OCT 4, 2010 5:25am ET

Related Links

New Product News – May 24, 2013
May 24, 2013
Are Social Networks an Effective Business Communications Tool?
May 24, 2013
BI Gravitates Toward a Mixed Bag of What Works
May 24, 2013

Web Seminars

Data Protection in the Cloud: What You Need to Know About Security and Compliance—Right Now
Available On Demand

Privacy Expert To Congress: Mandate More Protections

Print
Reprints
Email

October 4, 2010 – The Center for Democracy & Technology is recommending to Congress a series of steps to go beyond the HITECH Act and further improve the privacy and security of health information.

These include denying meaningful use incentive payments to provider organizations that significantly violate the HIPAA privacy and security rules, giving patients a limited right to sue for privacy violations, and mandating certain strong security safeguards, including encryption.

"The prospect of storing and moving personal health data electronically in an environment where security is a low institutional priority should give us all pause," said Deven McGraw, director of CDT's health privacy project in congressional testimony on Sept. 30. "We need - through certified electronic health record requirements and enhancements to the HIPAA Security Rule - stronger requirements with respect to data security, as well as more proactive education and guidance from regulators."

For instance, electronic health records certification requirements require the ability of EHRs to encrypt data in motion and at rest, generate an audit trail and provide authentication and access controls.

"However, there is no clear requirement, either in the meaningful use criteria or in the HIPAA Security Rule, to actually implement and routinely use these functionalities," McGraw testified. "Providers are required under meaningful use to perform a security risk assessment and respond to any deficiencies discovered, but this falls short of a clear requirement to implement or have a plan for implementing the functionalities required for EHR certification."

To access the full testimony of McGraw and others who appeared before the House Committee on Science and Technology, click here.

This story originally appeared on Health Data Management.

Joseph Goedert is news editor at Health Data Management.

Advertisement

Comments (0)

Be the first to comment on this post using the section below.

Add Your Comments:
You must be registered to post a comment.
Not Registered?
You must be registered to post a comment. Click here to register.
Already registered? Log in here
Please note you must now log in with your email address and password.

Where do young IT professionals (30 and under) obtain information to aid with daily role responsibilities and career development?

Trade publication websites 14%
Social media 23%
Vendor websites 4%
Vendor/community forums 7%
Newsletters 1%
Trade conferences/meetups 2%
RSS feeds 6%
Web search 44%

 

Twitter
Facebook
LinkedIn
Login  |  My Account  |  White Papers  |  Web Seminars  |  Events |  Newsletters |  eBooks
FOLLOW US
Please note you must now log in with your email address and password.