Government
HHS rules require patient notification of privacy breaches
NEWS IN BRIEF — Posted Aug. 31, 2009
New Dept. of Health and Human Services regulations will require physicians and other entities covered by the Health Insurance Portability and Accountability Act to notify patients promptly and directly when the security of their private health information has been breached by unauthorized parties.
The government hopes that the rules will bolster privacy and security, as well as patient trust, as use of electronic health records and other paperless information becomes more widespread. The regulations were authorized under the latest federal stimulus act and will take effect 30 days after their Aug. 19 publication date.
Breaches affecting more than 500 individuals at one time also must be reported promptly to HHS and to the media, whereas anything smaller must be reported to the government on an annual basis.
The HHS rules, which are open to a 60-day comment period, accompany similar requirements released by the Federal Trade Commission that apply to vendors of personal health information systems and other non-HIPAA entities.
Note: This item originally appeared at http://www.ama-assn.org/amednews/2009/08/31/gvbf0831.htm.












