Showing posts with label PHI. Show all posts
Showing posts with label PHI. Show all posts

Saturday, March 1, 2014

Faxing error causes United Healthcare breach

A Portland, Oregon man has been receiving erroneous faxes containing protected health information (PHI) from Community Memorial Hospital patients through an apparent error with United Healthcare, an insurance company, according to a report from 620WTMJ.com.
The initial fax, which included patient names, dates of birth, patient ID numbers, admission dates, and discharge dates, was sent to Stephen Butler’s home about a year ago. After tracing the number to Community Memorial Hospital in Menomonee Falls, Wisconsin, Butler called the hospital to inform them of the error.
Froedtert Health, which runs Community Memorial Hospital, was alerted of the breach through a patient of the hospital who had been contacted by Butler. After an investigation, the breach was determined to be caused by United Healthcare.
While United has not yet been able to determine if the breach was a result of human error or a glitch in their system, a representative issued 602WTMJ a statement saying, “We were alerted by Froedtert Health about this issue earlier today, and we are working closely with them to investigate and determine the facts. We take very seriously the privacy and personal information of our members.”


Friday, November 15, 2013

Data Mining, Meaningful Use, Secondary Use, & Potential Misuse of Electronic Health Records



Donna Hanrahan
Donna Hanrahan
Ethical Technology

Posted: Nov 15, 2013

Healthcare providers are establishing electronic health record (EHR) systems at an astonishing rate, due in part to the Health Information Technology for Economic and Clinical Health (HITECH) Act. The HITECH Act was created as a part of the American Recovery and Reinvestment Act of 2009.
i The $27 billion dollar piece of legislation offers eligible providers incentives for expanding the use of healthcare information technology (HIT).ii This includes promoting the “meaningful use” of EHRs. The “meaningful use” standard was designed to use HIT to improve quality of care and health outcomes for patients, as well as to lower costs by eliminating repeat medical tests and reducing preventable medical errors that pervade the health-care system today. This legislation has been extremely effective in persuading healthcare providers to use of electronic health records. In fact, the incentives outlined in the HITECH Act are estimated to increase EHR adoption rates to 90% of all physicians by 2019.iii Despite healthcare technology’s vast potential to improve patient health in the medical arena, there exists a host of complex legal, technical, and ethical concerns surrounding the use of HIT as incentivized in the HITECH Act, namely issues of privacy, confidentiality, autonomy, and the preservation of the physician-patient relationship.
The HITECH Act and “Meaningful Use”
The Health Information Technology for Economic and Clinical Health (HITECH) Act offers hospitals and eligible healthcare professionals incentives for expanding the use of healthcare information technology, including the “meaningful use” of EHRs.iv Incentive payments are made available through the Medicaid and Medicare programs. The Centers for Medicare & Medicaid Services (CMS) judges whether a health care provide has satisfied the meaningful use core objectives through the use certified health technologies.
The Department of Health and Human Services defines meaningful use as using certified EHR technology to: (1) improve quality, safety, efficiency, and reduce health disparities; (2) engage patients and families; improve care coordination, and population and public health; and (3) maintain privacy and security of patient health information.v The “meaningful use” framework incentivizes improvement to clinical care and quality by encouraging healthcare professionals to take advantage of instantaneous and patient-specific information. There are three stages of “meaningful use.” The first stage is the use of HIT for basic data collection, including demographic and medication history. The second stage is the use of EHR data to improve clinical processes including patient controlled data, clinical decision support, health information exchange (HIE), and quality measurement and research. The third stage is the use of EHR data to improve health outcomes, quality, safety, efficiency, and population health at the national level.vi Hospitals and providers eligible for the EHR Incentive Program do not need to attest to meaningful use in their first year of participation. Rather, they must simply implement an EHR to receive an incentive payment from their State.
The incentive payments under HITECH are quite substantial. To receive payments, eligible professionals and hospitals must meet at least 5 of the “meaningful use” criteria defined, consisting of 15 core data points and 10 menu options.vii These criteria include the entry of patient demographic and insurance information,
e-prescribing, and the use of drug interaction software to ensure patient safety.viii Eligible professionals and hospitals that meet the criteria can be rewarded up to $44,000 in Medicare and $63,750 in Medicaid payments over 5 years. After 2015, physicians who fail to meaningfully use EHRs will be subject to reductions in Medicare and Medicaid reimbursement.ix
Health Information Exchanges
The HITECH Act is a step towards the eventual goal of a national, interoperable, private, and secure electronic system to allow information to be shared among all the sites where patients receive care.x While still in its infancy, Health Information Exchanges (HIEs) are being established at the community, state, and national level to facilitate the electronic exchange between systems. The State Health Information Exchange Cooperative Agreement and the Nationwide Health Information Network (NHIN) received $600 million in federal funding to create a platform for health information exchange across the United States. xi At the state level, governments are creating statewide health information networks (HINs). At the national level, the Office of the National Coordinator (ONC), which oversees deployment of the HITECH Act, is executing plan to create a National Health Information Network (NHIN). Provider organizations participating in NHIN include Kaiser Permanente, the Cleveland Clinic, and the Veterans Administration.
These networks can lead to the development of data repositories filled with rich sets of health data for millions of individuals. Such data repositories can provide researchers with information necessary to improve quality of care and make significant discoveries in medicine that they may not otherwise have access to. Despite their great potential, progress in developing HIEs and repositories has been gradual. Many hospitals and clinics are hesitant to implement the systems because they do not have the finances or infrastructure necessary to do so. Moreover, there are also significant concerns over patient privacy and autonomy, which is to be discussed “Ethical Implications” sections below.
Secondary Use of Health Data
Until recently, collecting data for “secondary use” was an arduous task. “Secondary use” in healthcare is defined as the use of information collected from health records, electronic or manual, outside of direct patient care delivery. This includes data collection for the purpose of “research, quality and safety measurement, public health, payment, provider certification or accreditation, marketing, and other business applications.”xii Such use of healthcare data in biomedical research has the potential to drastically improve the quality and affordability of healthcare services in the United States. EHRs contain structured information about patients, which is extremely valuable in research because now information can be retrieved in a much quicker and more efficient fashion than more traditional methods of record keeping. Researchers can develop algorithms to search through EHRs, including free-text clinician notes, to find data valuable to a specific study.xiii
