Friday, June 15, 2007

Save My Grave

Wow! Another great "Golden Hippo" nominee for creative use of HIPAA. This time it is Nebraska Attorney General Jon Bruning, who has declared that numbered markers on graves from the state mental hospital from over a century ago cannot be indentified by name, because of HIPAA. The McCook Daily Gazette disagrees:

We understand Nebraska Health and Human Services' reluctance to release patient information -- most of us wouldn't want such information about ourselves to be made public.

But we have seen HIPAA used as an excuse for all sorts of obstruction, from the condition of accident victims to the location of a house fire.

We have to question the need to conceal the name or date of death for someone who died nearly 120 years ago, especially to people who only want to trace their family trees.

Send in the Clowns

Security is a strategy, not a policy!

A box left in a trash bin could end up leaving some local doctors a little lighter in the wallet.

The Greenwich Post was given a box filled medical documents from the Dearfield Medical Building that may have been improperly disposed of. The box was discovered at 4 Dearfield Drive inside a trash bin in May and contains information about lab tests and insurance approvals as well as other medical issues. These documents are not medical charts, but do contain patient names and contact information.

According the United States Department of Health and Human Services, under the privacy regulations for the Health Insurance Portability and Accountability Act (HIPAA), documents such as the ones in the trash bin are supposed to be kept confidential and then shredded when disposed of, not just thrown out in a box.

While it was not confirmed from which office at the medical building all the documents originated, the names of Alfred Padilla and Judith Goldberg-Berman, who run an endocrinology practice in the building, appear frequently on the documents.
Dr. Padilla spoke to Greenwich Post on Tuesday and expressed surprise that the documents had not been shredded. He said it was the practice’s policy to make sure all medical documents were properly disposed of.

“We take HIPAA very seriously,” Dr. Padilla said. “In general we will shred everything we throw away.”

Dr. Padilla said there were some documents that were kept in a room at the practice to be shredded, but hadn’t yet been. He speculated that the cleaning crew at the building might have accidentally disposed of them.

“We have a pile of boxes to be shredded,” Dr. Padilla said. “If the cleaning people came and took the box, mistaking it for garbage, that would have been what happened... My suspicion is that one of our shredding boxes ended up in the trash bin. That’s the only theory I can come up with.”


Sheesh. Who'da ever thunk that cleaning people might mishandle patient records?

Fight For All The Wrong Reasons

I TOLD you so!

An audit of Atlanta's Piedmont Hospital that was initiated by the U.S. Department of Health and Human Services in March is raising concerns in the health care industry about the prospect of more enforcement actions related to the data security requirements of the federal HIPAA legislation.

The audit was the first of its kind since the Health Insurance Portability and Accountability Act's security rules went into effect in April 2005, joining data privacy mandates that were already in place. The security rules require organizations that handle electronic health data to implement measures for controlling access to confidential medical information and protecting it against compromise and misuse.


If your management has been slacking on compliance, it is time to read them this article from Computer World. Enforcement is the new black; the free ride is over. I absolutely agree with Barry Runyon:

The mere fact that an audit of HIPAA security compliance was conducted for the first time has many in the health care industry preparing for more enforcement actions, according to Barry Runyon, an analyst at Gartner Inc. "I don't think Piedmont was an anomaly," he said. "My sense is that there is going to be more feet on the street from HHS going on unannounced audits."


Good grief, we in this industry have had plenty of time to get our acts together, and most of the provisions are nothing more than best practices anyway.

Please, please, please do not be the next hospital, clinic, or other covered entity that I write about here. Get compliant!

Wednesday, June 13, 2007

If Everyone Cared

From another forum where I am a moderator comes this question from someone worried about IT security:

I was asked this question, and I'm not quite sure how to answer it. Where does one turn when they see a complete disregard and lack of importance in the compliance for HIPAA security. The privacy rules are basically followed. But on the technology side, they have policies in place that are just not followed, upper management has stated behind closed doors that HIPAA and security really aren't that important. There really is no one who is the HIPAA security officer. HR is the HIPAA privacy officer. And no one in the healthcare facility will take the issues seriously - even when approached by their own IT about its importance.
Where do they turn, and how do they go about it while keeping their job


