On March 25, 2005, the Centers for Medicare & Medicaid Services (CMS) issued the federal register notice setting forth the procedures for filing with the Secretary of the Department of Health and Human Services a complaint of non-compliance by a covered entity with certain provisions of the administrative simplification rules under 45 CFR parts 160, 162, and 164. The federal register notice also describes the procedures the Department employs to review the complaints.
The complaint procedures do not apply to the regulations adopted under section 264 of the Health
Insurance Portability and Accountability Act of 1996 (HIPAA), Pub. L. 104–191, as amended, known as
the Privacy Rule. The Secretary has delegated to the Office for Civil Rights the authority to receive and investigate complaints as they may relate to the Privacy Rule codified at 45 CFR parts 160 and 164. For the purpose of this notice, ‘‘administrative simplification provisions’’ means the administrative simplification regulatory requirements under HIPAA, other than privacy.
The effective date of the rule is April 25, 2005.
Categoris
- #FitWV (2)
- 2011 (1)
- 4th Circuit (1)
- Accounting (1)
- advance directives (1)
- AHLA (9)
- AHLA Connections (1)
- ama (3)
- American Well (1)
- anatomy (1)
- anonymous (2)
- Antikickback (1)
- arbitration (1)
- Arizona (1)
- ARRA (15)
- Atari (1)
- Athena Health (1)
- attorney general (1)
- attorney-client privilege (1)
- authorization (1)
- Avvo (2)
- baby boomers (1)
- beBetter (1)
- Best Lawyers (6)
- Bethany College (2)
- bigfoot (1)
- black friday (1)
- Blacksburg (1)
- blawg (9)
- Blawg Review (6)
- blawgreview (4)
- Blog (12)
- blog rally (2)
- Blog World (1)
- blogger (10)
- blogger buzz (1)
- Blogging (20)
- blogs (13)
- Blogs of Note (1)
- Board of Medicine (1)
- Body Browser (1)
- book banning (1)
- bosworth (1)
- Boy Scout (1)
- brailer (1)
- bug (1)
- business associate (1)
- butterfly (1)
- CAB (2)
- California (2)
- camera (1)
- cardiac (1)
- Carlyle (1)
- carnival (2)
- CCHIT (1)
- Certificate of Need (20)
- certification (2)
- Charleston (24)
- Charleston Area Alliance (2)
- CHCF (1)
- Christmas (2)
- CIO (1)
- Cleveland Clinic (2)
- CMS (8)
- computers (1)
- CON (21)
- conference (3)
- confidentiality (2)
- Congress (3)
- Connecticut (1)
- Conroy (1)
- consumer (3)
- Consumers Checkbook (1)
- cookies (1)
- CoP (1)
- costs (3)
- couch (1)
- country doctor (1)
- Create WV (9)
- creative (5)
- credentialing (1)
- criminal (2)
- CT (1)
- cycling (1)
- Dartmouth (1)
- data breach (11)
- dCard (1)
- DEA (1)
- Deal (1)
- death (1)
- DHHR (2)
- DHHS (2)
- diabetes (2)
- diabetes mine (2)
- diabetic (1)
- Digital Health Revolution (1)
- Disclosures (1)
- Dossia (1)
- Dr. Val (2)
- drafting (1)
- Earth Day (1)
- eBay (1)
- economy (1)
- education (1)
- EHR (11)
- election (1)
- electronic prescription (1)
- Emergiblog (1)
- employment (1)
- employment law (2)
- EMR (7)
- end of life care (5)
- enforcement (1)
- Engage with Grace (3)
- entrepreneurship (2)
- environmental (1)
- epresribing (4)
- ethics (1)
- Eweek (1)
- EWG (1)
- Executive Order (1)
- Express Scripts (1)
- FACA (1)
- Facebook (5)
- false claims (2)
- family (1)
- FBI (1)
- FDA (1)
- Federal Register (4)
- FestiVALL (9)
- FICO (1)
- fiesta bowl (1)
- film (1)
- Final 4 (1)
- FitWV (2)
- flea (2)
- Florida (1)
- flu (2)
- flu trends (2)
- FOIA (2)
- football (1)
- fraud (1)
- Frischkorn (1)
- FSB (1)
- FTC (3)
- genealogy (1)
- George Clooney (1)
- gift (1)
- Glendale (1)
- GoHelp (1)
- Google (14)
- Google Health (5)
- Government (3)
- grammar (1)
- Grand Rounds (8)
- guitar hero (1)
- H1N1 (1)
- hail (1)
- harm (1)
- HCB2007 (1)
- HCQIA (1)
- HCSM (2)
- health (13)
- health care (50)
- health 2.0 (61)
- health care (68)
- health care reform (3)
- Health Cloud (1)
- health information technology (34)
- Health Wonk Review (1)
- Healthcare Blogging Summit (2)
- HealthVault (3)
- HFMA (1)
- HHS (10)
- HIE (9)
- HIMSS (1)
- HIO (1)
- HIPAA (33)
- HISPC (1)
- history (1)
- HIT (14)
- HIT Policy Committee (2)
- HIT Standards Committee (2)
- HITECH (24)
- holiday (1)
- home health (1)
- hospital (12)
- house call (1)
- Howell (1)
- HRSA (1)
- human body (1)
- human subjects research (1)
- HWR (1)
- Internet (1)
- Intuit (1)
- Iowa (1)
- Joint Commission (2)
- judges (1)
- Julian Beever (1)
- jury (1)
- Justia (1)
- Kaiser (1)
- Kentucky (1)
- Kibbee (1)
- kickback (1)
- Kiplinger (2)
- KY (1)
- Las Vegas (1)
- law (57)
- law 2.0 (2)
- Leavitt (1)
- legal contracts (1)
- legal ethics (3)
- Legislature (3)
- LeMoyne Coffield (1)
- liability (1)
- liberal arts (2)
- licensure (1)
- lifeline (1)
- lions (1)
- litigation (2)
- Lorman (2)
- Manor Care (1)
- Markle (1)
- mashup (1)
- Massachusetts (1)
- Mayo (1)
- McCain (1)
- Meaningful Use (3)
- Medicaid (4)
- Medicaid Redesign (4)
- medical home (1)
- medical malpractice (1)
- medical records (2)
- Medicare (10)
- medicine (1)
- medicine 2.0 (2)
- Medpedia (1)
- meme (1)
- mental health (1)
- metadata (2)
- Mexico (1)
- Michigan (1)
- micro practice (1)
- Microsoft (6)
- Microsoft Healthvault (4)
- minimum necessary (1)
- mobile device (1)
- moms (1)
- Mountaineers (5)
- music (3)
- myhealthdata (1)
- MySpace (1)
- NCAA (1)
- NCVHS (4)
- Never Events (1)
- New Martinsville (3)
- New York Times (1)
- Nexeon (1)
- NLRB (1)
- Northern District (1)
- notification (2)
- NYT (3)
- Obama (5)
- obesity (2)
- OCR (12)
- OHFLAC (1)
- Ohio (1)
- OIG (3)
- ONC (18)
- Orlando (2)
- Oxycontin (1)
- patient safety (1)
- patientslikeme (2)
- peerclip (1)
- PEIA (1)
- penalties (2)
- Pennsylvania (1)
- personal health records (2)
- Pew (2)
- Pfister (1)
- pharmacy (1)
- PHI (1)
- photo (1)
- PHR (18)
- physician (18)
- Picture West Virginia (2)
- podcast (1)
- Politics (2)
- PowerPoint (1)
- PPS (1)
- preemption (1)
- presidential debate (2)
- prevention (1)
- privacy (44)
- privileging (1)
- pro hac vice (3)
- Providence (1)
- public health (2)
- Purkinje (1)
- rainmaking (1)
- reform (2)
- regulations (1)
- retail clinic (1)
- retention (1)
- revolution health (4)
- revoluton health (1)
- RHIO (1)
- Rick Lee (2)
- risk (1)
- rock band (1)
- Rockefeller (1)
- Rodriquez (1)
- RSS (2)
- rules (1)
- Saas (1)
- SAMHSA (1)
- Scribe Media (1)
- Search Story (1)
- Searls (1)
- Second Life (1)
- security (21)
- self referral (1)
- sermo (3)
- social media (18)
- social networking (5)
- Stark (5)
- State Journal (1)
- stent (1)
- stereotypes (1)
- storm (1)
- substance abuse (2)
- survey (1)
- swine (1)
- Swine Flu (1)
- tag cloud (1)
- tax (1)
- technology (3)
- teleconference (1)
- Texas (1)
- Thanksgiving (1)
- theatre (1)
- This Week In Law (1)
- timeline (1)
- Tour de France (1)
- transparency (3)
- turkey (1)
- TWiL (1)
- Twitter (12)
- United States District Court (2)
- Unknown Hinson (1)
- Veterans Day (1)
- Virginia (2)
- Virginia Tech (1)
- virtual medicine (1)
- VT (1)
- Walt Disney World (1)
- Washington Post (1)
- web 2.0 (8)
- West Virginia (130)
- West Virginia College of Law (2)
- West Virginia State Bar (2)
- WHCC (1)
- Wii (1)
- wiki (3)
- wild (1)
- willful neglect (1)
- wistleblower (1)
- wonderful (1)
- Wordle (2)
- world diabetes day (1)
- World's Strongest Man (2)
- WSJ (5)
- WV (140)
- WV FestiVALL (1)
- WVBOM (1)
- WVHCA (11)
- WVHII (2)
- WVHIN (8)
- WVMI (1)
- WVPBS (1)
- WVRHITEC (1)
- WVSCA (2)
- wvu (4)
- X PRIZE (1)
- YouTube (2)
- ZDNet (1)
CMS Issues Complaint Procedures for Investigating and Resolving Violations of the Aministrative Simplification Rules (HIPAA)
Monday, March 28, 2005Posted by Oliver at 5:26 AM 0 comments
Mountaineers Madness Moves On to the Elite 8
Thursday, March 24, 2005Tonight the West Virginia Mountaineers moved on to the Elite 8 by beating Bobby Knight and the Texas Tech Red Raiders 65-60 in The Pitt, Albuquerque, New Mexico. Kevin Pittsnogle scored 22 points to lead the Mountaineers.
The Mountaineers will now face the Louisville Cardinals on Saturday at 4:40 p.m. Everyone in the state of West Virginia will be tuned in to watch the Moutaineers make its bid to move on to the 2005 Final Four. This run by the Moutaineers is great for the players, the team, the University and the State of West Virginia.
One of the most exicting points of this years Moutaineer team is to watch different players step up night after night. Pittsnogle, Gansey, Beilein, Sally, Fischer and the list goes on. I think one of the reasons teams have had touble handling the Mountaineers is because they come out with a different look every night.
It is great to see Coach Beilein getting the credit that he deserves at putting together a great year end run to the Final Four.
Posted by Oliver at 9:23 PM 0 comments
Kaiser Permanente Files New Motions Against the Diva of Disgruntled Blogger
Friday, March 18, 2005An article in today's San Jose Mercery News reports that Kaiser Permanente filed new motions in an existing lawsuit against a former employee, Elisa D. Cooper, aka the "Diva of Disgruntled" asserting claims based on invasion of privacy and breach of a confidentiality agreement.
