Government  Health IT
TwitterFacebookLinkedIn
  • Home
  • Topics
    • Cloud Computing
    • Election 2012
    • Electronic Health Record
    • ePrescribing
    • Health Information Exchange (HIE)
    • Meaningful Use
    • Medicaid
    • Medicare
    • Military Health
    • Mobile/ Wireless
    • NHIN
    • Policy & Legislation
    • Population Health
    • Privacy and Security
    • Quality and Safety
    • Telehealth
    • Workforce Management
  • Issues
    • Sept/Oct 2011
    • July/August 2011
    • May/June 2011
    • March/April 2011
    • Jan/Feb 2011
    • Nov/Dec 2010
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Blog
  • Events
  • Jobs
  • RSS
  • Slideshows
  • Videos
  • Podcasts
  • Newsletters
  • Advertise
  • LOGIN
  • REGISTER
  • SUBSCRIBE
Home » News » Electronic Health Record | Health Information Exchange (HIE) | Meaningful Use | Medicaid | Medicare | Policy & Legislation | Privacy and Security
Receive News
By Email

  • del.icio.us
  • Digg
  • Facebook
  • Google
  • Reddit
  • StumbleUpon
  • RSS Icon
  

Tweet

Quick parse: 4 parts to HIPAA final rule on Privacy and Security

January 17, 2013 | Tom Sullivan, Editor

Suggested Content

  • Q&A: MeHI director looks at Massachusetts' HIE road ahead
  • Why HAI health IT should fall under meaningful use
  • Report: HIT market will swell to $56B by 2017
  • HHS puts a cool $1 billion toward Innovation Awards
  • Tavenner confirmation triggers applause from industry

Related Resources

  • Accelerate Healthcare Reform with Information Technology
  • Securing Mobile Devices in the Business Environment
  • A Reference Architecture for Healthcare Benefit Exchange
  • The State of EHR Adoption: On The Road to Improving Patient Safety
  • 5 Tips for Successful Patient Identity Management in Government Agencies

The most eagerly awaited — if not anxiety-laden — set of regulations in the healthcare spectrum arrived late Thursday: HHS issued modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules.

“This final rule is comprised of four final rules,” HHS explains in the document (PDF), “which have been combined to reduce the impact and number of times certain compliance activities need to be undertaken by the regulated entities.”

Without any more ado, then, and directly from the HHS document linked to above, here are those four:

1. Final modifications to the HIPAA Privacy, Security, and Enforcement Rules mandated by the Health Information Technology for Economic and Clinical Health (HITECH) Act, and certain other modifications to improve the Rules, which were issued as a proposed rule on July 14, 2010. These modifications:

  • Make business associates of covered entities directly liable for compliance with certain of the HIPAA Privacy and Security Rules’ requirements.
  • Strengthen the limitations on the use and disclosure of protected health information for marketing and fundraising purposes, and prohibit the sale of protected health information without individual authorization.
  • Expand individuals’ rights to receive electronic copies of their health information and to restrict disclosures to a health plan concerning treatment for which the individual has paid out of pocket in full.
  • Require modifications to, and redistribution of, a covered entity’s notice of privacy practices.
  • Modify the individual authorization and other requirements to facilitate research and disclosure of child immunization proof to schools, and to enable access to decedent information by family members or others.
  • Adopt the additional HITECH Act enhancements to the Enforcement Rule not previously adopted in the October 30, 2009, interim final rule (referenced immediately below), such as the provisions addressing enforcement of noncompliance with the HIPAA Rules due to willful neglect.

2. Final rule adopting changes to the HIPAA Enforcement Rule to incorporate the increased and tiered civil money penalty structure provided by the HITECH Act, originally published as an interim final rule on October 30, 2009.

3. Final rule on Breach Notification for Unsecured Protected Health Information under the HITECH Act, which replaces the breach notification rule’s “harm” threshold with a more objective standard and supplants an interim final rule published on August 24, 2009.

4. Final rule modifying the HIPAA Privacy Rule as required by the Genetic Information Nondiscrimination Act (GINA) to prohibit most health plans from using or disclosing genetic information for underwriting purposes, which was published as a proposed rule on October 7, 2009.

