Home About Us Partners Speaking
HIPAA   Forensics   Client Login   Links
 
 

Overview | Tracker | Resources | Updates | FAQs

Health Insurance Portability and Accountability Act of 1996 (HIPAA)

The increase in the use of electronic systems to capture, manage and transmit health information has increased the public's concern with the security and confidentiality of health information. HIPAA directed Congress to enact a comprehensive patient confidentiality law by August 1999. HIPAA also specified that, if Congress failed to act by August 1999, the Department of Health and Human Services (HHS) must create and enact privacy and security rules by February 2000.

Congress failed to act, and HHS published draft regulations, for security in 1998 and for privacy in 1999.

The security standards apply chiefly to hardware and the control of access to information systems. The security standards, as published in the Federal Register on February 20, 2003, required compliance for most covered entities on April 20, 2005. Small health plans were again given an additional year, and must achieve compliance by April 20, 2006.

In contrast, the privacy standards are concerned with the ways in which identifiable information can be used, the policies that describe how patients gain access to their medical information, and the steps that must be taken to maintain the accuracy of stored information; these rules have caused considerable concern due to their requirements for extensive policy reviews, personnel education, and, potentially, the need for enhancements to existing information systems. The privacy standards, as published in the Federal Register on August 14, 2002, required compliance for most covered entities on April 14, 2003. Small health plans were given an additional year to comply, until April 14, 2003.

Stay Informed

Recent accidental releases of private health information illustrate the need for vigilance in maintaining HIPAA compliance. Use our Updates page to keep abreast of current HIPAA-related issues and our Resources page to achieve and maintain compliance.

Second set of UPMC data found on Internet Pittsburgh Post-Gazette, 15 April 2007
Hundreds Of Patient Records Dumped On Street KTVU, 13 October 2006
US Healthcare IT Czar Resigns Red Herring, 21 April 2006
Maine's Medicaid Mistakes CIO, 15 April 2006
Four lose jobs after data breach at Oregon health care facility Computerworld, 28 February 2006
Sidebar: Insurer Puts Social Security Numbers in the Mail Computerworld, 13 February 2006
Brigham sent bank new moms' records Boston Herald, 7 February 2006
'Human error' exposes patients' Social Security numbers in N.C. Computerworld, 7 February 2006
Confidential patient data sent to wrong company - for 15 months Computerworld, 6 February 2006
Clinton File Snoopers Rapped New York Daily News, 11 September 2004
 
 
Ocius Medical Informatics