Paralegal Division

JurisdictionUnited States,Federal
CitationVol. 26 No. 6 Pg. 66
Pages66
Publication year2013
Paralegal Division
Vol. 26 No. 6 Pg. 66
Utah Bar Journal
December, 2013

November, 2013

PRIVACY & SECURITY: A QUICK LOOK INTO THE OMNIBUS FINAL RULE OF THE HIPAA & HITECH ACTS

Heather J. Allen.

On January 25, 2013, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) promulgated the final rule under Health Information Portability Accountability Act (HIPAA) and Health Information Technology for Economic and Clinical Health Act (HITECH). Compliance with the new rule was required by September 23, 2013. The final rule can be found at 45 CFR 160-164. This rule, actually, includes four final rules:

The Final Modifications to the HIPAA Privacy, Security, and Enforcement Rules

According to HHS, the final modifications to the HIPAA Privacy, Security and Enforcement Rules were issued to (1) "Make business associates of covered entities directly liable for compliance with certain of the HIPAA Privacy and Security Rules' requirements."

(2) "Strengthen the limitations on the use and disclosure of PHI for marketing and fundraising purposes, and prohibit the sale of protected health information without individual authorization."

(3) "Expand individuals' rights to receive electronic copies of their health information and to restrict disclosures to a health plan concerning treatment for which the individual has paid out of pocket in full." (4) "Require modifications to, and redistribution of, a covered entity's notice of privacy practices." (5) "Modify the individual authorization and other requirements to facilitate research and disclosure of child immunization proof to schools, and to enable access to decedent information by family members or others." (6) "Adopt the additional HITECH Act enhancements to the Enforcement Rule not previously adopted." Federal Register Vol 78, No. 17, Friday January 25, 2013, 5566-5567 (outlining and detailing final modifications).

A covered entity is a health care provider, a health plan, or a health care clearinghouse. A business associate is an entity that receives, creates, transmits, and/or maintains protected health information (PHI) on behalf of a covered entity. (Detailed definitions can be found at 45 CFR 160.103.) Business associates are now held to a higher level and required to comply with the rules and protect the privacy and security of PHI. The rules have expanded this definition to include subcontractors of traditional business associates and other groups, such as...

To continue reading

Request your trial

VLEX uses login cookies to provide you with a better browsing experience. If you click on 'Accept' or continue browsing this site we consider that you accept our cookie policy. ACCEPT