Skip to content
  • About
  • Contact
  • Contribute
  • Book
  • Careers
  • Podcast
  • Recommended
  • Speaking
KevinMD
  • All
  • Physician
  • Practice
  • Policy
  • Finance
  • Conditions
  • .edu
  • Patient
  • Meds
  • Tech
  • Social
  • Video
  • All
  • Physician
  • Practice
  • Policy
  • Finance
  • Conditions
  • .edu
  • Patient
  • Meds
  • Tech
  • Social
  • Video
    • All
    • Physician
    • Practice
    • Policy
    • Finance
    • Conditions
    • .edu
    • Patient
    • Meds
    • Tech
    • Social
    • Video
    • About
    • Contact
    • Contribute
    • Book
    • Careers
    • Podcast
    • Recommended
    • Speaking
KevinMD
  • All
  • Physician
  • Practice
  • Policy
  • Finance
  • Conditions
  • .edu
  • Patient
  • Meds
  • Tech
  • Social
  • Video
    • All
    • Physician
    • Practice
    • Policy
    • Finance
    • Conditions
    • .edu
    • Patient
    • Meds
    • Tech
    • Social
    • Video
    • About
    • Contact
    • Contribute
    • Book
    • Careers
    • Podcast
    • Recommended
    • Speaking
  • About KevinMD | Kevin Pho, MD
  • Be heard on social media’s leading physician voice
  • Contact Kevin
  • Discounted enhanced author page
  • DMCA Policy
  • Establishing, Managing, and Protecting Your Online Reputation: A Social Media Guide for Physicians and Medical Practices
  • Group vs. individual disability insurance for doctors: pros and cons
  • KevinMD influencer opportunities
  • Opinion and commentary by KevinMD
  • Physician burnout speakers to keynote your conference
  • Physician Coaching by KevinMD
  • Physician keynote speaker: Kevin Pho, MD
  • Physician Speaking by KevinMD: a boutique speakers bureau
  • Primary care physician in Nashua, NH | Kevin Pho, MD
  • Privacy Policy
  • Recommended services by KevinMD
  • Terms of Use Agreement
  • Thank you for subscribing to KevinMD
  • Thank you for upgrading to the KevinMD enhanced author page
  • The biggest mistake doctors make when purchasing disability insurance
  • The doctor’s guide to disability insurance: short-term vs. long-term
  • The KevinMD ToolKit
  • Upgrade to the KevinMD enhanced author page
  • Why own-occupation disability insurance is a must for doctors

Protecting the security of electronic patient data

David Harlow
Tech
January 12, 2010
Share
Tweet
Share

Originally published on HCPLive.com

If your patient records aren’t already stored digitally, they are likely to be digitized soon. There is a tremendous push by the federal government—as well as by some private payors and self-insured employers—to get all healthcare providers wired in the near future, in order to better coordinate patient care, improve outcomes, and “bend the cost curve” all at the same time. There are some financial incentives in play to achieving “meaningful use” of “certified” EHR systems; those terms are to be defined in federal regulations later this year, but the outlines of those definitions are already pretty clear.

Once all that patient data—or as it is known in HIPAA-speak, protected health information (PHI)—is stored electronically, it becomes exposed to potential data breaches. In late September, two sets of federal regulations took effect that address the way in which PHI should be maintained, and the steps that should be taken to prevent a data breach and to notify the government and affected individuals in the event there is a data breach.

Compliance with these rules— issued under authority of the HITECH Act by the US Department of Health and Human Services (HHS) with respect to healthcare providers, and by the Federal Trade Commission (FTC) with respect to EHR vendors and other similar third parties—requires affected practices and businesses to assess and update their data privacy and security policies and procedures, as well as train all affected staff accordingly.

The exposure in case of violation is significant, both in terms of fines and penalties and in terms of bad publicity—certain data breaches require notice to potentially affected individuals via the general media in addition to notices required to be filed with the regulators. The new rules—I call them Son of HIPAA— are layered on top of existing HIPAA privacy and security rules: the FTC’s Red Flags Rule, regarding identity theft protections to be put in place by any “creditor” (which includes healthcare providers not paid in full at the time of service), and state privacy rules. While HHS and FTC took some pains to harmonize the new rules so that patients will not be bombarded with multiple data breach notifications about the same incident, for example, the other applicable rules out there have not been harmonized.

