Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

As other others have pointed out HIPPA is an old law. But what most people do not realize is that it has not been enforced (for 10 years?) because no bureaucracy had responsibility for enforcement. This has led to a high level of complacency regarding the seriousness of the HIPPA law. HIPPA now has an "owner" (i.e. enforcer) at the HHS in the Dept. of Civil Rights and they are spooling up to start cracking down and auditing and fining healthcare providers and their business associates. This process has already begun so things are about to change.

For years, under advice of my lawyer, I operated under a signed contract with all my healthcare customers that included a disclaimer that HIPPA was not my responsibility and I had no HIPPA responsibilities. Recent decisions by the DCR have ruled such disclaimers invalid and defined Business Associates as providers to healthcare providers that have access to PHI and thus to which the HIPPA regulations apply directly. My lawyer said he can no longer limit my liability or responsibility for HIPPA with a disclaimer and advised me to implement full HIPPA compliant policies, procedures and documentation or drop my healthcare customers.

Please feel free to ignore reality if you want to get blind-sided by this.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: