<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HIPAA Compliance Journal</title>
	<atom:link href="http://www.hipaacompliancejournal.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.hipaacompliancejournal.com</link>
	<description>HIPAA Compliance Journal</description>
	<lastBuildDate>Sat, 03 Mar 2012 11:52:07 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Knowing about changes in HIPAA for better compliance</title>
		<link>http://www.hipaacompliancejournal.com/knowing-about-changes-in-hipaa-for-better-compliance/</link>
		<comments>http://www.hipaacompliancejournal.com/knowing-about-changes-in-hipaa-for-better-compliance/#comments</comments>
		<pubDate>Sat, 03 Mar 2012 11:52:07 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Act]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Guide]]></category>
		<category><![CDATA[Legislation]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Privacy & security]]></category>
		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://www.hipaacompliancejournal.com/?p=491</guid>
		<description><![CDATA[The American Recovery and Reinvestment Act of 2009 (ARRA), also known as the stimulus bill made quite a few amendments to the Health Insurance Portability and Accountability Act (HIPAA), which was enacted in 1996. The most important and noticeable changes include the expansion of enforcement to states’ attorneys general and expansion of privacy and security &#8230; <a href="http://www.hipaacompliancejournal.com/knowing-about-changes-in-hipaa-for-better-compliance/">Continue reading</a>]]></description>
			<content:encoded><![CDATA[<p>The American Recovery and Reinvestment Act of 2009 (ARRA), also known as the stimulus bill made quite a few amendments to the Health Insurance Portability and Accountability Act (HIPAA), which was enacted in 1996.</p>
<p>The most important and noticeable changes include the expansion of enforcement to states’ attorneys general and expansion of privacy and security provisions related to “business associates” and new breach notification provisions along with changes in penalties to be imposed in case of breach of HIPAA.</p>
<p>With changes in HIPAA, the penalties can now be imposed on covered entities along with individuals in position to the previous law where penalties could only be imposed on covered entities. As such, if someone within an organization willingly neglects and doesn’t comply with the rules and makes wrongful disclosures, he or she will be subject to fines, as well as possible imprisonment. Also, in the past, enforcement and violations were addressed solely at the federal level by the Office of Civil Rights. Now, attorney generals are empowered to deal with enforcement and violations as well.</p>
<p>Protected health information can be released by covered entities without authorization only for purposes of treatment, billing and health care operations. Covered entities can’t release information beyond those purposes without authorization of the patient. In addition, specific types of information are viewed as more sensitive (e.g., mental health and substance abuse information, information about certain diseases, such as HIV) in many states and more restrictions on disclosure exist at the state level.</p>
<p>With new laws, patients will have a greater ability to try to find out who has accessed their protected health information. This means that covered entities and business associates could be asked to account for a good deal of information if they get a request. New regulations are being considered in this area, so it is an area to watch.</p>
<p>In order to make sure that they are HIPAA compliant, the covered entities should keep an eye on releases from HSS about changes, consult with their legal representative, make sure that their designated privacy officer is properly trained and that he or she is training their employees and keep their lines of communication open with business associates and make sure any contracts they have with them include appropriate provisions that will require they comply with HIPAA and all other state laws which may come into play.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.hipaacompliancejournal.com/the-hitech-act-revises-hipaa-regulations/" rel="bookmark" class="crp_title">The HITECH Act revises HIPAA regulations</a></li><li><a href="http://www.hipaacompliancejournal.com/how-should-chiropractors-comply-with-new-hipaa-regulations-for-business-associates/" rel="bookmark" class="crp_title">How should chiropractors comply with new HIPAA regulations for Business Associates?</a></li><li><a href="http://www.hipaacompliancejournal.com/federal-data-breach-notification-rules-kick-off/" rel="bookmark" class="crp_title">Federal Data Breach Notification Rules kick off</a></li><li><a href="http://www.hipaacompliancejournal.com/interim-final-rule-by-hhs-clarifies-breach-notification-provisions/" rel="bookmark" class="crp_title">Interim final rule by HHS clarifies breach notification provisions</a></li><li><a href="http://www.hipaacompliancejournal.com/medical-banking-and-hipaa-compliance/" rel="bookmark" class="crp_title">Medical Banking and HIPAA compliance</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.hipaacompliancejournal.com/knowing-about-changes-in-hipaa-for-better-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Forsythe To Offer Catbird&#8217;s Vsecurity® Software To Its Customers</title>
