Showing posts with label HIPAA. Show all posts
Showing posts with label HIPAA. Show all posts

Monday, June 21, 2010

SAMHSA and ONC: FAQs on Substance Abuse Confidentiality Regulations for HIEs

The Substance Abuse and Mental Health Services Administration (SAMHSA) and the Office of the National Coordinator for Health Information Technology (ONC) announced last week the release of FAQs for Applying the Substance Abuse Confidentiality Regulations to Health Information Exchanges (HIEs).


Cover letter regarding the FAQs by Pamela S. Hyde, the Administrator of SAMHSA, and David Blumenthal, National Coordinator for ONC. The letter describes that the the Substance Abuse Confidentiality Regulations under 42 CFR Part 2 were enacted years ago (circa 1975). Due to the age of the regulations SAMHSA and ONC created the FAQs to provide guidance and understanding of the scope of these regulations in the context of today's move toward an electronic health information system.


The FAQs outline the general requirements under 42 CFR Part 2, provide guidance on its application to HIEs, and identify methods for including substance abuse related health information into HIEs that is consistent with the Federal statute.


As a follow-up to the release of the FAQs, SAMHSA and ONC will convene a meeting of concerned or interested parties from both the Behavioral Health and Information Technology (BH-IT) communities on August 4, 2010. The meeting will be an opportunity for SAMHSA and ONC to receive questions and comments on the FAQs.


The FAQs for Applying the Substance Abuse Confidentiality Regulations to Health Information Exchanges (HIEs) provide information on the following 37 questions:

   1. Does the federal law that protects the confidentiality of alcohol and drug abuse patient records allow information about patients with substance use disorders to be included in electronic health information exchange systems?
   2. What types of providers are covered programs under 42 CFR Part 2 (“Part 2”)?
   3. What patients, and which records and information, are protected by 42 C.F.R Part 2?
   4. For the purposes of the applicability of 42 CFR Part 2, does it matter how HIOs are structured?
   5. Does 42 CFR Part 2 permit the disclosure of information without a patient’s consent for the purposes of treatment, payment, or health care operations?
   6. Under Part 2, can a Qualified Service Organization Agreement (QSOA) be used to facilitate communication between a Part 2 program and an HIO?
   7. May information protected by Part 2 be made available to an HIO for electronic exchange?
   8. If Part 2 information has been disclosed to the HIO, either pursuant to a Part 2- compliant consent form authorizing such disclosure or under a QSOA, may the HIO then make that Part 2 information available to HIO-affiliated members?
   9. How do different HIO patient choice models regarding whether general clinical health information may be disclosed to or through an HIO (e.g., no consent, opt in or opt out) affect the requirements of 42 CFR Part 2?
  10. If an HIO is holding or storing Part 2 patient data through a QSOA, can the HIO redisclose the data coming from the Part 2 program to a third party without patient consent?
  11. What are the required elements of a patient consent under Part 2?
  12. What must a Part 2 program do to notify the HIO, or any other recipient of Part 2 protected information, that it may not redisclose Part 2 information without patient consent?
  13. Can a single consent form be used to authorize the disclosure of Part 2 information to an HIO, as well as authorize the redisclosure of that information to other identified parties, such as HIO affiliated members?
  14. Does Part 2 allow the use of multiple-party consent forms?
  15. Does Part 2 require the use of original signed consents?
  16. Under Part 2, may an HIO release demographic information about Part 2 patients without patient consent?
  17. Under Part 2, can an HIO reveal that a patient had an encounter at a mixed use facility (or “general medical” facility – see FAQ #2) as long as the HIO does not reveal that the patient was in the mixed use facility’s Part 2 program? A mixed use facility can be defined as a service provider organization that provides substance abuse treatment services as well as other health services such as primary care, dental care, mental health services, social services, etc.
  18. Under Part 2, can an HIO use a consent form that provides for disclosure to “HIO members” and refers to the HIO’s website for a list of those members?
  19. Can an HIO use a consent form under Part 2 to allow for the disclosure of information to future HIO affiliated health care providers?
  20. Can an HIO use a consent form under Part 2 to allow for the disclosure of information to health care providers who are providing on-call coverage for HIO affiliated health care providers or with whom those affiliated providers consult?
  21. Can a Part 2 patient consent be used to enable multiple disclosures?
  22. Can a Part 2 program or HIO use a consent form that has no specific expiration date but rather states that disclosure is permitted until consent is revoked by the patient?
  23. Is “treatment” a sufficient description of the intended purpose of a disclosure on a Part 2 consent?
  24. Under Part 2, can any health care provider make the determination that a medical emergency exists, or must a Part 2 provider make that determination?
  25. May a computer system be used to automatically determine whether a medical emergency exists and whether a disclosure of Part 2 data can be made without the patient’s consent?
  26. If a medical emergency exists, can the entire Part 2 record be released?
  27. For documentation purposes, if a medical emergency is present, would it be permissible under Part 2 to have treating providers simply check a drop down box signifying the existence of such a medical emergency?
  28. Under Part 2, may an HIO system make clinical decision support functions (such as showing a patient’s medications to clinicians when they write prescriptions, automatically ordering medications, and/or alerting clinicians about potential drug interactions) available to HIO affiliated health care providers in a medical emergency?
  29. Does the Part 2 definition of medical emergency also include mental health emergencies?
  30. When the HIO keeps an electronic record of a medical emergency, does that fully meet Part 2’s requirement to document disclosures made in a medical emergencies in the patient’s record?
  31. If an HIO’s electronic system makes a disclosure in a medical emergency, would documenting the name of the discloser as “electronically disclosed through the system administered by HIO” meet Part 2’s requirement that the name of the person who made the disclosure be documented in the patient’s record?
  32. If an HIO’s electronic system sends Part 2 data in a medical emergency to a printer or fax machine in the emergency room, can “the printer in the emergency department” meet Part 2’s requirement to document in the patient’s record the name of the person to whom the disclosure was made?
  33. Once Part 2 information is disclosed in a medical emergency, can that information be redisclosed without obtaining patient consent?
  34. If a patient has previously refused to consent to the release of his/her Part 2 record to a particular HIO affiliated health care provider, and then the patient is brought to that provider in a bona fide medical emergency situation, can that provider gain access through the HIO to the information without the patient’s consent under Part 2?
  35. Can an HIO disclose data for Disease Management purposes under Part 2 without patient consent?
  36. Under Part 2, would an HIO be permitted to disclose to an HIO affiliated payer the data of several patients held by the HIO, which may include Part 2 data, in order for the payer to target where interventions could be made with particular patients to improve care and management of disease?
  37. If an HIO affiliated health care provider wishes to gain access to a minor’s Part 2 record held by the HIO, may the HIO or provider obtain only the consent of a parent or guardian, or must the minor’s consent also be obtained?

