HITECH Act: IT pros share liability with medical providers
The Health Information Technology for Economic and Clinical Health (HITECH) Act has done a lot to raise privacy standards for personal health information.
So much, in fact, that the vendors working with medical providers had better take it seriously -- business associates and subcontractors are also directly liable under HIPAA for complying with the security and privacy rules.
Business Associate Rule
Originally, the HIPAA Security Rule required a healthcare entity to maintain administrative, technical, and physical safeguards to ensure the confidentiality of all patient information. The HITECH Act extended the rule to business associates of covered entities, making those business associates subject to civil and criminal liability for any violations of the HIPAA Security Rule.
So, how does this shake down for a small IT provider? Simply put, it could put us out of business if it ever happened. Criminal penalties and civil fines can range up to $1.5 million—a crushing amount for a business with 20 employees or less.
This is why we must do a great job
We admit that it's a bit frightening to think of the ramifications -- should a security or data breach happen with one of our clients. But we think of ourselves as business partners to a medical practice, not just the IT guys. Beyond installing and monitoring the technical aspects of the office, we make sure that staff are well trained and understand all the possible ways a breach could happen. This includes things as simple (and avoidable) as giving out computer passwords, to the bigger issues like encryption which made the news last year in a huge breach at New York City Hospital - potentially affecting over 1.7M people!
http://www.healthitlawblog.com/2011/02/articles/new-york-city-hospitals-suffer-enormous-data-breach/
Who You Gonna Call?
Now that we've instilled some fear in everyone (including ourselves!), let's talk about what we can do to sleep a little easier. There's no doubt that the job of protecting patient privacy is a big one. Which is why all medical providers should take the task of finding the right IT professionals very seriously.
You want an IT shop that not only understands all of the nuances of the HITECH Act, but has the experience and know-how to keep things running smoothly. Proudly, iMedia Technology is one of those companies: we would never set up a healthcare practice in te technical sense without staying on board to make sure all of the staff understand how to use that technology and keep it safe.
Keeping in compliance with the HITECH Act is a big deal. We can help.