from David Harlow's Health Care Law Blog
Connecticut
Attorney General Richard Blumenthal entered a brave new world
yesterday, as the first state AG to file a HIPAA enforcement action
under the "Son of HIPAA" amendments found in the HITECH Act. Among other HIPAA changes made in the new law
(all of which should be of concern to health care providers, health
care payors, health care clearinghouses -- "covered entities" or CEs
-- and their "business associates" -- vendors who touch electronic
protected health information or ePHI), there is a provision that
permits state attorneys general to file HIPAA enforcement actions on
behalf of the people of their state, in order to protect their
interests, and to seek injunctive relief and/or money damages. See Sec. 13410(e) of ARRA (p. 160 of HR 1 PDF).
The basic
facts of the case are not unfamiliar: A hard drive gone missing from a
health insurance company's offices, this one with unencrypted
information about 250,000 plan members. The insurer, Health Net,
failed to promptly notify data subjects that the data had gone missing,
taking six months to issue a notice
and letters to affected individuals and offer credit monitoring and
repair for anyone affected. Unfortunately, data breaches are all too
common. See, for example, my post on the Virginia health data breach last year, and the recent Chilmark Research post asking, in essence, whether we can reasonably expect a breach-free world.
While
asserting a HIPAA claim is new territory for state AGs, the crux of the
claim is really a consumer protection claim, one of the state AGs'
mainstays.
Continue Reading
This blog tracks aging and disability news. Legislative information is provided via GovTrack.us.
In the right sidebar and at the page bottom, bills in the categories of Aging, Disability, Medicare, Medicaid, and Social Security are tracked.
Clicking on the bill title will connect to GovTrack updated bill status.
Showing posts with label HIPAA. Show all posts
Showing posts with label HIPAA. Show all posts
Sunday, January 24, 2010
Tuesday, September 22, 2009
The Health Care Blog: HIPAA's broken promises
Thursday, July 30, 2009
Standards for Privacy of Individually Identifiable Health Information
Agency Information Collection Request. 30-Day Public Comment Request
The Privacy Rule implements the privacy requirements of the Administrative Simplification subtitle of the Health Insurance Portability and Accountability Act of
1996. The final regulation requires covered entities (as defined in the regulation) to maintain strong protections for the privacy of individually identifiable health information; to use or disclose this information only as required or permitted by the Rule or with the express written authorization of the individual; to provide a notice of the entity’s privacy practices; and to document compliance with the Rule.
Read More
Sunday, December 7, 2008
Courts in 2 states rule on reach of HIPAA in medical liability cases
By Amy Lynn Sorrel, AMNews staff. Dec. 15, 2008 -- Some experts say the decisions point to ongoing confusion over the federal privacy statute in legal proceedings.
As HIPAA continues to raise hurdles for defendants in medical liability cases, courts in Georgia and Michigan addressed the role of the statute.
The courts interpreted to what extent, if any, the Health Insurance Portability and Accountability Act prevents a defendant physician's attorney from informally interviewing a plaintiff's prior or subsequent treating doctor in the course of litigation. The plaintiffs in the two cases sought to prevent any discussions regarding their medical histories, saying that would violate the federal privacy statute.
In a Nov. 3 ruling, the Georgia Supreme Court found that HIPAA preempted a state law allowing such oral communications without first notifying the patient. Justices unanimously said the federal regulation "affords patients more control over their medical records," and defendants must comply with the stronger privacy regulations. That means they may have those discussions, but only after obtaining patient authorization, a court order or other legal instruction.
The defendant physician in the case is asking the high court to reconsider its decision.
In a similar case in Michigan, the defendant physician had obtained a protective order, as outlined under the federal HIPAA statute, to speak with the plaintiff's other treating doctors.
But the plaintiff argued in court documents that the written medical records were sufficient. If more information were needed, the defendant could formally depose the plaintiff's physicians, the plaintiff said.
The Court of Appeals of Michigan unanimously disagreed in a Nov. 18 decision. While HIPAA supersedes state law with more stringent privacy protections -- which the defendant followed -- it does not forbid informal conversations. Those discussions can help keep litigation costs down and allow the parties to investigate what information could be useful at trial, judges said.
