ONC Releases Updated Guide To Privacy And Security Of Electronic Health Information

FL
Foley & Lardner

Contributor

Foley & Lardner LLP looks beyond the law to focus on the constantly evolving demands facing our clients and their industries. With over 1,100 lawyers in 24 offices across the United States, Mexico, Europe and Asia, Foley approaches client service by first understanding our clients’ priorities, objectives and challenges. We work hard to understand our clients’ issues and forge long-term relationships with them to help achieve successful outcomes and solve their legal issues through practical business advice and cutting-edge legal insight. Our clients view us as trusted business advisors because we understand that great legal service is only valuable if it is relevant, practical and beneficial to their businesses.
The Meaningful Use Programs incorporate and require implementation of several key the HIPAA security requirements for ePHI.
United States Food, Drugs, Healthcare, Life Sciences

The Office of the National Coordinator for Health Information Technology ("ONC") of the U.S. Department of Health and Human Services ("HHS") recently released Version 2.0 of the Guide to Privacy and Security of Electronic Health Information ("Guide"). The Guide is a tool intended to assist providers as they work to comply with federal programs' requirements administered through HHS and its various offices (such as ONC).

Last published in 2011, the new 2015 version of the Guide provides updated information about compliance with the Medicare & Medicaid Electronic Health Record Incentive Programs (also called "Meaningful Use" Programs) as well as the changes made by the Health Information Technology and Economic Health Act ("HITECH") as implemented by the Omnibus Final Rule.

At a high level, the Guide includes practical information on issues facing providers such as cybersecurity and patient access to information through certified electronic health record ("EHR") technology features available under the 2014 Edition Certification rule. The Guide is a practicable and useful tool in that it walks providers though applicable rules and standards, addressing topics such as "why do privacy and security matter", "understanding provider responsibilities under HIPAA", "understanding electronic health records, the HIPAA security rule and cybersecurity" and "breach notification, HIPAA enforcement, and other laws and requirements".

The Guide also addresses the Meaningful Use Programs, which set requirements for providers to demonstrate progressively integrated use of EHRs and to receive incentives for such meaningful use. The Meaningful Use Programs incorporate and require implementation of several key the HIPAA security requirements for ePHI. The Guide describes the Meaningful Use security requirements (which require implementation of certain technical controls to safeguard of PHI against unauthorized access, audit controls, and an annual security risk assessment) and ways to satisfy these requirements.

With respect to HIPAA Privacy, Security, and Breach Notification Rules, the Guide addresses and provides information regarding what to do if a provider has a breach (distinguishing between secured and unsecured PHI), the risk assessment process for breaches, and how to report breaches. The Guide also describes the types of key state laws that may impose requirements that are more stringent than HIPAA.

Finally, the Guide provides a sample seven-step approach to implement a security management process, which the ONC indicates providers can use as a takeaway reference.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More