The effective secondary use of health data for research has great potential to improve health outcomes, reduce medical errors, predict health trends, and demonstrate the comparative value of drugs and other treatments.xivOther benefits include the increased ability to analyze the efficacy of treatment options and identify evidence-based best practices. Furthermore, predictive modeling techniques may be applied to electronic health data to identify medical conditions before the onset of symptoms and promote earlier interventions. While experimental studies, such as randomized controlled clinical trials, are likely to continue to be the gold standard of clinical research compared to observational studies, they more expensive and time consuming. As such, electronic health data serves as a rich resource for the conduction of observational studies.
Nevertheless, the unprecedented surge in the amount of healthcare data, as well as the relative ease with which that data can be aggregated and exchanged between providers and researcher will raise ethical questions about its use in research, specifically concerning patient privacy and autonomy. The Health Insurance Portability and Accountability Act (HIPAA) requires patient health information (PHI) to be de-identified or authorized by the patient for release. However, de-identified data would omit significant clinical, demographic, and time-related data that would render the data sets much less useful for many research purposes. While de-identified data is invalid and leads to incomplete data sets, it seems like is a small price to pay for protected the privacy of patients, especially those with stigmatized conditions.
Accordingly, researchers are forced to walk a fine line between ensuring patient privacy and maximizing the descriptive power of their data sets. Before the value of secondary use can be fully realized, ethical considerations surrounding the mining of electronic health data must be explored, namely infringements on an individual's privacy, confidentiality, and autonomy. It is necessary to establish a national framework of policies for the secondary use electronic health data to allow stakeholders to harness valuable information to improve the U.S. health care systems while maintaining patient autonomy and privacy protections.xv
Ethical Implications of EHRs and Meaningful Use: Data Quality Concerns
The mass of recent electronic health data makes it possible to assess the overall burden of disease and evaluate the impact of interventions on a national scale. Despite its promise, research through electronic health data mining and “secondary use” is not without flaws. Data quality concerns are inherent in data that is being used for any purpose other than what it was originally intended, especially considering the fragmented nature of the healthcare industry and the numerous platforms on which data is being collected.xvi First, there are hundreds of different EHR systems, each with a distinct representation of data that makes it difficult to aggregate. Second, even within the same EHR system, information incompleteness, inaccuracy, and inconsistency are common challenges, as different healthcare professionals tend to use the same system differently.xvii Third, clinicians tend to prefer using free text compared to structured data entry because it is more easily adapted to their individual practice styles and work flows, although it may make it more difficult to compile and analyze. xviii While there are established clinical coding standards such as SNOMED and ICD-9 to facilitate easier data aggregation, consistency has still proved to be a challenge in clinical research. Fourth, incomplete and duplicate records threaten the quality of research using data mined from EHRs.
Furthermore, some critics may argue that EHRs make it more possible for clinician to falsify charts and reports, which would lead to both data quality and trust issues with patients. However, the falsification of records would not only violate the moral imperative against lying, but also infringe on the fiduciary relationship between the physician and patient. Furthermore, there are methods to protect against such acts, include audits, fraud charges, and reclamation of funds under the False Claims Act and the Deficit Reduction Act.xix These measures act as valid disincentives to data falsification when it comes to patient records. Lastly, while the incentives and mandates of HITECH and “meaningful use” have led to an enormous amount of data being stored and generated by the U.S. healthcare system, there is an extreme lack of interoperability. The electronic data exists in different formats on hundreds of different systems.
Aggregating this sizeable amount of this data for research purposes will prove difficult, if not impossible, without a national regulatory framework to reduce intersystem variation and improve data quality. The federal government must determine national data standards or guidelines and clinicians to decrease data variation between systems. By implementing legislation to address these issues, the federal government can alleviate many ethical concerns and while allowing the United States healthcare system to benefits from more effective and larger scale use of secondary data.
Ethical Implications of EHRs and Meaningful Use: HIPAA and Privacy Concerns
With improved access to data comes increased risk of wrongful disclosure of patient health information. EHR data is at risk of human error, hacking, IT glitches, and theft of hardware than contains such information. HITECH challenges certain the notions of privacy and security found in the Health Insurance Portability and Accountability Act of 1996 (HIPAA), yet enhances others. HIPAA prohibits the disclosure of protected health information (PHI) without the consent of the patient except for the purposes treatment, payment, or healthcare operations. Under HIPAA, “business associates” of covered entities with access to PHI are not directly regulated. xx Rather, they are obliged to comply with HIPAA pursuant to mandatory written agreements within the covered entities for which they work. The HITECH Act, on the other hand, provides for regulation of business associates and stipulates that HIPAA’s privacy and security rules directly apply to them.
When it comes to a security breaches involving PHI, HITECH mandates public notification when unsecure, unencrypted PHI is disclosed or used for an unauthorized purpose, similar to many state and federal financial data breach laws. The HITECH Act also requires that patients be notified of both internal and external breach of their data security. If a breach affects over 500 patients, the Department of Health and Human Services (HHS) must also be notified and the name of the breaching institution will be posted on the HHS web site. There are also certain circumstances where local media will need to be notified to inform the public of breaches than effect many people within a given area.xxi
While HITECH is a federal law, it the Department of Health and Human Services and state attorneys general are granted with the authority to enforce the law. Subtitle D of the HITECH Act addresses the privacy and security concerns of EHRS by strengthening both the civil and criminal enforcement of the HIPAA rules. xxii Section 13410(d) of the HITECH Act revised the Social Security Act by establishing significant penalties for violation of security policy of the HITECH Act.xxiii If an institution or individual is unaware of a violation despite due diligence, the minimum penalty is $100 per violation, with a cap of $25,000 for violations of an identical requirement within the same year.xxiv If the security violation is due to “willful neglect,” the minimum penalty is $10,000 per violation, with a cap of $250,000. xxv The maximum penalty is $50,000 per violation, with a cap of $1.5 million. xxviThese are clear examples of the HITECH’s acts attempts to deter data breaches and mitigate security concerns.
The healthcare industry continues to tread carefully when it comes pursuing “meaningful use” of HIT while protecting patient privacy under HIPAA regulations. Critics current HIPAA does not accommodate the powerful research opportunities that may become possible as HIT and HIEs become more commonplace. The public health benefits of secondary use merit judicious consideration of how such data can be optimized while protecting patient autonomy.
Ethical Concerns of EHRs and Meaningful Use:Confidentiality & Physician-Patient Relationship
Patients often express concerns about keeping their PHI is kept confidential and secure. Moreover, patients may fear re-identification of their de-identified health information. Furthermore, understanding that EHRs provide a rich source of data that is highly desirable to pharmaceutical companies, insurance firms, and researchers, it seems valid to be concerned that these entities may try to purchase, use, and resell this data. There must be high security standards and regulations set to ensure that patient information is secure and not vulnerable to such misuse. Such concerns by the patient are harmful to the vital physician-patient relationship. The physician-patient relationship is a unique and complex status in which confidentiality is key; Privacy of a patient’s health information is considered sacred in the medical field. Any perceived infringement on patient privacy will severely damage this unique physician-patient relationship.
If a patient does not feel confident about the security of his or her health information, he or she may feel the need to conceal sensitive information. For example, a patient might fear that sensitive health matters such as those relating to sexual health and mental health could be accessed by others and refrain from sharing information about those issues. This is particularly true pertaining to sensitive health issues, such as sexually transmitted infections or mental health disorders. As a result, the patient’s health and treatment may be compromised. This may result in patients not fully disclosing important facts or, worse, avoiding medical care entirely, which would clearly result in negative health outcomes.
Accordingly, it is essential for physicians to ensure doctor-patient confidentiality by openly discussing these concerns with patients and explaining the security attempts detailed above that are in place to mitigate them. Furthermore, it is important that patients be able to access their EHRs with relative ease. It would be wise to allow patients to have a degree of control over the records’ content by allowing them to write notes or amendments to the record. Lastly, a new informed consent system must be established to enable patients to play a role in the decisions about how much of their EHRs they wish to make public to researchers and other stakeholders. A system must established to enable patients to play a role in the decisions about how much of their EHRs they wish to make public to researchers. Allowing patients to set the level if access they choose to share with certain health care providers and researchers will maintain respect for their autonomy and right to confidentiality. While variation in data due to informed consent redactions may result in significant differences in the completeness of individual datasets, making them less powerful tools for research, it is a risk that we must face to protect patient autonomy while optimizing the research potential of electronic health data. xxvii Patient ownership of their health data, in terms of both privacy and content, is critical to the ethical to use EHR data.
Ethical Concerns of EHRs & Meaningful Use: Autonomy, Informed Consent, and Syndromic Surveillance
While the secondary use of electronic health data has the potential to improve the quality of care in the United States, there are several ethical considerations that must be addressed before a national framework is implemented to address issues of autonomy and informed consent. Patient autonomy is threatened when an individual’s personal health information is shared without that person’s knowledge or consent. When data mining electronic health data, it is unlikely that patients are told that their data is being accessed. It is even less likely that they are contacted for their consent. This is concerning, as champions of patient autonomy would argue that informed consent is necessary for the secondary use of health data. Patients often believe they have a right to know who is viewing their medical information, why it’s being accessed, and how it is being used. Additionally, those who champion patient autonomy believe that patients have a right to take an active part in decisions about the access, content, and ownership of EHR data. It would appear to be a violation of autonomy to aggregate and generate new information about a patient’s health without their knowledge or permission. Patients provide information to healthcare professionals in confidence with the specific goal of advancing their own personal health outcome. If the principle of autonomy is intrinsically linked to advancing an individuals own personal health outcome, then any form of secondary use (by definition as the use of PHI outside of direct patient care delivery) appears to be a violation of the principle of “respect for persons.” The real question here is whether or not you can turn a patient into a research subject without their knowledge or consent.
To overcome these issues of autonomy, patients should be able to access their EMRs with relative ease. Moreover, patients should maintain the right to have a degree of control over the records’ content. While it seems unreasonable to allows patients to modify or delete any of the content entered by health care professionals per se, it seems judicious to allow autonomous patients to review, annotate, or challenge their own electronic medical record. Furthermore, federal regulations must be reassessed to determine considered valid informed consent for research using electronic health data specifically. Some HIEs are attempting to develop new consent processes to overcome HIPAA compliance issues. Some are calling for a blanket “opt-in” or “opt-out” policy, while others suggest the independent ability to exclude certain types of sensitive data in one’s own health record. Ideally, to maintain the highest level of patient autonomy, the patient would have full say as to what specific information may be shared and with whom it may be shared.
That being said, there are certain public health situations where it is necessary and desirable to use electronic health data without informed consent. This is particularly true in public health emergencies. In the interest of population health, the HITECH framework allows for syndromic surveillance to notify public health officials of reportable conditions. Syndromic surveillance systems seek to use existing health data in real time to provide immediate analysis for early detection of disease outbreaks, and to monitor disease trends.xxviii It has been well established the government has the authority to do so under their police power authority to regulate for the safety and welfare for the population. However, it is important to consider from a bioethical perspective where the line ends between public health surveillance and an intrusion on one’s own individual liberty and autonomy. On the other hand, it could be argued that it would be a “tragedy of the commons” if individuals independently acted according to each one's self-interest and refused to be surveilled. To take a communitarian perspective, aggregation of public health data is an essential resource to public health officials and necessary for the welfare and beneficence of the population as a whole.
It is also necessary to note the point of “electronic exceptionalism.” There is a longstanding history of manual disease surveillance. However it seem more ethically unsettling when this process is done with high technology tools that can quickly aggregate and share data in unprecedented ways. While critics may look at syndromic surveillance through EHR data as exceptional because of its electronic nature, its use may not be so different than traditional methods after all. There has been mandatory reporting of certain conditions to public health officials at the local and national level for decades before EHRs existed, including the reporting of drug-resistant tuberculosis, certain cancers, and HIV. EHRs will make reporting of these conditions and others deemed necessary to protect public health easier, and may actually do a better job at protected patient health data by encrypting and preventing unauthorized access through password protection.