		<link>http://www.hipaacompliancejournal.com/forsythe-to-offer-catbirds-vsecurity%c2%ae-software-to-its-customers/</link>
		<comments>http://www.hipaacompliancejournal.com/forsythe-to-offer-catbirds-vsecurity%c2%ae-software-to-its-customers/#comments</comments>
		<pubDate>Mon, 07 Nov 2011 06:17:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Act]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Guide]]></category>
		<category><![CDATA[In the news]]></category>
		<category><![CDATA[Legislation]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Patients]]></category>
		<category><![CDATA[Privacy & security]]></category>
		<category><![CDATA[Products]]></category>
		<category><![CDATA[Strategy]]></category>
		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://www.hipaacompliancejournal.com/?p=489</guid>
		<description><![CDATA[Catbird is the pioneer in security and compliance for virtual, cloud and physical networks. The company has now entered into a partnership agreement with Forsythe, a leading IT infrastructure consultant and integrator, according to which Forsythe will offer Catbird&#8217;s vSecurity® software to bring PCI, HIPAA and SOX compliance to its customers who are moving to &#8230; <a href="http://www.hipaacompliancejournal.com/forsythe-to-offer-catbirds-vsecurity%c2%ae-software-to-its-customers/">Continue reading</a>]]></description>
			<content:encoded><![CDATA[<p>Catbird is the pioneer in security and compliance for virtual, cloud and physical networks. The company has now entered into a partnership agreement with Forsythe, a leading IT infrastructure consultant and integrator, according to which Forsythe will offer Catbird&#8217;s vSecurity® software to bring PCI, HIPAA and SOX compliance to its customers who are moving to virtual and cloud-based infrastructure.</p>
<p>This software from Catbird harnesses the power of virtualization to deliver the industry&#8217;s most comprehensive security and compliance solution for virtual and cloud systems. The software introduces a new model for data center security and enforces controls on virtual machines, their network attributes, virtual networks, and the switch fabric – protecting the whole data plane.</p>
<p>&#8220;Security and compliance are critical components for every IT infrastructure. As environments are virtualized, new risks are introduced due to a loss of process control across four change dimensions,&#8221; says David Poarch, VP, security of Forsythe. &#8220;Catbird has developed a solution specifically for virtualized environments that delivers dynamic, elastic security and integrated compliance for sensitive and mission-critical applications.&#8221;</p>
<p>&#8220;Recent guidance from PCI, NIST and SANS proves that relying on traditional physical firewalls and physical network inspection is risky and will not pass an audit. Catbird vSecurity® was built from the ground up to do virtual and cloud security better, faster and cheaper,&#8221; said Edmundo Costa, Catbird CEO. &#8220;Forsythe&#8217;s extensive experience in integrating not only virtualized solutions, but also physical infrastructure solutions, across security, servers, networks and storage make them a strong partner in helping our virtualization clients with their security needs.&#8221;</p>
<p>&#8220;Virtualization security opens the door for mission-critical applications that have traditionally been left out of virtualization roll-outs,&#8221; added Costa. &#8220;vSecurity will provide Forsythe customers with the ability to meet the new requirements and maximize their virtualization and cloud ROI by being able to include in their deployment plans most applications that were previously excluded, such as, for example, applications that handle PCI data.&#8221;</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.hipaacompliancejournal.com/what-about-network-security-in-vm-virtual-machine-servers/" rel="bookmark" class="crp_title">What about Network Security in VM (Virtual Machine) servers?</a></li><li><a href="http://www.hipaacompliancejournal.com/allied-telesis-hosted-pacs-solutions-partnership-to-offer-a-unique-cloud-based-pacs-service/" rel="bookmark" class="crp_title">Allied Telesis-Hosted PACS Solutions partnership to offer a unique cloud-based PACS service</a></li><li><a href="http://www.hipaacompliancejournal.com/cloud-storage-and-hipaa-compliance/" rel="bookmark" class="crp_title">Cloud storage and HIPAA compliance</a></li><li><a href="http://www.hipaacompliancejournal.com/25-more-health-care-organizations-opt-for-edgewall-nac-appliance/" rel="bookmark" class="crp_title">25 more health care organizations opt for EdgeWall NAC appliance</a></li><li><a href="http://www.hipaacompliancejournal.com/worm-emerging-as-a-new-generation-storage-technology-in-healthcare-industry/" rel="bookmark" class="crp_title">WORM emerging as a new generation storage technology in healthcare industry</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.hipaacompliancejournal.com/forsythe-to-offer-catbirds-vsecurity%c2%ae-software-to-its-customers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Harris Corporation to support VA&#8217;s transition to new coding standards</title>
		<link>http://www.hipaacompliancejournal.com/harris-corporation-to-support-vas-transition-to-new-coding-standards/</link>
		<comments>http://www.hipaacompliancejournal.com/harris-corporation-to-support-vas-transition-to-new-coding-standards/#comments</comments>