Monday, May 3, 2010

OCR Request for Information: HIPAA Privacy Rule Accounting of Disclosures under HITECH

Today the Office for Civil Rights (OCR), Department of Health and Human Services issued a Request for Information titled HIPAA Privacy Rule Accounting of Disclosures Under the Health Information Technology for Economic and Clinical Health Act (75 Fed Reg 23214 May 3, 2010). More information at the OCR website.


The Request for Information by OCR seeks comments from health consumers and health care providers/organizations. OCR seeks information on the following areas:

    * Understanding the interests of individuals (health consumers) with respect to learning of such disclosures; and
    * The administrative burden on covered entities (health care providers/organizations) and business associates of accounting for such disclosures.

The Request for Information states that Section 13405(c) of the Health Information Technology for Economic and Clinical Health (HITECH) Act expands an individual’s right under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Rule to receive an accounting of disclosures of protected health information made by HIPAA covered entities and their business associates. In particular, section 13405(c) of the HITECH Act requires that the HIPAA Privacy Rule be amended to require covered entities to account for disclosures of protected health information to carry out treatment, payment, and health care operations if such disclosures are through an electronic health record.


The Request for Information requests specific comments on the following nine questions:

1. What are the benefits to the individual of an accounting of disclosures, particularly of disclosures made for treatment, payment, and health care operations purposes?

2. Are individuals aware of their current right to receive an accounting of disclosures? On what do you base this assessment?

3. If you are a covered entity, how do you make clear to individuals their right to receive an accounting of disclosures? How many requests for an accounting have you received from individuals?

4. For individuals that have received an accounting of disclosures, did the accounting provide the individual with the information he or she was seeking? Are you aware of how individuals use this information once obtained?

5. With respect to treatment, payment, and health care operations disclosures, 45 CFR 170.210(e) currently provides the standard that an electronic health record system record the date, time, patient identification, user identification, and a description of the disclosure. In response to its interim final rule, the Office of the National Coordinator for Health Information Technology received comments on this standard and the corresponding certification criterion suggesting that the standard also include to whom a disclosure was made (i.e., recipient) and the reason or purpose for the disclosure. Should an accounting for treatment, payment, and health care operations disclosures include these or other elements and, if so, why? How important is it to individuals to know the specific purpose of a disclosure— i.e., would it be sufficient to describe the purpose generally (e.g., for ‘‘for treatment,’’ ‘‘for payment,’’ or ‘‘for health care operations purposes’’), or is more detail necessary for the accounting to be of value? To what extent are individuals familiar with the different activities that may constitute ‘‘health care operations?’’ On what do you base this assessment?

