This post was also written by Mark S. Melodia, Michael K. Brown, J. Ferd Convery, III, Shana R. Fried and Paul Bond.
Until now, the loss or theft of protected health information rarely resulted in notice to consumers. Very few state data security breach notification laws encompass medical information. The Health Insurance Portability and Accountability Act (“HIPAA”) merely required an “accounting” of such events to a patient upon the patient’s request.
All that has changed. Congress, in enacting the Health Information Technology for Economic and Clinical Health Act (“HITECH”), imposed breach notification obligations on many of the individuals and business entities that receive, create, or maintain patients’ individually identifiable health information. Pursuant to HITECH, on Aug. 17, the Federal Trade Commission (“FTC”) issued its Health Breach Notification Rule, governing the breach notification obligations of three new categories of entity: “vendors of personal health records,” “PHR related entities” and “third party service providers.”
To read the full alert, click here.