		<pubDate>Wed, 02 Nov 2011 06:05:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Guide]]></category>
		<category><![CDATA[In the news]]></category>
		<category><![CDATA[Privacy & security]]></category>
		<category><![CDATA[Products]]></category>
		<category><![CDATA[Strategy]]></category>
		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://www.hipaacompliancejournal.com/?p=485</guid>
		<description><![CDATA[The U.S. Department of Veterans Affairs (VA) has awarded Harris Corporation a $5.3 million two-year contract to provide remediation to the VA&#8217;s Health Administration Center (HAC) Cache System to address new medical coding standards. Harris will support the VA&#8217;s migration to new coding standards in time for Oct.1, 2013 transition which will improve VA billing &#8230; <a href="http://www.hipaacompliancejournal.com/harris-corporation-to-support-vas-transition-to-new-coding-standards/">Continue reading</a>]]></description>
			<content:encoded><![CDATA[<p>The U.S. Department of Veterans Affairs (VA) has awarded Harris Corporation a $5.3 million two-year contract to provide remediation to the VA&#8217;s Health Administration Center (HAC) Cache System to address new medical coding standards. Harris will support the VA&#8217;s migration to new coding standards in time for Oct.1, 2013 transition which will improve VA billing and payment processes for veterans.</p>
<p>This transition will also help HAC to produce more accurate records as well as conduct more detailed population assessments and studies. Additionally, the ICD-10 migration will improve the HAC&#8217;s payment systems for veterans and their family members with more accurate billing information. The Harris team, along with subcontractors 7 Delta Inc. and Vangent Inc., will complete all phases of the ICD-10 integration and software development life cycle.</p>
<p>International Statistical Classification of Diseases and Related Health Problems (ICD) Codes are used to classify diseases and other medical problems under a single standard and promote international comparability with treatment and billing. As part of the Health Insurance Portability and Accountability Act (HIPAA) 5010 transition, the U.S. Department of Health and Human Services (HHS) has mandated that all covered healthcare entities be ICD-10 compliant by Oct. 1, 2013.</p>
<p>&#8220;The ICD-10 transition will enable the HAC to improve the accuracy and efficiency of claims processing for veterans and their family members,&#8221; said Jim Traficant, president, Harris Healthcare. &#8220;By migrating to ICD-10, the Health Administration Center continues to lead the healthcare industry in adopting the latest standards to better serve our veterans.&#8221;</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.hipaacompliancejournal.com/emedon-launches-online-resource-to-help-transition-to-hipaa-upgraded-version/" rel="bookmark" class="crp_title">Emedon launches online resource to help transition to HIPAA upgraded version</a></li><li><a href="http://www.hipaacompliancejournal.com/is-the-transition-to-hipaa-5010-too-demanding-on-hospitals/" rel="bookmark" class="crp_title">Is the transition to HIPAA 5010 too demanding on hospitals?</a></li><li><a href="http://www.hipaacompliancejournal.com/axway-edifecs-to-provide-integrated-solutions-for-new-hipaa-regulations/" rel="bookmark" class="crp_title">Axway &#038; Edifecs to provide integrated solutions for new HIPAA regulations</a></li><li><a href="http://www.hipaacompliancejournal.com/foresights-customers-to-benefit-from-eemergences-interpretive-content/" rel="bookmark" class="crp_title">Foresight&#8217;s customers to benefit from eEmergence&#8217;s interpretive content</a></li><li><a href="http://www.hipaacompliancejournal.com/how-to-ensure-hipaa-compliance-with-international-outsourcing-of-healthcare-services/" rel="bookmark" class="crp_title">How to ensure HIPAA compliance with international outsourcing of healthcare services?</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.hipaacompliancejournal.com/harris-corporation-to-support-vas-transition-to-new-coding-standards/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>97% of Americans want more control on their PHI: New survey reveals</title>
		<link>http://www.hipaacompliancejournal.com/97-of-americans-want-more-control-on-their-phi-new-survey-reveals/</link>
		<comments>http://www.hipaacompliancejournal.com/97-of-americans-want-more-control-on-their-phi-new-survey-reveals/#comments</comments>
		<pubDate>Fri, 21 Oct 2011 07:14:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Guide]]></category>
		<category><![CDATA[In the news]]></category>
		<category><![CDATA[Legislation]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Patients]]></category>
		<category><![CDATA[Privacy & security]]></category>
		<category><![CDATA[Strategy]]></category>
		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://www.hipaacompliancejournal.com/?p=483</guid>
		<description><![CDATA[Privacy advocate Dr Deborah Peel ‘s Patient Privacy Rights Foundation and Zogby International has conducted a new survey which has revealed that a whopping 97% of the 2,000 adults questioned want the right to control their own personal medical information and be allowed to limit with whom their “sensitive information” is shared. In a press &#8230; <a href="http://www.hipaacompliancejournal.com/97-of-americans-want-more-control-on-their-phi-new-survey-reveals/">Continue reading</a>]]></description>
