Data encryption for HIE sounds obvious; not so simple to implement

One of the early themes that has emerged from the initial discussions of the Office of the National Coordinator’s privacy and security tiger team is the need for stronger protection of the confidentiality and privacy of…

Building patient trust in EHRs can’t be about security controls

The emphasis on security and privacy in electronic health record (EHR) systems as a prerequisite for building consumer trust in these systems both overstates the extent to which security controls can in fact provide trust, and…

Contrasting trust models under development for NHIN and NHIN Direct

The Nationwide Health Information Network (NHIN), a government-sponsored initiative started in 2004 and re-emphasized in the Health Information Technology for Clinical and Economic Health (HITECH) Act, is no longer envisioned as a “network” at all (in…

HITECH restrictions on sale of health record data constrain some EHR plans

As the provisions of the Health Information Technology for Economic and Clinical Health (HITECH) Act continue to be implemented, many health care organizations are beginning to understand that changes to security and privacy requirements originally promulgated…

State laws complicate navigation of health data disclosure rules

As noted this week in a blog posting from Hunton & Williams, a ruling issued in February from a federal district court in Ohio highlights some of the legal complexities in navigating both state and federal…

Thoughts about EHRs and accounting of disclosures

One of the provisions of the Health Information Technology for Economic and Clinical Health (HITECH) Act portion of the Recovery Act changed the requirements for HIPAA-covered entities to maintain an accounting of disclosures of health information….

Health IT advisory committees covering same ground, sometimes without coordination

Both of the two federal health IT advisory committees working in support of the Office of the National Coordinator (ONC) have taken up discussion on patient privacy and consent management, working through the respective privacy and…