Healthcare IT NewsHealthcare IT News
TwitterFacebookLinkedInHealthcareITNews International
  • Home
  • Topics
    • ARRA/Stimulus
    • Business Intelligence
    • Claims Processing
    • Data Warehousing
    • EDIS
    • Election 2012
    • Electronic Health Records
    • Enterprise Content Management
    • Enterprise Resource Planning
    • ePrescribing
    • Financial/Revenue Cycle Management
    • Health Information Exchange (HIE)
    • ICD-10
    • Mobile/Wireless
    • Network Infrastructure
    • Policy and Legislation
    • Privacy and Security
    • Quality and Safety
    • RIS and PACS
    • RTLS
    • Telehealth
    • Workforce Management
  • Issues
    • January 2012
    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • August 2011
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Blog
  • Events
  • HIMSS JobMine
  • RSS
  • Press Releases
  • Slideshows
  • Videos
  • Podcasts
  • Supplements
  • Survey Analyses
  • Newsletters
  • Advertise
  • Login
  • Register
  • SUBSCRIBE
    • Newspaper
    • Email Newsletter
Home » News
Receive News By Email

  • del.icio.us
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • Google
  • RSS Icon
  

HHS issues rule on EHR breach notification

August 19, 2009 | Diana Manos, Senior Editor

Suggested Content

  • HHS Consumer Health IT Summit power-charged for progress
  • Beacon Communities snag more money for IT
  • HHS proposes new privacy, security rules
  • David Blumenthal named new National Coordinator for Health IT
  • Community college training of HIT professionals questioned
  • Power-charged for progress
  • Nurses, Blue Button are highlighted during National Health IT Week
  • HHS unveils proposed regs for state insurance exchanges
  • HHS unveils proposed health insurance exchange regs
  • HHS launches Partners for Patients

WASHINGTON – The Department of Health and Human Services issued new regulations Wednesday requiring healthcare providers, health plans and other entities covered by the Health Insurance Portability and Accountability Act (HIPAA) to notify patients if their electronic health information has been breached.

The regulations are mandated by the Health Information Technology for Economic and Clinical Health (HITECH) Act, passed as part of American Recovery and Reinvestment Act of 2009 (ARRA) last February.

Developed by the HHS Office for Civil Rights, they require healthcare providers and other HIPAA "covered entities" to promptly notify people whose health records have been breached, as well as the HHS Secretary and the media in cases where a breach affects more than 500.

Covered entities include doctors, clinics, psychologists, dentists, chiropractors, nursing homes and pharmacies – if they transmit any information in an electronic form using a standard that HHS has adopted.

According to the OCR, the rule also applies to health insurance companies, HMOs, company health plans and government programs that pay for healthcare, such as Medicare, Medicaid and the military and veterans' health care programs. It includes healthcare clearinghouses that process non-standard health information received from another entity into a standard electronic format or data content, or vice versa.

"This new federal law ensures that covered entities and business associates are accountable to the department and to individuals for proper safeguarding of the private information entrusted to their care," said Robinsue Frohboese, acting director and principal deputy director of the OCR. "These protections will be a cornerstone of maintaining consumer trust as we move forward with meaningful use of electronic health records and electronic exchange of health information."

HHS officials said they developed the regulations after taking public comment last April and under "close consultation" with the Federal Trade Commission). The FTC has issued its own breach notification regulations that apply to vendors of personal health records and certain others not covered by HIPAA.

To help providers to determine when information is "unsecured" and notification is required by the HHS and FTC rules, HHS is also issuing an update to its guidance on encryption and destruction of technologies that are no longer usable. Providers that are subject to the HHS and FTC regulations that secure electronic health records according to HHS guidance through encryption or destruction are relieved from having to notify in the event of a breach. This guidance will be updated annually.

The HHS interim final regulations on breach notification will be effective 30 days after they are published in the Federal Register and will include a 60-day public comment period.

Related Topics:
  • Department of Health and Human Services
  • electronic health record
  • Federal Trade Commission
  • HHS
  • information technology
  • OCR
  • Washington

Reader Comments (0)Login to Post a Comment

Most Popular

Latest Headlines
Most Popular
  • Analytics and the future of healthcare
  • CNIO position on the rise
  • Health data breaches up 97 percent in 2011
  • Docs use iPads, but don't see them as game-changers
  • Greenway set for IPO
  • HIT figures prominently in GOP primary battle for Nevada
  • Mostashari expects big year ahead for data exchange
  • AMA, AHIMA at odds on ICD-10
  • Minnesota: A healthy appreciation for HIT
  • 5 issues affecting cloud service quality and performance

WEBINARS AND WHITE PAPERS

  • WHITE PAPERS
    The Scarborough Hospital: Establishing a Document Management Strategy for EHRs
  • WHITE PAPERS
    Winning the EHR Battle with Enterprise Content Management
  • ON DEMAND WEBINARS
    The Value of Document and Content Management in Healthcare Transformation
  • WHITE PAPERS
    Mobility Advantage: Health Care Made Easier
  • WHITE PAPERS
    Business Intelligence for Hospitals: Empowering Healthcare Providers to Make Informed Decisions
More Resources
Syndicate content

HIMSS JOBMINE

  • Program Analyst - Mathematica Policy Research - Princeton, NJ
  • Oracle Implementation Analyst - Virginia Mason Medical Center - Seattle, WA
  • Web and Custom Development Manager - Virginia Mason Medical Center - Seattle, Washington
  • Epic Analyst/Builder - Vitalize Consulting Solutions - Nationwide
  • Vice President - Tower Strategies - Remote
more jobs

Marketplace

Follow Healthcare IT News on TwitterFan Healthcare IT News on FacebookJoin Healthcare IT News on LinkedInRSS Subscriptions
Digital EditionBlogEvents
JobsMobile SiteMobile App
 
Healthcare Finance News Government Health IT EHRWatch Healthcare Payer News HITECHWatch ICD10Watch mHIMSS PhysBizTech NHINWatch
©2012 MedTech Media Healthcare IT News is a publication of MedTech Media
Subscribe Advertise About Us Privacy Policy