<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Avoid Breach Notification - Experior helps PHI Encryption &#187; Rulings</title>
	<atom:link href="http://www.experiordata.com/blog/category/rulings/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.experiordata.com/blog</link>
	<description>Encrypt your PHI, and avoid breach notification</description>
	<lastBuildDate>Tue, 18 May 2010 04:09:33 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>3 steps for breach notification protection</title>
		<link>http://www.experiordata.com/blog/2010/02/16/3-steps-for-breach-notification-protection/</link>
		<comments>http://www.experiordata.com/blog/2010/02/16/3-steps-for-breach-notification-protection/#comments</comments>
		<pubDate>Tue, 16 Feb 2010 14:37:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Regulation]]></category>
		<category><![CDATA[Rulings]]></category>
		<category><![CDATA[Section 13402]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[Data security]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=399</guid>
		<description><![CDATA[Using encryptio to protect phi creates a safe harbor against breach notification. 3 steps to help you comply with breach notification safe harbor in HITECH Act/HIPAA Security rule.]]></description>
			<content:encoded><![CDATA[<p>Beginning on February 18, HHS will have the legal authority to enforce the breach notification laws set forth last year as part of section 13402 of the HITECH Act,  within the American Recovery &amp; Reinvestment Act (ARRA). The penalties can now be up to $1.5 million and require media notification in cases where 500 or more records are breached. Business associates, as well as covered entities, must now comply with the HITECH Act breach notification rule (which essentially makes modifications to the <a class="zem_slink" title="Health Insurance Portability and Accountability Act" rel="wikipedia" href="http://en.wikipedia.org/wiki/Health_Insurance_Portability_and_Accountability_Act">HIPAA</a> Security Rule).</p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<ol>
<li>Perform an extensive security review and indentify where electronic protected health information (PHI or ePHI) resides on your IT systems. </li>
<li>Create a plan on protecting PHI.
<ul>
<li>Data <a class="zem_slink" title="Encryption" rel="wikipedia" href="http://en.wikipedia.org/wiki/Encryption">encryption</a> provides a <a class="zem_slink" title="Safe harbor" rel="wikipedia" href="http://en.wikipedia.org/wiki/Safe_harbor">safe harbor</a> from breach notification. Determine where PHI can be encrypted.</li>
<li>Identify public facing extranet portals and web applications that can allow access to PHI.</li>
<li>Identify databases that hold PHI.</li>
<li>Execute the plan </li>
</ul>
<ul>
</ul>
<ul>
</ul>
</li>
<li> Implement data encryption where practical.
<ul>
</ul>
<ul>
<li>For databases, implement a database security product to monitor database requests and protect from intrusion.</li>
</ul>
<ul>
<li>For web apps, implement a web application security product to protect from <a class="zem_slink" title="Cross-site scripting" rel="wikipedia" href="http://en.wikipedia.org/wiki/Cross-site_scripting">cross-site scripting</a> and various attacks to access databases to PHI.</li>
</ul>
<ul>
<li>Protect endpoints such as laptops, tablets, etc with data at rest encryption by implementing whole disk encryption,</li>
</ul>
<ol> </ol>
</li>
</ol>
<p><br class="spacer_" /></p>
<p>Experior Data helps customers plan and execute data security assessments and technology implementation for healthcare. Our proprietary Technical Security Audit includes a personalized review of your IT systems and well as a vulnerability scan of all your network components.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://healthblawg.typepad.com/healthblawg/2009/09/hitech-act-security-breach-rules-now-effective-federales-give-a-sixmonth-pass.html">HITECH Act security breach rules now effective; federales give a six-month pass. Now&#8217;s the time to kick compliance efforts into high gear</a> (healthblawg.typepad.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.slideshare.net/jonneiditz/hitech-and-state-breach-notification">HITECH and State Breach Notification</a> (slideshare.net)</li>
<li class="zemanta-article-ul-li"><a href="http://yro.slashdot.org/story/09/09/19/2157217/Using-Encryption-Garners-Exemption-For-Data-Breach-Notification?from=rss">Using Encryption Garners Exemption For Data Breach Notification</a> (yro.slashdot.org)</li>
<li class="zemanta-article-ul-li"><a href="http://healthblawg.typepad.com/healthblawg/2009/11/son-of-hipaa-breach-notification-rules-whos-ready.html">Son of HIPAA Breach Notification Rules and Business Associate Requirements: Who&#8217;s Ready?</a> (healthblawg.typepad.com)</li>
<li class="zemanta-article-ul-li"><a href="http://hunscher.typepad.com/futurehit/2010/01/the-cost-of-fear-why-docs-dont-embrace-technology.html">The Cost of Fear | Why Docs Don&#8217;t Embrace Technology (Dr. Rob)</a> (hunscher.typepad.com)</li>
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www.newswire.ca/en/releases/archive/February2010/01/c5838.html&amp;a=12426180&amp;rid=3a0266f6-3270-43a7-9d5d-72d3000b6dd6&amp;e=11c996da2d350263f04bcb67deeb4620">PGP Corporation to Announce Acquisition</a> (newswire.ca)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/3a0266f6-3270-43a7-9d5d-72d3000b6dd6/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=3a0266f6-3270-43a7-9d5d-72d3000b6dd6" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><br />
<script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script><br />
<br />
 </span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2010/02/16/3-steps-for-breach-notification-protection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Analysis of Privacy &amp; Security in Meaningful Use rule</title>
		<link>http://www.experiordata.com/blog/2009/12/31/analysis-of-privacy-security-in-meaningful-use-rule/</link>
