HITECH Act Privacy and Security
Changes to Current HIPAA Laws and Regulations
My colleague Jonathan Krasner at Business Engineering, Inc. in Reston, Virginia sent me the following information about HIPAA changes that take effect this week. His information pertains to physician offices, medical billing companies, hospitals and a host of other healthcare facilities and vendors.
Congress passed and President Barack Obama signed the American Recovery & Reinvestment Act (ARRA) in February, 2009. The healthcare IT component of the ARRA is commonly referred to as the HITECH (Health Information Technology for Economic and Clinical Health) Act. The HITECH Act covers a broad range of healthcare IT initiatives including providing over $20 billion in funding towards implementation of healthcare IT. The HITECH Act also includes “Subtitle D” which focuses on privacy and modifies and broadens portions of the HIPAA Privacy and Security laws and regulations. The following is a high level overview of how the HITECH Act impacts current HIPAA laws and regulations. This first section is an overview of the changes that will go into effect on February 17, 2010; changes that were or will be effective on other dates are summarized on the second page of this document.
Application of Security/ Privacy Rules to Business Associates
Business Associates (BA’s – generally defined as those who do not work for a covered entity (CE) but handle protected health information (PHI))[mj1] will now be required to directly comply with the Administrative Safeguards, Physical Safeguards, Technical Safeguards and Policies and Procedures provisions of the existing HIPAA Security Rule. Similarly, BA’s are now directly bound by the privacy rules in the existing HIPAA regulations. They are also now directly subject to civil and criminal penalties for violations. Previously BA’s were only indirectly regulated through BA agreements with CE’s.
Restrictions on Certain Disclosures
CE’s are required to grant a request from an individual to restrict disclosure of their PHI if the disclosure is to a health plan for purposes of either payment or health care operations and the PHI pertains to a service for which the individual paid in-full, out-of-pocket. CE’s were not previously required to grant requests for restriction of any disclosure for payment or healthcare operations.
Disclosures Limited to the "Minimum Necessary"
CE’s are currently required to limit requests, use or disclosure of PHI to the “minimum necessary”. The HITECH Act clarifies that the “minimum necessary” will only be satisfied if a CE or BA uses a “limited data set” which is defined in HIPAA as PHI that excludes a specific set of direct identifiers of the individual. However, if using a “limited data set” is not practical then the “minimum necessary” guidance still applies. This HITECH Act also clarifies that it is the CE or BA disclosing the PHI that determines the “minimum necessary”.
Access to PHI in Electronic Format
CE’s that use an EHR must provide individuals the option to receive an electronic copy of their PHI. Any associated fee charged by the CE can only cover its labor costs for providing the electronic copy. Previously there was no requirement that an electronic copy had to be made available to individuals.
Marketing
Under HIPAA a CE generally must obtain authorization for any use or disclosure of PHI for marketing purposes except if the communication is for “health care operations”. This has been revised under HITECH. If a CE has received payment for making a communication, the communications for “health care operations” is allowed if (1) it relates to a drug or biologic that is currently being prescribed or (2) individual authorization has been obtained and or (3) a BA makes the communication on behalf of a CE that is within the framework of the BA agreement.
Fundraising
The requirement that a CE must, in any fundraising materials it sends to an individual, allow that individual to opt out of receiving any future fundraising communications is unchanged except that it is now a statutory requirement of the HITECH Act and not just a regulatory requirement.
Other HIPAA Changes in the HITECH Act
Clarification of Criminal Penalties (effective 2/17/2009)
The Department of Justice declared in a June 1, 2005 position paper that only CE’s could be directly liable for HIPAA criminal violations. The HITECH Act clarifies this to include that individuals, whether or not they are employees of a CE, can now be criminally liable for violations of HIPAA. BA’s are also now directly liable for violations of HIPAA or the HITECH Act. A new set of tiered, significant civil monetary penalties have also been established. Fines start at $100 per violation (max. $25K[mj1] per year) and go to $50K per violation ($1.5M per year), depending upon the violation type.
Improved Enforcement (effective 2/17/2009)
The HITECH Act now requires that HHS must investigate any complaint that may have resulted from “willful neglect” by a CE or BA. Also, a methodology must be developed by which victims of privacy violations may receive a share of the collected penalties. Finally, states’ attorneys general are also now permitted to bring a federal civil action on behalf of the residents of their states whom they believe have been adversely affected by a HIPAA violation.
Notification in Case of Breach of Confidentiality (effective 9/24/2009)
CE’s must now notify individuals whose unsecured protected health information (PHI) has been accessed or disclosed as a result of a breach. BA’s must similarly notify CE’s who must then notify affected individuals. Notification must be in writing within 60 days of discovery of the breach. If more than 500 individuals are affected Health and Human Services (HHS) and prominent media outlets must also be notified.
