Showing posts with label HIPAA. Show all posts
Showing posts with label HIPAA. Show all posts

Sunday, January 24, 2010

HIPAA enforcement by state attorneys general: The shape of things to come

from David Harlow's Health Care Law Blog

Connecticut Attorney General Richard Blumenthal entered a brave new world yesterday, as the first state AG to file a HIPAA enforcement action under the "Son of HIPAA" amendments found in the HITECH Act.  Among other HIPAA changes made in the new law (all of which should be of concern to health care providers, health care payors, health care clearinghouses  -- "covered entities" or CEs -- and their "business associates" -- vendors who touch electronic protected health information or ePHI), there is a provision that permits state attorneys general to file HIPAA enforcement actions on behalf of the people of their state, in order to protect their interests, and to seek injunctive relief and/or money damages.  See Sec. 13410(e) of ARRA (p. 160 of HR 1 PDF)

The basic facts of the case are not unfamiliar:  A hard drive gone missing from a health insurance company's offices, this one with unencrypted information about 250,000 plan members.  The insurer, Health Net, failed to promptly notify data subjects that the data had gone missing, taking six months to issue a notice and letters to affected individuals and offer credit monitoring and repair for anyone affected.  Unfortunately, data breaches are all too common.  See, for example, my post on the Virginia health data breach last year, and the recent Chilmark Research post asking, in essence, whether we can reasonably expect a breach-free world.

While asserting a HIPAA claim is new territory for state AGs, the crux of the claim is really a consumer protection claim, one of the state AGs' mainstays.

Continue Reading

Tuesday, September 22, 2009

The Health Care Blog: HIPAA's broken promises

By SUSANNAH FOX

If you hate HIPAA, it’s your lucky day. Paul Ohm is handing you ammunition in his article, “Broken Promises of Privacy: Responding to the Surprising Failure of Anonymization.” His argument: our current information privacy structure is a house built on sand.

Read More
Reblog this post [with Zemanta]

Thursday, July 30, 2009

Standards for Privacy of Individually Identifiable Health Information

Agency Information Collection Request. 30-Day Public Comment Request The Privacy Rule implements the privacy requirements of the Administrative Simplification subtitle of the Health Insurance Portability and Accountability Act of 1996. The final regulation requires covered entities (as defined in the regulation) to maintain strong protections for the privacy of individually identifiable health information; to use or disclose this information only as required or permitted by the Rule or with the express written authorization of the individual; to provide a notice of the entity’s privacy practices; and to document compliance with the Rule. Read More

Sunday, December 7, 2008

Courts in 2 states rule on reach of HIPAA in medical liability cases

By Amy Lynn Sorrel, AMNews staff. Dec. 15, 2008 -- Some experts say the decisions point to ongoing confusion over the federal privacy statute in legal proceedings. As HIPAA continues to raise hurdles for defendants in medical liability cases, courts in Georgia and Michigan addressed the role of the statute. The courts interpreted to what extent, if any, the Health Insurance Portability and Accountability Act prevents a defendant physician's attorney from informally interviewing a plaintiff's prior or subsequent treating doctor in the course of litigation. The plaintiffs in the two cases sought to prevent any discussions regarding their medical histories, saying that would violate the federal privacy statute. In a Nov. 3 ruling, the Georgia Supreme Court found that HIPAA preempted a state law allowing such oral communications without first notifying the patient. Justices unanimously said the federal regulation "affords patients more control over their medical records," and defendants must comply with the stronger privacy regulations. That means they may have those discussions, but only after obtaining patient authorization, a court order or other legal instruction. The defendant physician in the case is asking the high court to reconsider its decision. In a similar case in Michigan, the defendant physician had obtained a protective order, as outlined under the federal HIPAA statute, to speak with the plaintiff's other treating doctors. But the plaintiff argued in court documents that the written medical records were sufficient. If more information were needed, the defendant could formally depose the plaintiff's physicians, the plaintiff said. The Court of Appeals of Michigan unanimously disagreed in a Nov. 18 decision. While HIPAA supersedes state law with more stringent privacy protections -- which the defendant followed -- it does not forbid informal conversations. Those discussions can help keep litigation costs down and allow the parties to investigate what information could be useful at trial, judges said. The plaintiff is appealing the decision to the state Supreme Court, but her attorney declined to comment further. The high court will decide whether to accept the case.

