<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Experior Data Encryption Blog &#187; Section 13402</title>
	<atom:link href="http://www.experiordata.com/blog/category/section-13402/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.experiordata.com/blog</link>
	<description>Encrypt your PHI, and avoid breach notification</description>
	<lastBuildDate>Tue, 18 May 2010 04:09:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>White House is Concerned About Protecting PHI</title>
		<link>http://www.experiordata.com/blog/2010/05/17/white-house-is-concerned-about-protecting-phi/</link>
		<comments>http://www.experiordata.com/blog/2010/05/17/white-house-is-concerned-about-protecting-phi/#comments</comments>
		<pubDate>Tue, 18 May 2010 01:28:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Regulation]]></category>
		<category><![CDATA[Section 13402]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security Coordinator]]></category>
		<category><![CDATA[Cyber Security Czar]]></category>
		<category><![CDATA[Howard Schmidt]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[PHI]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=443</guid>
		<description><![CDATA[Howard Schmidt talks about cyber security as it pertains to protected health information and HIPAA security rule.]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<p><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; "><a href="http://www.whitehouse.gov/blog/2009/12/22/introducing-new-cybersecurity-coordinator" style="color: rgb(54, 82, 114); text-decoration: underline; " target="_blank" title="Howard Schmidt talks about data security at the NIST 2010 HIPAA conference">Howard Schmidt</a>, Obama administration&#39;s cyber security czar, prepared&nbsp;a fantastic presentation about the four guiding principles of his&nbsp;<a href="http://www.whitehouse.gov/cybersecurity" style="color: rgb(54, 82, 114); text-decoration: underline; " target="_blank" title="White House Cybersecurity Page">cyber security</a>&nbsp;plan:</span></p>
<p>&nbsp;</p>
<ul>
<li><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; "><strong>Deterrence</strong>&nbsp;is a primary factor in preventing cyber security threats. Applying strong protectionlike two factor authentication, one time passwords, smart cards, and implementing standard data protection systems were mentioned.<br />
		<font class="Apple-style-span" color="#222222"><span class="Apple-style-span" style="line-height: normal; "></p>
<p>		</span></font></span></li>
<li><span class="Apple-style-span" style="color: rgb(51, 51, 51); font-family: Arial, Verdana, sans-serif; font-size: 12px; line-height: 16px; "><strong>Resilience</strong>&nbsp;is the ability to recover from an attack. Designing systems that are able to recover from an attack is paramount to national security, and especially protected health information (PHI). It was noted (in a different part) of the NIST Conference that doctors relying on Health information systems (HIT) need to ensure that a disaster recovery and backup plan is in place and is tested regularly. A doctor&rsquo;s office or a hospital would be nearly impossible to operate if access to PHI is not available after moving entirely to electronic medical records.
<p>
		</span></li>
<li><span class="Apple-style-span" style="color: rgb(51, 51, 51); font-family: Arial, Verdana, sans-serif; font-size: 12px; line-height: 16px; "><strong>Privacy</strong>&nbsp;is important to the White House. It&rsquo;s clear that legislation and the regulations that follow have privacy in mind. An good example is the Breach Notification law written into section 13402 in the HITECH ACt, part of the American Recovery and Reinvestment Act of 2009 (ARRA). The HITECH Act specifically provides safe harbors in case of a breach of encrypted PHI. The government is clearly incentivizing the use of data encryption to protect privacy.
