Further, the Department of Health and Human Services on April 17 issued guidance on technologies and methodologies to secure health information by rendering data unusable, unreadable or indecipherable to unauthorized individuals.
The American Recovery and Reinvestment Act requires the Department of Health and Human Services, in consultation with the FTC, by February 2010 to release a study on potential privacy, security and breach notification requirements for PHR vendors and related entities.
In the meantime, the Act mandates an interim final rule from the FTC by August. The FTC intends to develop the interim final rule following the public comment period on the proposed rule.
The FTC's proposed rule is not as formal as most proposed rules. It appears to be a substantial outline, or "first look," at what provisions could be in the interim final rule. The rule is available at ftc.gov/opa/2009/04/healthbreach.shtm.
HHS will issue a breach notification rule covering HIPAA-covered entities.
The guidance issued April 17 outlines steps entities can take to secure health information and establishes the trigger for when entities must notify patients that their data has been compromised. The guidance is available at hhs.gov.ocr/privacy.
(c) 2009 Health Data Management and SourceMedia, Inc. All Rights Reserved.
http://www.healthdatamanagment.com/ http://www.sourcemedia.com/





















Be the first to comment on this post using the section below.