Anzeige
Mehr »
Dienstag, 01.07.2025 - Börsentäglich über 12.000 News
Diese KI-Biotech-Aktie revolutioniert die Krebstherapie: Lernen Sie Rakovina Therapeutics kennen
Anzeige

Indizes

Kurs

%
News
24 h / 7 T
Aufrufe
7 Tage

Aktien

Kurs

%
News
24 h / 7 T
Aufrufe
7 Tage

Xetra-Orderbuch

Fonds

Kurs

%

Devisen

Kurs

%

Rohstoffe

Kurs

%

Themen

Kurs

%

Erweiterte Suche
ACCESS Newswire
336 Leser
Artikel bewerten:
(1)

Electronic Healthcare Network Accreditation Commission (EHNAC): EHNAC Executive Director Addresses Impact of HIPAA Safe Harbor Law

Lee Barrett outlines ruling; discusses benefits for companies employing recognized security practices

FARMINGTON, CT / ACCESSWIRE / March 22, 2021 / On January 5 of this year, H.R. 7898 (Public Law 116-321), also known as the HIPAA Safe Harbor Law, was enacted. Under this legislation, covered entities (CEs) and business associates (BAs) that deal with protected health information (PHI) and maintain accredited security standards for more than 1 year could face lesser fines, penalties, and audit scrutiny by the Office for Civil Rights (OCR) in the event of a cyberattack or data breach. With uncertainty surrounding the exact requirements that will be mandated by the U.S. Department for Health and Human Services (HHS), Lee Barrett, CEO and Executive Director of the Electronic Healthcare Network Accreditation Commission (EHNAC) tackled several questions to better help the industry understand the benefits for employing recognized security practices.

Q: How does the law affect my organization?

Barrett: The law amends the HITECH Act to require HHS to consider "recognized security practices" when considering fines or penalties under the HIPAA Security Rule for CEs and BAs. Fines from OCR can top $1 million, in addition to audit and mitigation costs and loss of business due to adverse publicity.

Obtaining a security accreditation or certification would count as a recognized security practice while providing a high level of assurance for employees, patients, associates, and others that data flowing through a company's servers and being exchanged with others is being protected.

Q: What are 'recognized security practices'?

Barrett: According to the law, "the term 'recognized security practices' means the standards, guidelines, best practices, methodologies, procedures, and processes developed under section 2(c)(15) of the National Institute of Standards and Technology Act, the approaches promulgated under section 405(d) of the Cybersecurity Act of 2015, and other programs and processes that address cybersecurity and that are developed, recognized, or promulgated through regulations under other statutory authorities. Such practices shall be determined by the covered entity or business associate, consistent with the HIPAA Security rule (part 160 of title 45 Code of Federal Regulations and subparts A and C of part 164 of such title)."

Q: Why is it important?

Barrett: Cybersecurity remains a critical issue for healthcare providers, payers, clearinghouses, healthcare software vendors, and other covered entities and business associates. According to the OCR Breach Portal, healthcare server breaches were up 23% the first 10 months of 2020 compared to the same period of 2019. Providers accounted for 79% of all healthcare breaches, showing the value of patient information on the black market.

Between January and October 2020, healthcare network server breaches increased 23% over the same 10-month span in 2019. According to Healthcare Innovation, ransomware attacks cost healthcare organizations $21B in 2020. The average cost to mitigate a healthcare data breach tops $7 million, the highest-ranked industry, and nearly double the global average to mitigate a breach in other industries.

Q: What should be considered when choosing an accreditation organization?

Barrett: Not all accreditation organizations are created equal. To maximize benefits, organizations should look at selecting an accreditation from an organization that is solely focused on healthcare and specifically designed to safeguard PHI. Each type of healthcare stakeholder has unique needs, and when selecting a program, it should serve the range of stakeholder types, from health systems to payers to HIEs. Additionally, accreditation may cost less than most think and certainly a lot less than costs associated with mitigating a breach and potentially paying penalties or fines, revenue loss, or loss of credibility.

About EHNAC
The Electronic Healthcare Network Accreditation Commission (EHNAC) is a voluntary, self-governing standards development organization (SDO) established to develop standard criteria and accredit organizations that electronically exchange healthcare data. These entities include accountable care organizations, data registries, electronic health networks, EPCS vendors, e-prescribing solution providers, financial services firms, health information exchanges, health information service providers, management service organizations, medical billers, outsourced service providers, payers, practice management system vendors, third-party administrators, and trusted networks. The Commission is an authorized HITRUST External Assessor, making it the only organization able to provide both EHNAC accreditation as well as to conduct HITRUST CSF assessment services.

EHNAC was founded in 1993 and is a tax-exempt 501(c)(6) nonprofit organization. Guided by peer evaluation, the EHNAC accreditation process promotes quality service, innovation, cooperation, and open competition in healthcare. To learn more, visit www.ehnac.org, contact info@ehnac.org, or follow us on Twitter, LinkedIn, and YouTube.

Press Contact Information:
Tom Testa, Anderson Interactive
617-872-0184
tom@andersoni.com

Debra Hopkinson, EHNAC
860-408-1620
dhopkinson@ehnac.org

SOURCE: Electronic Healthcare Network Accreditation Commission (EHNAC)



View source version on accesswire.com:
https://www.accesswire.com/636464/EHNAC-Executive-Director-Addresses-Impact-of-HIPAA-Safe-Harbor-Law

© 2021 ACCESS Newswire
Zeitenwende! 3 Uranaktien vor der Neubewertung
Ende Mai leitete US-Präsident Donald Trump mit der Unterzeichnung mehrerer Dekrete eine weitreichende Wende in der amerikanischen Energiepolitik ein. Im Fokus: der beschleunigte Ausbau der Kernenergie.

Mit einem umfassenden Maßnahmenpaket sollen Genehmigungsprozesse reformiert, kleinere Reaktoren gefördert und der Anteil von Atomstrom in den USA massiv gesteigert werden. Auslöser ist der explodierende Energiebedarf durch KI-Rechenzentren, der eine stabile, CO₂-arme Grundlastversorgung zwingend notwendig macht.

In unserem kostenlosen Spezialreport erfahren Sie, welche 3 Unternehmen jetzt im Zentrum dieser energiepolitischen Neuausrichtung stehen, und wer vom kommenden Boom der Nuklearindustrie besonders profitieren könnte.

Holen Sie sich den neuesten Report! Verpassen Sie nicht, welche Aktien besonders von der Energiewende in den USA profitieren dürften, und laden Sie sich das Gratis-PDF jetzt kostenlos herunter.

Dieses exklusive Angebot gilt aber nur für kurze Zeit! Daher jetzt downloaden!
Werbehinweise: Die Billigung des Basisprospekts durch die BaFin ist nicht als ihre Befürwortung der angebotenen Wertpapiere zu verstehen. Wir empfehlen Interessenten und potenziellen Anlegern den Basisprospekt und die Endgültigen Bedingungen zu lesen, bevor sie eine Anlageentscheidung treffen, um sich möglichst umfassend zu informieren, insbesondere über die potenziellen Risiken und Chancen des Wertpapiers. Sie sind im Begriff, ein Produkt zu erwerben, das nicht einfach ist und schwer zu verstehen sein kann.