What happens after a data breach?
The federal healthcare breach notification rule requires HIPAA covered entities-comprising providers, insurers and vendors who must comply with HIPAA transaction sets-to report breaches of protected health information affecting 500 or more individuals to the Department of Health and Human Services' Office for Civil Rights. OCR posts the breaches to a public Web site. And there have been a lot of postings: by mid-June, 288 listings had filled what is called the "Wall of Shame" in just an 18-month period. Health Data Management contacted numerous organizations that had suffered a data breach, hoping to find one that would share its experiences about dealing with and recovering from a major breach. Only one responded, and that was to say it declined to comment. Susan McAndrew, deputy director for health information privacy at OCR, believes the reluctance is a missed opportunity.
- Senators Hear How Two-Midnight Rule Harms Patients, Hospitals
- 3 Management Lessons from a Supermarket Debacle
- Medicare Advantage Carriers See 'No Choice' But to Accept Cuts
- Physicians to Appeal 'Docs v. Glocks' Ruling in FL
- IOM Identifies GME Problems, Calls for Finance Changes
- Handshaking Spreads Germs. Get Over It.
- Healthcare Costs Start With What We Eat
- Revenue Cycles Get a Boost from Simple JPEG Files
- Hospitals Likely to Outsource ICD-10 at Launch
- Anatomy of 3 Health System Rebranding Efforts