New Security Rules for the Electronic Health Care Record Incentive Program

In 2009, the Ways and Means committee put forth the Health Information Technology for Economic and Clinical Health Act or HITECH Act. The bill states that Health information technology helps save lives and lower costs. One of the four major goals of the legislation is to “Strengthening Federal privacy and security law to protect identifiable health [...]

Medical Records Access Report Too Burdensome

On May 31, 2011, the Department of Health and Human Services’ (HHS) Office for Civil Rights proposed a new rule recommending that patients have the right to ask for a report on who has accessed their medical records. The recommendation has been out for public comment since that time.

A number of healthcare organizations including the Medical Group [...]

HealthCare Providers Need IT Security Training

It appears that the health care industry lacks understanding of basic information technology security. Dr David Lee Scher, MD, just wrote an article for the Healthcare IT and Technology blog outlining five things healthcare providers should know about electronic health care record security. From his article, it is obvious that health care workers could use some [...]

Access Logs Recommended for EHRs

Department of Health and Human Services’ Office for Civil Rights’ recent notice of proposed rulemaking on accounting of disclosures introduces a valuable privacy tool for individuals—the access report.

The HIPAA Security Rule’s information system activity review specification [164.308(a)(1)] requires organizations to “implement procedures to regularly review records of information system activity, such as audit logs, access reports, [...]

Health IT Policy Committee Recommends Two-Factor Authentication for EHRs

The Health IT Policy Committee on June 8 accepted a recommendation that all organizations participating in the Nationwide Health Information Network initiative (NwHIN) should use digital certificates that meet the same authentication standards already required for federal agencies. Ultimate approval for the recommendation falls on the Department of Health and Human Services.

One of the main motivations [...]

Electronic Health Records Help Bring Hospital Back On Line After Disaster

Just weeks before the powerful F5 tornado ripped though Joplin Missouri severely damaging the St. John’s Regional Medical Center, St. John’s had converted to a new electronic health records system. Having all their records online and backed up in another city, allowed the hospital to be up and running a 60 bed mobile hospital in less [...]

Maine reverses decision on HIE Consent

After hearing objections from hospitals and physicians about a proposed “opt-in” approach to obtaining patient consent for health information exchange (HIE), the Maine legislature has dropped a proposal to switch from an “Opt-out” approach.

The original proposal would have been required to give patients an opt-in form that they would need to sign to authorize having their [...]

HHS OIG finds Security Lacking in Health Information Technology Infrastructure

The Department’s Office of the National Coordinator (ONC) provides leadership for the development and nationwide implementation of an interoperable health information technology (HIT) infrastructure. ONC is charged with guiding the nationwide implementation of interoperable HIT to reduce medical errors, improve quality, produce greater value for health care expenditures, ensure that patients’ individually identifiable health information is [...]

HHS Privacy and Security Tiger Team Findings Part 2

Last week, I summarized the Health and Human Services Health Information Technology Policy Committee Privacy and Security Tiger Team (Tiger Team)’s findings.

As a reminder, their charge was to “make short-term and long term recommendations to the Health Information Technology Policy Committee (HITPC) on privacy and security policies and practices that well help build public trust in health [...]