Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
31
12:00 AM - EXPO.health
5
6
8
9
10
11
13
15
16
18
19
20
21
22
23
24
26
27
28
30
1
32nd Annual Summer Seminar in Health Care Ethics & Surgical Ethics
2019-07-29 - 2019-08-02    
All Day
32nd Annual Summer Seminar in Health Care Ethics & Surgical Ethics is organized by University of Washington School of Medicine (UWSOM) Continuing Medical Education (CME) [...]
3-Day Physician Assistant PANCE / PANRE Board Review Course by Certified Medical Educators (CME) - Salt Lake City
2019-07-29 - 2019-07-31    
All Day
3-Day Physician Assistant PANCE / PANRE Board Review Course is organized by Certified Medical Educators (CME) and will be held from Jul 29 - 31, [...]
Four Week Radiologic Pathology Correlation Course (Jul 29 - Aug 23, 2019)
2019-07-29 - 2019-08-23    
All Day
Four Week Radiologic Pathology Correlation Course is organized by American Institute for Radiologic Pathology (AIRP) and will be held from Jul 29 - Aug 23, [...]
Third Annual Philadelphia Trauma Training Conference
2019-07-30 - 2019-08-01    
All Day
Third Annual Philadelphia Trauma Training Conference is organized by Thomas Jefferson University (TJU) and will be held from Jul 30 - Aug 01, 2019 at [...]
IDAA Annual Meeting 2019
2019-07-31 - 2019-08-04    
All Day
International Doctors in Alcoholics Anonymous (IDAA) 70th Annual Meeting 2019 is organized by International Doctors in Alcoholics Anonymous (IDAA) and will be held from Jul [...]
EXPO.health
2019-07-31 - 2019-08-02    
All Day
EXPO.health Schedule July 31 - August 2, 2019 - Location: Boston, MA Join us at EXPO.health (Formerly Healthcare IT Expo – HITExpo) 2019 happening July [...]
01 Aug
2019-08-01 - 2019-08-03    
All Day
UCSF CME: Neurosurgery Update 2019 is organized by The University of California, San Francisco (UCSF) Office of Continuing Medical Education and will be held from [...]
PBI Medical Ethics & Professionalism (ME-22) - Irvine
2019-08-02 - 2019-08-03    
All Day
PBI Medical Ethics & Professionalism (ME-22) is organized by Professional Boundaries, Inc. (PBI) and will be held from Aug 02 - 03, 2019 at Wyndham [...]
The 8th Beijing International Top Health & Medical Exhibition (BIHM)
2019-08-02 - 2019-08-04    
All Day
The 8th Beijing International Private Health and Medical Exhibition will be held at the China International Exhibition Center from August 2nd to August 4th, 2019. [...]
Angiogenesis Gordon Research Seminar (GRS) 2019
2019-08-03 - 2019-08-04    
12:00 am
Angiogenesis Gordon Research Seminar (GRS) is organized by Gordon Research Conferences (GRC) and will be held from Aug 03 - 04, 2019 at Salve Regina [...]
Lung Development, Injury and Repair Gordon Research Seminar (GRS) 2019
2019-08-03 - 2019-08-04    
All Day
Lung Development, Injury and Repair Gordon Research Seminar (GRS) is organized by Gordon Research Conferences (GRC) and will be held from Aug 03 - 04, [...]
Platelet Rich Plasma for Aesthetics Course - Miami (Aug 2019)
Platelet Rich Plasma for Aesthetics Course is organized by Empire Medical Training (EMT), Inc and will be held on Aug 04, 2019 at GALLERYone - [...]
Physician Medical Weight Loss Training (Aug 04, 2019)
2019-08-04    
All Day
Physician Medical Weight Loss Training is organized by Empire Medical Training (EMT), Inc and will be held on Aug 04, 2019 at The Platinum Hotel [...]
Grand opening for Saint Alphonsus Regional Rehabilitation Hospital
2019-08-07    
4:00 pm - 6:00 pm
Grand opening for Saint Alphonsus Regional Rehabilitation Hospital 711 North Curtis Road | Boise, Idaho Aug 7, 2019 4:00 p.m. MDT A new home for Saint Alphonsus [...]
7th International Conference on  Medical Informatics & Telemedicine
2019-08-12 - 2019-08-13    
All Day
Conference Date : August 12-13, 2019 Rome, Italy Theme: Innovative information technologies for the improvement of patient care “7th International Conference on Medical Informatics and Telemedicine” will take [...]
CMBBE 2019 - 16th International Symposium on Computer Methods in Biomechanics and Biomedical Engineering and the 4th Conference on Imaging and Visualization
2019-08-14 - 2019-08-16    
8:00 am - 6:00 pm
CMBBE 2019 - 16th International Symposium on Computer Methods in Biomechanics and Biomedical Engineering and the 4th Conference on Imaging and Visualization is organized by [...]
Joint / Extremity / Non Spinal Injection Course (Aug 17, 2019)
2019-08-17    
All Day
Joint / Extremity / Non Spinal Injection Course is organized by Empire Medical Training (EMT), Inc and will be held on Aug 17, 2019 at [...]
Wilderness Medicine Expedition Course 2019
2019-08-25 - 2019-09-02    
All Day
Wilderness Medicine Expedition Course is organized by National Outdoor Leadership School (NOLS) and will be held from Aug 25 - Sep 02, 2019 at Wyss [...]
Diabetes, Lipidology, Pulmonary Medicine, and Critical Care Conference
2019-08-25 - 2019-09-01    
All Day
Diabetes, Lipidology, Pulmonary Medicine, and Critical Care Conference is organized by Continuing Education, Inc and will be held from Aug 25 - Sep 01, 2019 [...]
Neurology Certification Review 2019
2019-08-29 - 2019-09-03    
All Day
Neurology Certification Review is organized by The Osler Institute and will be held from Aug 29 - Sep 03, 2019 at Holiday Inn Chicago Oakbrook, [...]
Ophthalmology Lecture Review Course 2019
2019-08-31 - 2019-09-05    
All Day
Ophthalmology Lecture Review Course is organized by The Osler Institute and will be held from Aug 31 - Sep 05, 2019 at Holiday Inn Chicago [...]
Emergency Medicine, Sex and Gender Based Medicine, Risk Management/Legal Medicine, and Physician Wellness
2019-09-01 - 2019-09-08    
All Day
Emergency Medicine, Sex and Gender Based Medicine, Risk Management/Legal Medicine, and Physician Wellness is organized by Continuing Education, Inc and will be held from Sep [...]
Events on 2019-07-30
Events on 2019-07-31
IDAA Annual Meeting 2019
31 Jul 19
Knoxville
EXPO.health
31 Jul 19
Boston
Events on 2019-08-01
01 Aug
Events on 2019-08-29
Events on 2019-08-31
Articles

