What a Healthcare Compliance Attorney Heard at the OCR’s HIPAA Security Conference
I spent two days at the beginning of September at the National Institute of Standards and Technology campus in Gaithersburg, Maryland, at the conference NIST co-hosts with the Office for Civil Rights on HIPAA security. It is a government event held on a federal campus, which keeps it small, and the attendance tends to attract those closest to the work: the people in the room are the ones writing the guidance, enforcing the rules, or responsible for following them. Over two days I heard presentations from and spoke with OCR leadership, with security practitioners, and with the people who carry compliance responsibility inside healthcare organizations. I went expecting to spend most of my attention on the proposed Security Rule overhaul, which has drawn heavier objection from the healthcare industry than any HIPAA rulemaking in years. OCR Deputy Director Timothy Noonan has previously said the agency received roughly 4,745 comments on it. A great many raised the same point: the proposed requirements would cost too much, and the organizations least able to absorb that cost would be hit...


