RE: HIPAA Privacy Rule Accounting for Disclosures, RIN 0991-AB62

Size: px
Start display at page:

Download "RE: HIPAA Privacy Rule Accounting for Disclosures, RIN 0991-AB62"

Transcription

1 Submitted electronically at Ms. Susan McAndrew Deputy Director for Health Information Privacy Office for Civil Rights U.S. Department of Health and Human Services Hubert H. Humphrey Building 200 Independence Avenue, S.W. Washington, D.C RE: HIPAA Privacy Rule Accounting for Disclosures, RIN 0991-AB62 Dear Ms. McAndrew: The Association of American Medical Colleges (AAMC or the Association) is pleased to have this opportunity to comment on the Office for Civil Rights (OCR or the Agency) proposed rule, HIPAA Privacy Rule Accounting for Disclosures Under the Health Information Technology for Economic and Clinical Health Act, 76 Fed. Reg (May 31, 2011). The AAMC represents all 134 accredited U.S. medical schools; approximately 300 acute care hospitals and health systems; and nearly 90 academic and scientific societies. Through these institutions and organizations, the AAMC represents over 100,000 clinical faculty, 75,000 medical students, and 106,000 resident physicians. While the AAMC welcomes the proposed revisions to the accounting for disclosures requirements and generally supports them, the Association is very concerned about the proposed creation of the access report. The creation of a right to an access report will be extremely burdensome to providers in contravention both of Executive Order 13563, Improving Regulation and Regulatory Review, and Congressional intent as expressed throughout the Conference Report to the Health Information Technology for Economic and Clinical Health (HITECH) Act. While AAMC acknowledges the importance of allowing patients to obtain important, relevant information about the use of their medical information, OCR has failed to demonstrate that the access report will meet a need of patients or their representatives. Therefore, as discussed below, the AAMC requests that OCR withdraw all provisions related to the access report. If OCR determines that this necessitates major revisions related to the accounting for disclosures requirements, then the Agency should consider withdrawing the entire rule and developing a new notice of proposed rulemaking.

2 Page 2 ACCOUNTING FOR DISCLOSURES General Requirements The AAMC supports the more limited accounting for disclosures that OCR has proposed, and agrees with the Agency that most of these changes will provide information of value to individuals while placing a reasonable burden on covered entities and business associates. (76 Fed.Reg. at 31429) Nonetheless, the AAMC suggests the following revisions to the accounting for disclosures requirements: Right to an Accounting: Although OCR has proposed to limit the accounting provision to protected health information in a designated record set, the preamble states that this includes the medical and health care payment records maintained by or for a covered entity, and other records used by or for the covered entity to make decisions about individuals. This is far too broad a definition as it would include information in practice management and other systems that are not part of the electronic health record (EHR) and that are not designed to provide the type of information that is necessary for an accounting. The AAMC requests that OCR limit the accounting to information maintained in an electronic health record. Content of the Accounting: One of the data elements is a brief description of the type of protected health information disclosed. If this requirement is finalized, the AAMC asks that OCR provide simple and flexible guidance about what is meant by type of PHI. Provision of Accounting: The final rule should retain the current 60 day time period for covered entities to respond to a request for an accounting. Although the proposed rule allows for 30 days and a one-time 30 day extension, OCR has produced no evidence to suggest that 60 days is too long and notes that we understand that generating an accounting for disclosures is still a very manual process. (76 Fed. Reg. at 31435) In addition, providers currently are prepared to comply with a 60 day deadline. Therefore, the current response period should be retained. Compliance Enforcement Deadline: To provide adequate time for the development of EHR systems that can more easily produce the information necessary for an accounting of disclosures, the compliance enforcement deadline should be extended to Requirements Related to Research The AAMC strongly encourages OCR to finalize its proposal to wholly exempt covered entities from having to provide an accounting of disclosures for research conducted under (i), including through a protocol listing. The AAMC agrees with OCR s proposal that the accounting requirement does not need to be applied when an institutional review board (IRB) or privacy board has granted a waiver from the requirement for individual authorization. As the proposed rule accurately points out, such a waiver is granted only after an IRB or Privacy Board has made a determination that there is no more than a minimal risk to the individual s privacy, in addition to several other criteria designed to protect the research subjects. Such protections, in addition to the responsibilities of individual researchers to protect research

3 Page 3 subjects, render the application of the accounting requirement to this research both unnecessary and burdensome. The current Privacy Rule allows a covered entity to provide individuals with a protocol listing, a compilation of research protocol titles for which an individual s PHI may have been disclosed, rather than an individualized accounting, for those studies in which 50 or more subjects are involved. AAMC members report that the burden of compiling such a list is significant and is of little value to an individual, who would not be able to use this information to gain a clearer understanding of whether his or her PHI had been disclosed, and in what context. In addition, it is difficult for institutions to distinguish the protocols that may have disclosed PHI and thus triggered the accounting requirement from the total number of protocols that have been granted waiver of the requirement for individual authorization. An AAMC member reported that such waivers have been granted for approximately 10 percent of all active protocols. The member estimates that under the proposed accounting requirement, the number of protocols that might be included is over 100 protocols targeting enrollment of fewer than 50 subjects, and approximately 375 protocols with a targeted enrollment of over 50, a significant change from the current requirements. Most often PHI is accessed for the purpose of retrospective chart reviews or reviews of large databases, which include information on several thousand or more individuals. Whether PHI related to each of these protocols is used (and thus not subject to the accounting requirement) or disclosed (triggering inclusion in the protocol listing) is burdensome to determine and complicated to explain, resulting in a protocol listing that is likely to be of limited or no value to an individual. ACCESS REPORT The Requirement for a Right to an Access Report Should Be Withdrawn The AAMC strongly urges OCR to withdraw the requirement for the access report because the proposal: 1. Seems to ignore the directive in the HITECH Conference Report that... in developing regulations on the accounting of disclosures through an EHR, the Secretary would be required to take into account an individual s interest in learning when the PHI was disclosed and to whom, as well as the cost of accounting for such disclosures Appears to be based on the erroneous premise that the right to an access report will be a more automated process that provides valuable information to individuals with less burden to covered entities and business associates. (76 Fed.Reg. at 31429) 3. Underestimates the burden of creating access reports when OCR states that if few individuals request access reports, then covered entities will rarely need to undertake the burden of generating an access report. (76 Fed.Reg. at 31439) This fails to take into account that regardless of the number of requests, covered entities must have in place all the systems, policies, and staff that will be necessary if even one request is received. AAMC members report that patients who have a concern that their protected health information was inappropriately accessed most frequently question whether a particular hospital employee,

