The HIPAA Omnibus Rule

June 12, 2012
63 Views

The HIPAA omnibus rule, which extends the reach of liability to include business associates and subcontractors, should be out by the end of summer, according to Farzad Mostashari, the national coordinator for health information technology.

Submitted in March, the Office of Management and Budget will have up to 90 days to review the rule. HealthDataManagement.com reports Mostashari made the announcement during the opening keynote of the Health Privacy Summit in Washington, D.C.

The HIPAA omnibus rule, which extends the reach of liability to include business associates and subcontractors, should be out by the end of summer, according to Farzad Mostashari, the national coordinator for health information technology.

Submitted in March, the Office of Management and Budget will have up to 90 days to review the rule. HealthDataManagement.com reports Mostashari made the announcement during the opening keynote of the Health Privacy Summit in Washington, D.C.

When it comes to specific technology and HIPAA hosting requirements, the rule requires:

  1. Information system activity review – organizations must implement procedures to regularly review records of system activity, such as audit logs, access reports and security incident tracking reports. Log monitoring is a service that can address this requirement.
  2. Security reminders – take note of periodic security updates and implement them.
  3. Protection from malicious software – implement procedures for guarding against, detecting and reporting malicious software.
  4. Login monitoring – establish procedures for monitoring login attempts and reporting discrepancies. Multi-factor authentication, or two-factor authentication, is a low-cost and easy way to implement an additional security measure and method of verifying authorized access.
  5. Password management – document procedures for creating, changing and safeguarding passwords.

To ensure any lost or stolen data is recoverable and integrity is intact, the rule also requires:

  1. Data backup plan – establish and implement procedures to create and maintain retrievable exact copies of electronic protected health information (ePHI).
  2. Disaster recovery plan- establish (and implement as needed) procedures to restore any loss of data. [Read more about IT disaster recovery solutions].

According to Lexology.com, overall, the omnibus rule will propose changes to:

  • The Breach Notification Rule.
  • The HIPAA Enforcement Rule, implementing changes mandated by the HITECH Act.
  • The Privacy and Security Rules, implementing changes mandated by the HITECH Act, as well as other changes to the Privacy Rule proposed in July 2010.
  • The Privacy Rule, implementing changes required by the Genetic Information Nondiscrimination Act.

Do and be able to prove your due diligence as a covered entity. Find out the Top 5 Questions to Ask Your HIPAA Hosting Provider and read our HIPAA white paper for a deeper dive into staying compliant and working with business associates.

References:
HIPAA/HITECH Act Privacy Rule Coming in July 2012?
Mostashari: HIPAA Rules Out by Summer’s End

You may be interested

Healthcare Tech Advances That All Clinics Should Use
Medical Devices
461 views
Medical Devices
461 views

Healthcare Tech Advances That All Clinics Should Use

Dennis Hung - August 12, 2017

Healthcare will always be important to employees and the government since the issues surrounding healthcare are inherently ethical and moral…

Balancing Smart Data With Cybersecurity for Hospitals
Hospital Administration
454 views
Hospital Administration
454 views

Balancing Smart Data With Cybersecurity for Hospitals

Kayla Matthews - August 11, 2017

It should come as no surprise that your discussions and interactions with physicians and health professionals influence diagnoses, prescriptions, visit…

4 Ways to Halt Testosterone Problems After 40
Wellness
470 views
Wellness
470 views

4 Ways to Halt Testosterone Problems After 40

JohnHenning - August 10, 2017

Among men of all ages, testosterone is an important hormone for regulating health. Men over the age of 65 tend…