HITECH

Showing posts with label HITECH. Show all posts
Showing posts with label HITECH. Show all posts

OCR Designates HIPAA Regional Office Privacy Advisors

The Acting Director and Principal Deputy Director for the Office for Civil Rights, Robinsue Frohboese, has designated Office for Civil Rights Regional Managers in each of the HHS Regional Offices to serve as the Regional Office Privacy Advisors. On July 27, 2009, Secretary Sebelius authorized the Director of the Office for Civil Rights to carry out the designation required under the Health Information Technology for Economic and Clinical Health (HITECH) Act (Title XIII of Division A and Title IV of Division B of the American Recovery and Reinvestment Act of 2009 (ARRA).

The designation of these Regional Office Privacy Advisors was mandated by the ARRA-HITECH provisions under Section 13403(a). The Regional Office Privacy Advisors will offer guidance and education to covered entities, business associates, and individuals on their rights and responsibilities related to the HIPAA Privacy and Security Rules

The names, addresses, and contact information for each of the Regional Managers are listed together with a list of the States for which each Regional Manager has responsibility are listed below:

Region I - Boston (Connecticut, Maine, Massachusetts, New Hampshire, Rhode Island, Vermont)
Peter Chan, Regional Manager
Office for Civil Rights
U.S. Department of Health and Human Services
Government Center
J.F. Kennedy Federal Building - Room 1875
Boston, MA 02203
Voice phone(617)565-1340
FAX (617)565-3809
TDD (617)565-1343

Region II - New York (New Jersey, New York, Puerto Rico, Virgin Islands)
Michael Carter, Regional Manager
Office for Civil Rights
U.S. Department of Health and Human Services
Jacob Javits Federal Building
26 Federal Plaza - Suite 3312
New York, NY 10278
Voice Phone (212)264-3313
FAX (212)264-3039
TDD (212)264-2355

Region III - Philadelphia (Delaware, District of Columbia, Maryland, Pennsylvania, Virginia, West Virginia)
Paul Cushing, Regional Manager
Office for Civil Rights
U.S. Department of Health and Human Services
150 S. Independence Mall West
Suite 372, Public Ledger Building
Philadelphia, PA 19106-9111
Main Line (215)861-4441
Hotline (800) 368-1019
FAX (215)861-4431
TDD (215)861-4440

Region IV - Atlanta (Alabama, Florida, Georgia, Kentucky, Mississippi, North Carolina, South Carolina, Tennessee)
Roosevelt Freeman, Regional Manager
Office for Civil Rights
U.S. Department of Health and Human Services
Atlanta Federal Center, Suite 3B70
61 Forsyth Street, S.W.
Atlanta, GA 30303-8909
Voice Phone (404)562-7886
FAX (404)562-7881
TDD (404)331-2867

Region V - Chicago (Illinois, Indiana, Michigan, Minnesota, Ohio, Wisconsin)
Valerie Morgan-Alston, Regional Manager
Office for Civil Rights
U.S. Department of Health and Human Services
233 N. Michigan Ave., Suite 240
Chicago, IL 60601
Voice Phone (312)886-2359
FAX (312)886-1807
TDD (312)353-5693

Region VI - Dallas (Arkansas, Louisiana, New Mexico, Oklahoma, Texas)
Ralph Rouse, Regional Manager
Office for Civil Rights
U.S. Department of Health and Human Services
1301 Young Street, Suite 1169
Dallas, TX 75202
Voice Phone (214)767-4056
FAX (214)767-0432
TDD (214)767-8940

Region VII - Kansas City (Iowa, Kansas, Missouri, Nebraska)
Frank Campbell, Regional Manager
Office for Civil Rights
U.S. Department of Health and Human Services
601 East 12th Street - Room 248
Kansas City, MO 64106
Voice Phone (816)426-7277
FAX (816)426-3686
TDD (816)426-7065

Region VIII - Denver (Colorado, Montana, North Dakota, South Dakota, Utah, Wyoming)
Velveta Howell, Regional Manager
Office for Civil Rights
U.S. Department of Health and Human Services
1961 Stout Street -- Room 1426 FOB
Denver, CO 80294-3538
Voice Phone (303)844-2024
FAX (303)844-2025
TDD (303)844-3439

Region IX - San Francisco (American Samoa, Arizona, California, Guam, Hawaii, Nevada)
Michael Kruley, Regional Manager
Office for Civil Rights
U.S. Department of Health and Human Services
90 7th Street, Suite 4-100
San Francisco, CA 94103
Voice Phone (415)437-8310
FAX (415)437-8329
TDD (415)437-8311

Region X - Seattle(Alaska, Idaho, Oregon, Washington)
Linda Yuu Connor, Regional Manager
Office for Civil Rights
U.S. Department of Health and Human Services
2201 Sixth Avenue - M/S: RX-11
Seattle, WA 98121-1831
Voice Phone (206)615-2290
FAX (206)615-2297
TDD (206)615-2296

ONC Issues Final Rule for EHR Temporary Certification Program

Last Friday the Office of National Coordinator for Health Information Technology (ONC) issued a final rule providing the details on how organizations can be authorized by ONC to test and certify EHR technology. ONC discusses the details the Temporary Certification Program.

Certification is important because the Medicare and Medicaid EHR incentives under HITECH require the use of certificate EHR technology for eligible hospital and providers to recieve payments under the incentive program.

For more information check out the Temporary Certification Program information on the ONC Health IT website, including a link to a complete copy of the Temporary Certification Program Final Rule.

More information from Government Health IT, ONC launches health IT certification program and iHealthBeat, ONC To Start Accepting Bids for Entities to Certify EHR Products.