<p>		</span></li>
</ul>
<ul>
<li><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; "><strong>Partnerships</strong>&nbsp;with private industry were mentioned as well, although not in too much detail. Perhaps the White House wants to make sure that whatever steps they put in place have transparency to the public and the private industry.</span></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2010/05/17/white-house-is-concerned-about-protecting-phi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Government is Serious: Breach Notifications WILL be posted</title>
		<link>http://www.experiordata.com/blog/2010/02/23/the-government-is-serious-breach-notifications-will-be-posted/</link>
		<comments>http://www.experiordata.com/blog/2010/02/23/the-government-is-serious-breach-notifications-will-be-posted/#comments</comments>
		<pubDate>Tue, 23 Feb 2010 04:22:48 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ARRA]]></category>
		<category><![CDATA[Encyption]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Section 13402]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[HITECH Act]]></category>
		<category><![CDATA[PHI]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=411</guid>
		<description><![CDATA[HHS OCR names covered entities and business associates involved in data breaches over 500 records of PHI lost. Unencrypted PHI that is breached must be reported to HHS and mass media.]]></description>
			<content:encoded><![CDATA[<p>The government is naming names! Today the Office of Civil Rights, part of the Department of Health and Human Services, did what they they said all along that they will do &#8211; post the names of covered entities AND business associates who are involved in data breaches. The somewhat <a title="OCR list of covered entities and business associates with breaches of PHI" href="http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/postedbreaches.html" target="_blank">lengthly list</a> provides an insight into the organizations involved in breaches of unsecured protected health information (PHI).</p>
<p><br class="spacer_" /></p>
<p>Protected Health Information (PHI) is a term used widely in HIPAA. PHI is information that can identify and individual, such as name, address, social security number, and clinical information about the individual. Part of the American Recovery and Reinvestment Act (ARRA) called the HITECH Act, section 13402, specifically requires a covered entity or business associate to notify HHS and the mass media of breaches of uprotected PHI involving more than 500 records. PHI that is encrypted is considered <em>protected </em>and, therefore, provides a safe harbor against breach notification.</p>
<p><br class="spacer_" /></p>
<p>Among those involved in the data breaches are hospitals, clinics, dentists, insurance companies, private medical practices (though it&#8217;s unclear as to why their names are being withheld), universities, state governments, and several Blue Cross Blue shield organizations.</p>
<p><br class="spacer_" /></p>
<p>More importantly, business associates &#8211; which are essentially service providers to covered entities &#8211; are not only listed but are named. Most of them are IT services providers to covered entities.</p>
<p><br class="spacer_" /></p>
<p>Data at rest appears to be the most common form of breach, most likely a result of lost laptops, backup tapes, and a seemingly missing server.</p>
<p><br class="spacer_" /></p>
<p>Data encryption provides a safe harbor against breach notification and should be implemented in places where PHI is stored.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2010/02/23/the-government-is-serious-breach-notifications-will-be-posted/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>3 steps for breach notification protection</title>
		<link>http://www.experiordata.com/blog/2010/02/16/3-steps-for-breach-notification-protection/</link>
		<comments>http://www.experiordata.com/blog/2010/02/16/3-steps-for-breach-notification-protection/#comments</comments>
		<pubDate>Tue, 16 Feb 2010 14:37:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Regulation]]></category>
		<category><![CDATA[Rulings]]></category>
		<category><![CDATA[Section 13402]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[Data security]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=399</guid>
		<description><![CDATA[Using encryptio to protect phi creates a safe harbor against breach notification. 3 steps to help you comply with breach notification safe harbor in HITECH Act/HIPAA Security rule.]]></description>
			<content:encoded><![CDATA[<p>Beginning on February 18, HHS will have the legal authority to enforce the breach notification laws set forth last year as part of section 13402 of the HITECH Act,  within the American Recovery &amp; Reinvestment Act (ARRA). The penalties can now be up to $1.5 million and require media notification in cases where 500 or more records are breached. Business associates, as well as covered entities, must now comply with the HITECH Act breach notification rule (which essentially makes modifications to the <a class="zem_slink" title="Health Insurance Portability and Accountability Act" rel="wikipedia" href="http://en.wikipedia.org/wiki/Health_Insurance_Portability_and_Accountability_Act">HIPAA</a> Security Rule).</p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<ol>
<li>Perform an extensive security review and indentify where electronic protected health information (PHI or ePHI) resides on your IT systems. </li>
<li>Create a plan on protecting PHI.
<ul>
<li>Data <a class="zem_slink" title="Encryption" rel="wikipedia" href="http://en.wikipedia.org/wiki/Encryption">encryption</a> provides a <a class="zem_slink" title="Safe harbor" rel="wikipedia" href="http://en.wikipedia.org/wiki/Safe_harbor">safe harbor</a> from breach notification. Determine where PHI can be encrypted.</li>
<li>Identify public facing extranet portals and web applications that can allow access to PHI.</li>
<li>Identify databases that hold PHI.</li>
<li>Execute the plan </li>
</ul>
<ul>
</ul>
<ul>
</ul>
</li>
<li> Implement data encryption where practical.
