November 30, 2010, the Senate passed this legislation by unanimous consent. The bill has been cleared to the White House for signature. The following information from the Library of Congress summarizes S 3987 (see http://thomas.loc.gov): “Amends the Fair Credit Reporting Act, with respect to federal agency (red flag) guidelines regarding identity theft…
Categories Red Flags Rules1 Comment200 Breaches Impacting Almost 5.9 Million Individuals, with Theft and Loss of Laptops and PEDs Major Cause
December 2, 2010.M Under the Health Information Technology for Economic and Clinical Health Act (HITECH Act), enacted as part of the American Recovery and Reinvestment Act of 2009, covered entities are required to report to the Secretary of the Department of Health and Human Services (HHS) any breach affecting 500 or more individuals within 60 days of discovery of the breach by the covered entity or its business associate. The HHS Office for Civil Rights (OCR), which is responsible for HIPAA privacy and security enforcement, is required to post these HIPAA privacy or security breaches on its Web site (please note that this URL is a change from the initial…
Categories American Recovery and Reinvestment Act, Enforcement, Health IT and HITECH, Privacy, SecurityLeave a commentHHS Pulls Breach Notification Final Rule
The HIPAA Administrative Simplification; Notification in the Case of Breach Final Rule (Regulation Identifier Number (RIN) 0991-AB56) has been at the Office of Management and Budget (OMB) since May 14, 2010, for Executive Order (EO) 12866 review and approval prior to publication in the Federal Register. On July 28, 2010, HHS “withdrew” this Final Rule, with the following explanation: “The Interim Final Rule for Breach Notification for Unsecured Protected Health Information, issued pursuant to the Health Information Technology for Economic and Clinical Health (HITECH) Act, was published in the Federal Register on August 24, 2009, and became effective on September 23, 2009. During the 60-day public comment period on the…
Categories American Recovery and Reinvestment Act, Enforcement, Health IT and HITECH, HIPAA Law, Privacy, SecurityLeave a commentEHR Incentive and Certification Criteria Final Rules Published in Federal Register
The EHR Incentive and Certification final rules were published in the Federal Register this morning, July 28, 2010. HIPAA.com provides the title, summary, effective date, and URL for each below. Department of Health and Human Services, Centers for Medicare & Medicaid Services, “42 CFR Parts 412, 413, 422, and 495; Medicare and Medicaid Programs; Electronic Health Record Incentive Program; Final Rule, Federal Register, 75(144), Wednesday, July 28, 2010, pp. 44313-44588. Summary: This final rule implements the provisions of the American Recovery and Reinvestment Act of 2009 (ARRA)(Public Law 111-5) that provide incentive payments to eligible professionals (EPs), eligible hospitals and critical access hospitals (CAHs) participating in Medicare and Medicaid programs…
Categories American Recovery and Reinvestment Act, Health IT and HITECH, Meaningful UseLeave a commentOMB Completes Review of Final Rules for EHR Incentive Program and for Initial Certification Criteria
On Friday, July 9, 2010, the Office of Management and Budget (OMB) completed review of the two Final Rules: Health Information Technology: Initial Set of Standards, Implementation Specifications, and Certification Criteria for Electronic Health Record (RIN: 0991-AB58) and Electronic Health Record (EHR) Incentive Program (RIN: 0938-AP78). RIN means Regulatory Identification Number, used to track a regulatory action through its development. These rules are on a fast track, follow on the heels of the June 24 Final Rule: Establishment of the Temporary Certification Program for Health Information Technology (75 Federal Register 36157-36209), and are expected to be available for prepublication inspection at the Federal Register imminently. For additional information and updates,…
Categories American Recovery and Reinvestment Act, Health IT and HITECH, Meaningful UseLeave a commentOCR Reports 107 Breaches Affecting Over 4 Million Individuals (II)
The Office for Civil Rights (OCR) regularly updates its Web site listing of breaches affecting 500 or more individuals. As of July 2, 2010, there were 107 breaches listed that were reported to have occurred between September 22, 2009 and June 11, 2010. Individuals affected by these publicly listed breaches totaled 4,086,980. Six of the 107 breaches, or 5.6% of the total, affected 3,353,627 individuals, or 82% of the total. This is the second of three postings that analyzes the data from these 107 breaches. This posting (II) covers paper breaches. The first posting (I) covered electronic breaches, and the final posting (III) looks at the prevalence of business associate…
Categories American Recovery and Reinvestment Act, Enforcement, Health IT and HITECH, HIPAA Law, Privacy, SecurityLeave a commentHIPAA Privacy, Security, Enforcement Rule Modifications NPRM at Federal Register
This morning, July 8, 2010, HHS’ Modifications to the HIPAA Privacy, Security, and Enforcement Rules under the Health Information Technology for Economic and Clinical Health Act Notice of Proposed Rulemaking (NPRM) was posted at the Federal Register for public access prior to publication. It will be published on Wednesday, July 14, 2010. The 234 page NPRM can be accessed in portable document format (pdf) online at: http://www.ofr.gov/OFRUpload/OFRData/2010-16718_PI.pdf. There will be a 60-day comment period relating to the content of the NPRM. HIPAA.com will provide a synopsis of the NPRM in a series of postings following publication in the Federal Register.
Categories American Recovery and Reinvestment Act, Enforcement, Health IT and HITECH, HIPAA Law, Privacy, SecurityLeave a comment