This was successfully posted to your pofile.
This box will close automatically in a few seconds. Close this window
We don't have an e-mail address on file for you. To use AAFP Connection, you must have an e-mail address in our records. Click Here
Stimulus Package Includes New HIPAA Security Rules
Small Practices Face Greatest Financial Impact
By Sheri Porter
According to provisions in the legislation, physicians now will be required to track any disclosure of a patient's medical information. Previous regulations allowed physicians to disclose patient information for the purpose of treatment, payment or health care operations, but they were not required to track when that information was disclosed.
However, the new legislation requires physicians who use an electronic health record, or EHR, to "have the ability to track every time (patient) information has been disclosed," said Robert Tennant, a senior policy advisor for the Colorado-based Medical Group Management Association, or MGMA.
Although the provision doesn't kick in for current EHR users until Jan. 1, 2014, patients will be able to request an accounting of disclosures of their electronic personal health information three years from the date of the request, potentially dating back to 2011.
In addition, the legislation requires practices to post information about security breaches if a breach affects 10 or more patients. If a security breach affects 500 or more patients, practices must notify all of their patients, a local media outlet, and the HHS secretary.
"It's very similar to what is occurring in a lot of states that have laws against identity theft," said Mike Fleischman, a principal of Gates, Moore and Co., an Atlanta-based health care consulting and accounting firm.
Even a small family medicine practice could have thousands of patient records in its database, said Tennant. A stolen laptop computer or misplaced PDA could potentially compromise large amounts of patient data.
The new legislation also calls for beefed up enforcement rules and a new aggressiveness in assigning fines. Fines for security breaches start at $100 and can go as high as $1.5 million.
In addition, the legislation empowers state attorneys general to enforce some HIPAA elements and gives them the authority to bring class action suits, said Fleischman.
Impact on Physicians
The upside is that the regulations will give consumers more control over their personal health information, said Kibbe. "But the regulations will also likely increase the uncertainty, complexity, cost and risk for anyone or any organization who collects, stores, manages or transmits personal health information."
He noted that provisions of the HITECH Act were long debated and "reflect a compromise that most people on Capitol Hill like."
Tennant said he's focusing on how the provisions apply to family medicine practices and how they will affect physicians' ability to treat patients. Overall, he sees the provisions as adding a "new layer of confusion that can't do anything positive to patient care."
He also pointed out that there is no stimulus money provided to help physicians shore up their privacy policies and procedures. "This is all money that comes off (physicians') bottom line," said Tennant.
Fleischman countered that although there was no immediate cause for alarm, physicians should be aware of the rules that pertain to them. He called the new legislation "a tweaking" of the HIPAA regulations from 1996.
The biggest change affects physicians' business associates, said Fleischman. They now will be required to fully comply with HIPAA privacy and security rules. That means clearinghouses, accountants, lawyers and others who support physicians and have access to protected health information will have more culpability in terms of privacy violations.
What to Do
He also suggested that physicians go back and review HIPAA policy in general, paying particular attention to new staff members who may not be up to snuff on privacy policies and procedures.
"There's a new sheriff in town and what used to be a minor infraction … could very well lead to a substantial fine," said Tennant. "What you don't want is for the practice to make a mistake simply because staff weren't trained or weren't aware."
Tennant and Fleischman agreed that physicians should keep a close eye on pertinent government appointments because even though some of the new regulations take effect almost immediately, much of the content in the HITECH Act will be fleshed out during the coming months.
"We're waiting to see what the new HHS secretary and CMS administrator will do in terms of crafting regulations to support and further define the legislation," said Tennant.
Concerns About Unintended Consequences
Small practices have fewer financial resources and, therefore, have fewer options, said Kibbe. "Put very bluntly, the small medical practice is going to face additional costs for health IT implementation as a result of the HITECH Act's amendments to HIPAA."
Kibbe also is wary of possible unintended consequences from the audit reports that will be necessary to account for disclosures of patient information. He called them "technically challenging and operationally burdensome," and he didn't think any of the EHRs currently marketed for ambulatory care could provide the reports.
Physicians contemplating an EHR purchase -- an action the feds desperately want physicians to take -- might further delay their purchases "until they know the products have this feature and that it works," cautioned Kibbe.
Steven Waldren, M.D., director of the AAFP's Center for Health IT, said the Academy soon would be making additional educational resources available to help members further understand and comply with the government's latest privacy and security regulations.
Health IT, Primary Care Come Out Ahead in Massive Stimulus Bill
Approved Legislation Addresses Key AAFP Issues
(2/13/2009)
Experts Urge Congress to Move Ahead With HIT Carefully
(1/21/2009)
More From AAFP
HIPAA Privacy
HIPAA Security
This was successfully posted to your pofile.
This box will close automatically in a few seconds. Close this window
We don't have an e-mail address on file for you. To use AAFP Connection, you must have an e-mail address in our records. Click Here
PCMH Is Answer to Medicare Payment Problems
Physician Groups Unite to Call for SGR Repeal
Threatened Medicare Payment Cuts Cause Chaos for FPs
AAFP, Medical Organizations Push for SGR Repeal
Focus of Conference Call is Shared Savings, Advance Payment
FPs Can Expect Slight Changes in Medicare Pay for 2012
HHS Approach to Essential Health Benefits Falls Flat
CMS Delays Implementation of 'Sunshine Act'
Congress Works Out Temporary Solution to SGR Cut
Community-based Residencies Would Benefit From House Bill
GME Funding to Remain Level in 2012
House Rejects Measure to Block Medicare Pay Cut
House Addresses Medicare Payment Cut
AAFP Backs Tavenner as New CMS Administrator
Supercommittee Fails to Address SGR
Overcoming Scarce Resources to Enact Health Care Reform
Medicare Payment: Value Is as Important as Volume
AAFP President-elect Makes Return Visit to Capitol Hill
Insurance Exchanges, CO-OPs Might Provide Opportunity for FPs
AAFP Members Speak Out on Title VII Funding
Campaign Addresses Need for Medicare Payment Reform
AAFP Continues to Press Congress for Payment Solution
AAFP Leaders Take On Washington
Campaign Focuses on GME Outreach
'Family Medicine Matters,' AAFP Members Tell Congress
AAFP Outlines Suggested Changes for CO-OP Program
Groups Call on Supercommittee to Address Medical Liability Reform
Grassroots Efforts to Repeal SGR Continue
Bill Linking Mandatory Education to Prescribing Not Needed
Blended Payment Model Gives Boost to Primary Care Services
AAFP Joins AMA, Other Groups in Calling for SGR Repeal
Eliminating SGR May Come With High Price
Tobacco Oversight Must Include Cigars, Say AAFP, Other Groups
AAFP Rallies Congress of Delegates on Medicare Payment
AMA Task Force Focuses on Fixing the SGR
2012 Physician Fee Schedule Needs Work, Says AAFP
New Task Force Takes Steps to Better Value Primary Care
Deficit-reduction Plan Must Eliminate SGR, Says AAFP
Physicians File Lawsuit Over RUC, CMS Relationship
Policy Brief Explains HHS Insurance Exchange Plans
