Patents Rights to Medical Test Data Improved under HIPAA
Access to personal healthcare information empowers patients to take charge of their health and work alongside their care providers. Gaining access to information has now become easier following the issuing of the final rule amending the Clinical Laboratory Improvement Amendments of 1988 (CLIA). The new change, which was announced today, allows a patient or his or her nominated representative to access the complete laboratory reports following medical testing. Previously a restriction existed under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Rule preventing access to the data in certain circumstances. As before, patients will be able to obtain their test results from their doctor, although now they are also able to request the information directly from the laboratory that conducted the tests. The new law ensures patient data is kept private with strong protections in place to prevent unauthorized access while ensuring the patient is provided with timely information they can use to improve their health. Three agencies within the HHS are responsible...
March 1st Deadline for 2013 HIPAA Breach Reports
The U.S Department of Health and Human Services requires all HIPAA covered entities to submit annual reports of HIPAA breaches, and the deadline for submitting 2013 breaches is fast approaching. While there is a requirement under the Breach Notification Rule for healthcare institutions and their business associates to notify the HHS of any breaches involving more than 500 individuals without delay, smaller breaches affecting fewer than 500 individuals only need to be included in an annual report. HIPAA-covered entities now only have a few weeks to submit the reports, which must be received by the HSS no later than March 1st, 2014. A PHI breach involving less than 500 individuals must be reported to the HHS within 60 days of the end of the calendar year during which the breach was discovered. Therefore any data breaches identified during 2013 must now be included in the report to the HHS. In many security breaches it is not immediately clear how many individuals have been affected. If an investigation is still ongoing, the entity in question should provide an estimate of the number...
Healthcare Organizations Concerned about HIPAA Security and Compliance
A recent survey conducted by eFax aimed to discover some of the main issues faced by HIPAA-covered entities when it comes to the transmission of Protected Health Information (PHI). The survey was conducted to allow the company to explore healthcare communications and to identify some of the key issues which need to be addressed to help IT administrators become, and stay, compliant with HIPAA. The survey was sent to the company’s corporate healthcare customers, which included large healthcare providers and hospitals, physician, group practices and medical suppliers. HIPAA Compliance is the Major Concern 54.1% of respondents said that HIPAA compliance was their biggest area of concern for dealing with the increase in paperwork that comes with healthcare exchanges and the Affordable Care Act. It is now 6 months on from the issuing of the Omnibus Rule and compliance is still clearly a major problem, as are the huge financial penalties that can be issued for HIPAA violations. 37.1% of respondents said that their biggest security concern about PHI and sensitive data was financial...
AV-Comparatives Rates FortiGuard Top Security Product with Full Marks for Anti-Phishing and Malware Removal
AV-Comparatives has given Fortinet’s FortiGuard full marks in its recent December Summary Report 2013. The Fortinet Advanced Threat Protection (APT) technology was given top marks (3 stars) for anti-phishing, proactive catch rate, file detection, malware removal, and its real-world test. For the report, AV-Comparatives assessed FortiGuard along with 21 other antivirus products for their ability to block malicious software without preventing legitimate content from being accessed. The assessments took place over the course of the year. AV-Comparatives publishes the findings of its research in its annual report and highlights the products that have performed the best and achieved the highest scores across all of the test areas. The reports help businesses choose the most effective anti-virus products. All of the 21 products under test achieved reasonable and acceptable scores in all test areas, although some products provided outstanding protection. Those products were recognized and give awards. AV-Comparatives CEO and Founder Andreas Clementi explained that not all of the products...
Windows XP No Longer HIPAA Compliant
If your organization has not yet upgraded your IT operating systems and is still using Windows XP on some or all workstations, it has only until April 8, 2014 to migrate to a new OS as Windows XP will no longer be HIPAA or meaningful use compliant in six weeks. Any organization found to be using the outdated software will be in violation of The Security Rule of the Health Insurance Portability and Accountability Act of 1996. Windows XP is now old and out of date with the software first introduced in 2001. Microsoft has now made the decision to stop issuing patches and security updates for XP, rendering it obsolete. Since software updates are a requirement under the Security Rule, companies will be forced to upgrade computer software. The cost of upgrading computer systems can be considerable, but the financial penalties organizations now face for HIPAA non-compliance are likely to be substantially higher. Since the deadline for upgrading software is just 12 weeks away, it does not give institutions very long to effect the appropriate changes. Healthcare organizations, government...