		<comments>http://www.experiordata.com/blog/2009/12/31/analysis-of-privacy-security-in-meaningful-use-rule/#comments</comments>
		<pubDate>Thu, 31 Dec 2009 21:38:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Regulation]]></category>
		<category><![CDATA[Rulings]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=366</guid>
		<description><![CDATA[HHS released the interim final rule on meaningful use. Certified EHRs must include encryption technology to protect patient records. However, Certified EHRs DO NOT protect from HIPAA Security and Privacy rules.]]></description>
			<content:encoded><![CDATA[<h2>HHS Issues Interim Final Rule on Meaningful Use of Certified <a class="zem_slink" title="Electronic health record" rel="wikipedia" href="http://en.wikipedia.org/wiki/Electronic_health_record">Electronic Health Records</a></h2>
<h2>
<dt class="wp-caption-dt"> </dt>
</h2>
<p>On Wednesday, December 30th, the U.S <a class="zem_slink" title="United States Department of Health and Human Services" rel="wikipedia" href="http://en.wikipedia.org/wiki/United_States_Department_of_Health_and_Human_Services">Department of Health and Human Services</a> (HHS) released its Interim Final Rule on Meaningful use. This rule is applicable to covered entities who chose to participate in the <a title="Center for Medicare and Medicaide web site describing the incentive program for elegible professionals and elegible hospitals" href="http://www.cms.hhs.gov/Recovery/11_HealthIT.asp" target="_blank">Medicare and Medicaid EHR Incentive Programs.</a> Essentially, healthcare providers must prove that they are using the EHRs and meet HHS&#8217;s standards of meaningful use in order to receive reimbursement for implementing the EHR system.</p>
<h2>Stages</h2>
<p><strong>Stage 1 </strong>(starting in 2011):  Focused on electronically <strong>capturing</strong> health information, <strong>implementing</strong> clinical decision support tools to facilitate disease and medication management, and <strong>reporting </strong>clinical quality measures and public health information. Note that in this stage <strong>electronic protected health information (PHI)</strong> is being captured and stored, and as a result, must be secured. <span style="text-decoration: underline;"><strong>It is this specific information that must be protected from <a class="zem_slink" title="Computer security" rel="wikipedia" href="http://en.wikipedia.org/wiki/Computer_security">security breaches</a>.</strong></span></p>
<p><span style="text-decoration: underline;"><strong><br />
 </strong></span></p>
<p><strong>Stage 2 </strong>(starting in 2013):<strong> </strong>Focused on using captured information to improve care, electronic transmission of diagnostic test results, and computerized provider order entry (CPOE).</p>
<p><br class="spacer_" /></p>
<p><strong>Stage 3 </strong>(starting in 2015): Focused on decision support and improvements in quality and safety.</p>
<p><br class="spacer_" /></p>
<h2>Role of Security &amp; Privacy in Meaningful Use</h2>
<p>In general, HHS has specifically <strong>included</strong> encryption as a requirement for a Certified EHR system (only Certified EHR systems are eligible for cost reimbursement). The inclusion of encryption in meaningful use is indicative of the Federal government&#8217;s recognition that encryption is a critical technology in securing protected health information (PHI).</p>
<p><br class="spacer_" /></p>
<p>Certified EHRs must be able to provide the patient an <strong>electronic</strong> copy of their health information upon their request. This information must be provided within 96 hours from the time the provider obtains the information, such as lab results, for example. This patient information must secured with <strong>at least </strong>a symmetric 128 bit fixed-block cipher algorithm capable of using 128, 192, or 256 bit <a class="zem_slink" title="Encryption" rel="wikipedia" href="http://en.wikipedia.org/wiki/Encryption">encryption key</a>.</p>
<p><br class="spacer_" /></p>
<p>Certified EHRs must protect electronic health information by implementing controls and encyption, such as:</p>
<p>- Assigning a unique user name for each user</p>
<p><img src="file:///Users/Alex/Library/Caches/TemporaryItems/moz-screenshot-4.png" alt="" />- Encrypt and decrypt health information for backups, removable media, etc.</p>
<p>- Event recording such as deletion of records</p>
<p>- Audit review log</p>
<p>- Systems to ensure health information has not been altered using a hash algorithm</p>
<p>- Record disclosures made for treatment</p>
<p>- Ensure identity management is in place<img src="file:///Users/Alex/Library/Caches/TemporaryItems/moz-screenshot-5.png" alt="" /><img src="file:///Users/Alex/Library/Caches/TemporaryItems/moz-screenshot-6.png" alt="" /><img src="file:///Users/Alex/Library/Caches/TemporaryItems/moz-screenshot-7.png" alt="" /><img src="file:///Users/Alex/Library/Caches/TemporaryItems/moz-screenshot-2.png" alt="" /><img src="file:///Users/Alex/Library/Caches/TemporaryItems/moz-screenshot-1.png" alt="" /><img src="file:///Users/Alex/Library/Caches/TemporaryItems/moz-screenshot.png" alt="" /></p>
<ul>
</ul>
<h2>Systems outside of Certified EHRs</h2>
<p>As a matter of policy HHS has decided NOT to dictate standards on privacy and security in the context of meaninful use for systems other than Certified EHRs. In other words, they acknowledge that there are other systems that are part of the electronic health IT ecosystem, such as backup systems, hard drives, removable media,  domain name systems (<a class="zem_slink" title="Domain Name System" rel="wikipedia" href="http://en.wikipedia.org/wiki/Domain_Name_System">DNS</a>), time servers (NNTP), etc. They acknowledge that these systems should be protected. However, for the purposes of the scope of the ruling they decided not to dictate standards or requirements beyond those for the actual EHR system.</p>