UPDATE (6/24/2010): The official Federal Register version of the Final Rule is now available: 45 CFR Part 170, Establishment of the Temporary Certification Program for Health Information Technology; Final Rule (75 Fed. Reg. 36158, June 24, 2010). The Final Rule is effective on June 24, 2010.

HIPAA Privacy Rule Accounting of Disclosures under HITECH

Today's Federal Register includes the Office of Civil Rights (OCR) Notice of Proposed Rulemaking (NPRM) modifying the HIPAA Privacy Rule's Accounting of Disclosure requirements for protected health information. OCR was required to make these modifications to the HIPAA Privacy Rule to implement the requirements under the Health Information Technology for Economic and Clinical Health Act (HITECH) section of the ARRA.
HIPAA Privacy Rule Accounting of Disclosures Under the Health Information Technology for Economic and Clinical Health Act, Office for Civil Rights, Notice of Proposed Rulemaking (76 FR 31426, May 31, 2011)
The regulations greatly expand the responsibility for health care covered entities and business associates to document and track the use and disclosure of health information held in an electronic health record (EHR). Health care providers and business associates should plan to thoroughly review these new regulations to understand the impact on their existing policies and procedures.

The regulations outline new procedures for accounting of disclosures of health information held in an electronic health record and disclosed for treatment, payment, and health care operations (as defined under HIPAA). The accounting period under the proposed regulations is three years. The proposed regulations focus on two rights for individuals -- a right to an accounting of disclosure and a "new" right to an access report. The new access report does not distinguish between a use (think internal use by a health care provider) and disclosure (providing the information to a third party). Instead the new right to an access report focuses on whether someone "accessed" the information in the EHR.

Previously under HIPAA, uses and disclosures for treatment, payment, and health care operations (commonly referred to as "TPO") were exempt from the accounting of disclosures requirements. The requirement for accounting for some limited uses and disclosures has always been a part of the HIPAA Privacy Rule.

The rule proposes separate compliance dates for the changes to the accounting of disclosures requirements (180 days after the effective date of the final rule - 240 days after publication of the final rule) and for the right to receive an access report (beginning January 1, 2013, for any EHR system acquired after January 1, 2009 and January 1, 2014, for any EHR system acquired on or before January 1, 2009).

My initial comments above are based upon a quick review of the proposed regulations. Official comments on the NPRM must be submitted on or before August 1, 2011.

ONC Releases HIT ARRA Implementation Plan

The Office of the National Coordinator for Health Information Technology (ONC) has released an operating plan titled the Health Information Technology American Recovery and Reinvestment Act (ARRA) Implementation Plan.

The operating plan is included on the DHHS Agency Wide Plan page under the "List of Recovery Programs within HHS."

The operating plan outlines immediate actions to meet statutory requirements under the Health Information Technology for Economic and Clinical Health Act (HITECH) provisions of the ARRA. The

The topic headings for the operating plan include:

A. Funding Table
B. Objectives
C-E. Activities, Characteristics and Delivery Schedules
F. Environmental Review Compliance
G. Measures
H. Monitoring/Evaluation
I. Transparency
J. Accountability
K. Barriers to Effective Implementation
L. Federal Infrascructure Investment

Thanks to Jim Tate (@jimtate) and John Chilmark (@john_chilmark) for pointing out the report.

HITECH Final Regulations Update: Coming Soon!

Susan McAndrew, deputy director for health information privacy at the Office for Civil Rights (OCR) indicated this week that various final regulations modifying the HIPAA privacy and security rules required by the Health Information Technology for Economic and Clinical Health Act (HITECH) will be issued soon. Health lawyers have been waiting on these regulations to better understand the full impact of the HITECH changes to HIPAA, including whether the "harm standard" will remain a part of the Interim Final Rule on breach notification.

According to a Health Information Security News article, McAndrew made this announcement this week while speaking at the 2011 NIST HIPAA Conference, Safeguarding Health Information: Building Assurance through HIPAA Security, held in Washington.

The article also indicated that a separate NPRM will be issued announcing the approach OCR plans to take regarding the accounting for disclosure modifications under the HITECH Act. The HITECH Act modified the traditional rule regarding those types of uses and disclosures that must be accounted for by health care providers and covered entities. Under the traditional rule -- health care providers did not have to provide an accounting of disclosure for uses and disclosures for treatment, payment, and health care operations. However, the modification by the HITECH Act now requires health care providers who utilize an electronic health record system (EHR)to provide, upon request, an accounting of disclosure of all uses and disclosures including those for treatment, payment, and health care operations which occurred within the last three year period. Of further interest will be how the NPRM suggests how business associates who obtain PHI from health care providers must also track and maintain a list of uses and disclosures for accounting of disclosure requests.

Update On HIT Policy and Standards Committees

Last week the Federal Register (April 29, 2009) contained a Notification of the Establishment of the HIT Policy Committee and HIT Standards Committee. I had previously posted about the creation of these committee and recommended suggested members.

More information will be made available via the "new" Health Information Technology website of the Office of the National Coordinator.

The summary of the notice on establishing the HIT Policy Committee states:
This notice announces the establishment of the HIT Policy Committee. The American Recovery and Reinvestment Act of 2009 (Pub. L. 111-5), section 13101, directs the establishment of the HIT Policy Committee.

