, 2003-01-15
As we ring in the new year, it's in with the new and out with the old. Or is it? Our fearless forecaster thinks not.
Expand all |
Post comment
The Curmudgeon's Crystal Ball: Security Predictions for 2003
2003-01-16
Anonymous (1 replies)
Anonymous (1 replies)

What will affect thousands of clinics, small healthcare institutions and organizations, is the *required* compliance to the Privacy Standards section by April 14, 2003. For more info about the Privacy Standards, go to this web site: http://aspe.hhs.gov/admnsimp/bannerps.htm or here: http://www.hhs.gov/ocr/hipaa/.
In a nutshell, this provision relates to privacy issues, and the disclosure (or in this case, the lack of disclosure) of information to patients and other healthcare organizations.
Some organizations won't be required to be compliant until next year (2004); however, this is the beginning of a series of steps of compliancy to provisions that are *required* by our federal government. And NEXT year (2004) will hold other surprises, esp. when the Security Standards will be required.
And here's the best part -- non-compliancy to HIPAA -- if found to be in violation -- carries stiff penalities, fines and imprisonment -- for everyone that uses, processes, distributes, and relays ANY patient information in their processes, records tracking systems, documents, etc.
This is not something that should be overlooked nor viewed lightly. I think that you should consider reviewing the impacts of what would happen if healthcare institutions DO NOT implement the *required* compliancy to HIPAA starting with this year.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/135/17811#17811