<h2>Application of <a class="zem_slink" title="Health Insurance Portability and Accountability Act" rel="wikipedia" href="http://en.wikipedia.org/wiki/Health_Insurance_Portability_and_Accountability_Act">HIPAA</a> Privacy and Security Rule</h2>
<p>HHS took the time to reiterate that using a Certified EHR <strong>&#8220;<span style="text-decoration: underline;"><em>does not </em>change existing HIPAA Privacy Rule or Security Rule requirements</span>, guarantee compliance with those requirements, or absolve an eligible professional, eligible hospital, or other health care provider who adopts Certified EHR Technology from having to comply with any applicable provision of the HIPAA Privacy or Security Rules.</strong></p>
<p><strong><br />
 </strong></p>
<p>This essentially means that you must still consider the security of systems outside the Certified EHR system and, if necessary, secure these systems. Implementing a Certified EHR system does not absolve your organization from the HIPAA Privacy and Security Rules. They go on further to say:</p>
<p><br class="spacer_" /></p>
<p>&#8220;While the capabilities provided by Certified EHR Technology may assist an eligible professional or eligible hospital in improving their technical safeguards in order to meet some or all of the HIPAA Security Rule’s requirements or influence their risk analysis, <em><span style="text-decoration: underline;"><strong>the use of Certified EHR Technology alone does not equate to compliance with the HIPAA Privacy or Security Rules.</strong></span></em></p>
<p><em><span style="text-decoration: underline;"><strong><br />
 </strong></span></em></p>
<p>Make sure you look at out healthcare IT system holistically. Implementing a Certified EHR is only part of the overall security equation in your organization.</p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://healthcarebloglaw.blogspot.com/2009/12/cms-and-onc-issue-rules-on-proposing.html">CMS and ONC Issue Rules on Proposing a Definition of Meaningful Use and Setting Standards for EHR Incentive Program</a> (healthcarebloglaw.blogspot.com)</li>
<li class="zemanta-article-ul-li"><a href="http://healthblawg.typepad.com/healthblawg/2009/11/son-of-hipaa-breach-notification-rules.html">Son of HIPAA Breach Notification Rules</a> (healthblawg.typepad.com)</li>
<li class="zemanta-article-ul-li"><a href="http://seattletimes.nwsource.com/html/businesstechnology/2010642103_apusmedicalrecordsstimulusmoney.html?syndication=rss">Medicare officials plan for health stimulus funds</a> (seattletimes.nwsource.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.huffingtonpost.com/2009/12/30/switch-to-electronic-heal_n_407865.html">Switch To Electronic Health Records Could Miss Federal Targets</a> (huffingtonpost.com)</li>
<li class="zemanta-article-ul-li"><a href="http://healthmgmtrx.blogspot.com/2009/12/cms-proposes-definition-of-meaningful.html">Cms Proposes Definition of Meaningful Use of Certified Electronic Health Records (ehr) Technology</a> (healthmgmtrx.blogspot.com)</li>
<li class="zemanta-article-ul-li"><a href="http://ducknetweb.blogspot.com/2009/12/meaningful-use-556-page-proposed-rule.html">Meaningful Use 556 Page Proposed Rule is Out &#8211; Thanks WSJ for the Shortcut to the Meat and Potatoes</a> (ducknetweb.blogspot.com)</li>
<li class="zemanta-article-ul-li"><a href="http://blog.deurainfosec.com/hipaa-and-business-associate">HIPAA and business associate</a> (deurainfosec.com)</li>
<li class="zemanta-article-ul-li"><a href="http://clinicalit.blogspot.com/2009/12/heres-rule-for-meaningful-use.html">Here&#8217;s the rule for meaningful use</a> (clinicalit.blogspot.com)</li>
<li class="zemanta-article-ul-li"><a href="http://chilmarkresearch.com/2009/12/31/meaningful-use-rules-hit-the-streets/">Meaningful Use Rules Hit the Streets</a> (chilmarkresearch.com)</li>
<li class="zemanta-article-ul-li"><a href="http://histalk2.com/2009/12/30/onchit-releases-preliminary-definition-of-meaningful-use/">ONCHIT Releases Preliminary Definition of Meaningful Use</a> (histalk2.com)</li>
<li class="zemanta-article-ul-li"><a href="http://projecthealthdesign.typepad.com/project_health_design/2009/08/further-clarifications-of-meaningful-use-are-needed-.html">Further Clarifications of &#8220;Meaningful Use&#8221; Are Needed</a> (projecthealthdesign.typepad.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/6e87899c-e6e7-4f3a-9683-3d2ac9ec511b/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=6e87899c-e6e7-4f3a-9683-3d2ac9ec511b" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><br />
<script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p></span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/12/31/analysis-of-privacy-security-in-meaningful-use-rule/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security for Meaningful Use: Part 2 &#8211; Electronic Access to Protected Health Information (PHI)</title>
		<link>http://www.experiordata.com/blog/2009/12/31/security-for-meaningful-use-part-2-electronic-access-to-protected-health-information-phi/</link>
		<comments>http://www.experiordata.com/blog/2009/12/31/security-for-meaningful-use-part-2-electronic-access-to-protected-health-information-phi/#comments</comments>
		<pubDate>Thu, 31 Dec 2009 17:34:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Encyption]]></category>
		<category><![CDATA[PGP]]></category>
		<category><![CDATA[Rulings]]></category>
		<category><![CDATA[Add new tag]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[Health Insurance Portability and Accountability Act]]></category>
		<category><![CDATA[PHI]]></category>
		<category><![CDATA[Pretty Good Privacy]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=352</guid>
		<description><![CDATA[Standards Set for Providing Secure Access to Patient Records





Image via Wikipedia



According to the Initial Set of Standards for Electronic Health Records patients must be provided with their health information (most certainly protected health information -PHI- under HIPAA) electronically and securely within 96 hours.


