privacy

Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Learning: Privacy and Security Monitoring, Audits and Investigations

On November 13, 2007, I will be speaking at a Lorman Eduational Services seminar to be held in Charleston, West Virginia. The seminar topic is "Health Care Information Privacy and Security Monitoring, Audits and Investigations: How to avoid an investigation and what you should expect if the state or federal officials call". You can register online here.

Also speaking at the seminar will be (read full bios):
  • Jack Shaffer, CIO for the Community Health Network of West Virginia who has experience in all aspects of technology, including systems development, enterprise application integration, networking, telecommunications, data center operations, database administration, disaster recovery, security and mobile computing.
Below is a copy of the seminar agenda:

9:00 am – 10:30 am Legal Overview of HIPAA Privacy and Security Enforcement

Robert L. Coffield, Esq.

  • HIPAA Refresher on Enforcement Rules and Penalties
  • OCR Privacy Investigation Statistics
  • Best Practices on Conducting Internal Investigations
  • Responding to OCR/CMS Investigation
10:30 am – 10:45 am Break
10:45 am – 11:30 am Preparing for an Audit

Michael T. Harmon, CIPP/G

  • Auditing vs. Monitoring
  • Other Governmental Auditors – e.g., OIG, Legislature
  • Elements of the OIG Audit of Piedmont Hospital in Atlanta
  • New Kennedy/Leahy Legislation and Changes to Current Practice
  • Privacy and Security Accreditation
11:30 am – 12:30 pm Lunch (On Your Own)
12:30 pm – 2:30 pm Technologies and Procedures for HIPAA Compliance

Jack L. Shaffer Jr.

  • Acceptable Use Policies and Enforcement
  • Protecting PHI With Encryption Technologies
  • Auditing and Monitoring Tools
2:30 pm – 2:45 pm Break
2:45 pm – 3:45 pm The Role of the Privacy Officer

Terrisita Barrett, CIPP

  • The Changing Privacy and Security Landscape
  • Role and Responsibilities: Past, Present and Future
  • Challenges Affecting the Privacy Officer Role
3:45 pm – 4:30 pm Panel Discussion, and Questions and Answers

Terrisita Barrett, CIPP, Robert L. Coffield, Esq.,

Michael T. Harmon, CIPP/G, and Jack L. Shaffer Jr.

OCR Designates HIPAA Regional Office Privacy Advisors

The Acting Director and Principal Deputy Director for the Office for Civil Rights, Robinsue Frohboese, has designated Office for Civil Rights Regional Managers in each of the HHS Regional Offices to serve as the Regional Office Privacy Advisors. On July 27, 2009, Secretary Sebelius authorized the Director of the Office for Civil Rights to carry out the designation required under the Health Information Technology for Economic and Clinical Health (HITECH) Act (Title XIII of Division A and Title IV of Division B of the American Recovery and Reinvestment Act of 2009 (ARRA).

The designation of these Regional Office Privacy Advisors was mandated by the ARRA-HITECH provisions under Section 13403(a). The Regional Office Privacy Advisors will offer guidance and education to covered entities, business associates, and individuals on their rights and responsibilities related to the HIPAA Privacy and Security Rules

The names, addresses, and contact information for each of the Regional Managers are listed together with a list of the States for which each Regional Manager has responsibility are listed below:

Region I - Boston (Connecticut, Maine, Massachusetts, New Hampshire, Rhode Island, Vermont)
Peter Chan, Regional Manager
Office for Civil Rights
U.S. Department of Health and Human Services
Government Center
J.F. Kennedy Federal Building - Room 1875
Boston, MA 02203
Voice phone(617)565-1340
FAX (617)565-3809
TDD (617)565-1343

Region II - New York (New Jersey, New York, Puerto Rico, Virgin Islands)
Michael Carter, Regional Manager
Office for Civil Rights
U.S. Department of Health and Human Services
Jacob Javits Federal Building
26 Federal Plaza - Suite 3312
New York, NY 10278
Voice Phone (212)264-3313
FAX (212)264-3039
TDD (212)264-2355

Region III - Philadelphia (Delaware, District of Columbia, Maryland, Pennsylvania, Virginia, West Virginia)
Paul Cushing, Regional Manager
Office for Civil Rights
U.S. Department of Health and Human Services
150 S. Independence Mall West
Suite 372, Public Ledger Building
Philadelphia, PA 19106-9111
Main Line (215)861-4441
Hotline (800) 368-1019
FAX (215)861-4431
TDD (215)861-4440

Region IV - Atlanta (Alabama, Florida, Georgia, Kentucky, Mississippi, North Carolina, South Carolina, Tennessee)
Roosevelt Freeman, Regional Manager
Office for Civil Rights
U.S. Department of Health and Human Services
Atlanta Federal Center, Suite 3B70
61 Forsyth Street, S.W.
Atlanta, GA 30303-8909
Voice Phone (404)562-7886
FAX (404)562-7881
TDD (404)331-2867

Region V - Chicago (Illinois, Indiana, Michigan, Minnesota, Ohio, Wisconsin)
Valerie Morgan-Alston, Regional Manager
Office for Civil Rights
U.S. Department of Health and Human Services
233 N. Michigan Ave., Suite 240
Chicago, IL 60601
Voice Phone (312)886-2359
FAX (312)886-1807
TDD (312)353-5693

Region VI - Dallas (Arkansas, Louisiana, New Mexico, Oklahoma, Texas)
Ralph Rouse, Regional Manager
Office for Civil Rights
U.S. Department of Health and Human Services
1301 Young Street, Suite 1169
Dallas, TX 75202
Voice Phone (214)767-4056
FAX (214)767-0432
TDD (214)767-8940

Region VII - Kansas City (Iowa, Kansas, Missouri, Nebraska)
Frank Campbell, Regional Manager
Office for Civil Rights
U.S. Department of Health and Human Services
601 East 12th Street - Room 248
Kansas City, MO 64106
Voice Phone (816)426-7277
FAX (816)426-3686
TDD (816)426-7065

Region VIII - Denver (Colorado, Montana, North Dakota, South Dakota, Utah, Wyoming)
Velveta Howell, Regional Manager
Office for Civil Rights
U.S. Department of Health and Human Services
1961 Stout Street -- Room 1426 FOB
Denver, CO 80294-3538
Voice Phone (303)844-2024
FAX (303)844-2025
TDD (303)844-3439

Region IX - San Francisco (American Samoa, Arizona, California, Guam, Hawaii, Nevada)
Michael Kruley, Regional Manager
Office for Civil Rights
U.S. Department of Health and Human Services
90 7th Street, Suite 4-100
San Francisco, CA 94103
Voice Phone (415)437-8310
FAX (415)437-8329
TDD (415)437-8311

Region X - Seattle(Alaska, Idaho, Oregon, Washington)
Linda Yuu Connor, Regional Manager
Office for Civil Rights
U.S. Department of Health and Human Services
2201 Sixth Avenue - M/S: RX-11
Seattle, WA 98121-1831
Voice Phone (206)615-2290
FAX (206)615-2297
TDD (206)615-2296

HIPAA Security Rule Enforcement Delegated to OCR

Today HHS Secretary Kathleen Sebelius announced that enforcement of the Security Rule under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) will be delegated to the Office for Civil Rights (OCR).