Meeting the HIPAA Omnibus Rule Compliance Deadline: What Providers Need to Know

Significant changes have been made to the privacy and security obligations of providers with respect to patients’ protected health information (PHI) with the release of the Omnibus Final Rule (Omnibus Rule) on January 17, 2013. With the Omnibus Rule, the Department of Health and Human Services (HHS) made important changes to the privacy and security requirements under HIPAA and the HITECH Act, including creating a new breach standard, clarifying the definition of a business associate, and implementing the increased liability and penalty structure mandated by the HITECH Act. Except with respect to certain grandfathered business associate agreements, covered entities and business associates are required to come into full compliance with the Omnibus Rule by September 23, 2013. With this compliance deadline quickly approaching, providers need to take the steps discussed below to ensure that they will be in full compliance by the deadline.

1. Updating Internal Policies.

In order to comply with the Omnibus Rule, providers must update their internal privacy policies to reflect the changes to the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule. Below are certain key changes that a provider will likely need to make to its internal privacy policies.

a. Breach standard. The Omnibus Rule changed the standard for determining whether a breach of unsecured PHI has occurred, and thus, when a provider must follow the notification requirements under HIPAA. Who must be notified however, has remained unchanged. The new breach standard should be included in providers’ internal policies on responding to a potential breach. Once the new standard has been incorporated into a provider’s policies, the provider should no longer use the prior breach standard, even for potential breaches that occur prior to the Omnibus Rule’s compliance deadline of September 23, 2013.

b. Marketing and sale of PHI. Under the Omnibus Rule, the marketing of third party products and services and sale of PHI is generally prohibited. These general prohibitions do not apply if the provider has received valid authorization from the patient. Therefore, in order for a provider to market third party services to patients based on their PHI, or to sell or provide access to PHI for payment, the provider must request permission to do so from each patient whose PHI it wishes to use. Providers should also ensure that any definitions of “marketing” and “sale of PHI” in their policies comports with the revised definitions and standards under the Omnibus Rule.

