Category: HHS

  • HIPAA: Then & Now

    A story about HIPAA that starts with once upon a time, in the late 1990s, the U.S. healthcare system was in dire need of a change. The Health Insurance Portability and Accountability Act of 1996 (HIPAA) was created to address this need. The act aimed to improve the portability and accountability of health insurance coverage, guarantee coverage for employees with pre-existing conditions, and prevent โ€œjob lockโ€ โ€“ a scenario in which plan members stayed in a job to avoid losing health benefits.

    HIPAA introduced several measures to ensure the continuity of coverage between jobs, including the creation of national standards to protect sensitive patient health information from being disclosed without the patientโ€™s consent or knowledge. The U.S. Department of Health and Human Services (HHS) issued the HIPAA Privacy Rule to implement the requirements of HIPAA. The Privacy Rule standards address the use and disclosure of individualsโ€™ health information (known as protected health information or PHI) by entities subject to the Privacy Rule. These individuals and organizations are called โ€œcovered entitiesโ€. The Privacy Rule also contains standards for individualsโ€™ rights to understand and control how their health information is used.

    The story of HIPAA is not just about the creation of a law, but also about the implementation and enforcement of that law. The HIPAA Security Rule protects a subset of information covered by the Privacy Rule. The Security Rule requires appropriate administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and security of electronic protected health information.

    The implementation of HIPAA has not been without its challenges. There have been concerns about the cost of implementing the Privacy and Security Rules, as well as understanding what is reasonable and appropriate for an organization, based on size. However, the benefits of HIPAA are clear. The act has helped to ensure that patientsโ€™ health information is protected, and that they have greater control over how their information is used. The act also required that Covered Entities and Business Associates must do to protect that information and comply with the HIPAA Security Standards and Implementation Specifications.

    In 2009, the enforcement authority was delegated to the HHS Office for Civil Rights (OCR) by then U.S. Secretary of Health and Human Services, Kathleen Sebelius. Since then, OCR has settled or imposed a civil money penalty in 137 cases resulting in a total dollar amount of almost $137 million. OCR continues to investigate privacy and security complaints against numerous organizations and businesses, regardless of size.

    But legislative changes are needed, especially with the advancements in health technology applications and data analytics. The regulations have not kept pace with technical safeguard requirements. From a compliance standpoint, there are times when it feels like you are trying to stick a round peg into a square hole. It takes experienced compliance officers, HIPAA consultants, and lawyers to understand what the regulations call for, now almost 30 years since HIPAA was enacted. At some point, Congress will need to tackle the issue of updating the HIPAA regulations. For now, keep those round pegs available.

  • Coronavirus and HIPAA – An Announcement from HHS

    In light of the recent Novel Coronavirus outbreak, the U.S. Department of Health and Human Services (HHS) has issued a reminder for HIPAA adherence pertaining to the ways that patient information can be shared during outbreaks of infectious disease and other emergency situations such as this one.

    According to the Office for Civil Rights, HIPAA covered entities may disclose, without patient authorization, protected health information (PHI) about the patient as necessary to perform treatment. How far does this leeway extend and how will privacy be protected during outbreaks? Letโ€™s take a closer look.

    HIPAA applies only to covered entities and business associates

    According to HHS, by law the HIPAA Privacy Rule applies only to covered entities โ€“ โ€œhealth plans, health care clearinghouses, and certain health care providers.โ€ At least this much has not changed. Normally, individuals, organizations and agencies that meet the definition of a covered entity under HIPAA would have to comply with the requirements to protect the privacy and security of health information and must provide individuals with certain rights with respect to their health information.

    However, โ€œtreatmentโ€ in these cases can include the coordination or management of healthcare and related services by one or more providers, which could also include consultations between providers as well as the referral of patients.

    Employees may not access or disclose patient records for an unauthorized purpose

    This much has not changed either. Under HIPAA, employees may only access or disclose patient records when specifically authorized to do so as part of their job, or when required to do so under law. Employees are not allowed to look up a patientโ€™s medical record to see if it mentions anything about coronavirus, no matter how strong that temptation may be.

    Information CAN be shared with friends and family of the coronavirus patient

    Family members, friends, and any individual involved in the care of the patient can be notified about the patientโ€™s condition so long as verbal permission has been obtained, or that it can be reasonably inferred that the patient does not object. If a patient is incapacitated, then professional judgement should be used as to whether the sharing of information is in the patientโ€™s best interest.

    Patient data may be shared to protect public health

    Providing specific information about an identifiable patient to the media or public at large is not permitted. However, if there is serious or imminent threat to the health and safety of another person or to the public, necessary information may be shared in order to protect those who would be affected. It should be noted that even this must be restricted. In general, the information thatโ€™s shared should be as minimal as possible.

    When outbreaks like these occur, itโ€™s easy for the public to begin to panic. From there itโ€™s a slippery slope, as rules and regulations can become blurred amidst the chaos. Thatโ€™s why when incidents like these do happen, itโ€™s more important than ever to have a clear set of guidelines to follow. And itโ€™s even more important to make sure youโ€™re following them correctly. Do not allow public panic to sway you from civic responsibility and the law.

    Take Action Now

    For more information on determining when and how information should be disclosed in the event of an emergency such as coronavirus and other similar outbreaks, HHS has published an Emergency Preparedness Decision Tool which can be found here.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • Important Notice Regarding Individualsโ€™ Right of Access to Health

    On January 28, the HHS Office for Civil Rights issued an important notice regarding an individualsโ€™ right of access to health records and more specifically, when a request is made to transmit medical records to a third party.

