Security ruling could spell double trouble for hospital CIOs

From: FierceHealthIT/Editor’s Corner

 By

As if data breaches weren’t already painful enough for hospital CIOs with the new HIPAA rules, now it appears that government regulation may not end with the Office for Civil Rights.

The Federal Trade Commission, last month, disagreed with Atlanta-based medical testing laboratory LabMD that the company was not subject to FTC security enforcement since it already was considered a covered entity under the Health Insurance Portability and Accountability Act. That means you could be dinged by both OCR and the FTC for a data breach.

Just how concerned should you be about this double threat? FierceHealthIT spoke exclusively with Jeff Smith, director of federal relations for the College of Healthcare Information Management Executives, and health attorney David Harlow to get a sense of what providers are up against.

“I think the FTC is going to become a more active player where enforcement is concerned,” Smith told FierceHealthIT via email. “The FTC is already active in monitoring mobile application marketing practices in healthcare [and] medical identity theft, and the case in question underscores their intentions to flex their muscle where information and data security compliance is concerned.”

Read Complete Article

Facebooktwittergoogle_plusredditpinterestlinkedinmail

Leave a Reply

Your email address will not be published.

Please Answer: *