			<content:encoded><![CDATA[<p>Privacy advocate Dr Deborah Peel ‘s Patient Privacy Rights Foundation and Zogby International has conducted a new survey which has revealed that a whopping 97% of the 2,000 adults questioned want the right to control their own personal medical information and be allowed to limit with whom their “sensitive information” is shared.</p>
<p>In a press release accompanying the release of the survey results Dr Peel said “No matter how you look at it, Americans want to control their own private health information. They overwhelmingly believe that they are the only people in the right position to make decisions about how their information can be used. Researchers do not get a free pass.”</p>
<p>The survey reveals that many of the Americans want to be in control of all of their electronic medical records and have the right to limit with whom their doctors, insurance companies and even the government can allow the information to be given to. Some of them showed their worry about the fact that their sensitive information was at risk of being accessed by employers, researchers, ex-spouses and abusive partners.</p>
<p>Dr Peel’s Austin, TX based advocacy group is calling for the creation of a “do not release” list, something that would work along the same lines as the “do not call” lists that telemarketers must abide by. 73% of those surveyed said they would sign up if such a list were ever to be created.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.hipaacompliancejournal.com/people-want-more-control-on-their-phi-reveals-dr-peels-survey/" rel="bookmark" class="crp_title">People want more control on their PHI: Reveals Dr. Peel&#8217;s survey</a></li><li><a href="http://www.hipaacompliancejournal.com/mgma-survey-reveals-that-practices-still-not-prepared-for-hipaa-5010/" rel="bookmark" class="crp_title">MGMA survey reveals that practices still not prepared for HIPAA 5010</a></li><li><a href="http://www.hipaacompliancejournal.com/millions-of-americans-losing-health-insurance-due-to-cost-issues/" rel="bookmark" class="crp_title">Millions of Americans losing health insurance due to cost issues</a></li><li><a href="http://www.hipaacompliancejournal.com/complacency-afflict-hipaa-compliance/" rel="bookmark" class="crp_title">Complacency afflict HIPAA compliance?</a></li><li><a href="http://www.hipaacompliancejournal.com/hipaa-ordered-calls-exempted-under-new-telemarketing-rules/" rel="bookmark" class="crp_title">HIPAA ordered calls exempted under new Telemarketing rules</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.hipaacompliancejournal.com/97-of-americans-want-more-control-on-their-phi-new-survey-reveals/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HIMSS webinar on importance of HIPAA compliance to an IT manager</title>
		<link>http://www.hipaacompliancejournal.com/himss-webinar-on-importance-of-hipaa-compliance-to-an-it-manager/</link>
		<comments>http://www.hipaacompliancejournal.com/himss-webinar-on-importance-of-hipaa-compliance-to-an-it-manager/#comments</comments>
		<pubDate>Wed, 19 Oct 2011 11:43:30 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Act]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[In the news]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Patients]]></category>
		<category><![CDATA[Privacy & security]]></category>
		<category><![CDATA[Strategy]]></category>
		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://www.hipaacompliancejournal.com/?p=479</guid>
		<description><![CDATA[A Health Information &#38; Management Systems Society (HIMSS) webinar based on the importance of HIPAA compliance for an IT manager is to be held on October 20, 2011, which will be sponsored by Axway, the Business Interaction Networks company. The webinar which has been entitled, &#8220;What does HIPAA Compliance mean to an IT Manager?&#8221; will &#8230; <a href="http://www.hipaacompliancejournal.com/himss-webinar-on-importance-of-hipaa-compliance-to-an-it-manager/">Continue reading</a>]]></description>
			<content:encoded><![CDATA[<p>A Health Information &amp; Management Systems Society (HIMSS) webinar based on the importance of HIPAA compliance for an IT manager is to be held on October 20, 2011, which will be sponsored by Axway, the Business Interaction Networks company.</p>
<p>The webinar which has been entitled, &#8220;What does HIPAA Compliance mean to an IT Manager?&#8221; will be a case study with Catholic Healthcare West. The webcast will explore how Catholic Healthcare West is managing the challenges of rapidly building their healthcare managed file transfer (MFT) ecosystem while continuing to adhere to Health Information Portability and Accountability Act (HIPAA) compliance. Catholic Healthcare West will share their secrets as to how they ensure patient privacy, and build partner networks that make end-to-end management of certain patient files possible.</p>
