Civil rights office receives 637 HIPAA privacy complaints
HIPAA Weekly Advisor, June 27, 2003
Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!
HHS' Office for Civil Rights (OCR), which enforces the HIPAA privacy rule, has received 637 privacy complaints. The office began accepting complaints after the April privacy compliance deadline, and its figures reflect those complaints received through the middle of June, according to data presented to the National Committee on Vital and Health Statistics (NCVHS) at its June meeting.
Of those complaints, OCR has accepted 260 for investigation. The office closed 124 without further investigation and hasn't yet decided whether to investigate the remaining 253 complaints.
Stephanie Kaminsky, JD, the OCR liaison to the NCVHS, says OCR accepts a complaint for investigation when it determines that, if substantiated, a complaint represents a HIPAA violation. It rejects cases that would not constitute a violation. It has most often closed cases that refer to events that happened before the April privacy compliance deadline. The following are the top reasons for complaints that it has accepted:
- Patient denied access to his or her medical records
- No notice of privacy practices provided to patients
- Inadequate privacy safeguards in place in treatment settings
In addition, Kaminsky told the committee, it has received several HIPAA privacy complaints from employees reporting the organization where they work. "I don't know if it's full-fledged whistleblowing, but it's along those lines," she said. OCR is still developing criteria for when to refer a complaint to the Department of Justice for criminal prosecution. She said she knows of no complaints to date that have been referred for prosecution.
Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!
Related Products
Most Popular
- Articles
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- Catch up on what's new with injections and infusions
- Topic: CMS, OESS post new security compliance review information, checklist
- Capturing all necessary codes for IUD insertion and removal can be challenging
- HIPAA Q&A: Level of encryption needed for email
- Identify potential Medicaid RAC target areas
- What does case-mix index mean to you?
- QA:Coding multiple initial infusions
- OB services: Coding inside and outside of the package
- E-mailed
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- HIPAA Q&A: Level of encryption needed for email
- Q&A: Follow CMS' coding guidelines when using modifier -25
- CMS has reformulated payments for some bilateral procedures
- Catch up on what's new with injections and infusions
- New conflicts of interest create new challenges
- Q/A. One injection code or two?
- What does case-mix index mean to you?
- ED-to-inpatient transfers are flawed with safety gaps
- Searched