Educause Security Discussion mailing list archives

hhs.gov RFI - Accounting of Disclosures Under HIPAA/HITECH


From: Faith Mcgrath <faith.mcgrath () YALE EDU>
Date: Mon, 17 May 2010 12:09:57 -0400

Yale is discussing whether to respond to this RFI and is curious as to whether other schools including AMCs (medical colleges) may have plans to comment. From an IT perspective, the functionality of your EHR (electronic health record) may impact the burden of this requirement. This may not be of general interest to the entire list, but please feel free to contact me off-list if you are willing to share what your institution is discussing/planning. Thanks. -Faith

___________________________________________________________________
HIPAA Privacy Rule Accounting of Disclosures Under the Health Information Technology for Economic and Clinical Health Act; Request for Information
http://edocket.access.gpo.gov/2010/pdf/2010-10054.pdf
"Section 13405(c) of the Health Information Technology for Economic and Clinical Health (HITECH) Act expands an individual’s right under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Rule to receive an accounting of disclosures of protected health information made by HIPAA covered entities and their business associates. In particular, section 13405(c) of the HITECH Act requires the Department of Health and Human Services (‘‘Department’’ or ‘‘HHS’’) to revise the HIPAA Privacy Rule to require covered entities to account for disclosures of protected health information to carry out treatment, payment, and health care operations if such disclosures are through an electronic health record. This document is a request for information (RFI) to help us better understand the interests of individuals with respect to learning of such disclosures, the administrative burden on covered entities and business associates of accounting for such disclosures, and other information that may inform the Department’s rulemaking in this area."

http://www.hhs.gov/ocr/privacy/hipaa/understanding/special/healthit/accountingrfi.html


--
Faith McGrath, Compliance Officer
Yale University ITS - Information Security
faith.mcgrath () yale edu
voice: 203.737.4087
security () yale edu || security.yale.edu

Save a tree - please consider the environment before printing this email.
Please be aware that email communication can be intercepted in transmission or misdirected. Please consider communicating any sensitive information by telephone, fax or mail. The information contained in this message may be privileged and confidential. If you are NOT the intended recipient, please notify the sender immediately and destroy this message. If you wish to confirm the content of this message and/or the identity of the sender please contact me at the phone number given above.

Current thread: