<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.lexblog.com/~d/styles/itemcontent.css"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
   <channel>
      <title>HIPAA, HITECH &amp; HIT</title>
      <link>http://hipaahealthlaw.foxrothschild.com/</link>
      <description>Fox Rothschild LLP</description>
      <language>en</language>
      <copyright>Copyright 2013</copyright>
      <lastBuildDate>Tue, 26 Mar 2013 15:23:01 -0500</lastBuildDate>
      <pubDate>Tue, 26 Mar 2013 15:23:01 -0500</pubDate>
      <generator>http://www.movabletype.org</generator>
      <docs>http://blogs.law.harvard.edu/tech/rss</docs> 

            <feedburner:info uri="hipaahealthlaw" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://hipaahealthlaw.foxrothschild.com/index.xml" /><feedburner:feedFlare href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Fhipaahealthlaw.foxrothschild.com%2Findex.xml" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Fhipaahealthlaw.foxrothschild.com%2Findex.xml" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare href="http://feeds.my.aol.com/add.jsp?url=http%3A%2F%2Fhipaahealthlaw.foxrothschild.com%2Findex.xml" src="http://o.aolcdn.com/favorites.my.aol.com/webmaster/ffclient/webroot/locale/en-US/images/myAOLButtonSmall.gif">Subscribe with My AOL</feedburner:feedFlare><feedburner:feedFlare href="http://www.bloglines.com/sub/http://hipaahealthlaw.foxrothschild.com/index.xml" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Fhipaahealthlaw.foxrothschild.com%2Findex.xml" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare href="http://fusion.google.com/add?feedurl=http%3A%2F%2Fhipaahealthlaw.foxrothschild.com%2Findex.xml" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Fhipaahealthlaw.foxrothschild.com%2Findex.xml" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><item>
         <title>Omnibus Rule Takes Effect Today - Or Does It?</title>
         <description>&lt;p&gt;The HIPAA/HITECH Omnibus Rule that appeared in the January 25, 2013 &lt;i&gt;Federal Register&lt;/i&gt; contained this cryptic and apparently contradictory statement:&lt;/p&gt;
&lt;p style="margin: 0in 1in 0pt"&gt;&lt;b&gt;DATES: &lt;/b&gt;&lt;i&gt;Effective date: &lt;/i&gt;This final rule is effective on March 26, 2013.&lt;/p&gt;
&lt;p style="margin: 0in 1in 0pt"&gt;&lt;i&gt;Compliance date: &lt;/i&gt;Covered entities and business associates must comply with the applicable requirements of this final rule by September 23, 2013.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;What does it mean for the final rule to be effective today if covered entities and business associates are not required to comply for six more months?&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;Keep in mind that many of the provisions addressed in the Omnibus Rule were enacted by Congress in the HITECH Act and took effect on February 18, 2010, with some exceptions.&amp;nbsp;The tiered and increased civil money penalty provisions of section 13410(d) were effective for violations occurring after the date HITECH was enacted, February 18, 2009. Accordingly, covered entities and business associates were obligated to comply in good faith with the statutory requirements except where the statute provided that it did not take effect until after publication of regulations.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;HHS proposed a 180-day compliance period in its &lt;a href="http://www.gpo.gov/fdsys/pkg/FR-2010-07-14/pdf/2010-16718.pdf"&gt;&lt;font color="#800080"&gt;July 14, 2010 notice of proposed rulemaking&lt;/font&gt;&lt;/a&gt;, and has implemented that grace period in the &lt;a href="http://www.gpo.gov/fdsys/pkg/FR-2013-01-25/pdf/2013-01073.pdf"&gt;&lt;font color="#800080"&gt;final omnibus rule&lt;/font&gt;&lt;/a&gt;. &amp;nbsp;The 180-day grace period was intended to give covered entities and business associates time to comply while best protecting the privacy and security of patient information, in accordance with the goals of the HITECH Act.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;For breaches of unsecured protected health information discovered on or after September 23, 2009, the date of the publication of the interim final rule, through September 23, 2013, covered entities and business associates are still required to comply with the breach notification requirements under the HITECH Act and must continue to comply with the requirements of the interim final rule.&amp;nbsp;A cautious approach during the interim would be to analyze any unauthorized disclosure under both the old &amp;ldquo;subjective&amp;rdquo; standard and the new &amp;ldquo;four part&amp;rdquo; process, and err on the side of concluding that a disclosure is a reportable breach unless it passes both tests.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;The gap between the &amp;ldquo;effective date&amp;rdquo; and the compliance date leaves some open issues. For example, the definition of &amp;ldquo;business associate&amp;rdquo; has been expanded by the omnibus rule to include new entities who &amp;ldquo;maintain&amp;rdquo; PHI such as cloud-based data storage companies and warehouse service providers. When do they become BA&amp;rsquo;s &amp;ndash; March 26 or September 23?&amp;nbsp;It appears that covered entities will not be required to have written agreements in place with these newly-designated BA&amp;rsquo;s until September 23, but it is not clear that such a BA that causes a breach of unsecured PHI during the gap period would not still be directly liable.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&lt;span style="font-size: 10pt; font-family: Arial; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;These remaining uncertainties offer a valid reason for covered entities, existing business associates and newly-added BA&amp;rsquo;s to prioritize the process of evaluating and updating their HIPAA/HITECH compliance efforts, starting with new BAA&amp;rsquo;s, Notices of Privacy Practices and Breach Notification policies. Procrastination is rarely a good strategy, and waiting until the last minute to comply with the omnibus rule could have costly unanticipated consequences&lt;/span&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/HipaaHealthLaw/~4/PfwgAQZ1imI" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/HipaaHealthLaw/~3/PfwgAQZ1imI/</link>
         <guid isPermaLink="false">http://hipaahealthlaw.foxrothschild.com/2013/03/articles/hitech-act/omnibus-rule-takes-effect-today-or-does-it/</guid>
         <category domain="http://hipaahealthlaw.foxrothschild.com/articles">HITECH Act</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Omnibus rule</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">effective date</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">mega-rule</category>
         <pubDate>Tue, 26 Mar 2013 14:27:12 -0500</pubDate>
         <dc:creator>William Maruca</dc:creator>
      
      <feedburner:origLink>http://hipaahealthlaw.foxrothschild.com/2013/03/articles/hitech-act/omnibus-rule-takes-effect-today-or-does-it/</feedburner:origLink></item>
            <item>
         <title>The New and Improved HIPAA/HITECH Rules: What Employers Need to Know</title>
         <description>&lt;p&gt;On February 7, 2013, our partner &lt;a href="http://www.foxrothschild.com/attorneys/keith-mcmurdy.html "&gt;Keith McMurdy, Esq&lt;/a&gt;., posted an excellent entry on the &lt;a href="http://employeebenefits.foxrothschild.com/ "&gt;Employee Benefits Blog&lt;/a&gt; of Fox Rothschild LLP that merits republishing for our readers as well.&amp;nbsp;The post outlines some direct effects of the new HIPAA Omnibus Rule on employers and their health plans.&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&lt;a href="http://www.foxrothschild.com/attorneys/keith-mcmurdy.html "&gt;Keith McMurdy&lt;/a&gt; writes as follows:&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;On January 25, the new (final?) rules about HIPAA&amp;nbsp;Privacy under the HITECH&amp;nbsp;Act were issued in the &lt;a href="http://www.gpo.gov/fdsys/pkg/FR-2013-01-25/pdf/2013-01073.pdf  "&gt;Federal Register&lt;/a&gt;.&amp;nbsp; While the effect of the new rules may not be to substantially change the way HIPAA privacy is viewed, there are a number of action items for employers&amp;nbsp;as plan sponsors that have to be accomplished when these rules go into effect.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;There are two pieces of good news.&amp;nbsp; The first is that the general purpose of compliance remains the same.&amp;nbsp; Plan sponsors have to ensure PHI&amp;nbsp;is properly protected, refrain from impermissible disclosures and provide notices of security breaches.&amp;nbsp; The second is that the earliest possible deadline for compliance with the new rules is September 23, 2013, so there is some time to prepare.&amp;nbsp; But it is not a bad idea to start preparing now.&amp;nbsp; So let's consider the key changes.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&lt;b&gt;1. Tougher Security Breach Notification Standard&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;Under the old rule, the standard&amp;nbsp;for notification&amp;nbsp;to participants of a security breach was only necessary if&amp;nbsp;the release of information&amp;nbsp;&amp;quot;posed a significant risk of financial, reputational or other harm&amp;quot; to a covered person.&amp;nbsp; Now, that standard is tightened to apply to ANY&amp;nbsp;security breach unless the plan sponsor can prove &amp;quot;a low probability that the [PHI] has been compromised based on a risk assessment.&amp;quot;&amp;nbsp; This should encourage plan sponsors to tighten their security breach protections because any release, even things like accidental e-mails, can potentially become reportable events.&amp;nbsp; So the first step in compliance would be to review security standards and document steps taken to avoid security breaches.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&lt;b&gt;2.&amp;nbsp;Tougher Standards for Business Associates Agreements&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;Because the new rule provides for penalties to a covered entity for breaches by business associates, the default position is that plan sponsors should&amp;nbsp;be much more concerned&amp;nbsp;about how compliant their&amp;nbsp;business associates really are.&amp;nbsp;&amp;nbsp;Where in the past, plan sponsors may have felt comfortable simply handing off certain protection functions to service providers, the new rule makes it pretty clear that plan sponsors have to actually know that their business associates are HIPAA compliant and diligently seek to confirm that compliance.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&lt;b&gt;3.&amp;nbsp; New Privacy Notices for 2013 Open Enrollment&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;The new rule also requires that&amp;nbsp;plan sponsors add or amend their privacy notices:&lt;/p&gt;
&lt;ol type="1"&gt;
    &lt;li style="margin: 0in 0in 0pt"&gt;The notice must specifically state that the covered health plans are required to obtain plan participants' authorization to use or disclose psychotherapy notes, to use PHI for marketing purposes, to sell PHI, or to use or disclose PHI for any purpose not described in the notice as well as a statement explaining how plan participants may revoke an authorization.&lt;/li&gt;
    &lt;li style="margin: 0in 0in 0pt"&gt;The notices must state that the plans (other than a long-term care plan) are prohibited from using PHI that is genetic information for underwriting purposes&lt;/li&gt;
    &lt;li style="margin: 0in 0in 0pt"&gt;The notice must inform plan participants of their right to receive a notice when there is a breach of their unsecured PHI.&lt;/li&gt;
&lt;/ol&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;The new rules makes it clear that since this new language is a &amp;quot;material change,&amp;quot; plan sponsors are required to distribute this revised notice, even if they had just recently sent the old notice.&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&lt;b&gt;4.&amp;nbsp;Genetic Information and the GINA&amp;nbsp;Notice&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;The Genetic Information Non-Discrimination Act of 2008 (GINA)&amp;nbsp;prohibits discrimination based on genetic information.&amp;nbsp; The HIPAA Privacy Rule&amp;nbsp;now similarly&amp;nbsp;prohibits&amp;nbsp;HIPAA-covered plans from taking genetic information into consideration when offering incentives or discounts through a health risk assessment.&amp;nbsp; Because this modification of the Privacy Rule materially affects how a plan may use PHI, the HIPAA Privacy Rule requires that plan participants be informed in the plan's privacy notice of the prohibition on the use of PHI for underwriting purposes.&amp;nbsp; See the second item under Part 3, above.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;So in the midst of our struggles to comply with PPACA, plan sponsors should not forget about HIPAA&amp;nbsp;medical privacy concerns.&amp;nbsp; Start pulling together privacy notices, business associates agreements and plan documents for review and amendment.&amp;nbsp; Review your security practices to avoid even accidental breaches.&amp;nbsp; And be prepared to issue new notices as necessary for your next open enrollment.&amp;nbsp; For more detailed information about HIPAA and HITECH&amp;nbsp;Compliance, please make sure to check out our &lt;a href="http://hipaahealthlaw.foxrothschild.com/ "&gt;HIPAA&amp;nbsp;Blog&lt;/a&gt; as well.&amp;nbsp; More information means better compliance, which is always a good thing.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/HipaaHealthLaw/~4/jjJ9-Hkt1YU" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/HipaaHealthLaw/~3/jjJ9-Hkt1YU/</link>
         <guid isPermaLink="false">http://hipaahealthlaw.foxrothschild.com/2013/02/articles/privacy/the-new-and-improved-hipaahitech-rules-what-employers-need-to-know/</guid>
         <category domain="http://hipaahealthlaw.foxrothschild.com/tags">GINA</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Genetic Information Non-Discrimination Act of 2008</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">HIPAA</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">HITECH</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Health and Human Services</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">PHI</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">PPACA</category><category domain="http://hipaahealthlaw.foxrothschild.com/articles">Privacy &amp; Security</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Privacy Rule</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Security Breach Notification</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">protected health information</category>
         <pubDate>Sun, 17 Feb 2013 13:55:39 -0500</pubDate>
         <dc:creator>Michael Kline</dc:creator>
      
