HHS: tougher HIPAA rules apply Nov. 30

By Mary Mosquera
Friday, October 30, 2009

The Health & Human Services Department today published a rule that strengthens its enforcement of the Health Insurance Portability and Accountability Act (HIPAA) by aligning it with tougher privacy terms of the stimulus law.

The Health Information Technology for Economic and Clinical Health (HITECH) Act significantly increased financial  penalties against healthcare providers and health plans for HIPAA infractions and called for a prompt response against violators.

The rule will take effect Nov. 30, but the public may comment on it until Dec. 29. 

“This strengthened penalty scheme will encourage health care providers, health plans and other health care entities required to comply with HIPAA to ensure that their compliance programs are effectively designed to prevent, detect and quickly correct violations of the HIPAA rules,” said Georgina Verdugo, director of HHS’s Office for Civil Rights, which oversees HIPAA's privacy, security and breach notification rules.  

Under the previous HIPAA rule, HHS could not fine healthcare organizations more than $100 for each violation and imposed a ceiling of $25,000 for all similar violations of the same provision.

The stimulus made it more expensive for healthcare organizations to breach sensitive health information or put data at risk of unauthorized use. It also set tiered ranges of escalating minimum penalty amounts, with a maximum penalty of $1.5 million for all violations of an identical provision. 

A provider or health plan also can no longer escape the imposition of a financial penalty for a violation it says it did not know about unless it corrects the problem within 30 days of discovery.

The HHS interim final rule is online, as well as more information about HIPAA privacy.



Please use the space provided below to write your comments to our editorial staff. We will respond to your comments and input via e-mail.

Your Name: (optional)


Your Email: (optional)


Your Location: (optional)


Comment:
 
 
  

Cover Story

magazine coverCover Story
Gauging meaningful use
The systems used to verify 'meaningful use' will help determine whether $34 billion in federal health IT incentives is money well spent.
Read more

eSeminar

'Meaningful Use' of the Nationwide Health Information Network: Lessons Learned from SSA and the States
February 11, 2010 11:00 Eastern / 10:00 Central / 09:00 Mountain / 08:00 Pacific
Nationwide Health Information Network pioneers will draw from their experiences establishing the first interstate application of the NHIN in a live health information exchange to offer their views on how the NHIN will support the meaningful use of health IT by government agencies, health information exchanges and individual care givers by 2011 and beyond.


Register Now >>

 

HIMSS10 Military Health Services

HIMSS is proud to provide timely and relevant educational sessions aimed at the unique needs of the Military and its health delivery systems. These sessions will instruct the Military community on the latest in their field, and will provide non-Military attendees with a perspective on the capabilities, processes and initiatives used by the military that may be applied to the commercial sector. more >>