The key concept in the new breach notification rules is that encryption of patient data will eliminate the need to notify patients and the federal regulators in case of an inappropriate release of data. Such a release, if the data is encrypted (ie, unusable, unreadable, or indecipherable), is not considered a breach. Encryption is not required, though, and each affected entity must engage in a cost-benefit analysis before deciding whether to encrypt all affected data.

Another important aspect of the rule is the concept of harm—the regulators decided that not every data breach should trigger all of the notice requirements, just breaches that “pose a significant risk of financial, reputational, or other harm to the individual.” For example, if an employee of a healthcare provider accesses a patient record inappropriately, but immediately realizes his or her mistake, and exits the record quickly and does not retain any PHI, that is not a reportable data breach.

Finally, “business associates” under HIPAA are now required to implement policies and procedures to maintain privacy and security of PHI, parallel to those that have been required of “covered entities” under HIPAA since the beginning. All business associate agreements and notice of privacy practices (NPPs) will have to be updated to account for the new requirements before February. Healthcare providers that wish to distinguish themselves should consider revising their NPPs to highlight the ease with which they will make copies of records available to patients. This is a bone of contention for many patients, and ensuring that patients’ rights to their records are easily exercised () could be a way to build goodwill among patients and potential patients.

By necessity, this is an extremely brief introduction to a very involved set of regulations. My hope is that you now have a sense of how important it is to be sure that your operations are fully compliant with the regulatory requirements before full enforcement and random field audits begin in February 2010.

David Harlow is a health care lawyer and consultant who blogs at HealthBlawg.

Submit a guest post and be heard.

 

Prev

How sleeping late can lead to depression in teenagers

January 12, 2010 Kevin 2
…
Next

Why I had to fire my primary care doctor

January 12, 2010 Kevin 35
…

Tagged as: Health IT, Patients, Public Health & Policy

< Previous Post
How sleeping late can lead to depression in teenagers
Next Post >
Why I had to fire my primary care doctor

ADVERTISEMENT

More by David Harlow

  • a desk with keyboard and ipad with the kevinmd logo

    The legal landscape of health care social media

    David Harlow
  • a desk with keyboard and ipad with the kevinmd logo

    Why an ACO is essentially an American product

    David Harlow
  • a desk with keyboard and ipad with the kevinmd logo

    Pharmacies selling prescription information to data mining companies

    David Harlow

More in Tech

  • The hidden risks of AI-generated progress notes in psychotherapy

    Arthur Lazarus, MD, MBA
  • How AI in dentistry is changing your next checkup

    Sowjanya Gunukula, DDS
  • Early-stage medical device innovation: How to discuss untested ideas

    Jarelis Cabrera
  • AI in health care data management: Curing the EHR overload

    Hamad Husainy, DO
  • AI in clinical documentation: Who is liable for medical errors?

    Harvey Castro, MD, MBA
  • Physician burnout and gaming: Why doctors turn to video games

    Gerald Kuo
  • Most Popular

  • Past Week

    • The dangers of vertical integration in health care

      Stephanie Waggel, MD | Policy
    • Why does sex work seem like a more viable path than medicine in 2026?

      Corina Fratila, MD | Physician
    • The future of U.S. medicine: 10 health care trends in 2026

      Richard E. Anderson, MD & The Doctors Company | Physician
    • The passion vine: a lesson on restraint in medicine and life

      Rao M. Uppu, PhD | Conditions
    • Navigating the patchwork of CME requirements by state

      Vladislav Tchatalbachev, MD | Physician
    • The Platinum Rule in health care: Moving beyond the Golden Rule

      Harvey Max Chochinov, MD, PhD | Conditions
  • Past 6 Months

    • Missed diagnosis visceral leishmaniasis: a tragedy of note bloat

      Arthur Lazarus, MD, MBA | Conditions
    • The dangers of vertical integration in health care

      Stephanie Waggel, MD | Policy
    • Menstrual health in medicine: Addressing the gender gap in care

      Cynthia Kumaran | Conditions
    • Why does sex work seem like a more viable path than medicine in 2026?