The HIT Policy Committee (also referred to as the "Committee'') is charged with recommending to the National Coordinator a policy framework for the development and adoption of a nationwide health information technology infrastructure that permits the electronic exchange and use of health information as is consistent with the Federal Health IT Strategic Plan and that includes recommendations on the areas in which standards, implementation specifications, and certification criteria are needed. The HIT Policy Committee is also charged with recommending to the National Coordinator an order of priority for the development, harmonization, and recognition of such standards, specifications, and certification criteria.
The notice outlines the criteria for members of the HIT Policy Commitee and states that the appointments shall be made in the following manner:
  • 1 member shall be appointed by the majority leader of the Senate;
  • 1 member shall be appointed by the minority leader of the Senate;
  • 1 member shall be appointed by the Speaker of the House of Representatives;
  • 1 member shall be appointed by the minority leader of the House of Representatives;
  • Such other members as shall be appointed by the President as representatives of other relevant Federal agencies;
  • 13 members shall be appointed by the Comptroller General of the United States of whom-
  • 3 members shall be advocates for patients or consumers;
  • 2 members shall represent health care providers, one of which shall be a physician;
  • 1 member shall be from a labor organization representing health care workers;
  • 1 member shall have expertise in health information privacy and security;
  • 1 member shall have expertise in improving the health of vulnerable populations;
  • 1 member shall be from the research community;
  • 1 member shall represent health plans or other third-party payers;
  • 1 member shall represent information technology vendors;
  • 1 member shall represent purchasers or employers; and
  • 1 member shall have expertise in health care quality measurement and reporting.
  • Non-federal members of the Committee shall be Special Government
  • Employees, unless classified as representatives.

The summary of the notice on establishing the HIT Standards Committee states:
This notice announces the establishment of the HIT Standards Committee. The American Recovery and Reinvestment Act of 2009 (ARRA) (Pub. L. 111-5), section 13101, directs the establishment of the HIT Standards Committee. The HIT Standards Committee (also referred to as the "Committee'') is charged with making recommendations to the National Coordinator on standards, implementation specifications, and certification criteria for the electronic exchange and use of health information for purposes of adoption, consistent with the implementation of the Federal Health IT Strategic Plan, and in accordance with policies developed by the HIT Policy Committee.
The notice outlines the criteria for members of the HIT Standards Commitee and states that the appointments shall be made in the following manner:
The HIT Standards Committee shall not exceed thirty (30) voting members, including a Chair and Vice Chair, and members are appointed by the Secretary with input from the National Coordinator. Membership of the Committee shall at least reflect providers, ancillary healthcare workers, consumers, purchasers, health plans, technology vendors, researchers, relevant Federal agencies, and individuals with technical expertise on health care quality, privacy and security, and on the electronic exchange and use of health information and shall represent a balance among various sectors of the health care system so that no single sector unduly influences the recommendations of the Committee. Non-Federal members of the Committee shall be Special Government Employees, unless classified as representatives.
Thanks for the tip on the issuance of the notice to John Halamka at Life as a Healthcare CIO: Next Steps on the HIT Policy and Standards Committees.



UPDATE (5/7/09): Brian Ahier (@ahier) provides the latest update on with information on the first meetings of the HIT Policy Committee on May 11 and HIT Standards Committee meeting on May 15. Brian also provides links to the announcment by the GAO of 13 of the members of the HIT Policy Committee.

The announcment includes a list of the 13 members appointed by the Acting Comptroller General covering 10 different categories:

Advocates for Patients or Consumers

1. Christine Bechtel, Washington, D.C. (3 year term)
Vice President, National Partnership for Women & Families

2. Arthur Davidson, M.D., Denver Colorado (2 year term)
Denver Public Health Department; Director, Public Health Informatics; Director, Denver Center for Public Health Preparedness; Medical epidemiologist; Director, HIV/AIDS Surveillance, City and County of Denver

3. Adam Clark, Ph.D., Austin, Texas (1 year term)
Director of Research and Policy, Lance Armstrong Foundation

Representatives of Health Care Providers, including 1 physician

4. Marc Probst, Salt Lake City, Utah (3 year term)
Chief Information Officer, Intermountain Healthcare

5. Paul Tang, M.D., Mountain View, California (2 year term)
Vice President and Chief Medical Information Officer, Palo Alto Medical Foundation

Labor Organization Representing Health Care Workers

6. Scott White, New York City, New York (1 year term)
Assistant Director, Technology Project Director, 1199 SEIU Training and Employment Fund

Expert in Health Information Privacy & Security

7. LaTanya Sweeney, Ph.D., Pittsburgh, Pennsylvania (3 year term)
Director, Data Privacy Lab, Associate Professor of Computer Science, Technology and Policy, Carnegie Mellon University

Expert in Improving the Health of Vulnerable Populations

8. Neil Calman, M.D., New York City, New York (2 year term)
President and CEO, The Institute for Family Health, Inc.
Research Community

9. Connie Delaney, R.N., Ph.D., Minneapolis, Minnesota (1 year term)
Dean, School of Nursing, University of Minnesota

Representative of Health Plans or Other Third-Party Payers

10. Charles Kennedy, M.D., Camarillo, California (3 year term)
Vice President, Health Information Technology, Wellpoint, Inc.
Representative of Information Technology Vendors

11. Judith Faulkner, Verona, Wisconsin (2 year term)
Founder, CEO, President, Chairman of the Board, Epic Systems Corporation
Representative of Purchasers or Employers

12. David Lansky, Ph.D., San Francisco, California (1 year term)
President and CEO, Pacific Business Group on Health

Expert in Health Care Quality Measurement and Reporting

13. David Bates, M.D., Boston, Massachusetts (3 year term)
Medical Director for Clinical and Quality Analysis, Chief of General Internal Medicine, Partners HealthCare/Brigham & Women’s Hospital

More information on the upcoming meetings:

OCR Request for Information: HIPAA Privacy Rule Accounting of Disclosures under HITECH

Today the Office for Civil Rights (OCR), Department of Health and Human Services issued a Request for Information titled HIPAA Privacy Rule Accounting of Disclosures Under the Health Information Technology for Economic and Clinical Health Act (75 Fed Reg 23214 May 3, 2010). More information at the OCR website.

