On May 27, 2011, the Department of Health and Human Services (HHS) released for public review a Notice of Proposed Rulemaking (NPRM) about the accounting provisions of the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule. An advance copy of this NPRM is here. The Federal Register publication of the rule is available here. There will be a 60-day comment period once the NPRM is published.
This proposed rule implements a statutory provision from the Health Information Technology for Economic and Clinical Health (HITECH) law. It dramatically alters the current HIPAA accounting rule, with substantially increased burdens for covered entities and business associates. For example, it requires a much broader set of disclosures to be tracked by covered entities and business associates. More significantly, it also creates-based on HHS' general authority under HIPAA rather than the HITECH law-a new obligation for covered entities and business associates to track internal "access" to protected health information in a designated record set.
Over the next few weeks, companies in the health care industry-including all covered entities and their business associates-should evaluate these proposals carefully and should determine promptly whether they wish to comment on this proposed rule.