Ethical Implications of EHRs and Meaningful Use: Meaningful for Whom?
It is clear that the “meaningful use” of EHRs is on the rise, but is important to question for whom is it meaningful, and how meaningful is it? Let us consider one of the primary goals of “meaningful use,” which is to provide patients with electronic resources to increase participation in their own care. This involves providing patients with an electronic copy of their health information within three business days if requested, including diagnostic test results, medication lists, allergies, discharge summary, and procedures.xxix Accordingly, providers often offer patients access to online personal health record (PHR). PHRs are largely secure as they are encrypted and password-protected. However, it is important to note that patients need more than just Internet access and a very basic understanding of health information to fully benefit from PHRs.xxx Rather, they need access to the basic resources required to act on the information provided through this technology. Not only must patients be able to read and interpret lab results; they must be willing and capable to act on the information he or she receives. This point has been largely neglected in discussions surrounding the HITECH Act. For those without access the Internet, those with very limited health literacy, and those unable to act on that information for financial or other reasons, EHRs have limited to no directed benefit. It is important to note this limitation and ethical concern of the HITECH Act, as well as to acknowledge the justice and access issues it presents.
It is also necessary to consider community outreach and education programs that focus on Internet and health literacy, rather than merely advertising new electronic and personal health record capabilities.xxxi Many fear that patients will misunderstand or misinterpret information if they read it without a medical professional to interpret it. It is possible that the HITECH Act granted health care providers a new ethical obligation to work with patients to ensure they understand these tools and how to use them. Furthermore, healthcare professionals run the risk of relying solely on PHRs to communicate important health information to their patients. This stands to cause great harm to the doctor-patient relationship. Electronic tools must not replace the face-to-face communication between healthcare provider and patient that is essential to maintaining trust and achieving improved health outcomes.
Beneficence of Electronic Data in Medical Research
Despite the ethical concerns addressed above, the use of electronic health data is critical to ensuring patient health, improving our healthcare system, and making new scientific discoveries in this technological age. Critics may question whether EHRs are truly meaningful or whether it is an “excessive bureaucratic requirement to spend public dollars on doctors’ computer systems.”xxxii This answer to this question can be discussed through the principle of justice. It is ethical, one could argue, to expend public funds for EHR systems that provides for the greater good and benefits for the public as a whole. Having data that is structured and easily retrievable benefits clinicians, patients, and the greater population. These benefits include safer prescribing, prevention of medication errors, epidemiological tracking to protect population health, and public medical error reporting. Furthermore, there is a clear need to switch from outdated, burdensome, and inefficient clinical charting traditions to electronic format.
EHR adoption aims to reduce cost, which is a primary goal of health reform in the United States. The increase in information available to clinicians can help prevent redundant or unnecessary tests and imaging. Furthermore, EHRs can provide point-of-care clinical decision support (CDS) as doctors prescribe tests, medications, and imaging requests, which can also help reduce costs. Lastly, “shared savings,” or “gain-sharing,” allows hospitals and healthcare providers to collaborate to reach quality metrics.xxxiii Accordingly, EHRs enable users to measure desired outcomes and report this data more quickly and easily, saving both time and money. With regard to the costs associated with EHRs, studies have documented the strong return on financial investment that may be achieved following EHR implementation.xxxiv Other financial benefits include increased revenues due to improved care coordination, averted costs of paperwork, chart pulls, and billing errors, and fee-for-service savings including the rate of new procedures and charge capture. Furthermore, the secondary use of health record information is anticipated to become one of the healthcare industry’s greatest assets and the key to greater quality and cost savings over the next five years.xxxv In fact, a recent report by the McKinsey Global Institute, estimates the potential annual value to the healthcare industry at over 300 billion dollars.xxxvi These savings in cost benefit both the patient and provider.
There are also several patient-centered benefits that result from the “meaningful use” EHR data. Perhaps one of the most promising results of EHR data mining is the use of predictive modeling techniques to identify medical conditions and promote interventions before the onset of symptoms. Furthermore, retrospective analysis of the health data mined from EHRs could expedite scientific discovery in medicine by providing valuable information for research. In addition, physicians’ access to data and analysis could demonstrate the efficacy of different treatment options across large populations, which could help treat and prevent chronic conditions. Lastly, such data can be used to identify evidence-based best practices, identify potential patients for clinical trials, and monitor patient compliance and drug safety. These measures show beneficence towards the patient by providing better more individualized care.
Conclusion
EHRs can facilitate the efficient delivery of health care in a cost-effective, safe, and patient-centered way. The safety, privacy, and of patients and potential research participants is of utmost concern and can be maintained while capitalizing on technological advances to improve the United States healthcare system. It is possible to reconcile the use electronic health data for research while maintaining respect for patient’s autonomy. Accomplishing this will require collaboration among ethicists, researchers, clinicians, informatics specialists, and policy makers.xxxvii By reevaluating, clarifying, and enforcing HIPAA guidelines as they pertain specifically to secondary use, the federal government could point the healthcare field in a direction that both protects of patients’ privacy and autonomy while empowering researchers with valuable data sets. Permitting the establishment HIEs and data repositories of EHR data for research purposes has great potential for identifying evidence-based best practices, monitoring patient compliance and drug safety, and showing the efficacy of different treatment options across large populations. However, we must provide patients with the right to dictate which information they choose to share and allow them to opt out of the platform to protect patient autonomy while optimizing the research potential of electronic health data. Moreover, EHRs cannot be considered a cure-all for patient health and we must acknowledge the effect it may have on the physician-patient relationship.
The HITECH Act’s initiatives take us a step closer to President Obama’s stated goal of “an EHR for every American by 2014.”xxxviii The integration of HIT into our health care system is more than just a technological upgrade; it represents a fundamental change in our approach healthcare practice in the United States. EHRs will continue to evolve as a critical component in the medical field, and can be ethically integrated to deliver the highest quality healthcare to Americans in the 21st century.