4 Page 4 such as a neighbor, looked at their records. Members already respond to these concerns and are able to work with individual patients, conducting targeted reviews to address specific instances of suspected inappropriate access. Many also engage in frequent monitoring of patient records. If a potentially inappropriate access is detected, they have policies and procedures that require an investigation and impose consequences on any individual who is found to have inappropriately accessed a patient s protected health information. While this is anecdotal evidence, it suggests a framework that OCR can use to craft a requirement that meets the mandate of HITECH, ensures that all patients are able to obtain the information they want, and does not create an unreasonable burden on hospitals, physicians, and others that must comply with HIPAA. Cost of Complying Will Be Large In addition to putting forth no evidence to support the need for the access report, the Agency also underestimates the financial and staff cost that will be needed to ensure that a covered entity is able to produce an access report. It is not uncommon for an organization to have one system for inpatient records, one for outpatient, and separate systems for the operating room, emergency department, radiology, and other ancillaries. One AAMC member estimated the cost of complying with this regulation for 10 systems, not the total number of systems that would fall under the definition of designated record set. Based on the use of Fair Warning, a privacy breach detection software used by many AAMC members, this member has broken out the annual costs for the 10 systems as follows: Capital cost of Fair Warning to monitor 10 systems: $170, Staff time per system monitored: - Security program manager- 36 hours - Application program- 18 hours - Application Analyst - 54 hours Total man-hours for each system monitored: 108 hours. Total costs for the monitoring of 10 systems are: $170, man-hours This estimate does not include the substantial staff time that also will be needed when a patient is provided with an access report that is difficult, if not impossible, to understand. This will necessitate identifying and training individuals to explain the meaning of the report, determine if a particular individual s access is appropriate, and answer questions. Information Should Be Limited to what is Included in the EHR, Not the Designated Record Set The HITECH requirement that the proposed rule is seeking to implement is limited to a covered entity that uses or maintains an electronic health record with respect to protected health information. (emphasis added; (c) HITECH) Although there seems to be no regulatory definition of an electronic health record, it might most commonly be considered to be equivalent to a patient s medical record. Nonetheless, rather than define an electronic health record, OCR has proposed that the access report will include everything that is in a designated record set (45 CFR ), resulting in a broad application of the proposal that seems to go

5 Page 5 far beyond what is required by the law. OCR should ensure that any revisions to the accounting for disclosures requirements are consistent with the law and apply to systems that may reasonably have the capacity to produce the required information. Information Contained in Logs Is Not In A Readily Understandable Format Current electronic health record systems are not designed to provide access information in a format that is understandable to individuals. Below is a one-page sample of a log from an AAMC member s emergency department system: Another member reports that the log for a routine hospital stay is 500 pages in length. System security access logs typically contain the following information: 1. Date time stamp of the log entry 2. User in the system that performed the action. (This user can be presented in a multitude of ways especially if the user is an automated non human account) 3. The action they performed 4. The goal for that action

6 Page 6 5. Details about the action itself 6. In some cases, multiple actions may constitute a flow and end up as one log entry Generally, a log also includes information about records activity occurring due to automated functions in between different clinical systems. In addition the presence of codes and acronyms in logs make the presentation of the data challenging and lengthy, and provides no information about whether access by a particular individual is appropriate. OCR seems to recognize that the complete logs may be extremely lengthy and encourage[s] covered entities to create forms for individuals to request an access report that provides information about the information the individual will receive and allows the individual to narrow the request based on the individual s interests. However, a narrow request is not mandatory so a covered entity must be fully prepared to respond to any patient request of any size. Names of Employees Should Not Be Provided AAMC members have expressed significant safety concerns about releasing the names of their employees as part of the access report. For example, many AAMC members treat criminals and mentally ill patients who, once they know the names of employees, may pose a danger to them. Some members have expressed concerns that in some circumstances the requirement for providing names may compromise patient care. Knowing that their name may be released to a patient who is seen as potentially dangerous may make some providers reluctant to access that patient s medical record, even when doing so is appropriate. The Access Report and Research To advance research and improve health for patients and populations, researchers, with appropriate ethical oversight, routinely access subjects electronic health records. The AAMC is concerned that the proposed requirement to provide requesting individuals with comprehensive access reports not only greatly increases the burdens on researchers and institutions but would provide individuals with no greater protections than are currently required through the oversight of research protocols. While not explicitly required by the proposed rule, an institution must be prepared to provide information about the identities of the individuals listed in an access report and the purpose for which the PHI was accessed, in response to questions from a recipient of an access report. As is true on the clinical side, AAMC members also have concerns about providing individuals with the names of members of a research team. Particularly when a medical record is accessed for research purposes pursuant to a waiver of individual authorization from an IRB or Privacy Board, research team members may not be prepared to answer questions about a particular protocol. This raises potential ethical concerns, as such contact between a potential subject and researcher had been neither contemplated nor approved by an IRB. Research subjects who have given individual authorization for the use and disclosure of PHI for research are already provided with contact information for the research team, where they can direct any specific privacy concerns or questions.

7 Page 7 Given the potentially staggering number of times that electronic health records may be accessed in a single study, research-related contact events could significantly increase the burden on institutions when an access report is requested. AAMC members have reported that the number of unique contact events for research purposes alone is in the millions and predicted that the cost of collecting this data and responding to subsequent inquiries about research access could be substantial. One member reported that the number of such contact events from a subset of the databases that would need to be queried to create such an event exceeded 2.9 million in 2010 and was expected to exceed 4.5 million research-related contact events in Identification of all appropriate designated records sets could extend, under the proposed rule, to electronic case report forms and research databases, increasing the burden of compliance, the data generated, and the potentially for including confusing or redundant information. If OCR finalizes the proposed right to an access report, the AAMC urges the Agency to provide a broad exemption related to PHI that is accessed for research purposes. However, the AAMC recognizes that even the creation of such an exemption will be of limited value because very few institutions have the ability to distinguish access for research purposes from access for other purposes. This underscores the need to withdraw the access report requirement entirely. If the Rule is Adopted the Compliance Date Should Be Delayed At a time when hospitals and physicians are struggling to implement EHRs, imposing a requirement that none are able to meet is unreasonable. If OCR decides to finalize the proposed right to an access report, there must be a significant delay in the compliance date, until at least This will provide time for vendors to make the needed changes to electronic systems and will avoid imposing a distraction on hospitals and physicians at a time when they are working hard to adopt EHRs and to meet the Medicare program s meaningful use requirements. * * * * * * * * * * If you have questions about these comments, please direct them to Ivy Baer, J.D., M.P.H. (ibaer@aamc.org or ) or Heather Pierce, J.D., M.P.H. (hpierce@aamc.org or ). Sincerely, Darrell G. Kirch, M.D. President and CEO cc: Ivy Baer, J.D. Heather Pierce, J.D.