The official delegation occurred on July 27, 2009. More information about the transition of authority for the administration and enforcement of the Security Rule can be found in the OCR press release. The official Delegation of Authority by the Office of the Secretary has been issued and will appear in the August 4, 2009 Federal Register.

Prior to today, administration and enforcement of the HIPAA Security Rule has been the responsibility of the Centers for Medicare & Medicaid Services (CMS).

Providence Health & Services Agrees To $100,000 Voluntary Settlement of Potential HIPAA Violation

The U.S. Department of Health and Human Services (HHS) issued a press release last Thursday that it had entered into a Resolution Agreement with Seattle-based Providence Heath & ServicesHealth Insurance Portability and Accountability Act of 1996 (HIPAA) privacy and security rules. The agreement calls for Providence to pay a voluntary settlement of $100,000 and implement a detailed corrective action plan to ensure against future theft or loss of electronic patient health information (ePHI).

The incidents giving rise to the agreement involved two Providence entities, Providence Home and Community Services and Providence Hospice and Home Care. On or about December 30, 2005, data contained on several computer backup disks and tapes was stolen from the unattended car of a Providence employee. In addition to the theft of disks and tapes, several laptop computers were stolen from Providence employees on September 29, 2005, December 7, 2005, February 27, 2006, and March 3, 2006. The laptops, disks and tapes involved in those thefts contained the unencrypted records of more than 386,000 patients of Providence.

Under the terms of the Resolution Agreement, Providence agrees to pay $100,000 by check or electronic funds to HHS. Providence also agrees to enter into and abide by the terms of the Corrective Action Plan that is incorporated into the agreement. The Corrective Action Plan is effective for three years and requires that Providence submit copies of its written policies and procedures to HHS for approval. The Corrective Action Plan outlines nine categories of minimum content required in the policies and procedures. Specifically, the Corrective Action Plan requires that Providence to:
  • Conduct a risk assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI when it is created, received, maintained, used or transmitted off-site;
  • Implement a risk management plan that incorporates security measures sufficient to reduce the risks and vulnerabilities identified by the risk assessment to a reasonable and appropriate level; and
  • Implement several physical and technical safeguards, including encryption, to ensure the protection of ePHI whenever it is stored or transported off-site by any portable device or electronic media.
The Corrective Action Plan also requires Providence train and monitor its workforce so that all employees are familiar with the policies and procedures. Providence is also required to submit to HHS both a one-time Implementation Report and Annual Reports for three years detailing its compliance to the policies and procedures under the Resolution Agreement.

Initially, HHS officials received more than 30 complaints about the stolen tapes and disks after Providence, pursuant to state notification laws, informed patients of theft. Providence also reported the stolen media to HHS. Providence faced a pending class action lawsuit alleging that the health system failed to safeguard the data as required by HIPAA and violated Oregon’s Unfair Trade Practices Act. The proposed class action was dismissed in November, 2007. The incident was also investigated by the Oregon Attorney General’s Office resulting in an Assurance of Voluntary Compliance Agreement requiring Providence to provide credit monitoring services, credit restoration services, implement security program enhancements and pay $95,764 into the Consumer Protection and Education Revolving Account.

Providence settlement and corrective action plan sends a signal that OCR and CMS are taking a stronger position against privacy and security incidents. The settlement should prompt providers who are required to comply with HIPAA to reexamine their privacy and security policies, procedures, employee training protocols and ongoing monitoring of compliance.

Ohio Court Creates New Tort For Unauthorized Dislcosure of Medical Information

The Ohio Supreme Court issued a recent decision in Hageman v. Southwest General Health Center, et al. Slip Opinion No. 2008-Ohio-3343 (July 9, 2008), holding that an attorney's unauthorized disclosure of medical information obtained during litigation in a separate proceeding could be the basis of a tort claim. The decision in Hageman has implications regarding the waiver of confidentiality and the secondary release of medical information under a standard HIPAA compliant authorization.

The Court in Hageman held:
With these considerations in mind, we hold that when the cloak of confidentiality that applies to medical records is waived for the purposes of litigation, the waiver is limited to that case. An attorney can certainly use medical records obtained lawfully through the discovery process for the purposes of the case at hand—e.g., submitting them to expert witnesses for analysis or introducing them at trial. However, an attorney may be liable to an opposing party for the unauthorized disclosure of that party’s medical information that was obtained through litigation. Thus, as in our decision in Biddle, we conclude that an independent tort exists to provide an injured individual with a remedy for such an action.
In ruling the Court in Hageman ooked to the Court's prior decision in Biddle v. Warren General Hospital, 86 Ohio St.3d 395, 715 N.E. 518 (1999), where the Court found a separate tort for breach of privacy and confidentiality related to medical records.

The Court in Biddle made the following findings:
1. In Ohio, an independent tort exists for the unauthorized, unprivileged disclosure to a third party of nonpublic medical information that a physician or hospital has learned within a physician-patient relationship.

2. In the absence of prior authorization, a physician or hospital is privileged to disclose otherwise confidential medical information in those special situations where disclosure is made in accordance with a statutory mandate or common-law duty, or where disclosure is necessary to protect or further a countervailing interest that outweighs the patient’s interest in confidentiality.

3. A third party can be held liable for inducing the unauthorized, unprivileged disclosure of nonpublic medical information that a physician or hospital has learned within a physician-patient relationship. To establish liability the plaintiff must prove that (1) the defendant knew or reasonably should have known of the existence of the physician-patient relationship, (2) the defendant intended to induce the physician to disclose information about the patient or the defendant reasonably should have anticipated that his actions would induce the physician to disclose such information, and (3) the defendant did not reasonably believe that the physician could disclose that information to the defendant without violating the duty of confidentiality
that the physician owed the patient.


MD Net Guide Article: Are Physician Blogs in a Legal and Ethical Twilight Zone?

Last month I had the opportunity to collaborate with Fard Johnmar of Envision Solutions on an article for MD Net Guide, "Social Media Notebook: Are Physician Blogs in a Legal and Ethical Twilight Zone?" The article looks at the recent incident involving Dr. Lindeman, who blogged under the pseudonym "Flea," and the risks associated with physician blogging.

