Showing posts with label HIPAA. Show all posts
Showing posts with label HIPAA. Show all posts

Sunday, March 7, 2010

HIPAA Enforcement

Is HIPAA meaningful? For a long time, the answer to that question was arguably no. The date for compliance with the privacy rules was April 14, 2003, and the date for compliance with the security rule was two years later (the HIPAA Wikipedia entry has a good summary of this history). Nevertheless, it wasn't until 2007 that the first HIPAA audit took place (see here), and the lack of enforcement led many to believe that HIPAA was basically toothless (see, e.g., here).

Now though, that may be changing. One of the notable features of the HITECH act was that it gave state attorneys general the right to file suit on behalf of state residents who have been harmed by a HIPAA violation (the text of the act can be found here). Since then, the attorney general of Connecticut has taken advantage of that new authority, and filed suit against Health Net Connecticut, Inc. for HIPAA violations (among other things). The press release is here, and the complaint can be found here. Does this herald a new era of aggressive HIPAA enforcement? I tend to think not. The HITECH act limits the amount of damages recoverable by attorneys general to $25,000 per calendar year for violations of any individual requirement or prohibition, so HIPAA enforcement isn't going to be a panacea for states which already have limited enforcement budgets. On the other hand, there has already been one suit, and if an attorney general is already thinking about bringing an action (e.g., under some applicable state law), the extra HIPAA recovery could make the difference in whether a suit is brought. Either way though, with the Connecticut attorney general's action, the era of absent HIPAA enforcement is officially closed.

Saturday, April 4, 2009

Federal Security Breach Notification is Here

After years of talk, and failed attempts, tucked into a corner of the massive American Recovery and Reinvestment Act, we get a federal security breach notification law. Actually, we get a whole chunk of health care related privacy legislation, but what I'm going to focus on is the security breach notification part of it, as there's simply too much there for a single post otherwise.

In any case, the relevant provisions are sections 13402 (Notification in the case of breach, starting at page 146 in the linked PDF) and 13407 (Temporary breach notification requirement for vendors of personal health records and other non-HIPAA covered entities, starting at page 155 in the linked PDF). The question that needs to be asked is: how do they stack up against existing state security breach notification laws? The answer: reasonably well. The new federal law covers security breaches which expose individually identifiable health information* which means it's actually broader than some state laws which limit their coverage based on how the information is stored (e.g., California's SB1386 which is limited to "computerized" data). The new federal law also includes a media notice provision, which requires notice to "prominent media outlets" if the unsecured protected health information of more than 500 residents is compromised. That provision is actually stricter than the media notice from California's security breach notification law (used as a model for similar laws around the country), which is triggered if the number of people to be notified exceeds 500,000.

On the other hand, while the new federal law is stricter in some ways, it lacks what I consider one of the most important features of an effective protection - an individual right to bring suit. The lack of an individual right in various state laws has been used against people seeking compensation before (e.g., here), and I think the fact that the new federal law could be used in the same way could undermine enforcement. However, even though enforcement is a little questionable, the substance of the new federal law looks like a significant expansion in the rights of individuals to be notified when their data is exposed to unauthorized parties.

*Note: I am aware that it says it covers "unsecured protected health information". However, if you look at the definitions, the "unsecured" part basically means unencrypted, while the "protected health information" refers back to the HIPAA regulations, and translates into individually identifiable health information which is either transmitted or maintained in any medium.

Monday, November 17, 2008

Encryption and the Law

Encryption technology is so commonplace, one might think that it would be required by basically all information security laws and regulations. However, as discussed in the comments to yesterday's post, encryption isn't even required by HIPAA, one of the most well known information security laws on the books. Well, as was the case with data breach notification laws, states are stepping up to fill the void left by the Federal Government. For example, as discussed in this post at The Email Admin Massachusetts is set to implement legislation requiring encryption of personal data for its residents (rule here). It is this kind of law (+ private rights of action) that I was referring to when I said if people want legal protection they should work to get new laws passed. The Federal Government is slow, and generally lags far behind. If consumers really want to make a change, the place to do it is at the state, not the federal, level.

