Skip to main content

Wilson Juniors Complete Golf Set

HIPAA Law Protects Against Improper Disclosure of Health Information by Health Care Providers

HIPAA Law Protects Against Improper Disclosure of Health Information by Health Care Providers

HIPAA: A Practical Guide to the Privacy and Security of Health Data 2nd Edition

 


In June 2009, a 22-year-old Honolulu mother of three young children was sentenced to a year in prison for illegally accessing another woman's medical records and posting on a MySpace page that she had HIV.

HIPAA Law Protects Against Improper Disclosure of Health Information by Health Care Providers

HIPAA Law Protects Against Improper Disclosure of Health Information by Health Care Providers

HIPAA Law Protects Against Improper Disclosure of Health Information by Health Care Providers


HIPAA Law Protects Against Improper Disclosure of Health Information by Health Care Providers



HIPAA Law Protects Against Improper Disclosure of Health Information by Health Care Providers

The State of Hawaii brought charges against the woman under a state statute criminalizing the unauthorized access to a Computer; and which categorized the conduct of the defendant as a class B felony.

According to accounts of the incidents that led to the woman's conviction, there was a feud between the victim and the victim's sister-in-law, a friend of the defendant. The defendant, who worked as a patient service representative at the hospital where the victim was a patient, accessed the Computer for the victim's sister-in-law.

Over the course of approximatelyten months, the defendant accessed the patient's medical records three times through a computer. After she learned of the victim's medical condition, the defendant posted on her MySpace page that the victim had HIV. In a second posting, she said the victim was dying of AIDS.

The victim complained to hospital officials of the unauthorized access. After an internal investigation the hospital terminated the defendant's employMent.

The defendant's conduct, of course, was egregious and inexcusable. The one-year jail term handed down by the Court exceeded the term recomMended by the prosecutor. Nevertheless, beyond the issue of holding the defendant accountable for her actions "some may question to what extent the hospital should bear responsibility for the breaches ofconfidentiality that occurred.

Federal law imposes statutory burdens on health care providers to protect against the improper use or disclosure of personal health information and to reasonably limit uses and disclosures to the minimum necessary to accomplish their intended purpose.

Specifically, the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") privacy regulations became effective on April 14, 2003. HIPAA is intended to protect consumers ' health information, allow consumers greater access and control to such information, enhance health care, and finally to create a national framework for health privacy protection. HIPAA covers health plans, health care clearinghouses, and those health care providers that conduct certain financial and administrativetransactions electronically.

In addition to the privacy regulations, HIPAA's security rule became effective on April 21, 2005. Together the privacy and security regulations are the only national set of regulations that governs the use and disclosure of private, confidential and sensitive information.

Under HIPAA's Security Rule, the standards for the protection of electronic information covered by HIPAA are divided into three groups: Administrative safeguards, Physical safeguards and Technical safeguards.

A couple of the most significant safeguards required under HIPAA are the Administrative "Sanction Policy" and "Security Awareness Training" safeguards.

The sanction policy standard requires a communication to all employees regarding the disciplinary action thatwill be taken by the covered entity for violations of HIPAA. The sanction policy should have a notice of civil or criminal penalties for misuses or misappropriation of health information and make employees aware that violations may result in notification to law enforcement officials and regulatory, accreditation, and licensure organizations.

The security awareness training standard requires all employees, agents, and contractors to participate in information security awareness training programs. Based on Job responsibilities, the covered entity should require individuals to attend customized education programs that focus on issues regarding use of health information and responsibilities regarding confidentiality and security.

The HIPAA privacy and security regulations requirea privacy officer and security officer to be designated by the covered entity. The privacy and security officer should continually analyze and manage risk by thoroughly assessing potential risks and vulnerabilities, and implementing related security measures.

The U.S. Department of Justice ("DOJ") clarified the penalties that may be assessed and against whom for HIPAA violations. Covered entities and individuals whom "knowingly" obtain or disclose individually barly identifiable health information in violation of HIPAA may be fined up to $ 50,000, as well as up to one year imprisonment (novel).

Offenses committed under false pretenses allow penalties to be increased--a $ 100,000 fine, with up to five years in prison. Finally, offenses committed with the intent to sell, transfer, or useindividually barly identifiable health information for commercial advanTAGe, personal gain, or malicious harm permit fines of $ 250,000 and imprisonment (novel) for up to ten years.

Given the security breach that led to the tragic events, including the one-year jail term for the defendant, Hawaii employers, health care providers and health plans should review their privacy and HIPAA policies and conduct an audit of their practices in order to protect against the improper use and disclosure of private health information and to reduce the risk of privacy breaches in their own organization.

HIPAA Law Protects Against Improper Disclosure of Health Information by Health Care Providers

Comments

Popular posts from this blog

The 8 Most Common Signs Of Cheating

The 8 Most Common Signs Of Cheating   Does your partner suddenly seem cold and distant to you? Or, is he sometimes exaggeratedly caring and affectionate? Does he delete text messages and calls, which he didn't usually do before? If your answers to these questions are yes, then he or she is possibly cheating on you. The 8 Most Common Signs Of Cheating The 8 Most Common Signs Of Cheating The 8 Most Common Signs Of Cheating The 8 Most Common Signs Of Cheating According to statistics, most Men and woMen cheat. It is one of the most inevitable problems that every relationship has to face. However, signs of cheating vary from one person to another. Seeing one or two signs cannot really prove that your spouse is having an affAir. But if you notice most of these signs, plus your instinct bugs you most of the time, you probably need to keep your senses sharp. This article will cite the eight most common signs of cheating observed from both Men andwomen. 1. Ther...

Working at Height-How to Develop a Rescue Plan

Working at Height-How to Develop a Rescue Plan   Rescue plans don't have to be complex. Working at Height-How to Develop a Rescue Plan Working at Height-How to Develop a Rescue Plan Working at Height-How to Develop a Rescue Plan Working at Height-How to Develop a Rescue Plan Employers should impleMent a rescue plan that includes procedures for: Preventing prolonged suspension Performing rescue and treatMent as quickly as possible Identifying suspension trauma signs and symptoms ManageMent responsibility for safety needs to give careful consideration to the methodology of rescuing a fallen. Such considerations might include: Dialing 999 (911). -Often we think of the word ' rescue ' as calling 999 (911), but calling the local fire brigade does not constitute an effective rescue plan. Response times can be too slow, and not all fire brigades have the capability to rescue from height. Crane Man Basket -This option has severe limitations, the m...

How to Detect the Presence of Ghosts and Other Spirits

How to Detect the Presence of Ghosts and Other Spirits   Haunting happens - it's more popular than many people would like to think. One of the practical aspects of every book that discusses ghosts and other paranormal activities, is a way to test if your house is haunted. In other words, how to detect the presence of ghosts and spirits? There are many ways to do so, that I'm going to describe right now. Cold Spots One of the most popular phenoMenons regarding haunting and ghosts is called "cold spots". As the name states, those are the spots of cold Air that can be sensed out of nowhere. Imagine that you're walking through warm corridor, and suddenly you can sense cold space. You're making few steps forward, and it's warm again. You're going back, and cold spot is still there. It is believed for cold spots to be places where ghosts and spirits draw psychic energies to sustain their own "life" energies. Just be careful not to consider A...