Important Information on HIPAA Business Associate Agreements
The Omnibus Rule has now been in effect for a week and is an amendment to HIPAA regulations which requires all Business Associate Agreements to be HIPAA-compliant. Any new BAA’s issued – or those issued after Sept 23, 2014 – must comply with the HIPAA Omnibus Rule; however the same applies to any business agreements already in place. Existing agreements must also be updated to take the new Omnibus Rule into account. If any agreements have not been updated, the HHS’ OCR will consider this a HIPAA violation and would be within its rights to issue a financial penalty for each agreement that does not comply with the new rule. It is therefore essential that healthcare organizations perform a full review of all BAA’s currently active and address any non-compliance issues. Issuing HIPAA Compliant Business Associate Agreements A HIPAA-compliant BAA must be issued and signed by a Business Associate (BA) to ensure that PHI is properly protected. A Business Associate is classed as any individual, company, organization or other entity that performs a function, offers a service or conducts...
Oct 6 Deadline for Laboratories to Comply with HIPAA Privacy Rule Changes
The deadline for compliance following the introduction of the new HIPAA Privacy Rule is October 6, 2014. Hospitals with on-site laboratories subject to the Clinical Laboratory Improvement Amendments of 1988 (“CLIA”) as well as laboratories covered by HIPAA must adapt policies and procedures to take the new legislation changes into account. The change provides patients with improved access to their medical data. The changes have now been finalized by the HHS Office for Civil Rights and the Centers for Disease Control and Prevention and Centers for Medicare & Medicaid Service, which amended CLIA regulations earlier this year. Laboratories are currently permitted to provide medical test results directly to patients, provided that it can be established that the results of the tests belong to patient in question. Results can also be released to patients’ nominated representatives. The change to HIPAA privacy laws from October 6 mean that laboratories are now required to provide PHI to patients upon request and that patients have full access rights. Any non-HIPAA covered entity is...
Government Conference Highlights Importance of HIPAA Compliance
This September the Government held the 7th annual conference, Safeguarding Health Information: Building Assurance Through HIPAA Security, in Washington, D.C. The conference was co-hosted by the National Institute of Standards and Technology (NIST), the Office for Civil Rights (OCR) and the Department of Health and Human Services (HHS). One of the main aims of the conference was to highlight the current state of health information management and to explore the use of information technology in healthcare while ensuring Health Insurance Portability and Accountability Act (HIPAA) compliance. Practical advice and strategies were also provided to streamline implementation of the HIPAA Security Rule. The HIPAA Security Rule was introduced to set a standard to protect the privacy and confidentiality of patients’ health information. Healthcare organizations and other HIPAA covered entities are required implement appropriate safeguards to protect electronic health information during storage and transit. Appropriate technical, administrative and physical safeguards must be employed to prevent...
WEDI Announces HIPAA Health Plan Identifier (HPID) Usage Survey Results
The nation’s leading non-profit authority on Information Technology usage in the U.S healthcare industry has announced the results of a recent survey conducted on the use of the Health Plan Identifier (HPID) in electronic transactions under the Health Insurance and Portability and Accountability Act (HIPAA). The Workgroup for Electronic Data Interchange (WEDI) has now processed the responses from 262 participants from its recent survey, which was conducted between Aug 20 and Sept 5 of this year. Respondents included software vendors, providers, clearing houses, administrators and multiple stakeholders. The findings have been posted online and sent to the Department of Health and Human Services (HHS). Key findings of the survey: • The value of HPID use was only recognized by 15% of stakeholders • Almost a quarter (24%) of respondents had no issues with the implementation of HPID alongside other mandates • 39% of respondents are not able to predict the likely impact while 51% believe they will be impacted by an increase in granularity • 55% of respondents agreed that HPID use within...
New OCR Director Makes First Speech on OCR HIPAA Enforcement
New OCR Director, Jocelyn Samuels, has chosen National Health IT Week to make her first major speech as head of the government’s HIPAA enforcement team. Samuels took over from Director Leon Rodriguez earlier this year at a time when the second round of compliance audits were in the process of being finalized. The audits are scheduled to take place this fall and the healthcare industry is keen to discover the new director’s plans for enforcing HIPAA. Samuels has a wealth of experience in federal law enforcement having previously served as acting assistant attorney general for civil rights at the U.S. Department of Justice where she was tasked with enforcing the government’s regulations on discrimination. She also served as senior policy attorney at the Equal Employment Opportunity Commission, although she has not previously worked in the healthcare sector. In her 10-minute speech at the ONC’s 2014 Consumer Health Summit in Washington, Samuels announced that the OCR will be enforcing privacy provisions to ensure patients are given access to their health records. She believes it...