I shared some legal tips that physician bloggers should consider when blogging, including:
  • Anonymous blogging does not guarantee your privacy
  • Consider informing your employer about your blog
  • Follow your HIPAA training
  • Post a legal disclaimer
  • Be cautious about giving advice to patients
Check out the current issue of MD Net Guide to read the complete article. Also, the complete article, "Social Media Notebook: Are Physician Blogs in a Legal and Ethical Twilight Zone?" can be accessed via the web (registration required).

University of California Settles Potential HIPAA Privacy and Security Violations with OCR for $865,500

The U.S. Department of Health and Human Services, Office for Civil Rights (OCR) announced that the University of California at Los Angeles Health System which includes UCLA Ronald Reagan Medical Center, UCLA Santa Monica Medical Center, and Orthopedic Hospital, Resnick Neuropsychiatric Hospital, and the Faculty Practice Group of UCLA (UCLAHS) has agreed to settle potential violations under the HIPAA Privacy and Security Rules for $865,500. Read the OCR press release.

The settlement highlights that hospitals, physicians, and other covered entities must understand the importance of monitoring the level of access workforce members have to medical and health information. Covered entities must have policies and procedures in place and educate workforce members about only accessing records for necessary and permissible purposes. This settlement resulted from an investigation by OCR after certain celebrity/VIP patients at the UCLA facilities complained that hospital staff, including unauthorized physicians, had inappropriately accessed their health and medical information.

UCLAHS agreed to a Corrective Action Plan for a period of three years under the terms of the Resolution Agreement. The Corrective Action Plan requires UCLAHS to review/update its current HIPAA policies and procedures, conduct follow up workforce training, monitor compliance and submit a monitoring plan, and submit an implementation report and annual reports to OCR. of can be found attached to the Resolution Agreement.

The Resolution Agreement described the events that occurred that lead to the settlement as follows:
On June 5, 2009 and June 30, 2009, HHS began investigations of two separate complaints alleging that the Covered Entity was in violation of the Privacy and/or Security Rules. The investigations indicated that the following conduct occurred (“Covered Conduct”):
(i) During the period from August 31, 2005 to November 16, 2005, numerous Covered Entity workforce members repeatedly and without a permissible reason examined the electronic protected health information of Covered Entity patients, and during the period from January 31, 2008 to February 2, 2008, numerous Covered Entity workforce members repeatedly and without a permissible reason examined the electronic protected health information of a Covered Entity patient.

(ii) During the period 2005-2008, a workforce member of Covered Entity employed in the office of the Director of Nursing repeatedly and without a permissible reason examined the electronic protected health information of many patients.

(iii) During the period 2005-2008, Covered Entity did not provide and/or did not document the provision of necessary and appropriate Privacy and/or Security Rule training for all members of its workforce to carry out their function within the Covered Entity.

(iv) During the period 2005-2008, Covered Entity failed to apply appropriate sanctions and/or document sanctions on workforce members who impermissibly examined electronic protected health information.

(v) During the period from 2005-2009, Covered Entity failed to implement security measures sufficient to reduce the risks of impermissible access to electronic protected health information by unauthorized users to a reasonable and appropriate level.
 More information and background can be found in the iHealthBeat article, UCLA Health System Agrees to Pay $865K over Privacy Breaches, including a link to a statement on the settlement issued by UCLH Health System.

Sexting dos and don’ts (yep, they exist... apparently)

SextingFrom Motherboard.tv 09/06/11:

Obviously everyone knows what sexting is, but I would just like to explain it because I send these articles to my grandmother, and I don’t want to have to break down sexting to her face-to-face.

I don’t think anybody’s grandmother needs to know what sexting is. If she wants to swap X-rated polaroids with the rest of the church congregation that’s her business, but camera phones are just too much for the over 60s to cope with – particularly when there’s nakedness involved.

Basically, you take about a 100 pictures of your a*s in cute underwear and then one comes out good so you text it to a dude. ... The whole point of sexting is that as soon as the recipient gets it, they will speed over to your house for some hot sex.

As with any type of social exchange, there is a certain etiquette that needs to be followed.

Oh really?

For starters, don’t send a sext to someone who might not be down.

“not be down” ... I’ve no idea what this means.  I’m guessing it’s ‘up for it’ but I might be wrong.  Remember: I’m the chap who had to Google Andro’s use of the term “pwned” (something I still don’t fully understand) and, more recently, “fraped”.

If you want to test the waters, say something like, “do you like me? Y or N.” If they respond in a negative way, just pretend that you are drunk at a party and someone stole your phone.

Hold up: just because someone likes you, it doesn’t mean to say they want their phone polluted with an impromptu up-close-and-personal shot of your genitalia. That’s just not cricket.

When sending a picture, make sure it’s not trashy. I knew a kid whose ratty girlfriend sent him pictures of her [... you can read the rest of the this sentence over at motherboard.tv ;-) It made me chuckle. ].

Really? Can sexting ever NOT be trashy? Isn’t that part of the appeal?

Sexting is a dangerous game sometimes, but it’s always worth it. You can’t expect to get d**k pics if you don’t send out some artsy shots of your boobs strategically covered with suds during a bubble bath photo shoot.

…said the contract law lecturer to his class, trying to find a modern day example of quid pro quo in action. 

Be right back

Scoble On Google Privacy Discussion

Scoble has a good round up of the ongoing discussion about Google's ranking in the recent Privacy International Report titled, A Race to the Bottom: Privacy Ranking of Internet Service Companies and Privacy International's Open Letter to Google.

Children to be fingerprinted as part of library loan process

From The Telegraph 28/05/10:

Students in Manchester are having their thumbprints digitally transformed into electronic codes, which can then be recognised by a computer program.

Under the scheme, pupils swipe a bar code inside the book they want borrow then press their thumb on to a scanner to authorise the loan. Books are returned in the same way.

But critics said they were “appalled” at the system, developed by Microsoft which is also being trialled in other parts of the country.

“This is quite clearly appalling,” said Phil Booth, national coordinator of NO2ID, a privacy campaign group.

“For such a trivial issue as taking out of library books the taking of fingerprints is way over the top and wrong.

He added: “The money for such a system could be spent on actual school resources. How about some more books for the library instead?

Things aren’t that simple, of course. If resources are being directed at monitoring loaned books . Potentially, this system could allow for the school library loan processes to be automated to a far greater extent than they are currently.

Overall, I’d say this one isn’t quite as ludicrous as it initially appears. The idea of substituting a library card for a finger print is convenient – particularly for kids. 