Tuesday, April 15, 2008

A "New" Data Security Threat, and Why That's a Good Thing

this article from Computer World describes a "new" type of attack hackers have been using to get at credit card data: interception of unencrypted data while in transit. Now, as the article points out, the tools being used by hackers to intercept data in transit aren't novel technology, so the description of a "new" threat is, in one sense, not accurate. However, obtaining unencrypted information in transit marks a significant shift from the traditional hacker tactic of stealing information stolen from databases (see, e.g., TJX and CardSystems, the two biggest data security incidents on record). Of course, to a consumer, it doesn't matter much how their credit card numbers were stolen. However, to me, the fact that hackers are switching tactics is not only a big deal, it's also good news for at least three reasons.
First, it's harder for a hacker to steal huge amounts of data by intercepting it in transit than it is for a hacker to steal huge amounts of data by stealing it from a database. For example, it takes at least a month for a hacker to steal a month's worth of credit card numbers if they're being captured while in transit during a transaction. By contrast, a month's worth of credit card numbers can be stolen from a database in seconds. Thus, if hackers focusing on data in transit rather than data at rest should decrease the overall amount of data stolen.
Second, as described in the article, one reason that hackers are switching to catching information in transit rather than focusing on databases is that companies have hardened their databases in order to comply with the PCI DSS. This shows that compliance with the DSS, while admittedly not universal, has been widespread enough to change criminal behavior, something that is clearly a positive development for data security.
Third, the fact that hackers have switched from high value targets (databases) to relatively lower value targets (data transmissions) based on the behavior of their targets shows that, when properly motivated, regulation can address and alleviate serious problems (in this case, the problem of easily compromised databases). Of course, at this point, the switch from targeting databases to targeting transmissions means that some tinkering with the PCI DSS is probably in order. However, there is no reason why the same framework which resulted in the increases in database security that led to the shift can't also be used to address threats to transmissions. Thus, while the new tactics being used to steal credit cards represent new challenges, they also show that some progress has been made in the ongoing battle to increase the security of individual consumer data.

PostScript: On a quasi-related note for everyone who says that private initiatives are always superior to government action, the HIPAA security regulations actually address protecting information in transit and at rest, so they already address the "new" threat described in the article.

Sunday, February 24, 2008

It's Hard to Escape HIPAA

Computer World has an article up about online personal health records (PHR) systems, and a report which claims that they pose risks to consumer privacy. The premise of the report (and the article) is intriguing: online PHR systems could be a new type of business model which might undermine privacy and security rules governing traditional health care providers (particularly HIPAA). Happily (from a privacy standpoint), both the article and the report it is based on fail to make a case that PHR systems represent a new, serious hole in the privacy regime created by HIPAA. The biggest problems I had are that the report simply assumed that PHR systems are outside of HIPAA, and that it assumed that PHR systems which fall outside of HIPAA aren't required to comply with HIPAA's regulations. First, I'm not sure how many PHR systems actually fall outside of HIPAA. HIPAA doesn't just cover health care providers, it also covers health plans and health care clearinghouses. Before I become excited about PHR systems evading regulations covering health care providers, I would want to know whether they systems in question are part of one of the other categories of covered entities under HIPAA. Second, even if a PHR system isn't a covered entity under HIPAA, it might be required to comply with HIPAA due to its contracts with entities which are covered entities. Indeed, the HIPAA rules specifically require that covered entities enter into such contracts with certain of their business associates (e.g., 45 C.F.R. 164.314(a)(1) "Business Associate Contracts and Other Arrangements"). Again, the report simply didn't consider to what extent the hypothetical hole in HIPAA might be closed by the business associate portions of the regulations.

As a note, none of the above is meant to say that there aren't privacy risks involved in online PHR systems. For example, as the report notes, PHR systems represent one more repository of data which is subject to security breaches. Further, when you transmit data to such systems, it might be captured, either via snooping on a network, or via software like a keystroke logger installed on a local computer. However, neither of those risks have anything to do with HIPAA, and would be the same even if PHR systems were undeniably covered. Thus, while there are privacy concerns with PHR systems, the article didn't make the case that a HIPAA loophole is one of them.