The problem is, of course, that enforcement has been criminally lax. But with the recent change in power comes a new emphasis on enforcement, and there are going to be covered entities that are going to become the big, awful example. In the past very little was done when someone was found to be out of compliance, but recent news suggests that the tide is turning.
One of the most compelling reasons to follow the HIPAA security rules is that they are generally best practices anyway. The time to protect yourself is not after you have already been exposed.
All it would take would for there to be a big data loss, with PHI exposed, and those same scofflaws would be scrambling to save their behinds. And the goat would be the IT guy--- no matter the final outcome, the first instinct of those in charge is to blame underlings, and nobody likes IT people anyway.
The process is complaint driven, which means that someone has to rat them out first. The good news is that any affected person can complain, which in practice means just about anybody.
I would suggest the hair-on-fire approach, pointing out to the beancounters that the exposure is real, the dangers are extreme, and the risk to their jobs, the economic strength of the facility, and the possible irreparable PR disaster of a major data loss is not in any way worth not following procedures.
Of course, it is important to make certain that the procedures and policies don't interfere with the business at hand. Healthcare frontliners are notoriously hostile to extra steps that seem to make their primary mission more difficult. Your procedures need to be as transparent to the end user as possible, or they will be disregarded, bypassed or ignored.
The person may be able to convince management of the possible financial risks involved, as money seems to motivate. They may also volunteer to be the champion on this, as sometimes the only reason things don't happen is nobody wants to bell the cat.
Of course, without the buy-in of top management, this is all moot, because every organization is like a fish, in that it rots from the head down. Without a security officer, and absent help from on high, there is not much to be done.
Good luck on this!

Tuesday, May 22, 2007

Three Of A Perfect Pair

HIPAA as a PR Shield:
Javier Espinosa, a senior at SMU, recently came within two hours of dying. Doctors at Methodist Hospital in Dallas saved his life with an emergency liver transplant.

While Espinosa initially went to SMU's Memorial Health Center to be treated and diagnosed for his cold-like symptoms, he said the health center is not equipped with proper resources to diagnose and treat severe cases.

"The health center can't recognize and [doesn't] really know how to handle hard-core cases like mine," Espinosa said.

Espinosa said he expected the health center to offer advice and guidance when they were unable to diagnose his symptoms. However, staff at the health center said very little and did not suggest going to a hospital.

"I expected the health center to be more responsible," he said. "It was obvious my test results were off the chart and they weren't like 'Go and see a doctor in this hospital,' and they should have."

The health center had no comment regarding Espinosa's case and referred questions to SMU's Assistant Director of News & Communications, Robert Bobo.

Bobo said that Espinosa's case cannot be talked about unless he signs a contract releasing the school from HIPAA or FERPA. HIPAA is the Health Insurance Portability and Accountability Act and according to the online U.S. Department of Health and Human Services it's the "national standards to protect the privacy or personal health information." FERPA is the Family Educational Rights and Privacy Act.


HIPAA as interpreted by the Three Stooges:

So, we all trooped in to the county’s selected health care provider for TB testing. I really didn’t know exactly what was supposed to be done and presumed that the Occupational Medicine Center we went to did. Wrong. I came to find out that while half of us received the appropriate testing, the other half received misinformation. And our second test was done way too soon, necessitating a third test. Further, I found out that we were treated as “new hires” in a big hospital rather than acute EMS exposures. After several weeks of attempting to deal with the situation as Jane Q. Paramedic, I was still unable to convince the hospital to give me a copy of my own medical records, despite executed HIPAA releases and dozens of phone calls. Seems you have to get your medical records from somewhere six states away. Then, they sent me all of my medical records for the last 10 years, with the exception of the one for the exposure, which was the only one I requested. They also sent me a big bill for the copies.


And finally, HIPAA as the New Sheriff in Town:

Arizona requires mandatory disclosure of medical records in medical malpractice cases and, amazingly, is currently considering a change to mandatory arbitration procedures to require the same thing. As we have often explained, these provisions violate HIPPA, the comprehensive federal scheme that provides essential privacy rights for medical records.

