No Final Guidance on Unsecure PHI—Yet
HHS failed to meet its August 18 HITECH Act deadline for final guidance on unsecure PHI.
Talk about "unsecure PHI" talk comes down to this—if patient information escapes your backdoor, is it protected by these standards? If it is, then you've got a "safe harbor" for avoiding breach notification.
If it isn't, then you're talking breach notification—to the individual, HHS, and possibly local media (the latter if it involves at least 500 patient records).
John C. Parmigiani, president of John C. Parmigiani & Associates, LLC, in Ellicott, MD, says encryption of patient records today is a necessity rather than an "add-on." He adds that patients now have a "growing concern" for the appropriate safeguarding of their personal and medical information and are calling for organizations to mitigate data leakages and losses.
"The need to encrypt and the provision to notify have become standard ingredients of the many state data protection laws," Parmigiani says. "They have been reinforced by not only the recent CMS report of its findings from the 'Security Rule compliance reviews' but also in the original HITECH wording and the subsequent HHS guidance in April."
- New G-Codes to Pay Doctors for Broad Array of Non-Face-to-Face Care
- CMS Sets 2014 Pay Rates for Hospital Outpatient and Physician Services
- Telehealth Improves Patient Care in ICUs
- Hospital M&A Volume Up, Value Down in 3Q
- Douglas Hawthorne—A Chance to Do Something Big
- 50 Years of Fighting Pressure Ulcers Called Into Question
- States Rejecting Medicaid Expansion Forgo Billions in Federal Funds
- Why You Should Involve Patients in Nursing Handoffs
- Small Doesn't Mean Doomed
- The 5 Biggest Healthcare Finance Trouble Spots