Flurry of HIPAA Activity Expected Over Next Three Months
As for enforcement, Congress promised in ARRA "periodic audits" to ensure HIPAA compliance. Government officials told HealthLeaders Media in September they weren't sure what that meant, and Apgar says OCR still does not have a definitive plan. Likely, they will not publish a plan until second quarter 2010.
"If you've got a headline [because of a major breach], they're likely going to come and investigate you," Apgar says. "But they're wavering on how they will conduct compliance audits. Not because they're not going to do it, but because they don't know when yet. The House version of the healthcare reform bill calls for more strict enforcement than ARRA, so they want to wait to see what comes out in healthcare reform."
Apgar adds the government can fine up to $50,000 for one HIPAA violation and a maximum of $1.5 million for the same type of violation per calendar year—regardless of the severity of the breach.
Dom Nicastro is a senior managing editor at HCPro, Inc. in Danvers, MA. He edits the Briefings on HIPAA newsletter and manages the HIPAA Update Blog. E-mail him at dnicastro@hcpro.com.

- Healthcare Continues Strong Job Growth
- Essential Health Benefits Bulletin Draws Fire
- 5010 Deadline Extended, But Threat Remains, Says AMA
- 2 Tactics for ICD-10 & VBP Clinical Documentation
- Keeping Readmission Rates Low with Treatment Guidelines
- What If Your Car Cared About Your Health?
- Engineering a High-Performance Emergency Department
- Top 10 Healthcare Quality Issues for 2011
- Hospital HCAHPS Scores Beat Expectations
- Don't Give Up on Dead Claims