The voice of reason is finally kicking in: the Georgia Supreme Court recently struck down their statute requiring mandatory disclosure of medical records in medical malpractice cases citing HIPPA preemption. The decision basically holds that the Georgia statute's failure to include provisions required by HIPPA, such as "the HIPAA requirement of notice of the right to revoke" or "the failure to require a specific and meaningful identification of the information to be disclosed and the failure to provide for an expiration date or a sufficient expiration event," makes the Georgia invalid in light of the preemptive effect of HIPPA.

Sunday, April 29, 2007

I Made My Excuses and Left

No more excuses:

The same swing can be seen with other laws. Twenty-five percent of large companies are not compliant with California’s security breach notification law but only 14 percent of midsize companies are not compliant. Midsize companies are less compliant when it comes to the Health Insurance Portability and Accountability Act, or HIPAA (27 percent of midsize companies are noncompliant versus 21 percent of large companies).

The reason, as usual, is money. Sarbanes-Oxley and HIPAA compliance is more complicated and expensive than, for example, GLBA compliance. But the mid-market’s excuse that it doesn’t have the money to comply may be becoming obsolete. According to Mark Lobel, a PricewaterhouseCoopers advisory partner specializing in security, the price is dropping for technologies that help companies comply with security and privacy laws. With affordable tools coming onto the market that can sniff out the data you need to protect, excuses from mid-market CIOs that it’s too expensive to comply with Sox and other laws will no longer work, Lobel asserts.

Mo Money, Mo Problems

AAAAAAAAArrrrrrgggggg!

Attorney David Hanson, a partner in Michael Best & Friedrich and chairman of its healthcare practice group, noted there are people in the health field who think the industry already is spending too much time and money on patient data security - thanks to regulations like the Health Insurance Portability and Accountability Act.


Too much time and money? Yeah, like there hasn't been any data-breeches lately in the health-care sector. Only if you are spending your money stupidly. Only if your time is spent trying to find ways to just barely comply, as a part of a general CYA policy concerning compliance.

Show me a properly designed and fully supported patient data security system. Then bitch about too much time and money. Anybody who thinks this deserves whatever exposure to lawsuit they get.

"It's a strategy, not a policy!"

Days of Our Wives

You know, this HIPAA thing often seems to lead in completely unexpected directions. Who would have ever guessed that a boring collection of medical regulations would somehow connect with the trial for statuatory rape of a notorious cult leader?

A 5th District judge has ordered a media coalition seeking to unseal a secret petition issued in the prosecution of polygamous sect leader Warren S. Jeffs to submit to the court briefs addressing issues of the leader's privacy rights under HIPAA, the Health Insurance Portability and Accountability Act of 1996.


You know, it used to be if I wanted to be left alone on a long flight, when the person in the seat next to me asked what I did, I told them I was a HIPAA consultant and offered to tell them all about it. They would immediately feign fatigue, and be fake-snoring in minutes. But if this sort of thing keeps happeneing, I'll be wearing wrap-around shades and travelling with an entourage.

Hat too Flat

At a recent speech in Washington DC, Google's Adam Bosworth set forth a bunch of stuff planned for Google Health, described as as likely to be “simple, sloppy solution” as befitting the Google way of doing business. All of it sounded pretty good, except when he unleashed this whopper:

Google is trying to lay the groundwork to have HIPAA overturned, and short of that would like to educate providers and patients about how to get at their information even within the constraints of current laws. They’d like to see consumers have the ability to review and challenge their records as is the case with credit bureau information


Ummm.... this is already a right under HIPAA--- Mr.Bosworth seems to have been talking through his hat.

Wednesday, April 04, 2007

Stupid Things

How in the world can this still happen?

Empire Blue Cross and Blue Shield, a division of WellPoint a medical services company in the US , has begun notifying 75,000 members that a compact disc holding their personal and medical information has been lost, according to published reports.

The personal data was stored on an unencrypted CD


Not one day passes that there isn't another report of ID theft or smething similar, so awareness must surely be there. Low cost encription software is cheap, easy to use and ubiquitous. There are thousans of us out there talking ourselves blue in the face about this stuff.
Johns Hopkins had a similar issue lately, but the data was encripted, so no problem.
How can this still happen?

Highway Rain

Shred, please.

Hundreds of confidential documents from the Cleveland Clinic littered Interstate 77 on Tuesday after blowing off the back of a garbage truck.

Clinic spokeswoman Eileen Sheil said "almost all" of the 300 to 500 documents were recovered from the area of Fleet Avenue.

