Stimulus provisions will improve HIPAA.

PositionHEALTH RECORDS

The stimulus package passed earlier this year included $20 billion to help jumpstart and build out a nationwide health IT network. It also included changes to health information privacy and security provisions under the Health Insurance Portability and Accountability Act (HIPAA), which many privacy advocates have criticized as lax.

[ILLUSTRATION OMITTED]

The Health Information Technology for Economic and Clinical Health (HITECH) Act, which is intended to promote widespread adoption of health IT, was incorporated into the American Recovery and Reinvestment Act (ARRA) of 2009. According to provisions in the legislation, physicians will be required to track any disclosure of a patient's medical information. Previous regulations allowed physicians to disclose patient information for the purpose of treatment, payment, or healthcare operations, but they were not required to track when that data was disclosed.

However, the new legislation requires physicians who use electronic health records (EHRs) to be able to track each time patient data has been disclosed. That provision won't become effective for current EHR users until Jan. 1, 2014, but patients can request information about any disclosures of their electronic personal health records three years from the date of the request, potentially dating back to 2011.

The legislation also requires practices to post information about security breaches if a breach affects 10 or more patients. If a security breach affects 500 or more patients, practices must notify their patients, a local media outlet, and the Department of Health and Human Services secretary.

The new legislation also calls for enhanced enforcement rules and a new aggressiveness in as signing fines. Fines for security breaches start at...

To continue reading

Request your trial

VLEX uses login cookies to provide you with a better browsing experience. If you click on 'Accept' or continue browsing this site we consider that you accept our cookie policy. ACCEPT