|
What's HIPAA?I just got a warning from a colleague that I need to ensure that our weblog needs to be HIPAA complaint because I've ended up having a lot of ER nurses join our community and share stories about life in the emergency room. What the heck? What's HIPAA and why do I need to worry about it? There are a small number of privacy laws that fill the business world with great anxiety because of the tremendous burden it puts on people to be fully compliant and the dangers of non-compliance. One splendid example that you'll read about every week in the business press is Sarbanes-Oxley (which I've also written about here: What is Sarbanes-Oxley?) Another of these regulations is HIPAA, aka the Health Insurance Portability and Accountability Act of 1996, which ostensibly focuses on health insurance, but is really much more about the critical importance of privacy for any online medical information. Personally, it's a really good law because there's little that I think should be more private and hard to dig up than personal medical information. As you might expect, the U.S. Government has a ton of information about HIPAA online, including an entire site from the Department of Health and Human Services's Office for Civil Rights - HIPAA, where they explain that: "A major goal of the Privacy Rule is to assure that individuals' health information is properly protected while allowing the flow of health information needed to provide and promote high quality health care and to protect the public's health and well being. The Rule strikes a balance that permits important uses of information, while protecting the privacy of people who seek care and healing. Given that the health care marketplace is diverse, the Rule is designed to be flexible and comprehensive to cover the variety of uses and disclosures that need to be addressed. " Now, does your online discussion weblog therefore mean that you too are subject to HIPAA regulations? I don't think so. According to their information on who must comply with HIPAA standards? you're not affected: "As required by Congress in HIPAA, the Privacy Rule covers:
"These entities (collectively called "covered entities") are bound by the new privacy standards even if they contract with others (called "business associates") to perform some of their essential functions. The law does not give the Department of Health and Human Services (HHS) the authority to regulate other types of private businesses or public agencies through this regulation. For example, HHS does not have the authority to regulate employers, life insurance companies, or public agencies that deliver social security or welfare benefits." I'm certainly not a lawyer and you shouldn't make legal decisions based on my interpretation of the HIPAA laws, but it does seem to me that you're clear in that regard. However, you do have some potential privacy issues on your weblog nonetheless. It's not about HIPAA, it's about privacy overall, and I would strongly encourage you to create some sort of privacy policy that requires anyone who participates in your site to respect the need for patient confidentiality and agree not to violate that privacy or even reference patients with sufficient detail that a skilled investigator could track a comment back to a specific patient. If there are a couple of nurses who are particularly explicit in their commentary you might also email them and let them know of your concerns in this regard. But HIPAA? No, I think you're probably clear in that regard. Good luck to you!
Categorized:
Business and Management
(Article 6435,
Written by Dave Taylor)
Tagged: Health Insurance Portability and Accountability Act of 1996, hipaa Previous: How come I can't see my friend's LinkedIn Connections? Next: How do I charge a completely dead Apple iPod? Subscribe!
Is there a need to sign the HIPAA form for all related health care information exchange that happens between two health care vendors or providers? Posted by: ashok at February 19, 2007 6:14 PMAlthough we don't have nurses and other health care types posting comments, we have done some research into HIPAA in conjunction with some of our products. We supply a line of wall files that we call HIPAA compliant wall files mainly aimed at doctors and other professionals offices and patient rooms. The primary concept we gleaned from this research was that reasonable steps must be taken to ensure visual security of a person's personal data. Posted by: Garnet Bailey at February 20, 2007 1:09 PMDear Dave, I work in the NICU. The Hospital I work for is a big advocate for not shutting the unit down even while report is going on. I feel like this is a HIPAA violation. Some of these parents are so interested in what is going on with other children they try to eaves drop on the report. I end up pointing to information on the Kardex to prevent information from being over heard. Is allowing parents to remain in the NICU during report a HIPAA violation? Can you help me find literature that shows whether or not HIPAA is being violated by this action? Posted by: Nurse's Nurse at May 15, 2007 11:09 AMHIPAA is indeed useful for protecting and securing PHI in the healthcare industry. Organizations that comply to HIPAA would be more relied on. Posted by: Ratika at September 6, 2010 7:15 AMI have something to say, now that you mention it, but ...
I do have a comment, now that you mention it!
|
Recommended
Recent Entries
Search
I Need Help!
Apple iPad Help
Articles and Reviews Auctions and Online Shopping Blogs and RSS Feeds Building Web Site Traffic Business and Management CGI Scripts and Web Site Programming Computer and Internet Basics d) None of the Above Facebook Help Google Plus Help HTML and CSS Industry News and Trade Shows iPhone and Cell Phone Help iPod, Sony PSP and MP3 Player Help Mac OS X Help Pay Per Click (PPC) Advertising Search Engine Optimization (SEO) Shell Script Programming Tech Support Video Help The Writing Business Twitter, LinkedIn and Social Network Help Unix and Linux Help Video Game Tips and Help Windows PC Help WordPress Help |