      <feedburner:origLink>http://hipaahealthlaw.foxrothschild.com/2013/02/articles/privacy/the-new-and-improved-hipaahitech-rules-what-employers-need-to-know/</feedburner:origLink></item>
            <item>
         <title>Collateral Effects of the Omnibus Rule: Exercise Caution in Using Past OCR Summaries on Large PHI Breaches as a Roadmap for Future Guidance</title>
         <description>&lt;p class="MsoNormal" style="margin: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;&lt;strong&gt;&lt;span style="font-weight: normal; mso-bidi-font-weight: bold"&gt;In&lt;/span&gt;&lt;/strong&gt; the wake of the post-Omnibus Rule (the &amp;ldquo;Rule&amp;rdquo;) frenzy, it is necessary to consider some collateral effects that the Rule may have brought about with respect to compliance with HIPAA/HITECH.&lt;span style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/span&gt;The Office of Civil Rights (&amp;ldquo;OCR&amp;rdquo;) summaries of closed investigations (the &amp;ldquo;Summaries&amp;rdquo;) &lt;a href="http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/breachtool.html   "&gt;posted&lt;/a&gt; on the U.S. Department of Health and Human Services (&amp;ldquo;HHS&amp;rdquo;) list (the &amp;ldquo;HHS List&amp;rdquo;) of breaches of unsecured PHI affecting 500 or more individuals (&amp;ldquo;List Breaches&amp;rdquo;) has been a source of meaningful guidance as &lt;a href="http://hipaahealthlaw.foxrothschild.com/ "&gt;discussed&lt;/a&gt; in previous posts on this blog. &lt;span style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/span&gt;For example, the summary (the &amp;ldquo;Tennessee Summary&amp;rdquo;) for a State of &lt;strong&gt;&lt;span style="font-weight: normal; mso-bidi-font-weight: bold"&gt;Tennessee Sponsored Group Health Plan breach (the &amp;ldquo;Tennessee Breach&amp;rdquo;) continues to provide an excellent road map of pre-Omnibus Rule actions for covered entities &lt;/span&gt;&lt;/strong&gt;(&amp;ldquo;CEs&amp;rdquo;) or business associates (&amp;ldquo;BAs&amp;rdquo;) &lt;span style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/span&gt;that suffer List Breaches or PHI breaches of any size.&amp;nbsp;&lt;span style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;font size="3" face="Times New Roman"&gt;While the Tennessee Breach itself dealt with mishandling of paper PHI and not electronic health records, the Tennessee Summary does give direction for early intervention by affected CEs or BAs before HHS knocks on their door.&lt;span style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/span&gt;However, while there was excellent compliance in the aftermath of the Tennessee Breach, advice from pre-Rule Summaries cannot be used without carefully taking into account the new requirements respecting PHI breaches under the Rule.&lt;span style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/span&gt;As will be further discussed below, the most important new requirement in this regard is the necessity for a CE, BA or subcontractor to analyze the level of risk of compromise of the affected PHI. &lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;u&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;The &lt;st1:place w:st="on"&gt;&lt;st1:state w:st="on"&gt;Tennessee&lt;/st1:state&gt;&lt;/st1:place&gt; Summary&lt;/font&gt;&lt;/font&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;u&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/u&gt;&lt;/b&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;The Tennessee Breach occurred on October 6, 2011 and involved approximately 1,770 &lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-font-weight: bold"&gt;enrollees with respect to names, addresses, birth dates and social security numbers.&lt;/span&gt;&lt;span style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/span&gt;According to the Tennessee Summary, a&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-font-weight: bold"&gt;n equipment operator at the state&amp;rsquo;s postal facility set the machine to insert four (4) pages per envelope instead of one (1) page per envelope, which caused the PHI of four individuals to be sent to one address per envelope.&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-font-weight: bold"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-font-weight: bold"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;The Tennessee Summary states that the CE did the following (with some parenthetical observations from the blog author):&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-font-weight: bold"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="text-indent: -0.5in; margin: 0in 0in 0pt 0.5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-font-weight: bold"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;1.&lt;span style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Retrained the equipment operator (suggesting that suspension and/or termination are not the only actions in appropriate cases with respect to dealing with employees involved with a PHI breach where rehabilitation is possible).&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="text-indent: -0.5in; margin: 0in 0in 0pt 0.5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-font-weight: bold"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;2.&lt;span style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Submitted a breach report to HHS (resulting in the posting on the HHS List).&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="text-indent: -0.5in; margin: 0in 0in 0pt 0.5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-font-weight: bold"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;3.&lt;span style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Provided notice to affected individuals.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="text-indent: -0.5in; margin: 0in 0in 0pt 0.5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-font-weight: bold"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;4.&lt;span style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Notified the media.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="text-indent: -0.5in; margin: 0in 0in 0pt 0.5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-font-weight: bold"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;5.&lt;span style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Created a toll-free number for information regarding the incident.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="text-indent: -0.5in; margin: 0in 0in 0pt 0.5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-font-weight: bold"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;6.&lt;span style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Posted notice on the CE&amp;rsquo;s website.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="text-indent: -0.5in; margin: 0in 0in 0pt 0.5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-font-weight: bold"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;7.&lt;span style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Modified policies to remove the social security number on templates for future mailings (a good policy whether paper or electronic PHI is involved).&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="text-indent: -0.5in; margin: 0in 0in 0pt 0.5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-font-weight: bold"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;8.&lt;span style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Offered identity theft protection to the affected individuals (a common decision for CEs and BAs based on the type of information that may have been compromised). &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="text-indent: -0.5in; margin: 0in 0in 0pt 0.5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-font-weight: bold"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;9.&lt;span style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Following the OCR investigation, reviewed its policies and procedures to ensure adequate safeguards are in place (with this disclosure in the Tennessee Summary, there is a suggestion that OCR continued to exercise some oversight or received reports after the investigation was finished).&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="text-indent: -0.5in; margin: 0in 0in 0pt 0.5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-font-weight: bold"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="text-indent: -0.5in; margin: 0in 0in 0pt 0.5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;b&gt;&lt;u&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;The &lt;st1:place w:st="on"&gt;&lt;st1:state w:st="on"&gt;Tennessee&lt;/st1:state&gt;&lt;/st1:place&gt; Breach in Retrospect after the Omnibus Rule&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="text-indent: -0.5in; margin: 0in 0in 0pt 0.5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;b&gt;&lt;u&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-font-weight: bold"&gt;There was no discussion in the Tennessee Summary of any analysis by the CE of the probable &amp;ldquo;risk of harm&amp;rdquo; from the Tennessee Breach under the proposed rule standards that prevailed prior to the Rule.&lt;span style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/span&gt;However, it is clear that, in the post-Rule period, a risk &lt;/span&gt;analysis&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-font-weight: bold"&gt; of the probability &lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: Arial"&gt;that the PHI &amp;ldquo;has been compromised&amp;rdquo; would be necessary for the CE; failure to do such an analysis may be a violation in itself.&lt;span style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Under the Rule, there is a presumption that a breach of PHI has taken place unless there is a low probability that the PHI has been compromised.&amp;nbsp; The four factor analysis that would have been required of the CE in the Tennessee Breach case had it happened after the effectiveness of the Rule encompasses the following (with parenthetical comments):&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: Arial"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="text-indent: -0.5in; margin: 0in 0in 0pt 0.5in"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: Arial"&gt;(i) &lt;span style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Identifying the nature and extent of the PHI involved, including types of identifiers and risk of re-identification (&lt;u&gt;i.e.&lt;/u&gt;, &lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-font-weight: bold"&gt;names, addresses, birth dates and social security numbers)&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: Arial"&gt;; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: Arial"&gt;&lt;o:p&gt;&lt;font size="3" face="Times New Roman"&gt;&amp;nbsp;&lt;/font&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="text-indent: -0.5in; margin: 0in 0in 0pt 0.5in"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: Arial"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;(ii) &lt;span style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Identifying the unauthorized person(s) who impermissibly used the PHI or to whom the disclosure was made (in the case of the Tennessee Breach, subscribers to the health plan who were not individuals that had an obligation of their own to comply with HIPAA/HITECH); &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: Arial"&gt;&lt;o:p&gt;&lt;font size="3" face="Times New Roman"&gt;&amp;nbsp;&lt;/font&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="text-indent: -0.5in; margin: 0in 0in 0pt 0.5in"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: Arial"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;(iii)&amp;nbsp;&lt;span style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Determining whether the PHI was actually acquired or viewed or, alternatively, if only the opportunity existed for the PHI to be acquired or viewed (in the case of the Tennessee Breach, there is a likelihood that numerous recipients of the PHI or others without the right to view such PHI did in fact view it); and &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: Arial"&gt;&lt;o:p&gt;&lt;font size="3" face="Times New Roman"&gt;&amp;nbsp;&lt;/font&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="text-indent: -0.5in; margin: 0in 0in 0pt 0.5in"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: Arial"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;(iv) &lt;span style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;The extent to which risk to the PHI&amp;nbsp;was mitigated (items 3, 4, 5, 6 and 8 above appear to be potential mitigating factors).&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;font size="3" face="Times New Roman"&gt;&amp;nbsp;&lt;/font&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt"&gt;&lt;font size="3" face="Times New Roman"&gt;As stated in an earlier postings &lt;a href="http://hipaahealthlaw.foxrothschild.com/2012/10/articles/breaches/as-the-breach-parade-passes-500-marchers-should-there-be-a-posting-on-the-hhs-list-for-a-third-massachusetts-eye-and-ear-infirmary-breach/ "&gt;here&lt;/a&gt; and &lt;a href="http://hipaahealthlaw.foxrothschild.com/2012/10/articles/breaches/as-the-parade-of-major-phi-breaches-marches-ever-onward-where-have-all-the-ocr-summaries-gone/ "&gt;here&lt;/a&gt;, no Summary has been posted by OCR for any List Breach that occurred later than October 6, 2011.&amp;nbsp;Additionally, no Summary has been posted by OCR for any List Breach involving a BA that occurred later than February 1, 2011.&lt;span style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/span&gt;While the Summaries continue to provide highly useful information for CEs, BAs and subcontractors relative to confronting PHI breaches, large and small, they must be analyzed with appropriate care and attention paid to changes brought about by the Rule.&lt;span style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/span&gt;It may be that a concern&amp;nbsp;of OCR about potential confusion&amp;nbsp;which could be created by publishing pre-Rule Summaries&amp;nbsp;has prevented OCR from making recent postings of Summaries on the HHS List.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/HipaaHealthLaw/~4/6k4fyB8XlB4" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/HipaaHealthLaw/~3/6k4fyB8XlB4/</link>
         <guid isPermaLink="false">http://hipaahealthlaw.foxrothschild.com/2013/02/articles/breaches/collateral-effects-of-the-omnibus-rule-exercise-caution-in-using-past-ocr-summaries-on-large-phi-breaches-as-a-roadmap-for-future-guidance/</guid>
         <category domain="http://hipaahealthlaw.foxrothschild.com/tags">HHS</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">HIPAA</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Health and Human Services</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">OCR</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Office of Civil Rights</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">PHI</category><category domain="http://hipaahealthlaw.foxrothschild.com/articles">Security Breach Notification </category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">State of Tennessee Sponsored Group Health</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">business associate</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">covered entity</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">protected health information</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">subcontractor</category>
         <pubDate>Fri, 01 Feb 2013 14:29:37 -0500</pubDate>
         <dc:creator>Michael Kline</dc:creator>
      
      <feedburner:origLink>http://hipaahealthlaw.foxrothschild.com/2013/02/articles/breaches/collateral-effects-of-the-omnibus-rule-exercise-caution-in-using-past-ocr-summaries-on-large-phi-breaches-as-a-roadmap-for-future-guidance/</feedburner:origLink></item>
            <item>
         <title>HIPAA "Mega Rule", Meet "Super BAA":  The CMS Data Use Agreement</title>
         <description>&lt;p&gt;The recent release of the HIPAA/HITECH &amp;ldquo;mega rule&amp;rdquo; or &amp;ldquo;omnibus rule&amp;rdquo; has given bloggers and lawyers like us plenty of topics for analysis and debate, as well as some tools with which to prod covered entities, business associates and subcontractors to put HIPAA/HITECH-compliant Business Associate Agreements (&amp;ldquo;BAAs&amp;rdquo;) in place.&amp;nbsp;It&amp;rsquo;s also a reminder to read BAAs that are already in place, and to make sure the provisions accurately describe how and why protected health information (&amp;ldquo;PHI&amp;rdquo;) is to be created, received, maintained, and/or transmitted.&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;If you are an entity that participates in the &lt;a href="http://www.cms.gov/Medicare/Medicare-Fee-for-Service-Payment/sharedsavingsprogram/index.html?redirect=/sharedsavingsprogram/"&gt;Medicare Shared Savings Program&lt;/a&gt; as a Medicare Accountable Care Organization (&amp;ldquo;ACO&amp;rdquo;), your ability to access patient data from Medicare depends on your having signed the &lt;a href="http://www.cms.gov/Medicare/Medicare-Fee-for-Service-Payment/sharedsavingsprogram/Downloads/Data-Use-Agreement.pdf"&gt;CMS Data Use Agreement &lt;/a&gt;(the &amp;ldquo;Data Use Agreement&amp;rdquo;).&amp;nbsp;Just as covered entities, business associates, and subcontractors should read and fully understand their BAAs, Medicare ACOs should make sure they are aware of several Data Use Agreement provisions that are more stringent than provisions typically included in a BAA and that may come as a surprise.&amp;nbsp;Here are ten provisions from the Data Use Agreement worth reviewing, whether you are a Medicare ACO or any other business associate or subcontractor, as these may very well resurface in some form in the &amp;ldquo;Super BAA&amp;rdquo; of the future:&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;1.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CMS (the covered entity) retains ownership rights in the patient data furnished to the ACO.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;2.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The ACO may only use the patient data for the purposes enumerated in the Data Use Agreement.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;3.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The ACO may not grant access to the patient data except as authorized by CMS.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;4.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The ACO agrees that, within the ACO and its agents, access to patient data will be limited to the minimum amount of data and minimum number of individuals necessary to achieve the stated purposes.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;5.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The ACO will only retain the patient data (and any derivative data) for one year or until 30 days after the purpose specified in the Data Use Agreement is completed, whichever is earlier, and the ACO must destroy the data and send written certification of the destruction to CMS within 30 days.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;6.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The ACO must establish administrative, technical, and physical safeguards that meet or exceed standards established by the Office of Management and Budget and the National Institute of Standards and Technology.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;7.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The ACO acknowledges that it is prohibited from using unsecured telecommunications, including the Internet, to transmit individually identifiable, bidder identifiable or deducible information derived from the patient files.&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;8.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The ACO agrees not to disclose any information derived from the patient data, even if the information does not include direct identifiers, if the information can, by itself or in combination with other data, be used to deduce an individual&amp;rsquo;s identity.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;9.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The ACO agrees to abide by CMS&amp;rsquo;s cell size suppression policy (which stipulates that no cell of 10 or less may be displayed).&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;And last, but certainly not least:&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;10. &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The ACO agrees to report to CMS any breach of personally identifiable information from the CMS data file(s), loss of these data, or disclosure to an unauthorized person by telephone or email &lt;b&gt;within one hour.&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;While the undertakings of a Medicare ACO and the terminology in the Data Use Agreement for protection of patient data may differ from those of covered entities, business associates and subcontractors and their BAAs under the HIPAA/HITECH regulations, they have many striking similarities and purposes.&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/HipaaHealthLaw/~4/xmSM41wrPE8" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/HipaaHealthLaw/~3/xmSM41wrPE8/</link>
         <guid isPermaLink="false">http://hipaahealthlaw.foxrothschild.com/2013/01/articles/privacy/hipaa-mega-rule-meet-super-baa-the-cms-data-use-agreement/</guid>
         <category domain="http://hipaahealthlaw.foxrothschild.com/tags">ACO</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Accountable  Care Organization</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">BAA</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">CMS</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">CMS Data Use Agreement</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Centers for Medicare and Medicaid Services</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">HIPAA</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">HIPAA Mega Rule</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">HIPAA Omnibus Rule</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">HITECH</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Medicare</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">PHI</category><category domain="http://hipaahealthlaw.foxrothschild.com/articles">Privacy &amp; Security</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">business associate agreements</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">patient data</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">protected health information</category>
         <pubDate>Thu, 24 Jan 2013 11:17:21 -0500</pubDate>
         <dc:creator>Elizabeth Litten</dc:creator>
      
      <feedburner:origLink>http://hipaahealthlaw.foxrothschild.com/2013/01/articles/privacy/hipaa-mega-rule-meet-super-baa-the-cms-data-use-agreement/</feedburner:origLink></item>
            <item>
         <title>Urgent - Verify Your Business Associate and Subcontractor Agreements by This Friday 1/25/13 to Qualify for Extension</title>
         <description>&lt;p&gt;The September 23, 2013 deadline for updating Business Associate Agreements is extended for one year under the Omnibus Rule for covered entities who have compliant Business Associate Agreements in place by &lt;strong&gt;Friday, January 25, 2013&lt;/strong&gt;. This also applies to agreements between Business Associates and their subcontractors.&lt;/p&gt;
&lt;p&gt;Covered Entities and Business Associates (as well as Business Associates&amp;nbsp;and their subcontractors) may continue to rely on&amp;nbsp;those agreements for up to one year beyond the compliance date of the modifications, regardless of whether the contract meets the applicable contract requirements in the Omnibus Rule. This includes existing written agreements between business associates and subcontractors&amp;nbsp;under which such subcontractors agree to the same restrictions and conditions that apply to the business associate.&amp;nbsp;Such contracts are deemed to be compliant with the modifications to the Rules until either the covered entity or business associate has renewed or modified the contract following the compliance date of the modifications, or until &lt;strong&gt;September 23, 2014&lt;/strong&gt; (one year after the compliance date), whichever is sooner.&amp;nbsp;&amp;quot;Evergreen&amp;quot; contracts which automatically renew also qualify for the extension.&lt;/p&gt;
&lt;p style="margin-left: 40px"&gt;&lt;u&gt;Covered Entities&lt;/u&gt; (providers, health plans/insurers, and clearinghouses) should verify that they have current signed&amp;nbsp;business associate agreements in place no later than this Friday in order to be grandfathered&amp;nbsp;for an extra year.&lt;/p&gt;
&lt;p style="margin-left: 40px"&gt;&lt;u&gt;Business Associates&lt;/u&gt;&amp;nbsp;who have delegated functions to subcontractors involving PHI need to make sure they have signed written agreements in place that meet the standards of the existing rule under which the subcontractors agree to follow HIPAA.&amp;nbsp;&amp;nbsp;&amp;nbsp;This is where there may be more gaps, since many Business Associates&amp;nbsp;may have been unaware of&amp;nbsp;their obligations to assure compliance by&amp;nbsp;their subcontractors.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: 10pt"&gt;Even grandfathered Business Associate Agreements&amp;nbsp;and subcontractor agreements should be reviewed to see if the contracted party (business associate&amp;nbsp;or subcontractor) is acting as an agent of the Covered Entity or&amp;nbsp;Business Associate.&amp;nbsp; If it is, the date on which a breach is discovered (or should have been discovered) is imputed up contractual chain and could mean that the Covered Entity&amp;nbsp;is responsible for reporting breaches it knows nothing about.&lt;/span&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;If you need help determining&amp;nbsp;whether you&amp;nbsp;qualify for grandfathering, please contact your Fox Rothschild attorney immediately&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/HipaaHealthLaw/~4/GXnagRz2oE0" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/HipaaHealthLaw/~3/GXnagRz2oE0/</link>
         <guid isPermaLink="false">http://hipaahealthlaw.foxrothschild.com/2013/01/articles/business-associates/urgent-verify-your-business-associate-and-subcontractor-agreements-by-this-friday-12513-to-qualify-for-extension/</guid>
         <category domain="http://hipaahealthlaw.foxrothschild.com/articles">HIPAA Business Associates</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">business associate</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">deadline</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">grandfathering</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">subcontractor</category>
         <pubDate>Wed, 23 Jan 2013 10:59:15 -0500</pubDate>
         <dc:creator>William Maruca</dc:creator>
      
