New HITECH-driven privacy rules forthcoming from HHS

The Department of Health and Human Services announced its plans to propose a new set of rules strengthening privacy and security of personal health information protected. The rules will implement various provisions of the Health Information…

Not ready to comply with HITECH? That’s OK, HHS isn’t ready to enforce it yet either

Government observers are well aware that there is a big difference between passing a provision in a piece of legislation, crafting the rules that implement the provision, and then putting those rules into effect. Where new…

Lack of readiness to adopt HITECH requirements shouldn’t be a show-stopper

There are lots of new and improved privacy and security requirements scheduled to come into effect over the next few months, including enhancements of existing HIPAA security and privacy provisions that were added in the HITECH…

New health data breach notification rules go into effect

The rules contained in the HITECH Act requiring HIPAA-covered entities, business associates, and non-covered entities that provide personal health records (PHR) to disclose breaches of personal health information go into effect on September 23. The draft…

Health data breach notification rules published

The Department of Health and Human Services has published an interim final rule in the Federal Register formalizing requirements contained in the HITECH portion of the American Recovery and Reinvestment Act that that organizations provide breach…

Accounting of disclosures to become more comprehensive

One of the requirements under the HIPAA Privacy Rule is that covered entities maintain an “accounting of disclosures” of protected health information, in part so that an individual may request a record of who accessed their…

New Federal notification requirement for breaches of protected health information

One of the more widely anticipated provisions of the HITECH Act is a new provision requiring many health information exchange participants (specifically, covered entities and business associates under HIPAA) to provide notification to individuals in the…