The plaintiff is appealing the decision to the state Supreme Court, but her attorney declined to comment further. The high court will decide whether to accept the case.
Thursday, October 30, 2008
DHHS OIG Nationwide Review of CMS HIPAA Oversight
On October 7, 2003, the U.S. Department of Health and Human Services delegated to CMS:
(I) the authority and responsibility to interpret, implement, and enforce the HIPAA Security Rule provisions; (2) the authority to conduct compliance reviews and to investigate and resolve complaints ofHIPAA Security Rule noncompliance; and (3) the authority to impose civil monetary penalties for a covered entity's failure to complywith the HIPAA Security Rule provisions. The Final Rule for enforcement of this delegation became effective on February 16, 2006.
Our objective was to evaluate the effectiveness of CMS's oversight and enforcement of covered entities' implementation of the HIPAA Security Rule.
CMS had taken limited actions to ensure that covered entities adequately implement the HIPAA Security Rule. These actions had not provided effective oversight or encouraged enforcement of the HIPAA Security Rule by covered entities. Although authorized to do so by Federal, regulations as of February 16,2006, CMS had not conducted any HIPAA Security Rule compliance reviews of covered entities. To fulfill its oversight responsibilities, CMS r{{lied on complaints to identify any noncompliant covered entities that it might investigate. As a result, CMS had no effective mechanism to ensure that covered entities were complying with the HIPAA Security Rule or that ePHI was being adequately protected.
Although reliance on complaints alone was ineffective for identifying noncompliant covered entities, we noted that CMS had an effective process for receiving, categorizing, tracking, and resolving complaints. CMS has developed and implemented detailed procedures for receiving complaints, communicating with filed-against entities, coordinating with the Office for Civil Rights for complaints with privacy elements, developing corrective action plans, and remediating complaints.
Ongoing Office of Inspector General audits of various hospitals nationwide indicate that CMS needs to become more proactive in overseeing and enforcing implementation of the HIPAA Security Rule by focusing on compliance reviews. Preliminary results of these audits show numerous, significant vulnerabilities in the systems and controls intended to protect ePHI at covered entities. These vulnerabilities place the confidentiality and integrity of ePHI at high risk. During our audit, CMS began taking steps to conduct compliance reviews. After we completed our fieldwork but before we issued our report, CMS executed a contract to conduct compliance reviews at covered entities.
We recommend that CMS establish policies and procedures for conducting HIPAA Security Rule compliance reviews of covered entities.
CMS did not agree with our findings because it believes that its complaint-driven enforcement process has furthered the goal of voluntary compliance. CMS agreed, however, that compliance reviews are a useful enforcement tool as part of a more comprehensive enforcement strategy. CMS agreed with our recommendation to establish specific policies and procedures for conducting compliance reviews of covered entities but emphasized that compliance reviews are just one of several tools that can be used to promote compliance.
Although CMS’s complaint-driven enforcement process has furthered the goal of voluntary compliance, the significant vulnerabilities we identified at hospitals throughout the country would not generally have been identified in HIPAA Security Rule complaints. In fact, CMS has received very few complaints regarding potential HIPAA Security Rule violations. Including compliance reviews of covered entities to its oversight process will enhance CMS’s ability to determine whether the HIPAA Security Rule is being properly implemented.
OIG Report
Monday, October 6, 2008
Is your EMR legal?
By Pamela Lewis Dolan, AMNews staff. Oct. 13, 2008 in American Medical News
Questions are emerging as more physicians go electronic. Federal Rules of Civil Procedure, approved by the U.S. Supreme Court in December 2006, not only make any electronically stored data discoverable in a trial, but also open up physicians to several new liabilities inherent in the detail electronic data provides.
For example, if a nurse records information under your login and password, and that information is incorrect, you could be the one held liable. Or the record's metadata -- the time stamp of who entered what when -- can dispute a doctor's version of events.
While EMRs are touted as a way to make life easier for physicians, health IT and legal professionals say they can make life miserable for a doctor who buys the wrong system, or uses it in the wrong way.
"Where these issues can raise their heads is somewhat unpredictable," said Reed Gelzer, MD, co-founder of Advocates for Documentation Integrity and Compliance, an advocacy and consulting group that educates physicians and health care entities on the legal EMR.