The Request for Information by OCR seeks comments from health consumers and health care providers/organizations. OCR seeks information on the following areas:
  • Understanding the interests of individuals (health consumers) with respect to learning of such disclosures; and
  • The administrative burden on covered entities (health care providers/organizations) and business associates of accounting for such disclosures.
The Request for Information states that Section 13405(c) of the Health Information Technology for Economic and Clinical Health (HITECH) Act expands an individual’s right under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Rule to receive an accounting of disclosures of protected health information made by HIPAA covered entities and their business associates. In particular, section 13405(c) of the HITECH Act requires that the HIPAA Privacy Rule be amended to require covered entities to account for disclosures of protected health information to carry out treatment, payment, and health care operations if such disclosures are through an electronic health record.

The Request for Information requests specific comments on the following nine questions:

1. What are the benefits to the individual of an accounting of disclosures, particularly of disclosures made for treatment, payment, and health care operations purposes?

2. Are individuals aware of their current right to receive an accounting of disclosures? On what do you base this assessment?

3. If you are a covered entity, how do you make clear to individuals their right to receive an accounting of disclosures? How many requests for an accounting have you received from individuals?

4. For individuals that have received an accounting of disclosures, did the accounting provide the individual with the information he or she was seeking? Are you aware of how individuals use this information once obtained?

5. With respect to treatment, payment, and health care operations disclosures, 45 CFR 170.210(e) currently provides the standard that an electronic health record system record the date, time, patient identification, user identification, and a description of the disclosure. In response to its interim final rule, the Office of the National Coordinator for Health Information Technology received comments on this standard and the corresponding certification criterion suggesting that the standard also include to whom a disclosure was made (i.e., recipient) and the reason or purpose for the disclosure. Should an accounting for treatment, payment, and health care operations disclosures include these or other elements and, if so, why? How important is it to individuals to know the specific purpose of a disclosure— i.e., would it be sufficient to describe the purpose generally (e.g., for ‘‘for treatment,’’ ‘‘for payment,’’ or ‘‘for health care operations purposes’’), or is more detail necessary for the accounting to be of value? To what extent are individuals familiar with the different activities that may constitute ‘‘health care operations?’’ On what do you base this assessment?

6. For existing electronic health record systems:
(a) Is the system able to distinguish between ‘‘uses’’ and ‘‘disclosures’’ as those terms are defined under the HIPAA Privacy Rule? Note that the term ‘‘disclosure’’ includes the sharing of information between a hospital and physicians who are on the hospital’s medical staff but who are not members of its workforce.
(b) If the system is limited to only recording access to information without regard to whether it is a use or disclosure, such as certain audit logs, what information is recorded? How long is such information retained? What would be the burden to retain the information for three years?
(c) If the system is able to distinguish between uses and disclosures of information, what data elements are automatically collected by the system for disclosures (i.e., collected without requiring any additional manual input by the person making the disclosure)? What information, if any, is manually entered by the person making the disclosure?
(d) If the system is able to distinguish between uses and disclosures of information, does it record a description of disclosures in a standardized manner (for example, does the system offer or require a user to select from a limited list of types of disclosures)? If yes, is such a feature being utilized and what are its benefits and drawbacks?
(e) Is there a single, centralized electronic health record system? Or is it a decentralized system (e.g., different
departments maintain different electronic health record systems and an accounting of disclosures for treatment,
payment, and health care operations would need to be tracked for each system)?
(f) Does the system automatically generate an accounting for disclosures under the current HIPAA Privacy Rule (i.e., does the system account for disclosures other than to carry out treatment, payment, and health care
operations)?
i. If yes, what would be the additional burden to also account for disclosures to carry out treatment, payment, and health care operations? Would there be additional hardware requirements (e.g., to store such accounting information)? Would such an accounting feature impact system performance?
ii. If not, is there a different automated system for accounting for disclosures, and does it interface with the electronic health record system?

7. The HITECH Act provides that a covered entity that has acquired an electronic health record after January 1, 2009 must comply with the new accounting requirement beginning January 1, 2011 (or anytime after that date when it acquires an electronic health record), unless we extend this compliance deadline to no later than 2013. Will covered entities be able to begin accounting for disclosures through an electronic health record to carry out treatment, payment, and health care operations by January 1, 2011? If not, how much time would it take vendors of electronic health record systems to design and implement such a feature? Once such a feature is available, how much time would it take for a covered entity to install an updated electronic health record system with this feature?

8. What is the feasibility of an electronic health record module that is exclusively dedicated to accounting for disclosures (both disclosures that must be tracked for the purpose of accounting under the current HIPAA Privacy Rule and disclosures to carry out treatment, payment, and health care operations)? Would such a module work with covered entities that maintain decentralized electronic health record systems?

9. Is there any other information that would be helpful to the Department regarding accounting for disclosures
through an electronic health record to carry out treatment, payment, and health care operations?

Written comments to OCR must be submitted on or before May 18, 2010.

CMS and ONC Issue Rules on Proposing a Definition of Meaningful Use and Setting Standards for EHR Incentive Program

Yesterday the Centers for Medicare & Medicare Services (CMS) and the Office of the National Coordinator for Health Information Technology (ONC) issued two regulations laying the foundation for improving quality, efficiency and safety through meaningful use of certified electronic health record (EHR) technology.

