New portal to clear up HIPAA regs for mobile developers
A new online portal is designed to help mobile health technology developers better understand HIPAA privacy and security issues.
The Department of Health and Human Services' (HHS) Office for Civil Rights (OCR) established the portal in response to calls from legislators. In September 2014, Reps. Tom Marino (R-Pa.) and Peter DeFazio (D-Ore.) wrote to HHS Secretary Sylvia Mathews Burwell urging the agency to clarify and update HIPAA regulations for mobile application developers.
The letter asks federal officials to clarify HIPAA obligations for services storing data on the cloud; offer implementation standards through OCR; recruit employees who can work with startups to produce HIPAA-compliant products; and update the steps vendors must take to comply with HIPAA.
OCR said the platform will help the agency better determine where to focus its guidance for developers, especially those involved in mobile health technology.
Anyone can browse the site and visitors also can register with the website. User identities and email addresses will be anonymous to OCR. Registered users have the ability to offer comments on other submissions, submit questions and vote on the relevancy of topics.
OCR noted that posting or commenting on a question will not result in enforcement action.
"We are experiencing an explosion of technology using data about the health of individuals in innovative ways to improve health outcomes," OCR said in an announcement. "Building privacy and security protections into technology products enhances their value by providing some assurance to users that the information is safe and secure and will be used and disclosed only as approved or expected. ... Yet many mHealth developers are not familiar with the HIPAA rules and how the rules would apply to their products."