Dr. Gelzer said electronic records can save you when the record-keeping combines with the metadata to provide an accurate picture. But, as some recent cases of snooping hospital employees have proven, EMRs can also detect when someone violates HIPAA. And, just because an EMR creates something that looks like a medical record doesn't mean that document fits the legal definition of a medical record.
Thursday, October 2, 2008
California Enacts Two Laws on Patient Privacy
In Wall Street Journal Health Blog Posted by Jacob Goldstein
California Gov. Arnold Schwarzenegger yesterday signed into law two bills designed to protect patient privacy. In recent months, the privacy of dozens of high-profile patients at UCLA Medical Center was violated when unauthorized employees looked at their files.
What’s more, plenty of folks have cited privacy worries as one of the barriers slowing the move toward electronic record-keeping in health care.
So it makes sense that California’s Legislature would have been eager to pass (and the governor ready to sign) the new laws. They allow for penalties of up to $250,000 for breaches of patient privacy, and create a new “Office of Health Information Integrity” within the state health department.
Wednesday, August 27, 2008
After Hospital’s Celebrity Snooping, a Push for Tougher Penalties
Posted by Jacob Goldstein in WSJ Health blog
In recent months, we’ve heard one report after another that employees at UCLA Medical Center have improperly peeked at the files of celebrities such as Britney Spears, Farrah Fawcett and Maria Shriver.
Those reports apparently made their way up to Sacramento as well. California’s state Senate yesterday passed a bill that would create a state Office of Health Information Integrity, authorized to levy fines of as much as $250,000. The bill is online here; a list of who voted for and against is here.
Friday, August 22, 2008
To Adopt ICD-10-CM and ICD-10-PCS; Proposed Rule
This proposed rule would modify two of the medical data code set standards adopted in the Transactions and Code Sets final rule published in the Federal Register. It would also implement certain provisions of the Administrative Simplification subtitle of the Health Insurance Portability and Accountability Act (HIPAA) of 1996.
Specifically, the proposed rule would modify the standard code sets for coding diagnoses and inpatient hospital procedures by concurrently adopting the International Classification of Diseases, Tenth Revision, Clinical Modification (ICD-10-CM) for diagnosis coding, and the International Classification of Diseases, Tenth Revision, Procedure Coding System (ICD-10-PCS) for inpatient hospital procedure coding.
These new codes would replace the International Classification of Diseases, Ninth Revision, Clinical Modification (ICD-9-CM) Volumes 1 and 2, and the International Classification of Diseases, Ninth Revision, Clinical Modification (CM) Volume 3 for diagnosis and procedure codes, respectively.
DATES: Comments will be considered if we receive them at the appropriate address, as provided below, no later than 5 p.m. on October 21, 2008.
Modifications to the HIPAA Electronic Transaction Standards
This rule proposes to adopt updated versions of the standards for electronic transactions originally adopted in the regulations entitled, ``Health Insurance Reform: Standards for Electronic Transactions,'' published in the Federal Register on August 17, 2000, which implemented some of the requirements of the Administrative Simplification subtitle of the Health Insurance Portability and Accountability Act of 1996 (HIPAA). These standards were modified in our rule entitled, ``Health Insurance Reform: Modifications to Electronic Data Transaction Standards and Code Sets,'' published in the Federal Register on February 20, 2003.
This rule also proposes the adoption of a transaction standard for Medicaid Pharmacy Subrogation.
In addition, this rule proposes to adopt two standards for billing retail pharmacy supplies and professional services, and to clarify who the ``senders'' and ``receivers'' are in the descriptions of certain transactions.
DATES: To be assured consideration, comments must be received at one of the addresses provided below, no later than 5 p.m. on October 21, 2008.
Monday, July 7, 2008
Criminal HIPAA case targets employee, not clinic, for breach
By Amy Lynn Sorrel, AMNews staff. July 14, 2008.
The latest HIPAA criminal case may signal more aggressive efforts by the government to root out privacy breaches, while highlighting some legal risks for doctors and other "covered entities" for violations made by their employees, experts said.
Subscribe to:
Posts (Atom)