Thursday, October 3, 2013

Google agrees to sign BAA as means to HIPAA compliance

Google removes a barrier to Google Apps adoption by offering to sign BAA for organizations that need to comply with HIPAA. 
HIPAA.gif
In September 2013, Google offered for the first time to sign a HIPAA Business Associate Agreement (BAA) available for Google Apps. That's good news for organizations unwilling to deploy Google Apps without such an agreement. It is also a smart competitive move, as it matches Microsoft, which offers to sign a BAA for Office365.

HIPAA: The basics

For those who may be unfamiliar, HIPAA (Health Insurance Portability and Accountability Act), refers to a set of laws passed in the United States in 1996. The laws seek to limit access to individually identifiable healthcare information to those that "need to know". HIPAA holds healthcare industry professionals accountable for the privacy of patient information.
Effective HIPAA compliance implementations resemble effective security systems: they're designed with the aim of protecting individually identifiable health information (IIHI). Such information is broadly referred to as "protected health information", or PHI. This information includes an individual's name, address, and any information related to the individual's health or payment records. A Business Associate Agreement (BAA) provides written assurances that an organization's partners will also seek to secure an individual's PHI.

Google Apps BAA

Google's BAA agreement covers three Google Apps services (Gmail, Calendar, and Drive), along with the Google Apps Vault service, which archives user data from the other three services. To sign up, an Administrator for the Google Apps domain must answer three questions online. From the website:
  1. Are you a Covered Entity (or Business Associate of a Covered Entity) under HIPAA?
  2. Will you be using Google Apps in connection with Protect Health Information?
  3. Are you authorized to request and agree to a Business Associate Agreement with Google for your Google Apps domain?
After responding, the Administrator will be taken to the BAA document for signature. As of September 27, 2013, Google is using Adobe's Echosign to obtain digital signatures.

Read before signing

The BAA terms state "...other Google services or third party Marketplace Apps should not be used in connections with PHI. This agreement requires that you disable all Additional services in the Admin console." (Emphasis is mine.)
An organization signing the BAA would not be able to use the domain covered by this agreement for additional useful Google services, such as Google+, Google Groups, or Google Sites. As the terms state, you must disable all Additional services: you may use Gmail, Calendar, Drive and Google Vault. The terms also appear to prohibit the use of Marketplace Apps in conjunction with PHI. (It is unclear whether the terms also prohibit the use of apps intended to secure and protect PHI, such as zSentry. zSentry offers to sign a BAA, and is a third-party app, which may be connected through the Marketplace.)

Implement thoughtfully

If your organization needs HIPAA compliant email, calendars and document storage, then sign the BAA and move forward with the migration. Your organization can adopt Gmail, Calendar, and Drive, confident that IIHI and PHI in those apps will be protected by the BAA.
If your organization is already using Google Apps, review your usage carefully before signing the BAA. If you've already implemented measures to ensure HIPAA compliance, the availability of a BAA may not change anything for your organization. For example, you might already prohibit the use of PHI in Gmail, Calendar and Drive. You might already use tools to audit and verify compliance, such as CloudLock.

Documents don't ensure security

Google-Apps-logo.png
Google's willingness to sign a BAA for organizations that need to comply with HIPAA is helpful and certainly welcomed. It may remove a barrier to adoption for some organizations. But healthcare professionals need to remember that HIPAA compliance, like all IT security, involves complex systems comprised of people, policies, and practices. (For example, you still need effective password policies, security measures such as 2-step authentication, and appropriate user permission settings.)
Signing a BAA doesn't ensure your entire organization is HIPAA compliant: the BAA is just one piece of a complex system needed to protect IIHI and PHI.


Thursday, September 26, 2013

Fax Sent to Wrong Number Results in HIPAA Violation


Fax Sent to Wrong Number Results in HIPAA Violation
Fax Sent to Wrong Number Results in HIPAA Violation
Dr. G, 58, was a urologist with a solo practice. His business was thriving, and he employed both a nurse and an office manager to help him.
One morning, the office manager got a call from one of the practice's patients, Mr. M, a 52-year-old, HIV-positive man who had been seeing Dr. G for a decade. Although he was happy with the treatment he had been receiving, Mr. M's company was promoting him and he was relocating to another town. He called to ask Dr. G to fax his medical records to his new urologist.
The office manager was juggling numerous tasks, but managed to send the fax out later that day. The office did not have personalized fax cover sheets, just sheets that the office manager printed off once a week which had spaces to fill in the “to” and “from” sections. She hurriedly filled them in and shot off the fax, one of several she had to do before checking in the next patient.
At the end of the day she told Dr. G that it had been done. He thought nothing of it until the following Monday when the office manager came into the back office to speak to him. She was pale and looked shaken, and the physician immediately asked if she was okay.
“It's Mr. M,” the office manager said. “He just called – absolutely furious. He says that we faxed his medical records to his employer rather than his new doctor, and that now his company is aware of his HIV status. He is extremely upset.”
“I'm so sorry,” the office manager said tearfully. “I was the one who sent that fax out. I must have accidentally grabbed the wrong number from his file. What should we do?” She looked at Dr. G for guidance.
Dr. G was holding his forehead, and trying to figure out how to remedy the situation. “The first thing we're going to do is to call Mr. M and apologize. Then we'll take it from there.”
The office manager and Dr. G called Mr. M and apologized profusely for the mix-up. Mr. M understood that it had not been done maliciously, but he was still not satisfied and reported the incident to the U.S. Department of Health and Human Services' (HHS) Office for Civil Rights (OCR). 
An initial investigation indicated that the incident was not criminal and so it was not referred to the Department of Justice. Rather, it was handled by the OCR. OCR officials appeared at Dr. G's office to look into the matter, and after a thorough investigation, the OCR issued a letter of warning to the office manager, referred the office staff for HIPAA privacy training, and had the office revise the fax cover sheets to underscore that they contain a confidential communication for the intended recipient only.

