HHS Addresses Privacy, Security Concerns in EHR Program
HIPAA privacy and security concerns with the government's EHR certification program are so great that hundreds of practitioners have called for the program's cancellation, the Department of Health & Human Services (HHS) announced in its final rule on meaningful use released Tuesday.
It hasn't happened, of course.
The final rule, issued through the Centers for Medicare & Medicaid Services (CMS), defines "meaningful use" for the first two years (2011 and 2012) of a long-term financial incentive plan through Medicare and Medicaid under the Health Information for Economic and Clinical Health (HITECH) Act, signed into law by President Barack Obama February 17, 2009.
HHS released a second final rule the same day, through the Office of the National Coordinator for Health Information Technology (ONC). It establishes an initial set of standards, implementation specifications, and certification for EHR technology for vendor products.
Through its technology standards final rule, HHS addresses privacy and security concerns by requiring organizations to perform risk analyses and correct security deficiencies and by requiring the EHR technology to include among other security functions:
- Encryption capabilities
- Auditing capabilities including read-only access to patient records
- Automatic log-off capabilities
- File and message integrity checking
- 'Mega Boards' Could be Rural Healthcare Disruptor
- 1 in 5 Eligible Hospitals Penalized for HACs
- HL20: Rebecca Katz—Cooking Up Sustainable Nourishment
- Meaningful Use Payment Adjustments Begin
- HL20: Peter Semczuk, DDS, MPH—Taking on the Big Challenges
- PA hospital to pay $662,000 to settle Medicare fraud case
- Supreme Court to hear Obamacare subsidy challenge in March
- Dr. Oz gets fact-checked and the results aren't pretty
- How the high cost of medical care is affecting Americans
- Why single payer died in VT