<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Law Blog 2.0 &#187; Enforcement</title>
	<atom:link href="http://law2point0.com/wordpress/topics/computer-security-law-federal/enforcement-computer-security-law-federal/feed/" rel="self" type="application/rss+xml" />
	<link>http://law2point0.com/wordpress</link>
	<description>This blog covers privacy, security, health information technology and e-discovery related topics. The primary goal of this blog is to raise public awareness of legal issues pertaining to the use of law and technology.</description>
	<lastBuildDate>Sat, 12 Jun 2010 02:39:44 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>HHS Tranfers Enforcement of the HIPAA Security Rule to OCR (Office of Civil Rights)</title>
		<link>http://law2point0.com/wordpress/2009/08/05/hhs-tranfer-of-enforcement-of-the-hipaa-security-rule-to-ocr-officr-of-civil-rights_/</link>
		<comments>http://law2point0.com/wordpress/2009/08/05/hhs-tranfer-of-enforcement-of-the-hipaa-security-rule-to-ocr-officr-of-civil-rights_/#comments</comments>
		<pubDate>Wed, 05 Aug 2009 05:56:56 +0000</pubDate>
		<dc:creator>Robert Hudock</dc:creator>
				<category><![CDATA[CMS]]></category>
		<category><![CDATA[Enforcement]]></category>
		<category><![CDATA[HIPAA Security]]></category>
		<category><![CDATA[Health and Humans Services (HHS)]]></category>
		<category><![CDATA[Office of Civil Rights]]></category>
		<category><![CDATA[Privacy Law]]></category>
		<category><![CDATA[HHS]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[OCR]]></category>
		<category><![CDATA[Poor Enforcement]]></category>

		<guid isPermaLink="false">http://law2point0.com/wordpress/?p=986</guid>
		<description><![CDATA[It appears HHS has taken this critique to heart.  HHS recently released notice of an important shift in the internal responsibility/delegation of authority for the monitoring and enforcement of the HIPAA Security Rule (and all additional health IT-related security responsibilities, under ARRA).  Previously responsibility for administering (interpretation, education, guidance, FAQs, etc), monitoring and enforcing the HIPAA Security Rule was a CMS responsibility (specifically, the CMS Office of E-Standards and Services or CMS/OESS).  The administration, monitoring and enforcement of the HIPAA Privacy Rule fell under the Office for Civil Rights [...]]]></description>
			<content:encoded><![CDATA[<p><div id="attachment_921" class="wp-caption alignleft" style="width: 160px"><a href="http://law2point0.com/wordpress/wp-content/uploads/2009/07/bigstockphoto_Analyzing_The_Laptop_4595739.jpg"  ><img class="size-thumbnail wp-image-921"  src="http://law2point0.com/wordpress/wp-content/uploads/2009/07/bigstockphoto_Analyzing_The_Laptop_4595739-150x150.jpg" alt="HIPAA Enforcement" width="150" height="150" /></a><p class="wp-caption-text">HIPAA Enforcement</p></div><br />
On October27, 2008 OCR issued a final report assessing CMS’s enforcement of the HIPAA Security Rule, entitled Nationwide Review of the Centers for Medicate Medicaid Services Health Insurance Portability and Accountability Act of 1996 Oversight (avaliable at </span><span style="text-decoration: underline;"><a href="http://law2point0.com/wordpress/wp-content/uploads/2009/08/CriticalOCR.pdf"    target="_blank">CriticalOCR</a>)</span> concluded that –</p>
<blockquote><p>CMS had taken limited actions to ensure that covered entities adequately implement the HIPAA Security Rule. These actions had not provided effective oversight or encouraged enforcement of the HIPAA Security Rule by covered entities. Although authorized to do so by Federal, regulations as of February 16,2006, CMS had not conducted any HIPAA Security Rule compliance reviews of covered entities. To fulfill its oversight responsibilities, CMS relied on complaints to identify any noncompliant covered entities that it might investigate. As a result, CMS had no effective mechanism to ensure that covered entities were complying with the HIPAA Security Rule or that ePHI was being adequately protected.</p></blockquote>