c. Decedents’ PHI. Under the Omnibus Rule, the definition of “protected health information” now expressly excludes the health information of a person who has been deceased for more than 50 years. In addition, the Omnibus Rule provides that providers may disclose the PHI of a deceased person to such person’s family members, relatives, or close friends, or other individuals indicated by the deceased, who were involved either in the deceased’s care or the payment of care. Providers may disclose only PHI that is relevant to the family member, relative, or friend’s involvement in the deceased’s care. PHI cannot be disclosed if the provider is aware that the deceased person expressed a prior preference for it not to be disclosed to the person in question.

d. Disclosures to schools. A provider’s policies on when PHI can be disclosed should also reflect the new permitted disclosure of proof of immunizations to schools. Under the Omnibus Rule, providers may disclose proof of immunization to schools if the school is required by state, or other, law to have proof of immunization prior to admitting the individual, and the provider obtains and documents the oral agreement to the disclosure by either a parent, guardian, or other person acting in loco parentis of the individual, or from the individual if he or she is an adult or emancipated minor.

e. Patient rights to limit disclosures. Under the Omnibus Rule, a provider must comply with a patient’s request that PHI regarding a specific health care item or service not be disclosed to a health plan for purposes of payment or health care operations if the patient paid out-of-pocket, in full, for that item or service.

f. Provision of electronic copies of medical records. Providers complying with a patient’s request for an electronic copy of his or her PHI are required to provide access to such records in the electronic format requested by the patient if the records are maintained by the provider in an electronic designated record set and are readily producible in the requested format. There has been no change to the rules regarding whether a provider is required to grant access to a patient’s medical records.

Providers should assess whether it makes sense to take the opportunity to replace their policies or update existing policies. HHS has posted on its websitethe audit protocol derived from the recently completed audit pilot program. The audit protocol provides a helpful list of the items that an auditor will review when assessing whether a covered entity is in compliance with HIPAA. We recommend using the audit protocol provided by HHS to assess whether existing policies generally pass muster. If existing policies generally meet the requirements in the audit protocol, it likely makes sense to update existing forms. If however, existing policies are generally lacking, it may be more cost effective to replace existing policies with new, Omnibus Rule-compliant, policies.

After the policies are finalized, the provider should formally adopt and approve the policies pursuant to any procedural requirements in the provider’s governing documents or standard operating procedures.

2. Staff Training.

It is important that a provider’s policies are both updated and implemented. Once a provider has updated its privacy policies, workforce members should receive training on any new and revised policies. In particular, management and higher-level employees should be fully trained on the new breach standard, so that, if necessary, they can correctly perform the required analysis.

Training is important both as a preventative measure and to ensure compliance with HIPAA and the HITECH Act. Training should be documented and maintained in the event training logs and program details are requested during an audit or investigation.

3. Notice of Privacy Practices.

The Omnibus Rule modifies and expands the content of the notice of privacy practices (NPP) that a provider is required to maintain and distribute to its patients. After a provider has updated its NPP, the provider must make the NPP readily available to existing patients who request a copy on or after the effective date of the revisions; must post the revised notice on its website, if applicable; and must post the notice in a prominent location on its premises. New patients who receive services for the first time after modification of an NPP should be provided with a copy of the revised NPP. Consistent with the existing rules, providers should retain copies of previous versions of their NPPs and of any written acknowledgements by patients of receipt of NPPs.

4. Business Associate Agreements.

Providers should revise their business associate agreement (BAA) form to reflect the new requirements under the Omnibus Rule. Providers must enter into new BAAs or modify existing BAAs by September 23, 2013. However, existing BAAs that were entered into on or before January 25, 2013 and have not been modified after March 26, 2013 do not have to be updated until September 23, 2014.

Once the provider has updated its form BAA, we recommend conducting an inventory of all current BAAs (including BAAs in which the provider is the covered entity and BAAs in which the provider is a business associate or subcontractor). Each of these BAAs will need to be modified by an amendment or replaced with the provider’s revised form BAA. This may also be a good opportunity to consider whether the protections and restrictions in the form agreement go far enough in protecting patients and the provider.

Providers should review all business relationships to ensure they have a BAA in place where one is required under HIPAA. Providers may have relationships that did not previously require a BAA, but do now under the Omnibus Rule’s expansion of the definition of “business associate.” One key change to the definition of business associate is the inclusion of subcontractors of business associates that deal with PHI. However, covered entities are not required to enter into BAAs with downstream subcontractors. Rather, the business associate who contracts with the subcontractor must enter into a BAA with the subcontractor.

In light of the numerous changes that have been made to HIPAA under the Omnibus Rule, it is important for providers to start working on compliance with the new requirements as soon as possible. Please contact the authors if you would like more information about compliance with the Omnibus Rule or HIPAA compliance generally.

(Source)