Sunday, August 18, 2013

Compliance Date for New HIPAA Rules is September 23

New rules for the updated Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule are effective September 23, 2013. The federal rule applies to health care providers, health plans and other covered entities and their business associates. 

New Rule
The revisions, announced in March 2013 and effective September 23, require the following steps:
  • Conduct a security risk assessment;
  • Revise their existing privacy, security and breach notification policies and procedures;
  • Make copies of those revised privacy policies available to patients;
  • Amend business associate agreements to reflect the new regulations; and
  • Retrain practice staff on the revised policies
The new rule prohibits the sale of federally protected patient health information (PHI), and prohibits the use of PHI for marketing purposes without authorization from the patient. In addition, a patient may request a practice to withhold disclosure of PHI related to a particular service to a health plan if the patient has paid for the service out-of-pocket.

Federal law requires practitioners to provide all patients with notices of the measures taken to protect patient information. Failure to provide the required HIPAA notices or meet standards may result in investigations and possible civil or criminal penalties.


HIPAA Resources
AOA is providing resources to help optometrists follow the mandatory HIPAA rules, including a newly developed HIPAA Compliance Section of the AOA website. Resources include:


In addition, the  AOAExcelTM HIPAA page includes the AOA White paper Updated HIPAA Regulations-What Optometrists Need to Know, with questions and answers about the privacy regulations.  
The U.S. Department of Health & Human Services (HHS) offers resources for HIPAA-covered entities and their business associates.