6. For existing electronic health record systems:
(a) Is the system able to distinguish between ‘‘uses’’ and ‘‘disclosures’’ as those terms are defined under the HIPAA Privacy Rule? Note that the term ‘‘disclosure’’ includes the sharing of information between a hospital and physicians who are on the hospital’s medical staff but who are not members of its workforce.
(b) If the system is limited to only recording access to information without regard to whether it is a use or disclosure, such as certain audit logs, what information is recorded? How long is such information retained? What would be the burden to retain the information for three years?
(c) If the system is able to distinguish between uses and disclosures of information, what data elements are automatically collected by the system for disclosures (i.e., collected without requiring any additional manual input by the person making the disclosure)? What information, if any, is manually entered by the person making the disclosure?
(d) If the system is able to distinguish between uses and disclosures of information, does it record a description of disclosures in a standardized manner (for example, does the system offer or require a user to select from a limited list of types of disclosures)? If yes, is such a feature being utilized and what are its benefits and drawbacks?
(e) Is there a single, centralized electronic health record system? Or is it a decentralized system (e.g., different
departments maintain different electronic health record systems and an accounting of disclosures for treatment,
payment, and health care operations would need to be tracked for each system)?
(f) Does the system automatically generate an accounting for disclosures under the current HIPAA Privacy Rule (i.e., does the system account for disclosures other than to carry out treatment, payment, and health care
operations)?
i. If yes, what would be the additional burden to also account for disclosures to carry out treatment, payment, and health care operations? Would there be additional hardware requirements (e.g., to store such accounting information)? Would such an accounting feature impact system performance?
ii. If not, is there a different automated system for accounting for disclosures, and does it interface with the electronic health record system?

7. The HITECH Act provides that a covered entity that has acquired an electronic health record after January 1, 2009 must comply with the new accounting requirement beginning January 1, 2011 (or anytime after that date when it acquires an electronic health record), unless we extend this compliance deadline to no later than 2013. Will covered entities be able to begin accounting for disclosures through an electronic health record to carry out treatment, payment, and health care operations by January 1, 2011? If not, how much time would it take vendors of electronic health record systems to design and implement such a feature? Once such a feature is available, how much time would it take for a covered entity to install an updated electronic health record system with this feature?

8. What is the feasibility of an electronic health record module that is exclusively dedicated to accounting for disclosures (both disclosures that must be tracked for the purpose of accounting under the current HIPAA Privacy Rule and disclosures to carry out treatment, payment, and health care operations)? Would such a module work with covered entities that maintain decentralized electronic health record systems?

9. Is there any other information that would be helpful to the Department regarding accounting for disclosures
through an electronic health record to carry out treatment, payment, and health care operations?

Written comments to OCR must be submitted on or before May 18, 2010.

Thursday, March 18, 2010

OCR Update on Issuance of HIPAA HITECH Rulemaking

Update from Office for Civil Rights (OCR) on issuance of the Notice of Proposed Rulemaking (NPRM) implementing changes to HIPAA under the Health Information Technology for Economic and Clinical Health Act (HITECH). Health care organizations and health lawyers have been anxiously awaiting rules implementing and interpreting the changes because the effective date for many of the HITECH requirements was February 17, 2010. Of particular interest has been whether or not health care organizations are required to amend business associate agreement.

The notice seems to indicate that the the date for compliance and enforcement may be delayed since it states that the NPRM "will provide specific information regarding the expected date of compliance and enforcement." However, covered entities and business associates need to weigh the risks of not complying with the new requirements while waiting for further clarification from OCR.

The notice states:
OCR will implement important privacy and security provisions of the Health Information Technology for Economic and Clinical Health (HITECH) Act through notice and comment rulemaking, as required by the Administrative Procedure Act. These provisions include: business associate liability; new limitations on the sale of protected health information, marketing, and fundraising communications; and stronger individual rights to access electronic medical records and restrict the disclosure of certain information. OCR continues work on a Notice of Proposed Rulemaking (NPRM) regarding these provisions. Although the effective date (February 17, 2010) for many of these HITECH Act provisions has passed, the NPRM and the final rule that follows will provide specific information regarding the expected date of compliance and enforcement of these new requirements.

However, interim final rules implementing HITECH Act provisions in two areas have already been issued and are currently in effect: enforcement and breach notification. New civil money penalty amounts apply to HIPAA Privacy and Security Rule violations occurring after February 17, 2009. Covered entities and business associates must comply now with breach notification obligations for breaches that are discovered on or after September 23, 2009. OCR announced previously that it would use its enforcement discretion not to impose fiscal sanctions with regard to breaches discovered before February 22, 2010. Since that date has passed, OCR will enforce the Breach Notification Interim Final Rule, including with the possible imposition of sanctions, as it does with the HIPAA Privacy and Security Rule requirements.

