Showing posts with label HIPAA. Show all posts
Showing posts with label HIPAA. Show all posts

Wednesday, February 23, 2011

Another Privacy Breach and HIPAA

Here is some current reporting in regard to HIPAA and your privacy.  For many years, since this legislation was enacted, we have warned that it does little to protect your medical records or your privacy.  Rather it has been almost an open door for all kinds of distribution, even to many not involved in health care. 

We suggest you ask your health insurance provider about the status of your medical records and get copies of everything for your own file.

February 22, 2011, 4:02 pm

Health insurer fined $4.3M for HIPAA violation

By Jason Millman
The federal health department is slapping a Maryland health insurer with a $4.3 million civil money penalty (CMP) for violating medical records rules. 
Cignet Health's failure to honor patients' requests for access to their medical records earned the Department of Health and Human Services’s first-ever CMP for a violation of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) privacy rule.
The fine represents the Obama administration’s toughened enforcement of medical privacy laws. The 2009 stimulus package, which provided almost $30 billion to develop electronic health record systems, included boosted penalties for HIPAA violations.
According to HHS’s Office for Civil Rights (OCR), Cignet was fined $1.3 million for denying 41 patients access to their medical records between September 2008 and October 2009. The insurer was fined another $3 million for failing to cooperate with the OCR investigation.
“Ensuring that Americans’ health information privacy is protected is vital to our healthcare system and a priority of this Administration,” HHS Secretary Kathleen Sebelius said in a statement. “[HHS] is serious about enforcing individual rights guaranteed by the HIPAA Privacy Rule.” 

Daniel E. Austin, the owner of Cignet Health, a Christian-influenced health center, did not return calls to his office seeking comment. The Maryland Board of Physicians revoked his license in 2000 for his conviction for mail and loan fraud. Among the physicians listed on the center's Web site is one whose license was revoked in 2008 for engaging in sexual improprieties and sexual misconduct with patients.
Seeger said Cignet also provided health insurance. But last year, the Maryland Insurance Administration ordered Cignet to stop selling health insurance because it was not licensed to do so.
Several of the patients informed Cignet that they were requesting copies of their medical records so they could see doctors other than those working at Cignet, according to HHS documents.
To date HHS Secretary Sebelius has failed to enact several parts of healthcare legislation related to records due in Summer 2010.

Selections from Natural Health News
 
Oct 17, 2010
I started posting articles about electronic health and medical records in 2006 on Natural Health News. I am not in favour of this push in the arena of cost savings in the US health system. To date little has been shown to indicate any 
Jul 19, 2010
1 in 10 medical records on the new electronic database contains errors that could put patients at risk, doctors warn. They contain out of date information, errors on medication or drug allergies etc. ...
Jul 28, 2009
We also know that electronic medical record will not save money as well as the fact that HIPAA was the open sesame for everyone to get access to your data. You do have a choice, and most likely it is to find a health care professional
Nov 17, 2009
I started posting articles about electronic health and medical records in 2006 on Natural Health News. I am not in favour of this push in the arena of cost savings in the US health system. To date little has been shown to indicate any
May 21, 2008
Google's online filing cabinet for medical records opened to the public Monday, giving users instant electronic access to their health histories while reigniting privacy concerns. Called Google Health, the service lets users link ...

Wednesday, September 22, 2010

HIPAA: Privacy Still at Risk

Most people have been led to believe that HIPAA is to protect your information, especially your health information.  That has never been the case and here is an item that calls this to your attention, even though we have been reporting on this for many years.
It is important to note that the HIPAA privacy rule permits public-health workers to use and disclose individually identifiable health data without patients' authorization. This is a major loophole that allows patients’ personal health information to be shared with many others—without their consent.  (See 45 CFR Subtitle A, Subpart E—Privacy of Individually Identifiable Health Information; section 164.512 “Uses and disclosures for which an authorization or opportunity to agree or object is not required.”)
Further, the information below should be an eye opener. 


