by Jay Hodes – President, Colington Consulting
In March and April of this year, the HHS Office for Civil Rights (OCR) announced its enforcement discretion when it came to some provisions within the HIPAA Security and Privacy Rules due to COVID-19. These notices were limited and narrow in scope. The March notice stated OCR would “not impose penalties for noncompliance with the regulatory requirements under the HIPAA Rules against covered health care providers in connection with the good faith provision of telehealth during the COVID-19 nationwide public health emergency.” The April notice specified OCR “will not impose penalties for violations of certain provisions of the HIPAA Privacy Rule against health care providers or their business associates for the good faith uses and disclosures of protected health information (PHI) by business associates for public health and health oversight activities during the COVID-19 nationwide public health emergency.”
It is my belief some in the healthcare sector, especially in the small to mid-size provider community, interpreted these notices to mean OCR was not going to enforce any of the HIPAA rules. That misunderstanding of enforcement discretion was enough for some organizations to put their HIPAA compliance programs on the back burner. The operational mindset, then and in some cases now, was there was not a need to perform required Security Risk Assessments, review or create HIPAA policies and procedures, or adhere to many of the obligations in the HIPAA Privacy Rule.
Let me be clear; the rules are still the rules. Healthcare organizations and business associates must still comply with the HIPAA requirements. As the notices indicate, there still must be adherence to the good faith provision. That means regardless of any enforcement discretion, organizations must still be able to demonstrate compliance with the rules and show the effort to do so.
As proof enforcement actions continue, this week OCR announced five settlements for violations under the HIPAA Privacy Rule that pertain to individuals’ rights to access their medical records. Although not earth-shattering monetary settlement amounts that ranged from $3,500 to $70,000, these cases serve as another wake-up call to providers. There is just as much culpability under the Privacy Rule as the Security Rule.
The two types of infractions in these recent cases involve (1) refusals by healthcare providers to give patients access and copies of their medical records and (2) when requests for medical records were made by personal representatives seeking access to those records for family members were denied.
The OCR listserv email regarding these cases states “OCR’s enforcement actions are designed to send a message to the health care industry about the importance and necessity of compliance with the HIPAA Rules.” Message sending indeed as OCR’s right of access initiative continues. OCR Director Roger Severino stated in the email “Today’s announcement is about empowering patients and holding health care providers accountable for failing to take their HIPAA obligations seriously enough.”
Has your organization ever conducted a Privacy Assessment to see if requirements of the HIPAA Privacy Rule are being met and understood? This type of assessment is part of our overall assessment process for both Covered Entities and Business Associates.
At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.