Legal Background


The Health Insurance Portability and Accountability Act, commonly known as HIPAA, protects personally identifiable health information of patients, and specifies to providers how such information may be used. HIPAA has been in effect for about a decade, and in that time, the HHS has received a total of almost 80,000 complaints.
Of those, more than 44,000 were dismissed, 19,000 were investigated and resolved with changes to privacy practice, and 9,000 were investigated but no violations were found. 
According to HHS, private medical practices were the ones most often required to take corrective action as a result of enforcement. The top two compliance issues most frequently investigated are impermissible use and disclosure of protected health information and lack of safeguards for protected health information.
When a HIPAA complaint is filed with the HHS, the first determination made is whether there was a possible privacy violation and whether it was of a criminal nature. If it was determined to be criminal, the case is referred to the Department of Justice for investigation and possible prosecution. If it was determined that it was not a criminal issue (as in this case) the violation is investigated by the OCR. 
If it is determined that a HIPAA violation did, in fact, take place, the OCR can either obtain voluntary compliance, corrective action or some other voluntary agreement with the offender, or the OCR can issue a formal finding of violation and force the offender to change its practices.
In this particular case, the office manager and Dr. G recognized the mistake and immediately tried to take corrective action by apologizing to the patient. Dr. G's office also voluntarily agreed to extra compliance training for the staff and to a change in their faxing procedures to indicate that the faxed materials are confidential.

Protecting Yourself


This particular scenario was the result of a careless error. While a careless error can happen to anyone, one such as this could cause irreparable harm to the patient if his employer now views or treats him differently because of the new knowledge of his HIV-positive status.
Confidential patient records must be treated with the greatest of care as they contain information of an extremely personal nature. Many HIPAA cases have involved the unintentional divulging of the HIV or AIDS status of a patient. 
In a similar case, a dental practice was reported for using red stickers and the word AIDS on the outside of patient folders. And in a case that took place in a hospital, a nurse and orderly lost their jobs for discussing a patient's HIV status within earshot of other patients.
A good rule of thumb is to treat a patient's confidential information as you would want yours to be treated, and then add a little extra security for good measure.


Thursday, August 29, 2013

Due Diligence: Your Greatest Ally in Healthcare Fraud Prevention


 Kameron Gifford, CPC

If you are practicing medicine today, you are at risk for allegations of fraud. What steps have you taken to minimize this risk? Does your clinic have a compliance plan? Does you compliance plan address coding and documentation risks and identify an actionable plan of oversight? When was the last time you had an independent review of your billing practices and office policies? What type of annual training is provided to your office staff and what type of assessments have been given?

If your practice can not answer these questions, you need to take action NOW.

Begin by creating a practical compliance plan. If you choose to buy a compliance plan off the shelf, remember this must be updated to reflect your office and your policies. Once you have a plan, use it. This is a common problem area for many practices.

Next review your clinic's billing policies and practices. If you don't have any, now is the time to create them. In the event of fraud allegations, this document proves your good intentions. Be sure to include specific steps to ensure compliance with local, state and federal regulations as well as contract level requirements

Plan an internal audit. Due diligence is your greatest ally in fraud prevention. If you are a physican who does their own coding or your office does not have a certified coder, I highly recommend an annual audit with a certified coder. The average primary care physican has a panel of 1200 patients. On average, the cost to audit 1% of your records annually would be $7,500. A small price to pay for peace of mind.

Educate everyone in your office.This is the single most important investment that you can make in your organization. Look for education providers that will come to your clinic and work to improve the entire team. A successful transition to ICD-10 will require extensive training and preparation. With the deadline less than a year away, what is your plan of action?

By following these simple steps, you will significantly reduce your chances of fraud allegations. ERM routinely works with physicians, clinics, hospitals and health plans to identify specific gaps in policies and practices, reduce error rates, and eliminate future defects. Don't wait until you recieve an audit notification. Act now.  


Tuesday, August 27, 2013

Sept. 23 deadline looms for business compliance with HITECH Act on patient privacy