The two regulations are part of the implementation of the EHR incentive programs for physicians and hospitals enacted under the HITECH provisions of the American Recovery and Reinvestment Act of 2009 (ARRA). CMS issued a proposed rule outlining the proposed provisions governing the EHR incentive programs, including defining the central concept of “meaningful use” of EHR technology. ONC issued an interim final regulation setting forth the initial standards, implementation specifications, and certification criteria for EHR technology.

For more details see the following CMS Press Release. Also, CMS has issued Fact Sheets on the proposed regulations:
Below are links to complete copies of the rules. Once they are published in the Federal Register I will update with the specific Fed Reg details. Some light reading for the New Year!
Medicare and Medicaid Programs; Electronic Health Record Incentive Program
AGENCY: Centers for Medicare & Medicaid Services (CMS), HHS.
ACTION: Proposed rule.
SUMMARY: This proposed rule would implement the provisions of the American Recovery and Reinvestment Act of 2009 (ARRA) (Pub. L. 111-5) that provide incentive payments to eligible professionals (EPs) and eligible hospitals participating in Medicare and Medicaid programs that adopt and meaningfully use certified electronic health record (EHR) technology. The proposed rule would specify the-- initial criteria an EP and eligible hospital must meet in order to qualify for the incentive payment; calculation of the incentive payment amounts; payment adjustments under Medicare for covered professional services and inpatient hospital services provided by EPs and eligible hospitals failing to meaningfully use certified EHR technology; and other program participation requirements. Also, as required by ARRA the Office of the National Coordinator for Health Information Technology (ONC) will be issuing a closely related interim final rule that specifies the Secretary’s adoption of an initial set of standards, implementation, specifications, and certification criteria for electronic health records. ONC will also be issuing a notice of proposed rulemaking on the process for organizations to conduct the certification of EHR technology.

Health Information Technology: Initial Set of Standards, Implementation Specifications, and Certification Criteria for Electronic Health Record Technology
AGENCY: Office of the National Coordinator for Health Information Technology,
Department of Health and Human Services.
ACTION: Interim final rule.
SUMMARY: The Department of Health and Human Services (HHS) is issuing this interim final rule with a request for comments to adopt an initial set of standards, implementation specifications, and certification criteria, as required by section 3004(b)(1) of the Public Health Service Act. This interim final rule represents the first step in an incremental approach to adopting standards, implementation specifications, and certification criteria to enhance the interoperability, functionality, utility, and security of health information technology and to support its meaningful use. The certification criteria adopted in this initial set establish the capabilities and related standards that certified electronic health record (EHR) technology will need to include in order to, at a minimum, support the achievement of the proposed meaningful use Stage 1 (beginning in 2011) by eligible professionals and eligible hospitals under the Medicare and Medicaid EHR Incentive Programs.

AHLA Teleconference: HIPAA Privacy Fundamentals

Next month I will be co-presenting on an American Health Lawyer Association Teleconference on the topic of HIPAA Privacy Regulation Fundamentals - An Introductory Course.

The teleconference is scheduled for May 13, 2009, 1:00 - 2:30 pm EST. My co-presenter is Rebecca L. Williams of Davis Wright Tremaine LLP and the moderator will be Phyllis Granade of Adorn & Yoss.

This teleconference is geared toward a gaining a basic understanding of HIPAA privacy law for health lawyers (think, HIPAA 101). We will also be discussing the impact of the changes unde rthe HITECH Act of 2009. Although geared toward health lawyers this teleconference would also be valuable for health care professionals and others in the industry interested in learning more about HIPAA.

You can find out more about the teleconference and how to register via the AHLA website.

Lorman Medical Records Law Seminar: March 18, 2010

On March 18, 2010 I will be speaking on Medical Records Law at a seminar in Charleston, West Virginia. The seminar is sponsored by Lorman Educational Services. Joining me for the day long seminar will be three very knowledgeable health care colleagues:
  • Michael T. Harmon, MPA, CIPP/G, Compliance Specialist for the West Virginia Mutual Insurance Company, a Medical Professional Liability Insurance Company
  • Sallie H. Milam, J.D., CIPP/G, Executive Director of the West Virginia Health Information Network and Chief Privacy Officer for the West Virginia State Government
  • James W. Thomas, Esq., Manager of the Charleston, West Virginia Business Law Department of Jackson Kelly PLLC whose practice focuses primarily upon health care matters of a business, regulatory and operational nature
Additional information about the seminar and how to register can be found at Lorman Educational Services. Following is the full seminar agenda:

8:30 am – 9:00 am


Registration




9:00 am – 9:15 am


Overview




9:15 am – 10:30 am


HIPAA Compliance: Reality and Perspective



— Michael T. Harmon, MPA, CIPP/G



  • Overview
  • Enforcement
  • Complaints
  • Case Examples
  • Summary of HITECH Changes




10:30 am – 10:45 am


Break




10:45 am – 12:00 pm


HITECH Financial Incentives for Implementation of HIT



— James W. Thomas, Esq.



  • Qualifying an Electronic Health Record System
  • Available Financial Incentives




12:00 pm – 1:00 pm


Lunch (On Your Own)




1:00 pm – 2:00 pm


Health Information Exchange in West Virginia: Impact on Patient Records



— Sallie H. Milam, J.D., CIPP/G




2:00 pm – 2:15 pm


Break




2:15 pm – 3:30 pm


Consumer Driven Health Care: HITECH, Health 2.0, Social Media and Personal Health Records



— Robert L. Coffield, Esq.



