New HIPAA-HITECH rules for mental health centers and private practices
HIPAA Compliance: What You Need to Know About the New HIPAA-HITECH RulesCounselors who have not already done so will need to update their policies and contracts tocomply with new HIPAA rules added by the Health Information Technology for Economic andClinical Health Act (HITECH). If you think HIPAA is no big deal or don't have a clue whatHITECH means, this could be a wake-up call.On January 17, 2013, the U.S. Department of Health and Human Services (HHS) Office for CivilRights (OCR) issued the final omnibus HIPAA-HITECH rules (45 CFR Parts 160 and 164) withan enforcement date of September 22, 2014.Unfortunately, pleading ignorance won’t get you very far with HHS or the attorneys general ofyour state. The term “did not know” is actually one of three penalty categories for violating thenew HIPAA-HITECH rules, along with “reasonable cause” and “willful neglect.” All of them comewith penalties. In the “did not know” category, a breach will cost you $100–$50,000 for eachpersonal health information (PHI) item.If it has been a while since you brushed up on HIPAA-HITECH, you may be surprised to findthat PHI and electronic PHI (ePHI) includes any of the following pertaining to a client: first name,last name, e-mail, ZIP code (yes, ZIP code), city, county, phone number, IP address and more(18 items in all). But hey, at least there’s a $1,500,000 annual cap on penalties! Bottom line, itwould not be an overstatement to say these penalties would be devastating to a private practiceor one’s professional career. It is time to get serious about HIPAA-HITECH.Enforcement is not just in hospitals anymore. HHS.gov cites several case examples ofenforcement in mental health centers and private practices.Read the whole article at http://www.nbcc.org/assets/HIPAA_Compliance.pdf
Comments