"We have researched this scheme thoroughly. It is a biometric recognition system and no image of a fingerprint is ever stored. It is a voluntary system,” she said.

"The thumbprint creates a mathematical template. All parents have been written to and we have told them what the system is all about. From the responses we have had there has been overwhelming support."

If I were a parent, I don’t think I’d have an issue with this.  Moreover, children in schools all around the country are already fingerprinted as part of the payment system for school dinners.  I think NO2ID should focus on frying bigger fish quite frankly.

ONC-Coordinated Federal HIT Strategic Plan: 2008-2012

Today the Office of the National Coordinator for Health Information Technology (ONC) released "The ONC-Coordinated Federal Health Information Technology Strategic Plan: 2008-2012". Find more information here, including a synopsis of the full report.

The plan is meant to serve as a guide to coordinate the federal government's health IT efforts to achieve a nationwide implementation of an interoperable health information infrastructure.

Robert Kolondner, MD, National Coordinator for Health Information Technology states in the synopsis summary:
Looking toward the future, we can envision a health care system that is centered on each and every individual patient. Clinicians will have at their fingertips all of the information needed to provide the best care; individuals will have access to this and other information that can help them engage and insert their values in the decision-making process about their health and care; and, secure and authorized access to health data will provide new ways that biomedical research and public health can improve individual health, and the health of communities and the Nation.
The synopsis goes on to state that the plan has two goals -- "patient focused health care and population health" and describes them as follows:
Patient-focused Health Care: Enable the transformation to higher quality, more cost-efficient, patient-focused health care through electronic health information access and use by care providers, and by patients and their designees.

Population Health: Enable the appropriate, authorized, and timely access and use of electronic health information to benefit public health, biomedical research, quality improvement, and emergency preparedness.

Each goal has four objectives and the themes of privacy and security, interoperability, adoption, and collaborative governance recur across the goals, but they apply in very different ways to health care and population health.
I've only had a chance to scan the synopsis and the 115 page full report but should make for interesting reading for anyone involved in the ongoing evolution of our health care system and the impact that health technology is having on the industry.

PHRs, The Model T, Meaningful Use and the Patient-Centric HIT Revolution

There is a growing discussion on the health consumer-centric (patient-centric) meaning of "meaningful use" of EHRs and health information technology. Jane Sarasohn-Kahn summarizes this discussion in her recent post, "Meaningful USe - or, whose health is it, anyway?" at Health Populi where she reflects on Ted Eytan's post, "Is it Meaningful If Patients Can't Use It?"

Since Ted's post other health care thought leaders have offered their comments. A list of these individuals can be found in Jane's post. As Jane mentions, this topic was central to much of the discussion that occurred during the first two days of the testimony before the National Committee on Vital and Health Statistics (NCVHS) on the Future of Personal Health Records held on May 20 and 21. The discussion will continue at the NCVHS hearing on June 9 when there will be a panel focused on "Consumer Advocates and Attitudes" that will include Susannah Fox, Dave deBronkart, Deven McGraw, JD and Robert Gellman, JD.

Jane mentions in her post our testimony before the Subcommittee on Privacy, Confidentiality and Security of the National Committee on Vital and Health Statistics (NCVHS) on the future of PHRs. Our panel, including me, Jane and Daniel Weitzner, the W3C Technology and Society Policy Director, opened the hearings on PHRs. Our role as the opening panel was to try to set the stage for the context of the discussion on the future of PHRs and consumer facing health care information technology.

As the opening speaker at the hearing I decided to stay away from immediately diving into the legal issues and instead give the committee a landscape view of where I think we are in the history of health information. My goal was to provide a historic framework for PHR development by drawing some historic parallels to the history of the development of our transportation system. By analogy I compared today's PHRs to the Model T era of the automobile area and taking a page from Dave deBronkart told the committee my personal family e-health information story. Below is a complete copy of my written testimony submitted to the committee.

As the discussion continues on "meaningful use" the role that PHRs play is important. Focusing on health care consumers and their practical use of PHR tools is vital to the future of our health care system. As I said in my testimony there will be game changers but we need to see the potential of today's Model T PHRs and build toward the Prius Hybrid PHRs of the future.


Prepared Statement for Subcommittee on Privacy, Confidentiality, and Security National Committee on Vital and Health Statistics (NCVHS)

Discussion on the Future of Personal Health Records

Good morning. I want to thank the Co-Chairs, Subcommittee and Committee Staff for the opportunity to participate in today’s discussion on the current state of the personal health record (PHR) and the future use of this and other health care technology tools by the health care industry and the health care consumer.

My name is Bob Coffield. I am a health care attorney from Charleston, West Virginia, with the law firm of Flaherty, Sensabaugh & Bonasso, PLLC. I have a broad-based health care practice, providing legal and business services to a variety of health care clients. A large portion of my practice focuses around health information issues, regulatory compliance, privacy, security, and health technology. Over the past five years, I have become involved in the social media movement, and that involvement has changed the way I live, work, collaborate and communicate. My involvement and interest in the social media movement and its impact on our lives has led me to focus a portion of my practice on legal concepts and issues generated by the use of social media tools and technologies in health care, law and other industries.

Introduction: Today’s PHR is the Model T

As the opening speaker, I want to set the stage for today’s discussion on the questions raised by the committee. As the committee examines the issues, I recommend that you look toward a longer horizon of 20 to 50 years. In this age of information and accelerating technology, it is often easier to predict what may happen in 50 years than what will happen next year. As information technology advances and new technologies are developed, it has become more difficult to conduct short-term strategic planning in the three to five-year range. Over the past 10 years of the maturing information era, we have seen incredible advances and significant disruption in all business, including health care.

At its center, the information age is characterized by the ability to create and transfer information and knowledge freely and to have instant access to knowledge that would have been impossible, difficult or too expensive to find in the past. Jane Sarasohn-Kahn and others today will provide the Committee with an understanding of the current health care consumer marketplace and the major motivators driving health care consumer empowerment in the information age, and also will provide a perspective on the current state of consumer engagement in health care. It is my belief that this changing era is having a profound impact on today’s health care industry. The strategies, systems, approaches and governing rules used today and by past generations may not be successful in today’s and tomorrow’s changing information era.

A part of today’s process should be to consider what the long-term goals are for health information technology, including the PHR, and how it can be used to drive consumer-focused and controlled health care in the information age. Along with this discussion, we have a responsibility to talk about why involvement of the consumer matters and what impact it will have on improving care, reducing costs and creating efficiencies in the health care system.