<ul>
</ul>
<ul>
<li>For databases, implement a database security product to monitor database requests and protect from intrusion.</li>
</ul>
<ul>
<li>For web apps, implement a web application security product to protect from <a class="zem_slink" title="Cross-site scripting" rel="wikipedia" href="http://en.wikipedia.org/wiki/Cross-site_scripting">cross-site scripting</a> and various attacks to access databases to PHI.</li>
</ul>
<ul>
<li>Protect endpoints such as laptops, tablets, etc with data at rest encryption by implementing whole disk encryption,</li>
</ul>
<ol> </ol>
</li>
</ol>
<p><br class="spacer_" /></p>
<p>Experior Data helps customers plan and execute data security assessments and technology implementation for healthcare. Our proprietary Technical Security Audit includes a personalized review of your IT systems and well as a vulnerability scan of all your network components.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://healthblawg.typepad.com/healthblawg/2009/09/hitech-act-security-breach-rules-now-effective-federales-give-a-sixmonth-pass.html">HITECH Act security breach rules now effective; federales give a six-month pass. Now&#8217;s the time to kick compliance efforts into high gear</a> (healthblawg.typepad.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.slideshare.net/jonneiditz/hitech-and-state-breach-notification">HITECH and State Breach Notification</a> (slideshare.net)</li>
<li class="zemanta-article-ul-li"><a href="http://yro.slashdot.org/story/09/09/19/2157217/Using-Encryption-Garners-Exemption-For-Data-Breach-Notification?from=rss">Using Encryption Garners Exemption For Data Breach Notification</a> (yro.slashdot.org)</li>
<li class="zemanta-article-ul-li"><a href="http://healthblawg.typepad.com/healthblawg/2009/11/son-of-hipaa-breach-notification-rules-whos-ready.html">Son of HIPAA Breach Notification Rules and Business Associate Requirements: Who&#8217;s Ready?</a> (healthblawg.typepad.com)</li>
<li class="zemanta-article-ul-li"><a href="http://hunscher.typepad.com/futurehit/2010/01/the-cost-of-fear-why-docs-dont-embrace-technology.html">The Cost of Fear | Why Docs Don&#8217;t Embrace Technology (Dr. Rob)</a> (hunscher.typepad.com)</li>
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www.newswire.ca/en/releases/archive/February2010/01/c5838.html&amp;a=12426180&amp;rid=3a0266f6-3270-43a7-9d5d-72d3000b6dd6&amp;e=11c996da2d350263f04bcb67deeb4620">PGP Corporation to Announce Acquisition</a> (newswire.ca)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/3a0266f6-3270-43a7-9d5d-72d3000b6dd6/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=3a0266f6-3270-43a7-9d5d-72d3000b6dd6" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><br />
<script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script><br />
<br />
 </span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2010/02/16/3-steps-for-breach-notification-protection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Congress to HHS: Remove the harm assessment!</title>
		<link>http://www.experiordata.com/blog/2009/10/03/congress-to-hhs-remove-the-harm-assessment/</link>
		<comments>http://www.experiordata.com/blog/2009/10/03/congress-to-hhs-remove-the-harm-assessment/#comments</comments>
		<pubDate>Sat, 03 Oct 2009 19:15:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ARRA]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Regulation]]></category>
		<category><![CDATA[Rulings]]></category>
		<category><![CDATA[Section 13402]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[congress]]></category>
		<category><![CDATA[media notification]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=143</guid>
		<description><![CDATA[Image via Wikipedia In a strongly-worded letter sent and signed by six congressmen to HHS Secretary Kathleen Sebelius the message was clear: remove the harm assessment that lawmakers rejected when writing the privacy regulations into ARRA. The harm standard essentially says that in case of a breach the covered entity must make an assessment of whether [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 218px;">
<dt class="wp-caption-dt"><a href="http://commons.wikipedia.org/wiki/Image:Sebelius_speaking_with_troops_in_Pakistan%2C_27_Nov%2C_2005%2C_cropped.jpg"><img title="Kansas Governor :en:Kathleen Sebelius speaks w..." src="http://upload.wikimedia.org/wikipedia/commons/1/1d/Sebelius_speaking_with_troops_in_Pakistan%2C_27_Nov%2C_2005%2C_cropped.jpg" alt="Kansas Governor :en:Kathleen Sebelius speaks w..." width="208" height="332" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://commons.wikipedia.org/wiki/Image:Sebelius_speaking_with_troops_in_Pakistan%2C_27_Nov%2C_2005%2C_cropped.jpg">Wikipedia</a></dd>