Organizations handling healthcare data have a month to comply with new security and privacy requirements under the Health Information Technology for Economic and Clinical Health (HITECH) Act.
After Sept. 23, all covered entities, including online storage vendors and cloud service providers, will be subject to new breach notification standards and limitations on how they can use and disclose PHI. They will also be required to ensure that their business associates and subcontractors are compliant with the privacy and security requirements of the Health Insurance Portability and Accountability Act (HIPAA). The HITECH Act amended portions of HIPAA by adding new security and privacy provisions on patient information.
In addition, covered entities will be required to have updated patient privacy notices in place that state the patient's rights over the data and how the data can be used and shared.
Unlike the original HIPAA privacy and security rules, which primarily applied to healthcare organizations and insurance companies, the new HIPAA Omnibus rules apply to business associates and their subcontractors. Under the omnibus rules, a business associate of a healthcare provider, such as a cloud service provider, is directly liable for protecting any patient data it handles, even if the vendor is just storing the data.
Business associates are also liable for ensuring that any subcontractor it hires, such as a document-shredding company, is similarly protecting PHI.
The new rules for safeguarding PHI create a complex liability chain, said Peter MacKoul, president of consulting firm HIPAA Solutions LC. A covered entity or a business associate could face stiff civil penalties for a breach by a subcontractor, regardless of how far down the chain the subcontractor might be, he said.
Under Omnibus HIPAA rules, covered entities and business associates are directly responsible for protecting against the use of PHI by employees, contract workers, trainees and even unpaid volunteers and interns, MacKoul noted.
The rules also give healthcare organizations and business associates less latitude to determine when to make a breach notification, he said.
Previously, a healthcare organization needed to notify individuals of a data breach only if there was a serious risk of financial or reputational harm. Under the new requirements, covered entities and business associates will be required to issue a breach notification in most cases, unless they can specifically show there is a "low probability" of the breached data being misused, MacKoul said.
Healthcare companies will be required to consider four specific factors, including the nature of the data that was breached and whether PHI was acquired or viewed only, to determine the seriousness of a breach. Importantly, breach notification requirements can be triggered even if an employee, contractor or unpaid volunteer uses PHI in an impermissible manner, he said.
Healthcare entities need to identify all their business associates, especially newly covered entities such as data storage companies, and ensure they have proper business associate agreements with them by Sept. 23, said William Maruca, a partner with Fox Rothschild LLP.
Healthcare companies also must have updated patient privacy notices in place by the deadline, Maruca said. The notice must specifically state that the covered entity is required to obtain the patient's authorization to use or sell his or her information for marketing or other purposes and to use or disclose psychotherapy notes, Maruca said. Privacy notices will also need to include a description of how an individual can revoke an authorization and explain their right to receive a notification in the event of a data breach, Maruca said.
"I think the readiness level varies considerably," Maruca noted. "Larger health systems and similar organizations with dedicated health privacy officers may be ahead of the curve, and some savvy smaller entities have been very proactive," he said. But "others are dragging their feet. I think it may take a high-profile enforcement ... to get the attention of the smaller players."
Deborah Peel, founder and chairman of the advocacy group Patient Privacy Rights , noted that while the changes are designed to improve patient privacy, several loopholes remain.
Despite the changes, most health data can still be sold, she said. There is also no chain of custody for health data despite the generally strong security and contract requirements for business associates and subcontractors, Peel said.
As a result there is no way for patients "to obtain a complete map or picture of who used your health information or why. Without a complete data map that tracks all flows of data, we have no idea about the harms and misuses, making it impossible to weigh the risks vs. benefits of using," health information technology systems, she noted.

Friday, August 23, 2013

HHS settles with health plan in photocopier breach case


Under a settlement with the U.S. Department of Health and Human Services (HHS), Affinity Health Plan, Inc. will settle potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules for $1,215,780.  Affinity Health Plan is a not-for-profit managed care plan serving the New York metropolitan area.

Affinity filed a breach report with the HHS Office for Civil Rights (OCR) on April 15, 2010, as required by the Health Information Technology for Economic and Clinical Health, or HITECH Act. The HITECH Breach Notification Rule requires HIPAA-covered entities to notify HHS of a breach of unsecured protected health information.  Affinity indicated that it was informed by a representative of CBS Evening News that, as part of an investigatory report, CBS had purchased a photocopier previously leased by Affinity.  CBS informed Affinity that the copier that Affinity had used contained confidential medical information on the hard drive.

Affinity estimated that up to 344,579 individuals may have been affected by this breach. OCR’s investigation indicated that Affinity impermissibly disclosed the protected health information of these affected individuals when it returned multiple photocopiers to leasing agents without erasing the data contained on the copier hard drives.  In addition, the investigation revealed that Affinity failed to incorporate the electronic protected health information (ePHI) stored on photocopier hard drives in its analysis of risks and vulnerabilities as required by the Security Rule, and failed to implement policies and procedures when returning the photocopiers to its leasing agents. 

"This settlement illustrates an important reminder about equipment designed to retain electronic information: Make sure that all personal information is wiped from hardware before it’s recycled, thrown away or sent back to a leasing agent," said OCR Director Leon Rodriguez.  “HIPAA covered entities are required to undertake a careful risk analysis to understand the threats and vulnerabilities to individuals’ data, and have appropriate safeguards in place to protect this information.”

In addition to the $1,215,780 payment, the settlement includes a corrective action plan requiring Affinity to use its best efforts to retrieve all hard drives that were contained on photocopiers previously leased by the plan that remain in the possession of the leasing agent, and to take certain measures to safeguard all ePHI.

For more information on safeguarding sensitive data stored in the hard drives of digital copiers: http://business.ftc.gov/documents/bus43-copier-data-security

The National Institute of Standards and Technology has issued guidance on media sanitation: http://csrc.nist.gov/publications/drafts/800-88-rev1/sp800_88_r1_draft.pdf

OCR offers free training on compliance with the HIPAA Privacy and Security Rules for continuing medical education credit athttp://www.medscape.org/sites/advances/patients-rights.


The HHS Resolution Agreement and CAP can be found on the OCR website athttp://www.hhs.gov/ocr/privacy/hipaa/enforcement/examples/affinity-agreement.html

HHS settles with health plan in photocopier breach case

Thursday, July 25, 2013

Providers stumble after recent HIPAA audits | Contemporary OB/GYN




When it comes to securing and protecting patient health information, physician practices with fewer than 50 providers fared the worst in a recent audit by the U.S. Department of Health and Human Services’ Office for Civil Rights (OCR).
In fact, Linda Sanches, MPH, an OCR senior adviser, reports that only two of the 64 healthcare providers in the audit passed without problems.
While OCR’s audit on privacy and security also included health plans and healthcare clearinghouses, the report says that significant compliance issues exist among physician practices.
OCR evaluated practices related to security (administrative, physical and technical safeguards), breach notification, and privacy [access to patient health information (PHI), administrative requirements, uses and disclosures of PHI, etc.]. Security problems accounted for 60% of the findings and observations. Data privacy problems were noted in 30% of the audits, while only 10% were attributed to data breach notifications.
Small practices, OCR notes, “struggled with all three audit areas.”
Nearly 50% of the smaller practices posted negative findings and observations related to compliance of uses and disclosure of PHI, another 30% were dinged for not having acceptable administrative requirements in place, 30% had compliance problems related to patient access, and another 31% had findings and observations related to notice of privacy practices for PHI.
Many of the audit problems, Sanches says, were triggered simply because providers were unaware of the requirements. She urged physicians to evaluate the regulations and conduct a compliance assessment to help protect PHI from breaches.


