With No Harm Threshold, Nearly All Breaches Substantiated in CA

Dom Nicastro, for HealthLeaders Media , August 26, 2010

California, the state that signed a precedent-setting privacy law, fields more than 220 notifications of potential breaches from licensed facilities per month, according to numbers released by the state's Department of Public Health.

From January 1, 2009, when law AB 211 went into effect, through May 31, 2010, entities have reported a total of 3,766 breaches. The law calls for health providers to prevent unlawful access, use, or disclosure of patients' medical information and to report violations to DPH and the individuals affected.

The California Department of Public Health (CDPH), which enforces the law, receives notification of a little more than seven breaches a day. While California law calls for licensed entities to report any and all potential breaches, federal regulation currently allows providers a backdoor out.

In the HITECH interim final rule on breach notification, providers through the "harm threshold" provision may conduct a risk assessment to see if the potential breach causes a significant risk of financial, reputational or other harm to the patient.

If it doesn't, no notification is required.

Congress did not write this into the HITECH Act. But the Office for Civil Rights (OCR), which on the federal level enforces the HIPAA privacy and security rules, included it through regulation.

1 | 2 | 3 | 4

Comments are moderated. Please be patient.


MOST POPULAR

SPONSORED REPORTS
SPONSORED HEADLINES

SIGN UP

FREE e-Newsletters Join the Council Subscribe to HL magazine

SPONSORSHIP & ADVERTISING

100 Winners Circle Suite 300
Brentwood, TN 37027

800-727-5257

About | Advertise | Terms of Use | Privacy Policy | Reprints/Permissions | Contact
© HealthLeaders Media 2014 a division of BLR All rights reserved.