Providers and privacy groups confused over tentative security definition

Center for Public Integrity: Tentative Security Definition Confuses Health Care Providers, Privacy Groups
Doctors, hospitals and insurance companies using electronic health records are required by law to report security breaches to patients and the government — but only after they have done their own risk assessment to determine whether the breaches posed "significant harm" to patients. This standard, established as a temporary regulation by the Department of Health and Human Services' Office for Civil Rights, came under sharp criticism by Congress and privacy advocates when it was released Aug. 24, 2009. The term "significant harm" is subjective, they say, and skirts adequate transparency on the side of the health industry (Leonard, 6/29).


http://www.kaiserhealthnews.orgThis article was reprinted from kaiserhealthnews.org with permission from the Henry J. Kaiser Family Foundation. Kaiser Health News, an editorially independent news service, is a program of the Kaiser Family Foundation, a nonpartisan health care policy research organization unaffiliated with Kaiser Permanente.

Comments

The opinions expressed here are the views of the writer and do not necessarily reflect the views and opinions of News Medical.
Post a new comment
Post

While we only use edited and approved content for Azthena answers, it may on occasions provide incorrect responses. Please confirm any data provided with the related suppliers or authors. We do not provide medical advice, if you search for medical information you must always consult a medical professional before acting on any information provided.

Your questions, but not your email details will be shared with OpenAI and retained for 30 days in accordance with their privacy principles.

Please do not ask questions that use sensitive or confidential information.

Read the full Terms & Conditions.

You might also like...
How the gut microbiome links obesity to colorectal cancer