From: iHealthBeat
by John Moore, iHealthBeat Contributing Reporter
The arcane world of data security regulations just got a little more ambiguous.
In January, the Federal Trade Commission affirmed its authority to bring action against businesses that fail to adequately protect consumer data. The decision has particular implications for health care, as the case involved LabMD, a medical testing laboratory and a covered entity under HIPAA.
FTC last August filed a complaint against LabMD alleging the company exposed the personal information of about 10,000 people in two incidents. LabMD responded with its own missive: a motion to dismiss the complaint on the grounds that the FTC enforcement action clashed with HIPAA’s information security regulations.
On Jan. 16, FTC commissioners rejected LabMD’s arguments. As a result, health care providers and their business associates now need to consider FTC in addition to HHS’ Office for Civil Rights as a data security enforcement organization.
“What the FTC is saying is they feel they have the latitude … to go after anyone who doesn’t live up to the promises they make with respect to protecting their data,” said Mac McMillan, CEO of CynergisTek, an IT security consulting firm that focuses on health care.
“This was a big surprise to a lot of people,” McMillan said, adding, “Most health care organizations have never really viewed FTC as a regulatory body as it relates to privacy and security.”
Leave a Reply