Sunday, February 14, 2010

AIS Report on Patient Privacy: Analysis of Willful Neglect Under HITECH

Recently I was interviewed for a story focused on the changes to the HIPAA civil penalty enforcement under the HITECH Act.

The article, Willful Neglect Is Difficult to Pin Down, but Can Result in Enormous HIPAA Penalties, appears in the Report on Patient Privacy: Practical News and Strategies for Complying with HIPAA, Volume 10, Number 2 February 2010 published by Atalantic Information Services, Inc. (AIS). The article discusses the definition and interpretation of "willful neglect" under the HIPAA penalty provisions. Health care privacy officers should find this article helpful in better understanding their role and responsibility in overseeing privacy compliance efforts.

The full story was reprinted on AIS Health Business Daily website.

Thursday, January 14, 2010

State Attorney General HIPAA HITECH Enforcement

My health law colleague, David Harlow, covers the news today on the first HIPAA enforcement action taken by a state attorney general under the new HITECH provision of American Recovery and Reinvestment Act of 2009 (ARRA).

David's post, HIPAA enforcement by state attorney general: The shape of things to come, provides a good summary of the announcement by the Connecticut Attorney General. More information via the Connecticut Attorney General press release.

The lawsuit filed by the Connecticut Attorney General Richard Blumenthal (coincidentally brother of David Blumenthal, National Coordinator of Health Information Technology) alleges that a health insurer, Health Net of Connecticut, Inc., failed to promptly notify the AG and other officials of a missing portable computer disk drive that contained unencrypted protected health information, Social Security numbers and bank accounts for approximately 446,000 individuals. The lawsuit also named UnitedHealth Group Inc. and Oxford Health Plans, LLC who acquired ownership of Health Net of Connecticut. The action also seeks a court order against Health Net to encrypt all information held on electronic devices.

Since the early days of HIPAA implementation and compliance there has largely been a lack of real enforcement efforts. The new provisions under HITECH allowing state attorney generals to file HIPAA enforcement actions on behalf of the public bring a new era of enforcement against health care providers who are unfortunate to have a health data breach and fail to properly respond to such breach in a timely manner.

David offers some good advice and takeaway points to health care providers and others who regularly handle health information. It is not enough to have policies and procedures in place but to regularly monitor whether they are being followed. Today's health data is liquid and it can flow in many directions. Providers need to understand where and how data is stored, used and transferred.

Wednesday, December 23, 2009

Tweet By Hospital Employee: What information is considered PHI?

Interesting Tweet HIPAA Breach story coming out of Mississippi involving Governor Haley Barbour. The incident involved a response to Governor Barbour's tweet by a University Medical Center employee.

Ves Dimov, M.D. at Clinical Cases and Images Blog posts about the story - Single tweet by hospital employee to Mississippi Governor allegedly violates HIPAA, forces her to resign.

The incident will provide a good case study for health privacy lawyers who regularly consider the question of what information is and is not protected health information (PHI) under 45 CFR 160.103. PHI is defined under HIPAA as:

The Privacy Rule protects all "individually identifiable health information" held or transmitted by a covered entity or its business associate, in any form or media, whether electronic, paper, or oral. The Privacy Rule calls this information "protected health information (PHI)."

“Individually identifiable health information” is information, including demographic data, that relates to:

  • the individual’s past, present or future physical or mental health or condition,
  • the provision of health care to the individual, or
  • the past, present, or future payment for the provision of health care to the individual,

and that identifies the individual or for which there is a reasonable basis to believe it can be used to identify the individual. Individually identifiable health information includes many common identifiers (e.g., name, address, birth date, Social Security Number).

Thanks for the tip @RLBates and @EdBennett.

Tuesday, December 22, 2009

Lorman Medical Records Law Seminar: March 18, 2010

On March 18, 2010 I will be speaking on Medical Records Law at a seminar in Charleston, West Virginia. The seminar is sponsored by Lorman Educational Services. Joining me for the day long seminar will be three very knowledgeable health care colleagues:
  • Michael T. Harmon, MPA, CIPP/G, Compliance Specialist for the West Virginia Mutual Insurance Company, a Medical Professional Liability Insurance Company
  • Sallie H. Milam, J.D., CIPP/G, Executive Director of the West Virginia Health Information Network and Chief Privacy Officer for the West Virginia State Government
  • James W. Thomas, Esq., Manager of the Charleston, West Virginia Business Law Department of Jackson Kelly PLLC whose practice focuses primarily upon health care matters of a business, regulatory and operational nature
Additional information about the seminar and how to register can be found at Lorman Educational Services. Following is the full seminar agenda:

8:30 am – 9:00 am


Registration




9:00 am – 9:15 am


Overview




9:15 am – 10:30 am


HIPAA Compliance: Reality and Perspective



— Michael T. Harmon, MPA, CIPP/G



  • Overview
  • Enforcement
  • Complaints
  • Case Examples
  • Summary of HITECH Changes




10:30 am – 10:45 am


Break




10:45 am – 12:00 pm


HITECH Financial Incentives for Implementation of HIT



— James W. Thomas, Esq.