&#8220;Consistent with the HIT Policy Committee&#8217;s recommendations, we propose the following additional clarification [...]]]></description>
			<content:encoded><![CDATA[<h2>Standards Set for Providing Secure Access to Patient Records</h2>
<p><br class="spacer_" /></p>
<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 310px;">
<dt class="wp-caption-dt"><a href="http://en.wikipedia.org/wiki/Image:VistA_Img.png"><img title="Sample patient record view from VistA Imaging" src="http://upload.wikimedia.org/wikipedia/en/thumb/8/8f/VistA_Img.png/300px-VistA_Img.png" alt="Sample patient record view from VistA Imaging" width="300" height="225" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://en.wikipedia.org/wiki/Image:VistA_Img.png">Wikipedia</a></dd>
</dl>
</div>
</div>
<p>According to the <a title="Initial set of standards for certified electronic health records (EHRs) released by HHS/CMS" href="http://www.experiordata.com/blog/2009/12/31/regulation-bonanza-hhs-releases-two-interim-rules-on-123009/">Initial Set of Standards</a> for <a class="zem_slink" title="Electronic health record" rel="wikipedia" href="http://en.wikipedia.org/wiki/Electronic_health_record">Electronic Health Records</a> patients must be provided with their health information (most certainly <strong>protected</strong> health information -PHI- under <a class="zem_slink" title="Health Insurance Portability and Accountability Act" rel="wikipedia" href="http://en.wikipedia.org/wiki/Health_Insurance_Portability_and_Accountability_Act">HIPAA</a>) electronically <strong>and</strong> securely within 96 hours.</p>
<p><br class="spacer_" /></p>
<address>
<p>&#8220;Consistent with the HIT Policy Committee&#8217;s recommendations, we propose the following additional clarification of this objective. Electronic copies may be provided through a number of secure electronic methods (for example, personal health record (</p>
</address>
<address>
<p>PHR), patient portal, CD, <a class="zem_slink" title="Universal Serial Bus" rel="wikipedia" href="http://en.wikipedia.org/wiki/Universal_Serial_Bus">USB</a> drive).</p>
<p><br class="spacer_" /></p>
<p>Provide patients with timely electronic access to their health information (including lab results, problem list, medication lists, allergies) within 96 hours of the information being available to the EP. Also, consistent with the HIT Policy Committee recommendations, we propose the following additional clarification of this objective. Electronic access may be provided by a number of <span style="font-style: normal;"><strong>s</strong></span><strong>ecure electronic methods (for example, PHR, patient portal, CD, USB drive).</strong> Timely is defined as within 96 hours of the information being available to the EP either through the receipt of final lab results or a patient interaction that updates the EP&#8217;s knowledge of the patient&#8217;s health. We judge 96 hours to be a reasonable amount of time to ensure that certified EHR technology is up to date. We welcome comment on if a shorter or longer time is advantageous.&#8221;</p>
</address>
<address> </address>
<h2><span style="font-style: normal;">How to Secure Health Records</span></h2>
<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 310px;">
<dt class="wp-caption-dt"><a href="http://commons.wikipedia.org/wiki/Image:USBVacuumCleaner.jpg"><img title="USB Vacuum Cleaner, a giveaway from an IBM event" src="http://upload.wikimedia.org/wikipedia/commons/thumb/7/77/USBVacuumCleaner.jpg/300px-USBVacuumCleaner.jpg" alt="USB Vacuum Cleaner, a giveaway from an IBM event" width="300" height="225" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://commons.wikipedia.org/wiki/Image:USBVacuumCleaner.jpg">Wikipedia</a></dd>
</dl>
</div>
</div>
<p><span style="font-style: normal;">You may be wondering how can patient information be secured. The best way to secure information is by encrypting the </span><span style="font-style: normal;">media. However, note that <strong>patients must be able to decrypt the information</strong> on their own computer equipment. One of the product Experior Data implements is called <a title="PGP Portable allows you to encrypt data on removable media but lets people decrypt it on other computers without requiring special software to be installed" href="http://www.pgp.com/products/portable/index.html" target="_blank">PGP Portable</a>. For example, the patient provides a USB drive for you to copy the PHI onto it. PGP Portable encrypts the entire USB device after the information is copied to it. The patient must provide a passphrase during the <a class="zem_slink" title="Encryption" rel="wikipedia" href="http://en.wikipedia.org/wiki/Encryption">encryption</a> process. When the patient goes home he/she inserts the USB drive into their home computer and is prompted for the passphrase. After the passphrase is entered access to the patient information is provided.</span></p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://projecthealthdesign.typepad.com/project_health_design/2009/08/hies-are-beginning-to-link-patients-directly-to-their-own-health-data.html">HIEs are Beginning to Link Patients Directly to their Own Health Data</a> (projecthealthdesign.typepad.com)</li>
<li class="zemanta-article-ul-li"><a href="http://chilmarkresearch.com/2009/09/23/pushing-onc-to-act-on-consumers-behalf/">Pushing ONC to Act on Consumer&#8217;s Behalf</a> (chilmarkresearch.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.medicineandtechnology.com/2009/12/medfusion-maintains-leadership-in.html">Medfusion Maintains Leadership in Patient Portal Performance</a> (medicineandtechnology.com)</li>
<li class="zemanta-article-ul-li"><a href="http://blogs.wsj.com/health/2009/12/30/how-to-get-20-billion-for-using-electronic-medical-records/">How to Get $20 Billion for Using Electronic Medical Records</a> (blogs.wsj.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/76960f38-a396-49b1-bf12-c9961f5125fc/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=76960f38-a396-49b1-bf12-c9961f5125fc" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><br />
<script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p></span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/12/31/security-for-meaningful-use-part-2-electronic-access-to-protected-health-information-phi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security for Meaningful Use: Part 1 &#8211; Web services</title>
		<link>http://www.experiordata.com/blog/2009/12/31/security-for-meaningful-use-part-1-web-services/</link>
		<comments>http://www.experiordata.com/blog/2009/12/31/security-for-meaningful-use-part-1-web-services/#comments</comments>
		<pubDate>Thu, 31 Dec 2009 06:48:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Regulation]]></category>
		<category><![CDATA[Rulings]]></category>
		<category><![CDATA[Add new tag]]></category>
		<category><![CDATA[Service-oriented architecture]]></category>
		<category><![CDATA[SOAP]]></category>
		<category><![CDATA[Web service]]></category>
		<category><![CDATA[XML]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=343</guid>
		<description><![CDATA[



Image via Wikipedia



Web Services At Forefront

If you intend on implementing electronic records and apply for the Electronic Health Record Incentive Program (EHRIP) you must demonstrate &#8220;meaningful use&#8221; of the electronic health record system. One of the provisions in EHRIP is information sharing. The authors of the EHRIP specifically set out to standardize on two protocols [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 285px;">