As we discuss health information technology and PHRs today, we have a responsibility to stay focused on this question: “What will improve the quality of care for you and me, as consumers of health care?” This single question needs to remain at the center of today’s discussion and the continuing debate on consumer health information technology. As the health care industry becomes more and more specialized, complex and technologically advanced, we often lose sight of the purpose of the health care system. That purpose is human care and compassion. You and I, as health care consumers, must remain at the center. My hope is that the future of our health care system will use technology, including PHRs, to improve the human experience and interaction between the professional caregiver and health care consumer.

The questions I often struggle with and hope to hear discussion on today are: How will PHRs drive consumer empowerment, and how will this consumer empowerment lead to improving care? We can all sit around and discuss the best ways to build PHRs, but the questions remain whether or not the health care consumer will be attracted to use PHRs and whether providers will be willing to incorporate PHRs into the treatment and care process.

As I said at the opening of my remarks, I want to set the stage for the discussion and testimony today by sharing a story and painting a historical perspective. As I looked over the agenda of those speaking today, I was struck by the level of experience and diverse backgrounds that each of us brings to the discussion. However, because of the level of specialization represented in this gathering, there is the risk of remaining deep in the weeds, dealing with details, and failing to step back and take a wider view of the landscape. The story and analogy I want to share with you is my attempt to take you on a tour of that broader view.

I am a believer in the adage that history repeats itself. What we are trying to do today is to provide you with a perspective and prediction of the role that the PHR will (should) play in the health information technology infrastructure over the next 10 years. So a historical sketch of where we have been and where we are is valuable to the discussion of where we may go.

I want to start the story with a quote from the 1800s, by inventor Oliver Evans, as he spoke about the future of the transportation system in the United States.
"The time will come when people will travel in stages moved by steam engines from one city to another, almost as fast as birds can fly, 15 or 20 miles an hour . . .

A carriage will start from Washington in the morning, the passengers will breakfast at Baltimore, dine at Philadelphia and supper in New York the same day . . . .
The 1800’s saw the dawn of the railroad system in the United States, as a result of the development of the steam engine. These developments led to the widespread use of trains as a mode of transportation for a growing population that, until that time, had been relatively immobile. The growth of the railroad system started at the local level, grew to regional connections and ultimately led to a national network of railroad tracks from east to west and from north to south. Prior to this time, personal travel required one to travel on foot, by horse or by carriage.

My ancestors, who grew up in the hills of northern West Virginia, came to West Virginia (then Virginia) in the late 1700’s. As we say in West Virginia, “they lived out on the ridge.” A number of generations went by, and there was little mobility of my family. They lived out their lives on those same ridges for well over 150 years. They raised their families and farmed. They lived a relatively isolated and stationary life. Traveling beyond a few miles was difficult, impractical and largely unnecessary, at least from their perspective of the world.

However, by 1900, the landscape had changed, and the Industrial Revolution was having a profound impact on the world. My great-grandfather and grandmother had two sons who were teens in the 1890s. In the 1890s, my great-uncle went to college, came back and taught school for a few years and then went on to law school. Likewise, my grandfather went to college, came home like his brother to teach school for a few years, and then continued on to medical school in Cincinnati, Ohio – at that time a long distance from the northern part of West Virginia. He came back and practiced medicine in Wetzel County, West Virginia, from 1911 until his death in 1936. He saw home patients initially by horseback, and then in 1915, he traveled to Pittsburgh, Pennsylvania by train to pick up a brand new Ford Model T, which replaced his horse in his rural medical practice.

As the rail system in the United States matured, it grew into a more complex mass transportation system. Individuals who, prior to that time, had used their own modes of transportation, whether on foot, by horse or carriage, started to rely upon the system for transportation. They became passengers who didn’t own the train or the rails. As the railroad system developed, we saw issues related to standards, such as the gauge of tracks. Local, state and federal government become involved in furthering the growth and expansion of the railroad system by providing financial support, political influence and regulatory assistance to the growing railroad industry.

At that stage in history, no one in the powerful railroad industry would have predicted the disruptive influence by a young, different type of engineer - Henry Ford. With the advent of the automobile and the mass production of the Model T in 1908, our transportation system in the United States was forever changed. Over the next 20 years, the adoption of automobile travel was unprecedented. This revolution led to a demand for better roadways and improvement of the largely privately built turnpike roads. The Federal Highway Act of 1921 authorized the Bureau of Public Roads to provide public funding to help state highway agencies construct paved systems of highways, and this led to the Federal-Aid Highway Act of 1956, which authorized the creation of the Interstate Highway System.

By analogy, we can compare the development of the transportation system to the development of today’s health information system and draw many comparisons and parallels. The health information system, up through the 1950’s and 1960’s, was paper-based, centrally located and uncomplicated. The medical record system for my grandfather’s practice – to the extent that it was used – was simple. Likewise, the medical record system and documentation used by my father and uncle during their medical careers, roughly 1940-2000, was relatively non-complex. During this time, there was little specialization: Physicians were generalists in everything. In large part, physicians from this era cared for their patients from birth to death and, in the case of my grandfather, father, and uncle, cared for multiple generations of families. Providers during that time had a relatively comprehensive picture of the medical history of each individual, as well as that individual’s immediate and collateral family members. Prior to specialization in health care, we had a health system focused on the individual patient, and health information was centered on that individual and the individual’s family.

By the 1970’s, we saw the development of the first electronic health record – the problem-oriented medical record (POMR), predecessor of today’s current Electronic Health Records (EHR) and Electronic Medical Records (EMR). At this same time, we saw the expansion of medical litigation, which has played a significant role in the health information system over the past 30 years.

Prior to 2000, little had been written or heard about PHRs. Back in 2001, in a report called Strategy for Building a National Health Information Infrastructure, the National Committee on Vital and Health Statistics mentions PHRs and the growing consumer use of Internet-based health information services. This was important because it was the first time that a national health body acknowledged or officially recognized PHRs. In 2005, the American Health Information Management Association (AHIMA) formed a work group to examine the role of PHRs in relation to EHRs, and the pace and interest in PHRs has continued to increase since that time.

Over the last year, interest and activity in the development and use of PHRs has accelerated. This new-found interest has now culminated in the first law directly regulating PHRs and PHR vendors, under the Health Information Technology for Economic and Clinical Health Act (HITECH), which is a part of the American Recovery and Reinvestment Act of 2009, signed into law on February 17, 2009.

How is the history of our transportation system analogous to our health information system? On a basic level, both provide transportation – one transported humans, and the other, human information. Both started as uncomplicated systems that were not interconnected. I imagine you are already formulating other parallel points between these two systems.

