Skip to main content
Paper Example Doctorate 1,732 words

HIPAA confidentiality violations and HITECH Act enforcement obligations

Last reviewed: May 31, 2019 ~9 min read
Essay 1,732 words

Violation of HIPAA – Confidentiality
Introduction
The Health Insurance Portability and Accountability Act (HIPAA) of 1996 is a legislation in the United States of America that provides for data privacy and safeguarding of medical information. In the recent years, the law has grown in its relevance especially with the proliferation of digital data breaches among them; cyber attacks and ransomware attacks on health providers, insurers, and healthcare databases e.g. the Electronic Health Records (EHR) and telehealth Apps. In addition to external attacks, HIPAA requires internal stakeholders, in particular, healthcare providers, centers, and insurers to protect patients/client’s data (HHS OCR, 2013). This law places a responsibility on healthcare providers to actively take and implement measures to protect patient’s data. This paper presents a discussion on the violation of HIPAA confidentiality. This will be done by selection of a federal or/and state law/statute, discuss the specific obligations to healthcare providers in protecting patient’s data, consequences of compliance, and present management strategies to improve on compliance.
The Health Information Technology for Economic and Clinical Health (HITECH) Act
The HITECH Act was enacted as part of the American Recovery and Reinvestment Act of 2009 signed into law by President Barack H. Obama on February 17, 2009 (HHS OCR, 2017). The purpose of the act was to promote the adoption and the meaningful use of health information technology. The privacy and security concerns related to the transmission of health information are addressed in Subtitle D of the HITECH Act. This section is also aimed towards strengthening the enforcement of civil and criminal aspects of the HIPAA rules.
Health care organization’s obligation to meet patient legal rights under the HITECH Act
Under the HITECH Act, hospitals, other healthcare organizations e.g. medical and nursing homes, and business associates have a responsibility to ensure that patient data is kept safe and secure. Healthcare organizations and business associates – who are mainly manufacturers of technical devices used in healthcare – have to make a determination on whether data collected from a patient is subject to both HIPAA and HITECH regulation. This determination is guided by three factors provided under HITECH Act; (i) whether the information collection qualifies to be health protected data. (ii) whether a covered Entity if part of the data, and (iii) whether there is a relationship between the health organization or business associate and the covered entity (Cerrato, 2016; HHS OCR, 2017). For information to be considered protected health data, information has to contain elements or parts that can identify an individual. A covered entity according to the regulation includes a healthcare provider, health plan, and healthcare clearinghouses. In any case that there is a breach of patient’s data, the HITECH Act requires that they are notified of the breach.
In addition to the responsibility to keep patient records safe and secured, the HITECH Act requires hospital organizations to grants patients the right to request restriction on disclosure of their protected health information by requiring covered entities to grant a restriction on disclosure of health information where the purpose of the disclosure is for the payment or healthcare operations especially where the involved care provider has been paid out of pocket (HHS OCR, 2017). This requirement is an omnibus rule that amends the HIPAA privacy rule and under this new requirement, if a patient pays out of pocket for a blood test and requests the physician not to disclose the protected health information pertaining solely to the blood test to the care plan, then the physician under the HITECH Act has no option but to comply with that request, unless disclosure is so required by law.
The HITECH Act also grants individuals the right to access protected health information. The Act requires that an individual has a right to obtain a copy of their protected health information in an electronic format, so long as that information is contained in the EHR. However, the Health and Human Services expressed concerns on applying this right to only information stored in the EHR would lead to confusion (HHS OCR, 2013). As a result, the rule was amended to include an individual’s protected health information maintained in one or more designated record sets electronically.
Consequence for non-compliance
The HITECH Act is a federal law and thus, it grants the Department of Health and Human Services as well as State Attorneys generals the mandate to foresee the enforcement of the law. This two-level enforcement authority provides an increased political motivation towards investigating cases of disclosure of protected health information by overly ambitious state attorneys’ generals from any of the 50 states. To this effect, in case of an investigation, and because professionals in health care have always benefitted from advice by lawyers, these investigations can be more punishing than the penalty. This is a political strategy used to cause state attorneys general to ensure compliance.
However, the HITECH Act has civil penalties that are mandatory whenever a case of violation as a result of purposeful neglect has been reported. Even though there are penalties stipulated under the HIPAA, the HITECH Act has increased these penalties.
Under the HIPAA, violation penalties and fines are categorized into tiers. Tier A covers penalties for violation of HIPAA in a case where the offender didn’t realize he/she had violated the Act. This means he/she would have handled the matters in a different manner had they were cognizant of the law. This violation attracts a fine of $100 for each individual violation and this cannot go beyond $25,000 per calendar year (HHS OCR, 2017).
Tier B covers violations as a result of reasonable cause, but not willful neglect. The fine for this category of violations is $1,000 for each violation and the fines can not exceed $100,000 per calendar year. Tier C covers violations as a result of willful neglect, but the health organization took a remedial action taken within 30 days. This violation attracts a fine of $10,000 for each violation but the fine is not to exceed $250,000 within a calendar year. Last is Tier D which covers willful neglect violations and there was no corrective measure taken. The fine for each violation is $50,000 and the fines can not exceed $1,500,000 per calendar year (HHS OCR, 2017).
In addition to these fines, the HITECH Act allows for state attorneys general to impose fines and require attorney’s fees on behalf of affected patients from the covered entities. In addition, the HITECH Act provides for courts to award costs to victims, an aspect that was lacking in the HIPAA.
Healthcare Management Action to meet HITECH Act patient rights
To meet the right to restriction of patient health information right provided for by the HITECH Act, I would implement several strategies. The first is effective recordkeeping. The law doesn’t require health care organizations to keep separate records on disclosure restrictions made by patients, however, to ensure efficiency, I would implement a strategy to enable flagging of protected health information the patient has requested restriction (Burde, 2011; Murray, Calhoun & Philipsen, 2011). The HITECH Act requires restriction on a service that the patient has paid for in out of pocket cash. In the case of bundled services, this requirement can be a problem when the patient has paid for a single element in the bundled package and asks for restriction of all services. To this effect, I would unbundle bundled services to ensure effective restriction of protected health information as per the HITECH Act.
In addition to the restriction of protected health information, the HITECH Act also grants individuals the right to access protected health information. It is the duty of health organization to ensure this right is granted. To provide for this right effectively, I would implement various actions. The first is to ensure that the file formats used within the organization are suitable (Cerrato, 2016). HITECH Act provides for individuals to be provided with a file format they so desire. If this format is not easily available, the law requires the covered entity to provide a copy of the protected health information in a readable electronic form, e.g. pdf but not hard copy.
HITECH Act allows individuals to instruct cover entities to transfer a copy of protected health information to a third party. The request to transmit such information should, however, be clear, conspicuous and precise (Cerrato, 2016). However, to ensure that there is no mistake or any future complication arising from such a request, the health organization management will require such requests to be in a writing form, duly signed by the individual and the third party clearly identified with the corresponding address.
Because a fee is normally charged for the right to access, to avoid any possible legal challenges or ethical concerns, the health organization will set up a cost-based fee structure to guide the fees charged for all requests. In addition, any requests are to be acted upon as soon as possible within a period of 30 days, but also with an extension of more 30 days in extenuating situations (Cerrato, 2016; Murray et al., 2011).
Conclusion
All working within the healthcare profession have a responsibility to respect the information they collect and more importantly, the protected health information. Previously, under the HIPAA, the real owners of this information, the patients, didn’t have a right over the same, but the HITECH Act recognized this anomaly and rectified it by granting patients the right to request for restriction and/or access of protected health information. It is the responsibility of healthcare professional and cover entities to ensure these rights are granted. Failure to attracts political repercussions for state attorneys general and penalties and fees.

