Relaxed HIPAA Rules Could Change IT Plans - InformationWeek

InformationWeek is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

IoT
IoT
News

Relaxed HIPAA Rules Could Change IT Plans

The proposed changes would eliminate the need for some projects.

A proposal to relax key provisions of the Health Insurance Portability and Accountability Act could ease the burden on health-care industry IT managers scrambling to meet an April 2003 deadline to implement the HIPAA rules.

The Department of Health and Human Services proposes to eliminate a patient-consent requirement that's now part of the HIPAA privacy regulations. That rule requires written patient consent before health-care providers can use protected health information for treatment and operations such as billing. The proposed changes were published in the Federal Register this week and could become part of HIPAA after a 30-day comment period.

The changes "will eliminate the need for a lot of crazy IT projects, like programs that force a patient to sign a consent form before making an appointment to see a physician," says John Halamka, senior VP and CIO of CareGroup Healthcare System, which operates six Boston area hospitals. "We want to protect patient privacy, but not reduce the quality of patient care." CareGroup had planned to devote about $1 million in IT resources this year for HIPAA projects. The proposed rule change will allow it to redirect about $200,000 in resources this year to other projects, including work on a Web-based medical-record program that fosters better communication between doctors and patients, as well as among doctors.

Another significant proposed change is in HIPAA's transactions and code-set rules. HIPAA requires that all contracts health-care providers have with billing companies and transaction service providers include patient-privacy safeguards. That meant IT processes to support those safeguards had to be in place. Health and Human Services now proposes that only new or renegotiated contracts have to have those safeguards by April 2003, while existing contracts don't have to have such provisions until April 2004.

We welcome your comments on this topic on our social media channels, or [contact us directly] with questions about the site.
Comment  | 
Print  | 
More Insights
The State of IT & Cybersecurity Operations 2020
The State of IT & Cybersecurity Operations 2020
Download this report from InformationWeek, in partnership with Dark Reading, to learn more about how today's IT operations teams work with cybersecurity operations, what technologies they are using, and how they communicate and share responsibility--or create risk by failing to do so. Get it now!
Slideshows
10 Cyberattacks on the Rise During the Pandemic
Cynthia Harvey, Freelance Journalist, InformationWeek,  6/24/2020
News
IT Trade Shows Go Virtual: Your 2020 List of Events
Jessica Davis, Senior Editor, Enterprise Apps,  5/29/2020
Commentary
Study: Cloud Migration Gaining Momentum
John Edwards, Technology Journalist & Author,  6/22/2020
Register for InformationWeek Newsletters
Video
Current Issue
Key to Cloud Success: The Right Management
This IT Trend highlights some of the steps IT teams can take to keep their cloud environments running in a safe, efficient manner.
White Papers
Slideshows
Twitter Feed
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.
Sponsored Video
Flash Poll