  • HITECH Breach Notification Requirements
  • Impact of Health 2.0 and Social Media Technology on the Future of Health Care
  • Development and Adoption of Personal Health Records
  • Discuss the Legal Implications of Emerging Technology




3:30 pm – 4:30 pm


Panel Discussion



— Robert L. Coffield, Esq., Michael T. Harmon, MPA, CIPP/G, Sallie H. Milam, J.D., CIPP/G and James W. Thomas, Esq.

HITECH Act Breach Notification Guidance: What Renders PHI Unusable, Unreadable or Indecipherable For Purposes of Breach Notification?

On April 17, 2009, the U.S. Department of Health & Human Services (HHS) issued guidance on the technology requirements to render protected health information (PHI) "unusable, unreadable or indecipherable to unauthorized individuals, as required by the Health Information Technology for Economic and Clinical Health Act (HITECH) which is a part of the American Recovery and Reinvestment Act of 2009 (ARRA).

The April 27, 2009 Federal Register (74 FR 19006),contains the official copy of the regulation, Guidance Specifying the Technologies and Methodologies That Render Protected Health Information Unusable, Unreadable, or Indecipherable to Unauthorized Individuals for Purposes of the Breach Notification Requirements Under Section 13402 of Title XIII (Health Information Technology for Economic and Clinical Health Act) of the American Recovery and Reinvestment Act of 2009; Request for Information

The guidance is effective as of April 17, 2009. However, the guidance will apply to breaches 30 days after publication of the interim final regulations.

HHS's press release on the guidance states:
The guidance issued today provides steps entities can take to secure personal health information and establishes the trigger for when entities must notify that patient data has been compromised. This guidance is related to “breach notification” regulations, which will be issued by HHS and the Federal Trade Commission respectively. The HHS regulations will apply to entities covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the FTC regulation will apply to vendors of personal health records and certain others not covered by HIPAA. The Recovery Act requires that these regulations be published within 180 days of enactment.
The guidance was developed through a joint effort by the HHS Office for Civil Rights (OCR), Office of the National Coordinator for Health Information Technology (ONC), and Centers for Medicare &Medicaid Services (CMS).
The guidance also seeks public comments on the guidance as well as the breach notification provisions under FTC's new Health Breach Notification Rule and the yet to be releases HHS Breach Notification Requirements for HIPAA Covered Entities and Business Associates. Public comments must be submitted on or before May 21, 2009.

OCR Update on Issuance of HIPAA HITECH Rulemaking

Update from Office for Civil Rights (OCR) on issuance of the Notice of Proposed Rulemaking (NPRM) implementing changes to HIPAA under the Health Information Technology for Economic and Clinical Health Act (HITECH). Health care organizations and health lawyers have been anxiously awaiting rules implementing and interpreting the changes because the effective date for many of the HITECH requirements was February 17, 2010. Of particular interest has been whether or not health care organizations are required to amend business associate agreement.

The notice seems to indicate that the the date for compliance and enforcement may be delayed since it states that the NPRM "will provide specific information regarding the expected date of compliance and enforcement." However, covered entities and business associates need to weigh the risks of not complying with the new requirements while waiting for further clarification from OCR.

The notice states:
OCR will implement important privacy and security provisions of the Health Information Technology for Economic and Clinical Health (HITECH) Act through notice and comment rulemaking, as required by the Administrative Procedure Act. These provisions include: business associate liability; new limitations on the sale of protected health information, marketing, and fundraising communications; and stronger individual rights to access electronic medical records and restrict the disclosure of certain information. OCR continues work on a Notice of Proposed Rulemaking (NPRM) regarding these provisions. Although the effective date (February 17, 2010) for many of these HITECH Act provisions has passed, the NPRM and the final rule that follows will provide specific information regarding the expected date of compliance and enforcement of these new requirements.

However, interim final rules implementing HITECH Act provisions in two areas have already been issued and are currently in effect: enforcement and breach notification. New civil money penalty amounts apply to HIPAA Privacy and Security Rule violations occurring after February 17, 2009. Covered entities and business associates must comply now with breach notification obligations for breaches that are discovered on or after September 23, 2009. OCR announced previously that it would use its enforcement discretion not to impose fiscal sanctions with regard to breaches discovered before February 22, 2010. Since that date has passed, OCR will enforce the Breach Notification Interim Final Rule, including with the possible imposition of sanctions, as it does with the HIPAA Privacy and Security Rule requirements.

ARRA Timelines

John Halamka at Life as a Healthcare CIO provides a good overview of the timeline and deadlines for the health information technology portions under the American Recovery and Reinvestment Act of 2009 (ARRA).

UPDATE (3/17/09): John Halamka has also added a summary of Timeline for ARRA Privacy Provisions which was based on work by Markle Foundation and the Center for Democracy and Technology.

Nominees for HITECH HIT Policy Committee and HIT Standards Committee

The Thursday, March 13 Federal Register (74 Fed Reg 10743) contained a notice for submitting nominees to the new committees created under ARRA-HITECH (stimulus bill) for developing health information technology standards and policy. The two commitees will be called the HIT Standards Commitee and HIT Policy Commitee. Details on these committees and the type of stakeholder representation on the commiteeis outlined in the notice listed below.

After seeing the notice I pushed it out to a variety of health colleagues via Twitter asking the question, "Who would you nominate?" The viral social networking nomination process was off and running and a Health Twitterstorm was started with many responses and recommended nominees. To view the process check out the tag #NominateHIT.

Jen McCabe Gorman (@jenmccabegorman) started to aggregate potential nominees to be submitted by the deadline of March 16. She has generously offered to coordinate the response and submit them to the ONC.

So far the results of potential nominees:
UPDATE: Jen McCabe Gorman aggregated all the nominees in one post. If you are interested in having your name submitted as a nominee - please follow the instructions by Jen listed in her post. Deadline for submission is today.