The documents are employees' performance reviews and patients' results from the cardiology laboratory, Sheil said.

The federal Health Insurance Portability and Accountability Act requires patient documents to be shredded, which these were not.

"Procedures were not followed," Sheil said. Clinic officials are investigating who was responsible.


Uh huh.

The First Cut Is The Deepest

ID theft is a huge problem, and when it involves medical records, the outcome can sometimes be deadly. But see if you can see the problem with this:

HIPAA also addressed security and privacy of health data, encouraging the widespread use of electronic data interaction.

The danger, however; comes when a thief uses a fraudulent identification to seek health treatment. His history - allergies, blood type, and treatment record - then becomes part of the data stored in the system, and can affect the care of the actual person.

“That's when they start giving me the wrong blood,” Jennings said, adding grimly. “I know a surgeon in Warsaw, Ind., that's removed an appendix from the same person five times.”


Five times? At what point do you notice something wrong? And who in the world is yanking so many appendices, anyway? What sort of patient population would allow for this? And how many is too many? Do you cut them off at some point? "Sorry, this coupon has a limit of three per customer."
Somehow I think someone is exaggerating for effect, don't you?

I Write the Songs

Gotta love a guy who heads his posts with song titles! This piece, titled Paper Doll, is a quick rundown on the various technologies available at low cost to help you get a little closer to that goal of a paperless office, dental style.
Most small practices don't have anybody to ramrod changes. New technology usually happens as something breaks. There are some ways that are relatively painless steps to friendlier processes, though, and if they are less expensive and easy to impliment, then they are both more likely to find their way into use, and less likely to be bypassed by the end users as being too much trouble or getting in the way of care.

One (Hu)man, One Vote Remix

From the comments on the post below about the pharmacy worker who was using patient records for her husband's political campaign:

pharmdatamining said...
She lives near me.
I'm changing pharmacies now! Doh!


My wife is a candidate for city council of the city in which we reside. I promise not to pirate anyone's information for her fundraising activities :)

I Fought the Law

Let's see if I can make sense of this: a woman was admitted to the hospital, told the folks there that her husband had pushed her, hospital calls police. All normal stuff. But then the woman decides she doesn't want to talk to the police, and the hospital staff decides HIPAA does not allow them to let the police in to interview the woman. They come back with an obstruction of justice warrant, and arrest the case manager. Woman goes home, police never talk to her. Obstruction charges are later dropped, but the arrested case manager sues for false arrest:

Melancon threw out the lawsuit, saying the federal Health Insurance Portability and Accountability Act does not block officers from getting information about a crime, and noting that the officers had obtained a warrant for Maier's arrest, meaning that a judge had found probable cause for the charge. He said that provides protection against accusations of false arrest.


It seems like everyone got caught in the machine, here. The police certainly needed to respond to the domestic violence call, and the patient's privacy was protected. In some states the domestic violence laws are strict enough that the cops would not have been allowed any discrection. But even though the charges were dropped, no one ever is edified by being escorted out of their place of employment in handcuffs.
Reading between the lines, I suspect this may have been a motivator:

Maier's attorney, Paul Marx, said Maier was far from the only person who told police that they could not give them the woman's name, but may have been the most vocal.


*Thanks for catching the typo, Jason!

Friday, March 09, 2007

Mr. Postman

From the comment section, below:

Anyone, please point me to right direction. My niece married to a doctor who later turned out to be a jerk. My niece finally gave up and filed for divorce. While the divorce is still pending he disclosed some very sensitive health information of her wife to like half of the town. Somebody told us to file a HIPAA complaint but we are not sure if it falls under that law? where to start from and what should we expect from HIPAA's end?
Thanks in advance for your help.
Regards
Ray


HIPAA will only apply if the doctor was also her caregiver. Information gathered and shared as a spouse is not covered, and the fact of his being a doctor will not automatically make him a covered entity.
Although things are looking better, enforcement has been very lax under the current administration. You might inquire, though, and other local privacy laws may apply.
The complaint process is here:
http://www.hhs.gov/ocr/privacyhowtofile.htm
Good Luck!

