Showing posts with label HIPAA. Show all posts
Showing posts with label HIPAA. Show all posts

Wednesday, November 5, 2014

HHS Delays HPID Requirement for Health Plans

The Department of Health and Human Services recently announced on its website that:

"Effective October 31, 2014, the...Department of Health & Human Services (HHS)...announces a delay, until further notice, in enforcement of 45 CFR 162, Subpart E, the regulations pertaining to health plan enumeration and use of the Health Plan Identifier (HPID) in HIPAA transactions adopted in the HPID final rule (CMS-0040-F).

This enforcement delay applies to all HIPAA covered entities, including healthcare providers, health plans, and healthcare clearinghouses."

To read more, click here.

Wednesday, October 8, 2014

HHS Issues FAQs on Health Plan Identifiers

The U.S. Department of Health and Human Services (HHS) recently posted Frequently Asked Questions (FAQs) on health plan identifiers (HPIDs). The FAQs state:

"Are Flexible Spending Accounts (FSAs), Health Reimbursement Arrangements (HRAs), Health Savings Account (HSAs), wrap-plans, or cafeteria plans required to get HPIDs?

FSAs and HSAs are individual accounts directed by the consumer to pay health care costs. As such, they do not require an HPID..."

They also state:

"Can a health plan authorize a person to get a Health Plan Identifier (HPID) for the health plan?

Yes. An authorized person is permitted to enroll the health plan in the Health Plan and Other Entity Enumeration System (HPOES)."

The FAQs are available here.

Friday, April 4, 2014

ERIC Urges HHS to Rule That Self-Funded Plans Should Not Be Subject to HIPAA Certification Requirements

The ERISA Industry Committee (ERIC) on April 3 urged the Department of Health and Human Services (HHS) to modify proposed rules that would require employer group health plans to certify compliance with standards and operating rules adopted under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) for certain electronic transactions.

ERIC's press release is available here.
For ERIC's comment letter, click here.
The proposed regulations are available here.

Wednesday, February 26, 2014

HHS posts more information about HIPAA on its website

HHS posts "HIPAA Privacy Rule and Sharing Information Related to Mental Health", which provides that:

"In this guidance, we address some of the more frequently asked questions about when it is appropriate under the Privacy Rule for a health care provider to share the protected health information of a patient who is being treated for a mental health condition."


To read more, click here.

Monday, January 6, 2014

Stepped Up Enforcement for HIPAA Requirements

In "Dust Off HIPAA Policies and Procedures Before HHS Comes Knocking," Covington & Burling explains that:

"Employers should be aware that the Department of Human Services (“HHS”) is stepping up its enforcement of requirements for covered entities, such as group health plans, to adopt and implement policies and procedures for protecting and securing protected health information in accordance with the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”)."

To read more, click here.

Wednesday, December 11, 2013

HHS Finds OCR Did Not Meet all Requirements for Enforcing HIPAA

The Department of Health and Human Services's Office of Inspector General recently issued a report titled "The Office for Civil Rights Did Not Meet All Federal Requirements in its Oversight and Enforcement of the Health Insurance Portability and Accountability Act Security Rule". The report stated that:

"OCR met some Federal requirements for oversight and enforcement of the Security Rule. OCR made available to covered entities guidance that promoted compliance with the Security Rule and OCR established an investigation process for responding to reported violations of the Security Rule. OCR also followed Federal regulations when imposing penalties for Security Rule violators. However, OCR did not meet other Federal requirements critical to the oversight and enforcement of the Security Rule..."

To read more, click here.

Friday, August 30, 2013

New Trends in HIPAA

HealthITSecurity.com reports:

"One month from today, as most healthcare organizations already (should) know, they will need to be compliant with the much-talked about HIPAA omnibus rule. Whether it’s a healthcare organization vetting the details of a “HIPAA compliant” product or establishing a concrete security training regimen for its staff, healthcare organizations have had a lot on their plate come Sept. 23, 2013.

Of course, the majority of organizations looking to be compliant have already done the necessary work. But others may be headed right down to the wire as the HIPAA compliance data nears. HealthITSecurity.com has spoken with a handful of legal and compliance experts regarding the HIPAA omnibus rule since the spring and there are a few trends they consistently see organizations still dealing with."

The article also includes a discussion by Dianne Bourque, partner at Mintz Levin, about the volume of business associate agreements.

For the full article, click here.

Thursday, August 29, 2013

HIPAA Violation Results in $1.2 Million Settlement with HHS

The U.S. Department of Health and Human Services, Office of Civil Rights (HHS) issued a press release announcing:

"Under a settlement with the U.S. Department of Health and Human Services (HHS), Affinity Health Plan, Inc. will settle potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules for $1,215,780. Affinity Health Plan is a not-for-profit managed care plan serving the New York metropolitan area.

Affinity filed a breach report with the HHS Office for Civil Rights (OCR) on April 15, 2010, as required by the Health Information Technology for Economic and Clinical Health, or HITECH Act. The HITECH Breach Notification Rule requires HIPAA-covered entities to notify HHS of a breach of unsecured protected health information. Affinity indicated that it was informed by a representative of CBS Evening News that, as part of an investigatory report, CBS had purchased a photocopier previously leased by Affinity. CBS informed Affinity that the copier that Affinity had used contained confidential medical information on the hard drive."

The full press release is available here.