Healthcare IT NewsHealthcare IT News
TwitterFacebookLinkedInHealthcareITNews International
  • Home
  • Topics
    • ARRA/Stimulus
    • Business Intelligence
    • Claims Processing
    • Data Warehousing
    • EDIS
    • Election 2012
    • Electronic Health Records
    • Enterprise Content Management
    • Enterprise Resource Planning
    • ePrescribing
    • Financial/Revenue Cycle Management
    • Health Information Exchange (HIE)
    • ICD-10
    • Mobile/Wireless
    • Network Infrastructure
    • Policy and Legislation
    • Privacy and Security
    • Quality and Safety
    • RIS and PACS
    • RTLS
    • Telehealth
    • Workforce Management
  • Issues
    • January 2012
    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • August 2011
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Blog
  • Events
  • HIMSS JobMine
  • RSS
  • Press Releases
  • Slideshows
  • Videos
  • Podcasts
  • Supplements
  • Survey Analyses
  • Newsletters
  • Advertise
  • Login
  • Register
  • SUBSCRIBE
    • Newspaper
    • Email Newsletter
Home » News
Receive News By Email

  • del.icio.us
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • Google
  • RSS Icon
  

FTC issues final rules on breach notices for electronic health information

August 25, 2009 | Bernie Monegain, Editor

Related Links

  • More information about the FTC rule

Suggested Content

  • Community college training of HIT professionals questioned
  • Veterans Affairs CIO Roger Baker on VLER progress
  • Beacon Communities snag more money for IT
  • Docs tell government panel EHR tales of woe
  • CAQH, Edifecs launch platform for certifying CORE conformance
  • University offers new way to measure HIE performance
  • Grants target transition from hospital to home
  • Doctors likely to be exempt from Red Flags Rule
  • Obama makes docs' exemption from Red Flags Rule law

WASHINGTON – The Federal Trade Commission has issued a final rule requiring certain Web-based businesses to notify consumers when the security of their electronic health information is breached.

The rule applies to vendors of personal health records as well as businesses that offer third-party applications for PHRs. The applications could include, for example, devices such as blood pressure cuffs or pedometers whose readings consumers can upload into their personal health records.

Many entities offering these types of services are not subject to the privacy and security requirements of the Health Insurance Portability and Accountability Act (HIPAA), which applies to healthcare service providers such as doctors' offices, hospitals and insurance companies.

Congress directed the FTC to issue the rule as part of the American Recovery and Reinvestment Act of 2009 (ARRA).

The ARRA requires the Department of Health and Human Services to conduct a study and report by February 2010, in consultation with the FTC, on potential privacy, security and breach-notification requirements for vendors of personal health records and related entities that are not subject to HIPAA. In the meantime, the law requires that the commission issue a rule requiring these entities to notify consumers if the security of their health information is breached. The commission announced a proposed rule in April 2009, collected public comments until June 1 and issued the final rule Monday.

The rule requires vendors of personal health records and related entities to notify consumers following a breach involving unsecured information. In addition, if a service provider to one of these entities has a breach, it must notify the entity, which in turn must notify consumers.

The rule also specifies the timing, method and content of notification, and in the case of certain breaches involving 500 or more people requires notice to the media. Entities covered by the rule must notify the FTC.

Related Topics:
  • Federal Trade Commission
  • Washington

Reader Comments (0)Login to Post a Comment

Most Popular

Latest Headlines
Most Popular
  • 10 most outlandish kinds of ICD-10 codes
  • 5 stages of EHR maturity and patient collaboration
  • 5 simple ways to realize ROI from your EHR
  • 'Obamacare' a lightning rod, but what about health IT?
  • Remote health monitoring pegged at 3 million users by 2016
  • H.I.T. Men and Women to pick up awards at HIMSS12
  • University challenge targets NCDs with mHealth and social media
  • Indiana health exchange taps AT&T to scale up
  • eHealth Initiative releases recommendations for accountable care
  • One surgeon's take on need for culture change in medicine

WEBINARS AND WHITE PAPERS

  • WHITE PAPERS
    Business Intelligence for Hospitals: Empowering Healthcare Providers to Make Informed Decisions
  • WHITE PAPERS
    The Christ Hospital Case Study: Improving Operations and Ensuring the Best Possible Patient Care with ECM
  • WHITE PAPERS
    The Scarborough Hospital: Establishing a Document Management Strategy for EHRs
  • WHITE PAPERS
    Sharp HealthCare: Growing Content Management into an Enterprise Strategy
  • WHITE PAPERS
    Mobility Advantage: Health Care Made Easier
More Resources
Syndicate content

HIMSS JOBMINE

  • Director, Sales - HIMSS - Arlington, VA
  • Program Analyst - Mathematica Policy Research - Princeton, NJ
  • Oracle Implementation Analyst - Virginia Mason Medical Center - Seattle, WA
  • Web and Custom Development Manager - Virginia Mason Medical Center - Seattle, Washington
  • Epic Analyst/Builder - Vitalize Consulting Solutions - Nationwide
more jobs

Marketplace

Follow Healthcare IT News on TwitterFan Healthcare IT News on FacebookJoin Healthcare IT News on LinkedInRSS Subscriptions
Digital EditionBlogEvents
JobsMobile SiteMobile App
 
Healthcare Finance News Government Health IT EHRWatch Healthcare Payer News HITECHWatch ICD10Watch mHIMSS PhysBizTech NHINWatch
©2012 MedTech Media Healthcare IT News is a publication of MedTech Media
Subscribe Advertise About Us Privacy Policy