May 18, 2010. Dear Director Verdugo,

May 18, 2010. Dear Director Verdugo, May 18, 2010 Director Georgina Verdugo U.S. Department of Health and Human Services, Office for Civil Rights Attention: HITECH Accounting of Disclosures Hubert H. Humphrey Building, Room 509F 200 Independence

More information

VIA ELCTRONIC SUBMISSION @ www.regulations.gov. March 15, 2010

VIA ELCTRONIC SUBMISSION @ www.regulations.gov. March 15, 2010 VIA ELCTRONIC SUBMISSION @ www.regulations.gov David Blumenthal, M.D., M.P.P. National Coordinator for Health Information Technology HHS/Office of the National Coordinator for Health Information Technology

More information

RE: Proposed Establishment of Certification Programs for Health Information Technology Permanent Certification Program, RIN 0991-AB59

RE: Proposed Establishment of Certification Programs for Health Information Technology Permanent Certification Program, RIN 0991-AB59 Via Electronic Submission @ www.regulations.gov David Blumenthal, M.D., M.P.P. National Coordinator for Health Information Technology HHS/Office of the National Coordinator for Health Information Technology

More information

Accounting for Disclosure Requirements Summary of Changes Included in the Proposed Rule 76 Federal Register 31426-31448 May 31, 2011

Accounting for Disclosure Requirements Summary of Changes Included in the Proposed Rule 76 Federal Register 31426-31448 May 31, 2011 Accounting for Disclosure Requirements Summary of Changes Included in the 76 Federal Register 31426-31448 May 31, 2011 Current Rule Right to an Accounting; Content Generally An individual has a right under

More information

October 22, 2009. 45 CFR PARTS 160 and 164

October 22, 2009. 45 CFR PARTS 160 and 164 October 22, 2009 U.S. Department of Health and Human Services Office for Civil Rights Attention: HITECH Breach Notification Hubert H. Humphrey Building Room 509 F 200 Independence Avenue, SW Washington,

More information

Vendor Perspective, Question #1

Vendor Perspective, Question #1 Page 1 of 14 September 25 th, 2013 HIT Policy Committee Privacy and Security Tiger Team: Epic appreciates this opportunity to provide testimony related to accounting of disclosures and access reports from

More information

Business Associates and Breach Reporting Under HITECH and the Omnibus Final HIPAA Rule

Business Associates and Breach Reporting Under HITECH and the Omnibus Final HIPAA Rule Business Associates and Breach Reporting Under HITECH and the Omnibus Final HIPAA Rule Patricia D. King, Esq. Associate General Counsel Swedish Covenant Hospital Chicago, IL I. Business Associates under

More information

Docket No. OSHA-2013-0023 Proposed Rule to Improve Tracking of Workplace Injuries and Illnesses

Docket No. OSHA-2013-0023 Proposed Rule to Improve Tracking of Workplace Injuries and Illnesses March 10, 2014 Via Electronic Submission: http://www.regulations.gov The Honorable David Michaels Assistant Secretary Occupational Safety and Health Administration U.S. Department of Labor 200 Constitution

More information

New Proposed HIPAA Accounting Regulation Adds Up To Big Changes for Health Plans

New Proposed HIPAA Accounting Regulation Adds Up To Big Changes for Health Plans July 13, 2011 Author: Christy A. Tinnes If you have questions, please contact your regular Groom attorney or any of the Health and Welfare attorneys listed below: Jon W. Breyfogle jbreyfogle@groom.com

More information

May 18, 2010. Georgina Verdugo Director Office for Civil Rights United States Department of Health and Human Services

May 18, 2010. Georgina Verdugo Director Office for Civil Rights United States Department of Health and Human Services May 18, 2010 Georgina Verdugo Director Office for Civil Rights United States Department of Health and Human Services RE: HIPAA Privacy Rule Accounting of Disclosures Under the Health Information Technology

More information

FirstCarolinaCare Insurance Company Business Associate Agreement

FirstCarolinaCare Insurance Company Business Associate Agreement FirstCarolinaCare Insurance Company Business Associate Agreement THIS BUSINESS ASSOCIATE AGREEMENT ("Agreement"), is made and entered into as of, 20 (the "Effective Date") between FirstCarolinaCare Insurance

More information

May 26, 2015. Attention: RIN 0991-AB93 Submitted electronically to: http://www.regulations.gov. Dear Dr. DeSalvo:

May 26, 2015. Attention: RIN 0991-AB93 Submitted electronically to: http://www.regulations.gov. Dear Dr. DeSalvo: Karen B. DeSalvo, M.D., M.P.H., M.Sc. National Coordinator for Health Information Technology Department of Health and Human Services 200 Independence Avenue, SW Washington, DC 20201 Attention: RIN 0991-AB93

More information

Updated HIPAA Regulations What Optometrists Need to Know Now. HIPAA Overview

Updated HIPAA Regulations What Optometrists Need to Know Now. HIPAA Overview Updated HIPAA Regulations What Optometrists Need to Know Now The U.S. Department of Health & Human Services Office for Civil Rights recently released updated regulations regarding the Health Insurance

More information

Welcome. This presentation focuses on Business Associates under the Omnibus Rule of 2013.

Welcome. This presentation focuses on Business Associates under the Omnibus Rule of 2013. Welcome. This presentation focuses on Business Associates under the Omnibus Rule of 2013. Business Associates have been part of the focus of the HIPAA regulations since 2003 when the privacy rule went

More information

The ReHabilitation Center. 1439 Buffalo Street. Olean. NY. 14760

The ReHabilitation Center. 1439 Buffalo Street. Olean. NY. 14760 Procedure Name: HITECH Breach Notification The ReHabilitation Center 1439 Buffalo Street. Olean. NY. 14760 Purpose To amend The ReHabilitation Center s HIPAA Policy and Procedure to include mandatory breach

More information

Karen DeSalvo, M.D., M.P.H., M.Sc. May 29, 2015 Page 2 of 7

Karen DeSalvo, M.D., M.P.H., M.Sc. May 29, 2015 Page 2 of 7 Karen DeSalvo, M.D., M.P.H., M.Sc. Acting Assistant Secretary for Health National Coordinator for Health Information Technology U.S. Department of Health and Human Services 200 Independence Avenue, S.W.