<dt class="wp-caption-dt"><a href="http://commons.wikipedia.org/wiki/Image:XML.svg"><img title="A graphical depiction of a very simple xml doc..." src="http://upload.wikimedia.org/wikipedia/commons/thumb/6/68/XML.svg/275px-XML.svg.png" alt="A graphical depiction of a very simple xml doc..." width="275" height="313" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://commons.wikipedia.org/wiki/Image:XML.svg">Wikipedia</a></dd>
</dl>
</div>
</div>
<h2>Web Services At Forefront</h2>
<p><br class="spacer_" /></p>
<p>If you intend on implementing electronic records and apply for the <a class="zem_slink" title="Electronic health record" rel="wikipedia" href="http://en.wikipedia.org/wiki/Electronic_health_record">Electronic Health Record</a> Incentive Program (EHRIP) you must demonstrate &#8220;meaningful use&#8221; of the electronic health record system. One of the provisions in EHRIP is information sharing. The authors of the EHRIP specifically set out to standardize on two protocols for information sharing:</p>
<ul>
<li><a class="zem_slink" title="SOAP" rel="wikipedia" href="http://en.wikipedia.org/wiki/SOAP">SOAP</a></li>
<li><a class="zem_slink" title="Representational State Transfer" rel="wikipedia" href="http://en.wikipedia.org/wiki/Representational_State_Transfer">REST</a></li>
</ul>
<p>Both of these technologies are know as <a class="zem_slink" title="Web service" rel="wikipedia" href="http://en.wikipedia.org/wiki/Web_service">web services</a>. Essentially, web services provide information sharing capabilities using <a class="zem_slink" title="Data model" rel="wikipedia" href="http://en.wikipedia.org/wiki/Data_model">structured data</a> files called <a class="zem_slink" title="XML" rel="wikipedia" href="http://en.wikipedia.org/wiki/XML">XML</a>. The purpose is to use these <a class="zem_slink" title="Open standard" rel="wikipedia" href="http://en.wikipedia.org/wiki/Open_standard">open standards</a> so that applications developed by different vendors could communicate and share information.</p>
<p><br class="spacer_" /></p>
<h2>Securing Web Services</h2>
<p><br class="spacer_" /></p>
<p>In terms of security it is important to ensure that the transmission between applications using these web services is properly encrypted using SSL <a class="zem_slink" title="Technology" rel="wikinvest" href="http://www.wikinvest.com/industry/Technology">technology</a>. In addition, considerations should be made to implement network and host <a class="zem_slink" title="Intrusion prevention system" rel="wikipedia" href="http://en.wikipedia.org/wiki/Intrusion_prevention_system">intrusion prevention systems</a> to ensure the security and integrity of the systems transmitting the shared information. For example, accepting SOAP requests will require you to set  up a <a class="zem_slink" title="DMZ (computing)" rel="wikipedia" href="http://en.wikipedia.org/wiki/DMZ_%28computing%29">DMZ</a> infrastructure. Servers sitting in the DMZ will need to accept SOAP requests and send them. It is the traffic to and from these servers, and the servers themselves, that need to be protected.</p>
<p><br class="spacer_" /></p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.slideshare.net/rnewton/web-services-hacking-and-hardening">Web Services Hacking And Hardening</a> (slideshare.net)</li>
<li class="zemanta-article-ul-li"><a href="http://devcentral.f5.com/weblogs/macvittie/archive/2009/12/11/the-xml-security-relay-race.aspx">The XML Security Relay Race</a> (devcentral.f5.com)</li>
<li class="zemanta-article-ul-li"><a href="http://ducknetweb.blogspot.com/2009/11/health-it-buzz-hhs-launches-healthcare.html">Health IT Buzz &#8211; HHS Launches Healthcare Blog to Communicate with Dr. Blumenthal</a> (ducknetweb.blogspot.com)</li>
<li class="zemanta-article-ul-li"><a href="http://clinicalit.blogspot.com/2009/12/heres-rule-for-meaningful-use.html">Here&#8217;s the rule for meaningful use</a> (clinicalit.blogspot.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/7993140a-f705-4f45-909d-e89dd1de5bd5/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=7993140a-f705-4f45-909d-e89dd1de5bd5" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><br />
<script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p></span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/12/31/security-for-meaningful-use-part-1-web-services/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Regulation Bonanza &#8211; HHS releases two interim rules on 12/30/09</title>
		<link>http://www.experiordata.com/blog/2009/12/31/regulation-bonanza-hhs-releases-two-interim-rules-on-123009/</link>
		<comments>http://www.experiordata.com/blog/2009/12/31/regulation-bonanza-hhs-releases-two-interim-rules-on-123009/#comments</comments>
		<pubDate>Thu, 31 Dec 2009 06:23:27 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Regulation]]></category>
		<category><![CDATA[Rulings]]></category>
		<category><![CDATA[meaningful use]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=338</guid>
		<description><![CDATA[



Image via Wikipedia



With $20 billion at stake the Federal government released two interim rules:


Medicare and Medicaid Programs; Electronic Health Record Incentive Program
Standards &#38; Certification Interim Final Rule: Initial Set of Standards, Implementation Specifications, and Certification Criteria for Electronic Health Record Technology


The Electronic Health Record Incentive Program spells out the proposed terms of the the reimbursements [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 130px;">
<dt class="wp-caption-dt"><a href="http://en.wikipedia.org/wiki/Image:Centers_for_Medicare_and_Medicaid_Services_logo.png"><img title="Centers for Medicare and Medicaid Services logo" src="http://upload.wikimedia.org/wikipedia/en/a/a1/Centers_for_Medicare_and_Medicaid_Services_logo.png" alt="Centers for Medicare and Medicaid Services logo" width="120" height="87" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://en.wikipedia.org/wiki/Image:Centers_for_Medicare_and_Medicaid_Services_logo.png">Wikipedia</a></dd>
</dl>
</div>
</div>
<p>With $20 billion at stake the Federal government released two interim rules:</p>
<p><br class="spacer_" /></p>
<ul>
<li><a href="http://www.federalregister.gov/OFRUpload/OFRData/2009-31217_PI.pdf">Medicare and Medicaid Programs; Electronic Health Record Incentive Program</a></li>
<li><a href="http://www.federalregister.gov/inspection.aspx#special">Standards &amp; Certification Interim Final Rule: Initial Set of Standards, Implementation Specifications, and Certification Criteria for Electronic Health Record Technology</a></li>
</ul>
<p><br class="spacer_" /></p>
<p>The <a href="http://www.federalregister.gov/OFRUpload/OFRData/2009-31217_PI.pdf">Electronic Health Record Incentive Program</a> spells out the proposed terms of the the reimbursements healthcare professionals and certain entities can receive by implementing electronic health records.</p>
<p><br class="spacer_" /></p>
<p>The <a href="http://www.federalregister.gov/inspection.aspx#special">Initial Set of Standards</a> rule discusses the concept of &#8220;meaningful use&#8221;, which is a major component of the incentive program. Healthcare entities must meet certain requirements, like sharing of information and being able to capture specific information from patients.</p>