References Burde, J.D.H. (2011). THE HITECH ACT: An Overview. Virtual Mentor, 13(3):172-175. Cerrato, P. (2016). Protecting Patient Information: A Decision-maker's Guide to Risk, Prevention, and Damage Control. Syngress. Murray, T. L., Calhoun, M., & Philipsen, N. C. (2011). Privacy, confidentiality, HIPAA, and HITECH: implications for the health care practitioner. The Journal for Nurse Practitioners, 7(9), 747-752. U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR). (2013). Omnibus HIPAA Rulemaking. Retrieved from http://www.hhs.gov/ocr/privacy/hipaa/administrative/omnibus/index.html on 31 May 2019 US Department of Health and Human Services (HHS), Office for Civil Rights (OCR). (last review. 2017). Health Information Technology for Economic and Clinical Health Act of 2009. Retrieved from https://www.hhs.gov/hipaa/for-professionals/special-topics/hitech-act-enforcement-interim-final-rule/index.html on 31 May 2019

Preview · 100% Shown
Cite This Paper
PaperDue. (2019). HIPAA confidentiality violations and HITECH Act enforcement obligations. PaperDue. https://www.paperdue.com/essay/violation-of-hipaa-and-its-confidentiality-research-paper-2174186

Always verify citation format against your institution’s current style guide requirements.