If you haven't looked at your HIPAA Privacy and Security Policies lately, NOW is the time to do so!! There were MAJOR changes included in the HITECH which was a part of the American Recovery and Reinvestment Act (ARRA). As a result of this, many of the policies and procedures physician practices implemented in 2003 when HIPAA went into effect, must be updated.
Some of the changes implemented are:
>Increased liability for not being in compliance with HIPAA standards (The old fine was a maximum of $25,000 per violation; NOW that's just the first level of fines and fines can now be $1.5 million for a single violation!!!)
>The HITECH act also mandates that audits be conducted on covered entities (physicians and physician practices); the federal government can walk into your office and ask to see your policies and procedures at ANY TIME even if NO complaints have been filed against you!!
>The breach notification policy states that if one patient's secured record has been breached, the patient must be notified, as well as, the Federal Government. If more than 500 patients' secured records have been breached, you must notify the affected patients, the Federal Government and local news media!
>Also, update your Business Associates Agreements-your BA has several new policies they must implement to protect you!
Don't delay in updating or implementing your Privacy and Security Policies-the consequences greatly out way any costs!
Showing posts with label HIPAA Privacy and Security. Show all posts
Showing posts with label HIPAA Privacy and Security. Show all posts
EHR Privacy
Published on FierceEMR (http://www.fierceemr.com)
80% of Americans worry about EHR privacy
By mdhirsch
Created Sep 22 2011 - 8:13am
The survey, released September 20, found that 80 percent of Americans were concerned about moving their personal medical information to EHRs because of the risks of identity theft, exposure of their information on the Internet and the viewing of their records by those not directly related to their care. There also was concern that patients' private health conditions could be revealed to current or potential employers.
The results were similar in other nations: 81 percent of Britons and 83 percent of Australians reported the same fears. Overall, 5,246 individuals, including 2,309 Americans.
While such fears are well founded, they aren't necessarily unique to electronic records. "It's a very real fear [for patients to have], but security concerns also exist with paper records," Tony Ryzinski, senior vice president of product management and marketing for Sage Healthcare, tells FierceEMR.
In fact, Irving, Texas-based OB/GYN Jeffery Livingston tells FierceEMR that he believes EHRs generally are more secure than paper records, since the files are encrypted. Livingston's practice transitioned to EHRs in 2007.
A major part of the concern involves human error and activity, such as lax access controls and inadequate security measures, SailPoint notes in the report.
"Consumers are right to be concerned about the possible exposure of their very private medical information," Jackie Gilbert, vice president of marketing and co-founder at SailPoint, said in a statement. "As the healthcare industry around the world moves toward digitalizing personal healthcare records, keeping patient information private and secure must be the highest priority. Healthcare organizations need to make sure that they have the proper controls in place to protect patient data; those that don't clearly risk lawsuits, fines, and most importantly, loss of patient trust."
Governments are aware of the public's fear of exposure regarding the use of EHRs. The HITECH Act addressed some of these concerns with its beefed up privacy and security rules and more stringent accounting of disclosure requirements [2] for providers who use EHRs, for which a proposed rule was published in the Federal Register May 31. The final rule implementing that measure has not yet been promulgated.
To learn more:
- here's the healthcare portion [1] of SailPoint's survey (.pdf)
- check out the SailPoint press release [3]
- read the proposed accounting for disclosures rule [4]
- view this SailPoint infographic [5]
Related Articles:
HHS: Patients should know who views their EHR [2]
OCR stepping up HIPAA privacy, security enforcement [6]
HHS raises maximum HIPAA privacy fines to $1.5 million [7]
Links:
[1] http://assets.fiercemarkets.com/public/newsletter/fierceemr/sailpoint.pdf
[2] http://www.fierceemr.com/story/hhs-patients-should-know-who-views-their-ehr/2011-06-02
[3] http://www.fiercehealthit.com/press-releases/sailpoint-survey-highlights-consumer-fear-over-stolen-personal-or-financial
[4] http://www.federalregister.gov/articles/2011/05/31/2011-13297/hipaa-privacy-rule-accounting-of-disclosures-under-the-health-information-technology-for-economic
[5] http://www.sailpoint.com/2011survey/
[6] http://www.fiercehealthit.com/story/ocr-stepping-hipaa-privacy-security-enforcement/2010-05-17
[7] http://www.fierceemr.com/story/hhs-raises-maximum-hipaa-privacy-fines-1-5-million/2009-11-05
[1] http://assets.fiercemarkets.com/public/newsletter/fierceemr/sailpoint.pdf
[2] http://www.fierceemr.com/story/hhs-patients-should-know-who-views-their-ehr/2011-06-02
[3] http://www.fiercehealthit.com/press-releases/sailpoint-survey-highlights-consumer-fear-over-stolen-personal-or-financial
[4] http://www.federalregister.gov/articles/2011/05/31/2011-13297/hipaa-privacy-rule-accounting-of-disclosures-under-the-health-information-technology-for-economic
[5] http://www.sailpoint.com/2011survey/
[6] http://www.fiercehealthit.com/story/ocr-stepping-hipaa-privacy-security-enforcement/2010-05-17
[7] http://www.fierceemr.com/story/hhs-raises-maximum-hipaa-privacy-fines-1-5-million/2009-11-05
Health IT News.....
