Sebelius Shifts HIPAA Security Rule Enforcement to Civil Rights Office
The secretary of HHS shifted enforcement of the HIPAA Security Rule from CMS to the Office for Civil Rights (OCR), according to an HHS announcement published Tuesday in the Federal Register.
Until now, OCR has enforced only the HIPAA Privacy Rule, which protects the privacy of patients' health information and the confidentiality provisions of the Patient Safety Rule, which protect PHI from being used to analyze patient safety events and improve patient safety.
The security rule–published in the Federal Register on February 20, 2003–specifies a series of administrative, technical, and physical security procedures for covered entities to assure the confidentiality of electronic protected health information (i.e., encryption standards).
"I think it's smart for HHS to merge the enforcement responsibilities," says Jeff Drummond, health law partner in the Dallas office of Jackson Walker LLP. "But I don't think this signals a watershed shift in enforcement strategy."
The announcement by HHS Secretary Kathleen Sebelius comes as Congress this year helped move a bill through that supports stronger enforcement of HIPAA laws and greater compliance duties from entities who handle PHI.
- Half of All Primary Care, Internal Medicine Jobs Unfilled in 2013
- How Digital Strategy Shapes Patient Engagement at Boston Children's Hospital
- CFO Exchange: Smartphones Poised to Disrupt Healthcare, Says Topol
- CNO on Hospital Redesign: 'You Can't Over-Communicate'
- Carondelet to Pay $35M to Settle Fraud Allegations
- Some Cancer Hospitals' Quality Data Will Soon Be Public
- PA Ranks See 'Phenomenal Growth,' Lack of Diversity
- Consumerism Drives Healthcare Branding, Rebranding Efforts
- CA Powers Up $80M HIE to 'Create Value in the Data'
- 3 Traits Personality Assessments Can't Reveal