      <feedburner:origLink>http://hipaahealthlaw.foxrothschild.com/2013/01/articles/business-associates/urgent-verify-your-business-associate-and-subcontractor-agreements-by-this-friday-12513-to-qualify-for-extension/</feedburner:origLink></item>
            <item>
         <title>This Just In: Guidance for Health Care Providers, and the Omnibus Rule</title>
         <description>&lt;p&gt;With gun violence and mental health concerns in the headlines, the Office of Civil Rights of the Department of Health and Human Services has published a &lt;a href="http://www.hhs.gov/ocr/office/lettertonationhcp.pdf"&gt;letter to health care providers&lt;/a&gt; clarifying when it is permissible to reveal PHI when a patient is reasonably believed to present a serious danger to himself or others.&amp;nbsp;&amp;nbsp;&amp;nbsp;The long-awaited&amp;nbsp;&lt;a href="https://s3.amazonaws.com/public-inspection.federalregister.gov/2013-01073.pdf"&gt;HIPAA Omnibus Rule&lt;/a&gt;, finally released yesterday, also addresses&amp;nbsp;concerns about how to balance patient privacy with public safety.&lt;/p&gt;
&lt;p&gt;Long before HIPAA, court decisions have supported the right, and the duty, of health care providers to&amp;nbsp;reveal a patient's health information&amp;nbsp;where&amp;nbsp;it may be necessary to protect the patient or the public from&amp;nbsp;identifiable&amp;nbsp;risks of harm.&amp;nbsp; The seminal case is the 1974 decision of the California Supreme Court in &lt;a href="http://www.stanford.edu/group/psylawseminar/Tarsoff%20I.htm"&gt;Tarasoff v. the Regents of the University of California&lt;/a&gt;.&amp;nbsp;In that case, the family of a murder victim brought suit based on the failure of the university psychologist who had treated her killer to warn her that he had threatened her life during therapy sessions. The psychologist had recommended that the patient be hospitalized and did inform campus police, but he was not deemed dangerous enough to detain involuntarily, and later carried out his&amp;nbsp;plan.&amp;nbsp;&amp;nbsp; This landmark case established a duty of health care providers to warn&amp;nbsp;potential victims&amp;nbsp;and the authorities when an individual makes a credible threat of violence.&amp;nbsp; Most states follow the &lt;em&gt;Tarasoff&lt;/em&gt; rule, either by statute or case law.&lt;/p&gt;
&lt;p&gt;As the recent OCR letter indicates, the HIPAA rule permits disclosures in similar situations.&amp;nbsp;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;When a health care provider believes in good faith that such a warning is necessary to prevent or lessen a serious and imminent threat to the health or safety of the patient or others, the Privacy Rule allows the provider, consistent with applicable law and standards of ethical conduct, to alert those persons whom the provider believes are reasonably able to prevent or lessen the threat. Further, the provider is presumed to have had a good faith belief when his or her belief is based upon the provider&amp;rsquo;s actual knowledge (i.e., based on the provider&amp;rsquo;s own interaction with the patient) or in reliance on a credible representation by a person with apparent knowledge or authority (i.e., based on a credible report from a family member of the patient or other person). These provisions may be found in the Privacy Rule at 45 CFR &amp;sect; 164.512(j).&lt;/p&gt;
&lt;p&gt;Under these provisions, a health care provider may disclose patient information, including information from mental health records, if necessary, to law enforcement, family members of the patient, or any other persons who may reasonably be able to prevent or lessen the risk of harm. For example, if a mental health professional has a patient who has made a credible threat to inflict serious and imminent bodily harm on one or more persons, HIPAA permits the mental health professional to alert the police, a parent or other family member, school administrators or campus police, and others who may be able to intervene to avert harm from the threat.&lt;span style="font-size: larger"&gt;&lt;font size="3"&gt; &lt;/font&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;font face="TimesNewRoman"&gt;In the spirit of the &amp;quot;imminent threat&amp;quot;&amp;nbsp;exception, and recalling the famous &lt;em&gt;Tarasoff&lt;/em&gt; decision quote, &amp;quot;&lt;span style="mso-bidi-font-family: 'Courier New'"&gt;The protective privilege ends where the public peril begins,&amp;quot;&amp;nbsp; the Omnibus rule resolves a controversy over when and how student immunization records may be shared with school officials. The rule simplifies the process to permit oral or written authorization to health care providers or other covered entities to supply this information to schools where required by state law for admission.&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;span id="1358540299911S" style="display: none"&gt;The final rule adopts the proposal to&lt;/span&gt;&lt;span id="1358540303709S" style="display: none"&gt; &lt;/span&gt;&lt;span class="st"&gt;The final rule adopts the proposal to &lt;/span&gt;amend &amp;sect; 164.512(b)(1) by adding a new paragraph that permits a covered entity to disclose proof of immunization to a school where State or other law requires the school to have such information prior to admitting the student. While written authorization will no longer be required to permit this disclosure, covered entities will still be required to obtain agreement, which may be oral, from a parent, guardian or other person acting in loco parentis for the individual, or from the individual himself or herself, if the individual is an adult or emancipated minor. We believe that the option to provide oral agreement for the disclosure of student immunization records will relieve burden on parents, schools, and covered entities, and greatly facilitate the role that schools play in public health, while still giving parents the opportunity to consider whether to agree to the disclosure of this information.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Documentation of the parental permission is still required, but the form of that documentation is up to the covered entity.&amp;nbsp; Note that once a school is in possession of a student's PHI,&amp;nbsp;the&amp;nbsp;school's handling of those records&amp;nbsp;is governed by the &lt;a href="http://www2.ed.gov/policy/gen/guid/fpco/ferpa/index.html"&gt;Family Educational Rights and Privacy Act (FERPA)&lt;/a&gt;, not HIPAA.&lt;/p&gt;
&lt;p&gt;The Omnibus rule is described by OCR director Leon Rodriguez as&amp;nbsp;making &amp;quot;the most sweeping changes to the HIPAA Privacy and Security Rules since they were first implemented.&amp;quot;&amp;nbsp; Many of these changes appeared in the Notice of Proposed Rulemaking published on July 14, 2010.&amp;nbsp; We will be analyzing these changes in forthcoming posts in the near future.&lt;span id="1358540302108E" style="display: none"&gt;&amp;nbsp;&lt;/span&gt;&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In light of the&amp;nbsp;Obama Administration's&amp;nbsp;initiatives following the Sandy Hook,&amp;nbsp;CT and Aurora, CO tragedies, HHS appears to be&amp;nbsp;responding to criticism of overly restrictive privacy rules that allegedly would have prevented disclosure of mental health information that may have saved lives.&amp;nbsp; Clearly the current rules permit disclosure of imminent, concrete threats directed at specific targets, and there is no indication that either of the&amp;nbsp;gunmen had&amp;nbsp;expressed any such threats in advance to healthcare&amp;nbsp;providers or otherwise.&amp;nbsp;&amp;nbsp;Nevertheless, the time may be right to dispel any misinformation about when such threats can be legally communicated to authorities and potential victims.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/HipaaHealthLaw/~4/Qj4Hx-KUjzQ" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/HipaaHealthLaw/~3/Qj4Hx-KUjzQ/</link>
         <guid isPermaLink="false">http://hipaahealthlaw.foxrothschild.com/2013/01/articles/hipaa-enforcement/this-just-in-guidance-for-health-care-providers-and-the-omnibus-rule/</guid>
         <category domain="http://hipaahealthlaw.foxrothschild.com/articles">HIPAA Enforcement</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Imminent threat</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">duty to warn</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">immunization</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">mental health</category>
         <pubDate>Fri, 18 Jan 2013 11:07:27 -0500</pubDate>
         <dc:creator>William Maruca</dc:creator>
      
      <feedburner:origLink>http://hipaahealthlaw.foxrothschild.com/2013/01/articles/hipaa-enforcement/this-just-in-guidance-for-health-care-providers-and-the-omnibus-rule/</feedburner:origLink></item>
            <item>
         <title>The Parade of Major Reported PHI Breaches Creeps Ahead to 525  - Theft Continues to Dominate the Numbers</title>
         <description>&lt;p&gt;This &lt;a href="http://hipaahealthlaw.foxrothschild.com  "&gt;blog series&lt;/a&gt; has been following breaches of Protected Health Information (&amp;ldquo;PHI&amp;rdquo;) that have been reported on the U.S. Department of Health and Human Services (&amp;ldquo;HHS&amp;rdquo;) ever-lengthening parade &lt;a href="http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/breachtool.html "&gt;list (the &amp;ldquo;HHS List&amp;rdquo;)&lt;/a&gt; of breaches of unsecured PHI affecting 500 or more individuals (the &amp;ldquo;List Breaches&amp;rdquo;).&amp;nbsp;As of January 1, 2013 (and as of today), there were 525 postings of List Breaches.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;A&amp;nbsp;previous blog post &lt;a href="http://hipaahealthlaw.foxrothschild.com/2012/03/articles/breaches/the-parade-of-major-reported-phi-breaches-hits-400-theft-is-the-primary-type-of-breach/ "&gt;reported&lt;/a&gt; that, on February 24, 2012, HHS listed the 400th List Breach.&amp;nbsp;As the first postings on the HHS List occurred on March 4, 2010, an average of about 200 postings of List Breaches were recorded in each of its first two years.&amp;nbsp;However, in the 10-plus months between February 24, 2012 and January 1, 2013, 125 additional List Breaches were posted, which on an annualized twelve month period basis would translate into 150 List Breaches.&amp;nbsp;It is not yet clear whether the lower volume of List Breaches since February 2012 is attributable to increased caution and better practices in protecting PHI on the part of covered entities (&amp;ldquo;CEs&amp;rdquo;) and business associates (&amp;ldquo;BAs&amp;rdquo;), greater use of encryption and other practices to protect PHI, slower postings of List Breaches by HHS, other factors or a combination thereof.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;Of the total of 525 List Breaches posted through January 1, 2013, there were approximately 274 (52.2%) events shat attributed the type of breach to involve &amp;ldquo;theft&amp;rdquo; of all kinds, including laptops, other portable electronic devices, desktop computers, network servers, paper records and others.&amp;nbsp;If the 60 additional List Breaches listing the category of&amp;nbsp;&amp;ldquo;loss&amp;rdquo; of all types is added to the 274 &amp;ldquo;theft&amp;rdquo; events, the total for the two categories swells to approximately 334 or 63.6% of the 525 posted List Breaches.&amp;nbsp;Combining the two categories appears to make some sense since it is likely that a number of the List Breaches categorized as a &amp;ldquo;loss&amp;rdquo; event may have involved some theft aspects.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;Even more revealing may be the fact that approximately 193 (36.8%) of the 525 List Breaches listed the cause or partial cause of the breach to be &amp;ldquo;theft&amp;rdquo; or &amp;ldquo;loss&amp;rdquo; respecting laptops or other portable electronic devices. &amp;nbsp;Theft or loss of laptops or other portable electronic devices thus constituted 51.6% of the 334 List Breaches that involved reported theft or loss.&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;Over the last 10 months since the number of List Breaches passed 400, it appears that the relative percentage of List Breaches attributable to theft and loss is trending mildly upward.&amp;nbsp;Of the 125 additional reported List Breaches, approximately 86 or 68.8% listed theft or loss as the source of the PHI breach.&amp;nbsp;The number of such 125 List Breaches that reported theft or loss of laptops or other portable electronic devices was 37 or 29.6%, a lower percentage than the 36.8% for all 525 List Breaches.&amp;nbsp; The sample sizes are relatively small, so that further following of these numbers is warranted.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;My partner, William Maruca, Esq., recently &lt;a href="http://hipaahealthlaw.foxrothschild.com/2013/01/articles/hipaa-enforcement/ocr-announces-first-under-500-breach-settlement/ "&gt;posted&lt;/a&gt; a blog entry highlighting the fact that the first breach settlement announcement by HHS in 2013 (the &amp;ldquo;2013 Settlement&amp;rdquo;) involved a $50,000 fine based on theft of a laptop containing 441 patients&amp;rsquo; unencrypted data.&amp;nbsp;It was&amp;nbsp;the first fine by HHS for a PHI security breach that involved fewer than 500 individuals and, therefore, was below the threshold for a List Breach.&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;While the parade of List Breaches continues to lengthen, the 2013 Settlement underscores the fact that there are many more PHI security breaches involving fewer than 500 individuals.&amp;nbsp;The PHI security breaches that are not List Breaches are receiving increased scrutiny by HHS.&amp;nbsp;As this blog series has emphasized in the past, it may become more a question of when a CE or BA will suffer a PHI security breach and how severe the breach will be, rather than if it will suffer a breach.&amp;nbsp;All CEs and BAs must exercise vigilance and use recommended protection procedures to avoid all PHI security breaches, not just large List Breaches.&amp;nbsp;The continuing proliferation of the use of portable electronic devices to receive, access and store PHI should be monitored, as it can be expected that this type of security breach will continue to expand.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/HipaaHealthLaw/~4/Z5htNDW0u2E" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/HipaaHealthLaw/~3/Z5htNDW0u2E/</link>
         <guid isPermaLink="false">http://hipaahealthlaw.foxrothschild.com/2013/01/articles/breaches/the-parade-of-major-reported-phi-breaches-creeps-ahead-to-525-theft-continues-to-dominate-the-numbers/</guid>
         <category domain="http://hipaahealthlaw.foxrothschild.com/tags">HHS</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Health and Human Services</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">PHI</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">PHI Security Breach Notification</category><category domain="http://hipaahealthlaw.foxrothschild.com/articles">Security Breach Notification </category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">business associate</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">covered entity</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">protected health information</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">security breach</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">theft of laptops</category>
         <pubDate>Tue, 08 Jan 2013 16:16:57 -0500</pubDate>
         <dc:creator>Michael Kline</dc:creator>
      
