LTN Law Technology News
  • Home
  • News
  • Reviews
  • Commentary
  • Surveys
  • Events
  • LegalTech® Directory
  • About LTN
  • Register
  • Topics:
  • E-Discovery & Compliance
  • Litigation Support
  • Practice Management
  • Office Tech
  • Mobile Lawyer
  • Research & Libraries
  • Tech Law

Home > The HIPAA Final Rule Is a Game-Changer for Breach Notification

Font Size: increase font decrease font

Previous

  • 2
  • 3
  • 4

Next

The HIPAA Final Rule Is a Game-Changer for Breach Notification

January 28, 2013

  •    
  •    
  •    
  •      
 

Most of these factors were likely considered previously by CEs, but they were considered in a different context. If a CE or BA concludes that a breach has not occurred, documentation sufficient to meet this burden of proof must be maintained. A decision to notify does not require an analysis of risk because the occurrence of a breach is presumed.

There are also a few requirements that remain the same, even if there was some clarification.

PRE-EMPTION OF STATE LAW

HHS has reminded CEs and BAs that HITECH only pre-empts state law to the extent HITECH is more strict. If a state law is more strict, then the CE and BA must follow the requirements of the state law as HHS considers the regulation to be the federal floor of privacy protection. Depending on the scope of the breach, a state may have more strict requirements involving timeliness of notification, notification to state agencies, and content of the notification letter. Some states such as Florida, Vermont, and Wisconsin for example require notification within 45 days. Other states expect notification within several weeks to 30 days even though the state law does not specify an exact time period. Knowledgeable privacy counsel is critical to advise organizations about these issues because the state statutes (and how they are applied) can be confusing.

ADDRESSABLE STANDARDS

HHS has made clear that the ability to deliver high-quality care must be balanced with compliance issues because each organization is unique and presented with different challenges. This does not mean that compliance takes a backseat to patient care issues, but it does mean that healthcare organizations can continue to document their decision-making process when accepting and addressing risks.

For example, the use of encryption continues to be an addressable standard. This means that it is not required to be adopted by healthcare organizations and vendors. There are several advantages, however, if the technology is implemented. These include safe harbors for breach notification and the ability to show clear compliance with certain HIPAA Security Rule requirements. If an organization decides not to deploy encryption technology, a documented risk assessment is required which details the decisions made by the organization and what other protections are in place to address the safeguarding of ePHI. OCR may disagree with your assessment.Recently, HHS provided guidance for the protection of mobile devices. Some of the protections that should be considered include:

1. Use a password or other user authentication.

2. Install and enable encryption.

3. Install and activate wiping and/or remote disabling.

4. Disable and do not install file-sharing applications.

5. Install and enable a firewall.

Continue reading

Previous

  • 2
  • 3
  • 4

Next



Subscribe to Law Technology News

You must be signed in to comment on an article

Find similar content

Companies, agencies mentioned

    
  • CE
  • British Airways PLC
  • Hitech
  • KPMG LLC
  • Office for Civil Rights
  • United States Department of Health and Human Services

Most viewed stories

    
  1. Big Law Whipped for Poor Tech Training
    •      
  2. 10 Devices You Should Never Take Along on a Business Trip
    •      
  3. Is Stanford Law the New Vortex of Legal Technology?
    •      
  4. Using Computer Forensics to Investigate IP Theft
    •      
  5. How the Predictive Coding Process Will Affect Paralegals
    •      
  6. Collaboration Is Key to Defending Cyberattacks
    •      
  7. ILTA Study to Gauge New Technologies' Impact on Law Practice
    •      
  8. CEIC: the Destination for Digital Investigation
    •      
  9. 3-D Printing: The Next Big Thing in IP Law?
    •      
  10. Cisco E-Book Delivers Ethics on the Go
    •      
lawjobs.com

TOP JOBS

MORE JOBS

POST A JOB

From the Law.com Network

Hiring Interns? Be Sure to Do It Right

ACC Weighs in on Arizona's In-House Pro Bono Rules

Ex-Dewey Partners Face New Foe in Firm's Bankruptcy

S&C Adds Linklaters Restructuring Partner in London
  •      
    • Subscription Required

Contrite Companies Can Win Forgiveness in Bribery Cases
  •      
    • Subscription Required

Plaintiffs Want to See Toyota's 'Crown Jewels'
  •      
    • Subscription Required

Enron Sandbox Stirs Up Private Data, Again

LegalTech West Coast Wraps Up With Ethics, VC News

Prolific ADA Plaintiff Faces Nemesis in Harassment Suit

Ullyot Exit Closes Chapter for Facebook

Fla. Attorneys Lead Force-Placed Insurance Fight

Lawsuit Names Missing Fla. Attorney for Alleged Fraud
  •      
    • Subscription Required

Summer Programs Still in a Drought

Lawyer Left Without Coverage for Alleged Malpractice at Prior Firm
  •      
    • Subscription Required

The Affordable State-Specific Practice Solution
Available in NY, NJ, PA and CT editions - research, draft and prepare even the most complex cases with ease.

Circuit Reinstates Lawsuit by Inmate Over Cell Conditions
  •      
    • Subscription Required

Custody Ruling in Bitter Fight May Turn on 11-Year-Old's Wish
  •      
    • Subscription Required

Castille Testifies in Favor of 'Civil Gideon' Funding

Workers' Comp Judges Can't Fight Rescinded Raise
  •      
    • Subscription Required

Law Schools Are Looking Beyond LSATs, Says Mich. Dean

Is Freezing Your Eggs the Solution?

Advising Clients on Weather and the Workplace
  •      
    • Subscription Required

Texas Sues BP, Others Over Deepwater Oil Spill Disaster
  •      
    • Subscription Required

'Follow That Escapee!'

Hospital Accuses Judge Of Violating Judicial Canons
  •      
    • Subscription Required

Corporate Bribery Case Part Of National Trend
  •      
    • Subscription Required

Court Continues To Grant Lawyers Fraud Immunity
  •      
    • Subscription Required

  • About LTN   |
  • Contact LTN   |
  • Advertise with Us   |
  • Sitemap
  • About |
  • ALM Properties |
  • ALM Reprints |
  • Customer Support |
  • Privacy Policy |
  • Terms & Conditions |
  • ALM User License Agreement
ALM Media