Flurry of HIPAA Activity Expected Over Next Three Months
As for enforcement, Congress promised in ARRA "periodic audits" to ensure HIPAA compliance. Government officials told HealthLeaders Media in September they weren't sure what that meant, and Apgar says OCR still does not have a definitive plan. Likely, they will not publish a plan until second quarter 2010.
"If you've got a headline [because of a major breach], they're likely going to come and investigate you," Apgar says. "But they're wavering on how they will conduct compliance audits. Not because they're not going to do it, but because they don't know when yet. The House version of the healthcare reform bill calls for more strict enforcement than ARRA, so they want to wait to see what comes out in healthcare reform."
Apgar adds the government can fine up to $50,000 for one HIPAA violation and a maximum of $1.5 million for the same type of violation per calendar year—regardless of the severity of the breach.
Dom Nicastro is a senior managing editor at HCPro, Inc. in Danvers, MA. He edits the Briefings on HIPAA newsletter and manages the HIPAA Update Blog. E-mail him at dnicastro@hcpro.com.

- CMS Reveals Central Line Infection Rates, Finally
- Keeping Readmission Rates Low with Treatment Guidelines
- 5010 Logjam Means No Pay for Physicians
- Medicare Physician Payment Rule Factors in GPCI
- Leading Change is Tough from the Back of a Limo
- Feds Release Final Rules on Health Plan Language
- Getting to the Heart of Cardiology Alignment
- Engineering a High-Performance Emergency Department
- UnitedHealth will tie doctors' payments to quality of care
- Parkland Keeping Consultant's Analysis Under Wraps

