Health Information Management

Can the privacy officer be held liable if there is a privacy breach? Do we have to display our notice of privacy practices throughout our organization?

HIPAA Weekly Advisor, January 10, 2002

Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!

Q: Can the privacy officer be held liable if there is a privacy breach? Do we have to display our notice of privacy practices throughout our organization?

A: I have not seen anything from the Department of Health and Human Services designating a specific individual liable for noncompliance. The privacy regulations indicate that the organization can be fined.

There is some potential under the criminal liability section, because you can't hold an organization criminally liable. It would boil down to people. That's only going to be in the most extreme circumstances, when somebody has gone off on his or her own and sold health care information for profit. Then, that person could be subject to criminal penalties.

Q: Do we have to display our notice of privacy practices, in its totality, throughout our organization, or can we just have it in one location where patients can pick it up?

A: The privacy regulations specify the content of the privacy notice, but give organizations some flexibility as far as how they disseminate the information to patients.

Organizations have to look at what would be the most effective means of communication. HHS will give further guidance to health care organizations on the content of the notice and communications with patients.

You're not going to want to take the entire notice and post it on the wall. If patients request it, you have to give them the entire notice. Calling their attention to it and making them aware of where they can get it will probably be sufficient.

Editor's note: Answered by Jill Callahan Dennis, JD, RHIA, principal of Health Risk Advantage, in Denver, and Kathleen Frawley, JD, MS, RHIA, president of Frawley and Associates, in Montclair, NJ.

The above questions are from The Greeley Company's (a division HCPro) December 10 audioconference, "The HIPAA Chief Privacy Officer.How to be successful in your new role."

Go to http://www.hcmarketplace.com/product.cfm?ID=12548 to order an audiocassette of the audioconference.



Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!

  • Briefings on APCs

    Worried about the complexities of the new rules under OPPS and APCs? Briefings on APCs helps you understand the new rules...

  • Medical Records Briefing

    Guiding Health Information Management professionals through the continuously changing field of medical records and toward a...

  • Briefings on Coding Compliance Strategies

    Submitting improper Medicare documentaion can lead to denial of fees, payback, fines, and increased diligence from payers...

  • Briefings on HIPAA

    How can you minimize the impact of HIPAA? Subscribe to Briefings on HIPAA, your health information management resource for...

  • APCs Weekly Monitor

    This HTML-based e-mail newsletter provides weekly tips and advice on the new ambulatory payment classifications regulations...

Most Popular

Related Articles