Skip to main content
Paper Example Undergraduate 1,147 words

Health data breach notification requirements under HITECH

Last reviewed: April 30, 2015 ~6 min read
Essay 1,147 words

¶ … Breaches have been reportedly increasing and worrying patients and their families (Collier, 2012). Portable devices can now access information in any distance and many of these are not encrypted. A new Redspin report said that, in the United States alone, a high 97% of health records in hospitals have been accessed without authority (Collier). And the cleaners of the hospital in question did not find it very difficult to gain access to confidential printouts, just lying around intact. But the situation should be addressed promptly as a threat to privacy and security of patient record is a serious matter (Cucoran et al., 2011).

The management of facilities should take stock of these breaches and come up with real solutions. On the outside, the Health Insurance Portability and Accountability or HIPAA safeguards these medical information and health records (Cucoran et al., 2011). It directs all administrative, physical and technical actions to insure this confidentiality, integrity and security of these records. Its rules should be invoked in cases like this (Cucoran et al.). But HIPAA needed more teeth and support to enforce its rules.

Staff Training

In response, the United States Congress passed the Health Information Technology for Clinical and Economic Health or HiTECH on February 18, 2009 (Kibbe, 2015). It greatly increased the capability of HIPAA to enforce its rules on data security. One of the new provisions is mandatory health data breach notification. It raised penalties from $25,000 to $500,000, enforcement by attorneys general and the revision of business associate agreements. The Department of Health and Human Service is the implementing agency of the new provisions (Kibbe). This notification applies to the case of the cleaners.

The HHS requires that the affected persons, the Secretary of the HHS and, when warranted, the, media, be immediately informed of the breach (Kibbe, 2015). The new provisions, however, confine the notification to unsecured protected health information. This is any information that has not made useless or unreadable to un-authorized persons through any technological means or method as specified by the Secretary. Hard copies, paper or film must be immediately shredded or destroyed in order to render them unreadable, un-reconstructible or un-retrievable. Redaction is, however, specifically excluded as a form of data destruction. All information from electronic media shall be erased, pursed or destroyed irretrievably. The bottom line is that the owner or manager of the facility shall immediately perform the required data breach notification as soon as the specified patient information in whatever medium has been casually discarded, accessed, read or viewed. Large fines will be imposed for failure to comply with these new provision (Kibbe).

Implementing a Management Plan Fisher & Madge 1996) manager's role

Patient confidentiality is top priority in importance between the doctor and his patient (Fisher & Madge, 1996). The possibility of moving greater amounts of confidential and non-confidential patient information looms large with the introduction of more and more sophisticated networks. These data will travel between general practitioners and hospitals in increasing speed to enhance their work and communication exchange. If and when confidential patient information is intercepted or sent without authority, harm and/or embarrassment can result (Fisher & Madge).

The British Medical Association introduced a bill on privacy and confidentiality, which would impose the encryption of all clinical data through all electronic networks (Fisher & Madge, 1996). The manager, therefore, is responsible for the dissemination of information to all employees on the principles of data protection, security of computer systems in the facility and the assurance that no breaches of security can be committed at outside or public locations (Fisher & Madge).

The manager should thus keep himself updated on developments on computer security, like digital signatures (Fisher & Madge, 1996). He should always be ready to explore these and other potential events when they loom. He must likewise continue monitoring access to terminals and to impose severe sanction on employees who commit the breach. Each of his subordinate managers must be aware or informed about employees under them and their need or intent "to know." They are mandated to promote confidentiality of patient information throughout the facility at all times. His management team should be as armed as he in every way. He must train new employees on the principles of data security and their accountability for data accessed without authorization. All healthcare organizations shall be accountable for data security and patient confidentiality. The top official is automatically most responsible. Allowing access to personal health records without consent from the patient, as a safe rule, is considered a statutory offense by the British Medical Association. All other national associations of health practitioners should consider this line of thinking (Fisher & Madge).

175 Words Hidden · 81% Shown
Cite This Paper
PaperDue. (2015). Health data breach notification requirements under HITECH. PaperDue. https://www.paperdue.com/essay/protecting-patient-information-2149933

Always verify citation format against your institution’s current style guide requirements.