HITECH Act Mandated Changes
Date: 4 Feb 2010 | Comment (0)As of February 18, 2010, all HIPAA covered entities (physicians and their employees) will also be under HITECH (Health Information Technology Economic and Clinical Health) Act. The HIPAA Security Rules require covered entities and business associates to implement and adopt administrative, physical, and technical safeguards to ensure that electronic protected health information (“ePHI”) is adequately protected.
HITECH also includes civil and criminal penalties for violations of HIPAA and compliance audits. These penalties range from $100 to $50,000 per violation based on the nature and extent of the violation and the extent of the resulting harm. With these new compliance responsibilities in an increased enforcement environment at both the federal and state levels, physicians need to quickly take steps to prepare themselves for the first wave of audits.
Covered entities also need to be cognizant of what measures to take to both limit their compliance liability with their Business Associates (BA) and to structure their contractual agreements with BAs to better enable efficient and effective compliance and notification response requirements.
Working with Joan Kiel, PhD, the Allegheny County Medical Society has developed sample policies and an online training module to help ensure compliance with the new HITECH rules. Additional information and registration details are available at http://www.acms.org/training/coveredentity/index.html