<p>It appears HHS has taken this critique to heart.  HHS recently released notice of an important shift in the internal responsibility/delegation of authority for the monitoring and enforcement of the HIPAA Security Rule (and all additional health IT-related security responsibilities, under ARRA).  Previously responsibility for administering (interpretation, education, guidance, FAQs, etc), monitoring and enforcing the HIPAA Security Rule was a CMS responsibility (specifically, the CMS Office of E-Standards and Services or CMS/OESS).  The administration, monitoring and enforcement of the HIPAA Privacy Rule fell under the Office for Civil Rights (OCR).</p>
<p>As of July 27, 2009 CMS no longer will handle enforcement of the HIPAA Security Rule.  HHS has made the decision to transfer the responsibility to OCR, which will now have the administrative and enforcement authority for both the HIPAA Privacy and HIPAA Security Rules, in addition to all the new ARRA provision on privacy and security (covering security of EHRs).  The Notice will be officially published August 4, 2009 in the Federal Register. (http://www.federalregister.gov/OFRUpload/OFRData/2009-18561_PI.pdf)</p>
<p>Over the past few years since the enactment of both HIPAA Rules, OCR and CMS have worked together on the administration and enforcement of the two rules.  According to their accounting of complaints and cases brought forward, the majority included both Privacy and a Security component.  In addition, the ARRA will result in increased security and enforcement of personal health information on EHRs, it seems HHS thought it would be the right time to make this transition and have a single office within the agency handle both related areas.</p>
<p>It is expected that people will be able to continue filing complaints through the same online system and that during a transition period, CMS will continue to work and now assist OCR in administering the Security enforcement responsibilities, as well as the administration of the Rule.  Increased enforcement is extremely likely.</p>
<div id="spreadx">&nbsp;<a target="_blank" href="http://digg.com/submit?phase=2&url=http://law2point0.com/wordpress/2009/08/05/hhs-tranfer-of-enforcement-of-the-hipaa-security-rule-to-ocr-officr-of-civil-rights_/"  target="_new"><img src="http://law2point0.com/wordpress/wp-content/plugins/spreadx/images/digg.gif" alt="Digg" border="0" /></a>&nbsp;&nbsp;<a target="_blank" href="http://www.facebook.com/share.php?u=http://law2point0.com/wordpress/2009/08/05/hhs-tranfer-of-enforcement-of-the-hipaa-security-rule-to-ocr-officr-of-civil-rights_/"  target="_new"><img src="http://law2point0.com/wordpress/wp-content/plugins/spreadx/images/facebook.gif" alt="Facebook" border="0" /></a>&nbsp;&nbsp;<a target="_blank" href="http://www.stumbleupon.com/submit?url=http://law2point0.com/wordpress/2009/08/05/hhs-tranfer-of-enforcement-of-the-hipaa-security-rule-to-ocr-officr-of-civil-rights_/&title=HHS+Tranfers+Enforcement+of+the+HIPAA+Security+Rule+to+OCR+%28Office+of+Civil+Rights%29"  target="_new"><img src="http://law2point0.com/wordpress/wp-content/plugins/spreadx/images/stumble.gif" alt="StumbleUpon" border="0" /></a>&nbsp;&nbsp;<a target="_blank" href="http://technorati.com/faves?add=http://law2point0.com/wordpress/2009/08/05/hhs-tranfer-of-enforcement-of-the-hipaa-security-rule-to-ocr-officr-of-civil-rights_/"  target="_new"><img src="http://law2point0.com/wordpress/wp-content/plugins/spreadx/images/technorati.gif" alt="Technorati" border="0" /></a>&nbsp;&nbsp;<a target="_blank" href="http://del.icio.us/post?url=http://law2point0.com/wordpress/2009/08/05/hhs-tranfer-of-enforcement-of-the-hipaa-security-rule-to-ocr-officr-of-civil-rights_/&title=HHS+Tranfers+Enforcement+of+the+HIPAA+Security+Rule+to+OCR+%28Office+of+Civil+Rights%29"  target="_new"><img src="http://law2point0.com/wordpress/wp-content/plugins/spreadx/images/delicious.gif" alt="Deli.cio.us" border="0" /></a>&nbsp;</div><p><a href="http://law2point0.com/wordpress/2009/08/05/hhs-tranfer-of-enforcement-of-the-hipaa-security-rule-to-ocr-officr-of-civil-rights_/" rel="bookmark">HHS Tranfers Enforcement of the HIPAA Security Rule to OCR (Office of Civil Rights)</a> originally appeared on <a href="http://law2point0.com/wordpress">Law Blog 2.0</a> on August 5, 2009.</p>
]]></content:encoded>
			<wfw:commentRss>http://law2point0.com/wordpress/2009/08/05/hhs-tranfer-of-enforcement-of-the-hipaa-security-rule-to-ocr-officr-of-civil-rights_/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