Thursday, October 30, 2008

DHHS OIG Nationwide Review of CMS HIPAA Oversight

On October 7, 2003, the U.S. Department of Health and Human Services delegated to CMS: (I) the authority and responsibility to interpret, implement, and enforce the HIPAA Security Rule provisions; (2) the authority to conduct compliance reviews and to investigate and resolve complaints ofHIPAA Security Rule noncompliance; and (3) the authority to impose civil monetary penalties for a covered entity's failure to complywith the HIPAA Security Rule provisions. The Final Rule for enforcement of this delegation became effective on February 16, 2006. Our objective was to evaluate the effectiveness of CMS's oversight and enforcement of covered entities' implementation of the HIPAA Security Rule. CMS had taken limited actions to ensure that covered entities adequately implement the HIPAA Security Rule. These actions had not provided effective oversight or encouraged enforcement of the HIPAA Security Rule by covered entities. Although authorized to do so by Federal, regulations as of February 16,2006, CMS had not conducted any HIPAA Security Rule compliance reviews of covered entities. To fulfill its oversight responsibilities, CMS r{{lied on complaints to identify any noncompliant covered entities that it might investigate. As a result, CMS had no effective mechanism to ensure that covered entities were complying with the HIPAA Security Rule or that ePHI was being adequately protected. Although reliance on complaints alone was ineffective for identifying noncompliant covered entities, we noted that CMS had an effective process for receiving, categorizing, tracking, and resolving complaints. CMS has developed and implemented detailed procedures for receiving complaints, communicating with filed-against entities, coordinating with the Office for Civil Rights for complaints with privacy elements, developing corrective action plans, and remediating complaints. Ongoing Office of Inspector General audits of various hospitals nationwide indicate that CMS needs to become more proactive in overseeing and enforcing implementation of the HIPAA Security Rule by focusing on compliance reviews. Preliminary results of these audits show numerous, significant vulnerabilities in the systems and controls intended to protect ePHI at covered entities. These vulnerabilities place the confidentiality and integrity of ePHI at high risk. During our audit, CMS began taking steps to conduct compliance reviews. After we completed our fieldwork but before we issued our report, CMS executed a contract to conduct compliance reviews at covered entities. We recommend that CMS establish policies and procedures for conducting HIPAA Security Rule compliance reviews of covered entities. CMS did not agree with our findings because it believes that its complaint-driven enforcement process has furthered the goal of voluntary compliance. CMS agreed, however, that compliance reviews are a useful enforcement tool as part of a more comprehensive enforcement strategy. CMS agreed with our recommendation to establish specific policies and procedures for conducting compliance reviews of covered entities but emphasized that compliance reviews are just one of several tools that can be used to promote compliance. Although CMS’s complaint-driven enforcement process has furthered the goal of voluntary compliance, the significant vulnerabilities we identified at hospitals throughout the country would not generally have been identified in HIPAA Security Rule complaints. In fact, CMS has received very few complaints regarding potential HIPAA Security Rule violations. Including compliance reviews of covered entities to its oversight process will enhance CMS’s ability to determine whether the HIPAA Security Rule is being properly implemented. OIG Report

Monday, October 6, 2008

Is your EMR legal?

By Pamela Lewis Dolan, AMNews staff. Oct. 13, 2008 in American Medical News Questions are emerging as more physicians go electronic. Federal Rules of Civil Procedure, approved by the U.S. Supreme Court in December 2006, not only make any electronically stored data discoverable in a trial, but also open up physicians to several new liabilities inherent in the detail electronic data provides. For example, if a nurse records information under your login and password, and that information is incorrect, you could be the one held liable. Or the record's metadata -- the time stamp of who entered what when -- can dispute a doctor's version of events. While EMRs are touted as a way to make life easier for physicians, health IT and legal professionals say they can make life miserable for a doctor who buys the wrong system, or uses it in the wrong way. "Where these issues can raise their heads is somewhat unpredictable," said Reed Gelzer, MD, co-founder of Advocates for Documentation Integrity and Compliance, an advocacy and consulting group that educates physicians and health care entities on the legal EMR. Dr. Gelzer said electronic records can save you when the record-keeping combines with the metadata to provide an accurate picture. But, as some recent cases of snooping hospital employees have proven, EMRs can also detect when someone violates HIPAA. And, just because an EMR creates something that looks like a medical record doesn't mean that document fits the legal definition of a medical record.

