Hospitals, health plan sponsors, health care providers, and their vendors need to act immediately to meet the new rules introduced by the Health Information Technology for Economic and Clinical Health Act (HITECH). HITECH (enacted as part of the American Recovery and Reinvestment Act of 2009) makes significant changes to HIPAA, including changes that subject various vendors directly to privacy and security requirements and require notice to individuals whose information is affected by a breach of privacy.   

By February 17, 2010, health plan sponsors and health care providers should review and update their HIPAA forms to comply with the HITECH rules concerning such things as:

  • Internal policies and procedures
  • Notice of privacy practices
  • HIPAA plan amendments
  • Agreements with vendors (business associates) who handle individually identifiable health information

Business associates under HIPAA will, for the first time, be directly subject to a number of HIPAA’s privacy requirements and virtually all of its security requirements. If

Full Article…