More information

White Paper THE HIPAA FINAL OMNIBUS RULE: NEW CHANGES IMPACTING BUSINESS ASSOCIATES

White Paper THE HIPAA FINAL OMNIBUS RULE: NEW CHANGES IMPACTING BUSINESS ASSOCIATES White Paper THE HIPAA FINAL OMNIBUS RULE: NEW CHANGES IMPACTING BUSINESS ASSOCIATES CONTENTS Introduction 3 Brief Overview of HIPPA Final Omnibus Rule 3 Changes to the Definition of Business Associate

More information

April 3, 2014. Submitted Electronically Via Federal Rulemaking Portal: www.regulations.gov

April 3, 2014. Submitted Electronically Via Federal Rulemaking Portal: www.regulations.gov April 3, 2014 Submitted Electronically Via Federal Rulemaking Portal: www.regulations.gov Centers for Medicare & Medicaid Services U.S. Department of Health and Human Services Attention: CMS-0037-P Room

More information

RE: Medicare and Medicaid Programs; Electronic Health Record Incentive Program Stage 2 Notice of Proposed Rulemaking (CMS-0044-P)

RE: Medicare and Medicaid Programs; Electronic Health Record Incentive Program Stage 2 Notice of Proposed Rulemaking (CMS-0044-P) May 4, 2012 Marilyn Tavenner Acting Administrator Centers for Medicare & Medicaid Services Department of Health and Human Services 200 Independence Avenue, S.W., Room 445-G Washington, DC 20201 RE: Medicare

More information

April 12, 2011 BY ELECTRONIC SUBMISSION. Elizabeth M. Murphy Secretary Securities and Exchange Commission 100 F Street, NE Washington, DC 20549-1090

April 12, 2011 BY ELECTRONIC SUBMISSION. Elizabeth M. Murphy Secretary Securities and Exchange Commission 100 F Street, NE Washington, DC 20549-1090 BY ELECTRONIC SUBMISSION Elizabeth M. Murphy Secretary Securities and Exchange Commission 100 F Street, NE Washington, DC 20549-1090 David A. Stawick Secretary Commodity Futures Trading Commission Three

More information

May 7, 2012. Submitted Electronically

May 7, 2012. Submitted Electronically May 7, 2012 Submitted Electronically Secretary Kathleen Sebelius Department of Health and Human Services Office of the National Coordinator for Health Information Technology Attention: 2014 edition EHR

More information

Health Record Banking Alliance

Health Record Banking Alliance Health Record Banking Alliance From: William A. Yasnoff, MD, PhD, President, Health Record Banking Alliance To: Regulations.Gov Website at http://www.regulations.gov/search/regs/home.html#home Date: May

More information

ACTION: Direct final rule with request for comments. SUMMARY: Defense Logistics Agency (DLA) is exempting records

ACTION: Direct final rule with request for comments. SUMMARY: Defense Logistics Agency (DLA) is exempting records 1 This document is scheduled to be published in the Federal Register on 07/09/2015 and available online at http://federalregister.gov/a/2015-16575, and on FDsys.gov Billing Code: 5001-06 DEPARTMENT OF

More information

May 4, 2012. Dear Dr. Mostashari:

May 4, 2012. Dear Dr. Mostashari: Dr. Farzad Mostashari, National Coordinator for Health Information Technology Office of the National Coordinator for Health Information Technology Department of Health and Human Services Attn: 2014 Edition

More information

Guidance Specifying Technologies and Methodologies DEPARTMENT OF HEALTH AND HUMAN SERVICES

Guidance Specifying Technologies and Methodologies DEPARTMENT OF HEALTH AND HUMAN SERVICES DEPARTMENT OF HEALTH AND HUMAN SERVICES 45 CFR PARTS 160 and 164 Guidance Specifying the Technologies and Methodologies That Render Protected Health Information Unusable, Unreadable, or Indecipherable

More information

Business Associates under HITECH: A Chain of Trust

Business Associates under HITECH: A Chain of Trust FAQ on InfoSafe Shredding Services: Frequently Asked Questions on InfoSafe Shredding Information And Video on One Time Cleanouts: Cleanouts and Purges Business Associates under HITECH: A Chain of Trust

More information

SDC-League Health Fund

SDC-League Health Fund SDC-League Health Fund 1501 Broadway, 17 th Floor New York, NY 10036 Tel: 212-869-8129 Fax: 212-302-6195 E-mail: health@sdcweb.org NOTICE OF PRIVACY PRACTICES THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION

More information

Connecticut Carpenters Health Fund Privacy Notice

Connecticut Carpenters Health Fund Privacy Notice Connecticut Carpenters Health Fund Privacy Notice THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

More information

March 15, 2010. Dear Dr. Blumenthal:

March 15, 2010. Dear Dr. Blumenthal: March 15, 2010 David Blumenthal, MD, MPP National Coordinator Office of the National Coordinator for Health Information Technology (ONCHIT) Department of Health and Human Services ATTN: HITECH Initial

More information

Isaac Willett April 5, 2011

Isaac Willett April 5, 2011 Current Options for EHR Implementation: Cloud or No Cloud? Regina Sharrow Isaac Willett April 5, 2011 Introduction Health Information Technology for Economic and Clinical Health Act ( HITECH (HITECH Act

More information

Re: FINRA Regulatory Notice 13-42: FINRA Requests Comments on a Concept Proposal to Develop the Comprehensive Automated Risk Data System

Re: FINRA Regulatory Notice 13-42: FINRA Requests Comments on a Concept Proposal to Develop the Comprehensive Automated Risk Data System Ms. Marcia E. Asquith Office of the Corporate Secretary FINRA 1735 K Street, NW Washington, DC 20006 Re: FINRA Regulatory Notice 13-42: FINRA Requests Comments on a Concept Proposal to Develop the Comprehensive

More information

The undersigned provider groups would like to draw your attention to implementation concerns regarding two administrative simplification issues:

The undersigned provider groups would like to draw your attention to implementation concerns regarding two administrative simplification issues: January 30, 2015 Marilyn B. Tavenner Administrator Centers for Medicare & Medicaid Services U.S. Department of Health and Human Services Hubert H. Humphrey Building, Room 445 G 200 Independence Avenue,

More information

HIPAA and HITECH Compliance for Cloud Applications

HIPAA and HITECH Compliance for Cloud Applications What Is HIPAA? The healthcare industry is rapidly moving towards increasing use of electronic information systems - including public and private cloud services - to provide electronic protected health

More information

Re: HIPAA/HITECH Final Rule Clarification and Guidance Sought on Refill Reminder Programs

Re: HIPAA/HITECH Final Rule Clarification and Guidance Sought on Refill Reminder Programs June 5, 2013 Ms. Susan McAndrew Deputy Director for Health Information Privacy Office for Civil Rights Department of Health and Human Services 200 Independence Ave., SW 56E 5 th Floor Washington, D.C.

