JUL 30, 2010 3:49pm ET

Related Links

Verizon, Health Evolution Partners Align to Accelerate Health I.T.
February 6, 2012
Vendors Team for Mock HIPAA Privacy Audits
February 1, 2012
Laptop Loaded with PHI Stolen from Lexington Clinic
January 31, 2012
Bi-Partisan Report Seeks Effective Federal HIT Spending
January 27, 2012
HHS Seeks Mobile Computing Security Best Practices
January 25, 2012
Social Security Numbers, Other Veterans’ PHI Ends Up on Ancestry.com
January 23, 2012
OSU Offers Credit Protection Following Data Breach
January 10, 2012

Web Seminars

The Evolution of Tablet Computing in Healthcare
Available On Demand
Which comes first? Chargemaster Standardization vs. System Conversion
Available On Demand
Chronic Care. Chronic I.T. Challenges
Available On Demand

HHS to Rework Final Breach Rule

Print
Reprints
Email

The Department of Health and Human Services' Office for Civil Rights has temporarily pulled a final breach notification rule it has developed but not yet published, according to an HHS notice. The rule had been submitted to the Office of Management and Budget for review before publication. It now is being withdrawn for further consideration based on OCR's experience thus far in administering the notification rule under an interim final rule.

OCR will not comment on factors that compelled the withdrawal. "These are routine, formal regulatory processes," according to a statement from the agency.

OCR has been under industry pressure, which was evident during a May conference that the agency hosted, to remove a "harm threshold" in the interim final rule that enables an organization to not issue notification of a breach if it determines no consequential harm has resulted or will result from the breach.

What follows is the HHS notice that it has temporarily pulled the final rule:

"The Interim Final Rule for Breach Notification for Unsecured Protected Health Information, issued pursuant to the Health Information Technology for Economic and Clinical Health (HITECH) Act, was published in the Federal Register on August 24, 2009, and became effective on September 23, 2009.  During the 60-day public comment period on the Interim Final Rule, HHS received approximately 120 comments.

"HHS reviewed the public comment on the interim rule and developed a final rule, which was submitted to the Office of Management and Budget (OMB) for Executive Order 12866 regulatory review on May 14, 2010.  At this time, however, HHS is withdrawing the breach notification final rule from OMB review to allow for further consideration, given the Department's experience to date in administering the regulations.  This is a complex issue and the Administration is committed to ensuring that individuals' health information is secured to the extent possible to avoid unauthorized uses and disclosures, and that individuals are appropriately notified when incidents do occur.  We intend to publish a final rule in the Federal Register in the coming months."

--Joseph Goedert

 

Comments (0)

Be the first to comment on this post using the section below.

Add Your Comments:
You must be registered to post a comment.
Not Registered?
You must be registered to post a comment. Click here to register.
Already registered? Log in here
Please note you must now log in with your email address and password.
Twitter
Facebook
LinkedIn

A major success factor for accountable care organizations will be linking caregivers across the spectrum of care delivery. If history is any indication, that's going to be an industrywide struggle.

Login  |  My Account  |  White Papers  |  Web Seminars  |  Events |  Newsletters |  eBooks
FOLLOW US
Already a subscriber? Log in here
Please note you must now log in with your email address and password.