Prohibition on Sale of PHI (regulations due by 8/16/2010, effective 6 months later)
CE’s and BA’s may only receive payment in exchange for PHI if the individual has signed an authorization that discloses that payment will be made to the CE or BA. There are some exceptions including disclosures for public health, research, treatment, sales or mergers, payments to a BA for services performed for the CE or payments by an individual to obtain a copy of that individual’s record. Previously, only sales of PHI for marketing purposes required an authorization that disclosed payment was involved.
Accounting of Disclosures (effective date varies by date CE implements EHR)
The HITECH Act will require that CE’s follow a detailed accounting practice not previously in place under HIPAA. If an individual requests an accounting of electronic health records (EHRs), CE’s must be able to provide to the individual disclosure information for the prior three years, if the disclosures were made for "treatment, payment or health care operations." This will be phased in between 2011 and 2014.
We have seen some of these changes already being enforced. For instance, in January 2010, Connecticut Attorney General Richard Blumenthal sued Health Net for multiple HIPAA violations. Protected private medical records and financial information on almost a half million Health Net enrollees in Connecticut were exposed for at least six months before Health Net notified appropriate authorities and consumers.
Note: The foregoing is intended solely for informational purposes and should not be construed as legal advice. Providers should consult with independent legal and accounting counsel before making any decisions.





This page added to Google cache Cached: http://google.com/search?q=cache:http://blog.capturebilling.com/2010/02/15/hitech-act-privacy-and-security.aspx?ref=rss&ei=AFQjCNHajN_OX0kgxzx7UGA1yBfpoRn tubedfWq
Reply to this
I was just thinking about That Auction and you've really helped out. Thanks!
Reply to this
I wanted to thank you for this great read!! I definitely enjoying every little bit of it I have you bookmarked to check out new stuff you post.
Reply to this
I got so many points here, that's why i love reading your post. Thank you so much!
Reply to this
Nicely presented information in this post, I prefer to read this kind of stuff. The quality of content is fine and the conclusion is good. Thanks for the post.
Reply to this
I enjoyed reading your articles. This is truly a great read for me. I have bookmarked it and I am looking forward to reading new articles. Keep up the good work!
Reply to this
Another great post admin. This is such good info for my research. I will bookmark your post here on Digg.
Reply to this
Wow, medical records exposed for almost 6 months before anyone took action?! That's ridiculous! Hopefully this new action will help stop this injustice to the American people. For our $20 billion's sake, I hope so!
Cheers!
-Booker
Reply to this
your article is so informative and interesting. nice shared.
Reply to this
Am I right in thinking the new HITECH regs, although they will require amendment of the Business Agreement, will generally not require amendment of plan document language.....
http://www.jeuxsurinternet.net/
Reply to this
IT could be very useful for the development of health care. If they manage to create a network between hospitals and medics around the country, diagnostics could be more accurate and solutions found a lot quicker.
Reply to this
Up until recently, IT hasn't really found it's way into the medical field. Now, creating a network between doctors everywhere can lead to a great improvement in health care as more different opinions can be consulted before giving a certain diagnose.
Reply to this
Thanks for the info. This was honestly alot of useful information. Took me most of the night to go through and read it all. Bookmarked!
Reply to this
Nice one, your article is so informative, learn a lot from it.
Reply to this
Your website is really useful for many people I think. You helped me in various situations because I many times I have found the useful information which was really important for me in your site. Reading this your post I have known many new things about the Hitech act privacy which I have not known before. It is really great that you share for us such useful stuff. Thanks a lot one more time for the useful information and I will be waiting for more great news from you in the nearest future.
Reply to this
Hey - nice blog, just looking around some blogs, seems a pretty nice platform you are using. I'm currently using Wordpress for a few of my sites but looking to change one of them over to a platform similar to yours as a trial run. Anything in particular you would recommend about it?
Reply to this
Hi ... I just stumbled upon your post.. a gud view point.. Hey ur post left me quenching for more Your post really gives out useful knowledge.. thanks
Reply to this
Hi..it was a gripping post hi......
Reply to this
I came lately to your website and have been reading along. I thought I would leave my initial comment. Keep writing, cause your posts are impressive! Doesn't it take up a lot of time to keep your blog so fascinating???
Reply to this
Business Associates (BA’s – generally defined as those who do not work for a covered entity (CE) but handle protected health information (PHI))[mj1] will now be required to directly comply with the Administrative Safeguards, Physical Safeguards, Technical Safeguards and Policies and Procedures provisions of the existing HIPAA Security Rule. Similarly, BA’s are now directly bound by the privacy rules in the existing HIPAA regulations. They are also now directly subject to civil and criminal penalties for violations. Previously BA’s were only indirectly regulated through BA agreements with CE’s.
