HHS Publishes Guidance on how the HIPAA Privacy Rule Applies to Refill Reminders
The HIPAA Privacy Rule gives individuals greater control over how their medical data can be used and disclosed to third parties. The Rule prohibits the disclosure or use of patient PHI for the purposes of marketing. Before health information can be used to market products, services or pharmaceuticals to a patient, a written authorization must be provided stating that the patient opted in for this service. The purpose of the Privacy Rule is to offer patients better protection; however, the legislation should not interfere with patients receiving the care they need. Oftentimes, communications must be sent to patients advising them of medical matters, services, and even products. While there may be some overlap between marketing and general communications, provisions have been included in the legislation to take these into account. The HHS has now published further clarification on how the Privacy Rule applies to sending refill reminders and other communications that involve the provision of products and services, and explanations have been provided on exceptions to the Privacy Rule....
Omnibus Final Rule Now Enforceable
The HIPAA Omnibus Rule came into force in March this year, although the OCR gave covered entities a grace period in which to bring their organizations policies and procedures up to date with the new regulations. The Omnibus Rule expanded HIPAA to cover Business Associates of covered entities – and their subcontractors – with the 6 month grace period intended to give these newly covered organizations time to become compliant. That grace period expired today and the Omnibus Rule is now enforceable, with the OCR able to issue fines for any non-compliance issues it now discovers. The Omnibus Rule adds a number of security measures to ensure that private medical records are properly protected, including new restrictions on who is able to access those records. Breach Notification Rules have been updated and now presume that any unauthorized access of PHI is a reportable breach, and not just those which pose a significant risk of harm. Potential victims – as well as the OCR – must be notified of the breach within 60 days of its discovery. Any security breach must be now assessed to...
HHS Makes Final Updates to HIPAA Privacy and Security Rules
The HIPAA Omnibus Rule becomes enforceable this coming Monday, although the Department of Health and Human Services’ Office for Civil Rights has just announced that there will be a an enforcement delay for certain covered entities to give them more time to update their Notices of Privacy Practices. The introduction of the Omnibus Rule requires laboratories covered under HIPAA to update NPPs, although entities certified or exempt under the Clinical Laboratory Improvement Amendments (CLIA) will be given more time to update their NPPs, in addition to those organizations which have been relieved from the HIPAA Privacy Rule requirement to provide patients with access to their laboratory test results. The delay will not apply to laboratories which are part of larger healthcare organizations that do not have their own laboratory-specific NPPs. The delay was deemed necessary due to the requirement to update NPPs as part of the Omnibus Rule and CLIA, because of the proximity of the two rules. The Omnibus Ruling comes into force today, September 23, and CLIA, which amends § 164.524 of the...
Results of 2013 Medical Identity Theft Survey Released
The Ponemon Institute has published the results of its 2013 Survey on Medical Identity Theft. The survey, sponsored by the Medical Identity Fraud Alliance (MIFA), aims to discover the extent of medical identity theft in the U.S and its impact on the healthcare industry and consumers. The annual survey can be used as an indicator of the prevalence of medical identity theft in the United States and also to identify trends and gauge how effective HIPAA regulations have been. Medical Identity theft is a growing problem which has grave implications for both healthcare organizations and consumers. Data breaches carry heavy penalties for healthcare organizations if appropriate measures to protect electronic health records of both employees and patients have not been employed. Data analysis of the survey data suggests up to 1.84 million U.S. citizens have now become victims of medical identity theft and have had to cover $12 billion in costs and expenses as a result of the theft or inappropriate use of their medical data. The problem is not limited to finances as medical identity theft can...
Business Associates Responsible for 22 Percent of HIPAA Violations
The introduction of the Omnibus Rule extended HIPAA’s reach to include business associates of HIPAA-covered entities and requires them to adhere to the same set of standards as the healthcare organizations with which they do business. Business Associates are classed as any organization or individual that is required to handle, view or come into contact with Protected Health Information. This means the providers of hosting or data storage services will now be covered under HIPAA and will be required to sign a business agreement that stipulates they will abide by HIPAA regulations. They will also be subject to financial penalties if the Department of Health and Human Services discovers any non-compliance issues. The new rule was introduced to ensure patient health data is protected, and in the case of business associates the change in legislation is long overdue. BAs are responsible for the exposure of a considerable amount of patient data and since HIPAA was passed, BAs have been implicated in 22% of all security breaches according to an analysis of HHS breach reports conducted by...