To begin today’s discussion on PHRs, we need to examine where PHRs fit in this historical perspective and timeline. What is the equivalent of the PHR in the history of our transportation system? Today’s PHR is the equivalent of the Ford Model T. The PHR will be the vehicle to individually transport health information in the future, introduce the involvement of consumers in their own health information and wellness and inspire a time of innovation and creativeness over the next five to 10 years. If the age of the PHR takes off, it will bring about a wholesale change in the way that health information technology is structured and will radically disrupt traditional health care industry models.

There are various other analogies to be drawn between the two historical perspectives. For example, do the trains and the rail system represent the traditional health care providers and payors in the industry who are maintaining data in silos and segregated systems? Can we draw comparisons between the powerful railroad industry versus the nascent auto industry and the current health care and insurance industry and the emerging Health 2.0 technology movement? Are the disagreements that occurred in the railroad industry over the gauge of railroad tracks analogous to the debate occurring over the need and process to develop standards for health information technology? Can we draw parallels between our country’s development of a national network of railroads through local, state, and federal initiatives to those ongoing efforts by state health information exchanges (HIEs), regional health information organizations (RHIOs) and the national health informational network (NHIN)? Will there be similarities between the freedom that consumers felt the first time they bought an automobile and drove it down the road and the feeling of empowerment experienced when a health care consumer adopts and uses a PHR? In the coming years, will the connecting of EHR and EMR systems and the development of the NHIN be relegated to being used to transfer bulk health data, not unlike the role that the railroad system plays today?

As we look toward the future of PHRs, we have to understand that we are now looking at the Model T stage of PHRs: Call it PHR 1.0. The PHRs of the past 10 years and, in large part, the PHRs of today, are still relatively rudimentary and impractical, not unlike the first automobiles. I suspect my grandfather’s experience of traveling to Pittsburgh by train, having never owned a car before, to pick up his new Ford Model T and drive it back into the hills of West Virginia, was not unlike Dave deBronkart’s experience when he set up his Google Health account and imported his own health information from his providers. Prior to their experiences, neither knew how to drive the vehicle, but they learned in the parking lot. Once they both bought into the product, they didn’t have any good roads to drive on, and when the vehicle broke down they had to fix it themselves. However, through their efforts the world began to change, and their lives were and will be forever changed.

Over the next five to 10 years, and probably longer, we may see PHRs become the multi-colored, sleek-designed, more powerful automobiles, analogous to the golden era of the automobile industry from 1940 to 1950. Continuously over that time period, new personal options will be developed as add-ons to the PHR. As PHR adoption grows, we will have to develop larger, longer and more robust highway systems to allow for the transfer of health data by and between PHRs. Likewise, new standards will come into existence, not unlike those adopted by industry or those created by government. Safety features also will be developed continuously to protect and secure the health information maintained, stored and transferred through PHRs. Think of these as the modern-day innovation, adoption and enforcement of traffic signals, the use of seat belts and requirement for guard rails.

As we look toward the future, we also have to be aware that there will be game changers that we can’t envision at this time. Although PHRs might now be the industry solution to change the way we aggregate and store health information, new technology may be invented that disrupts this strategy and approach. For example, consider the impact that air travel had on the automobile industry. We must remain open to change in this new information era – change will be the norm and not the exception.

Using PHRs to Transform the Health Care Industry

The efforts by large technology companies and other Health 2.0 technology companies could transform the health care industry by triggering advancements in health information technology and laying the groundwork for overall health care delivery and payment reform. Although it is too early to say whether the PHR, in fact, will be the catalyst for health care reform, the Committee, government and the larger health care industry and community need to understand and explore PHRs and their role and consider how the consumer-focused PHR revolution will impact the health industry.

A convergence of factors could cause a comprehensive shift in the way health information is stored and used. Innovations in health information management technology are altering the way that patients, health care providers and payers maintain, use, control, and disclose health information. Through such technology, the current, decentralized system of records maintained by multiple providers and entities at multiple locations – often with conflicting and duplicative information – is being transformed into a centralized record maintenance system that may rely on personal health information networks (PHIN), where the PHR serves as the central repository for health information shared through a system of developing regional or national health information exchanges. Vince Kuraitis of the e-CareManagement Blog calls this change a “transformation from Industrial Age medicine to Information Age health care.”[1]

This transformation in the way information is maintained, stored, and exchanged empowers the health care consumer by offering a new level of control and responsibility over his or her care. It will directly impact the patient-provider relationship.

The traditional model for maintaining medical records, in which the provider of care stores, maintains, and updates the record, is based upon the need to provide continuity of care. The medical record reflects the plan of care, documents the care provided, and records communications among providers. Also, the medical record assists in protecting the legal rights and interests of both consumers and providers.

In the 21st century, our health care system simultaneously has become more fragmented and specialized, on one hand, and more coordinated and wellness-focused, on the other. Health care consumers have become mobile and now seek the services from a variety of providers engaging in numerous specialties. These same consumers change providers on a regular basis and take advantage of new models of care, like urgent care services, to complement traditional primary care services. The increasingly mobile population has caused breakdowns in continuity of care. As individuals move from city to city and state to state, they leave behind a trail of partial medical records – some on paper, some electronic – with various providers, insurers, and others.

The increasing popularity of EMRs, EHRs, RHIOs, and HIEs signals a need to address the increasing complexity of maintaining and sharing these different types and silos of health information. The PHR may be the disruptive technology that provides a simple alternative to ongoing efforts to create an interconnected network of interoperable health information systems with detailed querying functions, capable of making accessible in one place the health information and continuity of care record for individual consumers. In contrast, PHRs would travel with health care consumers and provide a central location for information regarding the consumers’ individualized needs.

Ownership of Health Information

The shift to a consumer-controlled PHR from a provider-based and controlled medical record raises traditional property law issues. As health information becomes increasingly networked and technology permits health information to be transferred more easily, the lines demarcating ownership of health information become further blurred.

Health information is often viewed under the traditional notion of property as a “bundle of rights,” including the right to use, dispose, and exclude others from using. This legal application of historic property law may not be well-suited to the information age, in which patient information is shared through a variety of formats, copied, duplicated, merged, and combined with other patient records into large scale databases of highly valuable information.

Who owns health information? The physician? The insurer? The health care consumer? Under the traditional theory, providers own the medical records they maintain, subject to the consumer’s rights of access in the information contained in the record.[2] This tradition stems from the era of paper records, where physical control meant control and ownership. Provider ownership of the record is not absolute, however; HIPAA and most state laws provide consumers with some right to access and receive a copy of the record. Health care consumers have received other rights out of the bundle of property rights, including the right to request corrections to their medical information and the assurance that such records are maintained confidentially.

The PHR model, where all records are centrally located and maintained by the consumer, flips and realigns the current provider-based ownership model of managing health information. Instead of provider-based control, where the provider furnishes access to and/or copies of the record and is required to seek patient authorization to release medical information, the PHR model puts the health care consumer in control of his or her medical and health information.

