MAR 21, 2011 9:30am ET

Related Links

New Product News – May 24, 2013
May 24, 2013
Are Social Networks an Effective Business Communications Tool?
May 24, 2013
BI Gravitates Toward a Mixed Bag of What Works
May 24, 2013

Web Seminars

What Is Data Science? You Might Be Surprised!
June 3, 2013
AARP: Embracing Dynamic, Agile Analytics Platforms for Big Data
June 5, 2013
Hybrid Cloud Storage: Getting the Best of Two Worlds
June 26, 2013

OCR Seeks More Health Information Enforcement, Money

Print
Reprints
Email

March 21, 2011 - The HHS Office for Civil Rights in its fiscal year 2010 budget request is asking for $46.7 million in funding, an increase of $5.6 million over the current level, and with 76 percent of the new funds going for increased enforcement of health information privacy and security rules.

OCR's budget for health information privacy and security was $19.857 million in both fiscal years 2010 and 2011. The privacy/security FY 2010 request for $24.122 million - a $4.265 million increase - reflects a sharply increased workload because of the HITECH Act's provisions to strengthen and more aggressively enforce the HIPAA privacy and security rules, as well as enforce the breach notification rule.

The request for increased funding includes $2.283 million for placement of a privacy advisor in each of OCR's 10 regional offices, $1 million for enforcement of the security rule and $1.335 million for investigation of breaches of health information. The breach notification rule has substantially increased the office's workload, according to an OCR report justifying its budget requests that was sent to congressional appropriations committees.

"Current OCR practice is to validate, post to the HHS Web site and subsequently investigate all breach reports that impacted more than 500 individuals," according to the document. "Breach reports that impacted fewer than 500 individuals are compiled for future reporting to Congress, however, they are treated as discretionary and only investigated if resources permit. Based on OCR's current HIPAA caseload, almost all breach reports that impact less than 500 individuals are not investigated.

"This issue creates a problem in that if these breach reports were submitted to OCR as complaints by members of the public they would be investigated; however, investigating these reports would result in a more than doubling of OCR's HIPAA workload. The breach reports received to date represent a 109 percent increase in total HIPAA workload. This new workload would be in addition to the nearly 9,400 HIPAA Privacy and Security Rule complaints that OCR investigated in FY 2010. Additional FTEs are critical if OCR is to successfully investigate the estimated 20,000 combined breach reports and HIPAA complaints that are anticipated to be received annually."

OCR's report to justify its budget is available as a PDF here.

This story originally appeared on Health Data Management.

Joseph Goedert is news editor at Health Data Management.

Advertisement

Comments (0)

Be the first to comment on this post using the section below.

Add Your Comments:
You must be registered to post a comment.
Not Registered?
You must be registered to post a comment. Click here to register.
Already registered? Log in here
Please note you must now log in with your email address and password.

Where do young IT professionals (30 and under) obtain information to aid with daily role responsibilities and career development?

Trade publication websites 14%
Social media 23%
Vendor websites 4%
Vendor/community forums 7%
Newsletters 1%
Trade conferences/meetups 2%
RSS feeds 6%
Web search 44%

 

Twitter
Facebook
LinkedIn
Login  |  My Account  |  White Papers  |  Web Seminars  |  Events |  Newsletters |  eBooks
FOLLOW US
Please note you must now log in with your email address and password.