“These changes are consistent with, and arise in part from, the Department’s obligations under Executive Order 13563 to conduct a retrospective review of our existing regulations for the purpose of identifying ways to reduce costs and increase flexibilities under the HIPAA Rules,” HHS explains in the document.

Leon Rodriguez, HHS Office for Civil Rights Director, said in a prepared statement: “This final omnibus rule marks the most sweeping changes to the HIPAA Privacy and Security Rules since they were first implemented." Rodriguez continued that the modifications "not only greatly enhance a patient’s privacy rights and protections, but also strengthen the ability of my office to vigorously enforce the HIPAA privacy and security protections, regardless of whether the information is being held by a health plan, a health care provider, or one of their business associates.”

Check back with Government Health IT for more coverage and analysis about the final rule.

Related articles:

Are providers ripe for a medical records heist?

Not merely lost: A look at what happens to stolen medical records

3 tips for safeguarding against data breaches

3 minute podcast: Micky Tripathi, CEO of the Massachusetts eHealth Collaborative explains the compelling reasons all hospitals should encrypt their data.  PlayPlay in a new window

Q&A: On the delicate dance of data breach notification

Tom Sullivan
Editor of Government Health IT
Follow Tom on Twitter @GovHITeditor
Related Topics:
  • Online Only
  • Electronic Health Record
  • Health Information Exchange (HIE)
  • Meaningful Use
  • Medicaid
  • Medicare
  • Policy & Legislation
  • Privacy and Security
  • Massachusetts eHealth Collaborative
  • Person Career
  • Quotation
  • healthcare
  • immunization
  • information technology
  • Leon Rodriguez
  • Micky Tripathi

Reader Comments (0)Login to Post a Comment

Most Popular

Latest Headlines
Most Popular
  • Deloitte: Docs underutilize various health technologies
  • Commentary: How data sharing between AHLTA and VistA is possible
  • NYeC PHR design winners to shape public portal
  • First HIE launching in greater Philadelphia
  • Bipartisan bill would slash iEHR funding
  • 10 health reform benefits at risk in the election
  • Would Romney kill meaningful use?
  • CMS circulates final 2014 MU clinical quality measures
  • HIE is critical public utility in Sandy disaster
  • HIMSS: The intangibles of HIT employee retention
more news

WEBINARS AND WHITE PAPERS

  • WHITE PAPERS
    Enterprise-class API Patterns for Cloud & Mobile
  • WHITE PAPERS
    Beyond the EHR: Seamlessly Connecting Nurses and Physicians Using an EHR-Extender (EHR-e)
  • WHITE PAPERS
    A Reference Architecture for Healthcare Benefit Exchange
  • WHITE PAPERS
    New World Order: Effectively Securing Healthcare Data Through Secure Information Exchanges
  • WHITE PAPERS
    The First Federal Private Cloud: Learn to Shape, Transform & Manage Applications
More Resources
Syndicate content

HIMSS JOBMINE

  • Director of Clinical Applications - MidMichigan Health - Midland, MI
  • Information Services Director - Central Peninsula Hospital - Soldotna, AK
  • Director, Marketing and Business Development - Vermont Information Technology Leaders, Inc. - Burlington, VT
  • CIO - Bend Memorial Clinic - Bend, Oregon
  • Director of Clinical Transformation - Agnesian Healthcare - Fond du Lac, WI
more jobs
receive news by email

Marketplace

  • Home
  • Resource Central
  • Blog
  • Events
  • Jobs
  • Mobile Site
  • Advertise
  • RSS
  • About
  • Site map
  • Privacy Policy
Follow Government Health IT on TwitterLike Government Health IT on FacebookJoin Government Health IT on LinkedInRSS Subscriptions
BlogEvents
JobsMobile SiteMobile App
 
Healthcare IT NewsHealthcare Finance NewsHealthcare Payer NewsHIEWatch ICD10Watch mHIMSS PhysBizTech
©2013 MedTech Media Government Health IT is a publication of MedTech Media
Advertise About Us Privacy Policy