Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


September 29, 2009

New Data Breach Rule for Healthcare Companies

A useful law unwittingly diluted by bureaucratic whitewashing
RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
back to blog index

A new data security law recently went into effect as part of the U.S. Department of Health & Human Services (HHS) Health Information Technology for Economic and Clinical Health (HITECH) Act. This new law, called the "Breach Notification for Unsecured Protected Health Information," is aimed at health organizations covered by the Health Insurance Portability and Accountability Act (HIPAA).

According to the rule, only healthcare providers and healthcare plans that don't use HHS-approved techniques to encrypt or destroy information will be required to notify individuals within 60 days of a breach of such unsecured protected health information (PHI). Breaches that affect more than 500 people must be reported to the HHS, as well as to the media.

However, in an "interim final rule" version, the HHS amended the law to note that healthcare companies must publicly disclose data breaches only if the breach threatens significant financial or reputational harm to the individuals affected. And whether this risk is deemed significant is left up to the discretion of the healthcare company whose data has been compromised—which raises the hackles of opponents to the new rule, who contend that the amendment effectively guts the law.

Mark Bower, Voltage Security's director of information protection solutions, asserts that "the protection law should address everyone—including those who have already implemented encryption, since most encryption systems are point-to-point even when they say otherwise." In addition, Bower notes that "the bad guys are always looking for a way in, and in many cases they're highly sophisticated organized criminals, so we'll keep bumping into a wall if we don't get smart and protect data end-to-end."

For the full text of the breach notification rule, go to http://edocket.access.gpo.gov/2009/pdf/E9-20169.pdf.

End of Article



Reader Comments

You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now





Search Industry Bytes
 
Industry Bytes
NOVEMBER 2009
1 2 3 4 5 6 7
8 9 10 11 12 13 14
15 16 17 18 19 20 21
22 23 24 25 26 27 28
29 30      
or

 Recently in Industry Bytes
Interop News: Datacom Unveils New 10Gb Data Filtering Taps and Switches
Make a Comment
Tony Redmond's Top 10 Things About Exchange 2010

Last Comment
In defense of Tony's list, remember that it's "Top 10 Things You Need to Know About Exchange 2010," ...
(3 Comments)
Hire Better Employees with This 5-Step Process
Make a Comment
MOSS 2007 and SharePoint 2010: Walking the line between past and future
Make a Comment
Notes from the Hiring Table, Part 4: Become the Ultimate Employee
Make a Comment

More blogs about technology,
software, and Windows.

Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement