Stimulus Package Includes New HIPAA Security Rules
Small Practices Face Greatest Financial Impact
By Sheri Porter
3/18/2009
According to provisions in the legislation, physicians now will be required to track any disclosure of a patient's medical information. Previous regulations allowed physicians to disclose patient information for the purpose of treatment, payment or health care operations, but they were not required to track when that information was disclosed.
However, the new legislation requires physicians who use an electronic health record, or EHR, to "have the ability to track every time (patient) information has been disclosed," said Robert Tennant, a senior policy advisor for the Colorado-based Medical Group Management Association, or MGMA.
Although the provision doesn't kick in for current EHR users until Jan. 1, 2014, patients will be able to request an accounting of disclosures of their electronic personal health information three years from the date of the request, potentially dating back to 2011.
In addition, the legislation requires practices to post information about security breaches if a breach affects 10 or more patients. If a security breach affects 500 or more patients, practices must notify all of their patients, a local media outlet, and the HHS secretary.
"It's very similar to what is occurring in a lot of states that have laws against identity theft," said Mike Fleischman, a principal of Gates, Moore and Co., an Atlanta-based health care consulting and accounting firm.
Even a small family medicine practice could have thousands of patient records in its database, said Tennant. A stolen laptop computer or misplaced PDA could potentially compromise large amounts of patient data.
The new legislation also calls for beefed up enforcement rules and a new aggressiveness in assigning fines. Fines for security breaches start at $100 and can go as high as $1.5 million.
In addition, the legislation empowers state attorneys general to enforce some HIPAA elements and gives them the authority to bring class action suits, said Fleischman.
Impact on Physicians
The upside is that the regulations will give consumers more control over their personal health information, said Kibbe. "But the regulations will also likely increase the uncertainty, complexity, cost and risk for anyone or any organization who collects, stores, manages or transmits personal health information."
He noted that provisions of the HITECH Act were long debated and "reflect a compromise that most people on Capitol Hill like."
Tennant said he's focusing on how the provisions apply to family medicine practices and how they will affect physicians' ability to treat patients. Overall, he sees the provisions as adding a "new layer of confusion that can't do anything positive to patient care."
He also pointed out that there is no stimulus money provided to help physicians shore up their privacy policies and procedures. "This is all money that comes off (physicians') bottom line," said Tennant.
Fleischman countered that although there was no immediate cause for alarm, physicians should be aware of the rules that pertain to them. He called the new legislation "a tweaking" of the HIPAA regulations from 1996.
The biggest change affects physicians' business associates, said Fleischman. They now will be required to fully comply with HIPAA privacy and security rules. That means clearinghouses, accountants, lawyers and others who support physicians and have access to protected health information will have more culpability in terms of privacy violations.
What to Do
He also suggested that physicians go back and review HIPAA policy in general, paying particular attention to new staff members who may not be up to snuff on privacy policies and procedures.
"There's a new sheriff in town and what used to be a minor infraction … could very well lead to a substantial fine," said Tennant. "What you don't want is for the practice to make a mistake simply because staff weren't trained or weren't aware."
Tennant and Fleischman agreed that physicians should keep a close eye on pertinent government appointments because even though some of the new regulations take effect almost immediately, much of the content in the HITECH Act will be fleshed out during the coming months.
"We're waiting to see what the new HHS secretary and CMS administrator will do in terms of crafting regulations to support and further define the legislation," said Tennant.
Concerns About Unintended Consequences
Small practices have fewer financial resources and, therefore, have fewer options, said Kibbe. "Put very bluntly, the small medical practice is going to face additional costs for health IT implementation as a result of the HITECH Act's amendments to HIPAA."
Kibbe also is wary of possible unintended consequences from the audit reports that will be necessary to account for disclosures of patient information. He called them "technically challenging and operationally burdensome," and he didn't think any of the EHRs currently marketed for ambulatory care could provide the reports.
Physicians contemplating an EHR purchase -- an action the feds desperately want physicians to take -- might further delay their purchases "until they know the products have this feature and that it works," cautioned Kibbe.
Steven Waldren, M.D., director of the AAFP's Center for Health IT, said the Academy soon would be making additional educational resources available to help members further understand and comply with the government's latest privacy and security regulations.
AAFP Applauds House Passage of SGR Bill
AAFP Puts Muscle Behind Support for Bill to Fix SGR Formula
AAFP Continues to Press Congress on Health Care Reform
AAFP Letter to House Speaker Expresses Support for Reform Legislation
MedPAC Members Call RBRVS System Subjective, 'Deeply Flawed'
AAFP Leaders Make Case for Family Medicine in Capitol Hill Visits
Legislation Providing Permanent SGR Fix Dies in Senate
Legislation Could Fix SGR Formula
AAFP Supports Rural Physician Legislation
AAFP Leaders, Obama Discuss Health Care Reform in White House Meeting
AAFP President Praises Senate Bill, But Has Some Concerns
Physician Groups Call On Congress to Replace SGR
Obama Rallies Health Care Reform Support
Monday Last Opportunity to Comment on Fee Schedule
Primary Care Key Component of Health Care Reform
AAFP Leaders Engage White House Officials on Reform
Roundtable on Reform Spotlights Primary Care
AAFP Comments on Physician Fee Schedule
Stimulus Funds Help Health Centers
Medicaid EHR Bonus Provides Stimulus
Final Approval Lacking for Medical Home Project
AAFP Board Chair Makes Case for Health Care Reform on Capitol Hill
FP Praises Health IT Bill in Congressional Testimony
Obama Pushes for Health Care Reform in Prime Time News Conference
PCPCC: Feds Call Primary Care 'Fundamental' to Reform
Health IT, Primary Care Come Out Ahead in Massive Stimulus Bill
Approved Legislation Addresses Key AAFP Issues
(2/13/2009)
Experts Urge Congress to Move Ahead With HIT Carefully
(1/21/2009)
More From AAFP
HIPAA Privacy
HIPAA Security








