Healthcare IT NewsHealthcare IT News
TwitterFacebookLinkedInHealthcareITNews International
  • Home
  • Topics
    • ARRA/Stimulus
    • Business Intelligence
    • Claims Processing
    • Data Warehousing
    • EDIS
    • Election 2012
    • Electronic Health Records
    • Enterprise Content Management
    • Enterprise Resource Planning
    • ePrescribing
    • Financial/Revenue Cycle Management
    • Health Information Exchange (HIE)
    • ICD-10
    • Mobile/Wireless
    • Network Infrastructure
    • Policy and Legislation
    • Privacy and Security
    • Quality and Safety
    • RIS and PACS
    • RTLS
    • Telehealth
    • Workforce Management
  • Issues
    • January 2012
    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • August 2011
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Blog
  • Events
  • HIMSS JobMine
  • RSS
  • Press Releases
  • Slideshows
  • Videos
  • Podcasts
  • Supplements
  • Survey Analyses
  • Newsletters
  • Advertise
  • Login
  • Register
  • SUBSCRIBE
    • Newspaper
    • Email Newsletter
Home » News
Receive News By Email

  • del.icio.us
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • Google
  • RSS Icon
  

HIPAA violators could face fines of up to $1.5M

November 02, 2009 | Bernie Monegain, Editor

Related Links

  • Read the rule and comment
  • Additional information about HIPAA and several related rulemakings

Suggested Content

  • Community college training of HIT professionals questioned
  • Beacon Communities snag more money for IT
  • After Kolodner, then what?
  • LookAhead
  • Mostashari: Meaningful use to reach new heights
  • Venture Fair experts: The timing is right for mHealth entrepreneurs
  • HIT Policy Committee recommends delay for Stage 2 MU
  • A new chief for ONC
  • Blumenthal steps down from ONC

WASHINGTON – The U.S. Department of Health and Human Services has issued an interim final rule to strengthen enforcement and increase penalties for violations of the Health Insurance Portability and Accountability Act, known as HIPAA.

The Health Information Technology for Economic and Clinical Health (HITECH) Act, which was enacted as part of the American Recovery and Reinvestment Act of 2009, modified the penalties that the HHS could impose for violations of the HIPAA rules.

Prior to the HITECH Act, the penalty could be no more than $100 for each violation or $25,000 for all identical violations of the same provision.

A healthcare provider, health plan or clearinghouse could also bar the secretary's imposition of a civil money penalty by demonstrating that it did not know that it violated the HIPAA rules.

Section 13410(d) of the HITECH Act strengthened the enforcement by establishing tiered ranges of increasing minimum penalty amounts, with a maximum penalty of $1.5 million for all violations of an identical provision. A covered entity can no longer bar the imposition of a civil money penalty for an unknown violation unless it corrects the violation within 30 days of discovery.

The interim final rule with request for comments, published last week, conforms the HIPAA enforcement regulations to the revisions made by the HITECH Act. This rule will become effective on Nov. 30. HHS will consider all comments received by Dec. 29.

"The department's implementation of these HITECH Act enforcement provisions will strengthen the HIPAA protections and rights related to an individual's health information," said Georgina Verdugo, director of the HHS Office for Civil Rights, which is responsible for administering and enforcing HIPAA's privacy, security and breach notification rules.

"This strengthened penalty scheme will encourage healthcare providers, health plans and other healthcare entities required to comply with HIPAA to ensure that their compliance programs are effectively designed to prevent, detect and quickly correct violations of the HIPAA rules," said Verdugo. "Such heightened vigilance will give consumers greater confidence in the privacy and security of their health information and in the industry's use of health information technology."

This interim final rule with request for comments is the first of several steps HHS is taking to implement the HITECH Act's enforcement provisions, Verdugo said. The remaining provisions, which have yet to become effective, will be addressed in the next few months in forthcoming rulemakings.

Related Topics:
  • mobile technology
  • Georgina Verdugo
  • information technology
  • US Department of Health and Human Services
  • Washington

Reader Comments (4)Login to Post a Comment

medesun says: HITECH Law
February 26, 2010 | 3:11PM GMT

The Healthcare professional must be aware of the HIPAA Titles. PHI Privacy and Secuirty are very important. HITECH Law focuses on these. Education is Key for the HIPAA Implementation.
Dr Guptha, Director dermatology billing services

D Pollack says: HITECH Fines
November 09, 2009 | 5:28PM GMT

Note that the $1.5 million fines would be for organizations that have demonstrated "willful neglect" in providing for the security and privacy of patient information. This isn't very well defined in the Act, but organizations minimally should demonstrate that they have done a thorough patient data breach exposure assessment within the past year and have developed a comprehensive data breach incident response plan. Health and Human Services also require that organizations carry out a "risk assessment" whenever there is any kind of a security incident in order to determine the level of "harm" that exists to affected patients.

Doug Pollack, www.idexpertscorp.com

medesun says: Penalties
November 02, 2009 | 4:02PM GMT

The best way to avoid is to implement the safeguards, Physical, Administrative and Technical.
http://www.medicalcodingexperts.com

Sapmedical says: HIPAA
November 09, 2009 | 10:11AM GMT

Thats right, Implementing the Physical Safeguards, Administrative Safeguards and Technical Safeguards will definitely helps to be HIPAA Compliant. However training the staff is foremost requirement.

Most Popular

Latest Headlines
Most Popular
  • Analytics and the future of healthcare
  • CNIO position on the rise
  • Health data breaches up 97 percent in 2011
  • Docs use iPads, but don't see them as game-changers
  • Greenway set for IPO
  • HIT figures prominently in GOP primary battle for Nevada
  • Mostashari expects big year ahead for data exchange
  • AMA, AHIMA at odds on ICD-10
  • Minnesota: A healthy appreciation for HIT
  • 5 issues affecting cloud service quality and performance

WEBINARS AND WHITE PAPERS

  • WHITE PAPERS
    Driving Meaningful Use of Enterprise Content Management
  • WHITE PAPERS
    The Christ Hospital Case Study: Improving Operations and Ensuring the Best Possible Patient Care with ECM
  • WHITE PAPERS
    Winning the EHR Battle with Enterprise Content Management
  • WHITE PAPERS
    Sharp HealthCare: Growing Content Management into an Enterprise Strategy
  • ON DEMAND WEBINARS
    The Value of Document and Content Management in Healthcare Transformation
More Resources
Syndicate content

HIMSS JOBMINE

  • Program Analyst - Mathematica Policy Research - Princeton, NJ
  • Oracle Implementation Analyst - Virginia Mason Medical Center - Seattle, WA
  • Web and Custom Development Manager - Virginia Mason Medical Center - Seattle, Washington
  • Epic Analyst/Builder - Vitalize Consulting Solutions - Nationwide
  • Vice President - Tower Strategies - Remote
more jobs

Marketplace

Follow Healthcare IT News on TwitterFan Healthcare IT News on FacebookJoin Healthcare IT News on LinkedInRSS Subscriptions
Digital EditionBlogEvents
JobsMobile SiteMobile App
 
Healthcare Finance News Government Health IT EHRWatch Healthcare Payer News HITECHWatch ICD10Watch mHIMSS PhysBizTech NHINWatch
©2012 MedTech Media Healthcare IT News is a publication of MedTech Media
Subscribe Advertise About Us Privacy Policy