  • Qualifying an Electronic Health Record System
  • Available Financial Incentives




12:00 pm – 1:00 pm


Lunch (On Your Own)




1:00 pm – 2:00 pm


Health Information Exchange in West Virginia: Impact on Patient Records



— Sallie H. Milam, J.D., CIPP/G




2:00 pm – 2:15 pm


Break




2:15 pm – 3:30 pm


Consumer Driven Health Care: HITECH, Health 2.0, Social Media and Personal Health Records



— Robert L. Coffield, Esq.



  • HITECH Breach Notification Requirements
  • Impact of Health 2.0 and Social Media Technology on the Future of Health Care
  • Development and Adoption of Personal Health Records
  • Discuss the Legal Implications of Emerging Technology




3:30 pm – 4:30 pm


Panel Discussion



— Robert L. Coffield, Esq., Michael T. Harmon, MPA, CIPP/G, Sallie H. Milam, J.D., CIPP/G and James W. Thomas, Esq.

Thursday, December 10, 2009

HIPAA: Michigan Supreme Court Examing Preemption, Confidentiality and Ex Parte Interview of Treating Physicians in Medical Liability Litigation

The AMANews reports that the Michigan Supreme Court is examining whether the Health Insurance Portability and Accountability Act of 1996 (HIPAA) preempts state law to allow a defendant physician in a medical liability case to interview the plaintiff/patient's other treating physicians.

The history and docket information on the case before the Michigan Supreme Court, Andrea L. Holman v. Mark Rasak, SCt Case Number 137993, can be found via search here. Oral arguments were held on November 3, 2009. The Michigan Supreme Court provides a background summary of the case along with links to the briefs filed by the parties, including Amicus Curiae Briefs filed by the Michigan Association for Justice, Michigan Defense Trial Counsel, Michigan Health and Hospital Association, Michigan State Medical Society and ProAssurance Casualty Company and American Physicians Assurance Corporation.

The case involves a defendant physician who sought to interview the treating physicians, but the plaintiff/patient refused to waive her confidentiality rights under HIPAA. Plaintiff signed a HIPAA Authorization releasing the medical records but refused to provide a release for "oral communications." Defendant physician then sought a protective order to permit the ex parte interviews of the treating physicians but the circuit court denied the motion.

The circuit court concluded that the HIPAA provisions relative to the protective order only pertain to documentary evidence and that HIPAA does not authorize ex parte oral interviews.

On appeal the State of Michigan Court of Appeals in Andrea L. Holman v. Mark Rasak, D.O. ruling on November 18, 2008, reversed the circuit court's order denying the defendant physician's motion for a protective order to allow him to conduct ex parte interviews with the plaintiff/patient's treating physicians. The court held that HIPAA supersedes Michigan law to the extent that its protections and requirements are more stringent than those provided by stat law. The court held that the defendants may conduct an ex parte oral interview if a qualified protective order, consistent with 45 CFR 164.512(e)(1), is first put in place.

This will be an interesting ruling to watch. Stay tuned!

Monday, November 2, 2009

HIPAA Enforcement Meets HITECH: HIPAA Administrative Simplification: Enforcement Rule

On October 30, 2009, the Secretary of the Department of Health and Human Services (HHS) issued the HIPAA Administrative Simplification: Enforcement Interim Final Rule, 45 CFR Part 160 (74 Federal Register 56123, October 30, 2009).

This new rule was developed and adopted by HHS to conform the enforcement regulations under HIPAA to the revisions made to HIPAA under the Health Information Technology for Economic and Clinical Health Act (HITECH), which was part of the American Recovery and Reinvestment Act of 2009 (ARRA).

The rule amends the HIPAA enforcement regulations to include the imposition of tiered ranges for civil money penalty amounts based upon an increasing culpability associated with the violation. A full chart of the violation categories and related amounts can be found in the rule.

The interim final rule is effective on November 30, 2009. Comments on the rule can be made prior to December 29, 2009.

Monday, October 5, 2009

ARRA - HITECH: Health Care Information Breach Notification Regulations Now In Effect

Have you had a health data security breach? Do you know what a health data breach is? Are you required to notify individuals impacted by the breach? Do you have to notify federal agencies of such breach?

