Showing posts with label HIPAA. Show all posts
Showing posts with label HIPAA. Show all posts

Wednesday, August 5, 2015

New Guidance on Mobile Device Security for Health Care Providers

Written By Joanne Ceballos

At the end of July the National Institute of Standards and Technology of the U.S. Department of Commerce (“NIST”) released a draft practice guide, Securing Electronic Health Records on Mobile Devices, that demonstrates how health care IT professionals can use existing technologies, including commercially available and open source tools, to better protect electronic protected health information (“ePHI”) systems and facilitate secure sharing of ePHI through mobile devices.  According to the guide, the full text of which is available here, “many health care providers are using mobile devices in health care delivery before they have appropriate privacy and security protections in place.”  The guide is intended to provide a technical roadmap for achieving HIPAA-compliant use of mobile devices by health care professionals.

In order to arrive at their recommended solution, which can be implemented as outlined in the guidance or customized to a particular health care provider’s IT environment, NIST simulated interaction among mobile devices and an EHR system supported by the IT infrastructure of a medical organization.  They tested hypothetical scenarios in which a primary care physician uses a mobile device to send a referral containing a patient’s clinical information to another physician, to send an electronic prescription to a pharmacy, or to add information to a patient’s electronic health record.  In each scenario the mobile device interacts with an EHR system.

Health care providers using mobile devices to access or transmit patients’ ePHI are well-advised to confirm that their IT professionals are familiar with the guide’s recommendations.  Business Associates of health care providers who access or transmit ePHI via mobile devices should also consult with their IT personnel to determine whether those recommendations should be implemented by the Business Associate.  

Comments of the draft guidance may be submitted to NIST by September 25, 2015 via e-mail at HIT_NCCoE@nist.gov.         

Thursday, February 4, 2010

As of February 22, Comply with HIPAA Breach Notification Rules or Face Sanctions

The HITECH (“Health Information Technology for Economic and Clinical Health”) Act enacted last February imposed obligations on health care providers to notify patients if their protected health information was used or disclosed in a manner not permitted by HIPAA’s Privacy Rule. The U.S. Department of Health and Human Services published regulations which took effect in September 2009 specifying when and how providers have to notify patients of HIPAA breaches as well as recordkeeping requirements regarding reported HIPAA violations. When it published these “breach notification” regulations, HHS stated it would delay imposing sanctions for failure to comply with the regulations until February 22, 2010. So now is the time to familiarize yourself with the HITECH Act’s breach notification rules to avoid the prospect of hefty sanctions, ranging from a minimum of $10,000 up to $50,000 per violation, for willful neglect of the regulatory requirements.

Basically the breach notification rules require a health care provider to notify a patient if his/her protected health information (PHI) has been acquired, accessed, used or disclosed in a manner not permitted under HIPAA’s Privacy Rule which “poses a significant risk of financial, reputational, or other harm to the individual.” The form and manner of notification required under the regulations vary depending on whether a breach involves the PHI of fewer or more than 500 patients. There are certain good faith exceptions to the requirement to notify patients of PHI breaches.

The breach notification rules also require reporting of PHI breaches to HHS under certain circumstances, and impose an obligation on health care providers to document alleged HIPAA violations as well as the provider’s determination as to whether a breach occurred for purposes of the breach notification rules.

The key to compliance with the breach notification rules is establishing a procedure for receiving information about alleged HIPAA violations, evaluating whether a purported violation constitutes a breach for purposes of the notification rules, and documenting whether and how notification was provided. All documentation related to this procedure should be maintained in one location, preferably by one individual, in your practice. With February 22 just days away, it’s time to understand the HITECH breach notification rules and establish a procedure for complying with them.