Friday, March 02, 2007

Easy Does It

Here is what happens when HIPAA training happens in a calm and sensible manner:

Although people might complain about HIPAA requirements I no longer feel that they have a leg to stand on. There is nothing outrageous in these requirements (except maybe one or two really quirky things) and the only real problem will be the way that the auditors interpret the HIPAA standards and how they are applied within an organization. Of course this is true of any standard. There will always be a negotiation of the level of protections compared to the risks involved. My personal feeling is that through HIPAA we have a standard, a overall policy, that is applicable to these specific organizations. We can point to these standards to when the organization fails to adequately protect the sensitive information with which they are entrusted.


See? It wasn't that difficult, now was it?

Thursday, March 01, 2007

One (hu)'man One Vote

This is wrong in so many ways! Professional breach, HIPAA violation and most likely election law violation too. (My wife is a candidate for city council here on the opposite corner of the country, and while state laws vary, the allowable sources of voter information are usually pretty narrow.)

In her zeal to drum up votes for her husband, Loretta Jason said she used the customer list at Publix's pharmacy, where she works, to get the unlisted home number of a Dania Beach family to ask for their votes in the city's Feb. 13 primary


I have a great deal of sympathy for the poor lady, who after all was just trying to help her husband make a difference. Still, some pretty poor judgement on her part, poor enough that I tend to think she wasn't entirely unaware, and perhaps just didn't think she would get caught.

Street Fighting Man

Yes, HIPAA does mandate the assault of photographers, if Mr. Moon is to be believed:

During the pandemic drill on November 30, Mr. Sharpe approached news photographer Chip Moon from behind without warning, grabbed the photographer's arm and pulled him across the room to a Hudson police officer, demanding that the officer confiscate Mr. Moon's equipment and destroy any images in his camera.
The Independent had assigned Mr. Moon to photograph the event and had received advance clearance from the county Health Department. When a Health Department official at the site confirmed that Mr. Moon was authorized to be at the event, Mr. Sharpe left the room without any explanation.
According to the stipulation, in addition to serving a 30-calendar-day suspension without pay and issuing a statement expressing regret for his actions, Mr. Sharpe waives any right to a hearing. He acknowledges that he was offered the opportunity to consult with an attorney.
In his statement, Mr. Sharpe says at the time of the incident he had received a radio message that there was a breach of security by a photographer inside the school. "Due to the fact that established protocol was altered, I was unaware that the photographer had been given access and permission to take photos," he writes. "Being mindful of HIPAA rules and regulations, my actions were two-fold: 1) to protect the privacy of the person receiving the flu inoculation and 2) to protect the County from possible Federal HIPAA Law violation." HIPPA refers to the federal Health Insurance Portability and Accountability Act, part of which protects the confidentiality of patient records.


It is gratifying to learn that, as much as I love HIPAA and all of the many things it allows, that there is someone out there even more concerned about the privacy of others, enough so that he was ready to throw his body in the path of the rogue photographer in question and manhandle him away from the exposed vaccinationees!

Start Me Up

Jury returns guilty verdict in first HIPAA trial
The owner of a Florida claims handling company has been convicted of conspiracy to commit fraud, computer fraud, identity theft related to the use patient information from a local medical clinic, and violating the Health Insurance Portability and Accountability Act (HIPAA) through wrongful disclosure of personally identifiable health information. This HIPAA prosecution was the first HIPAA violation case that has gone to trial in the U.S., according to the Department of Justice (DOJ).

Identity theft and Medicare fraud. Fernando Ferrer, Jr., the owner of Advanced Medical Claims, Inc., purchased patient information from a former Cleveland Clinic employee. According to the indictment, the clinic employee accessed the clinic's computer system to download the personal identification information of more than 1,100 of the clinic's patients and sold the information to Ferrer. Ferrer then provided the information to others who used it to file fraudulent claims for Medicare reimbursement. The theft resulted in the submission of more than $7 million in fraudulent Medicare claims, with approximately $2.5 million paid to providers and suppliers.

Possible sentence. At sentencing, Ferrer faces statutory maximum prison terms of five years on the conspiracy count, five years on the computer fraud count, ten years on the wrongful disclosure of individually identifiable health information count, and two years on each count of aggravated identity theft. In addition, he may be required to pay fines totaling $750,000.

DOJ Press Release, Jan. 24, 2007. From CCH Healthcare.