More information

AVE MARIA UNIVERSITY HIPAA PRIVACY NOTICE

AVE MARIA UNIVERSITY HIPAA PRIVACY NOTICE AVE MARIA UNIVERSITY HIPAA PRIVACY NOTICE This Notice of Privacy Practices describes the legal obligations of Ave Maria University, Inc. (the plan ) and your legal rights regarding your protected health

More information

Data Breach Notification Burden Grows With First State Insurance Commissioner Mandate

Data Breach Notification Burden Grows With First State Insurance Commissioner Mandate Privacy, Data Security & Information Use September 16, 2010 Data Breach Notification Burden Grows With First State Insurance Commissioner Mandate by John L. Nicholson and Meighan E. O'Reardon Effective

More information

COMPLIANCE ALERT 10-12

COMPLIANCE ALERT 10-12 HAWAII HEALTH SYSTEMS C O R P O R A T I O N "Touching Lives Every Day COMPLIANCE ALERT 10-12 HIPAA Expansion under the American Recovery and Reinvestment Act of 2009 The American Recovery and Reinvestment

More information

POLICIES AND PROCEDURES. TOPIC: Patient Accounting of Disclosures DOCUMENT NUMBER: 900. EFFECTIVE DATE: January 30, 2014 I. BACKGROUND AND PURPOSE

POLICIES AND PROCEDURES. TOPIC: Patient Accounting of Disclosures DOCUMENT NUMBER: 900. EFFECTIVE DATE: January 30, 2014 I. BACKGROUND AND PURPOSE POLICIES AND PROCEDURES TOPIC: Patient Accounting of Disclosures DOCUMENT NUMBER: 900 EFFECTIVE DATE: January 30, 2014 I. BACKGROUND AND PURPOSE The purpose of this policy is to recognize and accommodate

More information

HHS Issues New HITECH/HIPAA Rule: Implications for Hospice Providers

HHS Issues New HITECH/HIPAA Rule: Implications for Hospice Providers Compliance Tip Sheet National Hospice and Palliative Care Organization www.nhpco.org/regulatory HHS Issues New HITECH/HIPAA Rule: Implications for Hospice Providers Hospice Provider Compliance To Do List

More information

HIPAA Compliance Manual

HIPAA Compliance Manual HIPAA Compliance Manual HIPAA Compliance Manual 1 This Manual is provided to assist your efforts to comply with the federal privacy and security rules mandated under HIPAA and HITECH, specifically as said

More information

Disclaimer: Template Business Associate Agreement (45 C.F.R. 164.308)

Disclaimer: Template Business Associate Agreement (45 C.F.R. 164.308) HIPAA Business Associate Agreement Sample Notice Disclaimer: Template Business Associate Agreement (45 C.F.R. 164.308) The information provided in this document does not constitute, and is no substitute

More information

Everett School Employee Benefit Trust. Reportable Breach Notification Policy HIPAA HITECH Rules and Washington State Law

Everett School Employee Benefit Trust. Reportable Breach Notification Policy HIPAA HITECH Rules and Washington State Law Everett School Employee Benefit Trust Reportable Breach Notification Policy HIPAA HITECH Rules and Washington State Law Introduction The Everett School Employee Benefit Trust ( Trust ) adopts this policy

More information

Business Associates, HITECH & the Omnibus HIPAA Final Rule

Business Associates, HITECH & the Omnibus HIPAA Final Rule Business Associates, HITECH & the Omnibus HIPAA Final Rule HIPAA Omnibus Final Rule Changes Business Associates Marissa Gordon-Nguyen, JD, MPH Health Information Privacy Specialist Office for Civil Rights/HHS

More information

By Ross C. D Emanuele, John T. Soshnik, and Kari Bomash, Dorsey & Whitney LLP Minneapolis, MN

By Ross C. D Emanuele, John T. Soshnik, and Kari Bomash, Dorsey & Whitney LLP Minneapolis, MN Major Changes to HIPAA Security and Privacy Rules Enacted in Economic Stimulus Package By Ross C. D Emanuele, John T. Soshnik, and Kari Bomash, Dorsey & Whitney LLP Minneapolis, MN The HITECH Act is the

More information

REPRODUCTIVE ASSOCIATES OF DELAWARE (RAD) NOTICE OF PRIVACY PRACTICES PLEASE REVIEW IT CAREFULLY.

REPRODUCTIVE ASSOCIATES OF DELAWARE (RAD) NOTICE OF PRIVACY PRACTICES PLEASE REVIEW IT CAREFULLY. REPRODUCTIVE ASSOCIATES OF DELAWARE (RAD) NOTICE OF PRIVACY PRACTICES THIS NOTICE DESCRIBES HOW PROTECTED HEALTH INFORMATION (PHI) ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS

More information

P C R C. Physician Clinical Registry Coalition. July 14, 2015

P C R C. Physician Clinical Registry Coalition. July 14, 2015 P C R C Physician Clinical Registry Coalition July 14, 2015 VIA ELECTRONIC MAIL Jeffrey R. Botkin, MD, MPH SACHRP Chair Jerry A. Menikoff, MD, JD Director, Office for Human Research Protections SACHRP

More information

CREATIVE SOLUTIONS IN HEALTHCARE, INC. Privacy Policy

CREATIVE SOLUTIONS IN HEALTHCARE, INC. Privacy Policy CREATIVE SOLUTIONS IN HEALTHCARE, INC. Privacy Policy Amended as of February 12, 2010 on the authority of the HIPAA Privacy Officer for Creative Solutions in Healthcare, Inc. TABLE OF CONTENTS ARTICLE

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement ( Agreement ) between Inphonite, LLC ( Business Associate and you, as our Customer ( Covered Entity ) (each individually, a Party, and collectively,

More information

Name of Other Party: Address of Other Party: Effective Date: Reference Number as applicable:

Name of Other Party: Address of Other Party: Effective Date: Reference Number as applicable: PLEASE NOTE: THIS DOCUMENT IS SUBMITTED AS A SAMPLE, FOR INFORMATIONAL PURPOSES ONLY TO ABC ORGANIZATION. HIPAA SOLUTIONS LC IS NOT ENGAGED IN THE PRACTICE OF LAW IN ANY STATE, JURISDICTION, OR VENUE OF

More information

Frequently Asked Questions About the Privacy Rule Under HIPAA

Frequently Asked Questions About the Privacy Rule Under HIPAA Q-1: What is HIPAA? Frequently Asked Questions About the Privacy Rule Under HIPAA A: HIPAA is the Health Insurance Portability and Accountability Act (passed by Congress in 1996). The Privacy Rule was

More information

Healthcare Practice. Breach Notification Requirements Under HIPAA/HITECH Act and Oregon Consumer Identity Theft Protection Act. Oregon.

