/PRNewswire/ -- The following statement was released today by Rita K. Bowen, President, AHIMA Board of Directors:
"While AHIMA (American Health Information Management Association ) continues to applaud federal government support for the ideal of protecting patients' health information rights, the proposed rule-making for HIPAA privacy, security and enforcement by HHS has a number of requirements that we do not believe the industry is ready to undertake; especially as it gears up for Meaningful Use. Today AHIMA is releasing its recommendations to the HHS Office of Civil Rights (OCR) that speak to the issues we believe are most critical to the patients of America, the healthcare industry and the best practice of health information management.
"As staunch supporters of patients' health information rights, AHIMA agrees the single most contentious issue in the proposed regulation is the ability of individuals to restrict the information held by their healthcare providers from being shared with their health plan. While AHIMA believes an individual's control over this data flow is valid, data flow restrictions in the HHS proposal creates unintended repercussions for data integrity, data processing and other elements within the current US reimbursement system.
"Many AHIMA members are engaged in providing patients' individual and aggregate data for a variety of approved uses. There is a continued discussion within the profession on how to best cover the costs of the retrieval, analysis and release of information within the context of the privacy and security regulations, patient restrictions; and the need to verify the requesting individual as a means of keeping released information available to a necessary minimum. Additionally, we remain concerned the charges permitted by states or HIPAA do not cover all costs and ultimately raise the cost of health care.
"AHIMA also questions the sale of patient health information when an organization is being absorbed by a second organization. The OCR's approach, while practical, raises the issue of whether consumers have the right to determine if their health information should be transferred with the ownership of a health organization.
"Finally, AHIMA feels strongly that the OCR needs to provide greater clarification regarding the definition of 'agents' as it relates to covered entities and who should be covered by HIPAA, including its hybrid organizations."
-----
Community News You Can Use
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Follow us on Twitter: @GAFrontPage
Monday, September 13, 2010
AHIMA Files Response to HHS Privacy Rules
Posted by
Georgia Front Page.com
at
10:37 AM
0
comments
Labels: costs, fayette front page, georgia, georgia front page, health care, hopaa, patients, privacy, requirements, rights, rule making, security
Thursday, August 20, 2009
HHS Issues Rule Requiring Individuals Be Notified of Breaches of Their Health Information
New regulations requiring health care providers, health plans, and other entities covered by the Health Insurance Portability and Accountability Act (HIPAA) to notify individuals when their health information is breached were issued today by the U.S. Department of Health and Human
Services (HHS).
These "breach notification" regulations implement provisions of the Health Information Technology for Economic and Clinical Health (HITECH) Act, passed as part of American Recovery and Reinvestment Act of 2009 (ARRA).
The regulations, developed by the HHS Office for Civil Rights (OCR), require health care providers and other HIPAA covered entities to promptly notify affected individuals of a breach, as well as the HHS Secretary and the media in cases where a breach affects more than 500
individuals. Breaches affecting fewer than 500 individuals will be reported to the HHS Secretary on an annual basis. The regulations also require business associates of covered entities to notify the covered entity of breaches at or by the business associate.
"This new federal law ensures that covered entities and business associates are accountable to the Department and to individuals for proper safeguarding of the private information entrusted to their care. These protections will be a cornerstone of maintaining consumer trust as we move forward with meaningful use of electronic health records and electronic exchange of health information," said Robinsue Frohboese, acting director and principal deputy director of OCR.
The regulations were developed after considering public comment received in response to an April 2009 request for information and after close consultation with the Federal Trade Commission (FTC), which has issued companion breach notification regulations that apply to vendors of personal health records and certain others not covered by HIPAA.
To determine when information is "unsecured" and notification is required by the HHS and FTC rules, HHS is also issuing in the same document as the regulations an update to its guidance specifying encryption and destruction as the technologies and methodologies that render protected health information unusable, unreadable, or indecipherable to unauthorized individuals. Entities subject to the HHS and FTC regulations that secure health information as specified by the guidance through encryption or destruction are relieved from having to notify in the event of a breach of such information. This guidance will be updated annually.
The HHS interim final regulations are effective 30 days after publication in the Federal Register and include a 60-day public comment period. For more information, visit the HHS Office for Civil Rights web site at http://www.hhs.gov/ocr/privacy/.
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Posted by
Georgia Front Page.com
at
7:00 AM
0
comments
Labels: atlanta, breach, business, electronic health records, fayette front page, federal law, georgia, georgia front page, health information, HIPAA, notification, privacy, protection, regulations
Wednesday, February 18, 2009
Patients Gain Protections in Health Information Technology Law
/PRNewswire-USNewswire/ -- Patients across the United States will benefit from a new health information technology (HIT) law providing comprehensive privacy and security standards for patient records including strong, protective provisions for psychotherapy records. The Health Information Technology for Economic and Clinical Health (HITECH) Act, part of the economic stimulus package, was passed by the House and Senate on February 13 and signed into law by President Obama on February 17.
The HITECH Act builds on the federal government's current efforts to encourage the development of a national interoperable, electronic health records network with the goal of providing improved patient care at lower cost. The core of the HITECH Act contains provisions to ensure records privacy and security as HIT develops. The Act will:
-- Provide for an ongoing process for setting standards to better ensure
that privacy and security are protected in the health care system
-- Incorporate Health Insurance Privacy and Accountability Act (HIPAA)
Privacy and Security Rule standards, where possible, including with
regard to psychotherapy notes and other sensitive patient information
-- Improve upon the HIPAA "minimum necessary" standard, which requires
that only the minimum amount of patient information can be disclosed
depending on the request for the information
-- Implement further restrictions on health care plan use of patient
records for administrative "health care operations" purposes
-- Allow a patient to pay privately for health care and not have his or
her records included in an electronic network
-- Implement a process to explore segmenting particularly sensitive
patient records (such as mental health records)
-- Provide a notice to the patient when privacy is breached
-- Examine technologies to help patients track how their records have
been disclosed
-- Contain new strong patient enforcement measures and strengthen
existing HIPAA enforcement measures
-- Require Health and Human Services to study expanding the HIPAA
psychotherapy notes authorization requirement to include mental health
testing data
-- Make psychologists eligible for funding provisions in the law to
implement health information technology into their practices and to
join into electronic networks in their communities
-- Preserve stronger state privacy laws and allow the continued
application of state consent provisions
-- Require a study for providing for patient consent in electronic
records systems
-- Protect the well-established psychotherapist-patient privilege
currently recognized under federal and state law, and
-- Provide for continued Congressional oversight to ensure the bill's
privacy and security standards are effective.
The HITECH Act is the most comprehensive HIT legislation introduced by Congress and represents a giant leap forward for psychologists and their patients, achieving strong patient records privacy and security protections.
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Posted by
Georgia Front Page.com
at
11:07 AM
0
comments
Labels: atlanta, electronic health records, fayette front page, georgia, georgia front page, health information, hitech, patient records, privacy, psychotherapy, technology
