Lawsuit for improper access to medical records faces many challenges

In a legal action noted by several privacy-minded observers, a woman in Cabell County, West Virginia filed suit in March against health care provider Marshall Health (the collective name for a group of clinical centers affiliated…

TRICARE data breach shows (again) why encryption of removable media is essential

The Department of Defense’s TRICARE program disclosed last week that backup tapes containing medical records on nearly 5 million active-duty and retired military personnel and their dependents were stolen from the car of a contractor who…

HIPAA “access report” potentially much simpler to implement, more valuable than accounting of disclosures

Among the provisions of the Health Information Technology for Economic and Clinical Health (HITECH) Act garnering significant attention are the changes to existing HIPAA requirements for covered entities to produce accounting of disclosures of protected health…

HHS releases new draft accounting of disclosure rules

The Department of Health and Human Services (HHS) has released a long-anticipated Notice of Proposed Rulemaking that would implement the changes to accounting of disclosures requirements under the HIPAA Privacy Rule. HHS opened a 60-day comment…

Healthcare entities leary of new government policy extending beyond HIPAA

As the Health IT Policy Committee’s Privacy and Security “Tiger Team” continues its work to provide recommendations and suggested policy guidance on health information exchange, there appears to be some concern among hospitals and other HIPAA-covered…

Trustworthy organizations do what they should even in the absence of legal enforcement

Joseph Conn of Modern Healthcare called attention in a blog post yesterday to the almost complete absence of civil penalties imposed against violators of the HIPAA Security and Privacy rules, pointing out that without some credible…

Significant work remains to produce standards and rules on accounting of disclosures for PHI

The Health Information Technology for Economic and Clinical Health (HITECH) Act passed as part of the Recovery Act in February 2009 included a variety of revisions included to requirements already in effect under the HIPAA Security…