State AGs Stepping Up HITECH Enforcement
Griffin began the investigation when patients contacted Griffin about "unsolicited contact by the physician who offered to perform professional services at another area hospital despite the patients' interest in having those services provided at Griffin Hospital."
Griffin said it has complied with HITECH breach notification requirements by:
- Notifying the HHS secretary
- Notifying patients who have had their PHI accessed in the breach
- Disclosing the information to the local media
- Posting information about the breach on Griffin's Web site
Griffin officials have also notified Blumenthal's office about the breach, changed all of the passwords for PACS users whose passwords were used without authorization, and advised all users of the need for strict password confidentiality.
Frank Ruelas, director of compliance and risk management at Maryvale Hospital and principal of HIPAA Boot Camp in Casa Grande, AZ, says bringing state AGs into the HITECH enforcement mix raises the possibility of discovered breaches to a "new level."
"I certainly can see attorney generals becoming motivated first responders to discovered breaches when compared to actions that may be taken by a federal entity. Bottom line, enforcement, or at least the threat of enforcement, is moving closer and closer to home with respect to the location of the involved covered entity," he says.
Dom Nicastro is a contributing writer. He edits the Medical Records Briefings newsletter and manages the HIPAA Update Blog.
- EHR Systems 'Immature, Costly,' AMA Says
- Anthem Blue Cross, 7 CA Health Systems Create New Challenger, Business Model
- Interstate Medical Licensure Effort Advances
- Better HCAHPS Scores Protect Revenue
- Data Points to Boom in Private HIX
- How to Build a Health Plan from Scratch
- CEO Exchange: Preparing for Population Health
- Narrow Networks Cut Costs, Not Quality, Economists Say
- Few Winners Among MSSP Participants
- Insurers see cost hikes in Partners HealthCare (MA) mergers