      <feedburner:origLink>http://hipaahealthlaw.foxrothschild.com/2013/01/articles/breaches/the-parade-of-major-reported-phi-breaches-creeps-ahead-to-525-theft-continues-to-dominate-the-numbers/</feedburner:origLink></item>
            <item>
         <title>OCR Announces First "Under 500" Breach Settlement</title>
         <description>&lt;p&gt;&lt;span style="font-size: 10pt"&gt;The first breach settlement announcement of the new year breaks new ground - a $50,000 fine based on theft of a laptop containing 441 patients' unencrypted data.&amp;nbsp;It's&amp;nbsp;the first settlement of a breach involving fewer than 500 individuals.&amp;nbsp; There was no indication that any PHI&amp;nbsp;was improperly viewed or accessed.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 12pt 0in 0pt"&gt;&lt;span style="font-size: 10pt"&gt;In a &lt;a href="http://www.hhs.gov/news/press/2013pres/01/20130102a.html"&gt;&lt;font color="#800080"&gt;press release&lt;/font&gt;&lt;/a&gt; issued January 2, 2013, OCR announced the negotiated resolution of a breach by the Hospice of North Idaho (HONI), which began when HONI&amp;nbsp;reported the June 2010 laptop theft.&amp;nbsp; The investigation revealed that HONI had not conducted a risk analysis to safeguard ePHI and had not adopted policies or procedures to address mobile device security.&lt;/span&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p style="margin: 12pt 0in 0pt"&gt;&lt;span style="font-size: 10pt"&gt;&amp;ldquo;This action sends a strong message to the health care industry that, regardless of size, covered entities must take action and will be held accountable for safeguarding their patients&amp;rsquo; health information.&amp;rdquo; said OCR Director Leon Rodriguez. &amp;ldquo;Encryption is an easy method for making lost information unusable, unreadable and undecipherable.&amp;rdquo;&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p style="margin: 12pt 0in 0pt"&gt;&lt;span style="font-size: 10pt"&gt;The Resolution Agreement, which appears &lt;a href="http://www.hhs.gov/ocr/privacy/hipaa/enforcement/examples/honi-agreement.pdf"&gt;here&lt;/a&gt;,&amp;nbsp;emphasized the hospice agency's&amp;nbsp;failure to anticipate the risk of loss of unprotected data on mobile devices which were commonly used&amp;nbsp;by its staff in field work:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p style="margin: 12pt 0in 0pt"&gt;&lt;span style="font-size: 10pt"&gt;&amp;quot;In particular, HONI did not evaluate the likelihood and impact of potential risks to the confidentiality of electronic PHI maintained in and transmitted using portable devices, implement appropriate security measures to address such potential risks, document the chosen security measures and the rationale for adopting those measures, and maintain on an on-going basis reasonable and appropriate security measures.&amp;quot;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p style="margin: 12pt 0in 0pt"&gt;&lt;span style="font-size: 10pt"&gt;The emphasis on a small covered entity's lack of analysis and risk assessment is reminiscent of OCR's settlement with two-physician &lt;a href="http://hipaahealthlaw.foxrothschild.com/2012/04/articles/hipaa-enforcement/first-small-physician-practice-joins-the-parade-of-hipaa-phi-security-breaches/"&gt;&lt;span style="color: purple"&gt;Phoenix Cardiac Surgery, P.C.&lt;/span&gt;&lt;/a&gt; announced in April 2012, another case widely considered to be a warning to similarly situated entities. Note that HONI&amp;nbsp;disputes the allegations in its own &lt;a href="http://s319030518.onlinehome.us/file_download/5/OCR%20Press%20Release%20Final.pdf"&gt;press release.&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 12pt 0in 0pt"&gt;&lt;span style="font-size: 10pt"&gt;OCR also required HONI&amp;nbsp;to enter into a two-year corrective action plan, which&amp;nbsp;requires HONI&amp;nbsp;to investigate any information indicating that any workforce member may have failed to comply with its Privacy and Security policies and procedures, and report the details of any such failure including sanctions imposed and steps taken to prevent recurrence.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 12pt 0in 0pt"&gt;&lt;span style="font-size: 10pt"&gt;Some lessons can be taken away from the HONI settlement. &lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 12pt 0in 0pt"&gt;&lt;span style="font-size: 10pt"&gt;First, &lt;strong&gt;&lt;i&gt;encryption&lt;/i&gt;&lt;/strong&gt; of ePHI&amp;nbsp;is critical! Given the prevalance of breaches associated with lost and stolen laptops, it is often forgotten that the loss of unreadable encrypted data is generally not a HIPAA breach.&amp;nbsp; &lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 12pt 0in 0pt"&gt;&lt;span style="font-size: 10pt"&gt;Next, all organizations but especially those like hospices, home health agencies and other entities with mobile workforces must prioritize securing &lt;strong&gt;&lt;i&gt;mobile devices&lt;/i&gt;&lt;/strong&gt;. For starters, refer to OCR's&amp;nbsp;guidance&amp;nbsp;entitled&amp;nbsp;&lt;a href="http://www.healthit.gov/providers-professionals/your-mobile-device-and-health-information-privacy-and-security"&gt;&lt;font color="#800080"&gt;Your Mobile Device and Health Information Privacy and Security&lt;/font&gt;&lt;/a&gt;, which is definitely worth reading.&amp;nbsp; Some of the advice seems to be common sense (password protection, remote wiping or disabiling, firewall and security software, avoiding file-sharing applications)&amp;nbsp;but needs to be enforced organization-wide, particularly in today's &amp;quot;bring your own device&amp;quot; environment.&amp;nbsp;&amp;nbsp; OCR has even created a handy one-page&amp;nbsp;&lt;a href="http://www.healthit.gov/sites/default/files/fact-sheet-take-steps-to-protect-information.pdf"&gt;&lt;font color="#800080"&gt;Fact Sheet&lt;/font&gt;&lt;/a&gt;&amp;nbsp;with useful&amp;nbsp;mobile device security tips.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 12pt 0in 0pt"&gt;&lt;span style="font-size: 10pt"&gt;Loss and theft of mobile devices may be&amp;nbsp;inevitable, but protection of the data those&amp;nbsp;devices contain is&amp;nbsp;not as&amp;nbsp;challenging as&amp;nbsp;many think, and effectively implementing such protection should be a priority for 2013.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/HipaaHealthLaw/~4/1l1yQ0tJ3eE" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/HipaaHealthLaw/~3/1l1yQ0tJ3eE/</link>
         <guid isPermaLink="false">http://hipaahealthlaw.foxrothschild.com/2013/01/articles/hipaa-enforcement/ocr-announces-first-under-500-breach-settlement/</guid>
         <category domain="http://hipaahealthlaw.foxrothschild.com/articles">HIPAA Enforcement</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">breach</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">laptop</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">settlement</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">theft</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">under 500</category>
         <pubDate>Fri, 04 Jan 2013 13:36:29 -0500</pubDate>
         <dc:creator>William Maruca</dc:creator>
      
      <feedburner:origLink>http://hipaahealthlaw.foxrothschild.com/2013/01/articles/hipaa-enforcement/ocr-announces-first-under-500-breach-settlement/</feedburner:origLink></item>
            <item>
         <title>Countdown to 2013 and the HITECH "Mega Rule":  Ten New Year's Resolutions to Protect Health Information</title>
         <description>&lt;p&gt;We have written several times in this &lt;a href="http://hipaahealthlaw.foxrothschild.com/  "&gt;blog series&lt;/a&gt; about the long-awaited (some would assert long overdue) HIPAA &amp;ldquo;Mega Rule.&amp;rdquo;&amp;nbsp;What was highly &lt;a href="http://hipaahealthlaw.foxrothschild.com/2012/08/articles/privacy/as-we-all-continue-to-anticipate-the-hipaahitech-mega-rule-from-hhs-we-can-test-our-prognosticating-skills/"&gt;anticipated&lt;/a&gt; for the summer of 2012 has become the winter of discontent and a new year for eager HIPAA professionals.&amp;nbsp;Below are ten HIPAA resolutions worth making for 2013 for anyone who has contact with protected health information (PHI), even without the benefit of the Mega Rule.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;10.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I will ask for a copy of my employer&amp;rsquo;s HIPAA Policies and Procedures.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;9.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I will read them.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;8.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I will compare what they say with what I do with PHI and will identify and correct discrepancies.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;7.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I will not snoop through PHI of others or access or use any PHI I do not need in order to do my job.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;6.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; If I get PHI from or send PHI to a third party (outside my employer) as part of my job, I will find out whether my employer has a Business Associate Agreement (&amp;ldquo;BAA&amp;rdquo;) in place with that third party (or has decided one is not needed).&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;5.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I will learn how to encrypt (as per National Institute of Standards and Technology) PHI before I save it or send it.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;4.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I will check my laptop, smartphone, or other portable device for encryption capability and make sure it is activated.&amp;nbsp;I will also check for any unencrypted PHI that may be lurking on my portable device(s).&amp;nbsp;I will encrypt or remove such PHI (if consistent with the HIPAA Policies and Procedures of my employer and any BAAs).&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;3.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I will investigate the &amp;ldquo;chain of control&amp;rdquo; of PHI before I send it to make sure it will not end up outside the jurisdiction of the United States.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;2.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I will educate myself as to whether and how PHI might be de-identified and will recommend that my employer consider a policy of de-identification in accordance with guidance &lt;a href="http://www.hhs.gov/ocr/privacy/hipaa/understanding/coveredentities/De-identification/hhs_deid_guidance.pdf "&gt;published&lt;/a&gt; by the Office of Civil Rights of the Department of Health and Human Services.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;1.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Even if I&amp;rsquo;ve accomplished resolution # 4, I will not leave my laptop, smartphone or other portable device containing PHI in plain sight inside my parked car, especially while at lunch.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;If everyone were to make and follow these resolutions, we all will have a Happy HIPAA New Year.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/HipaaHealthLaw/~4/RPQcuvPGxZI" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/HipaaHealthLaw/~3/RPQcuvPGxZI/</link>
         <guid isPermaLink="false">http://hipaahealthlaw.foxrothschild.com/2012/12/articles/privacy/countdown-to-2013-and-the-hitech-mega-rule-ten-new-years-resolutions-to-protect-health-information/</guid>
         <category domain="http://hipaahealthlaw.foxrothschild.com/tags">Department of Health and Human Services</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">HHS</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Mega Rule</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">OCR</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Office of Civil Rights</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">PHI</category><category domain="http://hipaahealthlaw.foxrothschild.com/articles">Privacy &amp; Security</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">de-identified data</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">protected health information</category>
         <pubDate>Thu, 27 Dec 2012 16:13:19 -0500</pubDate>
         <dc:creator>Elizabeth Litten</dc:creator>
      
      <feedburner:origLink>http://hipaahealthlaw.foxrothschild.com/2012/12/articles/privacy/countdown-to-2013-and-the-hitech-mega-rule-ten-new-years-resolutions-to-protect-health-information/</feedburner:origLink></item>
            <item>
         <title>Back to the SAIC Breach and a Look Across the Chasm Between Significant Risk and Actual Harm Resulting from a HIPAA Breach</title>
         <description>&lt;p&gt;&lt;a href="http://www.foxrothschild.com/attorneys/elizabeth-litten.html "&gt;Elizabeth Litten&lt;/a&gt; and &lt;a href="http://www.foxrothschild.com/attorneys/michael-kline.html"&gt;Michael&amp;nbsp;Kline&lt;/a&gt; write:&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;We have posted several blogs, including those &lt;a href="http://hipaahealthlaw.foxrothschild.com/2011/10/articles/breaches/saic-and-its-military-millions-march-flooding-the-parade-with-possible-phi-breaches-with-some-words-on-the-nemours-phi-breach-part-1/"&gt;here&lt;/a&gt; and &lt;a href="http://hipaahealthlaw.foxrothschild.com/2011/11/articles/breaches/did-tricaredod-make-a-proactive-response-or-a-preemptive-strike-with-saic-in-the-phi-breach-matter-whose-risk-is-it-anyway-part-4/"&gt;here&lt;/a&gt;, tracking the reported 2011 theft of computer tapes from the car of an employee of Science Applications International Corporation (&amp;ldquo;SAIC&amp;rdquo;) that contained the protected health information (&amp;ldquo;PHI&amp;rdquo;) affecting approximately 5 million military clinic and hospital patients (the &amp;ldquo;SAIC Breach&amp;rdquo;).&amp;nbsp; SAIC&amp;rsquo;s recent Motion to Dismiss (the &amp;ldquo;Motion&amp;rdquo;) the Consolidated Amended Complaint filed in federal court in Florida as a putative class action (the &amp;ldquo;SAIC Class Action&amp;rdquo;) highlights the gaps between an incident (like a theft) involving PHI, a determination that a breach of PHI has occurred, and the realization of harm resulting from the breach.&amp;nbsp;SAIC&amp;rsquo;s Motion&amp;nbsp;emphasizes this gap between the incident and the realization of harm, making it appear like a chasm so wide it practically swallows the breach into oblivion.&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;SAIC, a giant publicly-held government contractor that provides information technology (&amp;ldquo;IT&amp;rdquo;) management and, ironically, cyber security services, was engaged to provide IT management services to TRICARE Management Activity&lt;span style="font-size: 13pt"&gt;, &lt;/span&gt;a component of TRICARE, the military health plan (&amp;ldquo;TRICARE&amp;rdquo;) for active duty service members working for the U.S. Department of Defense&lt;span style="font-size: 13pt"&gt; (&amp;ldquo;&lt;/span&gt;DoD&amp;rdquo;).&amp;nbsp; SAIC employees had been contracted to transport backup tapes containing TRICARE members&amp;rsquo; PHI from one location to another.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;According to the original statement &lt;a href="http://www.tricare.mil/mybenefit/Download/Forms/DataBreach_PublicStatement.pdf"&gt;published&lt;/a&gt; in late September of 2011 ( the &amp;ldquo;TRICARE/SAIC Statement&amp;rdquo;) the PHI &amp;ldquo;may include Social Security numbers, addresses and phone numbers, and some personal health data such as clinical notes, laboratory tests and prescriptions.&amp;rdquo; However, the TRICARE/SAIC Statement said that there was no financial data, such as credit card or bank account information, on the backup tapes.&amp;nbsp;Note 17 to the audited financial statements (&amp;ldquo;Note 17&amp;rdquo;) contained in the SAIC Annual Report on &lt;a href="http://investors.saic.com/phoenix.zhtml?c=193857&amp;amp;p=irol-SECText&amp;amp;TEXT=aHR0cDovL2lyLmludC53ZXN0bGF3YnVzaW5lc3MuY29tL2RvY3VtZW50L3YxLzAwMDExOTMxMjUtMTItMTMzNjk3L3htbA%3d%3d "&gt;Form 10-K&lt;/a&gt; for the fiscal year ended January 31, 2012, dated March 27, 2012&amp;nbsp;(the &amp;ldquo;2012 Form 10-K&amp;rdquo;), filed with the Securities and Exchange Commission (the &amp;ldquo;SEC&amp;rdquo;) includes the following:&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin-left: 1in"&gt;There is no evidence that any of the data on the backup tapes has actually been accessed or viewed by an unauthorized person.&amp;nbsp;In order for an unauthorized person to access or view the data on the backup tapes, it would require knowledge of and access to specific hardware and software and knowledge of the system and data structure. &amp;nbsp;The Company [SAIC] has notified potentially impacted persons by letter and is offering one year of credit monitoring services to those who request these services and in certain circumstances, one year of identity restoration services.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;While the TRICARE/SAIC Statement contained similar language to that quoted above from Note 17, the earlier TRICARE/SAIC Statement also said, &amp;ldquo;The risk of harm to patients is judged to be low despite the data elements . . . .&amp;rdquo;&amp;nbsp;Because Note 17 does not contain such &amp;ldquo;risk of harm&amp;rdquo; language, it would appear that (i) there may have been a change in the assessment of risk by SAIC six months after the SAIC&amp;nbsp;Breach or (ii) SAIC did not want to&amp;nbsp;state such a judgment in an SEC filing.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;Note 17 also discloses that SAIC has reflected a $10 million loss provision in its financial statements relating to the &amp;nbsp;SAIC Class Action and various other putative class actions respecting the SAIC Breach filed between October 2011 and March 2012 (for a total of seven such actions filed in four different federal District Courts).&amp;nbsp; In Note 17 SAIC states&amp;nbsp;that the $10 million loss provision represents the &amp;ldquo;low end&amp;rdquo; of SAIC&amp;rsquo;s estimated loss and is the amount of SAIC&amp;rsquo;s deductible under insurance covering judgments or settlements and defense costs of litigation respecting the SAIC Breach. &amp;nbsp;SAIC expresses the belief in Note 17 that any loss experienced in excess of the $10 million loss provision would not exceed the insurance coverage.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;Such insurance coverage&amp;nbsp;would, however,&amp;nbsp;likely&amp;nbsp;not be available for any civil monetary penalties or counsel fees that may result from the current investigation of the SAIC Breach being conducted by the Office of Civil Rights of the Department of Health and Human Services (&amp;ldquo;HHS&amp;rdquo;) as described in Note 17.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;Initially, SAIC did not deem it necessary to offer credit monitoring to the almost 5 million reportedly affected individuals.&amp;nbsp;However, SAIC urged anyone suspecting they had been affected to contact the Federal Trade Commission&amp;rsquo;s identity theft website.&amp;nbsp;Approximately 6 weeks later, the DoD &lt;a href="http://www.defense.gov/releases/release.aspx?releaseid=14905"&gt;issued&lt;/a&gt; a press release stating that TRICARE had &amp;ldquo;directed&amp;rdquo; SAIC to take a &amp;ldquo;proactive&amp;rdquo; response by covering a year of free credit monitoring and restoration services for any patients expressing &amp;ldquo;concern about their credit as a result of the data breach.&amp;rdquo;&amp;nbsp;&amp;nbsp; The cost of such a proactive response easily can run into millions of dollars in the SAIC Breach.&amp;nbsp;It is unclear the extent, if any, to which insurance coverage would be available to cover the cost of the proactive response mandated by the DoD, even if the credit monitoring, restoration services and other remedial activities of SAIC were to become part of a judgment or settlement in the putative class actions.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;We have blogged about what constitutes an impermissible acquisition, access, use or disclosure of unsecured PHI that poses a &amp;ldquo;significant risk&amp;rdquo; of &amp;ldquo;financial, reputational, or other harm to the individual&amp;rdquo; amounting to a reportable HIPAA breach, and when that &amp;ldquo;significant risk&amp;rdquo; develops into harm that may create claims for damages by affected individuals.&amp;nbsp;Our partner William Maruca, Esq., artfully borrows a phrase from former Defense Secretary Donald Rumsfeld in &lt;a href="http://hipaahealthlaw.foxrothschild.com/2012/11/articles/breaches/known-unknowns-and-data-losses/"&gt;discussing&lt;/a&gt; a recent disappearance of unencrypted backup tapes reported by Women and Infants Hospital in Rhode Island.&amp;nbsp;If one knows PHI has disappeared, but doubts it can be accessed or used (due to the specialized equipment and expertise required to access or use the PHI), there is a &amp;ldquo;known unknown&amp;rdquo; that complicates the analysis as to whether a breach has occurred.&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;As we await publication of the &amp;ldquo;mega&amp;rdquo; HIPAA/HITECH regulations, continued tracking of the SAIC Breach and ensuing class action litigation (as well as SAIC&amp;rsquo;s SEC filings and other government filings and reports on the &lt;a href="http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/breachtool.html "&gt;HHS list&lt;/a&gt; of large PHI security breaches) provides some insights as to how covered entities and business associates respond to incidents involving the loss or theft of, or possible access to, PHI.&amp;nbsp;&amp;nbsp; If a covered entity or business associate concludes that the incident poses a &amp;ldquo;significant risk&amp;rdquo; of harm, but no harm actually materializes, perhaps (as the SAIC Motion repeatedly asserts) claims for damages are inappropriate.&amp;nbsp;When the covered entity or business associate takes a &amp;ldquo;proactive&amp;rdquo; approach in responding to what it has determined to be a &amp;ldquo;significant risk&amp;rdquo; (such as by offering credit monitoring and restoration services), perhaps the risk becomes less significant.&amp;nbsp;But once the incident (a/k/a, the ubiquitous laptop or computer tape theft from an employee&amp;rsquo;s car) has been deemed a breach, the chasm between incident and harm seems to open wide enough to encompass a mind-boggling number of privacy and security violation claims and issues.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/HipaaHealthLaw/~4/5GY1xPLTwCQ" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/HipaaHealthLaw/~3/5GY1xPLTwCQ/</link>
         <guid isPermaLink="false">http://hipaahealthlaw.foxrothschild.com/2012/12/articles/breaches/back-to-the-saic-breach-and-a-look-across-the-chasm-between-significant-risk-and-actual-harm-resulting-from-a-hipaa-breach/</guid>
         <category domain="http://hipaahealthlaw.foxrothschild.com/tags">Department of Defense</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Department of Health and Human Services</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">DoD</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">HHS</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">PHI</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">PHI security breach</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">SAIC</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">SEC</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Science Applications International Corporation</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Securities and Exchange Commission</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Security Breach Notification</category><category domain="http://hipaahealthlaw.foxrothschild.com/articles">Security Breach Notification </category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">breach notification rule</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">data breach</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">protected health information</category>
         <pubDate>Thu, 06 Dec 2012 22:33:10 -0500</pubDate>
         <dc:creator>Elizabeth Litten</dc:creator>
      
