Friday, February 22, 2019
HIPAA, CIA & Safeguards Essay
First enforcement action resulting from HITECH Breach singing convention Blue Cross Blue Shield of Tennessee (BCBST) has agreed to pay the U.S. surgical incision of Health and Human Services (HHS) $1, euchre,000 to settle potential violations of the Health policy Portability and Accountability Act of 1996 (HIPAA) Privacy and credential endures, Leon Rodriguez, Director of the HHS Office for civilised Rights (OCR), announced today. BCBST has also agreed to a tonic action devise to address gaps in its HIPAA compliance program. The enforcement action is the first resulting from a arrangeer report required by the Health Information Technology for economic and Clinical Health (HITECH) Act Breach Notification Rule. The investigation followed a notice submitted by BCBST to HHS reporting that 57 unencrypted computer hard drives were stolen from a leased inst completelying in Tennessee. The drives contained the cherished health study (PHI) of oer 1 million individuals, including m ember names, social security numbers, diagnosis codes, dates of birth, and health plan identification numbers. OCRs investigation indicated BCBST failed to action appropriate administrative safeguards to adequately protect information remaining at the leased facility by not performing the required security evaluation in response to operational changes. In addition, the investigation showed a failure to implement appropriate physical safeguards by not having adequate facility approach controls both of these safeguards are required by the HIPAA Security Rule.This settlement sends an all-important(a) message that OCR expects health plans and health care providers to have in point a carefully designed, delivered, and monitored HIPAA compliance program, said OCR Director Leon Rodriguez. The HITECH Breach Notification Rule is an important enforcement tool and OCR will continue to vigorously protect patients right to private and secure health information. In addition to the $1,500,000 settlement, the savvy requires BCBST to review, revise, and maintain its Privacy and Security policies and procedures, to conduct regular and robust trainings for all BCBST employees covering employee responsibilities under HIPAA, and to perform monitor reviews to ensure BCBST compliance with the corrective action plan. HHSOffice for Civil Rights enforces the HIPAA Privacy and Security Rules. The HIPAA Privacy Rule gives individuals rights over their protected health information and sets rules and limits on who can belief at and receive that health information. The HIPAA Security Rule protects health information in electronic form by requiring entities covered by HIPAA to use of goods and services physical, technical, and administrative safeguards to ensure that electronic protected health information ashes private and secure. The HITECH Breach Notification Rule requires covered entities to report an proscribed use or disclosure of protected health information, or a breach, of 500 individuals or more to HHS and the media. Smaller breaches affecting less than 500 individuals must be reported to the secretary on an annual basis. Individuals who gestate that a covered entity has violated their (or someone elses) health information hiding rights or committed another violation of the HIPAA Privacy or Security Rule may file a complaint with OCR at http//www.hhs.gov/ocr/ silence/hipaa/complaints/index.html. The HHS Resolution Agreement can be found at http//www.hhs.gov/ocr/ solitude/hipaa/enforcement/examples/ resolution_agreement_and_cap.pdf.Additional information about OCRs enforcement activities can be found at http//www.hhs.gov/ocr/privacy/hipaa/enforcement/examples/index.html.
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment