August 1996 | HIPAA passes Congress with the goal of modernizing the flow of healthcare information. |
December 2000 | The U. S. Department of Health and Human Services (HHS) finalizes the HIPAA Privacy Rule; it becomes the first ever federal healthcare information privacy law. |
April 2003 | HSS establishes the HIPAA Security Rule, setting national standards to protect individuals’ electronic personal health information. |
2008 | The Office for Civil Rights (OCR) comes under fire for lack of enforcement. By 2008, more than 33,000 complaints had been filed with OCR. While 5,600 investigations led to corrective action, no fines were imposed. |
February 2009 | The Health Information Technology for Economic and Clinical Health (HITECH) Act becomes law to promote the adoption and meaningful use of health information technology. |
2009 | OCR ratchets up enforcement; issues some entities fines exceeding $1 million for privacy breaches. |
January 2013 | HSS releases a HITECH’s HIPAA Modification Rule to strengthen privacy and security protection for personal health information and mandates enforcement. |
DISCLAIMER: MyHIPAA Guide content, including newsletters, is for informational purposes only. MyHIPAA Guide is not intended as legal advice or as a recommendation for a provider’s specific circumstances, and it is not intended as an exhaustive or definitive source on protecting health information from privacy and security risks. Providers and professionals seeking expert advice should consult an attorney and/or a risk assessment professional.
NOTICE TO READERS: We will do our best to report updates on HIPAA rules as quickly as possible following public notifications. In submitting questions or comments to MyHIPAAGuide.com, NEVER SEND THE PROTECTED HEALTH INFORMATION OF A PATIENT.
Copyright © by M.E.D. Media Mart LLC - Published by M.E.D. Media Mart LLC.