HHS Launches New Web Site on HIPAA Privacy Compliance and Enforcement
After four years, HIPAA remains a quiet reality, with health care providers obligated by this federal law to safeguard patient information, and with the potential for stringent penalties for failing to do so. In spite of the seeming stringency of the federal privacy rules, there have been few enforcement actions and the US Department of Health and Human Services (HHS) seems committed to a continuing effort to educate and assist providers in becoming and staying compliant, rather than focusing on hard-line, uncompromising enforcement. This does not mean, however, that doctors of chiropractic, along with other health care providers, should let down their guard or fail to take the potential consequences seriously.
To coincide with the fourth anniversary of the enforcement of the HIPAA Privacy Rule, HHS has announced the launch of an enhanced Web site designed to make it easier for consumers, health care providers and others to get information about how the Department enforces health information privacy rights and standards. In launching the website, Winston Wilkinson, the Director of the HHS Office for Civil Rights, noted: "HHS has obtained significant change in the privacy practices of covered entities through its enforcement program. Corrective actions obtained by HHS from these entities have resulted in change that is systemic and affects all the individuals they serve."
The Health Information Privacy Web site provides comprehensive information about the Privacy Rule, which creates important federal rights and requirements to protect the privacy of personal health information. The enhanced Web site, http://www.hhs.gov/ocr/privacy/enforcement provides information for consumers, health care providers, health plans and others in the health care industry about HHS’s compliance and enforcement efforts. The new information describes HHS activities in enforcing the Privacy Rule, the results of those enforcement activities, and statistics showing which types of complaints are received most frequently and the types of entities most often required to take corrective action as a result of consumer complaints. The other information on the Web site covers consumers’ rights to access their health information and significantly control how their personal health information is used and disclosed, as well as guidance about how to submit complaints about possible violations of the law and extensive guidance for entities who must comply with the rule.
HHS issued the patient privacy protections pursuant to the Health Insurance Portability and Accountability Act of 1996 (HIPAA). The first and only comprehensive federal privacy standards to protect patients` medical records and other health information provided to health plans, doctors, hospitals and other health care providers took effect on April 14, 2003. Developed by HHS, these standards provide patients with access to their health care records and more control over how their personal health information is used and disclosed. The regulation covers health plans, health care clearinghouses, and those health care providers who conduct certain financial and administrative transactions (e.g., enrollment, billing and eligibility verification) electronically. Doctors of chiropractic in the United States are covered under this law. HHS has conducted extensive outreach and provided guidance and technical assistance to providers and businesses to help them to implement the new privacy protections. These materials are available at http://www.hhs.gov/ocr/hipaa.