      <feedburner:origLink>http://hipaahealthlaw.foxrothschild.com/2012/12/articles/breaches/back-to-the-saic-breach-and-a-look-across-the-chasm-between-significant-risk-and-actual-harm-resulting-from-a-hipaa-breach/</feedburner:origLink></item>
            <item>
         <title>OIG Reports Shortcomings In EHR Incentive Oversight</title>
         <description>&lt;p&gt;CMS should improve its oversight of its electronic health record incentive program, according to a &lt;a href="https://oig.hhs.gov/oei/reports/oei-05-11-00250.pdf"&gt;&lt;font color="#800080"&gt;report&lt;/font&gt;&lt;/a&gt; by the Office of Inspector General released this month. &amp;nbsp;&amp;nbsp;The government watchdog agency faults CMS for both inadequate prepayment safeguards and insufficient postpayment monitoring of recipients of federal funding intended to help cover the costs of adoption and implementation of EHR.&lt;/p&gt;
&lt;p&gt;As this blog &lt;a href="http://hipaahealthlaw.foxrothschild.com/2012/11/articles/meaningful-use-of-ehr/oig-ehr-questionnaire-focuses-on-fraud-safeguards/"&gt;&lt;font color="#800080"&gt;noted&lt;/font&gt;&lt;/a&gt; earlier this month, some concerns have been raised in a &lt;a href="http://science.house.gov/sites/republicans.science.house.gov/files/documents/HHRG-112-SY19-WState-Q000024-20121114.pdf"&gt;&lt;font color="#800080"&gt;Congressional hearing&lt;/font&gt;&lt;/a&gt; about how the approximately $7.7 billion in taxpayer funds have been spent to date under the HITECH Act&amp;rsquo;s incentive program. &amp;nbsp;In its report, the OIG recommended that CMS:&lt;/p&gt;
&lt;p style="margin: 0in 1in 12pt"&gt;Obtain and review supporting documentation from selected professionals and hospitals prior to payment to verify the accuracy of their self-reported information;&lt;/p&gt;
&lt;p style="margin: 0in 1in 12pt"&gt;Issue guidance with specific examples of documentation that professionals and hospitals should maintain to support their compliance; and&lt;/p&gt;
&lt;p style="margin: 0in 1in 12pt"&gt;Conduct prepayment reviews to improve program oversight.&lt;/p&gt;
&lt;p style="margin: 0in 0in 12pt"&gt;OIG reported resistance from CMS regarding its recommendation to implement prepayment reviews, which CMS believes would increase the burden on practitioners and hospitals and could delay incentive payments. CMS agreed to take steps to improve program oversight.&amp;nbsp;CMS&amp;rsquo;s response appears as an exhibit to the OIG report at page 30.&lt;/p&gt;
&lt;p style="margin: 0in 0in 12pt"&gt;Next, the OIG turned to the &lt;a href="http://healthit.hhs.gov/portal/server.pt/community/healthit_hhs_gov__home/1204"&gt;&lt;font color="#800080"&gt;Office of the National Coordinator for Health Information Technology&lt;/font&gt;&lt;/a&gt; (ONC), the government agency that establishes EHR standards and certifies EHR technology. OIG recommended that the ONC:&lt;/p&gt;
&lt;p style="margin: 0in 1in 12pt"&gt;Require that certified EHR technology be capable of producing reports for yes/no meaningful use measures where possible; and&lt;/p&gt;
&lt;p style="margin: 0in 1in 12pt"&gt;Improve the certification process for EHR technology to ensure accurate EHR reports.&lt;/p&gt;
&lt;p style="margin: 0in 0in 12pt"&gt;ONC concurred with both recommendations, as noted in the letter from Dr. Farhad Mostashari appearing at page 32.&lt;/p&gt;
&lt;p style="margin: 0in 0in 12pt"&gt;The report noted that CMS currently conducts prepayment validation of professionals&amp;rsquo; and hospitals&amp;rsquo; self-reported meaningful use information to ensure that it meets program requirements, mostly by checking the math in the reports and verifying EHR certification codes.&amp;nbsp;&amp;nbsp; OIG also noted that CMS plans to audit selected professionals and hospitals after payment using a similar method to select audit targets based on inconsistencies in their reported data. At the time of the OIG review, CMS had not yet completed any postpayment audits.&lt;/p&gt;
&lt;p style="margin: 0in 0in 12pt"&gt;Among OIG&amp;rsquo;s findings were:&lt;/p&gt;
&lt;ul type="disc" style="margin-top: 0in"&gt;
    &lt;li style="margin: 0in 0in 12pt"&gt;CMS&amp;rsquo;s prepayment validation functions correctly but does not verify the accuracy of self-reported information.&lt;/li&gt;
    &lt;li style="margin: 0in 0in 12pt"&gt;Sufficient data are not available to verify self-reported information through automated system edits.&lt;/li&gt;
    &lt;li style="margin: 0in 0in 12pt"&gt;CMS does not collect supporting documentation to verify self-reported information prior to payment.&lt;/li&gt;
    &lt;li style="margin: 0in 0in 12pt"&gt;CMS&amp;rsquo;s planned postpayment audits may not conclusively verify the accuracy of professionals&amp;rsquo; and hospitals&amp;rsquo; self-reported meaningful use information.&lt;/li&gt;
    &lt;li style="margin: 0in 0in 12pt"&gt;Reports from certified EHR technology are not sufficient for CMS to verify self-reported information and may not always be accurate.&lt;/li&gt;
    &lt;li style="margin: 0in 0in 12pt"&gt;CMS may not be able to obtain sufficient supporting documentation to verify self-reported information during audits.&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="margin: 0in 0in 12pt"&gt;Given budgetary pressure and ongoing Congressional oversight, it is likely that CMS and ONC will be looking more closely at how HITECH incentive funds are being applied in the coming year.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/HipaaHealthLaw/~4/tAxssaKQLB4" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/HipaaHealthLaw/~3/tAxssaKQLB4/</link>
         <guid isPermaLink="false">http://hipaahealthlaw.foxrothschild.com/2012/11/articles/meaningful-use-of-ehr/oig-reports-shortcomings-in-ehr-incentive-oversight/</guid>
         <category domain="http://hipaahealthlaw.foxrothschild.com/">Articles</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">EHR incentives</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">HITECH</category><category domain="http://hipaahealthlaw.foxrothschild.com/articles">HITECH Act</category><category domain="http://hipaahealthlaw.foxrothschild.com/articles">Meaningful Use</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">OIG</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Oversight</category>
         <pubDate>Fri, 30 Nov 2012 11:33:10 -0500</pubDate>
         <dc:creator>William Maruca</dc:creator>
      
      <feedburner:origLink>http://hipaahealthlaw.foxrothschild.com/2012/11/articles/meaningful-use-of-ehr/oig-reports-shortcomings-in-ehr-incentive-oversight/</feedburner:origLink></item>
            <item>
         <title>Another Case of Snooping Prosecuted</title>
         <description>&lt;p&gt;Once again, a healthcare worker&amp;rsquo;s inability to resist the temptation to snoop in her employer's medical records has resulted in criminal prosecution.&amp;nbsp;In the latest incident, a Vermont ultrasound technologist improperly accessed the electronic medical records of her husband&amp;rsquo;s former wife and her children, allegedly over a period of 12 years.&amp;nbsp;The victim, also employed by the same hospital, was frustrated by the hospital administration&amp;rsquo;s delays in responding to her complaints and notified others including the FBI, her state senator and the American Civil Liberties Union before action was taken.&lt;/p&gt;
&lt;p style="margin: 12pt 0in 0pt"&gt;The &lt;a href="http://www.rutlandherald.com/article/20121110/NEWS02/711109899/1003"&gt;Rutland, VT Herald &lt;font color="#800080"&gt;reports&lt;/font&gt;&lt;/a&gt; that Kathy Tatro of Bennington, VT pleaded guilty to four counts of unauthorized access to computer records in a plea bargain that imposed probation and required her to serve 160 hours of community service, which will include talking to medical employees about the importance of privacy regarding patient records.&amp;nbsp;The &lt;a href="http://www.benningtonbanner.com/local/ci_21991260/former-hospital-technician-from-bennington-gets-suspended-sentence"&gt;Bennington Banner&lt;/a&gt; reports that Ms. Tatro&amp;nbsp;was given a 6-12 month suspended sentence, 2 years probation and a $2,000 fine.&lt;/p&gt;
&lt;p style="margin: 12pt 0in 0pt"&gt;This blog has noted other instances of snooping leading to serious consequences, including the case of a &lt;a href="http://hipaahealthlaw.foxrothschild.com/2010/05/articles/snoop-through-records-go-directly-to-jail/"&gt;&lt;font color="#800080"&gt;UCLA researcher sentenced to prison time&lt;/font&gt;&lt;/a&gt; for reading records of celebrities and co-workers, a &lt;a href="http://hipaahealthlaw.foxrothschild.com/2012/01/articles/hitech-act/when-will-they-learn-snooping-nurse-fired-patients-notified/"&gt;&lt;font color="#800080"&gt;Texas nurse&lt;/font&gt;&lt;/a&gt; fired for unauthorized access, a &lt;a href="http://hipaahealthlaw.foxrothschild.com/2010/06/articles/privacy/california-hospitals-fined-for-employees-unauthorized-access-of-patient-records/"&gt;&lt;font color="#800080"&gt;California hospital fined&lt;/font&gt;&lt;/a&gt; after employees accessed Michael Jackson&amp;rsquo;s records, a &lt;a href="http://hipaahealthlaw.foxrothschild.com/2007/10/articles/privacy/employees-suspended-for-snooping-about-george-clooney/"&gt;New York hospital&lt;/a&gt; that suspended employees for accessing George Clooney's records after a motorcycle accident, and the &lt;a href="http://hipaahealthlaw.foxrothschild.com/2009/12/articles/hipaa-enforcement/16-houston-hospital-employees-fired-for-snooping/"&gt;&lt;font color="#800080"&gt;termination of 16 hospital employees&lt;/font&gt;&lt;/a&gt; for accessing the records of an injured first-year resident.&lt;/p&gt;
&lt;p style="margin: 12pt 0in 0pt"&gt;&lt;a href="http://www.acluvt.org/blog/2012/11/14/e-med-records-privacy-a-false-sense-of-security/"&gt;The Vermont ACLU&lt;/a&gt;&amp;nbsp;claims that this incident is &amp;ldquo;believed to be the most extensive breach of personal electronic medical records ever reported in Vermont.&amp;rdquo; The ACLU noted that the victim had explained in court how the system let her down.&lt;/p&gt;
&lt;p style="margin: 12pt 0in 0pt 40px"&gt;&amp;ldquo;No investigation was begun nor any remedial action taken until she spoke up, complained, and dogged doctors, hospital administrators and trustees, state officials, federal officials, police officers, and the state&amp;rsquo;s attorney to do something. The privacy protections in place don&amp;rsquo;t work on their own; you have to fight to protect your rights.&amp;rdquo;&lt;/p&gt;
&lt;p style="margin: 12pt 0in 0pt"&gt;Based on reports, it appears this case was brought solely under state privacy laws, not HIPAA.&amp;nbsp;It is not clear whether the Vermont Attorney General was involved, even though it seems that the victim alerted a variety of authorities. &amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 12pt 0in 0pt"&gt;This case is yet another cautionary tale that should be considered by anyone in a position to access health records without a legitimate purpose, as well as by hospitals and other covered entities who should reevaluate the safeguards they have in place to track and prevent or at least discourage unauthorized access.&amp;nbsp;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/HipaaHealthLaw/~4/3ZavWAKrY7o" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/HipaaHealthLaw/~3/3ZavWAKrY7o/</link>
         <guid isPermaLink="false">http://hipaahealthlaw.foxrothschild.com/2012/11/articles/hipaa-enforcement/another-case-of-snooping-prosecuted/</guid>
         <category domain="http://hipaahealthlaw.foxrothschild.com/tags">Enforcement</category><category domain="http://hipaahealthlaw.foxrothschild.com/articles">HIPAA Enforcement</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Vermont</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">criminal penalties</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">snooping</category>
         <pubDate>Tue, 27 Nov 2012 16:52:31 -0500</pubDate>
         <dc:creator>William Maruca</dc:creator>
      
      <feedburner:origLink>http://hipaahealthlaw.foxrothschild.com/2012/11/articles/hipaa-enforcement/another-case-of-snooping-prosecuted/</feedburner:origLink></item>
            <item>
         <title>OIG EHR Questionnaire Focuses on Fraud Safeguards</title>
         <description>&lt;p&gt;The OIG is conducting a survey of hospitals who have certified the meaningful use of Electronic Health Record (EHR) Technology, with an emphasis on safeguards that protect the EHR systems from fraudulent access or alteration. A generous hospital compliance officer who has asked to remain nameless has provided me with a copy of the survey tool which can be accessed &lt;a href="http://tinyurl.com/OIG-EHR"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;Topics addressed in the survey include:&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;ul type="disc" style="margin-top: 0in"&gt;
    &lt;li style="margin: 0in 0in 0pt"&gt;Coding capabilities&lt;/li&gt;
    &lt;li style="margin: 0in 0in 0pt"&gt;User authentication and access&lt;/li&gt;
    &lt;li style="margin: 0in 0in 0pt"&gt;Access to EHR by outside entities&lt;/li&gt;
    &lt;li style="margin: 0in 0in 0pt"&gt;Audit log and metadata features&lt;/li&gt;
    &lt;li style="margin: 0in 0in 0pt"&gt;Methods for entering physician and nursing notes&lt;/li&gt;
    &lt;li style="margin: 0in 0in 0pt"&gt;Capabilities for exporting and transmitting EHR documents&lt;/li&gt;
    &lt;li style="margin: 0in 0in 0pt"&gt;Patient access&lt;/li&gt;
    &lt;li style="margin: 0in 0in 0pt"&gt;Patient identity management&lt;/li&gt;
    &lt;li style="margin: 0in 0in 0pt"&gt;Additional features and safeguards.&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;The underlying thread of the questionnaire looks to determine what each hospital is doing to ensure the integrity of the EHR data gathered, and to identify the barriers to more effective implementation of electronic records.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;Meanwhile, back on Capitol Hill, a &lt;a href="http://science.house.gov/sites/republicans.science.house.gov/files/documents/HHRG-112-SY19-20121114-SD001.pdf"&gt;&lt;font color="#800080"&gt;hearing&lt;/font&gt;&lt;/a&gt; was held on November 14, 2012 before the House Subcommittee on Technology and Innovation Committee on Science and Technology. The hearing topic was titled: &lt;b&gt;Is &amp;lsquo;Meaningful Use&amp;rsquo; Delivering Meaningful Results? An Examination of Health Information Technology Standards and Interoperability&lt;/b&gt;.&amp;nbsp;Witnesses were asked to address in their testimony:&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt 0.5in"&gt;What is the goal for health information interoperability under the HITECH Act?&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt 0.5in"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt 0.5in"&gt;How are Stage 1 and 2 meaningful use requirements and supporting standards advancing us towards this goal?&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt 0.5in"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt 0.5in"&gt;How have the lessons learned from the implementation of Stage 1 meaningful use requirements and supporting standards been applied in drafting Stage 2 requirements and Stage 3 proposals?&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt 0.5in"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt 0.5in"&gt;How does the ONC engage Federal agencies and other stakeholders (National Institute of Standards and Technology (NIST), vendors, and providers) in developing the meaningful use requirements and technical standards?&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt 0.5in"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt 0.5in"&gt;How does the HIT Standards Committee balance the need for common IT standards with the diversity of the healthcare industry? How does the Committee account for technology development and innovation in its standards recommendations?&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt 0.5in"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt 0.5in"&gt;How effective have HHS and the ONC been in establishing long-term goals and benchmarks for HIT adoption, interoperability, and provision of care?&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt 0.5in"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt 0.5in"&gt;What recommendations would you make for Federal policy makers as we consider futureHIT policies?&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;Dr. Farzad Mostashari,&amp;nbsp;HHS National Coordinator for Health Information Technology, presented prepared remarks which can be found &lt;a href="http://science.house.gov/sites/republicans.science.house.gov/files/documents/HHRG-112-SY19-WState-FMostashari-20121114.pdf"&gt;&lt;font color="#800080"&gt;here&lt;/font&gt;&lt;/a&gt;. Dr. Mostashari was cautiously optimistic about the pace of adoption of EHR and the progress being made toward interoperability.&amp;nbsp; He noted that as of September 2012, more than 300,000, more than half of the nation&amp;rsquo;s eligible professionals, as well as over 75 percent of eligible hospitals have registered to participate in the Medicare or Medicaid Incentive Programs.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;Summarizing the lessons learned by HHS to date, Dr. Mostashari stated &amp;ldquo;By creating standards-based methods for the electronic submission, receipt and processing of health IT, Federal agencies can improve the quality of the data they receive while also reducing the number of expensive, one-off solutions for addressing the varied needs of the stakeholders they serve.&amp;rdquo;&amp;nbsp;He praised his agency&amp;rsquo;s collaborations with &lt;a href="http://www.nist.gov/index.html"&gt;&lt;font color="#800080"&gt;NIST&lt;/font&gt;&lt;/a&gt; and recognized the over 6,400 comments received from stakeholders regarding the meaningful use process. He emphasized the efforts to provide new flexibility in definitions, exclusions, a shorter reporting period for the first year of Stage 2, and additional quality measures that account for the needs of many medical specialties to measure and improve the care they provide.&amp;nbsp;He also called attention to the &lt;a href="http://wiki.siframework.org/"&gt;&lt;font color="#800080"&gt;Standards and Interoperability Framework&lt;/font&gt;&lt;/a&gt;, a Wikipedia-style site for EHR developers, which he described as an example of &amp;ldquo;government as a platform&amp;rdquo; - enabled by integrated functions, processes, and tools &amp;ndash; for the open community of implementers and experts to work together to develop and harmonize health information exchange standards.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;Other witnesses appearing before the committee included Dr. Charles H. Romine, Director, Information Technology Laboratory, National Institute of Standards and Technology; &lt;a href="http://science.house.gov/sites/republicans.science.house.gov/files/documents/HHRG-112-SY19-WState-MProbst-20121114.pdf"&gt;&lt;font color="#800080"&gt;Marc Probst&lt;/font&gt;&lt;/a&gt;, Chief Information Officer and Vice President, Information Systems, Intermountain Healthcare; Ms. Rebecca Little, Senior Vice President, Medicity;&amp;nbsp;and &lt;a href="http://science.house.gov/sites/republicans.science.house.gov/files/documents/HHRG-112-SY19-WState-WFields-20121114.pdf"&gt;&lt;font color="#800080"&gt;Dr. Willa Fields&lt;/font&gt;&lt;/a&gt;, DNSc, RN, FHIMSS, Professor, School of Nursing, San Diego State University.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;In his introductory remarks, subcommittee chairman &lt;a href="http://science.house.gov/sites/republicans.science.house.gov/files/documents/HHRG-112-SY19-WState-Q000024-20121114.pdf"&gt;&lt;font color="#800080"&gt;Ben Quayle&lt;/font&gt;&lt;/a&gt; (R-AZ) noted :&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 1in 0pt"&gt;Given our current budget situation, it is vital that these taxpayer dollars are spent effectively in ways that lead to reduced costs and better health care down the road. &lt;b&gt;Nearly four years after the HITECH Act, taxpayers should know what we have &lt;/b&gt;&lt;b&gt;to show for it.&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;The recent survey suggests that the OIG intends to supply Rep. Quayle's subcommittee with a detailed answer to that question.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/HipaaHealthLaw/~4/d4h3jIK4BX8" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/HipaaHealthLaw/~3/d4h3jIK4BX8/</link>
         <guid isPermaLink="false">http://hipaahealthlaw.foxrothschild.com/2012/11/articles/meaningful-use-of-ehr/oig-ehr-questionnaire-focuses-on-fraud-safeguards/</guid>
         <category domain="http://hipaahealthlaw.foxrothschild.com/tags">House Subcommittee on Technology</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Innovation Committee on Science and Technology</category><category domain="http://hipaahealthlaw.foxrothschild.com/articles">Meaningful Use</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Mostashari</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">NIST</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">OIG Questionnaire</category>
         <pubDate>Mon, 19 Nov 2012 09:03:44 -0500</pubDate>
         <dc:creator>William Maruca</dc:creator>
      
      <feedburner:origLink>http://hipaahealthlaw.foxrothschild.com/2012/11/articles/meaningful-use-of-ehr/oig-ehr-questionnaire-focuses-on-fraud-safeguards/</feedburner:origLink></item>
            <item>
         <title>Known Unknowns and Data Losses</title>
         <description>&lt;p&gt;&amp;nbsp;A New England hospital has reported the disappearance of backup tapes containing ultrasound images and personal data of 14,000 patients.&amp;nbsp;How do you handle a data loss when you don&amp;rsquo;t have any way of determining where the data went or who may have seen it? &amp;nbsp;Is it still a &amp;ldquo;breach&amp;rdquo; in the technical sense?&lt;/p&gt;
&lt;p&gt;These questions call to mind former Defense Secretary Donald Rumsfeld&amp;rsquo;s &lt;a href="http://www.defense.gov/Transcripts/Transcript.aspx?TranscriptID=2636"&gt;famous observation&lt;/a&gt; about assessing knowledge gaps:&lt;/p&gt;
&lt;p style="margin-left: 40px"&gt;&amp;nbsp;&amp;ldquo;&lt;a href="http://www.youtube.com/watch?v=GiPe1OiKQuk&amp;amp;feature=player_detailpage"&gt;&lt;font color="#800080"&gt;There are known knowns; there are things we know we know. We also know there are known unknowns; that is to say we know there are some things we do not know. But there are also unknown unknowns -- the ones we don't know we don't know&lt;/font&gt;&lt;/a&gt;.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;And a less-famous Rumsfeld quote from the same press briefing, &amp;ldquo;&lt;i&gt;The absence of evidence is not evidence of absence, or vice versa&lt;/i&gt;&amp;rdquo; may also be applicable.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;What is known, according to the &lt;a href="http://www.womenandinfants.org/news/Confidentiality-Notice-for-Patients.cfm"&gt;&lt;font color="#800080"&gt;press release&lt;/font&gt;&lt;/a&gt; issued by &lt;a href="http://www.womenandinfants.org/"&gt;&lt;font color="#800080"&gt;Women and Infants Hospital of Rhode Island&lt;/font&gt;&lt;/a&gt;, is that on September 13, 2012, the institution learned that unencrypted backup tapes containing ultrasound images went missing from two ambulatory sites in Providence, Rhode Island and New Bedford, Massachusetts. The backup tapes contained ultrasound images and included patient names, dates of birth, dates of exams, physicians&amp;rsquo; names, patient ultrasound images, and, in some instances, Social Security numbers.&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;The hospital has concluded that they have no reason to believe that the information has been accessed or used improperly, because doing so would require specialized equipment and technical expertise.&amp;nbsp;The fact pattern and analysis recalls the 2011 breaches involving SAIC/Tricare and Nemours discussed on this &lt;a href="http://hipaahealthlaw.foxrothschild.com/2011/10/articles/breaches/saic-and-its-military-millions-march-flooding-the-parade-with-possible-phi-breaches-with-some-words-on-the-nemours-phi-breach-part-1/"&gt;&lt;font color="#800080"&gt;blog&lt;/font&gt;&lt;/a&gt; in October 2011 by my partner &lt;a href="http://www.foxrothschild.cohttp/www.foxrothschild.com/attorneys/bioDisplay.aspx?id=3640m/attorneys/bioDisplay.aspx?id=3640"&gt;Elizabeth Litten&lt;/a&gt;.&amp;nbsp;As she noted,&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 1in 0pt"&gt;When is the mere &amp;ldquo;ability&amp;rdquo; to read PHI, without evidence that the PHI was actually read or was likely to have been read, enough to trigger the notice requirement under the Breach Notification Rule?&amp;nbsp;Will covered entities provide notice out of an abundance of caution to report every unlocked or unencrypted data file, possibly flooding the HHS website that lists large PHI breaches (the &amp;ldquo;&lt;a href="http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/breachtool.html"&gt;&lt;font color="#800080"&gt;HHS List&lt;/font&gt;&lt;/a&gt;&amp;rdquo;) with &lt;i&gt;potential &lt;/i&gt;breaches that have minimal or no likelihood of access and unduly alarming notified individuals?&amp;nbsp;Could such reporting have the unintended effect of diluting the impact of reports involving &lt;i&gt;actual &lt;/i&gt;theft and snooping?&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 1in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;At this time, Women &amp;amp; Infants has notified affected patients and established a hotline but is not yet offering credit monitoring or identity theft protection. Further, there is no indication of a report having been filed with HHS, but once again &amp;ldquo;absence of evidence is not evidence of absence.&amp;rdquo;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;Applying the Rumsfeld test, I believe Women &amp;amp; Infants is facing both &amp;ldquo;known unknowns&amp;rdquo; and &amp;ldquo;unknown unknowns.&amp;rdquo; They know that they don&amp;rsquo;t and cannot be certain whether the data has been accessed, but if it has been, they cannot know the extent of the potential damage to the affected individuals. &amp;nbsp;The long-overdue &amp;ldquo;mega-regulation,&amp;rdquo; which may finally see the light of day now that the election is over, may provide some useful guidance.&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;In the meantime, enjoy some of former Secretary Rumsfeld's &lt;a href="http://www.slate.com/articles/news_and_politics/low_concept/2003/04/the_poetry_of_dh_rumsfeld.html"&gt;greatest hits&lt;/a&gt;.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/HipaaHealthLaw/~4/FRuiTTugCeQ" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/HipaaHealthLaw/~3/FRuiTTugCeQ/</link>
         <guid isPermaLink="false">http://hipaahealthlaw.foxrothschild.com/2012/11/articles/breaches/known-unknowns-and-data-losses/</guid>
         <category domain="http://hipaahealthlaw.foxrothschild.com/articles">Security Breach Notification </category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Women &amp; Infants</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">breach notification</category>
         <pubDate>Wed, 07 Nov 2012 11:52:15 -0500</pubDate>
         <dc:creator>William Maruca</dc:creator>
      
