One-hour notification mandate for HIX dropped but only because it's already covered
In response to numerous commenters who said a one-hour notification rule for privacy and security incidents is impractical and unworkable, the Centers for Medicare & Medicaid Services (CMS), in a final rule setting standards for health plans operating in state health insurance exchanges, dropped the proposed requirement.
However, CMS noted the provision wasn’t needed because it’s already in existing legal agreements. “Because the one hour incident response timeline has been included in all the data sharing agreements required under the Affordable Care Act, we have deleted the timing for incident reporting from regulation, proposed in section 155.280(c)(3), and expect it to be addressed through separate agreement," the final rule states.
Health insurance exchanges are set to open for business on Oct. 1 to support open enrollment as consumers compare and purchase health insurance with coverage beginning in January 2014.
Not all the provisions from the proposed rule have been finalized, as some need to be in effect by October while others can wait.
The final rule is available here.