HITPC: Update on HIPAA compliance activities

Susan McAndrews, deputy director for health information privacy, Office for Civil Rights (OCR), offered the latest in OCR’s privacy and security efforts and opened up about the audit program during the Health IT Policy Committee meeting on Dec. 4.

McAndrews informed the committee that the agency has nearly finished the final rulemaking for Clinical Laboratory Improvement Amendments regulations, which will allow lab vendors to send test results electronically available to patients.

Also, she said OCR currently is evaluating the audit program and presented some results of a recent study. Specifically, in an examination of audits, she said 58 or 59 providers had at least one security finding or observation. The most common cause identified was that the entity was unaware of the requirement, underscoring the need for even greater outreach and education, she said.

As for security, McAndrew said OCR is working to ensure that organizations understand that risk assessments are a foundational part of security, noting they have often been neglected. In the study, two-thirds of the entities lacked a complete and accurate risk assessment.

Following her presentation, Neil Calman, MD, president and CEO, department of family medicine and community health, Icahn School of Medicine at Mount Sinai in New York City, asked what OCR's expectations are if organizations are self-reporting breaches as they go through internal audits. He said it seems OCR has skipped over the ability to allow organizations to report on things that happen without fear of penalty. “I think sharing with the larger community is an important mechanism. If it’s all related to large fines, it defeats the purpose of what we’re trying to do,” he said, citing the $1.2 million fine charged to N.Y.-based Affinity Health Plan as part of a patient data breach case.

In response, McAndrew said the vast majority of breaches and complaints do not result in resolution agreement. “There is plenty of room for that sharing environment,” she said, adding, “The incident or breach that occurred is rarely the sole or prominent part of the whole complaint; it’s the event that got us to look at the entity to see what they’re doing. Most of our efforts are to work with entities, not to punish them.”

Around the web

Compensation for heart specialists continues to climb. What does this say about cardiology as a whole? Could private equity's rising influence bring about change? We spoke to MedAxiom CEO Jerry Blackwell, MD, MBA, a veteran cardiologist himself, to learn more.

The American College of Cardiology has shared its perspective on new CMS payment policies, highlighting revenue concerns while providing key details for cardiologists and other cardiology professionals. 

As debate simmers over how best to regulate AI, experts continue to offer guidance on where to start, how to proceed and what to emphasize. A new resource models its recommendations on what its authors call the “SETO Loop.”