Healthcare Practice. Breach Notification Requirements Under HIPAA/HITECH Act and Oregon Consumer Identity Theft Protection Act. Oregon. Healthcare Practice Breach Notification Requirements Under HIPAA/HITECH Act and Consumer Identity Theft Protection Act August 2013 Anchorage Beijing New York Portland Seattle Washington, D.C. www.gsblaw.com

More information

Form I: HIPAA Notice of Privacy Practices HIPAA NOTICE OF PRIVACY PRACTICES

Form I: HIPAA Notice of Privacy Practices HIPAA NOTICE OF PRIVACY PRACTICES Pg. 4 Form I: HIPAA Notice of Privacy Practices Susan Zaro, LMFT, BCB HIPAA NOTICE OF PRIVACY PRACTICES I. THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU

More information

On July 14 the U.S. Department of Health and Human Services published a Notice of

On July 14 the U.S. Department of Health and Human Services published a Notice of Casting a Vastly Expanded Regulatory Net: Implications of the New Definition of Business Associates under HITECH By Amy K. Fehn, Wachler & Associates, P.C. and John R. Christiansen, Christiansen IT Law

More information

What Virginia s Free Clinics Need to Know About HIPAA and HITECH

What Virginia s Free Clinics Need to Know About HIPAA and HITECH What Virginia s Free Clinics Need to Know About HIPAA and HITECH This document is one in a series of tools and white papers produced by the Virginia Health Care Foundation to help Virginia s free clinics

More information

THE HIPAA PRIVACY RULE AND THE NATIONAL HOSPITAL CARE SURVEY

THE HIPAA PRIVACY RULE AND THE NATIONAL HOSPITAL CARE SURVEY THE HIPAA PRIVACY RULE AND THE NATIONAL HOSPITAL CARE SURVEY Table of Contents I. Overview... 3 II. Legal Authority for NHCS... 3 III. Requirements of the HIPAA Privacy Rule... 3 IV. Extra Safeguards and

More information

Community First Health Plans Breach Notification for Unsecured PHI

Community First Health Plans Breach Notification for Unsecured PHI Community First Health Plans Breach Notification for Unsecured PHI The presentation is for informational purposes only. It is the responsibility of the Business Associate to ensure awareness and compliance

More information

Zip It! Feds, State Strengthen Privacy Protection. Practice Management Feature July 2012. Tex Med. 2012;108(7):33-37.

Zip It! Feds, State Strengthen Privacy Protection. Practice Management Feature July 2012. Tex Med. 2012;108(7):33-37. Zip It! Feds, State Strengthen Privacy Protection Practice Management Feature July 2012 Tex Med. 2012;108(7):33-37. By Crystal Conde Associate Editor When it comes to enforcing HIPAA data security and

More information

RIN 1210-AB39 Claims Procedure Regulation Amendment for Plans Providing Disability Benefits

RIN 1210-AB39 Claims Procedure Regulation Amendment for Plans Providing Disability Benefits 20 F Street, NW, Suite 200 Washington, D.C. 20001 202.558.3000 Fax 202.628.9244 www.businessgrouphealth.org Creative Health Benefits Solutions for Today, Strong Policy for Tomorrow January 19, 2016 Submitted

More information

HHS announces sweeping changes to the HIPAA Privacy and Security Rules in the final HIPAA Omnibus Rule

HHS announces sweeping changes to the HIPAA Privacy and Security Rules in the final HIPAA Omnibus Rule JANUARY 23, 2013 HHS announces sweeping changes to the HIPAA Privacy and Security Rules in the final HIPAA Omnibus Rule By Linn Foster Freedman, Kathryn M. Sylvia, Lindsay Maleson, and Brooke A. Lane On

More information

Re: REG 130266 11, Additional Requirements for Charitable Hospitals, Proposed Rule

Re: REG 130266 11, Additional Requirements for Charitable Hospitals, Proposed Rule Sarah Hall Ingram Commissioner IRS Tax Exempt & Government Entities Division Internal Revenue Service P.O. Box 7604 Ben Franklin Station Washington, DC 20044 Re: REG 130266 11, Additional Requirements

More information

Winthrop-University Hospital

Winthrop-University Hospital Winthrop-University Hospital Use of Patient Information in the Conduct of Research Activities In accordance with 45 CFR 164.512(i), 164.512(a-c) and in connection with the implementation of the HIPAA Compliance

More information

Information Protection Framework: Data Security Compliance and Today s Healthcare Industry

Information Protection Framework: Data Security Compliance and Today s Healthcare Industry Information Protection Framework: Data Security Compliance and Today s Healthcare Industry Executive Summary Today s Healthcare industry is facing complex privacy and data security requirements. The movement

More information

Memorandum. Factual Background

Memorandum. Factual Background Memorandum TO: FROM: SUBJECT: Chris Ianelli and Jill Mullan, ispecimen, Inc. Kristen Rosati and Ana Christian, Polsinelli, PC ispecimen Regulatory Compliance DATE: January 26, 2014 You have asked us to

More information

File No. 270-330, OMB Control No. 3235-0372: Proposed Collection; Comment Request Related to Rule 15c2-12 Dear Ms. Dyson:

File No. 270-330, OMB Control No. 3235-0372: Proposed Collection; Comment Request Related to Rule 15c2-12 Dear Ms. Dyson: January 17, 2015 Ms. Pamela Dyson Acting Director/Chief Information Officer c/o Remi Pavlik-Simon 100 F Street, NE. Washington, DC 20549 Re: File No. 270-330, OMB Control No. 3235-0372: Proposed Collection;

More information

Chief Privacy Officer Christian Brothers Services 1205 Windham Parkway Romeoville, IL 60446-1679 cpo@cbservices.org 800-807-0100

Chief Privacy Officer Christian Brothers Services 1205 Windham Parkway Romeoville, IL 60446-1679 cpo@cbservices.org 800-807-0100 Summary of Notice of Privacy Practices for Christian Brothers Prescription Drug Program Christian Brothers Services is the program sponsor of the Christian Brothers Prescription Drug Program (the Program

More information

JPMorgan Chase & Co. 1 Chase Manhattan Plaza, Floor 25 New York, NY 10081. Telephone: (212) 552-1721 Facsimile: (212) 383-8065 Jay.soloway@chase.

