Showing posts with label Privacy. Show all posts
Showing posts with label Privacy. Show all posts

Saturday, February 13, 2010

HITECH Act's Changes to HIPAA Privacy Rule Soon Taking Effect

Covered entities and business associates subject to the HIPAA Privacy Rule, including health care providers and revenue cycle vendors, should take note that the amendments to the Rule brought about by the Health Information Technology for Economic and Clinical Health Act, §§13400-13424 of the American Recovery and Reinvestment Act of 2009 (the "HITECH Act"), take effect February 17, 2010.

Previously, business associates' only liability for mishandling Protected Health Information (PHI) arose under the business associate's contract with the health care provider, and the only party responsible for ensuring the existence of a proper Business Associate Agreement was the provider itself. Under the amended regulations, a business associate can now be held directly responsible for improper use of PHI and for the failure to maintain proper policies for its protection.  §13404(a).

The HITECH Act makes the following provisions, previously directed at covered entities only, applicable to business associates:

Additionally, while HIPAA previously required action on breaches only by covered entities, the HITECH Act requires business associates to take action on known breaches of their agreements by the covered entities they serve, including curing the breach themselves, terminating the agreement, and/or notifying the department of the covered entity's breach. §13404(b).

The breach notification requirements affecting covered entities and business associates have also changed. The HITECH Act requires notification by a covered entity to the individual whose PHI has been breached, within a reasonable time, not longer than 60 days. Business associates must notify covered entities of any breach within the same time period. The notice must be sent in writing via first class mail, and in the case where the breach concerns 10 or more individuals and the individuals cannot be located, notice must be posted on the breaching party's website and through public media. Notice regarding the breach must also be provided to the Secretary, immediately in the case of a breach concerning 500 or more individuals, and via an annual log in the case of a breach of fewer than 500 individuals. §13402.

The penalties for failing to comply with these provisions include criminal charges, §13409, and civil sanctions, §13410

From a practical standpoint, this means that agencies should implement their own documented policies for protecting PHI and should immediately ensure that a Business Associate Agreement is executed with the covered entities with which they do business. Covered entities should review the policies of each and every business associate. If an agreement already exists (which it should), it may need to be amended. It must limit the exchange and use of PHI to the minimum amount necessary for the business associate to carry out its function. HHS has a website discussing the recommended contract language, here. Our sample contract is found below. Note: the agreement requires customization based upon the use of PHI contemplated by the parties' business relationship.

Tuesday, May 5, 2009

FTC Red Flags Compliance Deadline Extended to August 1, 2009

UPDATE - the Federal Trade Commission has once again extended the deadline for creditors and collection professionals to comply with their Red Flags Rule. The new deadline is August 1, 2009. Additionally, the FTC has launched a website and a report providing information for business who must comply. The Association of Credit and Collection Professionals has more information, including sample materials for members.

Jorge M. Abril, P.A. offers its clients model identity theft prevention policy review, design and documentation. Contact us for more information.

Tuesday, April 21, 2009

HIPAA and President Obama's Economic Stimulus Package

President Obama expects his economic stimulus, the American Recovery & Reinvestment Act of 2009, to affect the lives of many Americans. I, for one, will be attempting to capitalize on the $8,000 tax credit for first time home buyers, which I'm sure you've all heard about.

Lesser known provisions of the legislation have significant effect on the way HIPAA covered entities and business associates handle Patient Health Information (PHI). For example, under the new law, covered entities will be required to notify individuals when there has been a breach of their PHI, and business associates will be required to notify the covered entities they contract with of breaches, regardless of the terms of their contract. There are many other provisions of this new law that healthcare reimbursement professionals who exchange or utilize PHI should note. The text of the request for information created by the Department of Health and Human Services is provided here.

More information is available on this blog, and in this summary, provided by the Center for Democracy and Technology.

Monday, April 20, 2009

Red Flag Compliance Date Looms for Collection Agencies

May 1, 2009 marks the deadline for creditors, collection agencies, and anyone utilizing credit reports in deciding to extend or negotiate credit (yes, that includes you!) to comply with the FTC's Red Flag Rules. The regulations are intended to minimize the risk of identity theft, and they have far-reaching implications. The web is full of information on these wide-sweeping rules, including this from the FTC, and even a rap song from a company offering compliance-testing software (video below courtesy of youtube).



If you don't consider yourself a creditor, and as a result you think this rule might not apply to you, think again. Maybe it's because I'm a lawyer and I have mouths to feed, but my advice would be to trust only credible sources, and if there's any doubt as to whether and how this rule might apply to you, seek the advice of counsel. This information is thorough and well organized. And this is a good sample compliance policy. See our website, www.abrilaw.com for more on this rule in the coming days.