Read on for more information regarding the Office for Civil Right (OCR) and Federal Trade Commission (FTC) regulations requiring health care providers and other health data business vendors to assess and in some cases notify and report health information data breaches under the new federal law created by ARRA-HITECH.

The new regulations went into effect on September 23, 2009 and September 24, 2009, respectively, with a full compliance date of February 22, 2010. Health care providers covered under HIPAA and third party users of health information, including personal health record (PHR) companies and vendors, PHR related entities, health 2.0 companies and other third party health data service providers, should examine the regulations and understand the impact on their business.

The regulations require entities to develop internal compliance processes to act upon and advise individuals of data breaches that pose a significant risk of financial, reputational or other harm to the affected individual. The OCR regulations apply mainly to covered entities and business associates under HIPAA and the FTC regulations apply mainly to PHR vendors and PHR related entities. The regulations define a "breach" and set forth the time frames and scope of notification required. The regulations require the tracking and reporting of such data breaches to OCR and FTC. Also, OCR has published separate guidance specifying the technology and methods that will render health information unusable, unreadable and undecipherable as defined under ARRA-HITECH.

OCR has provided a summary of the breach notification rule on its website. OCR has also published instructions for reporting breaches to the HHS Secretary. The instructions include details for reporting "Breaches Affecting 500 or More Individuals" and "Breaches Affecting Fewer than 500 Individuals." OCR will also maintain a list of reported breaches that impact 500 or more individuals. The FTC also has a section on its website providing information on its health breach notification rule.

Below are links to the full regulation text:
  • OCR Guidance Specifying the Technologies and Methodologies That Render Protected Health Information Unusable, Unreadable, or Indecipherable to Unauthorized Individuals for Purposes of the Breach Notification Requirements Under Section 13402 of Title XIII (Health Information Technology for Economic and Clinical Health Act) of the American Recovery and Reinvestment Act of 2009; Request for Information 74 Fed. Reg. 19006 (April 27, 2009).
  • Federal Trade Commission: Health Breach Notification Rule: Final Rule -- Issued Pursuant to the American Recovery and Reinvestment Act of 2009 -- Requiring Vendors of Personal Health Records and Related Entities To Notify Consumers When the Security of Their Individually Identifiable Health Information Has Been Breached (16 CFR Part 318) 74 Fed. Reg. 42962 (Aug 25, 2009). The FTC has also issued a Breach Notification Form.
UPDATE (July 29, 2010):

Today the OCR/HHS issued a statement that the OCR Interim Final Rule listed above and published on August 24, 2010, is being withdrawn from the Office of Management and Budget (OMB). The full notice published on the OCR website states:

Breach Notification Final Rule Update

The Interim Final Rule for Breach Notification for Unsecured Protected Health Information, issued pursuant to the Health Information Technology for Economic and Clinical Health (HITECH) Act, was published in the Federal Register on August 24, 2009, and became effective on September 23, 2009. During the 60-day public comment period on the Interim Final Rule, HHS received approximately 120 comments.

HHS reviewed the public comment on the interim rule and developed a final rule, which was submitted to the Office of Management and Budget (OMB) for Executive Order 12866 regulatory review on May 14, 2010. At this time, however, HHS is withdrawing the breach notification final rule from OMB review to allow for further consideration, given the Department’s experience to date in administering the regulations. This is a complex issue and the Administration is committed to ensuring that individuals’ health information is secured to the extent possible to avoid unauthorized uses and disclosures, and that individuals are appropriately notified when incidents do occur. We intend to publish a final rule in the Federal Register in the coming months.



    Thursday, August 20, 2009

    OCR Designates HIPAA Regional Office Privacy Advisors

    The Acting Director and Principal Deputy Director for the Office for Civil Rights, Robinsue Frohboese, has designated Office for Civil Rights Regional Managers in each of the HHS Regional Offices to serve as the Regional Office Privacy Advisors. On July 27, 2009, Secretary Sebelius authorized the Director of the Office for Civil Rights to carry out the designation required under the Health Information Technology for Economic and Clinical Health (HITECH) Act (Title XIII of Division A and Title IV of Division B of the American Recovery and Reinvestment Act of 2009 (ARRA).