A number of people asked about my nominees so I thought I would add them here. Here goes in no particular order (if you find your name below and want to be considered please forward your information to Jen McCabe Gorman here):

Jane Sarasohn-Kahn, Health Economist, Health Populi

Christopher Parks, CEO of change:healthcare

John D. Halamka, MD, MS, CIO CareGroup Health System, Chief Information Officer and Dean for Technology at Harvard Medical School

Scott Shreeve, CEO ofCrossover Healthcare

Josh Lemieux, Markle Foundation

Jay Parkinson, MD, Hello Health

Jen McCabe Gorman, Health Management RX

Matthew Holt, Health Care Strategist and Co-Founder, Health 2.0

Jonathan Bush, CEO of Athena Health

Peter Neupert, VP Health Solutions Group, Microsoft

Roni Zeiger, MD, Product Manager, Google Health

Enoch Choi, MD, Partner, Palo Alto Medical Foundation, MedHelp.org

Marty Tenenbaum, Health 2.0 Accelerator Visionary

David Kibbe, Senior Advisor American Academy of Family Physicians

Amy Tenderich, Writer, Blogger, Consultant, Patient Advocate www.DiabetesMine.com

Adam Bosworth, CEO of Keas

Sarah Chouinard, MD, Community Health Network of WV

John Wiesendanger, CEO of West Virginia Medical Institute, Inc.
 

REMEMBER:
Change Doesn't come from Washington. Change comes to Washington.
President Obama




DEPARTMENT OF HEALTH AND HUMAN SERVICES
Office of the National Coordinator for Health Information Technology; HIT Standards Committee and HIT Policy Committee Nomination Letters


ACTION: Notice on letters of nomination.


SUMMARY: The American Recovery and Reinvestment Act of 2009 (Act), Public Law 111–5 amends the Public Health Service Act (PHSA) to add new sections 3002 and 3003. The new section 3003 of the PHSA establishes the HIT Standards Committee to make recommendations to the National Coordinator for Health Information Technology on standards, implementation specifications, and certification criteria for the electronic exchange and use of health information for purposes of health information technology adoption. The HIT Standards Committee members are to be appointed by the Secretary of the Department of Health and Human Services with the National Coordinator taking a leading role. Membership of the HIT Standards Committee should at least reflect the following categories of stakeholders and will include other individuals: providers, ancillary healthcare workers, consumers, purchasers, health plans, technology vendors, researchers, relevant Federal agencies, and individuals with technical expertise on health care quality, privacy
and security, and on the electronic exchange and use of health information.


In addition, we also seek nominations to the HIT Policy Committee (established by the new section 3002 of
the PHSA), which makes recommendations to the National Coordinator on the implementation of a nationwide health information technology infrastructure. The HIT Policy Committee will consist of at least 20 members. Three of these members will be appointed by the Secretary of the Department of Health and Human Services. Of the three members, one must be a representative of the Department of Health and Human Services and one must be a public health official. If, 45 days after the enactment of the Act, an official authorized under the Act to make appointments to the HIT Policy Committee has failed to make anappointment(s), the Act authorizes the Secretary of HHS to make such appointments. The Department of Health and Human Services is consequently accepting nominations for the HIT Policy Committee. New section 3008 of the PHSA allows the Secretary to recognize the NeHC (if modified to be consistent with the requirements of section 3002 and 3003 of the Act and other federal laws) as either the HIT Policy Committee or the HIT Standards Committee. At this time, the Department of Health and Human Services is evaluating options regarding the National eHealth Collaborative and its role in relation to those Committees. For appointments to either the HIT Standards Committee or the HIT Policy Committee, I am announcing the following: Letters of nomination and resumes should be submitted by March 16, 2009 to ensure adequate opportunity for review and consideration of nominees prior to appointment of members.


ADDRESSES: Office of the National Coordinator, Department of Health and Human Services, 200 Independence Avenue, NW., Washington, DC 20201, Attention: Judith Sparrow, Room 729D.

E-mail address:
HIT_FACA_nominations@hhs.gov.
Please indicate in your letter or e-mail to which Committee your nomination belongs.


FOR FURTHER INFORMATION CONTACT:
ONC/HHS, Judith Sparrow, (202) 205–4528.
Authority: The American Recovery and Reinvestment Act of 2009 (Pub. L. 111–5), section 13101.
Dated: March 9, 2009.
Robert M. Kolodner,
National Coordinator for Health Information Technology, Office of the National Coordinator for Health Information Technology.
[FR Doc. E9–5391 Filed 3–9–09; 4:15 pm]
BILLING CODE 4150–45–P

Federal Advisory Committee Blog (FACA Blog)

The Office of the National Coordinator for Health Information Technology (ONCHIT) has launched a new blog called the Federal Advisory Committee Blog (FACA Blog).

The initial post by Judy Sparrow discusses that the FACA Blog will be uses in a spirit of transparency and collaboration to help open a broader dialogue on the issues before the Health IT Standards Committee and the Health IT Policy Committee. The post also provides some background on the role that Federal Advisory Groups play under the Federal Advisory Committee Act.

The second post by Aneesh Chopra, Federal Chief Technology Officer, spells out the planned process for an open conversation that will take place over the next couple of weeks with various committee members blogging about a variety of topics (Proposed Standards, Interoperability, Vocabularies, Privacy, Security, Quality, Implementation Cases Studies).

The FACA Blog allows individuals to share public comments on each post and has an RSS feed. Great to see ONCHIT using a blog platform to quickly and efficiently distribute information about the ongoing work being done by the committees to further the health information technology efforts under HITECH.

