Archives: Health Data

Subscribe to Health Data RSS Feed

Twenty-First Century Cures Act Includes HIPAA Provisions

On December 13, 2016, President Obama signed the 21st Century Cures Act (“Cures Act”), Pub. L. 114-255, which aims to expand medical research and expedite the approvals of drug therapies for patients.  The Cures Act also contains several provisions related to the HIPAA Privacy and Security Rules.  None of these provisions make substantive changes to … Continue Reading

Incoming HHS Secretary Tom Price Brings Physician-Focused Perspective to Health IT

Tom Price, the Republican representative from Georgia, has been tapped by President-elect Trump as the new Secretary for the Department of Health and Human Services (HHS). Rep. Price is himself an orthopedic surgeon and comes from a family of doctors and, as a result, is focused closely on the ways in which government regulations burden … Continue Reading

HHS Issues Guidance on HIPAA and Cloud Providers

The Department of Health and Human Services (HHS) recently published guidance on HIPAA requirements governing the use of cloud computing entities, specifically cloud services providers (CSPs). In this guidance, HHS explains that CSPs that create, receive, maintain, or transmit protected health information (PHI) on behalf of a covered entity or business associate are considered business … Continue Reading

GAO Recommends that HHS Strengthen Privacy and Security Guidance and Oversight

Earlier this week the Government Accountability Office released a report critiquing the U.S. Department of Health and Humana Services’ (HHS) oversight of and guidance related to health information security and privacy. (The report is available here.) GAO cited the increasing incidence of hacking and other breaches, which affected over 113 million health records in 2015, … Continue Reading

JAMA Study Finds Low Rate of Digital Health Technology Use Among Seniors

A research letter published this month in the Journal of the American Medical Association reported that only a small fraction of seniors in the United States use digital health technology. The authors applied statistical analysis to data gleaned from a nationally representative sample of Medicare beneficiaries age 65 and older. In 2011, 16% of seniors … Continue Reading

UK Government Considering New Patient Data Security and Research Consent Standards, Sanctions

The UK Government has opened a consultation, running until September 7, 2016, regarding how UK National Health Service (NHS) patient data should be safeguarded, and how it could be used for purposes other than direct care (e.g. scientific research). The consultation comes after two parallel-track reviews of information governance and data security arrangements in the … Continue Reading

ONC Report to Congress Identifies Gaps in Oversight of Privacy and Security of mHealth Technologies and Health Social Media

Earlier this month the U.S. Department of Health and Human Services (HHS), Office of the National Coordinator for Health Information Technology (ONC), released a report to Congress highlighting “large gaps” in policies and oversight surrounding access to and security and privacy of health information held by certain “mHealth technologies” and “health social media.” mHealth technologies … Continue Reading

Significant HIPAA Fine Follows Business Associate’s Stolen iPhone

The Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) recently announced a significant settlement with Catholic Health Care Services of the Archdiocese of Philadelphia (CHCS), a business associate under HIPAA, arising from a breach of protected health information (PHI) after the theft of an employee’s iPhone.  The iPhone … Continue Reading

CMS Issues Guidance Encouraging the Use of Commercial Off-the-Shelf Technology and Software-as-a-Service for Medicaid Eligibility and Enrollment Systems

In March, CMS issued a State Medicaid Directors Letter (SMDL) about the availability of enhanced federal funding for state Medicaid programs’ eligibility and enrollment (E&E) systems. This SMDL represents CMS’s most recent effort to encourage States to use commercial “off-the-shelf” technology and “software as a service,” instead of customized electronic systems developed and built specifically … Continue Reading

FTC Releases Online Tool to Help Health App Developers Identify Applicable Laws

On April 5, the Federal Trade Commission (FTC), in conjunction with the Food and Drug Administration (FDA) and the Department of Health and Human Services (HHS), released a new web-based interactive tool to assist mobile health app developers in navigating applicable federal laws and regulations in the areas of advertising and marketing, medical devices, and … Continue Reading

HHS Proposes Rule to Increase ONC Review and Oversight of Certified Health IT

The U.S. Department of Health and Human Services and the Office of the National Coordinator for Health Information Technology (ONC) recently proposed a rule to enhance ONC oversight and accreditation of health IT.  Under the rule, the ONC’s primary goal would be to work with health IT developers to remedy any non-conformities with certified health … Continue Reading

