The HITECH Act (the Health Information Technology for Economic and Clinical Health Act) has significantly expanded the requirements for HIPAA in medical practices. A few of the more significant changes include that every medical practice must maintain policies that require the practice to:
. notify each individual whose information has been or is reasonably believed to have been accessed, acquired, or disclosed as a result of an unauthorized access or breach;
. honor a patient's request that protected health information not be disclosed if the patient out-of-pocket in full; and
. limit the use, disclosure or request of protected health information to the minimum necessary to accomplish the intended purpose of such use, disclosure or request.
Notably, the penalties for HIPAA violations have also been modified and where criminal liability only existed for a covered entity (medical practice) under HIPAA, the HITECH Act changes provide for criminal penalties
for wrongful disclosure of protected health information by individuals who without authorization obtain or disclose such information maintained by a covered entity, whether they are employees of the covered entity or not. For updated HIPAA policies visit www.kirschenbaumesq.com/healthcareorder.htm