[1] Vince Kuraitis, E-CareManagement Blog, Birth Announcement: the Personal Health Information Network, March 8, 2008, http://e-caremanagement.com/birth-announcement-the-personal-health-information-network-phin/.

[2] Alcantara, Oscar L. and Waller, Adelle, Ownership of Health Information in the Information Age, originally published in Journal of the AHIMA, March 30, 1998; http://www.goldbergkohn.com/news-publications-57.html.

HIPAA Privacy Rule Accounting of Disclosures under HITECH

Today's Federal Register includes the Office of Civil Rights (OCR) Notice of Proposed Rulemaking (NPRM) modifying the HIPAA Privacy Rule's Accounting of Disclosure requirements for protected health information. OCR was required to make these modifications to the HIPAA Privacy Rule to implement the requirements under the Health Information Technology for Economic and Clinical Health Act (HITECH) section of the ARRA.
HIPAA Privacy Rule Accounting of Disclosures Under the Health Information Technology for Economic and Clinical Health Act, Office for Civil Rights, Notice of Proposed Rulemaking (76 FR 31426, May 31, 2011)
The regulations greatly expand the responsibility for health care covered entities and business associates to document and track the use and disclosure of health information held in an electronic health record (EHR). Health care providers and business associates should plan to thoroughly review these new regulations to understand the impact on their existing policies and procedures.

The regulations outline new procedures for accounting of disclosures of health information held in an electronic health record and disclosed for treatment, payment, and health care operations (as defined under HIPAA). The accounting period under the proposed regulations is three years. The proposed regulations focus on two rights for individuals -- a right to an accounting of disclosure and a "new" right to an access report. The new access report does not distinguish between a use (think internal use by a health care provider) and disclosure (providing the information to a third party). Instead the new right to an access report focuses on whether someone "accessed" the information in the EHR.

Previously under HIPAA, uses and disclosures for treatment, payment, and health care operations (commonly referred to as "TPO") were exempt from the accounting of disclosures requirements. The requirement for accounting for some limited uses and disclosures has always been a part of the HIPAA Privacy Rule.

The rule proposes separate compliance dates for the changes to the accounting of disclosures requirements (180 days after the effective date of the final rule - 240 days after publication of the final rule) and for the right to receive an access report (beginning January 1, 2013, for any EHR system acquired after January 1, 2009 and January 1, 2014, for any EHR system acquired on or before January 1, 2009).

My initial comments above are based upon a quick review of the proposed regulations. Official comments on the NPRM must be submitted on or before August 1, 2011.

Modern Day Hatfield-McCoy: Google Health and Microsoft HealthVault

The Hatfields and McCoys, a metaphor for a modern day high-tech industry rivalry centered on personal health records (PHRs) involving Google Health, Microsoft HealthVault and other PHR vendors. An image that a West Virginia health care lawyer can really appreciate.

Thanks to a tweet by @2healthguru for pointing out the CNET article, Microsoft, Google in healthy competition. The article provides a good overview of the developing PHR movement and some insight into the future. However, I'm a bit concerned by the accuracy of the article when I see two of the individuals mentioned in the article (Matthew Holt and Dave deBronkart) tweeting (here and here) that they weren't really interviewed for the article.

Later this week I will be in D.C.along with others testifying at the Hearing on Personal Health Records before the National Committee on Vital and Health Statistics (NCVHS), Subcommittee on Privacy, Confidentiality and Security . The Subcommittee is looking at the future of the PHR marketplace and consumer-facing health information technology.

The story of the Hatfield-McCoy feud is woven into the fabric of southern West Virginia lore along the Tug River and well known by all West Virginians. Above is a photo of the West Virginia Hatfield clan around 1897, led by Devil Anse Hatfield, second from the left. For more history and photos check out the West Virginia Division of Culture and History.

Note: If you are into off-road vehicle trails, come visit West Virginia and check out the modern day version -- the Hatfield-McCoy Trails.

New HHS HIPAA Privacy Compliance and Enforcement Data

DHHS and the Office for Civil Rights (OCR) have added new enforcement statistics and data to the OCR HIPAA Privacy and Compliance and Enforcement site. Previously, I've posted about the statistics.

OCR added new information broken down by the following topics:
The statistics show that the number of complaints made to OCR continue to increase -- from 6,534 complaints in 2004 to 8,132 complaints in 2007.

Also, the statistics show that the top 5 types of complaints requiring corrective action have remained fairly consistent - except in 2007 "notice" jumps into the top 5.

I would be interested to hear others thoughts on the compliance statistics.

HITECH Final Regulations Update: Coming Soon!

Susan McAndrew, deputy director for health information privacy at the Office for Civil Rights (OCR) indicated this week that various final regulations modifying the HIPAA privacy and security rules required by the Health Information Technology for Economic and Clinical Health Act (HITECH) will be issued soon. Health lawyers have been waiting on these regulations to better understand the full impact of the HITECH changes to HIPAA, including whether the "harm standard" will remain a part of the Interim Final Rule on breach notification.

According to a Health Information Security News article, McAndrew made this announcement this week while speaking at the 2011 NIST HIPAA Conference, Safeguarding Health Information: Building Assurance through HIPAA Security, held in Washington.

The article also indicated that a separate NPRM will be issued announcing the approach OCR plans to take regarding the accounting for disclosure modifications under the HITECH Act. The HITECH Act modified the traditional rule regarding those types of uses and disclosures that must be accounted for by health care providers and covered entities. Under the traditional rule -- health care providers did not have to provide an accounting of disclosure for uses and disclosures for treatment, payment, and health care operations. However, the modification by the HITECH Act now requires health care providers who utilize an electronic health record system (EHR)to provide, upon request, an accounting of disclosure of all uses and disclosures including those for treatment, payment, and health care operations which occurred within the last three year period. Of further interest will be how the NPRM suggests how business associates who obtain PHI from health care providers must also track and maintain a list of uses and disclosures for accounting of disclosure requests.

Virginia Department of Health Professions Breach: Extortion Demand Regarding 8M Patient Records and 35M Prescriptions

Information Week is covering a story involving an extortion letter sent last week to the Virginia Department of Health Professions seeking $10M to return more than 8M patient records and 35M prescriptions allegedly stolen from the Virginia Department of Health Professions.