JPMorgan Chase & Co. 1 Chase Manhattan Plaza, Floor 25 New York, NY 10081. Telephone: (212) 552-1721 Facsimile: (212) 383-8065 Jay.soloway@chase. JPMorgan Chase & Co. 1 Chase Manhattan Plaza, Floor 25 New York, NY 10081 Telephone: (212) 552-1721 Facsimile: (212) 383-8065 Jay.soloway@chase.com Jay N. Soloway Senior Vice President Associate General

More information

August 1, 2011. HIPAA Privacy Rule Accounting of Disclosures 45CFR164; RIN0991-AB62

August 1, 2011. HIPAA Privacy Rule Accounting of Disclosures 45CFR164; RIN0991-AB62 August 1, 2011 Georgina Verdugo, JD, LLM, MPA Director HHS Office for Civil Rights Attention: HIPAA Privacy Rule Accounting of Disclosures U.S. Department of Health and Human Services Hubert H. Humphrey

More information

HIPAA Omnibus & HITECH Rules: Key Provisions and a Simple Checklist. www.riskwatch.com

HIPAA Omnibus & HITECH Rules: Key Provisions and a Simple Checklist. www.riskwatch.com HIPAA Omnibus & HITECH Rules: Key Provisions and a Simple Checklist www.riskwatch.com Introduction Last year, the federal government published its long awaited final regulations implementing the Health

More information

2016 OCR AUDIT E-BOOK

2016 OCR AUDIT E-BOOK !! 2016 OCR AUDIT E-BOOK About BlueOrange Compliance: We specialize in healthcare information privacy and security solutions. We understand that each organization is busy running its business and that

More information

NOTICE OF PRIVACY PRACTICES

NOTICE OF PRIVACY PRACTICES NOTICE OF PRIVACY PRACTICES The Pain Treatment Center, Inc. d/b/a Stone Road Surgery Center THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS

More information

Response to Revisions to the Permanent Certification Program for Health Information Technology NPRM (RIN 0991-AB82)

Response to Revisions to the Permanent Certification Program for Health Information Technology NPRM (RIN 0991-AB82) Response to Revisions to the Permanent Certification Program for Health Information Technology NPRM (RIN 0991-AB82) May 7, 2012 Secretary Kathleen Sebelius U.S. Department of Health and Human Services

More information

June 15, 2015. Submitted electronically via www.regulations.gov

June 15, 2015. Submitted electronically via www.regulations.gov June 15, 2015 Marilyn Tavenner, R.N. Administrator Center for Medicare and Medicaid Services Department of Health and Human Services P.O. Box 8013 Baltimore, MD 21244-8013 Submitted electronically via

More information

HIPAA PRIVACY AND SECURITY RULES BUSINESS ASSOCIATE AGREEMENT BETWEEN. Stewart C. Miller & Co., Inc. (Business Associate) AND

HIPAA PRIVACY AND SECURITY RULES BUSINESS ASSOCIATE AGREEMENT BETWEEN. Stewart C. Miller & Co., Inc. (Business Associate) AND HIPAA PRIVACY AND SECURITY RULES BUSINESS ASSOCIATE AGREEMENT BETWEEN Stewart C. Miller & Co., Inc. (Business Associate) AND City of West Lafayette Flexible Spending Plan (Covered Entity) TABLE OF CONTENTS

More information

BUSINESS ASSOCIATE AGREEMENT FOR ATTORNEYS

BUSINESS ASSOCIATE AGREEMENT FOR ATTORNEYS BUSINESS ASSOCIATE AGREEMENT FOR ATTORNEYS This Business Associate Agreement (this Agreement ), is made as of the day of, 20 (the Effective Date ), by and between ( Business Associate ) and ( Covered Entity

More information

The Meaningful Use Stage 2 Final Rule: Overview and Outlook

The Meaningful Use Stage 2 Final Rule: Overview and Outlook The Meaningful Use Stage 2 Final Rule: Overview and Outlook Devi Mehta, JD, MPH Cand. 1 Taylor Burke, JD, LLM 2 Lara Cartwright-Smith, JD, MPH 3 Jane Hyatt Thorpe, JD 4 Introduction On August 23, 2012,

More information

The Proposed Rule of Electronic Health Certification (EHSRT)

The Proposed Rule of Electronic Health Certification (EHSRT) April 28, 2014 VIA ELECTRONIC SUBMISSION Karen DeSalvo, MD, MPH, MSc National Coordinator for Health Information Technology Department of Health and Human Services 200 Independence Avenue, S.W. Washington,

More information

Health Insurance Portability and Accountability Act (HIPAA) Compliance Training

Health Insurance Portability and Accountability Act (HIPAA) Compliance Training Health Insurance Portability and Accountability Act (HIPAA) Compliance Training 1 Objectives By the end of this lesson, you should be able to: Define protected health information (PHI) covered under HIPAA

More information

B-327450. October 29, 2015

B-327450. October 29, 2015 441 G St. N.W. Washington, DC 20548 B-327450 October 29, 2015 The Honorable Lamar Alexander Chairman The Honorable Patty Murray Ranking Member Committee on Health, Education, Labor, and Pensions United

More information

May 7, 2012. Re: RIN 0991-AB82. Dear Secretary Sebelius:

May 7, 2012. Re: RIN 0991-AB82. Dear Secretary Sebelius: May 7, 2012 Department of Health and Human Services Office of the National Coordinator for Health Information Technology Attention: 2014 Edition EHR Standards and Certification Proposed Rule Hubert H.

More information

NACHC Issue Brief Changes to the Health Insurance Portability and Accountability Act Included in ARRA. March 2010

NACHC Issue Brief Changes to the Health Insurance Portability and Accountability Act Included in ARRA. March 2010 NACHC Issue Brief Changes to the Health Insurance Portability and Accountability Act Included in ARRA March 2010 Prepared By: Marisa Guevara and Marcie H. Zakheim Feldesman Tucker Leifer Fidell, LLP 2001

More information

Notice of Privacy Practices

Notice of Privacy Practices Notice of Privacy Practices This notice describes how medical information about you may be used and disclosed and how you can get access to this information. Please review it carefully. This Notice of

More information

HIPAA S BUSINESS ASSOCIATE REQUIREMENTS FOR PATHOLOGISTS AND LABORATORIES

HIPAA S BUSINESS ASSOCIATE REQUIREMENTS FOR PATHOLOGISTS AND LABORATORIES HIPAA S BUSINESS ASSOCIATE REQUIREMENTS FOR PATHOLOGISTS AND LABORATORIES What is HIPAA? The Health Insurance Portability and Accountability Act of 1996 ( HIPAA ) establishes new privacy requirements for

