von Briesen Health Law Blog

Capitol Building

October 29, 2009

HHS Inspector General Details Audit Plans for Health IT Efforts

Filed under: Records and TechnologyClaudia Egan @ 2:43 pm

HHS’ Office of the Inspector General (OIG) plans to audit CMS’ management of the stimulus package’s incentive payment program.  The program will provide roughly $30 billion to hospitals and doctors through the year 2016. The OIG also called for CMS to upgrade its IT systems to comply with the ‘meaningful use’ rules, which are due out shortly.

Proposed Rule That Modifies HIPAA

This month we have seen a lot of regulatory activity to implement the Genetic Information Nondiscrimination Act of 2008.  The IRS, the EBSA and CMS issued interim final rules that prohibit some health plans from using genetic information when conducting insurance functions such as underwriting. The Department of Health and Human Service’s Office of Civil Rights (OCR) issued a proposed rule that modifies HIPAA relating to the use and disclosure of genetic information by health plans. These final and proposed rules  were published in the Federal Register on October 7, 2009, and can be viewed at http://www.access.gpo.gov/su_docs/fedreg/a091007c.html.

October 28, 2009

First HIPAA “Snooping” Prosecution by a State Attorney General

Filed under: Records and TechnologyClaudia Egan @ 3:40 pm

Doctor and staff sentenced for accessing news anchorwoman’s’ records – first HIPAA “snooping” prosecution by a State AG.

http://www.justice.gov/usao/are/news_releases/PDFs_2009News_Releases/2009_index.html

September 3, 2009

von Briesen & Roper Law Bulletin: The Four Things You Need to Know and Do to Comply with the New HIPAA Breach Notification Rules

Filed under: Records and TechnologyClaudia Egan and Sally Ihlenfeld @ 4:39 pm

Effective September 23, 2009, if you are a health care provider, clearinghouse, or health plan that is a “Covered Entity” under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), you must notify affected individuals of certain breaches of their individually identifiable health information by you or your Business Associates.

This new “Rule” goes into effect on September 23, 2009; however, sanctions will not be imposed until after February 22, 2010. Read more…

August 24, 2009

Vice President Biden Announces Availability of Nearly $12 Billion in Grants to Help Hospitals and Doctors Use Electronic Health Records

Filed under: Records and TechnologyClaudia Egan @ 11:47 am

The grants will be awarded under the American Recovery and Reinvestment Act of 2009 (ARRA) and will help health care providers qualify for new incentives that will be made available in 2010 to doctors and hospitals that “meaningfully use” electronic health records. Click here to read the press release. Click here for more information about applying.

To track the progress of HHS activities funded through the ARRA, visit www.hhs.gov/recovery. To track all federal funds provided through the ARRA, visit www.recovery.gov.

August 19, 2009

HITECH Breach Notification Regulations

Filed under: Records and TechnologyClaudia Egan @ 11:48 am

The U.S. Department of Health and Human Services (HHS) issued new regulations today that require health care providers, health plans, and other entities covered by the Health Insurance Portability and Accountability Act (HIPAA) to notify individuals when their health information is breached.

The regulations require health care providers and other HIPAA covered entities to promptly notify affected individuals of a breach, and, in cases where a breach affects more than 500 individuals, to notify the HHS Secretary and the media.

Link to HHS press release.

August 17, 2009

FTC Issues Final Rule on PHR Security Breaches

Filed under: Records and TechnologyClaudia Egan @ 11:49 am

The Federal Trade Commission published its final rule requiring vendors of web-based personal health records to notify consumers when security of their information has been breached. Impacted vendors include many that do not have to comply with HIPAA, such as occupational health vendors that host employee health records and vendors who sell devices that include an option to upload data to a personal record. The rule can be found on the FTC web site.

July 20, 2009

von Briesen & Roper Law Bulletin: Hospital Procedures Broadcast via Social Media

Providers in the health care community are starting to use social networking mediums for promotion of their programs and public education. In fact, over 290 health care systems in the United States currently use a form of social networking, including several Wisconsin health care providers. This Bulletin provides a basic overview of the utility of using social networking websites to broadcast surgeries, and sets out some basic legal considerations related to this new trend. Read more…

May 21, 2009

ONCHIT Implementation Plan

Filed under: Records and TechnologyClaudia Egan @ 11:50 am

The Office of the National Coordinator for Health Information Technology recently published an operating plan to meet all the statutory requirements of the HITECH Act and Recovery Act. While we continue to say “don’t do anything yet”, it looks like providers, health plans and entities that furnish services to providers and health plans should be ready to make significant changes to their policies and practices relating to information technology beginning in mid-August, 2009. The Implementation Plan can be viewed here.

April 21, 2009

HHS Releases Guidance for Securing Health Information and Preventing Harm from Breaches

Filed under: Records and TechnologyClaudia Egan @ 2:52 pm

The U.S. Department of Health and Human Services (HHS) published guidance regarding technologies and methodologies to secure health information and prevent harm by rendering health information unusable, unreadable, or indecipherable to unauthorized individuals. The American Recovery and Reinvestment Act required publication of the guidance by April 18. This builds on the existing requirements of the HIPAA Privacy and Security Rules, which are unchanged.

The guidance issued provides steps entities can take to secure personal health information and establishes the trigger for when entities must notify that patient data has been compromised. This guidance is related to “breach notification” regulations, which will be issued by HHS and the Federal Trade Commission (FTC) respectively. The HHS regulations will apply to entities covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the FTC regulation will apply to vendors of personal health records and certain others not covered by HIPAA. The Recovery Act requires that these regulations be published within 180 days of enactment.

The guidance must be updated annually but HHS may update and reissue it this year, after public comment is considered and at the same time HHS’ breach notification regulation is published.

« Newer PostsOlder Posts »