<p><br class="spacer_" /></p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://seattletimes.nwsource.com/html/businesstechnology/2010642103_apusmedicalrecordsstimulusmoney.html?syndication=rss">Medicare officials plan for health stimulus funds</a> (seattletimes.nwsource.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.huffingtonpost.com/2009/12/30/switch-to-electronic-heal_n_407865.html">Switch To Electronic Health Records Could Miss Federal Targets</a> (huffingtonpost.com)</li>
<li class="zemanta-article-ul-li"><a href="http://ducknetweb.blogspot.com/2009/12/meaningful-use-556-page-proposed-rule.html">Meaningful Use 556 Page Proposed Rule is Out &#8211; Thanks WSJ for the Shortcut to the Meat and Potatoes</a> (ducknetweb.blogspot.com)</li>
<li class="zemanta-article-ul-li"><a href="http://clinicalit.blogspot.com/2009/12/heres-rule-for-meaningful-use.html">Here&#8217;s the rule for meaningful use</a> (clinicalit.blogspot.com)</li>
<li class="zemanta-article-ul-li"><a href="http://blogs.wsj.com/health/2009/12/30/how-to-get-20-billion-for-using-electronic-medical-records/">How to Get $20 Billion for Using Electronic Medical Records</a> (blogs.wsj.com)</li>
<li class="zemanta-article-ul-li"><a href="http://ducknetweb.blogspot.com/2009/11/health-it-buzz-hhs-launches-healthcare.html">Health IT Buzz &#8211; HHS Launches Healthcare Blog to Communicate with Dr. Blumenthal</a> (ducknetweb.blogspot.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/caa87e61-a76d-48bd-b1f5-285d46a2e078/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=caa87e61-a76d-48bd-b1f5-285d46a2e078" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><br />
<script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script><br />
<br />
 </span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/12/31/regulation-bonanza-hhs-releases-two-interim-rules-on-123009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Interim Final Rule on Enforcement Issued</title>
		<link>http://www.experiordata.com/blog/2009/11/17/interim-final-rule-on-enforcement-issued/</link>
		<comments>http://www.experiordata.com/blog/2009/11/17/interim-final-rule-on-enforcement-issued/#comments</comments>
		<pubDate>Tue, 17 Nov 2009 21:04:37 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Law firms]]></category>
		<category><![CDATA[Regulation]]></category>
		<category><![CDATA[Rulings]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[HITECH Act]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=169</guid>
		<description><![CDATA[According to Bricker &#38; Eckler, LLP
&#8230;
&#8220;On October 30, 2009, the Department of Health and Human Services (HHS) issued an interim final rule pertaining to the enforcement provisions of the HI-TECH Act. The final rule serves to conform HIPAA’s enforcement regulations to the revisions to the HIPAA statutes made by the HI-TECH Act.&#8221;
&#8230;
This is the government&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p>According to <a title="Bricker &amp; Eckler, LL" href="http://www.bricker.com/legalservices/industry/hcare/ealerts/rc/rc37.asp" target="_blank">Bricker &amp; Eckler, LLP</a></p>
<p><span style="color: #c0c0c0;">&#8230;</span></p>
<p>&#8220;On October 30, 2009, the Department of Health and Human Services (HHS) issued an <a href="http://www.hhs.gov/ocr/privacy/hipaa/administrative/enforcementrule/enfifr.pdf">interim final rule</a> pertaining to the enforcement provisions of the HI-TECH Act. The final rule serves to conform HIPAA’s enforcement regulations to the revisions to the HIPAA statutes made by the HI-TECH Act.&#8221;</p>
<p><span style="color: #c0c0c0;">&#8230;</span></p>
<p>This is the government&#8217;s way of saying &#8220;we&#8217;re made a rule, and we are now going to enforce it&#8221;. The enforcement ruling is an indicative of the federal government&#8217;s interest in protecting the privacy and identity of patients. As patient records get converted from paper to electronic security has become a very important part of the healthcare IT ecosystem.</p>
<p><span style="color: #c0c0c0;">..</span></p>
<p>Bricker and Echler, LLC go on further to say &#8220;The HI-TECH Act significantly increased the penalty amounts for HIPAA violations, as reflected in the final rule. Covered entities should understand the financial risks associated with HIPAA non-compliance and the changes to the available affirmative defenses. It is critical to have an effective HIPAA compliance program to avoid HIPAA violations and to identify and correct HIPAA violations in a timely manner, which can shield the organization from substantial financial penalties&#8221;</p>
<p><span style="color: #c0c0c0;">..</span></p>
<p>Related articles by Zemanta</p>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://healthblawg.typepad.com/healthblawg/2009/11/son-of-hipaa-breach-notification-rules.html">Son of HIPAA Breach Notification Rules</a> (healthblawg.typepad.com)</li>
<li class="zemanta-article-ul-li"><a href="http://docinthemachine.com/2009/11/09/encrypt/">Encrypt EHR &#8211; Else HIPAA Violations Need Be Reported To Government &amp; Media</a> (docinthemachine.com)</li>
<li class="zemanta-article-ul-li"><a href="http://medicareupdate.typepad.com/medicare_update/2009/10/hcfacreport2008.html">HHS Releases 2008 Health Care Fraud and Abuse Control Program Report</a> (medicareupdate.typepad.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.huffingtonpost.com/2009/11/05/stimulus-fuels-gold-rush_n_347311.html">Stimulus Fuels Gold Rush For Electronic Health Systems</a> (huffingtonpost.com)</li>
<li class="zemanta-article-ul-li"><a href="http://healthcarebloglaw.blogspot.com/2009/11/hipaa-enforcement-meets-hitech-hipaa.html">HIPAA Enforcement Meets HITECH: HIPAA Administrative Simplification: Enforcement Rule</a> (healthcarebloglaw.blogspot.com)</li>
<li class="zemanta-article-ul-li"><a href="http://healthcarebloglaw.blogspot.com/2009/10/arra-hitech-health-care-information.html">ARRA &#8211; HITECH: Health Care Information Breach Notification Regulations Now In Effect</a> (healthcarebloglaw.blogspot.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/0f8109dd-4181-4d3b-a3fb-759163ab8308/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=0f8109dd-4181-4d3b-a3fb-759163ab8308" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><br />
<script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></p>
<p> </span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/11/17/interim-final-rule-on-enforcement-issued/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Congress to HHS: Remove the harm assessment!</title>
		<link>http://www.experiordata.com/blog/2009/10/03/congress-to-hhs-remove-the-harm-assessment/</link>
		<comments>http://www.experiordata.com/blog/2009/10/03/congress-to-hhs-remove-the-harm-assessment/#comments</comments>
		<pubDate>Sat, 03 Oct 2009 19:15:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ARRA]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Regulation]]></category>
		<category><![CDATA[Rulings]]></category>
		<category><![CDATA[Section 13402]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[congress]]></category>
		<category><![CDATA[media notification]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=143</guid>
		<description><![CDATA[



Image via Wikipedia



In a strongly-worded letter sent and signed by six congressmen to HHS Secretary Kathleen Sebelius the message was clear: remove the harm assessment that lawmakers rejected when writing the privacy regulations into ARRA. The harm standard essentially says that in case of a breach the covered entity must make an assessment of whether or [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 218px;">