</dl>
</div>
</div>
<p>In a strongly-worded <a title="Letter from Congress to HHS asking to remove harm standard from breach notification" href="http://energycommerce.house.gov/Press_111/20091001/sebelius_letter.pdf" target="_blank">letter</a> sent and signed by six congressmen to <a class="zem_slink" title="United States Secretary of Health and Human Services" rel="wikipedia" href="http://en.wikipedia.org/wiki/United_States_Secretary_of_Health_and_Human_Services">HHS Secretary</a> <a class="zem_slink" title="Kathleen Sebelius" rel="wikipedia" href="http://en.wikipedia.org/wiki/Kathleen_Sebelius">Kathleen Sebelius</a> the message was clear: remove the harm assessment that lawmakers rejected when writing the <a class="zem_slink" title="Privacy" rel="wikipedia" href="http://en.wikipedia.org/wiki/Privacy">privacy</a> regulations into <a title="American Recovery and Reinvestment Act of 2009" href="http://www.experiordata.com/images/american_recovery_reinvestment_act.pdf" target="_blank">ARRA</a>. The harm standard essentially says that in case of a breach the covered entity must make an assessment of whether or not the breach can cause reputational, financial, and other types of harm.  This leaves open the possibility that a covered entity could decide to act in its own interest and make the decision not to follow the directives written into the <a title="Interim final ruling on breach notification" href="http://www.experiordata.com/images/interim_final_ruling.pdf" target="_blank">breach notification ruling</a>.</p>
<p><span style="color: #ffffff;">..</span></p>
<p>There are, of course, two sides of the sword. On one hand it&#8217;s difficult to enforce a policy with subjective elements present, such as the harm assessment. It is unlikely that a covered entity would risk the substantial fines, now as high as $1.5 million, and the possibility of criminal prosecution to avoid notification in case a serious breach occurs. However, the harm assessment leaves that possibility open.</p>
<p><span style="color: #ffffff;">..</span></p>
<p>A drawback to removing the harm assessment is that it is possible that, ironically, that too many breach notifications are sent to people, thereby creating a &#8220;boy that cries wolf&#8221; effect. In a perfect world breaches would never happen, so there would not need to be a reason to notify people. However, we all know that not to be the reality. Breaches do occur, intentional or not. And people need to be notified as soon as possible. Should covered entities be given the privilege of deciding the severity of the harm and potentially choosing not to notify people? We shall see the next steps Congress and HHS will take.</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/f109c045-b7ee-4c5f-b033-6660b8cf7572/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=f109c045-b7ee-4c5f-b033-6660b8cf7572" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><br />
<script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script><br />
</span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/10/03/congress-to-hhs-remove-the-harm-assessment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Breach notification goes into effect on September 23, 2009</title>
		<link>http://www.experiordata.com/blog/2009/09/02/breach-notification-goes-into-effect-on-september-23-2009/</link>
		<comments>http://www.experiordata.com/blog/2009/09/02/breach-notification-goes-into-effect-on-september-23-2009/#comments</comments>
		<pubDate>Thu, 03 Sep 2009 03:50:52 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ARRA]]></category>
		<category><![CDATA[Encyption]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Rulings]]></category>
		<category><![CDATA[Section 13402]]></category>
		<category><![CDATA[13402]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[encryption]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=102</guid>
		<description><![CDATA[The new breach notification guidelines go into effect on September 23rd, 2009. Even though breach notification goes into effect on 9/23/09, the Interim Rule states that civil penalties will not be imposed until February 18th, 2010. The government is aware of the ambiguity and clearly states that it has discretion on imposing sanctions for failure [...]]]></description>
