Oct 6 Deadline for Laboratories to Comply with HIPAA Privacy Rule Changes
The deadline for compliance following the introduction of the new HIPAA Privacy Rule is October 6, 2014. Hospitals with on-site laboratories subject to the Clinical Laboratory Improvement Amendments of 1988 (“CLIA”) as well as laboratories covered by HIPAA must adapt policies and procedures to take the new legislation changes into account. The change provides patients with improved access to their medical data. The changes have now been finalized by the HHS Office for Civil Rights and the Centers for Disease Control and Prevention and Centers for Medicare & Medicaid Service, which amended CLIA regulations earlier this year. Laboratories are currently permitted to provide medical test results directly to patients, provided that it can be established that the results of the tests belong to patient in question. Results can also be released to patients’ nominated representatives. The change to HIPAA privacy laws from October 6 mean that laboratories are now required to provide PHI to patients upon request and that patients have full access rights. Any non-HIPAA covered entity is...
Government Conference Highlights Importance of HIPAA Compliance
This September the Government held the 7th annual conference, Safeguarding Health Information: Building Assurance Through HIPAA Security, in Washington, D.C. The conference was co-hosted by the National Institute of Standards and Technology (NIST), the Office for Civil Rights (OCR) and the Department of Health and Human Services (HHS). One of the main aims of the conference was to highlight the current state of health information management and to explore the use of information technology in healthcare while ensuring Health Insurance Portability and Accountability Act (HIPAA) compliance. Practical advice and strategies were also provided to streamline implementation of the HIPAA Security Rule. The HIPAA Security Rule was introduced to set a standard to protect the privacy and confidentiality of patients’ health information. Healthcare organizations and other HIPAA covered entities are required implement appropriate safeguards to protect electronic health information during storage and transit. Appropriate technical, administrative and physical safeguards must be employed to prevent...
WEDI Announces HIPAA Health Plan Identifier (HPID) Usage Survey Results
The nation’s leading non-profit authority on Information Technology usage in the U.S healthcare industry has announced the results of a recent survey conducted on the use of the Health Plan Identifier (HPID) in electronic transactions under the Health Insurance and Portability and Accountability Act (HIPAA). The Workgroup for Electronic Data Interchange (WEDI) has now processed the responses from 262 participants from its recent survey, which was conducted between Aug 20 and Sept 5 of this year. Respondents included software vendors, providers, clearing houses, administrators and multiple stakeholders. The findings have been posted online and sent to the Department of Health and Human Services (HHS). Key findings of the survey: • The value of HPID use was only recognized by 15% of stakeholders • Almost a quarter (24%) of respondents had no issues with the implementation of HPID alongside other mandates • 39% of respondents are not able to predict the likely impact while 51% believe they will be impacted by an increase in granularity • 55% of respondents agreed that HPID use within...
New OCR Director Makes First Speech on OCR HIPAA Enforcement
New OCR Director, Jocelyn Samuels, has chosen National Health IT Week to make her first major speech as head of the government’s HIPAA enforcement team. Samuels took over from Director Leon Rodriguez earlier this year at a time when the second round of compliance audits were in the process of being finalized. The audits are scheduled to take place this fall and the healthcare industry is keen to discover the new director’s plans for enforcing HIPAA. Samuels has a wealth of experience in federal law enforcement having previously served as acting assistant attorney general for civil rights at the U.S. Department of Justice where she was tasked with enforcing the government’s regulations on discrimination. She also served as senior policy attorney at the Equal Employment Opportunity Commission, although she has not previously worked in the healthcare sector. In her 10-minute speech at the ONC’s 2014 Consumer Health Summit in Washington, Samuels announced that the OCR will be enforcing privacy provisions to ensure patients are given access to their health records. She believes it...
Aventura Hospital Suffers Third HIPAA Breach Exposing 82,601 Records
Aventura Hospital and Medical Center has discovered that the HIPAA breaches it suffered over the past two years were just the tip of the iceberg. It has just announced a third security breach which has affected up to 82,601 individuals. The healthcare provider has only recently identified the breach, although it started just one day after the last one was corrected. Between Oct. 1, 2012, and Dec. 31, 2012, the data of 948 patients were exposed, with a second HIPAA breach occurring between January 1, 2012, and September 12, 2012, affecting 2,560 patients. The third breach started the following day, September 13, 2012, with access to the data continuing until June 9, 2014. The latest HIPAA breach was caused by one of its business associates, Valesco Ventures. The company was alerted about an employee who could have inappropriately accessed patient data in May, although it was not until early June when it was confirmed that the employee in question improperly accessed patient names, dates of birth, and Social Security numbers of up to 82,601 individuals, according to a report on...



