Browse > Home / Data Security / Stimulus Bill significantly modifies HIPAA regulations

| Subcribe via RSS

Stimulus Bill significantly modifies HIPAA regulations

March 15th, 2009 | Brian Wahoff | Posted in Data Security
Bookmark and Share

Buried within the huge American Recovery and Reinvestment Act (a.k.a, the “Stimulus Bill”) are a few changes to HIPAA’s Privacy and Security Rules, increasing the scope of coverage to include Business Associates. This means data security providers, contractors, and partners can be directly fined for informational security breaches that occur on their watch. The bill also increases the penalties for some of the violations.

Previously, Business Associates were required to comply only with a written business associate agreement. Now Business Associates are subject to many of the same requirements hospitals and medical providers are. They will be required to appoint a security official, develop written policies and procedures pertaining to data leakage, and training its workforce in electronic data protection.

In addition, breach notification requirements were increased. If a breach occurs, the specific business entity that has the breach will be required to notify every individual affected by the security breach. If current contact information is not available, the entity may be required to post notification on their website or in some other broadcast medium (television, newspapers). The bill also provides for the creation of a website by the Health and Human Services department to list information about these breaches.

Source: Stimulus Bill dramatically modifies HIPAA rules

Related posts:

  1. Links of the Week: Data Security Edition There were some great articles on CIO.com this week relating...
  2. Buy a used hard drive on eBay, get government secrets for free! Imagine it, you purchased a computer on eBay, plug it...
  3. 10 Tips for Protecting Business Data How do you protect confidential business data? Here are 10...

EPC is a provider of IT asset recovery, data destruction, computer recycling, hard drive shredding, used computer sales, website hosting, and more throughout the US and Canada. EPC is a member of the Basel Action Network and its data destruction processes have been certified by NAID. EPC has been in business for over 25 years and is a wholly owned subsidiary of CSI Leasing, Inc. To learn more about the services we offer, see our home page.

One Response to “Stimulus Bill significantly modifies HIPAA regulations”

  1. ArtZ Says:

    I am *so* glad that I have avoided writing any software which comes anywhere near a business which is regulated by HIPAA!