REMINDER: Make your comments heard by HHS
HIPAA Weekly Advisor, May 18, 2009
Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!
You have until May 21 to issue comments to HHS about the definition of unsecure PHI.
HHS issued a proposal for security breach notification in a 20-page report that defines acceptable conditions for covered entities and business associates to encrypt or destroy their private patient data to secure protected health information (PHI) and prevent a breach.
The guidance released April 17 includes the technologies and methods specified by the Secretary of HHS that render PHI "unusable, unreadable, or indecipherable to unauthorized individuals." The American Recovery and Reinvestment Act of 2009 (ARRA) required the draft guidance by April 18, according to an HHS press release.
Covered entities and business associates are not required to follow the guidance. However, if they do, it creates a "safe harbor" and protects them from the notification requirements when a security breach occurs, according to the new HHS report.
Although the guidance is not final yet, covered entities and business associates should pay close attention to it because the guidance will help them determine whether their facility had a breach of patient privacy.
Title XIII of the ARRA—the Health Information Technology for Clinical and Economic Health (HITECH) Act—describes greater notification requirements for breaches of "unsecured PHI," or PHI that is not secured through technologies and methodologies specified by the Secretary.
The report released in April includes those specifications. After a public comment period, which ends May 21, HHS will release the final guidance by August 17, according to the ARRA.
Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!
Related Products
Most Popular
- Articles
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- Catch up on what's new with injections and infusions
- Identify potential Medicaid RAC target areas
- HIPAA Q&A: Level of encryption needed for email
- Topic: CMS, OESS post new security compliance review information, checklist
- Capturing all necessary codes for IUD insertion and removal can be challenging
- What does case-mix index mean to you?
- OB services: Coding inside and outside of the package
- QA:Coding multiple initial infusions
- E-mailed
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- HIPAA Q&A: Level of encryption needed for email
- Q&A: Follow CMS' coding guidelines when using modifier -25
- What does case-mix index mean to you?
- Catch up on what's new with injections and infusions
- CMS has reformulated payments for some bilateral procedures
- New conflicts of interest create new challenges
- Q/A. One injection code or two?
- ED-to-inpatient transfers are flawed with safety gaps
- Searched
