Original Goal
to imporve healthcare efficiency
Privacy Rule Disclosure Requirements
PHI may not be disclosed except to:
- the patient
- part of treatment/payment/healthcare operations
- under valid auth from patient
- other permitted/required disclosures
* Minimum necessary
Security Rule
ONLY APPLIES TO ePHI
- require minimum security standards (Amin/Technical/Physical safeguards)
- “reasonable and appropriate” level of security
- there are both “required” and “addressable” security controls
NIST SP 800- 662R> implement a security plan
Privacy Rule Patient Rights Requirements
Privacy Rule Safety Requirements
Require minimum security standards (Amin/Technical/Physical safeguards)
Enforcement
HHS Office of Civil Rights
- fines up to 2 million /year
- audits of CE/BA
DOJ- criminal prosecution
- prision up to 10 years
FTC- UDAP
State AG
HIPAA Safe Harbor Rule
Deidentifying data
- remove 18 idenitifiers
- after those are removed, you must not acutally know any realistic way the remaining data could still be idenitified
HIPAA HBNR - HHS Secretary
HIPAA HBNR - Media
HIPAA HBNR - Substitute Notice
if contact infor for 10+ affected individuals in not available, subsistute notice must be posted on orgs website
HIPAA HBNR - Business Associates
HIPAA Rulemaking
HHS OCR
HIPAA HBNR- Individuals