Skip to main content
Sister Publication Links
  • ESG: THE IMPLEMENTATION IMPERATIVE
Subscribe
  • Sign Up Free
  • Login
  • Subscribe
  • News
    • Current News
    • Providers
    • Insurance
    • Digital Health
    • Government
    • Finance
    • Technology
    • Safety & Quality
    • Transformation
    • People
    • Regional News
    • Digital Edition (Web Version)
    • Patients
    • Operations
    • Care Delivery
    • Payment
    • Midwest
    • Northeast
    • South
    • West
  • Unwell in America
  • Opinion
    • Bold Moves
    • Breaking Bias
    • Commentaries
    • Letters
    • Vital Signs Blog
    • From the Editor
  • Events & Awards
    • Awards
    • Conferences
    • Galas
    • Virtual Briefings
    • Webinars
    • Nominate/Eligibility
    • 100 Most Influential People
    • 50 Most Influential Clinical Executives
    • Best Places to Work in Healthcare
    • Excellence in Governance
    • Health Care Hall of Fame
    • Healthcare Marketing Impact Awards
    • Top 25 Emerging Leaders
    • Top 25 Innovators
    • Diversity in Healthcare
      • - Luminaries
      • - Top 25 Diversity Leaders
      • - Leaders to Watch
    • Women in Healthcare
      • - Luminaries
      • - Top 25 Women Leaders
      • - Women to Watch
    • Digital Health Transformation Summit
    • ESG: The Implementation Imperative Summit
    • Leadership Symposium
    • Social Determinants of Health Symposium
    • Women Leaders in Healthcare Conference
    • Best Places to Work Awards Gala
    • Health Care Hall of Fame Gala
    • Top 25 Diversity Leaders Gala
    • Top 25 Women Leaders Gala
    • - Hospital of the Future
    • - Value Based Care
    • - Hospital at Home
    • - Workplace of the Future
    • - Digital Health
    • - Future of Staffing
    • - Hospital of the Future (Fall)
  • Multimedia
    • Podcast - Beyond the Byline
    • Sponsored Podcast - Healthcare Insider
    • Video Series - The Check Up
    • Sponsored Video Series - One on One
  • Data Center
    • Data Center Home
    • Hospital Financials
    • Staffing & Compensation
    • Quality & Safety
    • Mergers & Acquisitions
    • Data Archive
    • Resource Guide: By the Numbers
    • Surveys
    • Data Points
  • MORE+
    • Contact Us
    • Advertise
    • Media Kit
    • Newsletters
    • Jobs
    • People on the Move
    • Reprints & Licensing
MENU
Breadcrumb
  1. Home
  2. Information Technology
October 27, 2009 01:00 AM

Watchdog says 'harm' threshold harmful to patients

Joseph Conn
  • Tweet
  • Share
  • Share
  • Email
  • More
    Reprints Print

    Getting in their last licks in a contentious privacy debate, a consumer advocacy group is alleging HHS overreached and defied the will of Congress in its proposed rule on when organizations must notify patients following a breach of their individually identifiable medical records; meanwhile, in contrast, a prominent group purchasing organization is making the opposite argument, saying the HHS interpretation embodied in its proposed rule is a reasonable compromise.

    The deadline for public comments to HHS on its breach notification rule, first published Aug. 24, has ended.

    Both Consumer Watchdog, a Washington-based not-for-profit organization that bills itself as a nonpartisan consumer advocacy group, and Premier, the GPO, issued news releases touting the filing of their dueling formal public comments.

    Please take today's HITS reader poll on this topic.

    At issue is a controversial addition by HHS, under pressure from the healthcare industry, to the definition of the word “breach” in the HHS rule.

    HHS added the concept of “harm” to that definition. In it, HHS says if providers, data-miners and other holders of patient-identifiable medical records experience a breach, they should first perform a risk analysis.

    If that analysis determines, in the data-holder's view, that their breach poses only minimal risk of harm to the patient, then no breach notification is required.

    HHS, meanwhile, provides no guidance in identifying what an appropriate harm threshold should be. In effect, HHS leaves it up to the offender to determine and admit it has committed an offense.

    The addition not only goes beyond the language of the statute as written by Congress—a harm threshold is unmentioned in the law—but also it is inconsistent with a companion rule on breach notification written by the Federal Trade Commission and released Aug. 17, which does not include a harm standard.

    Both HHS and FTC rules were written to put flesh on the bones of a new, federal breach-notification law Congress passed in February as part of the American Recovery and Reinvestment Act of 2009, also known as the stimulus law.

    The HHS version of the rule pertains to breaches of personally identifiable records held by hospitals, physicians and other so-called “covered entities” and their business associates under the privacy provisions of the Health Insurance Portability and Accountability Act of 1996, which the stimulus law amended.

    In contrast, the FTC rule pertains to firms and organizations that offer a broad array of new, consumer-oriented health IT products and services, including personal health records, which may or may not be covered organizations. The FTC rule targets these so-called health 2.0 providers and their business associates.

    In its 32-page interim final rule, HHS appeared to stretch the statute by saying that a breach “is considered a breach only if the use or disclosure poses some harm to the individual.” HHS went on to authorize the organization that committed the breach to self-assess and determine if it had caused harm. As part of that self-assessment, the organization committing the breach can take into consideration who the patient information was breached to as well as the level of sensitivity of the information released.