      <feedburner:origLink>http://hipaahealthlaw.foxrothschild.com/2012/11/articles/breaches/known-unknowns-and-data-losses/</feedburner:origLink></item>
            <item>
         <title>A Reader's Comment about a Third Potential Posting on the HHS Breach Parade for Massachusetts Eye and Ear Infirmary</title>
         <description>&lt;p&gt;A thoughtful reader commented on the recent &lt;a href="http://hipaahealthlaw.foxrothschild.com/2012/10/articles/breaches/as-the-breach-parade-passes-500-marchers-should-there-be-a-posting-on-the-hhs-list-for-a-third-massachusetts-eye-and-ear-infirmary-breach/ "&gt;blog post&lt;/a&gt; in this &lt;a href="http://hipaahealthlaw.foxrothschild.com/ "&gt;series&lt;/a&gt; that asked whether the 2012 Breach of Massachusetts Eye and Ear Infirmary (&amp;ldquo;MEEI&amp;rdquo;) should have by now been reflected in a third posting respecting MEEI on the HHS List.&amp;nbsp;(Capitalized terms not otherwise defined herein shall have the meanings assigned to them in the earlier &lt;a href="http://hipaahealthlaw.foxrothschild.com/2012/10/articles/breaches/as-the-breach-parade-passes-500-marchers-should-there-be-a-posting-on-the-hhs-list-for-a-third-massachusetts-eye-and-ear-infirmary-breach/ "&gt;blog post&lt;/a&gt;.)&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;The reader&amp;rsquo;s comments included the following:&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt 1in"&gt;&lt;span style="color: black"&gt;I have been wondering&amp;mdash;and this article [the blog post] continues to make me wonder&amp;mdash;whether covered entities will be less likely to &amp;ldquo;err on the side of caution&amp;rdquo; in making breach reports, now that they see the potentially draconian consequences of making such a report. I think it&amp;rsquo;s pretty clear (and I think OCR [the Office of Civil Rights] has even said publicly) that large breach reports will trigger investigations and, as we have seen, investigations are likely to open to scrutiny all aspects of the covered entity&amp;rsquo;s HIPAA policies, practices and procedures. Seeing million dollar resolution agreements may give covered entities pause about blowing the whistle on themselves, particularly where there is room to argue whether the disclosure creates a significant risk of harm. . . .&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt 1in"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&lt;span style="color: black"&gt;The reader&amp;rsquo;s comments point out the importance of evaluating the risk of harm by any covered entity that experiences a PHI security breach, even if it appears not to rise to the level of a potential List Breach.&amp;nbsp;I concur with the reader that &lt;/span&gt;more attention may be given by a covered entity in the future to make a risk analysis of the probable harm of a potential List Breach.&amp;nbsp;One of the purposes will be to determine the number of involved individuals and whether the entity can reasonably conclude that a List Breach has not occurred, and, therefore, there may be no need for a List Breach report to HHS.&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;The covered entity may so conclude even if it publicizes the PHI security breach, notifies &amp;ldquo;potentially affected individuals,&amp;rdquo; posts information about the breach on its Web site, engages in some &amp;ldquo;voluntary&amp;rdquo; remedial action for such potentially affected individuals, disciplines involved employees and makes improvements to its policies and procedures. Repeat marchers in the Breach Parade may be especially motivated to conclude that a List Breach has not occurred.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;However, the stakes may be high for a covered entity to conclude that a List Breach has not occurred.&amp;nbsp;The penalties that can flow from the potentially &amp;ldquo;draconian consequences &lt;span style="color: black"&gt;of making such a report&amp;rdquo; to HHS can be greatly amplified if the conclusion not to report the security breach as a List Breach turns out to be erroneous.&amp;nbsp;The failure to report a List Breach is a separate violation and can give rise to significant penalties.&amp;nbsp;Moreover, the covered entity must consider that most states have adopted their own requirements to make timely reports to state regulators about a PHI security breach, often with different standards for reporting, and state Attorneys General can seek to enforce a failure to make a mandatory report under both state law and HIPAA.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;To some observers, elements of the risk analysis of a covered entity for reporting a possible List Breach may be somewhat analogous to the considerations that exist for self-reporting by healthcare providers of potential false claims to the HHS Office of Inspector General under its voluntary disclosure program.&amp;nbsp;The important difference is that voluntary disclosure is optional; reporting a PHI security breach that is a List Breach to HHS is mandatory, with potential materially adverse consequences for failure to comply.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/HipaaHealthLaw/~4/OLNyu-Mkljc" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/HipaaHealthLaw/~3/OLNyu-Mkljc/</link>
         <guid isPermaLink="false">http://hipaahealthlaw.foxrothschild.com/2012/11/articles/breaches/a-readers-comment-about-a-third-potential-posting-on-the-hhs-breach-parade-for-massachusetts-eye-and-ear-infirmary/</guid>
         <category domain="http://hipaahealthlaw.foxrothschild.com/tags">HHS</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">HIPAA</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Mass. Eye and Ear</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Massachusetts Eye and Ear Infirmary</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">OCR</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">OIG</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Office of Civil Rights</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">PHI</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">PHI Security Breach Notification</category><category domain="http://hipaahealthlaw.foxrothschild.com/articles">Security Breach Notification </category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">covered entity</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">protected health information</category>
         <pubDate>Fri, 02 Nov 2012 13:29:54 -0500</pubDate>
         <dc:creator>Michael Kline</dc:creator>
      
      <feedburner:origLink>http://hipaahealthlaw.foxrothschild.com/2012/11/articles/breaches/a-readers-comment-about-a-third-potential-posting-on-the-hhs-breach-parade-for-massachusetts-eye-and-ear-infirmary/</feedburner:origLink></item>
            <item>
         <title>As the Breach Parade Passes 500 Marchers: Should There be a Posting on the HHS List for a Third Massachusetts Eye and Ear Infirmary Breach?</title>
         <description>&lt;p&gt;Much has been &lt;a href="http://www.hhs.gov/news/press/2012pres/09/20120917a.html"&gt;written&lt;/a&gt; about the circumstances surrounding the agreement of Massachusetts Eye and Ear Infirmary (&amp;ldquo;MEEI&amp;rdquo;) to pay the U.S. Department of Health and Human Services (&amp;ldquo;HHS&amp;rdquo;) the sum of $1.5 million to settle potential violations involving an alleged security breach (the &amp;ldquo;2010 Breach&amp;rdquo;) of Protected Health Information (&amp;ldquo;PHI&amp;rdquo;) under HIPAA.&amp;nbsp;However, relatively little has been written that the 2010 Breach was the second of what may be three significant PHI breaches experienced by MEEI within the last three years.&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;This &lt;a href="http://hipaahealthlaw.foxrothschild.com/ "&gt;blog series&lt;/a&gt; has been following breaches of PHI that have been reported on the &lt;a href="http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/breachtool.html "&gt;HHS list&lt;/a&gt; (the &amp;ldquo;HHS List&amp;rdquo;) of breaches of unsecured PHI affecting 500 or more individuals (the &amp;ldquo;List Breaches&amp;rdquo;).&amp;nbsp;Currently HHS has posted 502 List Breaches.&amp;nbsp;The first List Breach posted for MEEI on the HHS List (the &amp;ldquo;2009 Breach&amp;rdquo;) was&amp;nbsp;reported to have occurred by reason of a theft on November 10, 2009&amp;nbsp;that was said to have affected 1,076 individuals.&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;The 2010 Breach was reported to have occurred on February 19, 2010, only slightly more than three months after the 2009 Breach.&amp;nbsp;According to the HHS List, it affected 3,621 individuals.&amp;nbsp;A &lt;a href="http://www.masseyeandear.org/news/press_releases/recent/Resolution_Agreement/ "&gt;statement&lt;/a&gt; from MEEI on its Web site reports that HHS review of the 2010 Breach &lt;span style="color: black"&gt;was &amp;ldquo;triggered by the hospital&amp;rsquo;s proactive self-reporting of a doctor&amp;rsquo;s unencrypted laptop being stolen while he was traveling abroad in 2010.&amp;rdquo;&amp;nbsp; MEEI further stated that it &amp;ldquo;has no indication that any patients were harmed by this isolated incident.&amp;rdquo; Query: How &amp;ldquo;isolated&amp;rdquo; was the incident in view of the fact that the 2010 Breach occurred soon after the 2009 Breach?&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&lt;span style="color: black"&gt;Potential entries in the PHI Breach Parade did not end for MEEI, however, with the 2010 Breach.&amp;nbsp;On April 16, 2012, during a time that MEEI was likely to have been heavily negotiating with HHS&amp;nbsp;about the $1.5 million payment, MEEI posted the following &lt;a href="http://www.masseyeandear.org/news/press_releases/recent/data_breach_2012/ "&gt;statement&lt;/a&gt; on its Web site (the &amp;ldquo;2012 Statement&amp;rdquo;), about which relatively little was reported in the media: &lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0.2in 1in"&gt;&lt;span style="color: black"&gt;On March 5, 2012, the Quincy, Massachusetts, Police Department informed [MEEI] that they were investigating a [MEEI] employee for inappropriately using the names, Social Security numbers and dates of birth of certain individuals, some of whom were believed to be MEEI patients. . . .&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0.2in 1in"&gt;&lt;span style="color: black"&gt;While [MEEI] is only aware of four individuals whose personal information was actually misused, as a precaution we are notifying, by mail,&amp;nbsp; approximately 3,600 patients whose Social Security numbers were available to the former employee in the course of performing her assigned duties.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&lt;span style="color: black"&gt;The 2012 Statement went on to say that MEEI will &amp;ldquo;&lt;/span&gt;&lt;span style="color: black"&gt;provide one year of free credit monitoring to &lt;b&gt;potentially&lt;/b&gt; &lt;strong&gt;affected individuals&lt;/strong&gt; to protect them against &lt;strong&gt;possible harm&lt;/strong&gt; resulting from this incident.&amp;rdquo; &lt;/span&gt;&lt;span style="color: black"&gt;&amp;nbsp;[Emphasis supplied.]&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&lt;span style="color: black"&gt;It is perplexing that nothing about the 2012 Breach has been posted on the HHS List to this point, although &lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0.2in 1in"&gt;&lt;span style="color: black"&gt;(i)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the MEEI Web site reported the event more than six months ago,&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-indent: -0.5in; margin: 0in 0in 0.2in 1.5in"&gt;&lt;span style="color: black"&gt;(ii)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the number of&amp;nbsp;&amp;ldquo;potentially&amp;rdquo; affected individuals far exceeded the 500 minimum threshold for placement on the HHS List, and&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-indent: -0.5in; margin: 0in 0in 0.2in 1.5in"&gt;&lt;span style="color: black"&gt;(iii)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the period during which MEEI was dealing with HHS after the 2010 Breach overlapped with the occurrence and aftermath of the 2012 Breach.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0.2in"&gt;&lt;span style="color: black"&gt;Queries:&amp;nbsp;Did MEEI not report the 2012 Breach to the HHS List because it ultimately concluded that the 2012 Breach did not involve more than 500 individuals even though it does offer credit monitoring to more than 3,600 individuals?&amp;nbsp;(As a potential third time marcher in the Breach Parade, MEEI was certainly aware of its reporting obligations to HHS.)&amp;nbsp;In other words,&amp;nbsp;did MEEI determine by a reasonable risk assessment that the&amp;nbsp;potential access&amp;nbsp;by the former employee to PHI&amp;nbsp;of 3,600 individuals was not sufficient to require a report for the HHS List, absent more substantial proof that the PHI&amp;nbsp;of 500 or more individuals was actually accessed and/or that 500 or more individuals were actually harmed by such access?&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0.2in"&gt;&lt;span style="color: black"&gt;Alternatively, is it simply possible that HHS&amp;nbsp;has been&amp;nbsp;slow in reporting additional List Breaches on the HHS List, similar to&amp;nbsp;a suggestion in an earlier &lt;a href="http://hipaahealthlaw.foxrothschild.com/2012/10/articles/breaches/as-the-parade-of-major-phi-breaches-marches-ever-onward-where-have-all-the-ocr-summaries-gone/ "&gt;post&lt;/a&gt; in this blog series that HHS may be slow in posting Summaries of cases that it has investigated and closed? &lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0.2in"&gt;&lt;span style="color: black"&gt;This blog series will continue to monitor developments in this area.&lt;/span&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/HipaaHealthLaw/~4/uAJ7La6SzOs" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/HipaaHealthLaw/~3/uAJ7La6SzOs/</link>
         <guid isPermaLink="false">http://hipaahealthlaw.foxrothschild.com/2012/10/articles/breaches/as-the-breach-parade-passes-500-marchers-should-there-be-a-posting-on-the-hhs-list-for-a-third-massachusetts-eye-and-ear-infirmary-breach/</guid>
         <category domain="http://hipaahealthlaw.foxrothschild.com/tags">HHS</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">HIPAA</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Health and Human Services</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Mass. Eye and Ear</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Massachusetts Eye and Ear</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">PHI</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">PHI Security Breach Notification</category><category domain="http://hipaahealthlaw.foxrothschild.com/articles">Security Breach Notification </category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">covered entity</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">protected health information</category>
         <pubDate>Sun, 28 Oct 2012 20:05:06 -0500</pubDate>
         <dc:creator>Michael Kline</dc:creator>
      
      <feedburner:origLink>http://hipaahealthlaw.foxrothschild.com/2012/10/articles/breaches/as-the-breach-parade-passes-500-marchers-should-there-be-a-posting-on-the-hhs-list-for-a-third-massachusetts-eye-and-ear-infirmary-breach/</feedburner:origLink></item>
            <item>
         <title>As the Parade of Major PHI Breaches Marches Ever Onward, Where Have All the OCR Summaries Gone?</title>
         <description>&lt;p&gt;This &lt;a href="http://hipaahealthlaw.foxrothschild.com/ "&gt;blog series&lt;/a&gt; has been following breaches of Protected Health Information (&amp;ldquo;PHI&amp;rdquo;) that have been reported on the U.S. Department of Health and Human Services (&amp;ldquo;HHS&amp;rdquo;) &lt;a href="http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/breachtool.html "&gt;list&lt;/a&gt; (the &amp;ldquo;HHS List&amp;rdquo;) of breaches of unsecured PHI affecting 500 or more individuals (the &amp;ldquo;List Breaches&amp;rdquo;).&amp;nbsp;Currently HHS has posted 498 List Breaches reported by covered entities (&amp;ldquo;CEs&amp;rdquo;), of which approximately 102 (20.5%) have been reported as also involving business associates (&amp;ldquo;BAs&amp;rdquo;). &amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;As stated in an earlier &lt;a href="http://hipaahealthlaw.foxrothschild.com/2012/06/articles/privacy/the-parade-of-major-phi-breaches-marches-onward-what-lessons-can-be-learned-from-comments-by-ocrs-reviewing-stand/ "&gt;posting&lt;/a&gt; in this blog series, the HHS List includes valuable guidance for CEs and BAs in the form of &amp;ldquo;brief summaries of the breach cases that OCR [the federal Office of Civil Rights] has investigated and closed. . . .&amp;rdquo;&amp;nbsp;To date, the HHS List has posted&amp;nbsp;approximately 96 summaries (&amp;ldquo;Summaries&amp;rdquo;) respecting the 498 current postings&amp;nbsp;for CE&amp;nbsp;marchers in the Breach Parade (which include some multiple postings of List Breaches where a single alleged breach by a BA caused a number of CEs to have List Breaches).&amp;nbsp;Of the&amp;nbsp;96 List Breaches for which Summaries have been posted by OCR, 19 (19.8%) were reported as involving BAs.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;Unfortunately, since May 10, 2012, it would appear that only one new Summary has been posted by OCR, which relates to List Breach number 337 reported by Indiana University School of Optometry as CE.&amp;nbsp;According to the OCR Summary, that List Breach affected 757 individuals and resulted in accessibility over the Internet of patient names, birth dates, medical history, diagnoses and treatment plans for the period from August 8, 2011 through September 9, 2011.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;No Summary has been posted by OCR for any List Breach that occurred later than October 6, 2011, already a&amp;nbsp;year ago.&amp;nbsp;Additionally, no Summary has been posted by OCR for any List Breach involving a BA that occurred later than February 1, 2011, as discussed in an earlier posting in this blog series.&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;Moreover, the substantial majority of Summaries posted by OCR relate to List Breaches affecting fewer than 10,000 persons.&amp;nbsp;While this Summary history may be reflective of the population of List Breaches as &lt;a href="http://hipaahealthlaw.foxrothschild.com/2011/12/articles/breaches/the-silent-brigade-in-the-parade-of-major-reported-phi-breaches-of-security-and-privacy-business-associates-an-update/ "&gt;discussed&lt;/a&gt; in an earlier post in this blog series, the largest number of affected individuals for which a Summary has been posted to date is 83,000.&amp;nbsp;That List Breach,&amp;nbsp;which&amp;nbsp;occurred on November 12, 2009 and was number 21 on the HHS List,&amp;nbsp;related to&amp;nbsp;unauthorized access/disclosure of paper information and was reported by Universal American in New York as the CE with Democracy Data &amp;amp; Communications, LLC as an involved BA.&amp;nbsp;In light of the existence of complex List Breaches that reportedly&amp;nbsp;affect hundreds of thousands or even millions of individuals, Summaries respecting larger List Breaches&amp;nbsp;may be helpful in providing new and different insights for&amp;nbsp;CEs and BAs.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;There is great value in the guidance provided by the posted Summaries for educating CEs and BAs as to what OCR may deem to be significant&amp;nbsp;with respect to&amp;nbsp;List Breaches.&amp;nbsp;OCR Summaries may provide analysis not only&amp;nbsp;of the List Breaches themselves but also subsequent actions taken by the affected CEs and BAs.&amp;nbsp;However, because the paucity of recent postings of Summaries can&amp;nbsp;dampen their overall educational benefit, OCR is encouraged to increase the frequency, number, currentness and diversity of the Summaries posted.&amp;nbsp;&lt;span style="font-weight: normal"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/HipaaHealthLaw/~4/2EO436FFBU8" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/HipaaHealthLaw/~3/2EO436FFBU8/</link>
         <guid isPermaLink="false">http://hipaahealthlaw.foxrothschild.com/2012/10/articles/breaches/as-the-parade-of-major-phi-breaches-marches-ever-onward-where-have-all-the-ocr-summaries-gone/</guid>
         <category domain="http://hipaahealthlaw.foxrothschild.com/tags">Democracy Data &amp; Communications, LLC</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">HHS</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">HIPAA</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Health and Human Services</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Indiana University School of Optometry</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">OCR</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Office of Civil Rights</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">PHI</category><category domain="http://hipaahealthlaw.foxrothschild.com/articles">Security Breach Notification </category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Universal American</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">business associate</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">covered entity</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">protected health information</category>
         <pubDate>Fri, 05 Oct 2012 16:08:32 -0500</pubDate>
         <dc:creator>Michael Kline</dc:creator>
      
