A Notice of Proposed Rule making concerning the accounting of disclosures requirement under the Health Insurance Portability and Accountability (HIPAA) Act Privacy Rule, is available for public comment. The proposed rule would give people the right to get a report on who has electronically accessed their protected health information.
The U.S. Department of Health and Human Services' (HHS) Office for Civil Rights (OCR) is proposing changes to Privacy Rule, pursuant to the Health Information Technology for Economic and Clinical Health (HITECH) Act. HITECH is part of the American Recovery and Reinvestment Act of 2009.
"This proposed rule represents an important step in our continued efforts to promote accountability across the health care system, ensuring that providers properly safeguard private health information," said OCR Director Georgina Verdugo. "We need to protect peoples' rights so that they know how their health information has been used or disclosed."
People would obtain this information by requesting an access report, which would document the particular persons who electronically accessed and viewed their protected health information. Although covered entities are currently required by the HIPAA Security Rule to track access to electronic protected health information, they are not required to share this information with people.
People may now read the proposed rule here. Search for Proposed Rule through August 1, 2011.
People who believe a covered entity has violated their (or someone else's) health information privacy rights or committed another violation of the HIPAA Privacy or Security Rule, may file a complaint with OCR at http://www.hhs.gov/ocr/privacy/hipaa/complaints/index.html. Additional information about OCR's enforcement activities can be found at http://www.hhs.gov/ocr.