    The designation of these Regional Office Privacy Advisors was mandated by the ARRA-HITECH provisions under Section 13403(a). The Regional Office Privacy Advisors will offer guidance and education to covered entities, business associates, and individuals on their rights and responsibilities related to the HIPAA Privacy and Security Rules

    The names, addresses, and contact information for each of the Regional Managers are listed together with a list of the States for which each Regional Manager has responsibility are listed below:

    Region I - Boston (Connecticut, Maine, Massachusetts, New Hampshire, Rhode Island, Vermont)
    Peter Chan, Regional Manager
    Office for Civil Rights
    U.S. Department of Health and Human Services
    Government Center
    J.F. Kennedy Federal Building - Room 1875
    Boston, MA 02203
    Voice phone(617)565-1340
    FAX (617)565-3809
    TDD (617)565-1343

    Region II - New York (New Jersey, New York, Puerto Rico, Virgin Islands)
    Michael Carter, Regional Manager
    Office for Civil Rights
    U.S. Department of Health and Human Services
    Jacob Javits Federal Building
    26 Federal Plaza - Suite 3312
    New York, NY 10278
    Voice Phone (212)264-3313
    FAX (212)264-3039
    TDD (212)264-2355

    Region III - Philadelphia (Delaware, District of Columbia, Maryland, Pennsylvania, Virginia, West Virginia)
    Paul Cushing, Regional Manager
    Office for Civil Rights
    U.S. Department of Health and Human Services
    150 S. Independence Mall West
    Suite 372, Public Ledger Building
    Philadelphia, PA 19106-9111
    Main Line (215)861-4441
    Hotline (800) 368-1019
    FAX (215)861-4431
    TDD (215)861-4440

    Region IV - Atlanta (Alabama, Florida, Georgia, Kentucky, Mississippi, North Carolina, South Carolina, Tennessee)
    Roosevelt Freeman, Regional Manager
    Office for Civil Rights
    U.S. Department of Health and Human Services
    Atlanta Federal Center, Suite 3B70
    61 Forsyth Street, S.W.
    Atlanta, GA 30303-8909
    Voice Phone (404)562-7886
    FAX (404)562-7881
    TDD (404)331-2867

    Region V - Chicago (Illinois, Indiana, Michigan, Minnesota, Ohio, Wisconsin)
    Valerie Morgan-Alston, Regional Manager
    Office for Civil Rights
    U.S. Department of Health and Human Services
    233 N. Michigan Ave., Suite 240
    Chicago, IL 60601
    Voice Phone (312)886-2359
    FAX (312)886-1807
    TDD (312)353-5693

    Region VI - Dallas (Arkansas, Louisiana, New Mexico, Oklahoma, Texas)
    Ralph Rouse, Regional Manager
    Office for Civil Rights
    U.S. Department of Health and Human Services
    1301 Young Street, Suite 1169
    Dallas, TX 75202
    Voice Phone (214)767-4056
    FAX (214)767-0432
    TDD (214)767-8940

    Region VII - Kansas City (Iowa, Kansas, Missouri, Nebraska)
    Frank Campbell, Regional Manager
    Office for Civil Rights
    U.S. Department of Health and Human Services
    601 East 12th Street - Room 248
    Kansas City, MO 64106
    Voice Phone (816)426-7277
    FAX (816)426-3686
    TDD (816)426-7065

    Region VIII - Denver (Colorado, Montana, North Dakota, South Dakota, Utah, Wyoming)
    Velveta Howell, Regional Manager
    Office for Civil Rights
    U.S. Department of Health and Human Services
    1961 Stout Street -- Room 1426 FOB
    Denver, CO 80294-3538
    Voice Phone (303)844-2024
    FAX (303)844-2025
    TDD (303)844-3439

    Region IX - San Francisco (American Samoa, Arizona, California, Guam, Hawaii, Nevada)
    Michael Kruley, Regional Manager
    Office for Civil Rights
    U.S. Department of Health and Human Services
    90 7th Street, Suite 4-100
    San Francisco, CA 94103
    Voice Phone (415)437-8310
    FAX (415)437-8329
    TDD (415)437-8311

    Region X - Seattle(Alaska, Idaho, Oregon, Washington)
    Linda Yuu Connor, Regional Manager
    Office for Civil Rights
    U.S. Department of Health and Human Services
    2201 Sixth Avenue - M/S: RX-11
    Seattle, WA 98121-1831
    Voice Phone (206)615-2290
    FAX (206)615-2297
    TDD (206)615-2296

    Monday, August 3, 2009

    HIPAA Security Rule Enforcement Delegated to OCR

    Today HHS Secretary Kathleen Sebelius announced that enforcement of the Security Rule under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) will be delegated to the Office for Civil Rights (OCR).

    The official delegation occurred on July 27, 2009. More information about the transition of authority for the administration and enforcement of the Security Rule can be found in the OCR press release. The official Delegation of Authority by the Office of the Secretary has been issued and will appear in the August 4, 2009 Federal Register.

    Prior to today, administration and enforcement of the HIPAA Security Rule has been the responsibility of the Centers for Medicare & Medicaid Services (CMS).

    Wednesday, June 3, 2009

    Microsoft HealthVault: You put your right HIPAA in . . .