    “If the nature of the protected health information does not pose a significant risk of financial, reputational or other harm, then the violation is not a breach,” HHS said.

    Only if the organization determined harm had been caused would it then be required to notify individuals whose records had been exposed, according to HHS.

    Neither the statute nor the FTC rule mentioned harm as a precondition for notification, points noted by Consumer Watchdog in its protest of the HHS rule. In a news release, the group asked, rhetorically, “What prompted HHS to flout congressional intent. Could it be that Congress managed to fend off the pressures of the healthcare industry in passing ARRA only to have the lobbyists return to exert their influence on the rulemaking process?”

    Premier, however, in its news release, called on HHS Secretary Kathleen Sebelius to “maintain the harm standard that would ensure that notification requirements would only pertain to breaches that pose a significant risk to individuals.”

    “Without a harm standard, providers would be responsible for notifying patients of every instance of a compromise, even the most minimal, whether it imposes harm or not,” Premier said.

    What do you think? Write us with your comments at [email protected]. Please include your name, title and hometown.

    Letter
    to the
    Editor

    Send us a letter

    Have an opinion about this story? Click here to submit a Letter to the Editor, and we may publish it in print.

    Recommended for You
    Judy_Faulkner_Epic_HIMSS17_edit_i.jpg
    Epic outlines what's ahead for patient portal, Cosmos
    Cerner_fullsize_AP_i.jpg
    Cerner to pay $1.8M to resolve racial discrimination allegations
    Most Popular
    1
    More healthcare organizations at risk of credit default, Moody's says
    2
    Centene fills out senior executive team with new president, COO
    3
    SCAN, CareOregon plan to merge into the HealthRight Group
    4
    Blue Cross Blue Shield of Michigan unveils big push that lets physicians take on risk, reap rewards
    5
    Bright Health weighs reverse stock split as delisting looms
    Sponsored Content
    Health IT Strategist (HITS) Newsletter: Sign up for the latest IT and medical technology news delivered 3 days a week (M, W, F).
     
    Get Newsletters

    Sign up for enewsletters and alerts to receive breaking news and in-depth coverage of healthcare events and trends, as they happen, right to your inbox.

    Subscribe Today
    MH Magazine Cover

    MH magazine offers content that sheds light on healthcare leaders’ complex choices and touch points—from strategy, governance, leadership development and finance to operations, clinical care, and marketing.

    Subscribe
    Connect with Us
    • LinkedIn
    • Twitter
    • Facebook
    • RSS

    Our Mission

    Modern Healthcare empowers industry leaders to succeed by providing unbiased reporting of the news, insights, analysis and data.

    Contact Us

    (877) 812-1581

    Email us

     

    Resources
    • Contact Us
    • Advertise with Us
    • Ad Choices Ad Choices
    • Sitemap
    Editorial Dept
    • Submission Guidelines
    • Code of Ethics
    • Awards
    • About Us
    Legal
    • Terms and Conditions
    • Privacy Policy
    • Privacy Request
    Modern Healthcare
    Copyright © 1996-2023. Crain Communications, Inc. All Rights Reserved.
    • News
      • Current News
      • Providers
      • Insurance
      • Digital Health
      • Government
      • Finance
      • Technology
      • Safety & Quality
      • Transformation
        • Patients
        • Operations
        • Care Delivery
        • Payment
      • People
      • Regional News
        • Midwest
        • Northeast
        • South
        • West
      • Digital Edition (Web Version)
    • Unwell in America
    • Opinion
      • Bold Moves
      • Breaking Bias
      • Commentaries
      • Letters
      • Vital Signs Blog
      • From the Editor
    • Events & Awards
      • Awards
        • Nominate/Eligibility
        • 100 Most Influential People
        • 50 Most Influential Clinical Executives
        • Best Places to Work in Healthcare
        • Excellence in Governance
        • Health Care Hall of Fame
        • Healthcare Marketing Impact Awards
        • Top 25 Emerging Leaders
        • Top 25 Innovators
        • Diversity in Healthcare
          • - Luminaries
          • - Top 25 Diversity Leaders
          • - Leaders to Watch
        • Women in Healthcare
          • - Luminaries
          • - Top 25 Women Leaders
          • - Women to Watch
      • Conferences
        • Digital Health Transformation Summit
        • ESG: The Implementation Imperative Summit
        • Leadership Symposium
        • Social Determinants of Health Symposium
        • Women Leaders in Healthcare Conference
      • Galas
        • Best Places to Work Awards Gala
        • Health Care Hall of Fame Gala
        • Top 25 Diversity Leaders Gala
        • Top 25 Women Leaders Gala
      • Virtual Briefings
        • - Hospital of the Future
        • - Value Based Care
        • - Hospital at Home
        • - Workplace of the Future
        • - Digital Health
        • - Future of Staffing
        • - Hospital of the Future (Fall)
      • Webinars
    • Multimedia
      • Podcast - Beyond the Byline
      • Sponsored Podcast - Healthcare Insider
      • Video Series - The Check Up
      • Sponsored Video Series - One on One
    • Data Center
      • Data Center Home
      • Hospital Financials
      • Staffing & Compensation
      • Quality & Safety
      • Mergers & Acquisitions
      • Data Archive
      • Resource Guide: By the Numbers
      • Surveys
      • Data Points
    • MORE+
      • Contact Us
      • Advertise
      • Media Kit
      • Newsletters
      • Jobs
      • People on the Move
      • Reprints & Licensing