Senate HELP Committee Marks Up Precision Medicine, Other “Cures” Bills

Yesterday, the Senate Health, Education, Labor and Pensions (HELP) Committee held a final mark-up of legislation comprising the Committee’s counterpart to the House-passed 21st Century Cures Act.  The HELP Committee approved five bills including S. 2713 to advance the development of “precision medicine” through research and data sharing.  We have reported on the President’s precision medicine … Continue Reading

CMS Expands Scope of Enhanced Match for Promotion of Health IT

On February 29, 2016, the Centers for Medicare and Medicaid Services (CMS) issued a State Medicaid Directors Letter (SMDL) that expands the scope of expenditures eligible for the 90 percent federal match for activities to promote the use of a health information exchange (HIE) and the adoption of certified electronic health record (EHR) technology by … Continue Reading

Health Care Companies Agree to “Core Commitments” to Improve Access to EHR

Last month, the Department of Health and Human Services (HHS) announced that a number of large health care companies and providers had “agreed to implement three core commitments” to improve access to electronic health records (EHR).  HHS touted the commitments as a significant step toward increased EHR interoperability.… Continue Reading

New Telehealth Bill in Congress

On February 2, a bipartisan group of Senators introduced a bill, S. 2484 (CONNECT for Health Act), to expand the scope of Medicare reimbursements for telehealth and remote patient monitoring (RPM) services. (An identical bill, H.R. 4442 was introduced in the House on February 3.) If enacted, the bill would waive, for certain providers, existing … Continue Reading

CMS Extends Meaningful Use Attestation Deadline

On February 11, the Centers for Medicare & Medicaid Services (CMS) extended the attestation deadline for health-care providers in the Electronic Health Records (EHR) Meaningful Use program.  Originally, providers were required to attest that they met the requirements of the Meaningful Use Program by next Monday, February 29, 2016.  That deadline has been extended by … Continue Reading

After Two-Day Workshop, CDRH Releases Postmarket Cybersecurity Draft Guidance

Earlier today, on the InsideMedicalDevices blog, our colleague Christopher Hanson posted a summary of the FDA’s recent issuance of draft guidance on “Postmarket Management of Cybersecurity in Medical Devices.”  The release of the draft guidance coincided with the conclusion of a two-day public workshop hosted by the FDA entitled, “Moving Forward: Collaborative Approaches to Medical Device Cybersecurity.”  You … Continue Reading

FDA Regulatory Science Priorities Address Use of Data, Health Information Technology

On October 20, 2015, the U.S. Food and Drug Administration (FDA) Center for Devices and Radiological Health (CDRH) released its top ten Regulatory Science Priorities for FY 2016 to facilitate improvements in the safety and effectiveness of medical devices and accelerate innovation. Several of the priorities would harness health information technology or health data to … Continue Reading

Report Outlines Plan for Precision Medicine Database

In a 107-page report, released last week, the White House set forth its plan to create and manage a database containing 1 million or more Americans’ medical records in furtherance of the Precision Medicine Initiative. As announced by President Obama during his 2015 State of the Union Address, the Precision Medicine Initiative was launched “to … Continue Reading

UK Government Launches Cybersecurity Service for Healthcare Organizations

Earlier today, on the InsidePrivacy blog, our colleagues Mark Young and Phil Bradley-Schmieg posted a summary of the UK government’s announcement of a new national service providing expert cybersecurity advice to entities within the National Health Service (NHS) and the UK’s broader healthcare system.  The project, called CareCERT (Care Computing Emergency Response Team), is aiming for a … Continue Reading

Multistakeholder Group Seeks Comment on Draft Framework for IoT Device Manufactures

Last week, our colleague Libbie Cantor published a post on our InsidePrivacy blog regarding the Online Trust Alliance’s (OTA) release of a draft framework of best practices for Internet of Things device manufacturers and developers.  This draft framework applies to, among other things, eHealth technology, such as wearable fitness and health technologies.  The OTA is seeking comments on … Continue Reading

Comments Requested on Draft Guide on Securing Electronic Health Records on Mobile Devices

The National Cybersecurity Center of Excellence (“NCCoE”) has released a draft for public comment of the first guide in a new series of publications “that will show businesses and other organizations how to improve their cybersecurity using standards-based, commercially available or open-source tools.” The guide discusses how to secure electronic health records on mobile devices. … Continue Reading
LexBlog