The legislation, H.R. 6357, has been referred to the Science & Technology and Ways & Means Committees. Health Subcommittee Chairman Frank Pallone, D-N.J., said he hoped the entire committee would consider the bill before August recess, according to CongressDaily. The bill would affect the HIPAA privacy and security rules, calling for security safeguards under the security rule and penalties for violations apply to business associates in the same manner as applied to covered entities. It would also require individuals affected by breaches of unencrypted protected health information to be notified “without unreasonable delay and no later than 60 calendar days after discovery.” The bill would require the Secretary of Health and Human Services, in consultation with stakeholders, to annually issue guidance on the latest technologies for protecting information, according to CongressDaily. According to the Government HealthIT, Rep. Nathan Deal, R-Ga., the subcommittee’s ranking member, said he supports the bill but has concerns about the provisions regarding consent and marketing. The consent provision states that doctors, hospitals and other healthcare providers who adopt EHRs “may not use or disclose such protected health information for purposes of healthcare operations unless the [provider] obtains the consent of the individual to disclose such information for such purposes, and any such consent shall be revocable by the individual at any time,” Deal told Government HealthIT. Other provisions of the legislation include:
Last Updated ( Fri, Jun 27 2008 )
|