The extortion demand was posted on WikiLeaks. The WikiLeaks website states:

May 3, 2009
Summary
On Thursday, April 30, the secure site for the Virginia Prescription Monitoring Program (PMP) was replaced with a $US10M ransom demand:
"I have your shit! In *my* possession, right now, are 8,257,378 patient records and a total of 35,548,087 prescriptions. Also, I made an encrypted backup and deleted the original. Unfortunately for Virginia, their backups seem to have gone missing, too. Uhoh :(For $10 million, I will gladly send along the password."
The site, https://www.pmp.dhp.virginia.gov/pmpwebcenter/login.aspx appears to have been entirely disabled and is presently unavailable.
The linked file provides the full ransom message.
The PMP is used by pharmacists and others to discover prescription drug abuse.
The PMP declined to comment, although when contacted, appeared to be aware of the issue, instantly referring inquiries to the director of the DHP, who is presently unavailable.

The Virginia Department of Health Professions website indicates that they are "currently experiencing technical difficulties which affet computerand email systems."

Sandra Whitely Ryals, Director of Virginia Department of Health Professionals, responded to the inquiry by Information Week stating that "a criminal investigation is under way by federal and state authorities."

The Washington Post Security Fix blog is also covering this story. Follow more news on this story via Google News.


UPDATE (5/5/09):
At the bottom of his follow up post, John Chilmark asks the question: "Now the question is, under HIPAA, does the VDHP have to send out breach notifications to all consumers whose records have been compromised?

Here is my quick assessment. The HIPAA privacy rule (pre-ARRA HITECH) does not contain provisions that require a covered entity to notify individuals impacted by an alleged breach. However, when I have assisted clients with these types of data breach situations in the past I typically discuss with the client whether it is good practice to provide notification. The HIPAA privacy rule provisions do contain a requirement that a covered entity should mitigate potential harm to patients/individuals when there is a violation of the privacy rule. My interpretation is that this might, under certain circumstances, include providing notice to such individuals whose data has been compromised. Also, a question that factors into the equation is whether or not the Virginia Department of Health Professsions qualifies as either a covered entity or business associate under the HIPAA privacy rule. Handling these situations are very fact specific and depend upon a number of factors.

The new federal breach notification requirements contained in the HITECH section of the American Recovery and Reinvestment Act (ARRA) do not apply because the provisions do not go into effect until 30 days after the Department of Health and Human Services (HHS) publishes the interim final data breach notification regulations which has not yet occurred. The new federal breach notification law will be implemented in conjunction with the Federal Trade Commission's (FTC) proposed health breach notification rule that will apply to PHRs, PHR related vendors and other third party providers. The proposed rule is currently out for comment.

The regulations are currently in the works and HHS has now issued initial guidance on what data is classified as unsecured protected health information (not secured by technology that renders it "unusable, unreadable or indecipherable"). See the April 27, 2009 guidance for more on what this means. The guidance outlines the types of technologies that, if used, create a safe harbor for HIPAA privacy covered entities adn business associates to avoid having to provide notice in a situation where there has been a breach.

Also, the VDHP will likely have to assess the Virginia Data Breach Act (state-by-state survey of state breach laws by the National Conference of State Legislatures) to see whether notification or other action is required under state law.Over 40 states now have distinct state laws governing breach notification that extend to and cover everything from traditional personal information (name, social security number, etc.) to health related information. I've not dealt nor reviewed the Virginia Act but suspect a strong likelihood that notification will be required.

UPDATE (5/6/09): The Roanoke Times provides an update on the status of the pending investigation with comments from Governor Tim Kaine. The article states:
Gov. Tim Kaine said today that a hacker’s reported access to patient prescription records from a state database was “an intentional criminal act against the commonwealth by somebody who was trying to harm others” . . .

The FBI and the Virginia State Police are investigating the matter. Kaine said he could not discuss the probe.

“Right now our goal is to make sure that the investigation and criminal process works so that the person who is responsible is caught and prosecuted . . . and that we protect people whose data has been compromised,” Kaine said this morning.

The article also indicates that under Virginia law notification is required and that Virginia's breach notification law requires, like many state laws, that notice must be provided "without unreasonable delay."
The article also indicates that Virginia law requires notification of individuals whose personal information may have been accessed due to a computer security breach. The law states that notification must be provided “without unreasonable delay.”

New privacy laws come into force in the US at midnight

January 1 is a convenient time to bring new laws into effect. It seems like only two years ago that PIPEDA came fully into force for those of us in Canada. (And almost two years since this blog came into being.) The Associated Press has a summary of new US state laws, some of which are in reaction to the high-profile privacy breaches of the last year. Check it out:

New Year Brings Array of New State Laws - Yahoo! News

...This year, several states will take action to guard against the theft and misuse of personal information as more and more commerce moves to the Internet; several companies admitted in 2005 that hackers got into their supposedly secure databases. New Jersey and Virginia will bar making public a person's Social Security number, while Minnesota will require businesses that hold such information to quickly notify clients if there is a breach of security.

David Canton's PIPEDA predictions for 2006

David Canton, in his regular London Free Press Column, is making a few predictions for 2006. He leads off his column with predictions about privacy in Canada:

London Free Press - Business - Expect PIPEDA debates

The Personal Information Protection and Electronic Documents Act (PIPEDA) is slated for review in 2006. Expect to debate to rage on controversial issues such as whether individuals should be notified if their personal information is compromised.

Another issue is processing data outside Canada, common in a connected world. It raises issues regarding the ability of foreign governments to view our personal information -- without our knowledge, without judicial oversight, and despite contractual arrangements to the contrary.

A privacy issue that may come before the privacy commissioner is the printing of full credit or debit card numbers on receipts. This matter has not been the focus of a complaint to the privacy commissioner's office.

Many privacy commentators, myself included, believe that putting full credit or debit card numbers on either the customer's or the company's copy of a receipt is a violation of PIPEDA. The printing of those numbers serves no purpose and increases the risks of fraud.

Single Government ID Moves Closer to Reality

Further to my earlier posting on the new US Government identity verification project (PIPEDA and Canadian Privacy Law: US Government developing standard for positive identification), the Washington Post is carrying an article that comments, among other things, on privacy objections to the new standard:

Single Government ID Moves Closer to Reality:

"....Some federal employees have concerns about the new cards.

Colleen M. Kelley, president of the National Treasury Employees Union, which represents more than 150,000 federal workers in 30 agencies, said the proposed standard would permit agencies to print employees' pay grade and rank on the new cards, which many workers would consider an invasion of privacy.

'For example, an agency might seize upon this technology as a means to track employees as they move throughout a building,' Kelley said in written comments to NIST last week. 'That is troubling, standing alone. It would be particularly objectionable if the agency tried to track visits to particular sites such as the union office, Employee Assistance Program offices and the inspector general's office.'

NIST has gathered comments on the draft standard from more than 500 entities and individuals but has not made them public.... "


I wonder how long it will take before this makes its way into IDs for civilians, such as passports and drivers' licences.