More information

American Bar Association. Technical Session Between the Department of Health and Human Services and the Joint Committee on Employee Benefits

American Bar Association. Technical Session Between the Department of Health and Human Services and the Joint Committee on Employee Benefits American Bar Association Technical Session Between the Department of Health and Human Services and the Joint Committee on Employee Benefits May 6, 2008 The following notes are based upon the personal comments

More information

Data Breach, Electronic Health Records and Healthcare Reform

Data Breach, Electronic Health Records and Healthcare Reform Data Breach, Electronic Health Records and Healthcare Reform (This presentation is for informational purposes only and it is not intended, and should not be relied upon, as legal advice.) Overview of HIPAA

More information

GE Healthcare Healthcare IT

GE Healthcare Healthcare IT GE Healthcare Healthcare IT May 06, 2012 540 W. Northwest Highway Barrington, IL 60010 Farzad Mostashari, MD, ScM Department of Health and Human Services Office of the National Coordinator for Health Information

More information

Department of Health and Human Services. No. 17 January 25, 2013. Part II

Department of Health and Human Services. No. 17 January 25, 2013. Part II Vol. 78 Friday, No. 17 January 25, 2013 Part II Department of Health and Human Services Office of the Secretary 45 CFR Parts 160 and 164 Modifications to the HIPAA Privacy, Security, Enforcement, and Breach

More information

The OCR Audit Protocol a first look

The OCR Audit Protocol a first look The OCR Audit Protocol a first look On June 26, 2012, the Office for Civil Rights published its Audit Protocols for HIPAA Security, HIPAA Breach and Privacy at http://ocrnotifications.hhs.gov/hipaa.html.

More information

HIPAA Privacy Board Overview

HIPAA Privacy Board Overview Defense Health Agency Privacy and Civil Liberties Office HIPAA Privacy Board Overview April 30, 2015 1 Objectives The purpose of this presentation is to: Provide an overview of the DHA Privacy and Civil

More information

May 7, 2012. Dear Dr. Mostashari:

May 7, 2012. Dear Dr. Mostashari: McKesson Corporation One Post Street San Francisco, CA 94104-5296 Ann Richardson Berkey Senior Vice President, Public Affairs May 7, 2012 Farzad Mostashari, M.D., ScM. Director Office of the National Coordinator

More information

October 27, 2014. Docket No. CFPB-2014-0019, RIN 3170-AA10 Home Mortgage Disclosure (Regulation C)

October 27, 2014. Docket No. CFPB-2014-0019, RIN 3170-AA10 Home Mortgage Disclosure (Regulation C) October 27, 2014 The Honorable Richard Cordray Director Consumer Financial Protection Bureau 1700 G Street NW Washington, DC 20006-4702 Monica Jackson Office of the Executive Secretary Consumer Financial

More information

Long-Expected Omnibus HIPAA Rule Implements Significant Privacy and Security Regulations for Entities and Business Associates

Long-Expected Omnibus HIPAA Rule Implements Significant Privacy and Security Regulations for Entities and Business Associates Legal Update February 11, 2013 Long-Expected Omnibus HIPAA Rule Implements Significant Privacy and Security Regulations for Entities and Business Associates On January 17, 2013, the Department of Health

More information

In circumstances where an electronic brokerage has made a recommendation, the investment profile information required to be obtained and considered

In circumstances where an electronic brokerage has made a recommendation, the investment profile information required to be obtained and considered September 21, 2012 Ronald W. Smith Corporate Secretary Municipal Securities Rulemaking Board 1900 Duke Street, Suite 600 Alexandria, VA 22314 Re: Notice 2012-41 (August 9, 2012): Request for Comment on

More information

BREACH NOTIFICATION FOR UNSECURED PROTECTED HEALTH INFORMATION

BREACH NOTIFICATION FOR UNSECURED PROTECTED HEALTH INFORMATION BREACH NOTIFICATION FOR UNSECURED PROTECTED HEALTH INFORMATION Summary November 2009 On August 24, 2009, the Department of Health and Human Services (HHS) published an interim final rule (the Rule ) that

More information

Re: Medicare and Medicaid Programs: Electronic Health Record (EHR) Incentive Program- Stage 3 Proposed Rule, File Code CMS-3310-P

Re: Medicare and Medicaid Programs: Electronic Health Record (EHR) Incentive Program- Stage 3 Proposed Rule, File Code CMS-3310-P Via Electronic Submission (www.regulations.gov) Mr. Andrew Slavitt Acting Administrator Centers for Medicare & Medicaid Services U.S. Department of Health and Human Services Hubert H. Humphrey Building,

More information

Protecting Personal Health Information in Research: Understanding the HIPAA Privacy Rule

Protecting Personal Health Information in Research: Understanding the HIPAA Privacy Rule AA Privacy RuleP DEPARTMENT OF HE ALTH & HUMAN SERVICES USA Protecting Personal Health Information in Research: Understanding the HIPAA Privacy Rule NIH Publication Number 03-5388 The HI Protecting Personal

More information

Re: Interim Final Rules Relating to Internal Claims and Appeals and External Review Processes (RIN-0991-AB70)

Re: Interim Final Rules Relating to Internal Claims and Appeals and External Review Processes (RIN-0991-AB70) Office of Consumer Information and Insurance Oversight Department of Health and Human Services Room 445-G Hubert H. Humphrey Building 200 Independence Ave., SW Washington, DC 20201 Re: Interim Final Rules

More information

What Health Care Entities Need to Know about HIPAA and the American Recovery and Reinvestment Act

What Health Care Entities Need to Know about HIPAA and the American Recovery and Reinvestment Act What Health Care Entities Need to Know about HIPAA and the American Recovery and Reinvestment Act by Lane W. Staines and Cheri D. Green On February 17, 2009, The American Recovery and Reinvestment Act

More information

HIPAA NOTICE OF PRIVACY PRACTICES FOR PROTECTED HEALTH INFORMATION

HIPAA NOTICE OF PRIVACY PRACTICES FOR PROTECTED HEALTH INFORMATION HIPAA NOTICE OF PRIVACY PRACTICES FOR PROTECTED HEALTH INFORMATION THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN ACCESS THIS INFORMATION. PLEASE REVIEW

More information

Business Associate Agreement

Business Associate Agreement Business Associate Agreement This Agreement is entered into as of ("Effective Date"), between ( Covered Entity ), and ( Business Associate ). RECITALS WHEREAS, Business Associate provides services on behalf

More information