AHIMA: Proposed HIPAA Access Requirement a 'Significant Burden'
Because many entities do not have the ability to meet the technical requirements, OCR should delay its proposed compliance dates, AHIMA says. Currently compliance with the access reports provision is January 1, 2013, for electronic DRS systems acquired after January 1, 2009, and beginning January 1, 2014, for electronic DRS systems acquired prior to 2009.
Further, access reports should carry only identifiers for the work force members rather than actual names, AHIMA says. Patients asking who viewed their medical records often have a specific individual in mind, such as a former spouse, AHIMA says.
HIM professionals have reported to AHIMA several situations where employees have been stalked after their names are released to patients.
"While we fully support the requirement allowing an individual to have knowledge of access, we also want to protect the workplace staff of the covered entity," AHIMA states in its comments. "AHIMA supports narrowing the requests to specific individuals when possible. In some treatment environments (e.g., emergency departments and psychiatric facilities), providers are permitted to use pseudonyms to avoid patients stalking or contacting them outside the workplace. Access accounting would require facilities to share the legal names of their providers which defeat the protections that have been in place for long periods of time."
- Patient Harm Data to Remain on Medicare's Hospital Compare Site
- Quiet ORs Better for Patient Safety
- Tavenner Confirmed as CMS Administrator
- Leapfrog Hospital Safety Scores 'Depressing'
- CMS Seeks to 'Rapidly Reduce' Medicare Spending with $1B in Grants
- Building a Better Healthcare Board
- Hard-Nosed About Physician Teamwork
- Healthcare Leaders Sound Off on Organized Labor
- Case Study: Advance Care Conversations
- Esther Dyson's Population Health Dream