YOUR BUSINESS AUTHORITY

Springfield, MO

Log in Subscribe

Guest Column: Stimulus package expands health information protections

Posted online
On Feb. 17, President Barack Obama signed the Health Information Technology for Economic and Clinical Health Act into law as part of the American Recovery and Reinvestment Act of 2009. The act, also known as HITECH, expands the privacy and security protections provided by the Health Insurance Portability and Accountability Act and increases enforcement and penalties for violating those rules. Many of the provisions become effective in February of 2010, but some have earlier or later effective dates. These provisions have significant impact on players in the health care industry.

Notification changes

One significant HITECH requirement set to take effect in September mandates that covered entities notify individuals, the government, and in some cases, major media outlets about breaches of "unsecured" protected health information. Business associates are required to notify covered entities about any breaches. Under current laws, entities must only mitigate the known harmful effects of a breach.

HITECH stipulates that when a breach within the meaning of the law occurs, covered entities must notify affected individuals in writing. If more than 500 individuals in a state are involved, covered entities must notify major media outlets serving the state. Additionally, an annual log of breaches must be submitted to the U.S. Department of Health and Human Services.

Recently, a "safe harbor" to the notification requirements was created through HHS guidance. Specifically, if a breach involves protected health information that has been encrypted or destroyed through specific standards adopted by HHS, the notification requirements don't apply.

It is wise for covered entities and business associates to review their standards for encryption of electronic information as well as the destruction of information. They also should review their practices for safeguarding all protected health information. Any information, whether paper or electronic, which is not secured through the specified standards is subject to the notification requirements.

Business associate responsibilities

Business associates are individuals or entities that perform certain functions and activities involving the use or disclosure of protected health information on behalf of covered entities. HITECH expands the view of "business associate" to include certain types of entities such as health information exchange organizations and vendors of personal health records. It also extends responsibility for direct compliance with various privacy and security standards to business associates and subjects them to the same penalties for violations that apply to covered entities.

The provisions extending direct compliance to business associates go into effect in February. In the interim, covered entities and business associates should review existing arrangements and be prepared to amend or execute new business associate agreements that incorporate the new privacy and security requirements established by HITECH.

Patient rights

HITECH also strengthens patient rights to control their health information. Patients have the right to request a covered entity to restrict its use of their information for payment purposes.

A common request would be to ask a provider to refrain from billing a health insurer for a particular test or treatment. Covered entities are not required to accommodate the request under existing rules. Under HITECH, however, if a patient already has paid out-of-pocket for a service, a health care provider will be required to accommodate the patient's request. Health care providers need to evaluate their billing practices and work flow to assure that they can comply with such requests.

HITECH also enables patients to obtain copies of their medical information in electronic format, and to direct providers to transmit the copies to another entity or individual, provided the entity uses an "electronic health record" within the meaning of the law. Providers will need to work with their vendors to assure that their systems can readily produce electronic record copies and to determine the systems' capabilities to securely transmit information to external entities.

HITECH also requires entities using electronic health records within the meaning of the law to track disclosures made for purposes of treatment, payment and operations. Providers will need to evaluate the ability of their electronic health record systems to produce this information.

The new rules also supplement several other existing privacy standards, such as those for using the "minimum necessary" medical information, marketing and fundraising. It also creates a general prohibition against the sale of health information unless various exceptions are met and establishes privacy standards for vendors of personal health records and other entities that have not historically been covered under the HIPAA rules.

Overall, HITECH expands the responsibility of the health care industry to protect the privacy and security of patient information. Questions remain about how the new standards will be implemented and enforced, and about how those standards will fit with existing state laws. In the next several months, HHS will publish regulations and guidance, but affected entities in southwest Missouri should begin preparing for the standards now.Frank Evans III is a partner in the Springfield office of Lathrop & Gage LLP. He has tried lawsuits in state and federal courts throughout southwest Missouri and in Kansas City and St. Louis, including jury and nonjury matters involving the health care industry. He can be reached at fevans@lathropgage.com.

Comments

No comments on this story |
Please log in to add your comment
Editors' Pick
Fall 2026 Architects & Engineers Project Report

This installment of Springfield Business Journal’s Architects & Engineers Project Report showcases 26 endeavors by area design and engineering professionals.

Most Read
Update cookies preferences