<p>The webinar will include discussions between Axway and Catholic Healthcare West on how to leverage technology in a way that allows to access critical health information while maintaining security and the public&#8217;s trust at the same time. Various companies participating in the webinar will also get an opportunity to share their experiences designing internal project support for building large-scale MFT infrastructure projects and impart lessons learned during deployment.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.hipaacompliancejournal.com/webinar-on-hipaa-compliance-under-hitech-by-the-institute-for-health-technology-transformation/" rel="bookmark" class="crp_title">Webinar on HIPAA compliance under HITECH by the Institute for Health Technology Transformation</a></li><li><a href="http://www.hipaacompliancejournal.com/paul-reymann-to-review-hipaa-hitech-at-logrhythms-webinar/" rel="bookmark" class="crp_title">Paul Reymann to review HIPAA &#038; HITECH at LogRhythm&#8217;s webinar</a></li><li><a href="http://www.hipaacompliancejournal.com/a-webinar-on-hipaa-and-hitech-compliance/" rel="bookmark" class="crp_title">A webinar on HIPAA and HITECH compliance</a></li><li><a href="http://www.hipaacompliancejournal.com/allied-telesis-hosted-pacs-solutions-partnership-to-offer-a-unique-cloud-based-pacs-service/" rel="bookmark" class="crp_title">Allied Telesis-Hosted PACS Solutions partnership to offer a unique cloud-based PACS service</a></li><li><a href="http://www.hipaacompliancejournal.com/surveys-reveal-non-compliance-of-new-hitech-act-provisions/" rel="bookmark" class="crp_title">Surveys reveal non-compliance of new HITECH Act provisions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.hipaacompliancejournal.com/himss-webinar-on-importance-of-hipaa-compliance-to-an-it-manager/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The scope of HIPAA Security Rules</title>
		<link>http://www.hipaacompliancejournal.com/the-scope-of-hipaa-security-rules/</link>
		<comments>http://www.hipaacompliancejournal.com/the-scope-of-hipaa-security-rules/#comments</comments>
		<pubDate>Mon, 17 Oct 2011 04:56:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Act]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Guide]]></category>
		<category><![CDATA[In the news]]></category>
		<category><![CDATA[Legislation]]></category>
		<category><![CDATA[Patients]]></category>
		<category><![CDATA[Privacy & security]]></category>
		<category><![CDATA[Strategy]]></category>
		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://www.hipaacompliancejournal.com/?p=477</guid>
		<description><![CDATA[HIPAA security rules deal with health information that is maintained or transmitted electronically. This rule emphasizes on the security framework for those entities that deal with medically sensitive information.  As such, they apply to health plans, health care clearinghouses, and to any health care provider who transmits health information in electronic form in connection with &#8230; <a href="http://www.hipaacompliancejournal.com/the-scope-of-hipaa-security-rules/">Continue reading</a>]]></description>
			<content:encoded><![CDATA[<p>HIPAA security rules deal with health information that is maintained or transmitted electronically. This rule emphasizes on the security framework for those entities that deal with medically sensitive information.  As such, they apply to health plans, health care clearinghouses, and to any health care provider who transmits health information in electronic form in connection with a transaction for which the Secretary of HHS has adopted standards under HIPAA (the “covered entities”).</p>
<p>According to the Security rule, all HIPAA entities must provide a security plan with safeguards in the following areas:</p>
<p>Administrative safeguards: As per HIPAA Security Rule, a covered entity must identify and analyze potential risks to e-PHI, and it must implement security measures that reduce risks and vulnerabilities to a reasonable and appropriate level. It should also designate a security official who is responsible for developing and implementing its security policies and procedures.</p>
<p>Physical safeguards: A covered entity must limit physical access to its facilities while ensuring that authorized access is allowed.</p>
<p>Technical safeguards: A covered entity must implement technical policies and procedures that allow only authorized persons to access electronic protected health information (e-PHI).</p>
<p>HIPAA Security Rule is especially applicable to HIPAA compliant web designers and web-hosting providers. HIPAA entities looking for secure solutions must make sure that whatever solutions they implement must comply with the security specifications defined in the rule.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.hipaacompliancejournal.com/the-administrative-safeguards-policies-of-security-rule/" rel="bookmark" class="crp_title">The administrative safeguards policies of Security Rule</a></li><li><a href="http://www.hipaacompliancejournal.com/the-security-rule/" rel="bookmark" class="crp_title">The Security Rule</a></li><li><a href="http://www.hipaacompliancejournal.com/conforming-to-hipaa-privacy-and-security-rule/" rel="bookmark" class="crp_title">Conforming to HIPAA Privacy and Security Rule</a></li><li><a href="http://www.hipaacompliancejournal.com/complying-with-hipaa-administrative-security-rule/" rel="bookmark" class="crp_title">Complying with HIPAA Administrative Security Rule</a></li><li><a href="http://www.hipaacompliancejournal.com/how-to-look-for-a-security-official-to-safeguard-your-ephi/" rel="bookmark" class="crp_title">How to look for a Security Official to safeguard your EPHI?</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.hipaacompliancejournal.com/the-scope-of-hipaa-security-rules/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A Sample Patient Consent Form for HIPAA</title>
