• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer

  • COVID-19
  • Opinion
  • Health IT
    • Behavioral Health
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Patient Engagement
    • Population Health Management
    • Revenue Cycle Management
    • Social Determinants of Health
  • Digital Health
    • Artificial Intelligence
    • Blockchain
    • Mobile Health
    • Precision Medicine
    • Telehealth
    • Wearables
  • Startups
  • M&A
  • Value-based Care
    • Accountable Care (ACOs)
    • Medicare Advantage
  • Life Sciences
  • Research

New HIPAA Omnibus Final Rules: The Core of the Matter

by Our Thought Leaders 02/19/2013 4 Comments

Jan McDavid, General Counsel at HealthPort highlights some of key content in the new HIPAA omnibus final rules healthcare providers should understand. 

On January 17, 2013, to much fanfare, HHS released its eagerly anticipated HIPAA omnibus rule, which dramatically amends the HIPAA Privacy, Security, Breach and Enforcement Rules. The effect on healthcare providers and their business associates should not be taken lightly. The new rule goes into effect on March 26, and covered entities and business associates (BAs) are expected to comply by September 23 – not a lot of time to get one’s ducks in a row. Obviously, healthcare providers need to understand the new rule – and the depth of its ramifications – post-haste.

HHS Secretary Kathleen Sebelius made clear the intent of the new rule in an introductory statement:

“The final rule greatly enhances a patient’s privacy protections, provides individuals new rights to their health information, and strengthens the government’s ability to enforce the law.”

She went on to place the new rule in context:

“Much has changed in healthcare since HIPAA was enacted over 15 years ago. The new rule will help protect patient privacy and safeguard patients’ health information in an ever expanding digital age.”

The impressive document, at 563 pages, proved challenging to decipher. I’ll help you cut to the chase by highlighting some of its key content:

  • Business Associates (BAs) of covered entities are now directly liable for compliance with certain requirements of HIPAA Privacy and Security rules.
  • The rule revises the definition of a “breach,” which will make the occurrence of breaches – and the subsequent notification of the breach — more frequent.
  • The use and disclosure of protected health information for marketing and fundraising purposes is further limited, as is the sale of protected information without individual authorization (although there are several exceptions to this rule about sale).
  • The rule expands patients’ rights to receive electronic copies of their health information and to restrict disclosures to health plans regarding treatment for which the individual has paid out of pocket in full.
  • Covered entities are required to modify and redistribute their notice of privacy practices.
  • Rules on patient authorizations and other requirements are modified to facilitate medical research, expedite the disclosure of child immunization proof to schools, and enable access to decedent information by family members and others.
  • The HITECH Act interim enhancements to the Enforcement Rule are adopted, including provisions addressing enforcement of noncompliance with HIPAA rules due to willful neglect.

In a nutshell, healthcare providers have lots of work to do. Most immediately, providers need to update their business associate agreement and breach analysis and notification processes.

The notification of breaches also gains importance under the new final rule. With a new study by the Society of Corporate Compliance and Ethics and the Health Care Compliance Association showing that nearly 60% of organizations incurred a data breach within the last twelve months (and nearly 20% suffered multiple breaches), it makes sense for organizations to prepare themselves to react to inevitable breaches. And, as mentioned above, the rule’s expanded definition of “breach” will make breaches more numerous. Breaches are expensive. The same study showed that in 16% of breach occurrences, remediation costs were greater than $50,000. In 3% of occurrences, costs topped $500,000.

The new HIPAA omnibus rule will present challenges on multiple levels to healthcare providers as we all scramble to comply. Communicating requirements succinctly to BAs, updating your breach notification process, and keeping patient data organized and retrievable will go a long way in meeting these new challenges.

Jan P. McDavid, Esq. is the General Counsel and Chief Compliant Officer at HealthPort

Tagged With: HealthPort

Get in-depth healthcare technology analysis and commentary delivered straight to your email weekly

Reader Interactions

Primary Sidebar

Subscribe to HIT Consultant

Latest insightful articles delivered straight to your inbox weekly.

Submit a Tip or Pitch

Most Popular

Survey: Clinician Burnout Is A Public Health Crisis Demanding Urgent Action

17 Execs Share How Health IT Can Address Clinician Burnout, Staffing, & Capacity

Q/A: Dr. Johnson Talks Racial Disparities in Breast Cancer Care

Q/A: Dr. Johnson Talks Racial Disparities in Breast Cancer Care

Northwell Health Extends Contract with Allscripts Sunrise Platform Through 2027

Northwell to Deploy Epic Enterprise EHR Platform Across System

Sanofi Cuts Price of Lantus Insulin by 78% & Caps Out of Pocket Costs at $35 for All Patients

Sanofi Cuts Price of Lantus Insulin by 78% & Caps Out of Pocket Costs at $35 for All Patients

Pfizer Acquires Seagen for $43B to Tackle Cancer

Pfizer Acquires Seagen for $43B to Tackle Cancer

5 Key Trends Driving Purchasing Decisions in Healthcare IT

5 Key Trends Driving Purchasing Decisions in Healthcare IT

Sanofi to Acquire Diabetes Therapy Maker Provention Bio for $2.9B

Sanofi to Acquire Diabetes Therapy Maker Provention Bio for $2.9B

Dr. Arti Masturzo

Q/A: Dr. Masturzo Talks Addressing Food Insecurity with Patients

Transcarent Acquires 98point6 AI-Powered Virtual Care Platform and Care Business

Transcarent Acquires 98point6 AI-Powered Virtual Care Platform and Care Business

Eli Lilly Cuts Insulin Prices by 70%, Caps Patient Costs at $35 Per Month

Eli Lilly Cuts Insulin Prices by 70%, Caps Patient Costs at $35 Per Month

Secondary Sidebar

Footer

Company

  • About Us
  • Advertise with Us
  • Reprints and Permissions
  • 2023 Editorial Calendar
  • Submit An Op-Ed
  • Contact
  • Subscribe

Editorial Coverage

  • Opinion
  • Health IT
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Population Health Management
    • Revenue Cycle Management
  • Digital Health
    • Artificial Intelligence
    • Blockchain Tech
    • Precision Medicine
    • Telehealth
    • Wearables
  • Startups
  • Value-Based Care
    • Accountable Care
    • Medicare Advantage

Connect

Subscribe to HIT Consultant Media

Latest insightful articles delivered straight to your inbox weekly

Copyright © 2023. HIT Consultant Media. All Rights Reserved. Privacy Policy |