Published on Healthcare IT News (http://www.healthcareitnews.com/)
Home > PwC: Health industry under-prepared to protect privacy
PwC: Health industry under-prepared to protect privacy
By Mike Miliard, Managing Editor
Created 09/22/2011
NEW YORK – Most health organizations are under-prepared to protect patient privacy and secure personal health information as new uses for digital health data emerge and access to confidential patient information expands, according to a new report from PwC's Health Research Institute.
Old privacy and security controls no longer suffice to comply with existing privacy laws and patient consent agreements, say to PwC officials – who emphasize that health organizations need to update practices and adopt a more integrated approach to ensure that patient information doesn't fall into the wrong hands.
The report, titled "Old data learns new tricks: Managing patient privacy and security on a new data-sharing playground," shows how existing privacy and security controls have not kept pace with new realities in healthcare: increased access to information in electronic health records; greater data collaboration with external partners and business associations; the emergence of new uses for digital health information to improve the quality and cost of care; and the rise of social media and mobile technology to better and more efficiently manage patient health.
A recent nationwide PwC Health Research Institute survey of 600 executives from US hospitals and physician organizations, health insurers, and pharmaceutical and life sciences companies found:
Continued on next page.
A culture of confidentiality
PwC's research found considerable concern for the "knowledgeable insider." On average, improper use of personal health information by an internal party was the leading privacy/security issue experienced by healthcare organizations over the last two years. Because of lack of awareness or training, breaches can result easily and with greater probability from mishandling of paper documents, people talking in the elevator, or comments made via social media channels. In addition, risks of data breaches and the complexity of consent agreements rises when information is shared with business associates, the source of more than half of reported health data breaches affecting more than 11 million people since 2009.
PwC's survey found:
Digitized health data is becoming one of the most highly valued assets in the health industry, and, according to PwC, all kinds of organizations are now converging around the shared use of the information to enable new care delivery models such as accountable care organizations, outcomes-based reimbursement and the advance of wellness, preventive and personalized care.
Organizations also are discovering the potential in secondary uses of the information beyond treating patients, such as in clinical studies, post-market surveillance of drugs and the development of new products and services to better understand patient health and behaviors. Yet PwC found that while many organizations are sharing information, the complexity of consent further increases and few organizations have established proper restrictions and consent agreements to control proper access. PwC's research found that:
PwC's research found that the recent increase in breach enforcement actions have prompted health organizations to focus more on privacy and security, and that there is growing recognition of privacy and security compliance as central to maintaining a trusted brand.
"To protect patient trust and their own brand reputation, organizations need to go beyond minimum regulatory requirements and adopt an integrated approach that combines privacy, security and compliance within a culture where all employees see themselves as champions of confidentiality and where privacy is part of the patient experience," said Peter Harries, principal and co-leader, Health Information Privacy and Security Practice, PwC.
Organizations with integrated approaches to privacy and security say they have realized the benefits, including a significant increase in data security and a slight decrease in the number of privacy/security issues, depending on the extent of their integration. PwC found that health insurers were more likely than providers and pharmaceutical/life sciences companies to have integrated their approach to a great extent.
A full copy of PwC's report can be found here.
Old privacy and security controls no longer suffice to comply with existing privacy laws and patient consent agreements, say to PwC officials – who emphasize that health organizations need to update practices and adopt a more integrated approach to ensure that patient information doesn't fall into the wrong hands.
The report, titled "Old data learns new tricks: Managing patient privacy and security on a new data-sharing playground," shows how existing privacy and security controls have not kept pace with new realities in healthcare: increased access to information in electronic health records; greater data collaboration with external partners and business associations; the emergence of new uses for digital health information to improve the quality and cost of care; and the rise of social media and mobile technology to better and more efficiently manage patient health.