      Corina Fratila, MD | Physician
    • From Singapore to Canada: a blueprint for primary care transformation

      Ivy Oandasan, MD | Policy
    • How board certification fuels the physician shortage crisis

      Brian Hudes, MD | Physician
  • Recent Posts

    • Repeating history: the ethics of the new Guinea-Bissau hepatitis B study

      Meghan Johnston, MPH | Policy
    • Understanding the types of PTSD and how to treat them

      Faust Ruggiero | Conditions
    • Heat therapy activates proteins that repair cells and protect the heart [PODCAST]

      The Podcast by KevinMD | Podcast
    • The 9 laws of health care quality: Why metrics miss the point

      Constantine Ioannou, MD | Physician
    • The evolutionary intelligence of human milk: HMOs and lactose

      Rao M. Uppu, PhD | Conditions
    • The hidden risks of AI-generated progress notes in psychotherapy

      Arthur Lazarus, MD, MBA | Tech

Subscribe to KevinMD and never miss a story!

Get free updates delivered free to your inbox.


Find jobs at
Careers by KevinMD.com

Search thousands of physician, PA, NP, and CRNA jobs now.

Learn more

View 3 Comments >

Founded in 2004 by Kevin Pho, MD, KevinMD.com is the web’s leading platform where physicians, advanced practitioners, nurses, medical students, and patients share their insight and tell their stories.

Social

  • Like on Facebook
  • Follow on Twitter
  • Connect on Linkedin
  • Subscribe on Youtube
  • Instagram

ADVERTISEMENT

  • Most Popular

  • Past Week

    • The dangers of vertical integration in health care

      Stephanie Waggel, MD | Policy
    • Why does sex work seem like a more viable path than medicine in 2026?

      Corina Fratila, MD | Physician
    • The future of U.S. medicine: 10 health care trends in 2026

      Richard E. Anderson, MD & The Doctors Company | Physician
    • The passion vine: a lesson on restraint in medicine and life

      Rao M. Uppu, PhD | Conditions
    • Navigating the patchwork of CME requirements by state

      Vladislav Tchatalbachev, MD | Physician
    • The Platinum Rule in health care: Moving beyond the Golden Rule

      Harvey Max Chochinov, MD, PhD | Conditions
  • Past 6 Months

    • Missed diagnosis visceral leishmaniasis: a tragedy of note bloat

      Arthur Lazarus, MD, MBA | Conditions
    • The dangers of vertical integration in health care

      Stephanie Waggel, MD | Policy
    • Menstrual health in medicine: Addressing the gender gap in care

      Cynthia Kumaran | Conditions
    • Why does sex work seem like a more viable path than medicine in 2026?

      Corina Fratila, MD | Physician
    • From Singapore to Canada: a blueprint for primary care transformation

      Ivy Oandasan, MD | Policy
    • How board certification fuels the physician shortage crisis

      Brian Hudes, MD | Physician
  • Recent Posts

    • Repeating history: the ethics of the new Guinea-Bissau hepatitis B study

      Meghan Johnston, MPH | Policy
    • Understanding the types of PTSD and how to treat them

      Faust Ruggiero | Conditions
    • Heat therapy activates proteins that repair cells and protect the heart [PODCAST]

      The Podcast by KevinMD | Podcast
    • The 9 laws of health care quality: Why metrics miss the point

      Constantine Ioannou, MD | Physician
    • The evolutionary intelligence of human milk: HMOs and lactose

      Rao M. Uppu, PhD | Conditions
    • The hidden risks of AI-generated progress notes in psychotherapy

      Arthur Lazarus, MD, MBA | Tech

MedPage Today Professional

An Everyday Health Property Medpage Today

Copyright © 2026 KevinMD.com | Powered by Astra WordPress Theme

  • Terms of Use | Disclaimer
  • Privacy Policy
  • DMCA Policy
All Content © KevinMD, LLC
Site by Outthink Group

Protecting the security of electronic patient data
3 comments

Comments are moderated before they are published. Please read the comment policy.

Loading Comments...