Home -> Law Blog Directory -> Health Law Blogs -> HealthBlawg
(866) 635-2689 for Personal Injury or (866) 635-9402 for Criminal Defense
Find a Local Lawyer
Divorce (866) 635-6190
Personal Injury (866) 635-2689
Criminal Defense (866) 635-9402
Health Law
: HealthBlawgHIPAA enforcement: Business Associate Agreement rulemaking needed first - time to plan ahead
By David Harlow
After learning of comments on HIPAA enforcement made by a member of the HHS OCR legal staff at an ABA meeting on health care issues, I contacted him directly. Adam Greene confirmed that HITECH Act changes to HIPAA rules regarding business associate agreements will be implemented through standard notice and comment rulemaking, noting that this has been OCR's public take on the issue. Thus, a notice of proposed rulemaking will be published "shortly," followed by promulgation of a final rule after a comment period. Even thought the statute calls for the BAA provisions to be effective this month, they clearly will not be. The breach notification and penalty provisions are already the subject of an interim final rule, so they are in effect.
As I wrote several months ago,
"business associates" under HIPAA are now required to implement policies and procedures to maintain privacy and security of PHI, parallel to those that have been required of "covered entities" under HIPAA since the beginning. All business associate agreements and notice of privacy practices (NPPs) will have to be updated to account for the new requirements before February. Health care providers that wish to distinguish themselves should consider revising their NPPs to highlight the ease with which they will make copies of records available to patients. This is a bone of contention for many patients, and ensuring that patients' rights to their records are easily exercised could be a way to build goodwill among patients and potential patients.
Thanks to Bob Coffield for pointing to the post on the ABA meeting and raising the question.
I urge all covered entitites and business associates to take heed of these new requirements and begin planning now for implementation of the soon-to-be-released regulations. Don't sit back and end up being made an example of by OCR (e.g., with a million-dollar fine) or by a state attorney general. Contact the HealthBlawger now.
David HarlowThe Harlow Group LLC
Health Care Law and Consulting
Full post as published by HealthBlawg on February 22, 2010 (boomark / email).
HHS lax HIPAA enforcement
OIG slaps down HHS for lax HIPAA enforcement: The OIG has sent HHS a letter grading it's HIPAA enforcement activities. Apparently the OIG wants HHS to be more like it, at least in terms of aggressiveness...
HITECH/HIPAA: Who is a Business Associate
Business Associate (BA): This term has broad applicability under HITECH/HIPAA and includes "partners" wherein the product/service provided requires the disclosure of protected health information (PHI)...
Microsoft HealthVault: You put your right HIPAA in . . .
In a post today, Sean Nolan, Chief Architect of Microsoft Health Solutions and blogger at Family Health Guy explains Microsoft's position regarding whether Microsoft HealthVault is required to comply with the privacy standards under the Health Insurance Portability and Accountability Act of 1996 (HIPAA)...
CVS Reaches $2.25 Million Settlement Agreement
The U.S. Department of Health and Human Services and the Federal Trade Commission announced today that CVS will pay the U.S. government a $2.25 million settlement and take corrective action in connection with the government finding that CVS had violated the HIPAA Privacy Rule by failing to safeguard identifying information during disposal...
Providence's HIPAA Corrective Action Plan
As promised, here is a link to a copy of the Corrective Action Plan between Providence Hospital and the federal government.
HIPAA Audits Will Increase in 2008
In 2008, the Centers for Medicare & Medicaid Services (CMS) announced that it entered into a contract with a PricewaterhouseCoopers to audit covered entities and ensure compliance with the HIPAA security standards...
Prenuptial Agreements
Make an Airtight Prenuptial Agreement
COBRA Continuation of Healthcare Coverage after Layoff
Pensions and Health Care Coverage for Dislocated Workers
Uniform Pre-marital Agreement Act
Standard Prenuptial Law
Child Support Survival Guide
The Child Support Enforcement System
Traditional and Roth 401Ks
Selecting the right Retirement Plan
H&R Block Retirement Plan Fraud
How to Join Class Action Suit
Baltimore Strip Search Class Action
Judge Gives Go-ahead
Wesley A. Snyder et al.
alleging the consultants perpetrated a Ponzi scheme by encouraging borrowers to lend more than they needed.
Firm Associate
Attorney Jay Wingate ordered to pay widow $2.5 million settlement for collected legal fees.
Immigration and Customs Enforcement
alleging government agencies and officials violated immigrant workers' constitutional rights.
PhotoCop Tickets
Minneapolis to pay $2.6 million settlement in traffic enforcement lawsuit.
Loan Agreement
Vernalis to pay Endo Pharmaceuticals $7 million settlement.