    Here is the full transcript of the notice:

    On January 25, 2013, HHS published a final rule entitled โ€œModifications to the HIPAA Privacy, Security, and Enforcement Rules Under the Health Information Technology for Economic and Clinical Health Act, and the Genetic Information Nondiscrimination Act; Other Modifications to the HIPAA Rules.โ€ (2013 Omnibus Rule). A portion of that rule was challenged in federal court, specifically provisions within 45 C.F.R. ยง164.524, that cover an individualโ€™s access to protected health information. On January 23, 2020, a federal court vacated the โ€œthird-party directiveโ€ within the individual right of access โ€œinsofar as it expands the HITECH Actโ€™s third-party directive beyond requests for a copy of an electronic health record with respect to [protected health information] of an individual . . . in an electronic format.โ€ Additionally, the fee limitation set forth at 45 C.F.R. ยง 164.524(c)(4) will apply only to an individualโ€™s request for access to their own records, and does not apply to an individualโ€™s request to transmit records to a third party.

    The right of individuals to access their own records and the fee limitations that apply when exercising this right are undisturbed and remain in effect. OCR will continue to enforce the right of access provisions in 45 C.F.R. ยง 164.524 that are not restricted by the court order. A copy of the court order in Ciox Health, LLC v. Azar, et al., No. 18-cv-0040 (D.D.C. January 23, 2020), may be found at https://ecf.dcd.uscourts.gov/cgi-bin/show_public_doc?2018cv0040-51.

    What Healthcare Providers Should Know

    The HIPAA Privacy Rule permits a covered entity to impose a reasonable, cost-based fee to provide the individual (or the individualโ€™s personal representative) with a copy of the individualโ€™s PHI, or to direct the copy to a designated third party. The fee may include only the cost of certain labor, supplies, and postage:

    1. Labor for copying the PHI requested by the individual, whether in paper or electronic form.ย  Labor for copyingย includes onlyย labor for creating and delivering the electronic or paper copy in the form and format requested or agreed upon by the individual, once the PHI that is responsive to the request has been identified, retrieved or collected, compiled and/or collated, and is ready to be copied.ย  Labor for copyingย does not includeย costs associated with reviewing the request for access; or searching for and retrieving the PHI, which includes locating and reviewing the PHI in the medical or other record, and segregating or otherwise preparing the PHI that is responsive to the request for copying.
    2. Supplies for creating the paper copy (e.g.,ย  paper, toner) or electronic media (e.g., CD or USB drive)ย ifย theย  individual requests that the electronic copy be provided on portable media.ย  However, a covered entity mayย notย require anย  individual to purchase portable media; individuals have the right to have theirย  PHI e-mailed or mailed to them upon request.
    3. Labor to prepare an explanation or summary of the PHI, if the individualย in advanceย both chooses to receive an explanation or summaryย andย agrees to the fee that may be charged.
    4. Postage, when the individual requests that the copy, or the summary or explanation, be mailed.

    Thus, costs associated with updates to or maintenance of systems and data, capital for data storage and maintenance, labor associated with ensuring compliance with HIPAA (and other applicable law) in fulfilling the access request (e.g., verification, ensuring only information about the correct individual is included, etc.) and other costs not included above,ย even if authorized by State law, areย not permitted for purposes of calculating the fees that can be charged to individuals.ย  See 45 CFR 164.524(c)(4).

    Further, while the Privacy Rule permits the limited fee described above, covered entities should provide individuals who request access to their information with copies of their PHI free of charge.ย  While covered entities should forgo fees for all individuals, not charging fees for access is particularly vital in cases where the financial situation of an individual requesting access would make it difficult or impossible for the individual to afford the fee.ย  Providing individuals with access to their health information is a necessary component of delivering and paying for health care. We will continue to monitor whether the fees that are being charged to individuals are creating barriers to this access, will take enforcement action where necessary, and will reassess as necessary the provisions in the Privacy Rule that permit these fees to be charged.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • Office for Civil Rights (OCR) – Two Significant Announcements

    The U.S. Department of Health and Human Services, Office for Civil Rights (OCR) had two significant announcements this past week resulting in total of $4.6 million for a settlement and imposed penalty.ย  The two cases, one involving a public agency, the Texas Health and Human Services Commission (TX HHSC) and the second, a university medical center, the University of Rochester Medical Center (URMC).

    Both cases demonstrate OCR is continuing on an aggressive path to address reported breaches and investigate how organizations are just not being proactive with HIPAA compliance requirements.These investigations uncovered a slew of problems, especially in the Texas case.ย  What was troubling about this case, is the TX HHSC had such poor audit controls, it could not determine the number of persons who inappropriately accessed the protected health information in question.

    In the URMC case, it determined โ€œidentification of a lack of encryption as a high risk to ePHI, URMC [still] permitted the continued use of unencrypted mobile devices.โ€ย  This is a clear case of somebody dropping the ball due to reasons one can only speculate about.ย 

    If OCRโ€™s track record is similar to recent years, expect more settlement announcements to be made before the end of the year.ย  With the holidays quickly approaching, OCR may not be spreading good cheer for some.

    Read the TX HHSC Press Release

    Read the URMC Press Release