• Home
  • Practice Focus
    • Facial Plastic/Reconstructive
    • Head and Neck
    • Laryngology
    • Otology/Neurotology
    • Pediatric
    • Rhinology
    • Sleep Medicine
    • How I Do It
    • TRIO Best Practices
  • Business of Medicine
    • Health Policy
    • Legal Matters
    • Practice Management
    • Tech Talk
    • AI
  • Literature Reviews
    • Facial Plastic/Reconstructive
    • Head and Neck
    • Laryngology
    • Otology/Neurotology
    • Pediatric
    • Rhinology
    • Sleep Medicine
  • Career
    • Medical Education
    • Professional Development
    • Resident Focus
  • ENT Perspectives
    • ENT Expressions
    • Everyday Ethics
    • From TRIO
    • The Great Debate
    • Letter From the Editor
    • Rx: Wellness
    • The Voice
    • Viewpoint
  • TRIO Resources
    • Triological Society
    • The Laryngoscope
    • Laryngoscope Investigative Otolaryngology
    • TRIO Combined Sections Meetings
    • COSM
    • Related Otolaryngology Events
  • Search

Healthcare Providers Must Comply with HIPAA Privacy Practices

by Steven M. Harris, Esq. • August 1, 2013

  • Tweet
  • Click to email a link to a friend (Opens in new window) Email
Print-Friendly Version

You Might Also Like

  • Department of Health and Human Services’ Final Rule Expands HIPAA Obligations, Violation Penalties
  • HIPAA Privacy and Security Standards for the Electronic Office
  • HIPAA Expansion: Ensure your practice meets the law’s new provisions
  • Preparing for Increased HIPAA Audits Among Smaller Providers
Explore This Issue
August 2013

Steven M. Harris, Esq. “Failure to have an updated Notice of Privacy Practices by September 23 is a violation of HIPAA and could result in fines and penalties.”

—Steven M. Harris, Esq.

In my May 2013 article, “HIPAA Changes,” I noted that as part of the recent changes to the Health Insurance Portability and Accountability Act of 1996 (HIPAA), health care providers are required to update their “Notices of Privacy Practices.”

If you are a health care provider (e.g., medical practice, physician, hospital) and either do not have a Notice of Privacy Practices or have not updated your Notice of Privacy Practices in 2013, now is the time to get compliant. Failure to have an updated Notice of Privacy Practices by September 23, 2013 is a violation of HIPAA and could result in fines and penalties.

Background

In January 2013, the Office for Civil Rights (OCR) of the Department of Health and Human Services (HHS) issued an omnibus final rule (Final Rule) implementing various provisions of the Health Information Technology for Economic and Clinical Health Act (HITECH Act). The Final Rule revises HIPAA, and included in that rule are requirements affecting Notices of Privacy Practices.

What is a “Notice of Privacy Practices”?

A Notice of Privacy Practices is a written notice that health care providers are required under HIPAA and the HITECH Act to provide to patients that explains the patients’ rights as they relate to their health information and the privacy practices of the health care provider. Notices of Privacy Practices are intended to inform patients of their privacy rights, and to encourage patients to have discussions with their health care providers about these rights.

What Must Be Included in Notices of Privacy Practices?

Health care providers are required to provide patients with a Notice of Privacy Practices that is written in plain language and includes a number of elements.

First, Notices of Privacy Practices must describe how the health care provider can use and disclose a patient’s protected health information. A new change imposed by the Final Rule mandates that Notices of Privacy Practices include a description of certain types of uses and disclosures of protected health information that require an authorization. Now, Notices of Privacy Practices must explicitly state that if a health care provider will use or disclose a patient’s health care information for marketing purposes or in a sales transaction (receipt of remuneration in exchange for patient health information), or if such health information includes psychotherapy notes, then the health care provider must first obtain an authorization. Further, the authorization must explicitly acknowledge that remuneration is involved.

Second, Notices of Privacy Practices must contain a statement of the patient’s rights with respect to his or her health information and how the patient can exercise these rights. Such rights include the right to 1) request restrictions on certain uses and disclosures of a patient’s health information; 2) receive confidential communications of a patient’s health information; 3) inspect and copy records containing a patient’s health information; 4) amend such records; 5) receive an accounting of disclosures of a patient’s health information; and 6) receive a paper copy of the Notice of Privacy Practices.

Third, Notices of Privacy Practices must identify the health care provider’s legal duties with respect to patients’ protected health information by including a statement that the health care provider is required by law to maintain the privacy of protected health information. A new change imposed by the Final Rules mandates that Notices of Privacy Practices include a statement that the health care provider notify the patient in the event of a breach of the patient’s unsecured protected health information.