This follows up the announcement by Kaiser last week that it was notifying 140 patients in California that personal information, including names, addresses, telephone numbers, medical record numbers and results of routine lab tests, had been posted on the Web. According to the article today:
Kaiser has since acknowledged that it constructed the unsecured technical Web site but said it id not know if patient information was included on it. Cooper said she tried to notify Kaiser about he breach only to be rebuffed, and she subsequently filed a Federal health privacy complaint with the U.S. Department of Health and Human Services, which in turn contacted Oakland-based Kaiser.Also, the article reports that the California Department of Managed Health Care (DMHC) is investigating both Ms. Cooper and the actions of Kaiser Permanente. The DMHC has also ordered Ms. Cooper to stop posting certian information to her blog.
For more details and some interesting commentary on this matter check out Matthew Holt's most recent post on The Health Care Blog. Also, for more information about Ms. Cooper's termination from Kaiser you can read her post titled "Details of My Termination from Kaiser." You can also see the nature of the complaint that Ms. Cooper filed with the Office of Civil Rights who are responsible for investigating potential violations under the Privacy Rules of the Health Insurance Portability & Accountability Act of 1996 (HIPAA).
Also check out the March 16, 2005 ComputerWorld article for coverage of this matter.
Posted by Oliver at 9:41 AM 0 comments
Kaiser Permanente Gadfly
Monday, March 14, 2005Matthew Holt's "The Health Care Blog" has an interesting followup post on Kaiser Permanente's announcement last week about the breach of privacy involving patient health information of 140 individuals. The blog post also contains some interesting followup comments by the Gadfly and others.
UPDATE:
Yesterday, March 16, 2005, Matthew Holt posted an update on the outcome of the hearing involving the injunction filed by Kaiser Permanente against the Gadfly. The Gadfly also has a recent post on her blog giving her perspective on the outcome of the injunction hearing. the post is titled "My Morning in Court".
Posted by Oliver at 5:58 AM 0 comments
Private Patient Data Posted Online Blog by Disgruntled Former Kaiser Employee
Friday, March 11, 2005Today I read an article (see below) from the iHealthBeat newsletter reporting on an article which appeared in the March 11, 2005, San Jose Mercury News. This will be the 3rd well published breach of private data in as many weeks (see my post on ChoicePoint and Lexis-Nexis). This is also interesting because it involves blogging and employee issues which is the topic of much debate these days due to some other recent high profile cases.
Based on the comments in the article it appears that a privacy related complaint under the Privacy Rule created under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) was filed either by one of the parties involved or the blogger and former employee herself since the Office of Civil Rights is now involved and investigating. The article points out that the former employee may face significant fines and penalties, however the article does not point out that the health care provider responsible for complying with the HIPAA mandates may also face such charges.
I did some quick Googling and seemed to come across the blog of "Diva of Disgruntled" which is interestingly titled "Corporate Ethics". The blog contains a recent post today in response to the news break on the matter.
It will be interesting to watch this one unwind.
Following is the iHealthBeat article:
Kaiser Permanente is alerting 140 patients in Northern California that a disgruntled former employee posted private information about them on her blog, the San Jose Mercury News reports. The information includes medical record numbers, patient names and information about some routine lab tests, but not the test results. Kaiser in January learned of the breach from the federal Office of Civil Rights and has been investigating the issue since then, said Kaiser spokesperson Matthew Schiffgens. However, Schiffgens said Kaiser on Wednesday asked the Internet service provider hosting the blog to remove the data, the Mercury News reports. The former employee, who calls herself the "Diva of Disgruntled," said that the company posted the patient information on an unsecured Web site and that Kaiser took it down only after she pointed it out, the Mercury News reports. She said she reposted the information to another site to illustrate how easy it was for someone to access the information, which she said had been on the Internet for a year. She said she also filed a complaint with the federal Office of Civil Rights. Schiffgens said Kaiser has been unable to confirm the woman's claims that it posted private patient data, but he said the woman still breached her obligation to protect member confidentiality by posting the information herself. Schiffgens said Kaiser might take legal action against the woman, the Mercury News reports. Under HIPAA rules, she could face fines of up to $250,000 and 10 years in prison for unlawfully disclosing patient data (Feder Ostrov, San Jose Mercury News, 3/11).