<dt class="wp-caption-dt"><a href="http://commons.wikipedia.org/wiki/Image:Sebelius_speaking_with_troops_in_Pakistan%2C_27_Nov%2C_2005%2C_cropped.jpg"><img title="Kansas Governor :en:Kathleen Sebelius speaks w..." src="http://upload.wikimedia.org/wikipedia/commons/1/1d/Sebelius_speaking_with_troops_in_Pakistan%2C_27_Nov%2C_2005%2C_cropped.jpg" alt="Kansas Governor :en:Kathleen Sebelius speaks w..." width="208" height="332" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://commons.wikipedia.org/wiki/Image:Sebelius_speaking_with_troops_in_Pakistan%2C_27_Nov%2C_2005%2C_cropped.jpg">Wikipedia</a></dd>
</dl>
</div>
</div>
<p>In a strongly-worded <a title="Letter from Congress to HHS asking to remove harm standard from breach notification" href="http://energycommerce.house.gov/Press_111/20091001/sebelius_letter.pdf" target="_blank">letter</a> sent and signed by six congressmen to <a class="zem_slink" title="United States Secretary of Health and Human Services" rel="wikipedia" href="http://en.wikipedia.org/wiki/United_States_Secretary_of_Health_and_Human_Services">HHS Secretary</a> <a class="zem_slink" title="Kathleen Sebelius" rel="wikipedia" href="http://en.wikipedia.org/wiki/Kathleen_Sebelius">Kathleen Sebelius</a> the message was clear: remove the harm assessment that lawmakers rejected when writing the <a class="zem_slink" title="Privacy" rel="wikipedia" href="http://en.wikipedia.org/wiki/Privacy">privacy</a> regulations into <a title="American Recovery and Reinvestment Act of 2009" href="http://www.experiordata.com/images/american_recovery_reinvestment_act.pdf" target="_blank">ARRA</a>. The harm standard essentially says that in case of a breach the covered entity must make an assessment of whether or not the breach can cause reputational, financial, and other types of harm.  This leaves open the possibility that a covered entity could decide to act in its own interest and make the decision not to follow the directives written into the <a title="Interim final ruling on breach notification" href="http://www.experiordata.com/images/interim_final_ruling.pdf" target="_blank">breach notification ruling</a>.</p>
<p><span style="color: #ffffff;">..</span></p>
<p>There are, of course, two sides of the sword. On one hand it&#8217;s difficult to enforce a policy with subjective elements present, such as the harm assessment. It is unlikely that a covered entity would risk the substantial fines, now as high as $1.5 million, and the possibility of criminal prosecution to avoid notification in case a serious breach occurs. However, the harm assessment leaves that possibility open.</p>
<p><span style="color: #ffffff;">..</span></p>
<p>A drawback to removing the harm assessment is that it is possible that, ironically, that too many breach notifications are sent to people, thereby creating a &#8220;boy that cries wolf&#8221; effect. In a perfect world breaches would never happen, so there would not need to be a reason to notify people. However, we all know that not to be the reality. Breaches do occur, intentional or not. And people need to be notified as soon as possible. Should covered entities be given the privilege of deciding the severity of the harm and potentially choosing not to notify people? We shall see the next steps Congress and HHS will take.</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/f109c045-b7ee-4c5f-b033-6660b8cf7572/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=f109c045-b7ee-4c5f-b033-6660b8cf7572" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><br />
<script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script><br />
</span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/10/03/congress-to-hhs-remove-the-harm-assessment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Breach notification goes into effect on September 23, 2009</title>
		<link>http://www.experiordata.com/blog/2009/09/02/breach-notification-goes-into-effect-on-september-23-2009/</link>
		<comments>http://www.experiordata.com/blog/2009/09/02/breach-notification-goes-into-effect-on-september-23-2009/#comments</comments>
		<pubDate>Thu, 03 Sep 2009 03:50:52 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ARRA]]></category>
		<category><![CDATA[Encyption]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Rulings]]></category>
		<category><![CDATA[Section 13402]]></category>
		<category><![CDATA[13402]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[encryption]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=102</guid>
		<description><![CDATA[The new breach notification guidelines go into effect on September 23rd, 2009. Even though breach notification goes into effect on 9/23/09, the Interim Rule states that civil penalties will not be imposed until February 18th, 2010. The government is aware of the ambiguity and clearly states that it has discretion on imposing sanctions for failure [...]]]></description>
			<content:encoded><![CDATA[<p>The new breach notification guidelines go into effect on September 23rd, 2009. Even though breach notification goes into effect on 9/23/09, the <a title="Experior resoures on Interim Final Rule on Breach Notification" href="http://experiordata.com/resources.php">Interim Rule</a> states that civil penalties will not be imposed until February 18th, 2010. The government is aware of the ambiguity and clearly states that it has discretion on imposing sanctions for failure to provide notification in case of a breach notification for breaches occurring before 2/18/10.</p>
<p><span style="color: #ffffff;">..</span></p>
<p>During the 180 period between 8/2009 and  2/2010 covered entities have the perfect opportunity to review the data stored on their IT systems. The Interim Rule is concerned specifically with <a title="What is Data in Motion encryption?" href="http://www.experiordata.com/data_motion.php" target="_blank">Data in Motion</a>, <a title="What is Data in Motion encryption?" href="http://www.experiordata.com/data_use.php" target="_blank">Data in Use</a>, <a title="What is Data at Rest encryption?" href="http://www.experiordata.com/data_rest.php" target="_blank">Data at Rest</a>, and <a title="How to protect Data Disposed" href="http://www.experiordata.com/data_disposed.php" target="_blank">Data Disposed.</a> Experior can help  determine the best plan of action to implement encryption  in your IT systems to protect   your organization from breach notification requirements.</p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/09/02/breach-notification-goes-into-effect-on-september-23-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Protected Health Information &#8211; What is it?</title>
		<link>http://www.experiordata.com/blog/2009/08/24/protected-health-information-what-is-it/</link>
		<comments>http://www.experiordata.com/blog/2009/08/24/protected-health-information-what-is-it/#comments</comments>
		<pubDate>Tue, 25 Aug 2009 03:54:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ARRA]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Rulings]]></category>
		<category><![CDATA[PHI]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=36</guid>
		<description><![CDATA[The term Protected Health Information (PHI) has its roots in the term &#8220;Individually Identifiable Information&#8221; that was first used in the context of privacy regulation in the Health Insurance Portability and Accountability Act of 1996 (HIPAA).