Thursday, October 2, 2008

California Enacts Two Laws on Patient Privacy

In Wall Street Journal Health Blog Posted by Jacob Goldstein California Gov. Arnold Schwarzenegger yesterday signed into law two bills designed to protect patient privacy. In recent months, the privacy of dozens of high-profile patients at UCLA Medical Center was violated when unauthorized employees looked at their files. What’s more, plenty of folks have cited privacy worries as one of the barriers slowing the move toward electronic record-keeping in health care. So it makes sense that California’s Legislature would have been eager to pass (and the governor ready to sign) the new laws. They allow for penalties of up to $250,000 for breaches of patient privacy, and create a new “Office of Health Information Integrity” within the state health department.

Wednesday, August 27, 2008

After Hospital’s Celebrity Snooping, a Push for Tougher Penalties

Posted by Jacob Goldstein in WSJ Health blog In recent months, we’ve heard one report after another that employees at UCLA Medical Center have improperly peeked at the files of celebrities such as Britney Spears, Farrah Fawcett and Maria Shriver. Those reports apparently made their way up to Sacramento as well. California’s state Senate yesterday passed a bill that would create a state Office of Health Information Integrity, authorized to levy fines of as much as $250,000. The bill is online here; a list of who voted for and against is here.

Friday, August 22, 2008

To Adopt ICD-10-CM and ICD-10-PCS; Proposed Rule

This proposed rule would modify two of the medical data code set standards adopted in the Transactions and Code Sets final rule published in the Federal Register. It would also implement certain provisions of the Administrative Simplification subtitle of the Health Insurance Portability and Accountability Act (HIPAA) of 1996. Specifically, the proposed rule would modify the standard code sets for coding diagnoses and inpatient hospital procedures by concurrently adopting the International Classification of Diseases, Tenth Revision, Clinical Modification (ICD-10-CM) for diagnosis coding, and the International Classification of Diseases, Tenth Revision, Procedure Coding System (ICD-10-PCS) for inpatient hospital procedure coding. These new codes would replace the International Classification of Diseases, Ninth Revision, Clinical Modification (ICD-9-CM) Volumes 1 and 2, and the International Classification of Diseases, Ninth Revision, Clinical Modification (CM) Volume 3 for diagnosis and procedure codes, respectively. DATES: Comments will be considered if we receive them at the appropriate address, as provided below, no later than 5 p.m. on October 21, 2008.

Modifications to the HIPAA Electronic Transaction Standards

This rule proposes to adopt updated versions of the standards for electronic transactions originally adopted in the regulations entitled, ``Health Insurance Reform: Standards for Electronic Transactions,'' published in the Federal Register on August 17, 2000, which implemented some of the requirements of the Administrative Simplification subtitle of the Health Insurance Portability and Accountability Act of 1996 (HIPAA). These standards were modified in our rule entitled, ``Health Insurance Reform: Modifications to Electronic Data Transaction Standards and Code Sets,'' published in the Federal Register on February 20, 2003. This rule also proposes the adoption of a transaction standard for Medicaid Pharmacy Subrogation. In addition, this rule proposes to adopt two standards for billing retail pharmacy supplies and professional services, and to clarify who the ``senders'' and ``receivers'' are in the descriptions of certain transactions. DATES: To be assured consideration, comments must be received at one of the addresses provided below, no later than 5 p.m. on October 21, 2008.

Monday, July 7, 2008

Criminal HIPAA case targets employee, not clinic, for breach

By Amy Lynn Sorrel, AMNews staff. July 14, 2008. The latest HIPAA criminal case may signal more aggressive efforts by the government to root out privacy breaches, while highlighting some legal risks for doctors and other "covered entities" for violations made by their employees, experts said.