Mostashari: HIPAA Rules Out by Summer's End

The final omnibus HIPAA rule governing the privacy, security, breach notification and enforcement rules, and the Genetic Information Non-Discrimination Act, should be out by the end of summer, says Farzad Mostashari, national coordinator for health information technology.

He made the announcement during the opening keynote of the Health Privacy Summit underway in Washington, D.C. Mostashari also noted the rules will extend liability under HIPAA to business associates and subcontractors, which was a major provision of the proposed rules. The final omnibus rule was sent on March 24 to the Office of Management and Budget for review, one of the last steps before publication.

In his keynote, Mostashari emphasized that awareness of the importance of technical and cultural considerations to assure privacy protections are at the center of everything ONC does. The priority for the agency has been to expand adoption of electronic health records-an effort that has been successful, he noted. The next step is to increase the trust needed to exchange health data, then creating a "learning" health system where the data is routinely used appropriately. "You can't get information exchange unless there's trust. We can't get a learning health system unless there's trust."

ONC, Mostashari said, is working with software vendors on functionalities that are required to bring privacy into information systems by design. The goal is to have privacy protections build into the systems. When exchanging data, for example, personal identifiers should not be in the header but encrypted in the package. "Routing should never require personal information. This is privacy by design."

The industry also needs to better educate patients on their privacy rights, he said. They should know how their information is used and how to complain about violations. And providers need to better understand what HIPAA requires and does not require, as they often times misinterpret its provisions. Patients, he asserted, should never hear, "Sorry, I can't give you your health records because of HIPAA."

ONC's new Office of Consumer eHealth will focus on protecting information and making it available to consumers, Mostashari explained. It remains difficult for patients to ask providers for their records and changing provider attitudes is a priority of the office. ONC will work with nurses to help them become advocates for patients in asserting their privacy rights.

Get access to this article and thousands more...

All Health Data Management articles are archived after 7 days. REGISTER NOW for unlimited access to all recently archived articles, as well as thousands of searchable stories. Registered Members also gain access to exclusive industry white paper downloads, web seminars, podcasts, e-books, and conference discounts. Qualified members may also choose to receive our free monthly magazine and any of our e-newsletters covering the latest breaking news, opinions from industry leaders, developing trends and specialized topics like EHR's, revenue cycle management, health insurance exchanges, analytics, and more!

Already Registered?

Forgot Password/Need Help?
Comments (1)
HIPPA is a waste of healthcare dollar. It only raises the cost of everry thing! My data has be lost/breached by Veteran Admin. Mastercard and BC/BS. So how SAFE is data? It is NOT!!! Build out the system to H with more layers of protection that will protect no one. ONC should not wastse any more dollar, set conect criteria and get out of the way! Go avocate for simplicity and stick more regs where only a colonoscopy can find them!
Posted by mackley | Friday, June 08 2012 at 8:16AM ET
Add Your Comments:
Not Registered?
You must be registered to post a comment. Click here to register.
Already registered? Log in here
Please note you must now log in with your email address and password.


Slide Shows

Already a subscriber? Log in here
Please note you must now log in with your email address and password.