CT Breach Notification Case Proves HITECH's Worth
Dawn McDaniel, a spokesperson for the Connecticut Insurance Department, told HealthLeaders Media in an e-mail that the bulletin is in response to "some recent data breaches, which were not reported in what we believe to be a timely manner."
Though neither OCR nor Connecticut officials would say that the breach notification change in Connecticut is a direct effect of HITECH, OCR did praise Blumenthal's actions. In an e-mail to HealthLeaders Media, an OCR spokesperson called it an illustration of the strong partnership between federal and state regulators envisioned in the HITECH act.
"The Office for Civil Rights at HHS views the actions of the Connecticut state attorney general in the Health Net matter as demonstrating the effective federal-state partnership to HIPAA compliance as envisioned by the HITECH Act," he wrote. "These actions can provide greater protections for the residents of Connecticut, and serve to stimulate a more robust culture of compliance among organizations responsible for protected health information."
The spokesman called the actual breach notification changes in Connecticut a matter "within state jurisdiction and— independent of new HITECH authorities and HIPAA requirements."
Technically, yes. But it's hard to argue that the changes are not at least a residual effect of a HITECH-granted power.
Dom Nicastro is a contributing writer. He edits the Medical Records Briefings newsletter and manages the HIPAA Update Blog.
- CEO Exchange: Preparing for Population Health
- Advocate, NorthShore Deal Would Create 16-Hospital System
- Better HCAHPS Scores Protect Revenue
- 3 Strategies for Retaining Millennial Employees
- Narrow Networks Cut Costs, Not Quality, Economists Say
- Power of price: In South FL and the nation, healthcare costs often are shrouded in secrecy
- Hospital mergers may lead to higher prices
- Healthcare data of 1 million NJ patients compromised since 2009
- CEO Exchange: Pressure is On to Partner, Drive Quality