..
HIPAA explicitly defines this Information as &#8220;&#8230;any information, including demographic information collected from an individual, that&#8211;&#8221;(A) is created or received by [...]]]></description>
			<content:encoded><![CDATA[<p>The term Protected Health Information (PHI) has its roots in the term &#8220;Individually Identifiable Information&#8221; that was first used in the context of privacy regulation in the <a href="http://www.cms.hhs.gov/HIPAAGenInfo/Downloads/HIPAALaw.pdf">Health Insurance Portability and Accountability Act of 1996</a> (HIPAA).</p>
<p><span style="color: #ffffff;">..</span><br />
HIPAA explicitly defines this Information as &#8220;&#8230;any information, including demographic information collected from an individual, that&#8211;&#8221;(A) is created or received by a health care provider, health plan, employer, or health care clearinghouse; and &#8221;(B) relates to the past, present, or future physical or mental health or condition of an individual, the provision of health care to an individual, or the past, present, or future payment for the provision of health care to an individual, and&#8211;&#8221;(i) identifies the individual; or &#8221;(ii) with respect to which there is a reasonable basis to believe that the information can be used to identify the individual.&#8221;</p>
<p><span style="color: #ffffff;">..</span></p>
<p>Protected  Health Information takes that definition and applies and electronic twist to it. The <a href="http://www.experiordata.com/images/interim_final_ruling.pdf">Interim Final Rule on Breach Notification for Unsecured Protected Health Information</a> on page 4 of the preamble defines protected health information as:  &#8220;<strong>individually identifiable health information</strong> held or transmitted in any form or medium by HIPAA covered entities and business associates, subject to certain limited exceptions&#8221;.</p>
<p><span style="color: #ffffff;">..</span></p>
<p>&#8220;Subject to certain limited exceptions&#8221; can be interpreted to mean additional exclusions listed in <a href="http://www.hhs.gov/ocr/privacy/hipaa/administrative/privacyrule/privrulepd.pdf">Standards for Privacy of Individually Identifiable Health Information; Final Rule, 45 CFR Parts 160 and 164</a>, ss 164.501. Exclusions as written are an employer in its role as a covered entity (covered entities are employers as well) and education records specified in the Family Education Rights and Privacy Act, 20 U.S.C. 1232g.</p>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px;">&#8216;individually</div>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px;">identifiable health information&#8217; means any information, including demographic</div>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px;">information collected from an individual, that&#8211;</div>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px;">&#8220;(A) is created or received by a health care provider, health plan, employer, or</div>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px;">health care clearinghouse; and</div>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px;">&#8220;(B) relates to the past, present, or future physical or mental health or condition of</div>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px;">an individual, the provision of health care to an individual, or the past, present, or</div>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px;">future payment for the provision of health care to an individual, and&#8211;</div>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px;">&#8220;(i) identifies the individual; or</div>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px;">&#8220;(ii) with respect to which there is a reasonable basis to believe that the information</div>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px;">can be used to identify the individual</div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/08/24/protected-health-information-what-is-it/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HHS Ruling on Encryption &#8211; ARRA/HITECH ACT subsection 13402</title>
		<link>http://www.experiordata.com/blog/2009/08/24/hhs-ruling-on-encryption-arrahitech-act-subsection-13402/</link>
		<comments>http://www.experiordata.com/blog/2009/08/24/hhs-ruling-on-encryption-arrahitech-act-subsection-13402/#comments</comments>
		<pubDate>Mon, 24 Aug 2009 04:46:46 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ARRA]]></category>
		<category><![CDATA[Rulings]]></category>
		<category><![CDATA[Section 13402]]></category>
		<category><![CDATA[13402]]></category>
		<category><![CDATA[breach notification]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=3</guid>
		<description><![CDATA[On Thursday, August 20th, 2009, the U.S. Department of Health and Human Services (HHS) issued the Interim Final Rule on Breach Notification.
 An important part the interim final rule is the decision that encryption is the only acceptable technology to make protected health information (essentially, patient records) &#8220;unusable, unreadable, or indecipherable to unauthorized individuals&#8221;. The [...]]]></description>
			<content:encoded><![CDATA[<p>On Thursday, August 20th, 2009, the U.S. Department of Health and Human Services (HHS) issued the <a href="http://www.hhs.gov/ocr/privacy/hipaa/understanding/coveredentities/breachnotificationifr.html">Interim Final Rule on Breach Notification.</a><br />
<br/><a href="http://www.hhs.gov/ocr/privacy/hipaa/understanding/coveredentities/breachnotificationifr.html"></a> An important part the interim final rule is the decision that encryption is the only acceptable technology to make protected health information (essentially, patient records) &#8220;unusable, unreadable, or indecipherable to unauthorized individuals&#8221;. The preamble to the rule explains that even though other methods (such as access control) can continue to be used, if a breach occurs and the protected health information is disclosed to unauthorized individuals a breach notification is required.<br />
<br/>Breach notifications are essentially categorized as &#8220;under 500&#8243; and &#8220;over 500&#8243; records. If a breach occurred to under 500 records then covered entities must maintain a log of the breach and notify the patients. If a breach over 500 records has occurred then not only patients need to be notified but also major media outlet and HHS. In addition, a hotline must be established so that people can call and obtain more information about the breach (notification procedures are specified in the HITECH Act, Section 13402). HHS can issue fines and attorneys general of each state are empowered to pursue these types of breaches on a criminal level.<br/><br />
The government is clearly serious about patient record privacy to encourage covered entities to move paper records to electronic records as part of its overall healthcare reform efforts.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/08/24/hhs-ruling-on-encryption-arrahitech-act-subsection-13402/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
