Email this article   Print article 


HIPAA Subcontractor Extension To Lead To More Accountability: Security Experts

By Robert Westervelt
January 22, 2013    3:40 PM ET

Page 2 of 2

Risk assessments, as outlined by HIPPA, must consider the following four factors: the nature and extent of the protected health information involved, including the types of identifiers and the likelihood of re-identification; the unauthorized person who used the protected health information or to whom the disclosure was made; whether the protected health information was actually acquired or viewed; and the extent to which the risk to the protected health information has been mitigated.

In addition, penalties for noncompliance were increased to a maximum of $1.5 million per violation, one of the many anticipated changes.

Security experts say HIPAA enforcement has increased over the last several years with millions of dollars in fines handed down for HIPAA noncompliance in 2012. Many of the data breaches over the last year can be pinpointed to data exposure via third-party service providers and other business partners.

Protecting patient data is a serious challenge. A study issued in December by the Ponemon Institute surveyed 80 healthcare organizations and found that 94 percent had at least one data breach in the past two years.

The final HIPAA rule update also addresses the marketing of patient healthcare information. It requires healthcare organizations to gain authorization from patients to use their health information for research purposes. It also prohibits "the sale of protected health information without the express written authorization of the individual, as well as the other uses and disclosures for which the rule expressly requires the individual’s authorization."

PUBLISHED JAN. 22, 2013

<< Previous | 1 | 2

To continue reading this article, please download the free CRN Tech News app for your iPad or Windows 8 device.
Related: Videos | Slide Shows | Comments

SHARE THIS ARTICLE

More Security

Recent Articles

Head-To-Head: Symantec Vs. McAfee In Endpoint Protection

McAfee and Symantec are archrivals with a firm grip on the North American security market. CRN pits both vendors' endpoint security products against each other and names a winner.

The 8 Steps Behind The Massive $45M Cyber Bank Heist

More than $45 million was stolen from banks in the U.S. and 19 other countries in a scheme that law enforcement is calling an international conspiracy to drain millions from bank accounts using stolen debit cards and PIN numbers. Here's how they did it.

Name Of The Game: Top 10 States For Identity Theft

A Federal Trade Commission report provides statistics on identity theft and fraud complaints in 2012. Learn which state has the dubious distinction of having the most victims.

  More Slide Shows




Related Videos
Loading...