Healthcare IT NewsHealthcare IT News
TwitterFacebookLinkedInHealthcareITNews International
  • Home
  • Topics
    • Business Intelligence
    • Claims Processing
    • Data Warehousing
    • EDIS
    • Election 2012
    • Electronic Health Records
    • Enterprise Content Management
    • Enterprise Resource Planning
    • ePrescribing
    • Financial/Revenue Cycle Management
    • Health Information Exchange (HIE)
    • ICD-10
    • Meaningful Use
    • Mobile/Wireless
    • Network Infrastructure
    • Policy and Legislation
    • Privacy and Security
    • Quality and Safety
    • RIS and PACS
    • RTLS
    • Telehealth
    • Workforce Management
  • Issues
    • May 2012
    • April 2012
    • March 2012
    • February 2012
    • January 2012
    • December 2011
  • Blog
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Events
  • HIMSS JobMine
  • Press Releases
  • Slideshows
  • Videos
  • Podcasts
  • Supplements
  • Survey Analyses
  • Newsletters
  • Advertise
  • Login
  • Register
  • SUBSCRIBE
    • Newspaper
    • Email Newsletter
Home » News » Privacy and Security
Receive News By Email

  • del.icio.us
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • Google
  • RSS Icon
  

Government tiger team calls for privacy notices patients can understand

October 19, 2010 | Mary Mosquera, Contributing Editor

Related Resources

  • Moving Business Communication to the Cloud
  • Better Patient Care: Virtually There
  • The Case for Security Information and Event Management (SIEM) in Proactive Network Defense
  • Mobile Technology Meets Healthcare: Risks and Remedies
  • IBM with IDC Health Insights: Exploring the HITECH Act for Privacy and Security of Personal Health Information

WASHINGTON – Healthcare providers should supply patients with layered and easy to understand notices of how their information will be used and protected when it is exchanged, says an advisory panel of the Health & Human Services Department.

Physicians should include this description in a short summary in the privacy practices notice that is required by HIPAA, and that patients receive and sign at office visits, the panel concluded at an Oct. 15 meeting. But more detailed information exchange explanations should be readily available to patients.

When written, the Health Insurance Portability and Accountability Act (HIPAA) did not foresee the broad exchange of personal health data.

Transparency about information exchange practices is necessary to establish credibility with patients, according to the privacy and security panel of the federal Health IT Policy Committee.

At the same time, providers have to "balance the need to give patients complete information on how their health data is shared while doing so in a way that is manageable for patients to read and understand," said Paul Egerman, a software entrepreneur and co-chair of the Privacy and Security Tiger Team. 

"The summary notice has to describe the uses of information and be written so that 90 percent of patients can understand it," he said.

Physicians should also discuss face-to-face information exchange practices with their patients, in particular when a third party, such as a health information organization, handles the transport of personal data and could trigger the need for consent, or when the provider's electronic health record is shared within an integrated delivery network, he said.

The tiger team's layered notice supports proposals that the policy committee submitted to HHS in August setting out triggers for patient consent in direct exchanges between providers or with testing labs. Meaningful use in 2011 requires that providers be able to conduct simple exchanges.

Underlying all the tiger team recommendations is the principle that patients should not be surprised by what happens to their information.
 
The Office of the National Coordinator for Health IT has a role in educating consumers about health information exchange. ONC can require that health information exchanges and regional health IT extension centers that it funds to conduct public education about their information sharing policies and practices, Egerman said.

The tiger team also began to consider authentication or verification of the identity of the person or organization seeking access to health information. The group will explore methods of organization level authentication to facilitate exchange and the digital credentials needed to prove identity verification.

For example, the Defense Department uses the Common Access Card for verification of identification to enter DOD facilities and as a token for computer network access.

Among the questions the tiger team will explore over the next few weeks are whether ONC should select an established technology standard for digital credentials and whether the certification of electronic health records should include the function for using that standard, Egerman said.

Mary Mosquera
Senior Editor for Government Health IT
Follow Mary on Twitter @GovHITreporter
Related Topics:
  • Mary Mosquera
  • Paul Egerman
  • Washington
  • Privacy and Security

Reader Comments (0)Login to Post a Comment

Most Popular

Latest Headlines
Most Popular
  • 6 reasons physicians need to be on social media
  • Lawsuit seeks Allscripts CEO's removal
  • Tablet adoption by docs soars
  • Healthcare part of White House mobility mandate
  • Oregon to implement new statewide HIE
  • Lawsuit seeks Allscripts CEO's removal
  • Web First: Q&A with Allscripts CEO Glen Tullman
  • 6 reasons physicians need to be on social media
  • Oregon to implement new statewide HIE
  • Tablet adoption by docs soars
more news

WEBINARS AND WHITE PAPERS

  • WHITE PAPERS
    Driving Meaningful Use of Enterprise Content Management
  • UPCOMING WEBINARS
    June 5th @ 1PM ET--Get Control of Your Medical Images with a Cloud-Based Vendor-Neutral Archive
  • ON DEMAND WEBINARS
    Redefining Value and Success in Healthcare: Charting the Path to the Future
  • WHITE PAPERS
    Business Intelligence for Hospitals: Empowering Healthcare Providers to Make Informed Decisions
  • WHITE PAPERS
    Mobility Advantage: Health Care Made Easier
More Resources
Syndicate content

HIMSS JOBMINE

  • Regional Senior Quality Analyst - Memorial Medical Center - Modesto, CA
  • Network Engineer II - Carilion Clinic - Roanoke, VA
  • EMR Implementation - Project Manager Rothman Specialty Hospital - Rothman Specialty Hospital - Bensalem, PA
  • Director of Information Systems - Mission Regional Medical Center - Mission, Texas
  • Biostatistician II - Saudi Aramco - Dhahran, Saudi Arabia
more jobs

Marketplace

Follow Healthcare IT News on TwitterFan Healthcare IT News on FacebookJoin Healthcare IT News on LinkedInRSS Subscriptions
Digital EditionBlogEvents
JobsMobile SiteMobile App
 
Healthcare Finance News Government Health IT EHRWatch Healthcare Payer News HITECHWatch ICD10Watch mHIMSS PhysBizTech NHINWatch
©2012 MedTech Media Healthcare IT News is a publication of MedTech Media
Subscribe Advertise About Us Privacy Policy