Providers stumble after recent HIPAA audits | Contemporary OB/GYN

Sunday, June 23, 2013

ATTENTION GROUP HEALTH PLAN SPONSORS: ACTION REQUIRED TO COMPLY WITH FINAL HIPAA REGULATIONS

Group health plan sponsors have been focusing to a great extent upon the various
significant requirements imposed by the Patient Protection and Affordable Care Act,
most notably the “play or pay” provisions which become effective in 2014. However,
such sponsors with self-insured plans (including FSAs and HRAs) also need to focus
upon changes to the Health Insurance Portability and Accountability Act (HIPAA)
privacy and security rules which become effective later this year.
Earlier this year, the Department of Health and Human Services (HHS) published
a final rule modifying HIPAA, as amended by the Health Information Technology
for Economic and Clinical Health Act (HITECH) and the Genetic Information
Nondiscrimination Act (GINA). Group health plans, as well as their business
associates, are subject to various changes and generally must comply by September
23, 2013. Accordingly, prompt action is recommended.

The rules are of less concern to fully insured plans, since in those cases plan
sponsors rarely receive protected health information (PHI) other than enrollment and
summary information. Under those circumstances, most HIPAA privacy and security
compliance responsibility rests with the insurer. However, it is of significant relevance
to self-insured health plans maintained by an employer, since the employer then
has access (either directly or through a third party administrator) to the medical
information of its employees and is responsible for complying with HIPAA’s privacy
and security rules.
This Bulletin is not intended to provide an exhaustive summary of the changes
Rather, it is intended to highlight the most significant changes and to suggest action
steps.

Business Associates
The final regulations change the rules for the business associates of group health
plans. Third-party administrators and other consultants or health plan service
providers that have access to PHI in performing services are now directly liable for
the civil and criminal penalties for certain violations of HIPAA. Previously, compliance
had been a contractual obligation pursuant to the written agreement with the covered
entity relative to HIPAA compliance. Therefore, business associates must establish
and maintain policies and procedures to implement required safeguards. Business
associates must enter into written agreements with group health plans and with their
own subcontractors to ensure compliance with HIPAA. Business associates will also
often have a major role in breach notification compliance for group health plans.

The final rule allows for a transition period to renegotiate and revise existing
agreements. Generally, agreements in place as of January 25, 2013 that are not
renewed or modified before September 23, 2013 are considered to be compliant
until they are renewed or modified, or September 22, 2014 if earlier. Agreements
renewed or modified before September 23, 2013 must comply by September 23,
2013. The HHS website contains a revised model business associate agreement.

GINA Compliance
The final regulations implement rules under GINA as it applies to the use and
disclosure of PHI by group health plans and business associates. PHI that is genetic
information may not be used or disclosed for underwriting purposes.

Privacy Policies and Procedures
Self-funded health plans are required to have policies and procedures in place
to protect PHI from unauthorized use and disclosure. Some of those policies and
procedures will need to be revised to reflect the new requirements.

Notice of Privacy Practices
Notices of Privacy Practices will need to be updated to include the following:
• Individuals will be notified upon a breach of PHI.
• The use or disclosure of genetic information for underwriting purposes is
prohibited.
• Written authorization is required for disclosures for marketing purposes and for
the sale of PHI.
The notices will need to be revised and posted on the employer’s website, and copies
of its revised notice should be provided to participants and beneficiaries.

Breach Notification
The final regulations modify the factors that plans and business associates are to
take into account in conducting a “risk assessment” to determine whether a breach
requiring notice to affected individuals, the Department of Health and Human
Services, and in some cases the media, has occurred. A breach requiring notice will
be presumed to have occurred whenever PHI maintained by the plan or business
associate is acquired, accessed, used or disclosed in a manner that violates the
privacy rule. This presumption may be rebutted if the plan or business associate can
demonstrate, pursuant to factors provided under the regulations, that there is a “low
probability” that PHI has been compromised. The previous standard, which required
the violation to pose a “significant risk” of financial, reputational or other harm to the
individual, was eliminated.

Enforcement
The regulations include the civil and criminal penalties that apply to HIPAA violations
by group health plans and their business associates. Monetary penalties vary
according to the number of violations, the cause of such violations, and whether the
group health plan or business associate takes timely action to correct the violation.
Civil penalties can be up to $1.5 million per year for each violation of a standard or
requirement. HHS will continue to conduct random audits and investigate complaints,
and increasingly aggressive enforcement is expected.

Action Items for Group Health Plans
The regulations require immediate action by employers sponsoring self-insured
group health plans and their business associates. Plans need to:
• Update their HIPAA Policies and Procedures, and related administrative forms,
to reflect the final rules.
• For breach notification, replace the “significant risk” standard with the “low
probability” standard in conducting a risk assessment.
• Confirm that genetic information is not used for underwriting purposes.
• Update Notices of Privacy Practices.
• Train personnel who have access to PHI.
• Review business associate agreements and incorporate the final rule’s new requirements. Keep in mind the one year transition rule described above.
Business associates will need to come into compliance with the new rules as well,
including establishing policies and procedures of their own. Business associates will
also need to enter into business associate agreements with their subcontractors. In
that connection, business associates should identify which of their subcontractors
will access, use or disclose PHI in performing their services. Business associates
should also consider whether their existing liability insurance provides coverage for
HIPAA violations and whether new or additional coverage is needed.
Please contact any member of the Health Care Group if you need assistance in
complying with the new HIPAA requirements applicable to self-insured group health
plans.

http://www.murthalaw.com/files/hc__action_required_to_comply_with_final_hipaa_regs_6_2013_copy1.pdf