The U.S. Department of Health and Human Services (HHS) issued an interim final rule with request for comments today to strengthen its enforcement of the rules promulgated under the Health Insurance Portability and Accountability Act (HIPAA). The Health Information Technology for Economic and Clinical Health (HITECH) Act, which was enacted as part of the American Recovery and Reinvestment Act of 2009, modified the HHS Secretary's authority to impose civil money penalties for violations occurring after Feb. 18, 2009. These HITECH Act revisions significantly increase the penalty amounts the Secretary may impose for violations of
the HIPAA rules and encourage prompt corrective action.
Prior to the HITECH Act, the Secretary could not impose a penalty of more than $100 for each violation or $25,000 for all identical violations of the same provision. A covered health care provider, health plan or clearinghouse could also bar the Secretary's imposition of a civil money penalty by demonstrating that it did not know that it violated the HIPAA rules. Section 13410(d) of the HITECH Act strengthened the civil money penalty scheme by establishing tiered ranges of increasing minimum penalty amounts, with a maximum penalty of $1.5 million for all violations of an identical provision. A covered entity can no longer bar the imposition of a civil money penalty for an unknown violation unless it corrects the violation within 30 days of discovery.
The interim final rule with request for comments published today conforms the HIPAA enforcement regulations to these revisions made by the HITECH Act. It may be viewed and commented on at: www.regulations.gov. This rulemaking will become effective on Nov. 30,
2009, and HHS will consider all comments received by Dec. 29, 2009.
"The Department's implementation of these HITECH Act enforcement provisions will strengthen the HIPAA protections and rights related to an individual's health information," said Georgina Verdugo, the director of HHS Office for Civil Rights (OCR). OCR is responsible for
administering and enforcing HIPAA's privacy, security and breach notification rules.
"This strengthened penalty scheme will encourage health care providers, health plans and other health care entities required to comply with HIPAA to ensure that their compliance programs are effectively designed to prevent, detect and quickly correct violations of the HIPAA rules,"
said Verdugo. "Such heightened vigilance will give consumers greater confidence in the privacy and security of their health information and in the industry's use of health information technology."
This interim final rule with request for comments is the first of several steps HHS is taking to implement the HITECH Act's enforcement provisions. The remaining provisions, which have yet to become effective, will be addressed in the next few months in forthcoming rulemakings.
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
www.artsacrossgeorgia.com
Arts Across Georgia
Follow us on Twitter: @GAFrontPage
Friday, October 30, 2009
HHS Strengthens HIPAA Enforcement
Posted by
Georgia Front Page.com
at
3:27 PM
0
comments
Labels: enforcement, fayette front page, georgia front page, health, HIPAA, hitech, insurance, penalties, protection, rights, rules, violation
Thursday, October 1, 2009
New Rules Protect Patients' Genetic Information
Individuals' genetic information will have greater protections through new regulations issued today by the U.S. Departments of Health and Human Services (HHS), Labor, and the Treasury.
The interim final rule will help ensure that genetic information is not used adversely in determining health care coverage and will encourage more individuals to participate in genetic testing, which can help better identify and prevent certain illnesses.
"Echoing the late Senator Ted Kennedy, our efforts to protect Americans undergoing genetic testing from having the results of that testing used against them by their insurance companies is one of the 'first major new civil rights' of the new century," said HHS Secretary Kathleen Sebelius. "Consumer confidence in genetic testing can now grow and help researchers get a better handle on the genetic basis of diseases. Genetic testing will encourage the early diagnosis and treatment of certain diseases while allowing scientists to develop new medicines, treatments, and therapies."
The interim final rule with request for comments and the notice of proposed rulemaking implement Title I of the Genetic Information Nondiscrimination Act of 2008 (GINA). Under GINA, and the interim final rule, group health plans and issuers in the group market cannot:
increase premiums for the group based on the results of one enrollee's genetic information; deny enrollment; impose pre-existing condition exclusions; or do other forms of underwriting based on genetic information. In the individual health insurance market, GINA prohibits issuers from using genetic information to deny coverage, raise premiums, or impose pre-existing condition exclusions.