			<content:encoded><![CDATA[<p>The new breach notification guidelines go into effect on September 23rd, 2009. Even though breach notification goes into effect on 9/23/09, the <a title="Experior resoures on Interim Final Rule on Breach Notification" href="http://experiordata.com/resources.php">Interim Rule</a> states that civil penalties will not be imposed until February 18th, 2010. The government is aware of the ambiguity and clearly states that it has discretion on imposing sanctions for failure to provide notification in case of a breach notification for breaches occurring before 2/18/10.</p>
<p><span style="color: #ffffff;">..</span></p>
<p>During the 180 period between 8/2009 and  2/2010 covered entities have the perfect opportunity to review the data stored on their IT systems. The Interim Rule is concerned specifically with <a title="What is Data in Motion encryption?" href="http://www.experiordata.com/data_motion.php" target="_blank">Data in Motion</a>, <a title="What is Data in Motion encryption?" href="http://www.experiordata.com/data_use.php" target="_blank">Data in Use</a>, <a title="What is Data at Rest encryption?" href="http://www.experiordata.com/data_rest.php" target="_blank">Data at Rest</a>, and <a title="How to protect Data Disposed" href="http://www.experiordata.com/data_disposed.php" target="_blank">Data Disposed.</a> Experior can help  determine the best plan of action to implement encryption  in your IT systems to protect   your organization from breach notification requirements.</p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/09/02/breach-notification-goes-into-effect-on-september-23-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HHS Ruling on Encryption &#8211; ARRA/HITECH ACT subsection 13402</title>
		<link>http://www.experiordata.com/blog/2009/08/24/hhs-ruling-on-encryption-arrahitech-act-subsection-13402/</link>
		<comments>http://www.experiordata.com/blog/2009/08/24/hhs-ruling-on-encryption-arrahitech-act-subsection-13402/#comments</comments>
		<pubDate>Mon, 24 Aug 2009 04:46:46 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ARRA]]></category>
		<category><![CDATA[Rulings]]></category>
		<category><![CDATA[Section 13402]]></category>
		<category><![CDATA[13402]]></category>
		<category><![CDATA[breach notification]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=3</guid>
		<description><![CDATA[On Thursday, August 20th, 2009, the U.S. Department of Health and Human Services (HHS) issued the Interim Final Rule on Breach Notification. An important part the interim final rule is the decision that encryption is the only acceptable technology to make protected health information (essentially, patient records) &#8220;unusable, unreadable, or indecipherable to unauthorized individuals&#8221;. The [...]]]></description>
			<content:encoded><![CDATA[<p>On Thursday, August 20th, 2009, the U.S. Department of Health and Human Services (HHS) issued the <a href="http://www.hhs.gov/ocr/privacy/hipaa/understanding/coveredentities/breachnotificationifr.html">Interim Final Rule on Breach Notification.</a><br />
<br/><a href="http://www.hhs.gov/ocr/privacy/hipaa/understanding/coveredentities/breachnotificationifr.html"></a> An important part the interim final rule is the decision that encryption is the only acceptable technology to make protected health information (essentially, patient records) &#8220;unusable, unreadable, or indecipherable to unauthorized individuals&#8221;. The preamble to the rule explains that even though other methods (such as access control) can continue to be used, if a breach occurs and the protected health information is disclosed to unauthorized individuals a breach notification is required.<br />
<br/>Breach notifications are essentially categorized as &#8220;under 500&#8243; and &#8220;over 500&#8243; records. If a breach occurred to under 500 records then covered entities must maintain a log of the breach and notify the patients. If a breach over 500 records has occurred then not only patients need to be notified but also major media outlet and HHS. In addition, a hotline must be established so that people can call and obtain more information about the breach (notification procedures are specified in the HITECH Act, Section 13402). HHS can issue fines and attorneys general of each state are empowered to pursue these types of breaches on a criminal level.<br/><br />
The government is clearly serious about patient record privacy to encourage covered entities to move paper records to electronic records as part of its overall healthcare reform efforts.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/08/24/hhs-ruling-on-encryption-arrahitech-act-subsection-13402/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