A recent nationwide PwC Health Research Institute survey of 600 executives from US hospitals and physician organizations, health insurers, and pharmaceutical and life sciences companies found:
- Theft accounted for 66 percent of total reported health data breaches over the past two years. Also, medical identity theft appears to be on the rise. Over one third (36 percent) of provider organizations (hospitals and physician groups) confirmed that they have experienced patients seeking services using somebody else's name and identification.
- More than half (55 percent) of health organizations surveyed have not addressed privacy and security issues associated with the use of mobile devices, and less than one-quarter have addressed privacy and security implications of social media.
- More than half (54 percent) of health organizations surveyed reported at least one issue with information privacy and security over the past two years.
- The most frequently reported issue among providers was the improper use of protected health information by an internal party. Over the past two years, 40 percent of providers reported an incident of improper internal use of protected health information.
- The most frequently reported issue among health insurers and pharmaceutical and life science companies was the improper transfer of files containing personal health information to unauthorized parties. Over the past two years, one in five (21 percent) pharmaceutical and life sciences companies and one in four (25 percent) of health insurers improperly transferred files containing protected health information.
Continued on next page.
A culture of confidentiality
PwC's research found considerable concern for the "knowledgeable insider." On average, improper use of personal health information by an internal party was the leading privacy/security issue experienced by healthcare organizations over the last two years. Because of lack of awareness or training, breaches can result easily and with greater probability from mishandling of paper documents, people talking in the elevator, or comments made via social media channels. In addition, risks of data breaches and the complexity of consent agreements rises when information is shared with business associates, the source of more than half of reported health data breaches affecting more than 11 million people since 2009.
PwC's survey found:
- More than half of healthcare organizations allow access to social networking while at work; less than half have a policy covering the use of social media outside of work.
- Less than half (37 percent) of health organizations surveyed incorporate approved uses of mobile devices and social media as part of company privacy training.
- Only 58 percent of providers and 41 percent of health insurers say they include the appropriate use of electronic health records (EHR) as part of employee privacy training.
- Only 36 percent of health organizations perform a pre-contract assessment of their business associates such as business partners and vendors, and just 26 percent conduct post-contract compliance assessments.
Digitized health data is becoming one of the most highly valued assets in the health industry, and, according to PwC, all kinds of organizations are now converging around the shared use of the information to enable new care delivery models such as accountable care organizations, outcomes-based reimbursement and the advance of wellness, preventive and personalized care.
Organizations also are discovering the potential in secondary uses of the information beyond treating patients, such as in clinical studies, post-market surveillance of drugs and the development of new products and services to better understand patient health and behaviors. Yet PwC found that while many organizations are sharing information, the complexity of consent further increases and few organizations have established proper restrictions and consent agreements to control proper access. PwC's research found that:
- Only 17 percent of providers, 19 percent of payers and 22 percent of pharmaceutical/life sciences companies have a process in place to manage patients' consent for how their information can be used.
- Nearly three quarters (74 percent) of healthcare organizations surveyed said they already do or intend to seek secondary uses for health data; however, less than half have addressed or are in the process of addressing related privacy and security issues.
- Sixty-one percent of pharmaceutical and life sciences companies, 40 percent of health insurers and 38 percent of providers currently share information externally. Of those organizations that share data externally, only two in five pharmaceutical and life sciences companies (43 percent) and one in four insurers (25 percent) and providers (26 percent) have identified contractual, policy or legal restrictions on how the data can be used.
PwC's research found that the recent increase in breach enforcement actions have prompted health organizations to focus more on privacy and security, and that there is growing recognition of privacy and security compliance as central to maintaining a trusted brand.
"To protect patient trust and their own brand reputation, organizations need to go beyond minimum regulatory requirements and adopt an integrated approach that combines privacy, security and compliance within a culture where all employees see themselves as champions of confidentiality and where privacy is part of the patient experience," said Peter Harries, principal and co-leader, Health Information Privacy and Security Practice, PwC.
Organizations with integrated approaches to privacy and security say they have realized the benefits, including a significant increase in data security and a slight decrease in the number of privacy/security issues, depending on the extent of their integration. PwC found that health insurers were more likely than providers and pharmaceutical/life sciences companies to have integrated their approach to a great extent.
A full copy of PwC's report can be found here.
Links:
[1] http://www.pwc.com/us/HITprivacysecurity
[1] http://www.pwc.com/us/HITprivacysecurity
Subscribe to:
Posts (Atom)
