DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

AHIMA Files Response to HHS Privacy Rules

Posted on September 13, 2010 by Dissent

Press release from AHIMA:

“While AHIMA continues to applaud federal government support for the ideal of protecting patients’ health information rights, the proposed rule-making for HIPAA privacy, security and enforcement by HHS has a number of requirements that we do not believe the industry is ready to undertake; especially as it gears up for Meaningful Use. Today AHIMA is releasing its recommendations to the HHS Office of Civil Rights (OCR) that speak to the issues we believe are most critical to the patients of America, the healthcare industry and the best practice of health information management.

“As staunch supporters of patients’ health information rights, AHIMA agrees the single most contentious issue in the proposed regulation is the ability of individuals to restrict the information held by their healthcare providers from being shared with their health plan. While AHIMA believes an individual’s control over this data flow is valid, data flow restrictions in the HHS proposal creates unintended repercussions for data integrity, data processing and other elements within the current US reimbursement system.

“Many AHIMA members are engaged in providing patients’ individual and aggregate data for a variety of approved uses. There is a continued discussion within the profession on how to best cover the costs of the retrieval, analysis and release of information within the context of the privacy and security regulations, patient restrictions; and the need to verify the requesting individual as a means of keeping released information available to a necessary minimum. Additionally, we remain concerned the charges permitted by states or HIPAA do not cover all costs and ultimately raise the cost of health care.

“AHIMA also questions the sale of patient health information when an organization is being absorbed by a second organization. The OCR’s approach, while practical, raises the issue of whether consumers have the right to determine if their health information should be transferred with the ownership of a health organization.

“Finally, AHIMA feels strongly that the OCR needs to provide greater clarification regarding the definition of ‘agents’ as it relates to covered entities and who should be covered by HIPAA, including its hybrid organizations.”

Related posts:

  • HIPAA Security Rule Facility Access Controls – What are they and how do you implement them?
  • HHS Office for Civil Rights Imposes a $240,000 Civil Monetary Penalty Against Providence Medical Institute in HIPAA Ransomware Cybersecurity Investigation
  • HHS’ Office for Civil Rights Settles Malicious Insider Cybersecurity Investigation for $4.75 Million
  • HHS Office for Civil Rights Settles HIPAA Ransomware Cybersecurity Investigation for $90,000
Category: Uncategorized

Post navigation

← Follow-up: Lawsuit filed over horrific student records breach
ACH Case: Headed to Trial? →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Hunters International to provide free decryptors for all victims as they shut down (1)
  • SEC and SolarWinds Seek Settlement in Securities Fraud Case
  • Cyberattacks Disrupt Iran’s Bread Distribution, Payments Remain Frozen
  • Hacker with ‘political agenda’ stole data from Columbia, university says
  • Keymous+ Hacker Group Claims Responsibility for Over 700 Global DDoS Attacks
  • Data breach reveals Catwatchful ‘stalkerware’ is spying on thousands of phones
  • DOJ investigates ex-ransomware negotiator over extortion kickbacks
  • Hackers Using PDFs to Impersonate Microsoft, DocuSign, and More in Callback Phishing Campaigns
  • One in Five Law Firms Hit by Cyberattacks Over Past 12 Months
  • U.S. Sanctions Russian Bulletproof Hosting Provider for Supporting Cybercriminals Behind Ransomware

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Record-Breaking $1.55M CCPA Settlement Against Health Information Website Publisher
  • Ninth Circuit Reviews Website Tracking Class Actions and the Reach of California’s Privacy Law
  • US healthcare offshoring: Navigating patient data privacy laws and regulations
  • Data breach reveals Catwatchful ‘stalkerware’ is spying on thousands of phones
  • Google Trackers: What You Can Actually Escape And What You Can’t
  • Oregon Amends Its Comprehensive Privacy Statute
  • Wisconsin Supreme Court’s Liberal Majority Strikes Down 176-Year-Old Abortion Ban

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.