    In a post today, Sean Nolan, Chief Architect of Microsoft Health Solutions and blogger at Family Health Guy explains Microsoft's position regarding whether Microsoft HealthVault is required to comply with the privacy standards under the Health Insurance Portability and Accountability Act of 1996 (HIPAA).

    The blog post, "You put your right HIPAA in . . ." provides some background on the process that Microsoft has gone through to look at the question of whether they are directly required to comply with HIPAA as a "covered entity" or whether the must enter into "business associate agreement"with other covered entities. Although they don't reach a final definitive conclusion Microsoft does state that they are now prepared to sign a business associate agreement with any covered entity who concludes that it is important as a part of their compliance and responsibility under HIPAA.

    The post by also includes a link to the standard Microsoft HealthVault Business Associate Agreement.

    The conclusion reached by Microsoft seems like a practical one to this health care lawyer. Anyone who deals with health information has a responsibility to assess whether or not they are a covered entity under HIPAA. They further have a responsibility to be a part of the conversation with those other person that they deal with who are covered entities as to whether a business associate agreement must be in place. However, the final decision of whether a business associate agreement is required must be made by the covered entity who is responsible for complying with the privacy provisions.

    The determination of whether a particular party is a business associate under HIPAA is one that largely depends on the unique facts of the relationship that they have with a covered entity under HIPAA. There is not a blanket determination of whether someone is or is not a business associate for purposes of HIPAA compliance. The questions that must be asked to assess whether a business associate relationship exists under 160.103 and 164.502 are:
    1. Does the person/party "perform or assist" in the performance of a "function or activity" involving the use or dislcosure of individually identifiable health information" OR
    2. Does the person/party provide certain "professional services to or for the covered entity" involving the disclosure of individually identifiable health information (as these terms are futher defined under the regulations).
    As stated in the post there is still unclear areas as a result of the ARRA HITECH privacy provisions that will still need to be sorted out as we move forward. However, the important issue is to continue to move forward.

    Friday, April 24, 2009

    AHLA Teleconference: HIPAA Privacy Fundamentals

    Next month I will be co-presenting on an American Health Lawyer Association Teleconference on the topic of HIPAA Privacy Regulation Fundamentals - An Introductory Course.

    The teleconference is scheduled for May 13, 2009, 1:00 - 2:30 pm EST. My co-presenter is Rebecca L. Williams of Davis Wright Tremaine LLP and the moderator will be Phyllis Granade of Adorn & Yoss.

    This teleconference is geared toward a gaining a basic understanding of HIPAA privacy law for health lawyers (think, HIPAA 101). We will also be discussing the impact of the changes unde rthe HITECH Act of 2009. Although geared toward health lawyers this teleconference would also be valuable for health care professionals and others in the industry interested in learning more about HIPAA.

    You can find out more about the teleconference and how to register via the AHLA website.

    Sunday, April 19, 2009

    HITECH Act Breach Notification Guidance: What Renders PHI Unusable, Unreadable or Indecipherable For Purposes of Breach Notification?

    On April 17, 2009, the U.S. Department of Health & Human Services (HHS) issued guidance on the technology requirements to render protected health information (PHI) "unusable, unreadable or indecipherable to unauthorized individuals, as required by the Health Information Technology for Economic and Clinical Health Act (HITECH) which is a part of the American Recovery and Reinvestment Act of 2009 (ARRA).

    The April 27, 2009 Federal Register (74 FR 19006),contains the official copy of the regulation, Guidance Specifying the Technologies and Methodologies That Render Protected Health Information Unusable, Unreadable, or Indecipherable to Unauthorized Individuals for Purposes of the Breach Notification Requirements Under Section 13402 of Title XIII (Health Information Technology for Economic and Clinical Health Act) of the American Recovery and Reinvestment Act of 2009; Request for Information

    The guidance is effective as of April 17, 2009. However, the guidance will apply to breaches 30 days after publication of the interim final regulations.

    HHS's press release on the guidance states:
    The guidance issued today provides steps entities can take to secure personal health information and establishes the trigger for when entities must notify that patient data has been compromised. This guidance is related to “breach notification” regulations, which will be issued by HHS and the Federal Trade Commission respectively. The HHS regulations will apply to entities covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the FTC regulation will apply to vendors of personal health records and certain others not covered by HIPAA. The Recovery Act requires that these regulations be published within 180 days of enactment.
    The guidance was developed through a joint effort by the HHS Office for Civil Rights (OCR), Office of the National Coordinator for Health Information Technology (ONC), and Centers for Medicare &Medicaid Services (CMS).
    The guidance also seeks public comments on the guidance as well as the breach notification provisions under FTC's new Health Breach Notification Rule and the yet to be releases HHS Breach Notification Requirements for HIPAA Covered Entities and Business Associates. Public comments must be submitted on or before May 21, 2009.