      <feedburner:origLink>http://hipaahealthlaw.foxrothschild.com/2012/10/articles/breaches/as-the-parade-of-major-phi-breaches-marches-ever-onward-where-have-all-the-ocr-summaries-gone/</feedburner:origLink></item>
            <item>
         <title>PHI Breach Involving Health Plan Leads to Lawsuit by Identity Theft Victims Who Were Plan Members</title>
         <description>&lt;p&gt;A previous &lt;a href="http://hipaahealthlaw.foxrothschild.com/2012/07/articles/hipaa-enforcement/why-cant-i-sue-under-hipaa-for-a-breach-of-my-protected-health-information-what-can-i-do/"&gt;post&lt;/a&gt; to this blog by &lt;a href="http://www.foxrothschild.com/attorneys/bioDisplay.aspx?id=3690"&gt;Patricia McManus&lt;/a&gt; pointed out that individuals whose protected health information (&amp;ldquo;PHI&amp;rdquo;) is stolen, lost, or otherwise inappropriately used, accessed, or left unsecured have no private right of action against the person or entity responsible for the breach under the HIPAA/HITECH laws.&amp;nbsp;That may change for victims of identity theft who can show the theft was caused by a HIPAA breach, at least if the action is brought in the 11&lt;sup&gt;th&lt;/sup&gt; Circuit.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;The 11&lt;sup&gt;th&lt;/sup&gt; Circuit District Court (Southern District of Florida) decision that &lt;a href="http://scholar.google.com/scholar_case?case=6082902461873666531&amp;amp;q=resnick+v.+avmed&amp;amp;hl=en&amp;amp;as_sdt=2,39"&gt;came out&lt;/a&gt;&amp;nbsp;&amp;nbsp;on September 5, 2012 involved stolen unencrypted laptops containing PHI of approximately 1.2 million AvMed (health plan) patients. The lower court had dismissed the originally-filed class action because plaintiffs sought &amp;quot;to predicate recovery upon a mere specter of injury: a heightened likelihood of identity theft.&amp;quot;&amp;nbsp; The case was re-filed, naming as plaintiffs a subset of patients whose identities had been actually stolen since the laptop theft, alleging negligence by AvMed in protecting the sensitive information, breach of contract, unjust enrichment, breach of the implied covenant of good faith and fair dealing, and breach of fiduciary duty.&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;The District Court's decision to deny AvMed's motion to dismiss plaintiffs' claim that AvMed's data breach caused plaintiffs' identity theft was based on its finding that plaintiffs &amp;quot;sufficiently alleged a nexus between the data theft and the identify theft and therefore meet the federal pleading standards...&amp;nbsp; ,&amp;quot; even though the computers were stolen 10 and 14 months prior to the identity thefts of the two specific plaintiffs named in the action.&amp;nbsp;The court pointed out that both individuals were very protective of their personal data and did not transmit sensitive data electronically or store it on computers. One plaintiff's sensitive information was used to open a Bank of America account and change her address with the US Post Office, while the other plaintiff's sensitive information was used to open an E*Trade Financial account.&amp;nbsp;Neither had experienced identify theft before the theft of the AvMed laptops.&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;The court also refused to dismiss the plaintiffs' unjust enrichment claim, which was based on the fact that AvMed received premiums that were payments, at least in part, to protect sensitive information with &amp;quot;data management and security measures that are mandated by industry standards.&amp;quot;&amp;nbsp;Plaintiffs alleged AvMed failed to implement or inadequately implemented these policies.&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;If plaintiffs are ultimately successful in obtaining refunds of premiums and/or payments from AvMed for damages incurred as a result of the identity thefts, it could set an interesting precedent for future HIPAA breach victims, particularly if the court&amp;rsquo;s decision relies (as it seemed to rely in this decision) on the fact that the victims could show they were extremely careful not to store or transmit personal information via electronic means. &amp;nbsp;In this age of intensive use of computers and the Internet for&amp;nbsp;financial transactions,&amp;nbsp;such plaintiffs are probably highly unusual.&amp;nbsp;An individual who makes frequent or even occasional on-line purchases or pays bills electronically and who becomes the victim of &amp;nbsp;a HIPAA breach might have difficulty demonstrating that a subsequent identity theft was the direct result of the breach.&amp;nbsp;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/HipaaHealthLaw/~4/o6lDpxQ1VnI" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/HipaaHealthLaw/~3/o6lDpxQ1VnI/</link>
         <guid isPermaLink="false">http://hipaahealthlaw.foxrothschild.com/2012/09/articles/privacy/phi-breach-involving-health-plan-leads-to-lawsuit-by-identity-theft-victims-who-were-plan-members/</guid>
         <category domain="http://hipaahealthlaw.foxrothschild.com/tags">AVMed</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">HIPAA</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">HITECH</category><category domain="http://hipaahealthlaw.foxrothschild.com/articles">Lawsuits</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">PHI</category><category domain="http://hipaahealthlaw.foxrothschild.com/articles">Privacy &amp; Security</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">identity theft</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">protected health information</category>
         <pubDate>Tue, 18 Sep 2012 10:26:27 -0500</pubDate>
         <dc:creator>Elizabeth Litten</dc:creator>
      
      <feedburner:origLink>http://hipaahealthlaw.foxrothschild.com/2012/09/articles/privacy/phi-breach-involving-health-plan-leads-to-lawsuit-by-identity-theft-victims-who-were-plan-members/</feedburner:origLink></item>
            <item>
         <title>As We All Continue to Anticipate the HIPAA/HITECH "Mega Rule" from HHS, We Can Test Our Prognosticating Skills</title>
         <description>&lt;p&gt;We have seen substantial delay in publication of the long-awaited HIPAA/HITECH Omnibus Final Rule, sometimes affectionately referred to as the &amp;ldquo;Mega Rule.&amp;rdquo;&amp;nbsp;&lt;i&gt;Health Data Management&lt;/i&gt; &lt;a href="http://www.healthdatamanagement.com/news/privacy_HIPAA-44573-1.html "&gt;reported&lt;/a&gt; on June 6 of this year that Farzad Mostashari, national coordinator for health information technology, had said that the HIPAA Mega rule, which will include modifications to the privacy and security rule, breach notification and enforcement, &amp;ldquo;should&amp;rsquo; be published by &amp;ldquo;the end of summer.&amp;rdquo;&amp;nbsp;After previous disappointments and delays in regulations in other contexts from the U.S. Department of Health and Human Services, however, it may be noteworthy that Mr. Mostashari was said to have used the word &amp;ldquo;should,&amp;rdquo; and did not specify the summer of what year, e.g., 2012, 2013, 2014, etc.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;Now there has been some scuttlebutt that the Mega Rule may not surface until after Election Day, November 6, 2012, perhaps because of concerns about potential political implications.&amp;nbsp;Even as we wait, there is some justifiable trepidation as to the number of pages of regulations that will be published.&amp;nbsp;The recently-issued CMS final requirements that hospitals and other providers must meet to receive funding under the second phase of the federal electronic health-record incentive program, which is a relatively narrow topic, &lt;a href="http://ofr.gov/OFRUpload/OFRData/2012-21050_PI.pdf "&gt;constituted&lt;/a&gt; 672 pages.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;What can we expect from HHS on the Mega Rule?&amp;nbsp;Well, we can register our own speculations.&amp;nbsp;Marla Durben Hirsch, Editor of &lt;i&gt;Medical Practice Compliance Alert&lt;/i&gt; published by DecisionHealth, Inc., informed me of a clever contest that is being &lt;a href="http://www2.idexpertscorp.com/breach-solutions/final-countdown-contest/ "&gt;conducted&lt;/a&gt; on line by idexperts as to the Mega Rule.&amp;nbsp;Any household can put in a single entry as to the month, day and year that the Mega Rule will be published in the Federal Register. In the event of a tie, the number of pages in the Mega Rule will serve as a first tie breaker.&amp;nbsp;The prize for first place is a contribution of $2,500 in the name of the winner to the Wounded Warrior Project, a $200 Amazon gift card, a year&amp;rsquo;s subscription to RADAR published by idexperts and, of course, internet bragging rights.&lt;/p&gt;
&lt;p&gt;So, with the approach of Labor Day and the waning days of summer, join the contest and make the Mega Rule wait more enjoyable!&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/HipaaHealthLaw/~4/Jx__QaGyfZQ" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/HipaaHealthLaw/~3/Jx__QaGyfZQ/</link>
         <guid isPermaLink="false">http://hipaahealthlaw.foxrothschild.com/2012/08/articles/privacy/as-we-all-continue-to-anticipate-the-hipaahitech-mega-rule-from-hhs-we-can-test-our-prognosticating-skills/</guid>
         <category domain="http://hipaahealthlaw.foxrothschild.com/tags">CMS</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">HHS</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">HIPAA</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">HIPAA/HITECH Omnibus Final Rule</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Health and Human Services</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Marla Durben Hirsch</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Mega Rule</category><category domain="http://hipaahealthlaw.foxrothschild.com/articles">Privacy &amp; Security</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">contest</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">idexperts</category>
         <pubDate>Wed, 29 Aug 2012 10:36:16 -0500</pubDate>
         <dc:creator>Michael Kline</dc:creator>
      
      <feedburner:origLink>http://hipaahealthlaw.foxrothschild.com/2012/08/articles/privacy/as-we-all-continue-to-anticipate-the-hipaahitech-mega-rule-from-hhs-we-can-test-our-prognosticating-skills/</feedburner:origLink></item>
            <item>
         <title>Employers: Beware of PHI "Minimum Necessary" Standards Lurking Under Statutes Other Than HIPAA and State PHI Statutes</title>
         <description>&lt;p&gt;A recent &lt;a href="http://employmentdiscrimination.foxrothschild.com/2012/08/articles/americans-with-disabilities-ac/orders-to-go-see-the-doc-cost-baltimore-county-475000/ "&gt;posting&lt;/a&gt; by our partner &lt;a href="http://www.foxrothschild.com/attorneys/bioDisplay.aspx?id=4060 "&gt;Christina Stoneburner&lt;/a&gt;, Esq., on the Fox Rothschild &lt;a href="http://employmentdiscrimination.foxrothschild.com/"&gt;Employment Discrimination&amp;nbsp;blog&lt;/a&gt; discussed the need by employers to limit protected health information (&amp;ldquo;PHI&amp;rdquo;) that they provide with respect to medical examinations of employees and job applicants to the least amount of medical information necessary for evaluation.&amp;nbsp; Interestingly, the focus of her posting was not&amp;nbsp;disclosure under HIPAA/HITECH, or even state statutes regulating the use of PHI; it dealt with allegations that employees and job applicants had been sent for unnecessary medical examinations in violation of the Americans with Disabilities Act and the Genetic Information Nondisclosure Act.&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;Christina summarizes her posting with the following:&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin-left: 1in"&gt;In short, the least amount of medical information necessary to evaluate an employee is what should be provided to examiners.&amp;nbsp; For example, if you have an employee being evaluated to see if he can perform the essential functions of his job after a shoulder injury, the examining doctor should not be given the medical records relating to his planter's wart being removed.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;In her discussion, Christina noted our&amp;nbsp;blog &lt;a href="http://hipaahealthlaw.foxrothschild.com/ "&gt;series&lt;/a&gt; respecting large breaches and a particular recent &lt;a href="http://hipaahealthlaw.foxrothschild.com/2012/07/articles/hipaa-enforcement/business-associate-breach-leads-to-25m-settlement-by-accretive-but-who-is-the-covered-entity-or-business-associate-here-and-do-we-care/ "&gt;posting&lt;/a&gt; by &lt;a href="http://www.foxrothschild.com/attorneys/elizabeth-litten.html"&gt;Elizabeth Litten&lt;/a&gt;, Esq.&amp;nbsp; Christina also mentioned that the complaint on which her posting focused had alleged, &amp;quot;the employer often turned over Workers' Compensation records . . . ,&amp;nbsp;even where those records were not relevant to the examination.&amp;rdquo;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;Workers&amp;rsquo; compensation is an area where Christina&amp;rsquo;s posting comes full circle to our blog&amp;rsquo;s focus on HIPAA;&amp;nbsp; as HIPAA directly confronts&amp;nbsp;such area by making it clear that only the &amp;ldquo;minimum necessary&amp;rdquo;&amp;nbsp;disclosure of PHI is permitted by covered entities without patient authorization pursuant to &lt;a href="http://www.law.cornell.edu/cfr/text/45/164.512 "&gt;45 CFR 164.512(l)&lt;/a&gt;:&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt 1in"&gt;&lt;span&gt;A covered entity may disclose protected health information as authorized by and to the extent necessary to comply with laws relating to workers' compensation or other similar programs, established by law, that provide benefits for work-related injuries or illness without regard to fault.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt 1in"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;The Office of Civil Rights of the U.S. Department of Health and Human Services (&amp;ldquo;HHS&amp;rdquo;) has &lt;a href="http://www.hhs.gov/ocr/privacy/hipaa/understanding/coveredentities/workerscompensation.pdf "&gt;published&lt;/a&gt; further advice on how the workers&amp;rsquo; compensation Regulation works:&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt 1in"&gt;Covered entities are required reasonably to limit the amount of protected health information disclosed . . . to the minimum necessary to accomplish the worker&amp;rsquo;s compensation purpose.&amp;nbsp;Under this requirement, protected health information may be shared for such purposes to the full extent authorized by State or other law.&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt 1in"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;In summary, to avoid needless and costly violations, employers and other covered entities must be constantly aware of the need to comply with multiple regulatory schemes that may govern PHI, beyond those of HIPAA and State laws governing PHI;&amp;nbsp; there is not unlimited flexibility to disclose PHI even within the context of State-governed workers&amp;rsquo; compensation matters.&amp;nbsp;When the long-anticipated &amp;ldquo;mega-regulation&amp;rdquo; regarding HIPAA/HITECH&amp;nbsp;is finally published by HHS, special attention must be given to potential changes that may further tighten the &amp;ldquo;minimum necessary&amp;quot; standards.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/HipaaHealthLaw/~4/c31aZWByLVE" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/HipaaHealthLaw/~3/c31aZWByLVE/</link>
         <guid isPermaLink="false">http://hipaahealthlaw.foxrothschild.com/2012/08/articles/privacy/employers-beware-of-phi-minimum-necessary-standards-lurking-under-statutes-other-than-hipaa-and-state-phi-statutes/</guid>
         <category domain="http://hipaahealthlaw.foxrothschild.com/tags">Americans with Disabilities Act</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Genetic Information Nondisclosure Act</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">HHS</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">HIPAA</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">HITECH</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Health and Human Services</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">OCR</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">Office of Civil Rights</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">PHI</category><category domain="http://hipaahealthlaw.foxrothschild.com/articles">Privacy &amp; Security</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">covered entity</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">protected health information</category><category domain="http://hipaahealthlaw.foxrothschild.com/tags">workers' compensation</category>
         <pubDate>Sun, 12 Aug 2012 21:29:32 -0500</pubDate>
         <dc:creator>Michael Kline</dc:creator>
      
      <feedburner:origLink>http://hipaahealthlaw.foxrothschild.com/2012/08/articles/privacy/employers-beware-of-phi-minimum-necessary-standards-lurking-under-statutes-other-than-hipaa-and-state-phi-statutes/</feedburner:origLink></item>
      
   </channel>
</rss>