Reply to this
It is very generous of you for taking the time to discuss this, I feel strongly about it and will love to learning more on this at future. If possible, as you gain expertise, would you mind updating your blog more often with more useful information? Honestly It is extremely helpful for me .
Reply to this
Thanks your time
Reply to this
There are so many changes. It's interesting how it will affect.
Reply to this
It can be interesting, but, Who can guarantee my security?
Reply to this
Such a nice information
Reply to this
HITECH relates to the economic incentive for promotion of electronic health record and expansion of HIPAA privacy and security guidance. Unless you are a covered entity (health care provider, a health care clearinghouse, a health plan) or are a "Business Associate" sharing personal health information with a CE then you must comply with the guidelines.
Reply to this
Its very good post.I like it.
Reply to this
Oh boy. Thanks for taking the time to list all the changes in the laws and regulations. It is getting increasingly difficult to keep up with. I do appreciate regulations around protecting business colleagues, though.
Reply to this
It is interesting to know that with the new health care legislation there will be in place also some legislation around protection of privacy. If we all start using gov-controlled insurance, privacy will be even more important in times to come. Scary.
Reply to this
I admire the awesome information you offer in your articles. I will bookmark your blog and have my children check up here often. I am quite sure they will learn lots of new stuff here than anybody else
http://www.trucchidelpoker.it
Reply to this
Great. Already bookmarked this post. Very good post.
Reply to this
Huge thanks a lot for such a wonderful information about the Medical billing. I was actually looking for these information for quite a long time and i believe i have landed at the right page. I really liked your ways of expressing thoughts. You write too well. Moreover your article contains some worthy information which i guess will help lot of people. Thanks a lot one more time for publishing these nice posts and keep up publishing ones in the future too. BTW welcome to my new website about the payday loans no employment verification
Reply to this
It's a good post.
Reply to this
I love this post.
Reply to this
I love this post. Expecting more like this.
Reply to this
Awesome.
Reply to this
I read it. Its good.
Reply to this
Good post.
Reply to this
Its a great pleasure reading your blog. The blog content is powerful.Very Good.
Reply to this
Its a great pleasure reading your post.Its full of information I am looking for and I love to post a comment that "The content of your post is awesome" Great work.
Reply to this
Its a nice comment.I love reading it in detail and bookmarked it.I found some real value in the content.Loved it.
Reply to this
WoW Great post.I love to read more stuff like this.
Reply to this
I have to admit that I am so glad that I have found this your post because I have been searching for some information about the Hitech act privacy and security almost two hours. You helped me a lot indeed and reading this your article I have found many new and useful information about this subject. Well, I will definitely bookmark your website and wait for other useful and informative posts like this one in the future. Regards, Matt Watson from mp3 rocket music
Reply to this
This was a really quality post. In theory I'd like to write like this too - taking time and real effort to make a good article... but what can I say... I procrastinate alot and never seem to get something done.
Reply to this
Couldnt be written any better. Reading this post reminds me of my old room mate! He always kept talking about this. I will forward this article to him. Pretty sure he will have a good read. Thanks for sharing!
Reply to this
I really like the fact that from now onwards CE has to notify individuals whose unsecured protected health information (PHI) has been accessed or disclosed as a result of a breach.
Reply to this
Everyone sees a dream of havaing his own house. if you too want to have his own house, read this blog where you will find tips to buying a home .............. Thanks
Reply to this
more and more information about home purchasing are mentioned in this blog. Please read them and keep in mind. ----- Thanks
Reply to this
You got a really useful blog I have been here reading for about an hour. I am a newbie and your success is very much an inspiration for me.
Reply to this
Hi webmaster, commenters and everybody else !!! The blog was absolutely fantastic! Lots of great information and inspiration, both of which we all need!b Keep 'em coming... you all do such a great job at such Concepts... can't tell you how much I, for one appreciate all you do!
Reply to this
this is really cool and amazing i must say, liked reading this blog.
Reply to this
Nice post. This is a great blog and I have to congratulate you on the content.
Reply to this
Awesome information. Thank you for posting and keep up the good work. I'll be following your blog closely from now on! :-)
Reply to this
Very good post. I really like this article and you are given here really a wonderful information. Thanks a lot for sharing. Keep blogging.
Reply to this
I would like to thank you for the efforts you have made in writing this post. I am hoping the same best work from you in the future as well. In fact your creative writing abilities has inspired me to start my own BlogEngine blog now.
Reply to this
Why didn’t I find this post earlier? Keep up the good work!
Reply to this
your article is so informative and interesting. nice shared.
Reply to this
Your website is really useful for many people I think. You helped me in various situations because I many times I have found the useful information which was really important for me in your site.
Reply to this