US Approves New Guidelines For Medical Privacy
iElucidate writes: "Mindwire.org is reporting on the adoption by the US Department of Health and Human Services of guidelines for privacy of personal medical records. In 1996 Congress mandated the creation of medical privacy standards by the end of 1999. Since Congress did not act, responsibility went to the Department of Health, which drafted a standard, gave a year for public comment, and finally approved it for use. The new standard requires that hospitals and HMOs keep information secure, and requires stiff penalties for the release of unauthorized information. Finally, no more employers snooping on employees psych. records. About bloody time!" The Department of Health and Human Services issued a fact sheet summarizing the new regulations.
The problem is that very few organizations are really ready. While hospitals are probably the most ready, it's only the ones with a top-notch IT staff that think they'll make it. As for your local general practitioner's office: Forget It. These people have little idea the law was passed, much less that it's going into effect. If I had the background in CS/Security, I would seriously think about starting a company to *specialize* in HIPPA regulations. The public health industry will pay big bucks to make sure they don't run afoul of these laws....
Examples:
Now, the good news is that these laws won't fully go into effect for a few months, and it's very hard to see right now what priority the incoming Bush Jr. Administration will put on these regulations....sig not found
Although it may be illegal by the ADA, I know of people who were not hired because of health info, and I know another who was denied a mortgage because of a heart ailment.
May this help others in like case.