Saturday, October 13, 2007

George Clooney and an Object Lesson on HIPAA

My guess is that basically everyone is aware, on at least some level, that George Clooney was involved in a motorcycle accident (if not, the CNN story is here). Normally, this is something that would hold no interest for me, and it certainly wouldn't be worth putting in a blog about information security and data privacy. In this case though, there's a twist...it seems that this "news" was broken by personnel at the hospital where Clooney was treated after the crash, with nontreating employees accessing Clooney's medical records and passing them, along with other information like Clooney's girlfriend's phone number to the press (details here). Such a leak is a clear violation of the HIPAA privacy rules (available here, which as a general rule, require consent for the disclosure of personally identifiable health information. 45 C.F.R. 164.508(a)(1) ("Except as otherwise permitted or required by this subchapter, a covered entity may not use or disclose protected health information without an authorization that is valid under this section."). Of course, it is possible to de-identify information in compliance with HIPAA. However, there is no chance that the information provided about Clooney could be considered properly de-identified.

So what are the consequences of such a blatant violation? So far, 40 employees at the facility where Clooney was treated are under investigation, and more than two dozen have been suspended without pay. A representative from their union said that the punishment is too harsh, but I'm curious what she expected. Under HIPAA, a health care provider "must have and apply appropriate sanctions against members of its workforce who fail to comply with the privacy policies and procedures of the covered entity or the requirements of this subpart." 45 C.F.R. 164.530(e)(1). Translation: no matter how sorry the employees are, they are still subject to their employer's sanction policy, which the employer is required by law to enforce.

The take home message of all this? Don't disclose personally identifiable health information, especially not to the media. If you do, federal law requires that you be punished.

Tuesday, September 11, 2007

Presumably, These People had Heard of HIPAA

Computer World has an interesting article up about companies which have, through their own incompetence, run afoul of the HIPAA data security rules. Highly recommended reading, and quite entertaining in a Darwin Award sort of way. My personal favorite was the one where a manager asked an employee to take backup tapes containing unencrypted personal data for patients home with him in order to accomplish the off site data storage requirements of HIPAA. When the tapes were stolen (of course) the employee reported their theft to the authorities and was fired for his trouble. The story doesn't end there though - because the employee was following his company policy and instructions from a supervisor, the employee is potentially protected from retaltiation from his employer. Thus, the employer might have bought itself both a HIPAA nightmare and a suit under the applicable whistleblower protection laws.

However, the bottom line of the article is serious. Too many organizations have been behaving as if HIPAA simply doesn't exist, or as if its requirements had no meaning. While the keystone cops level of competence of some organizations is amusing, it's no joke for the organizations and people involved. So, for HIPAA, know it, read it, do it...otherwise you could find yourself included in the next compilation of HIPAA disasters.

Saturday, June 16, 2007

HIPAA Enforcement Actions

The Department of Health and Human Services has launched the first audit of a hospital's compliance with HIPAA's security and privacy rules since they went into effect in 2005. According to Barry Runyon, an analyst at Gartner quoted in this article, it is likely that there will be more unannounced audits in the future. What effect this will have is anyone's guess, though in Piedmont's case the audit has already lead to the approval of a 1.3 million dollar item for encryption software in next year's hospital budget. It seems safe to assume that there will be a number of similar purchases in the health care industry going forward.

Thursday, June 7, 2007

HIPAA Enforcement Steps Up

When the Health Insurance Portability and Accountability Act (HIPAA) became effective in 2003, many health care providers scrambled to create the privacy notices required by the Act and didn't give HIPAA a second thought. However, a recent spate of private HIPAA litigation is raising the concern of hospitals and other health care providers. Although HIPAA does not provide a private right of action, several courts have recently been allowing private plaintiffs to use HIPAA standards to prove liability for failure to sufficiently protect the plaintiffs' sensitive medical data. Courts in North Carolina and Utah have recognized a common law duty of confidentiality by the health care provider, and have based that duty on the HIPAA standard of care to be applied to medical data. In addition, the U.S. Department of Health and Human Services, which enforces HIPAA, has been more actively enforcing its requirements, and instituting new enforcement measures such as HIPAA compliance audits. Health care providers would be well-advised to review the data security of their patients personal information to guard against potential liability and regulatory enforcement actions.