MAY 18, 2011 5:33am ET

Related Links

Obama: Better Federal Data Quality, Availability within Year
May 23, 2012
Bloomberg Launches Data Management Service with PolarLake Buy
May 23, 2012
Dispatches from MIT CIO Symposium
May 22, 2012

Web Seminars

The Big Deal About Big Data Governance
Available On Demand
Treating Big Data Performance Woes with the Data Replication Cure
Available On Demand
The Role of Data Virtualization in a World of Big Data
June 6, 2012

Final PHI Protection Rule Won't Mandate Encryption

Print
Reprints
Email

May 18, 2011 – The omnibus federal final rule that will cover changes to the HIPAA privacy, security, breach notification and enforcement rules will not include a mandate for encryption of protected health information, confirms Susan McAndrew, deputy director for health information privacy in the Department of Health and Human Services' Office for Civil Rights.

Asked in an email interview with Health Data Management if some type of encryption mandate would be in the final rule, McAndrew noted that none of the earlier proposals called for a regulatory change to the existing security rule on encryption. Consequently, additional rulemaking would be necessary to mandate encryption, and such a mandate won't be in the omnibus final rule. "If the requirement for encryption changes from an addressable implementation specification to a required implementation specification under the security rule, then normal notice and comment rulemaking processes would need to follow," she said.

McAndrew wasn't as clear when asked if the breach notification "harm threshold," which enables an organization to not provide notification of a breach if it determines no consequential harm has or will result, will be eliminated in the final rule.

"OCR received public comment on the interim final breach notification rules both for and against how the rule defined incidents that qualified as breaches requiring individual notification," she noted. "These comments will be carefully reviewed and OCR will respond to them in the final rule."

McAndrew's answers to other questions broke no new ground:

Q: What are the reasons for the delay in the final privacy/security/breach/enforcement rules and the expected release?

A: OCR is working to address the concerns raised during the public comment periods on the proposed rules and is ensuring that the new regulatory requirements operate as intended. To minimize the transitional burden on covered entities OCR is also issuing a single final rulemaking that combines four separate dockets issued during 2009 and 2010. While there is no definite date, OCR expects to publish the rule in the coming months.

Q: What are the toughest issues being worked out?

A: Changes to HIPAA under the HITECH Act presents challenges to privacy and security protections for patient information. The impacts of the new breach notification requirements are already evident - not only in terms of public perception of those entities that are reporting breaches - but also in the behavior of covered entities. The increased penalties for failure to comply with the HIPAA privacy or security requirements, particularly with respect to business associates who face the same penalties as covered entities, have raised awareness and renewed commitment to a culture of compliance.

This story originally appeared on Health Data Management.

Joseph Goedert is news editor at Health Data Management.

Advertisement

Comments (0)

Be the first to comment on this post using the section below.

Add Your Comments:
You must be registered to post a comment.
Not Registered?
You must be registered to post a comment. Click here to register.
Already registered? Log in here
Please note you must now log in with your email address and password.
Twitter
Facebook
LinkedIn
Login  |  My Account  |  White Papers  |  Web Seminars  |  Events |  Newsletters |  eBooks
FOLLOW US
Please note you must now log in with your email address and password.