Healthcare IT NewsHealthcare IT News
TwitterFacebookLinkedInHealthcareITNews International
  • Home
  • Topics
    • Business Intelligence
    • Claims Processing
    • Data Warehousing
    • EDIS
    • Election 2012
    • Electronic Health Records
    • Enterprise Content Management
    • Enterprise Resource Planning
    • ePrescribing
    • Financial/Revenue Cycle Management
    • Health Information Exchange (HIE)
    • ICD-10
    • Meaningful Use
    • Mobile/Wireless
    • Network Infrastructure
    • Policy and Legislation
    • Privacy and Security
    • Quality and Safety
    • RIS and PACS
    • RTLS
    • Telehealth
    • Workforce Management
  • Issues
    • May 2012
    • April 2012
    • March 2012
    • February 2012
    • January 2012
    • December 2011
  • Blog
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Events
  • HIMSS JobMine
  • Press Releases
  • Slideshows
  • Videos
  • Podcasts
  • Supplements
  • Survey Analyses
  • Newsletters
  • Advertise
  • Login
  • Register
  • SUBSCRIBE
    • Newspaper
    • Email Newsletter
Home » News » Privacy and Security
Receive News By Email

  • del.icio.us
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • Google
  • RSS Icon
  

HHS withdraws breach notification rule in wake of $1M Rite Aid case

September 08, 2010 | Diana Manos, Senior Editor

Related Resources

  • Don't Get Hijacked – Protect Your Domain with DNSSEC
  • Integrating Faxes into Today's World of Healthcare e-Records
  • The Healthcare IT Innovation Imperative: Harnessing the Power of Technology for 21st Century Care Models
  • Transformational Strategies for Supporting EMR Adoption: IDC and Lahey Clinic Speak Out
  • Focus on Patient Care without Worrying about Underlying Technology

WASHINGTON – The Department of Health and Human Services withdrew its final breach notification rule for unsecured protected health information. Withdrawal of the rule came in late July, just days before the Rite Aid Corp. agreed to pay $1 million to settle potential violations of federal privacy rules.

Some observers say the Rite Aid case, in which the national drug store chain allegedly failed to protect discarded customer prescription information in publicly accessible dumpsters, may have triggered the withdrawal of the rule. The new rule was supposed to replace an interim rule that went in effect Sept. 23, 2009.

HHS said it withdrew its final breach notification final rule on July 28 from the White House Office of Management and Budget where it was being reviewed, "to allow for further consideration, given the department’s experience to date in administering the regulations."

"This is a complex issue and the Administration is committed to ensuring that individuals' health information is secured to the extent possible to avoid unauthorized uses and disclosures, and that individuals are appropriately notified when incidents do occur," HHS said in a statement.

HHS officials said they intend to publish a new final rule "in the coming months."

According to HHS' Office of Civil Rights Director Georgina Verdugo, as part of the settlement, Rite Aid will establish policies and train employees on how to protect sensitive patient information.

"We hope that this agreement will spur other health organizations to examine and improve their policies and procedures for protecting patient information during the disposal process," Verdugo said.

Patient Privacy Rights, a patient privacy advocacy group, was pleased HHS withdrew the rule because it did not allow for patients to be notified in every instance of a breach of their sensitive information.

"This is a huge step in the right direction," said Deborah Peel, founder of Patient Privacy Rights. "Congress, the Coalition for Patient Privacy, and patients everywhere spoke out against the blatant disregard for patients' rights to be notified of all breaches."

According to Peel, Patient Privacy Rights opposed a section of the rule they call, the "harm standard." The harm standard would allow businesses entities that suffer a breach of data security to decide whether patients are likely to be harmed by the breach.

"Put simply, the proposed final rule granted the power to decide whether to report breaches or not to the businesses that failed to protect sensitive health data, and would not want to disclose breaches," Peel said.

"Talk about letting the fox guard the hen house," she said.

Diana Manos
Senior Editor for Healthcare IT News
Follow Diana on Twitter @DManos_IT_News
Related Topics:
  • September 2010
  • Department of Health and Human Services
  • HHS
  • Patient Privacy Rights
  • Rite Aid Corp.
  • Washington
  • Privacy and Security

Reader Comments (0)Login to Post a Comment

Most Popular

Latest Headlines
Most Popular
  • 6 reasons physicians need to be on social media
  • Lawsuit seeks Allscripts CEO's removal
  • Tablet adoption by docs soars
  • 6 things patients want from social media
  • Healthcare part of White House mobility mandate
  • Lawsuit seeks Allscripts CEO's removal
  • Web First: Q&A with Allscripts CEO Glen Tullman
  • 6 reasons physicians need to be on social media
  • Oregon to implement new statewide HIE
  • Tablet adoption by docs soars
more news

WEBINARS AND WHITE PAPERS

  • WHITE PAPERS
    Sharp HealthCare: Growing Content Management into an Enterprise Strategy
  • WHITE PAPERS
    Mobility Advantage: Health Care Made Easier
  • WHITE PAPERS
    Winning the EHR Battle with Enterprise Content Management
  • ON DEMAND WEBINARS
    Case Study: Sentara Healthcare Completes an Award-Winning EHR with Enterprise Content Management
  • UPCOMING WEBINARS
    June 6th @ 2PM ET--Healthcare Best Practices: 4 Critical IT Strategies to Avoid Data Breaches
More Resources
Syndicate content

HIMSS JOBMINE

  • Regional Senior Quality Analyst - Memorial Medical Center - Modesto, CA
  • Network Engineer II - Carilion Clinic - Roanoke, VA
  • EMR Implementation - Project Manager Rothman Specialty Hospital - Rothman Specialty Hospital - Bensalem, PA
  • Director of Information Systems - Mission Regional Medical Center - Mission, Texas
  • Biostatistician II - Saudi Aramco - Dhahran, Saudi Arabia
more jobs

Marketplace

Follow Healthcare IT News on TwitterFan Healthcare IT News on FacebookJoin Healthcare IT News on LinkedInRSS Subscriptions
Digital EditionBlogEvents
JobsMobile SiteMobile App
 
Healthcare Finance News Government Health IT EHRWatch Healthcare Payer News HITECHWatch ICD10Watch mHIMSS PhysBizTech NHINWatch
©2012 MedTech Media Healthcare IT News is a publication of MedTech Media
Subscribe Advertise About Us Privacy Policy