Further, under GINA and the new interim final regulations, group health plans and health insurance issuers in both the group and individual markets cannot request, require or buy genetic information for underwriting purposes or prior to and in connection with enrollment.
Finally, plans and issuers are generally prohibited from asking individuals or family members to undergo a genetic test.
"Today's genetic technologies yield data that are vital to helping Americans make personal, medical decisions. It is essential that we protect such information and ensure it is not misused by health plans or insurers," said Labor Secretary Hilda L. Solis. "The rules issued today protect individuals against the unwarranted use of information related to their personal health because no one should have to fear that disclosure of their medical data will put their job or health coverage at risk."
Additionally, HHS, through its Office for Civil Rights (OCR), issued a notice of proposed rulemaking with a 60-day comment period, to propose changes to the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule to prohibit health plans from using or disclosing genetic information for underwriting purposes.
The proposed rule published today modifies the HIPAA Privacy Rule pursuant to GINA Title I to clarify that genetic information is health information and to prohibit the use and disclosure of genetic information by covered health plans for eligibility determinations, premium computations, applications of any pre-existing condition exclusions, and any other activities related to the creation, renewal, or replacement of a contract of health insurance or health benefits. In combination with the new penalties for violations of the HIPAA Privacy Rule, as provided for by the American Recovery and Reinvestment Act of 2009, a use or disclosure of genetic information in violation of the HIPAA Privacy Rule could result in a fine of $100 to $50,000 or more for each violation.
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Posted by
Georgia Front Page.com
at
6:27 PM
0
comments
Labels: atlanta, coverage, discrimination, fayette front page, genetic, georgia, georgia front page, insurance, protection, regulation, research, rules, testing
Thursday, August 20, 2009
HHS Issues Rule Requiring Individuals Be Notified of Breaches of Their Health Information
New regulations requiring health care providers, health plans, and other entities covered by the Health Insurance Portability and Accountability Act (HIPAA) to notify individuals when their health information is breached were issued today by the U.S. Department of Health and Human
Services (HHS).
These "breach notification" regulations implement provisions of the Health Information Technology for Economic and Clinical Health (HITECH) Act, passed as part of American Recovery and Reinvestment Act of 2009 (ARRA).
The regulations, developed by the HHS Office for Civil Rights (OCR), require health care providers and other HIPAA covered entities to promptly notify affected individuals of a breach, as well as the HHS Secretary and the media in cases where a breach affects more than 500
individuals. Breaches affecting fewer than 500 individuals will be reported to the HHS Secretary on an annual basis. The regulations also require business associates of covered entities to notify the covered entity of breaches at or by the business associate.
"This new federal law ensures that covered entities and business associates are accountable to the Department and to individuals for proper safeguarding of the private information entrusted to their care. These protections will be a cornerstone of maintaining consumer trust as we move forward with meaningful use of electronic health records and electronic exchange of health information," said Robinsue Frohboese, acting director and principal deputy director of OCR.
The regulations were developed after considering public comment received in response to an April 2009 request for information and after close consultation with the Federal Trade Commission (FTC), which has issued companion breach notification regulations that apply to vendors of personal health records and certain others not covered by HIPAA.
To determine when information is "unsecured" and notification is required by the HHS and FTC rules, HHS is also issuing in the same document as the regulations an update to its guidance specifying encryption and destruction as the technologies and methodologies that render protected health information unusable, unreadable, or indecipherable to unauthorized individuals. Entities subject to the HHS and FTC regulations that secure health information as specified by the guidance through encryption or destruction are relieved from having to notify in the event of a breach of such information. This guidance will be updated annually.
The HHS interim final regulations are effective 30 days after publication in the Federal Register and include a 60-day public comment period. For more information, visit the HHS Office for Civil Rights web site at http://www.hhs.gov/ocr/privacy/.
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Posted by
Georgia Front Page.com
at
7:00 AM
0
comments
Labels: atlanta, breach, business, electronic health records, fayette front page, federal law, georgia, georgia front page, health information, HIPAA, notification, privacy, protection, regulations
