Financial Freedom Insight

Financial Services Complete Review

Enhanced HIPAA Penalties Raise Stakes for Employers and Health Care Providers Responding to a Security Breach

Posted on August 5th, 2010

While HIPAA’s recently enhanced penalty provisions and newly enacted security breach notification requirements have each received a significant amount of attention, the connection between them and its significant implications for employers and health care providers subject to HIPAA have not. Most significantly, because of the enhanced penalties, it is critical that covered entities conduct a careful and documented risk assessment before deciding not to provide notice of a security incident.

HIPAA’s recently promulgated security breach notification regulations require notice only if (a) there has been access to, or acquisition, use or disclosure of, protected health information (PHI) in violation of the HIPAA Privacy Rule; and (b) that violation “poses a significant risk of financial, reputational or other harm” to the subjects of the PHI.  In the preamble to the security breach regulations, the U.S. Departme

Read more…

Tags: Breach, Security Breach
No Comments »

Best Tips