Also, Notices of Privacy Practices must include a statement explaining how patients can submit complaints regarding their privacy rights, and whom patients can contact for more information about the health care provider’s privacy policies.

Implementing and Revising the Notice of Privacy Practices

Absent an emergency situation, health care providers with direct patient contact must make the Notice of Privacy Practices available to patients no later than when service is first delivered to the patient. Health care providers with a physical service delivery site must have the Notice of Privacy Practices available onsite and posted in a clear and prominent location. In addition, if the health care provider has a website that includes information about the services offered, the Notice of Privacy Practices must also be prominently posted on the website.

Whenever the Notice of Privacy Practices is revised, the health care provider must promptly distribute the updated version to patients. The Notice of Privacy Practices must be available to patients upon request on or after the effective date of the revision, and shall be available onsite at the facility and posted in a clear and prominent

location. If a website is maintained, the updated Notice of Privacy Practices will also need to be posted on the website.

Health care providers are required to make a good faith effort to obtain a written acknowledgement from the patient that he or she received the Notice of Privacy Practices. If the Notice of Privacy Practices has been revised since the patient’s last written acknowledgment, a new written acknowledgment from the patient should be obtained. If a written acknowledgment is not obtained, the health care provider should document the good faith efforts to obtain the acknowledgment and the reason why it was not obtained.

Action Steps

Now is the time to get compliant. If you either do not have a Notice of Privacy Practices or have not updated your Notice of Privacy Practices to include the changes mandated by the Final Rule, you must do so before the September 23, 2013 deadline. Contact a health attorney experienced in HIPAA and HITECH Act matters to create a Notice of Privacy Practices for your practice.


Steven M. Harris, Esq., is a nationally recognized health care attorney and a member of the law firm McDonald Hopkins, LLC. He may be reached at sharris@mcdonaldhopkins.com.

Reprinted with permission from the American College of Rheumatology.

Pages: 1 2 3 | Multi-Page

Filed Under: Departments, Legal Matters Tagged With: HIPAA, legal, policyIssue: August 2013

You Might Also Like:

  • Department of Health and Human Services’ Final Rule Expands HIPAA Obligations, Violation Penalties
  • HIPAA Privacy and Security Standards for the Electronic Office
  • HIPAA Expansion: Ensure your practice meets the law’s new provisions
  • Preparing for Increased HIPAA Audits Among Smaller Providers

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

The Triological SocietyENTtoday is a publication of The Triological Society.

Polls

Would you choose a concierge physician as your PCP?

View Results

Loading ... Loading ...
  • Polls Archive

Top Articles for Residents

  • Applications Open for Resident Members of ENTtoday Edit Board
  • How To Provide Helpful Feedback To Residents
  • Call for Resident Bowl Questions
  • New Standardized Otolaryngology Curriculum Launching July 1 Should Be Valuable Resource For Physicians Around The World
  • Do Training Programs Give Otolaryngology Residents the Necessary Tools to Do Productive Research?
  • Popular this Week
  • Most Popular
  • Most Recent
    • A Journey Through Pay Inequity: A Physician’s Firsthand Account

    • The Dramatic Rise in Tongue Tie and Lip Tie Treatment

    • Otolaryngologists Are Still Debating the Effectiveness of Tongue Tie Treatment

    • Is Middle Ear Pressure Affected by Continuous Positive Airway Pressure Use?

    • Rating Laryngopharyngeal Reflux Severity: How Do Two Common Instruments Compare?

    • The Dramatic Rise in Tongue Tie and Lip Tie Treatment

    • Rating Laryngopharyngeal Reflux Severity: How Do Two Common Instruments Compare?

    • Is Middle Ear Pressure Affected by Continuous Positive Airway Pressure Use?

    • Otolaryngologists Are Still Debating the Effectiveness of Tongue Tie Treatment

    • Complications for When Physicians Change a Maiden Name

    • Excitement Around Gene Therapy for Hearing Restoration
    • “Small” Acts of Kindness
    • How To: Endoscopic Total Maxillectomy Without Facial Skin Incision
    • Science Communities Must Speak Out When Policies Threaten Health and Safety
    • Observation Most Cost-Effective in Addressing AECRS in Absence of Bacterial Infection

Follow Us

  • Contact Us
  • About Us
  • Advertise
  • The Triological Society
  • The Laryngoscope
  • Laryngoscope Investigative Otolaryngology
  • Privacy Policy
  • Terms of Use
  • Cookies

Wiley

Copyright © 2025 by John Wiley & Sons, Inc. All rights reserved, including rights for text and data mining and training of artificial technologies or similar technologies. ISSN 1559-4939