HIPAA Enforcement Meets HITECH: HIPAA Administrative Simplification: Enforcement Rule

On October 30, 2009, the Secretary of the Department of Health and Human Services (HHS) issued the HIPAA Administrative Simplification: Enforcement Interim Final Rule, 45 CFR Part 160 (74 Federal Register 56123, October 30, 2009).

This new rule was developed and adopted by HHS to conform the enforcement regulations under HIPAA to the revisions made to HIPAA under the Health Information Technology for Economic and Clinical Health Act (HITECH), which was part of the American Recovery and Reinvestment Act of 2009 (ARRA).

The rule amends the HIPAA enforcement regulations to include the imposition of tiered ranges for civil money penalty amounts based upon an increasing culpability associated with the violation. A full chart of the violation categories and related amounts can be found in the rule.

The interim final rule is effective on November 30, 2009. Comments on the rule can be made prior to December 29, 2009.

HITECH Law Blog

A warm welcome to fellow AHLA member and health law blogger, Kathie McDonald-McClure.

I just ran across her blog, HITECH Law Blog. She focuses the blog on health information technology, privacy and security and the blog was named after the HITECH Act. Looks like a great addition to the health law blogosphere.

Ms. McDonald-McClure is a member of the Health Care Services Team at Wyatt Tarrant & Combs, LLP in Louisville, KY.

WHCC Leadership Summit on Consumer Connectivity

Today I am attending the World Health Care Congress2nd Annual Leadership Summit on Consumer Connectivity in Carlsbad, CA. Good presentations and discussion with those in attendance. You can follow the conference via Twitter at #WHCC2 or get live blogging at EKIVE by Mark Schrimshire using Cover It Live.

I just finished up my afternoon presentation with Rod Piechowski with the American Hospital Association on the topic of Overcoming Legal and Policy Barriers for Health IT Adoption. With the recent passage of ARRA 2009 we thought it valuable to talk about the changing landscape of Health IT as a result of the new bill. Below are the slides from my presentation.

OCR Imposes $4.3M Penalty for Violation of HIPAA/HITECH Privacy Rule

UNTIL TODAY, many health care providers questioned whether HHS and the Office of Civil Rights (OCR) would ever issue any significant penalties for violations of the HIPAA Privacy Rule. However, will OCR ever be able to collect the penalties.

Today, HHS Office of Civil Rights (OCR) announced a civil money penalty (CMP) of $4.3 million against Cignet Health of Prince George's County, MD for violating the HIPAA Privacy Rule. This is the first ever civil money penalty issued by OCR for a violation of the HIPAA Privacy Rule. It is significant not only because it is the first - but also because of the size of the penalty and the basis for the violation.

OCR issued a Notice of Final Determination on February 4, 2011, outlining the procedure for payment of the $4.3 million civil money penalty. The Notice of Final Determination also indicates that Cignet failed to request a hearing on the matter or reach settlement with OCR. Prior to the issuance of the final notice, OCR had issued a Notice of Proposed Determination on October 20, 2010, which details the basis for the penalty, details the findings of fact, grounds for violation of HIPAA, and calculation of the penalty amount.

The Notice of Proposed Determination indicates that Cignet violated HIPAA by failing to provide individuals access to their health information under 45 CFR 164.524 and failed to cooperate with an investigation under 45 CFR 160.310(b). The Notice states:
1. Failure to Provide Access (45 C.F.R. § 164.524). Cignet failed to provide 41 individuals listed in Attachment A timely access to obtain a copy of the protected health information about them in the designated record sets (medical records) maintained by Cignet. These failures constitute violations of 45 C.F.R. § 164.524. Cignet's failure to provide each individual with access constitutes a separate violation of 45 C.F.R. § 164.524, and each day that the violation continued (that is, from the date specified in column 5 of Attachment A until April 7,2010) counts as a separate violation of 45 C.F.R. § 164.524.

2. Failure to Cooperate with an Investigation (45 C.F.R. § I60.310(b)). Cignet failed to cooperate with OCR's investigation of 27 complaints regarding Cignet's noncompliance described in paragraph 1 above. These failures to cooperate with an investigation constitute violations of 45 C.F.R. § 160.310(b). Cignet's failure to cooperate with OCR's investigation of each complaint constitutes a separate violation of 45 C.F.R. § 160.310(b), and each day that the violation continued (that is, from the date specified in column 7 of Attachment A until April 7, 2010) counts as a separate violation of 45 C.F.R. § 160.310(b). Each violation of 45 C.F.R. § 160.310(b) was due to Cignet's willful neglect of its obligation to comply with 45 C.F.R. § 160.310(b). Willful neglect means the conscious, intentional failure or reckless indifference to the obligation to comply with the administrative simplification provision violated. See 45 C.F.R. § 160.401.
The press release issued by HHS points out that the HIPAA Privacy Rule requires that health care providers must provide a patient with access and/or copy of their health information within 30 days (and no later than 60) days after the patient requests such information. Further, the press release indicates that covered entities and business associates must uphold their responsibility to provide patients with access to their own health information.

Read the HHS Press Release and OCR Press Release. More details via the OCR's Resolution Agreement page. For more background on Cignet Health check out David Harlow's post at HealthBlawg, HIPAA CMP's: What's the point?

Physician Incentives Under HITECH Act

Fellow health care lawyer colleague, AHLA HIT member and friend, Jud DeLoss, provides an excellent overview of the Physician Incentives under the HITECH ACT.

The incentives focus on providing direct payment for the adoption, implementation and maintenance of electronic health records (EHRs) to "eligible professional" who establishes the "meaninful use" of an EHR.

Check out this post and others at Jud's Minnesota Health IT Blog.