We use cookies, including third-party cookies from Google to serve personalized ads through AdSense, to operate this site and understand how it is used. By continuing to browse, you accept this use. See our Privacy Policy and Terms of Use for details, including how to opt out of personalized advertising.
Accept
Health Works CollectiveHealth Works CollectiveHealth Works Collective
  • Health
    • Mental Health
  • Policy and Law
    • Global Healthcare
    • Medical Ethics
  • Medical Innovations
  • News
  • Wellness
  • Tech
Search
© 2023 HealthWorks Collective. All Rights Reserved.
Reading: The HIPAA Omnibus Rule
Share
Notification Show More
Font ResizerAa
Health Works CollectiveHealth Works Collective
Font ResizerAa
Search
Follow US
  • About
  • Contact
  • Privacy
© 2023 HealthWorks Collective. All Rights Reserved.
Health Works Collective > eHealth > The HIPAA Omnibus Rule
eHealth

The HIPAA Omnibus Rule

onlinetech
onlinetech
Share
3 Min Read
SHARE

The HIPAA omnibus rule, which extends the reach of liability to include business associates and subcontractors, should be out by the end of summer, according to Farzad Mostashari, the national coordinator for health information technology.

Submitted in March, the Office of Management and Budget will have up to 90 days to review the rule. HealthDataManagement.com reports Mostashari made the announcement during the opening keynote of the Health Privacy Summit in Washington, D.C.

The HIPAA omnibus rule, which extends the reach of liability to include business associates and subcontractors, should be out by the end of summer, according to Farzad Mostashari, the national coordinator for health information technology.

Submitted in March, the Office of Management and Budget will have up to 90 days to review the rule. HealthDataManagement.com reports Mostashari made the announcement during the opening keynote of the Health Privacy Summit in Washington, D.C.

More Read

Image
Strategy and Practice Intertwine in a New Social Media Book by the Mayo Clinic
Regina Holliday’s Medical Advocacy Timeline
Join me on June 2 in Baltimore to hear me speak about mHealth, cloud, wireless life sciences, patient access to EHRs, and Connected Medical Devices
Do Electronic Health Records Reduce Malpractice Claims?
Video: Why Everyone in Your Practice Needs Basic Medical Coding Training

When it comes to specific technology and HIPAA hosting requirements, the rule requires:

  1. Information system activity review – organizations must implement procedures to regularly review records of system activity, such as audit logs, access reports and security incident tracking reports. Log monitoring is a service that can address this requirement.
  2. Security reminders – take note of periodic security updates and implement them.
  3. Protection from malicious software – implement procedures for guarding against, detecting and reporting malicious software.
  4. Login monitoring – establish procedures for monitoring login attempts and reporting discrepancies. Multi-factor authentication, or two-factor authentication, is a low-cost and easy way to implement an additional security measure and method of verifying authorized access.
  5. Password management – document procedures for creating, changing and safeguarding passwords.

To ensure any lost or stolen data is recoverable and integrity is intact, the rule also requires:

  1. Data backup plan – establish and implement procedures to create and maintain retrievable exact copies of electronic protected health information (ePHI).
  2. Disaster recovery plan- establish (and implement as needed) procedures to restore any loss of data. [Read more about IT disaster recovery solutions].

According to Lexology.com, overall, the omnibus rule will propose changes to:

  • The Breach Notification Rule.
  • The HIPAA Enforcement Rule, implementing changes mandated by the HITECH Act.
  • The Privacy and Security Rules, implementing changes mandated by the HITECH Act, as well as other changes to the Privacy Rule proposed in July 2010.
  • The Privacy Rule, implementing changes required by the Genetic Information Nondiscrimination Act.

Do and be able to prove your due diligence as a covered entity. Find out the Top 5 Questions to Ask Your HIPAA Hosting Provider and read our HIPAA white paper for a deeper dive into staying compliant and working with business associates.

References:
HIPAA/HITECH Act Privacy Rule Coming in July 2012?
Mostashari: HIPAA Rules Out by Summer’s End

TAGGED:HIT
Share This Article
Facebook Copy Link Print
Share

Stay Connected

1.5KFollowersLike
4.5KFollowersFollow
2.8KFollowersPin
136KSubscribersSubscribe

Latest News

Biofeedback Technology in Addiction Treatment: What the Evidence Shows So Far -- AI-generated illustration
Biofeedback Technology in Addiction Treatment: What the Evidence Shows So Far
Addiction Addiction Recovery
September 28, 2026
Charity Care Is Written Into Hospital Policy. It Rarely Makes It Onto the Bill. -- AI-generated illustration
Charity Care Is Written Into Hospital Policy. It Rarely Makes It Onto the Bill.
Business Hospital Administration
September 25, 2026
A Global Perspective on Medicine: Lessons Learned Across Borders -- AI-generated illustration
A Global Perspective on Medicine: Lessons Learned Across Borders
Medicines
September 23, 2026
KMG Psychiatry Discusses the Role of Self-Awareness in Mental Health  -- AI-generated illustration
KMG Psychiatry Discusses the Role of Self-Awareness in Mental Health 
Mental Health
September 23, 2026

You Might also Like

Forget the Ambien and Prozac–Just Put Away Your Cell Phone, Part I

July 11, 2012

Telemedicine in North Carolina

August 14, 2012

3 Steps Towards Adopting Electronic Health Records

August 16, 2011

HIE: The Information Sharing Imperative

November 13, 2011
Subscribe
Subscribe to our newsletter to get our newest articles instantly!
Follow US
© 2008-2026 HealthWorks Collective. All Rights Reserved.
  • About
  • Contact
  • Privacy
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?