CT Breach Notification Case Proves HITECH's Worth
Dawn McDaniel, a spokesperson for the Connecticut Insurance Department, told HealthLeaders Media in an e-mail that the bulletin is in response to "some recent data breaches, which were not reported in what we believe to be a timely manner."
Though neither OCR nor Connecticut officials would say that the breach notification change in Connecticut is a direct effect of HITECH, OCR did praise Blumenthal's actions. In an e-mail to HealthLeaders Media, an OCR spokesperson called it an illustration of the strong partnership between federal and state regulators envisioned in the HITECH act.
"The Office for Civil Rights at HHS views the actions of the Connecticut state attorney general in the Health Net matter as demonstrating the effective federal-state partnership to HIPAA compliance as envisioned by the HITECH Act," he wrote. "These actions can provide greater protections for the residents of Connecticut, and serve to stimulate a more robust culture of compliance among organizations responsible for protected health information."
The spokesman called the actual breach notification changes in Connecticut a matter "within state jurisdiction and— independent of new HITECH authorities and HIPAA requirements."
Technically, yes. But it's hard to argue that the changes are not at least a residual effect of a HITECH-granted power.
Dom Nicastro is a contributing writer. He edits the Medical Records Briefings newsletter and manages the HIPAA Update Blog.
- Sharp HealthCare Leaves Pioneer ACO Program
- Acute Kidney Injury Gets New Focus
- CNO Leads $1M Charge for New Scrubs, Uniforms
- Interventional Radiology No Longer a Sub-Specialty
- NFP Hospitals' Revenue Growth at 'All-Time Low'
- Half of All Primary Care, Internal Medicine Jobs Unfilled in 2013
- MA an Insurance Proving Ground for Providers
- Targeting Self-Insured Populations
- mHealth Tackles Readmissions
- States Without Medicaid Expansion Search for Alternatives