		<link>http://www.hipaacompliancejournal.com/a-sample-patient-consent-form-for-hipaa/</link>
		<comments>http://www.hipaacompliancejournal.com/a-sample-patient-consent-form-for-hipaa/#comments</comments>
		<pubDate>Fri, 14 Oct 2011 07:00:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Guide]]></category>
		<category><![CDATA[Legislation]]></category>
		<category><![CDATA[Patients]]></category>
		<category><![CDATA[Privacy & security]]></category>
		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://www.hipaacompliancejournal.com/?p=474</guid>
		<description><![CDATA[Medical practitioners often use Patient Consent Form in their practice which specifies methods by which a patient agrees to let him use his or her protected information for routine TPO purposes. Should a patient complain that his or her privacy rights have been violated, a consent form gives out an extra measure of protection if &#8230; <a href="http://www.hipaacompliancejournal.com/a-sample-patient-consent-form-for-hipaa/">Continue reading</a>]]></description>
			<content:encoded><![CDATA[<p>Medical practitioners often use Patient Consent Form in their practice which specifies methods by which a patient agrees to let him use his or her protected information for routine TPO purposes. Should a patient complain that his or her privacy rights have been violated, a consent form gives out an extra measure of protection if your practice is investigated for HIPAA noncompliance. <a href="http://www.tosmg.com/hipaa_consent_form.php"><strong>Patient Consent Form Can Be Downloaded Here.</strong></a></p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.hipaacompliancejournal.com/a-sample-of-patients-authorization-form-under-hipaa/" rel="bookmark" class="crp_title">A sample of patient&#8217;s authorization form under HIPAA</a></li><li><a href="http://www.hipaacompliancejournal.com/patient-consent-not-needed-for-%e2%80%98routine-use%e2%80%99-health-information-court/" rel="bookmark" class="crp_title">Patient consent not needed for ‘routine use’ health information: Court</a></li><li><a href="http://www.hipaacompliancejournal.com/lookout-for-fepra-and-hipaa-forms-when-your-child-starts-college/" rel="bookmark" class="crp_title">Lookout for FEPRA and HIPAA forms when your child starts college</a></li><li><a href="http://www.hipaacompliancejournal.com/vulnerability-of-hipaa/" rel="bookmark" class="crp_title">Vulnerability of HIPAA!</a></li><li><a href="http://www.hipaacompliancejournal.com/in-case-of-hipaa-violations/" rel="bookmark" class="crp_title">In Case of HIPAA Violations</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.hipaacompliancejournal.com/a-sample-patient-consent-form-for-hipaa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Shared Health awarded the HIPAA Security and Privacy Covered Entity accreditations from URAC</title>
		<link>http://www.hipaacompliancejournal.com/shared-health-awarded-the-hipaa-security-and-privacy-covered-entity-accreditations-from-urac/</link>
		<comments>http://www.hipaacompliancejournal.com/shared-health-awarded-the-hipaa-security-and-privacy-covered-entity-accreditations-from-urac/#comments</comments>
		<pubDate>Wed, 06 Jul 2011 05:15:06 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Act]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Guide]]></category>
		<category><![CDATA[In the news]]></category>
		<category><![CDATA[Legislation]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Privacy & security]]></category>
		<category><![CDATA[Products]]></category>
		<category><![CDATA[Strategy]]></category>
		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://www.hipaacompliancejournal.com/?p=467</guid>
		<description><![CDATA[URAC is a Washington, DC-based health care accrediting organization that establishes quality standards for the health care industry. It has awarded the HIPAA Security and Privacy Covered Entity accreditations to Shared Health, one of the leaders in HealthCare Industry. URAC&#8217;s HIPAA Security Accreditation program provides an emphasis on the fundamentals of ongoing risk managemen. It &#8230; <a href="http://www.hipaacompliancejournal.com/shared-health-awarded-the-hipaa-security-and-privacy-covered-entity-accreditations-from-urac/">Continue reading</a>]]></description>
			<content:encoded><![CDATA[<p>URAC is a Washington, DC-based health care accrediting organization that establishes quality standards for the health care industry. It has awarded the HIPAA Security and Privacy Covered Entity accreditations to Shared Health, one of the leaders in HealthCare Industry.</p>
<p>URAC&#8217;s HIPAA Security Accreditation program provides an emphasis on the fundamentals of ongoing risk managemen. It enables health care organizations to validate their security compliance program to safeguard Protected Health Information (PHI) in accordance with the HIPAA Security Rule. Thus, this rpogram ensure healthcare organizations’ commitment to fair information practices, and also helps them show others that they have taken the necessary steps to protect health information privacy in accordance with the HIPAA Privacy Rule.</p>
