HIPAA's Harm Threshold is a Huge Weakness
A lawyer and panelist at last week's 17th annual national HIPAA Summit called HHS' new "harm threshold" in its interim final rule on breach notification a "huge weakness."
Gerry Hinkley, Esq., partner and chair of HIT practice group for Davis Wright Tremaine in San Francisco, presented a talk on breach notification and the new components of HIPAA in the HITECH Act on Day 3 of the conference at the Wardman Park Hotel in Washington, DC, Friday.
Perhaps his most telling comment came about the new "harm threshold" in the HHS interim final rule on breach notification.
Hinkley called it a "huge weakness." If he's a patient, Hinkley said he wants to be the one determining whether information that was disclosed inappropriately could cause significant harm–and not the covered entity.
HHS says in the interim final rule that many commenters on the draft guidance in April suggested HHS add a "harm threshold such that an unauthorized use or disclosure of [PHI] is considered a breach only if the use or disclosure poses some harm to the individual."
HHS agreed. Hinkley necessarily does not.
HealthLeaders Media asked Hinkley at the Summit Friday if he sees instances where HHS will overrule a covered entity's determination of significant harm to a patient.
"You always have that risk because if your determination is not reasonable, you've got a HIPAA violation," Hinkley said. "You're going to be second-guessed so you want to be balanced and conservative in making that determination."
According to the interim final rule, covered entities and their BAs will perform a risk assessment to determine if there is significant risk of harm to the individual whose PHI was inappropriately dispensed into the wrong hands.
- Antibiotic Overuse a 'Huge Threat' to Patient Safety, Says CDC
- CFO Exchange: Smartphones Poised to Disrupt Healthcare, Says Topol
- Consumerism Drives Healthcare Branding, Rebranding Efforts
- 3 Traits Personality Assessments Can't Reveal
- PA Ranks See 'Phenomenal Growth,' Lack of Diversity
- CHS Hacked, 4.5M Patient Records Compromised
- CFO Exchange: Healthcare Leaders Share 5 Innovative Ideas
- Business Roundup: M&A Activity Down Slightly in First Half of 2014
- Large Employers Trimming Healthcare Spending
- Carondelet to Pay $35M to Settle Fraud Allegations