Proposed Changes to Privacy Rule Won’t Ensure Privacy
The federal government once again is modifying the HIPAA privacy rule.  This time around it’s modifying the rule to incorporate legal requirements in the economic stimulus law passed in 2009.   But since that law doesnot require consent before health information is shared for most purposes (including treatment, payment, and health-care operations), the modifications will fail to truly protect health privacy rights.  IHF first reported on this in March 2009: http://forhealthfreedom.org/Newsletter/March2009.html#Article2  
IHF noted that while the stimulus law aimed to prohibit the sale of electronic health records, the exceptions are so broad that it fails to meet its purported objective.  In fact, the stimulus law actually permits the selling of Americans’ electronic health records for public-health and research purposes—without patients’ consent.  The stimulus law also limits insurers’ access to health data, but only if patients pay out-of-pocket and forgo insurance reimbursement. 
Additionally, the stimulus law expanded the number of people authorized to access patients’ personal health information without patients’ consent.  Previously HHS estimated that about 600,000 covered entities (and their employees) would have access to patients’ data for many purposes.  However, the stimulus law added some 1.5 million “business associates” who can legally access patients’ health records—without patients’ consent.  Now over 2 million health-related organizations and their business partners will have legal access to patients’ health data without consent in many circumstances (see table below).  

Number of Health-Care Entities and Business Associates With Access to
Patients’ Health Information under HIPAA Privacy Rule
Health-Care Entity
Number
Business Associates* (conduct business on behalf of entities listed below)
1,500,000
Office of MDs, DOs, Mental Health Practitioners, Dentists, PT, OT, ST, Audiologists 
419,286
Durable Medical Equipment Suppliers
107,567
Pharmacies
88,396
Nursing Facilities**
34,400
Home Health Service Covered Entities
15,329
Outpatient Care Centers***
13,962
Medical Diagnostic, and Imaging Service Covered Entities 
7,879
Other Ambulatory Care Service Covered Entities (Ambulance and Other)
5,879
Hospitals (General Medical and Surgical, Psychiatric, Substance Abuse, Other Specialty)
4,060
Third Party Administrators Working on Behalf of Covered Health Plans 
3,522
Health Insurance Carriers 
1,045
Total Entities and Business Associates
2,201,325
* According to HHS, examples of business associates include third-party administrators or pharmacy benefit managers for health plans, claims processing or billing companies, transcription companies, and persons who perform legal, actuarial, accounting, management, or administrative services for covered entities and who require access to protected health information. 
** Includes nursing care facilities, residential mental retardation facilities, residential mental health and substance abuse facilities, community care facilities for the elderly, and continuing care retirement communities. 
*** Includes family planning centers, outpatient mental health and drug abuse centers, other outpatient health centers, HMO medical centers, kidney dialysis centers, freestanding ambulatory surgical and emergency centers,  and all other outpatient care centers.
Source: “Modifications to the HIPAA Privacy, Security, and Enforcement Rules Under the Health Information Technology for Economic and Clinical Health Act,” RIN: 0991–AB57, Federal Register, Vol. 75, No. 134, July 14, 2010 (see pages 40872, 40906, 40907, 40911).

Thus, the stimulus law expanded the number of people who can access patients’ health information but stillfailed to give patients the final say in who may—and may not—see their most personal health records. Rather than tinkering around the edges modifying the weak HIPAA privacy rule (as required by the stimulus law), it’s time to call on Congress to change the law to ensure that patient consent is required before personal health information is shared for any purpose, including public health. 

What’s more, although the stimulus law doesn’t give patients the right to control the electronic flow of their health information, it does require the secretary of HHS to post a list of breaches of “unsecured protected” (HHS’s term!) health information affecting 500 or more individuals.  The breaches are posted here:http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/breachtool.html 

Sources:
“How the Economic Stimulus Law Affects Your Health Privacy Rights,” Health Freedom Watch newsletter published by the Institute for Health Freedom, March 2009:http://forhealthfreedom.org/Newsletter/March2009.html#Article2


 
Design by Free WordPress Themes | Bloggerized by Lasantha - Premium Blogger Themes | Macys Printable Coupons