<p>&#8220;We are thrilled to achieve this high level in health care information security and privacy,&#8221; said Jana Skewes, chief executive officer of Shared Health. &#8220;The URAC accreditations highlight our commitment to delivering the most secure, best privacy protection practices in our industry through innovative health information technology solutions at the point of care, which is the perfect prescription for better health nationwide.&#8221;</p>
<p>Shared Health has shown lead by implementation of a comprehensive security compliance plan, rigorous management policies and procedures, administrative, physical and technical safeguards and special requirements for group health plans. It also met stringent standards for privacy protection, including implementation of a privacy compliance plan, strict policies and procedures, workforce training, disclosures, complaints and special requirements for health plans, group health plans, hybrid entities, health care providers, affiliated covered entities and organized health care arrangements.</p>
<p>&#8220;By applying for and receiving the HIPAA Security and Privacy Covered Entity accreditations, Shared Health has demonstrated a commitment to quality health care,&#8221; said Alan P. Spielman, URAC president and CEO. &#8220;Quality health care is crucial to our nation&#8217;s welfare and it is important to have organizations that are willing to measure themselves against national standards.&#8221;</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.hipaacompliancejournal.com/urac-awards-hipaa-security-privacy-covered-entity-accreditations-to-share-health/" rel="bookmark" class="crp_title">URAC awards HIPAA Security &#038; Privacy Covered Entity accreditations to Share Health</a></li><li><a href="http://www.hipaacompliancejournal.com/the-administrative-safeguards-policies-of-security-rule/" rel="bookmark" class="crp_title">The administrative safeguards policies of Security Rule</a></li><li><a href="http://www.hipaacompliancejournal.com/the-scope-of-hipaa-security-rules/" rel="bookmark" class="crp_title">The scope of HIPAA Security Rules</a></li><li><a href="http://www.hipaacompliancejournal.com/knowing-what-the-privacy-standards-provide-for/" rel="bookmark" class="crp_title">Knowing what the Privacy Standards provide for</a></li><li><a href="http://www.hipaacompliancejournal.com/april-21-d-day-for-small-plans/" rel="bookmark" class="crp_title">April 21 &#8211; D-Day For Small Plans</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.hipaacompliancejournal.com/shared-health-awarded-the-hipaa-security-and-privacy-covered-entity-accreditations-from-urac/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MGMA survey reveals that practices still not prepared for HIPAA 5010</title>
		<link>http://www.hipaacompliancejournal.com/mgma-survey-reveals-that-practices-still-not-prepared-for-hipaa-5010/</link>
		<comments>http://www.hipaacompliancejournal.com/mgma-survey-reveals-that-practices-still-not-prepared-for-hipaa-5010/#comments</comments>
		<pubDate>Wed, 29 Jun 2011 05:10:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Act]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Guide]]></category>
		<category><![CDATA[In the news]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Patients]]></category>
		<category><![CDATA[Privacy & security]]></category>
		<category><![CDATA[Strategy]]></category>
		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://www.hipaacompliancejournal.com/?p=466</guid>
		<description><![CDATA[The Medical Group Management Association has released its survey which reveals that most of the physicians are still unprepared for a shift to the new electronic claims submission standards known as HIPAA 5010, although the adoption deadline is just six months away. Only 9.2 per cent of the physicians were performing test procedures to the &#8230; <a href="http://www.hipaacompliancejournal.com/mgma-survey-reveals-that-practices-still-not-prepared-for-hipaa-5010/">Continue reading</a>]]></description>
			<content:encoded><![CDATA[<p>The Medical Group Management Association has released its survey which reveals that most of the physicians are still unprepared for a shift to the new electronic claims submission standards known as HIPAA 5010, although the adoption deadline is just six months away. Only 9.2 per cent of the physicians were performing test procedures to the software updates provided by the electronic medical record vendors and about 38.2 per cent had no schedules for such tests as yet.</p>
<p>Of the 356 practices that MGMA surveyed, just 15.2% had conducted an impact analysis to examine what the practice needed to do to prepare. Most practices said they had either not started preparing (45.2%) or were less than 25% done preparing (26.4%).</p>
