
Son of HIPAA--Who's Been Looking at My Data?
If your patient records aren't already stored digitally, they are likely to be digitized soon. There is a tremendous push by the federal government-as well as by some private payors and self-insured employers-to get all healthcare providers wired in the near future, in order to better coordinate patient care, improve outcomes, and "bend the cost curve" all at the same time.
If your patient records aren't already stored digitally, they are likely to be digitized soon. There is a tremendous push by the federal government-as well as by some private payors and self-insured employers-to get all healthcare providers wired in the near future, in order to better coordinate patient care, improve outcomes, and "bend the cost curve" all at the same time. There are some financial incentives in play to achieving "
Once all that patient data-or as it is known in HIPAA-speak, protected health information (PHI)-is stored electronically, it becomes exposed to potential data breaches. In late September, two sets of federal regulations took effect that address the way in which PHI should be maintained, and the steps that should be taken to prevent a data breach and to notify the government and affected individuals in the event there is a data breach. Compliance with these rules-issued under authority of the HITECH Act by the
The exposure in case of violation is significant, both in terms of fines and penalties and in terms of bad publicity-certain data breaches require notice to potentially affected individuals via the general media in addition to notices required to be fled with the regulators. The new rules-I call them Son of HIPAA-are layered on top of existing HIPAA privacy and security rules: the FTC's
The key concept in the new breach notification rules is that encryption of patient data will eliminate the need to notify patients and the federal regulators in case of an inappropriate release of data. Such a release, if the data is encrypted (ie, unusable, unreadable, or indecipherable), is not considered a breach. Encryption is not required, though, and each affected entity must engage in a cost-benefit analysis before deciding whether to encrypt all affected data.
Another important aspect of the rule is the concept of harm-the regulators decided that not every data breach should trigger all of the notice requirements, just breaches that "pose a significant risk of financial, reputational, or other harm to the individual." For example, if an employee of a healthcare provider accesses a patient record inappropriately, but immediately realizes his or her mistake, and exits the record quickly and does not retain any PHI, that is not a reportable data breach.
Finally, "business associates" under HIPAA are now required to implement policies and procedures to maintain privacy and security of PHI, parallel to those that have been required of "covered entities" under HIPAA since the beginning. All business associate agreements and notice of privacy practices (NPPs) will have to be updated to account for the new requirements before February. Healthcare providers that wish to distinguish themselves should consider revising their NPPs to highlight the ease with which they will make copies of records available to patients. This is a bone of contention for many patients, and
By necessity, this is an extremely brief introduction to a very involved set of regulations. My hope is that you now have a sense of how important it is to be sure that your operations are fully compliant with the regulatory requirements before full enforcement and random field audits begin in February 2010.
Mr. Harlow, Principal of The Harlow Group LLC, is a healthcare lawyer and consultant based in Boston, MA. He helps healthcare providers and related businesses of all shapes and sizes realize their goals in an increasingly regulated environment. His blog,
Newsletter
Stay informed and empowered with Medical Economics enewsletter, delivering expert insights, financial strategies, practice management tips and technology trends — tailored for today’s physicians.