Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« Information Security and Privacy Professionals Must Partner on Over 15 Different Enterprise Issues | Main | Keyloggers + Social Engineering = Identity Theft: Fraudsters Exploit Human Frailties with Seductive Messages »

HIPAA: More Changes and Initiatives by HHS

I've been reading so much about HIPAA lately; no enforcement actions yet, but a lot of changes, proposals and initiatives.

Two more I read about recently:

* On Friday, April 20, to coincide with the fourth anniversary of the enforcement of the HIPAA Privacy Rule, the Department of Health and Human Services (HHS) announced the launch of an enhanced Web site that will make it easier for consumers, health care providers and others to get information about how the Department enforces health information privacy rights and standards. According to the HHS:

"The Health Information Privacy Web site provides comprehensive information about the Privacy Rule, which creates important federal rights and requirements to protect the privacy of personal health information. The enhanced Web site, http://www.hhs.gov/ocr/privacy/enforcement provides information for consumers, health care providers, health plans and others in the health care industry about HHS’s compliance and enforcement efforts. The new information describes HHS activities in enforcing the Privacy Rule, the results of those enforcement activities, and statistics showing which types of complaints are received most frequently and the types of entities most often required to take corrective as a result of consumer complaints. The other information on the Web site covers consumers’ rights to access their health information and significantly control how their personal health information is used and disclosed, as well as guidance about how to submit complaints about possible violations of the law and extensive guidance for entities who must comply with the rule."

* On Monday, April 23, HHS Secretary Mike Leavitt formally announced he delegated subpoena powers to the Office for Civil Rights (OCR) at HHS and the authority for the director to re-delegate subpoena power for the investigation of potential violations of the privacy provisions of the Health Insurance Portability and Accountability Act (HIPAA) and the Patient Safety Quality Improvement Act.

According to HHS, HIPAA "authorizes the issuance of subpoenas requiring the attendance and testimony of witnesses and the production of any evidence that relates to any matter under investigation by the secretary and the enforcement of such a subpoena in court in event of refusal to comply."

In a separate announcement, Leavitt also granted subpoena power to the Centers for Medicare and Medicaid Services (CMS) to enforce other areas of HIPAA, including rules governing transaction and code sets.


I'm glad to see more information being provided about the actual enforcement activities and the related statistics; those have always been almost impossible to find, and numerous calls I've made to the HHS, OCR and CMS have always come up with virtually no one there knowing what the actual statistics were.

We shall see what the new subpeona powers mean...perhaps more active enforcement on the horizon?

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/389

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.