What happens after a data breach?
The federal healthcare breach notification rule requires HIPAA covered entities-comprising providers, insurers and vendors who must comply with HIPAA transaction sets-to report breaches of protected health information affecting 500 or more individuals to the Department of Health and Human Services' Office for Civil Rights. OCR posts the breaches to a public Web site. And there have been a lot of postings: by mid-June, 288 listings had filled what is called the "Wall of Shame" in just an 18-month period. Health Data Management contacted numerous organizations that had suffered a data breach, hoping to find one that would share its experiences about dealing with and recovering from a major breach. Only one responded, and that was to say it declined to comment. Susan McAndrew, deputy director for health information privacy at OCR, believes the reluctance is a missed opportunity.
- How Top-Ranked MA Plans Earn Their Stars
- Readmissions: No Quick Fix to Costly Hospital Challenge
- How Hospitals Can Become 'Upstreamists'
- 4 Ways to Lower the Cost to Collect from Self-Pay Patients
- WellPoint Dominates Nearly Half of Markets, AMA Says
- 4 Tips for Managing Employed Physicians
- CMS Offers Some ACOs $114M for 'Upfront' Costs
- House Calls Key to Pioneer ACO Success
- Ebola: Second TX Nurse Diagnosed After Improper Protective Gear Application
- How Telehealth Pays Off for Providers, Patients