<p>However, whether the medical practices participated in the event of 15th June was not revealed by the survey. The Centers for Medicare &amp; Medicaid Services had declared June 15 as National 5010 Testing Day. The American Medical Association and the MGMA had suggested that CMS conduct such an event.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.hipaacompliancejournal.com/cms-to-hold-teleconferences-on-icd-10-and-hipaa-5010-implementation/" rel="bookmark" class="crp_title">CMS to hold teleconferences on ICD-10 and HIPAA 5010 implementation</a></li><li><a href="http://www.hipaacompliancejournal.com/is-the-transition-to-hipaa-5010-too-demanding-on-hospitals/" rel="bookmark" class="crp_title">Is the transition to HIPAA 5010 too demanding on hospitals?</a></li><li><a href="http://www.hipaacompliancejournal.com/97-of-americans-want-more-control-on-their-phi-new-survey-reveals/" rel="bookmark" class="crp_title">97% of Americans want more control on their PHI: New survey reveals</a></li><li><a href="http://www.hipaacompliancejournal.com/people-want-more-control-on-their-phi-reveals-dr-peels-survey/" rel="bookmark" class="crp_title">People want more control on their PHI: Reveals Dr. Peel&#8217;s survey</a></li><li><a href="http://www.hipaacompliancejournal.com/mindleaf-introduces-new-5010-conversion-services/" rel="bookmark" class="crp_title">MindLeaf introduces new 5010 conversion services</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.hipaacompliancejournal.com/mgma-survey-reveals-that-practices-still-not-prepared-for-hipaa-5010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RAC agrees to pay $1 million to settle violations of HIPAA</title>
		<link>http://www.hipaacompliancejournal.com/rac-agrees-to-pay-1-million-to-settle-violations-of-hipaa/</link>
		<comments>http://www.hipaacompliancejournal.com/rac-agrees-to-pay-1-million-to-settle-violations-of-hipaa/#comments</comments>
		<pubDate>Sat, 11 Jun 2011 10:48:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Act]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Guide]]></category>
		<category><![CDATA[In the news]]></category>
		<category><![CDATA[Legislation]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Patients]]></category>
		<category><![CDATA[Privacy & security]]></category>
		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://www.hipaacompliancejournal.com/?p=464</guid>
		<description><![CDATA[The HIPAA Privacy Rule requires health plans, health care clearinghouses and most health care providers (covered entities), including most pharmacies, to safeguard the privacy of patient information, and maintain adequate levels of privacy and security when disposing off various information. When media circulated various videotaped incidents in a variety of cities across United States in &#8230; <a href="http://www.hipaacompliancejournal.com/rac-agrees-to-pay-1-million-to-settle-violations-of-hipaa/">Continue reading</a>]]></description>
			<content:encoded><![CDATA[<p>The HIPAA Privacy Rule requires health plans, health care clearinghouses and most health care providers (covered entities), including most pharmacies, to safeguard the privacy of patient information, and maintain adequate levels of privacy and security when disposing off various information.</p>
<p>When media circulated various videotaped incidents in a variety of cities across United States in which pharmacies were shown to have disposed of prescriptions and labeled pill bottles containing individuals&#8217; identifiable information in industrial trash containers that were accessible to the public. Rite Aid pharmacy stores in several of the cities were highlighted in media reports. Following this, OCR, which enforces the HIPAA Privacy and Security Rules, opened its investigation of RAC and found it guilty.</p>
<p>Now, Rite Aid Corporation and its 40 affiliated entities has decided to pay $1 million to settle potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Rule. It has also signed a consent order with the Federal Trade Commission (FTC) to settle potential violations of the FTC Act. Along with this, it has also agreed to take corrective action to improve measures to safeguard the privacy of its customers when disposing of identifying information on pill bottle labels and other health information.</p>
<p>&#8220;It is critical that companies, large and small, build a culture of compliance to protect consumers&#8217; right to privacy and safeguard health information. OCR is committed to strong enforcement of HIPAA,&#8221; said Georgina Verdugo, director of OCR. &#8220;We hope that this agreement will spur other health organizations to examine and improve their policies and procedures for protecting patient information during the disposal process.&#8221;</p>
<p>The HHS corrective action plan will be in place for three years; the FTC order will be in place for 20 years.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.hipaacompliancejournal.com/cvs-caremark-corp-to-pay-225-million-to-hhs/" rel="bookmark" class="crp_title">CVS Caremark Corp. to pay $2.25 million to HHS</a></li><li><a href="http://www.hipaacompliancejournal.com/government-agencies-have-finally-got-into-action-to-implement-hipaa/" rel="bookmark" class="crp_title">Government Agencies Have Finally Got Into Action to Implement HIPAA</a></li><li><a href="http://www.hipaacompliancejournal.com/common-mistakes-which-should-be-avoided-by-employers/" rel="bookmark" class="crp_title">Common mistakes which should be avoided by employers</a></li><li><a href="http://www.hipaacompliancejournal.com/complying-with-hipaa-administrative-security-rule/" rel="bookmark" class="crp_title">Complying with HIPAA Administrative Security Rule</a></li><li><a href="http://www.hipaacompliancejournal.com/hipaa-administrative-simplification-security-rule/" rel="bookmark" class="crp_title">HIPAA Administrative Simplification Security Rule</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.hipaacompliancejournal.com/rac-agrees-to-pay-1-million-to-settle-violations-of-hipaa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

