Advertisement

May 23, 2013

HHS Office of Civil Rights Co-Hosts Security Conference and Announces New Educational Materials

This is an eventful week for the Department of Health and Human Services’ Office of Civil Rights (OCR), the agency that enforces the privacy and security standards under the Health Information Portability and Accountability Act (HIPAA), as amended by the Health Information Technology for Economic and Clinical Health (HITECH) Act.  First, OCR is co-hosting the 5th annual Safeguarding Health Information: Building Assurance through HIPAA Security Conference (HIPAA Security Conference) on June 6 & 7, 2012, with the National Institute of Standards and Technology (NIST).   Second, OCR has posted some useful documents on its website:  1) HIPAA training materials for State Attorneys General (SAG materials), and 2) a “Right to Access” memo for health care consumers.    

The materials published on the OCR website this week provide health care entities with insight into how the federal government is approaching HIPAA and HITECH Act education from the alternative perspectives of state enforcers and health care consumers.   The SAG materials include videos and computer training modules of the enforcement training sessions so their availability on the website makes them an invaluable resource for the general public and health care entities who want to know what state enforcement agencies have learned directly from OCR.  Equally as important, the Right to Access memo guides consumers to links and videos on their rights to access their health information records to empower them to be more involved in their health care and assert their access rights.  OCR has been aggressive recently about enforcing consumers’ right to access, including imposing a $4.3 million civil monetary penalty on Cignet Health in Feburary 2011. Of that large penalty, $1.3 million was levied specifically because OCR found that Cignet Health failed to provide 41 patients with access to their records in accordance with HIPAA requirements.  

The HIPAA Security Conference and OCR’s release of the aforementioned educational materials are only a preview of the flurry of activity that the health care industry should expect if and when the HIPAA Omnibus Rule is released.  As we previously posted, the rule was submitted to the Office of Management and Budget on March 24, 2012.  So, according to the 90-day review timeline generally permitted for review, the HIPAA Omnibus Rule could be released later this month.  Also, according to OCR’s comments at the HIPAA Security Conference on June 7th, OCR will be issuing more informational documents soon, including the protocols for audits mandated under HITECH.

©1994-2013 Mintz, Levin, Cohn, Ferris, Glovsky and Popeo, P.C. All Rights Reserved.

About the Author

Associate

Stephanie is an Associate in the Washington, D.C. office, practicing in the Health Law Section.

Prior to joining Mintz Levin, Stephanie was an associate counsel in the Department of Health and Human Services’ Office of Counsel to the Inspector General. There, her practice focused on health care enforcement matters involving the False Claims Act, the Social Security Act, the Physician Self-Referral Act, the anti-kickback statute, the EMTALA, and other administrative actions.

(202) 434-7437

About the Author

Of Counsel

Dianne is Of Counsel in the firm’s Health Law Section. She advises a variety of health care clients on a broad range of issues, including licensure, regulatory, contractual, and risk management matters, and patient care. A large part of Dianne’s practice involves counseling researchers and research sponsors in matters related to FDA and OHRP regulated clinical research, including patient consent, access to and use of tissue and associated patient information, and the Institutional Review Board process. She also counsels health care clients and other business entities...

(617) 348-1614

Boost: AJAX core statistics

Legal Disclaimer

You are responsible for reading, understanding and agreeing to the National Law Review's (NLR’s) and the National Law Forum LLC's  Terms of Use and Privacy Policy before using the National Law Review website. The National Law Review is a free to use, no-log in database of legal and business articles. The content and links on www.NatLawReview.com are intended for general information purposes only. Any legal analysis, legislative updates or other content and links should not be construed as legal or professional advice or a substitute for such advice. No attorney-client or confidential relationship is formed by the transmission of information between you and the National Law Review website or any of the law firms, attorneys or other professionals or organizations who include content on the National Law Review website. If you require legal or professional advice, kindly contact an attorney or other suitable professional advisor.  

Some states have laws and ethical rules regarding solicitation and advertisement practices by attorneys and/or other professionals. NLR does not accept advertising from attorneys or law firms. The National Law Review is not a law firm nor is www.NatLawReview.com  intended to be an advertisement or a referral service for attorneys and/or other professionals. The NLR does not wish, nor does it intend, to solicit the business of anyone or to refer anyone to an attorney or other professional.  NLR does not answer legal questions nor will we refer you to an attorney or other professional if you request such information from us. 

Under certain state laws the following statements may be required on this website and we have included them in order to be in full compliance with these rules. The choice of a lawyer or other professional is an important decision and should not be based solely upon advertisem