Risk
11/2/2008
08:33 PM
George V. Hulme
George V. Hulme
Commentary
50%
50%

Inspector General Confirms It: Little HIPAA Enforcement

The Health Insurance Portability and Accountability Act of 1996 was set into law about 12 years ago, the security rules went into effect earlier this decade. Hospitals knew these regulations were coming long ago, so why is compliance so lax?

The Health Insurance Portability and Accountability Act of 1996 was set into law about 12 years ago, the security rules went into effect earlier this decade. Hospitals knew these regulations were coming long ago, so why is compliance so lax?A nationwide review of the Centers for Medicare & Medicaid Services' (CMS) HIPAA compliance by the U.S. Department of Health & Human Services Office of Inspector General found that little action was taken by governed organizations (health care providers and others that collect, store, or manage patient data) to implement adequate security controls.

This is from an overview of the IG's findings:

CMS had no effective mechanism to ensure that covered entities were complying with the HIPAA Security Rule or that electronic protected health information was being adequately protected. We noted that CMS had an effective process for receiving, categorizing, tracking, and resolving complaints.

We recommended that CMS establish policies and procedures for conducting HIPAA Security Rule compliance reviews of covered entities. CMS did not agree with our findings because it believed that its complaint-driven enforcement process has furthered the goal of voluntary compliance. However, CMS agreed with our recommendation to establish specific policies and procedures for conducting compliance reviews of covered entities. We maintain that adding these reviews to its oversight process will enhance CMS's ability to determine whether the HIPAA Security Rule is being properly implemented.

The HIPAA Security Rule is fairly simple: entities that manage patient data need to protect that data by making sure it stays confidential, that it isn't altered, and can't be accessed by those not authorized.

Hospitals knew these rules were coming since 1996. And while the final HIPAA rules went into effect in April 2005 for large health organizations, protecting the confidentiality, integrity, and availability of information should be considered basic due diligence. And it's time, in my opinion, that any organization that has failed to put in place the most basic of measures to secure patient privacy be fined.

You can find a copy of the full IG report here.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-4467
Published: 2015-01-30
WebKit, as used in Apple iOS before 8.1.3, does not properly determine scrollbar boundaries during the rendering of FRAME elements, which allows remote attackers to spoof the UI via a crafted web site.

CVE-2014-4476
Published: 2015-01-30
WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulner...

CVE-2014-4477
Published: 2015-01-30
WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulner...

CVE-2014-4479
Published: 2015-01-30
WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulner...

CVE-2014-4480
Published: 2015-01-30
Directory traversal vulnerability in afc in AppleFileConduit in Apple iOS before 8.1.3 and Apple TV before 7.0.3 allows attackers to access unintended filesystem locations by creating a symlink.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
If you’re a security professional, you’ve probably been asked many questions about the December attack on Sony. On Jan. 21 at 1pm eastern, you can join a special, one-hour Dark Reading Radio discussion devoted to the Sony hack and the issues that may arise from it.