• Home
  • Practice Focus
    • Facial Plastic/Reconstructive
    • Head and Neck
    • Laryngology
    • Otology/Neurotology
    • Pediatric
    • Rhinology
    • Sleep Medicine
    • How I Do It
    • TRIO Best Practices
  • Business of Medicine
    • Health Policy
    • Legal Matters
    • Practice Management
    • Tech Talk
    • AI
  • Literature Reviews
    • Facial Plastic/Reconstructive
    • Head and Neck
    • Laryngology
    • Otology/Neurotology
    • Pediatric
    • Rhinology
    • Sleep Medicine
  • Career
    • Medical Education
    • Professional Development
    • Resident Focus
  • ENT Perspectives
    • ENT Expressions
    • Everyday Ethics
    • From TRIO
    • The Great Debate
    • Letter From the Editor
    • Rx: Wellness
    • The Voice
    • Viewpoint
  • TRIO Resources
    • Triological Society
    • The Laryngoscope
    • Laryngoscope Investigative Otolaryngology
    • TRIO Combined Sections Meetings
    • COSM
    • Related Otolaryngology Events
  • Search

HIPAA Expansion: Ensure your practice meets the law’s new provisions

by Steven M. Harris, Esq. • January 1, 2010

  • Tweet
  • Click to email a link to a friend (Opens in new window) Email
Print-Friendly Version

For the privacy rule, the HITECH Act imposes an obligation on both parties to police the compliance of the other party. For example, if a third-party service provider becomes aware of a pattern of activity or practice of the physician that constitutes a material breach of the physician’s obligations under the Business Associate Agreement, the service provider must take reasonable steps to cure the breach. What is a reasonable step will vary with the circumstances and nature of the parties’ relationship. If those steps prove to be unsuccessful in curing the breach, the service provider must either terminate the contract with the physician, if feasible, or report the problem to the Department of Health and Human Services (HHS).

You Might Also Like

  • Department of Health and Human Services’ Final Rule Expands HIPAA Obligations, Violation Penalties
  • Healthcare Providers Must Comply with HIPAA Privacy Practices
  • Omnibus Rule Compliance Deadline Imminent
  • Preparing for Increased HIPAA Audits Among Smaller Providers
Explore This Issue
January 2010

While HIPAA already requires physicians and business associates to enter into a written contract, existing agreements should be reviewed to determine whether they are sufficient under the HITECH Act and should be modified accordingly.

Notification Requirement

The HITECH Act requires covered entities and business associates that access, maintain, retain, modify, record, store, destroy, or otherwise hold, use, or disclose unsecured PHI to provide notification upon discovering a breach of unsecured PHI. “Breach” is generally defined as the unauthorized acquisition, access, use, or disclosure of unsecured PHI. “Unsecured PHI” is PHI that is not secured through the use of a technology or methodology that renders PHI “unusable, unreadable, or indecipherable to unauthorized individuals.”

A physician who discovers a breach of unsecured PHI should inform the patient; a service provider that discovers a breach of unsecured PHI should notify the physician. In general, the notice must be provided “without unreasonable delay and in no case later than 60 calendar days after the discovery of the breach.”

Beyond HIPAA

The HITECH Act imposes many new requirements on the medical community that were not required under HIPAA. Be sure that you have a Business Associate Agreement in place that complies with the new requirements. For additional information, visit www.hhs.gov.

Disclosures upon Patient Request

The HITECH Act also requires physicians to comply with patient requests to restrict the disclosure of any PHI that pertains to a health care item or service paid out of pocket in full, under certain circumstances.

Accounting of Electronic PHI

In general, HIPAA provides the patient with the right to receive an accounting of any disclosures of his or her PHI. As such, HIPAA requires business associates to make information available to the physician to enable the physician to provide this accounting of disclosures to the patient. Under the HITECH Act, the physician must provide an accounting of the disclosures of PHI made by the physician and either an accounting of the disclosures made by service providers acting on behalf of the physician or a list of all service providers acting on the physician’s behalf, along with their contact information.

Prohibition on the Sale of PHI

The HITECH Act generally prohibits physicians and service providers from receiving remuneration in exchange for a patient’s PHI, unless the physician obtains a valid authorization from the patient. This prohibition is subject to exceptions, however, when the purpose of the exchange is for research, treatment of an individual, payment from a physician to a third-party service provider for activities involving the exchange of PHI, or other reasons determined by HHS.

Penalties and Enforcement

The HITECH Act expands enforcement activities and penalties for violations of the law. In the event of noncompliance, the violating party may be subject to civil monetary penalties ranging from $100 to $1.5 million per violation, depending on the amount of neglect and intent involved.

Pages: 1 2 3 | Single Page

Filed Under: Departments, Health Policy, Legal Matters, Practice Management, Tech Talk Tagged With: finance, healthcare reform, HIPAA, patient safety, policy, Security, technologyIssue: January 2010

You Might Also Like:

  • Department of Health and Human Services’ Final Rule Expands HIPAA Obligations, Violation Penalties
  • Healthcare Providers Must Comply with HIPAA Privacy Practices
  • Omnibus Rule Compliance Deadline Imminent
  • Preparing for Increased HIPAA Audits Among Smaller Providers

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

The Triological SocietyENTtoday is a publication of The Triological Society.

Polls

Would you choose a concierge physician as your PCP?

View Results

Loading ... Loading ...
  • Polls Archive

Top Articles for Residents

  • Applications Open for Resident Members of ENTtoday Edit Board
  • How To Provide Helpful Feedback To Residents
  • Call for Resident Bowl Questions
  • New Standardized Otolaryngology Curriculum Launching July 1 Should Be Valuable Resource For Physicians Around The World
  • Do Training Programs Give Otolaryngology Residents the Necessary Tools to Do Productive Research?
  • Popular this Week
  • Most Popular
  • Most Recent
    • A Journey Through Pay Inequity: A Physician’s Firsthand Account

    • The Dramatic Rise in Tongue Tie and Lip Tie Treatment

    • Otolaryngologists Are Still Debating the Effectiveness of Tongue Tie Treatment

    • Is Middle Ear Pressure Affected by Continuous Positive Airway Pressure Use?

    • Rating Laryngopharyngeal Reflux Severity: How Do Two Common Instruments Compare?

    • The Dramatic Rise in Tongue Tie and Lip Tie Treatment

    • Rating Laryngopharyngeal Reflux Severity: How Do Two Common Instruments Compare?

    • Is Middle Ear Pressure Affected by Continuous Positive Airway Pressure Use?

    • Otolaryngologists Are Still Debating the Effectiveness of Tongue Tie Treatment

    • Complications for When Physicians Change a Maiden Name

    • Excitement Around Gene Therapy for Hearing Restoration
    • “Small” Acts of Kindness
    • How To: Endoscopic Total Maxillectomy Without Facial Skin Incision
    • Science Communities Must Speak Out When Policies Threaten Health and Safety
    • Observation Most Cost-Effective in Addressing AECRS in Absence of Bacterial Infection

Follow Us

  • Contact Us
  • About Us
  • Advertise
  • The Triological Society
  • The Laryngoscope
  • Laryngoscope Investigative Otolaryngology
  • Privacy Policy
  • Terms of Use
  • Cookies

Wiley

Copyright © 2025 by John Wiley & Sons, Inc. All rights reserved, including rights for text and data mining and training of artificial technologies or similar technologies. ISSN 1559-4939