Posted by Oliver at 10:23 AM 0 comments
West Virginia Health Care Authority Issues Draft CON Standards on Cardiac Cath and Cardiac Surgery for Comment
Thursday, March 10, 2005The West Virginia Health Care Authority has published new standards for Cardiac Catheterization Standards and Cardiac Surgery Standards under the State Health Plan. The notice on the West Virginia Health Care Authority's website shows that providers in West Virginia have a 30 day public comment period that ends on April 8, 2005 to comment on the draft standards.
The current Cardiac Catheterization Standards were approved by the Governor of West Virginia on August 22, 2002. The current Cardiac Surgery Standards were approved by the Governor of West Virginia on May 5, 2004.
For those unfamiliar with the Certificate of Need (CON) process, West Virginia has a statutorily mandated CON review process which requires health care provider projects, new services, etc. to obtain CON approval prior to starting the project or new service. The CON review process typical includes the determination of need, consistency with the State Health Plan, and financial feasibility. Need for the project is determined using CON Standards, which generally include population-based quantifiable need methodologies. Financial feasibility includes the evaluation of the reasonableness of proposed charges to patients and the determination as to whether the expense and revenue projections demonstrate fiscal viability for the proposed project. Other review criteria include quality, accessibility, and continuum of care.
Posted by Oliver at 6:29 AM 0 comments
Confidential Information on 32,000 People Stolen from Lexis-Nexis Database
Wednesday, March 9, 2005Today Lexis-Nexis announced that hackers stole confidential information on 32,000 people. According to an news article from PC World the following information was stolen from a Lexis-Nexis subsidiary called Seisint. PCWorld reports that:
The hackers stole passwords, names, addresses, Social Security numbers, and drivers license numbers of legitimate customers of the company's Seisint division. Seisint collects data on individuals that law enforcement agencies and private companies use for debt recovery, fraud detection, and other services.
Here is a press release issued by Lexis-Nexis regarding the investigation into the privacy breach. Lexis-Nexis acquired Seisint in September 2004 for $775 Million. Due to the privacy breach I suspect that the price of the acquisition just went up substantially.
This is the second high profile breach of confidential health data in as many weeks. In mid February there was a report of a breach of 145,000 individuals confidential information at ChoicePoint. For more information on this particular breach read the following article from PCWorld. Interesting on March 4, 2005 ChoicePoint announced its decision to exit those lines of its business which involve the sale of confidential and sensitive consumer data.
Posted by Oliver at 7:00 PM 0 comments

My dad has been experimenting with Hello, software that allows you to share your digital photo, and Picassa, software which allows you to find, edit and organize digital photos that reside on your hardrive. These software downloads are part of Google's positioning to take over the desktop from Microsoft.
I have played around with Picassa and have found it very user friendly and intuitive. I think they have found a niche that needed to be filled. As an example, my dad is one of the most knowlegeable computer uses in the 80+ year old category and has been using computers back to the first macintosh that my sisters and I purchased for him in the late 1980s. However, something that has always been confusing for him is the ability to navigate the Explorer features, how to (and where to) save documents, files and now digital photos. Picassa brings to him the ability to have the software find and organize the photos on his hard drive.
He has been using Picassa for a couple of months and just recently sent me an invitation to join Hello so that we can share digital photos back and forth. I have been meaning to download and try out Hello, since I was interested in the feature that allows me to now share photos up to my Blogger blog (Blogger is another product/business swept up by Google). Above is a test post of a photo of my 9 month old during a recent trip to Florida with her, my wife and my 4 year old. 
Posted by Oliver at 11:48 PM 0 comments
Pizza and Privacy: ACLU Privacy Video
Wednesday, March 2, 2005Today someone referred me to an online video put out by the American Civil Liberties Union (ACLU) to demonstate how technology can be used, even by your local pizza business, to access and reveal sensetive financial, medical, employment and other personal data.
Although the video is done in fun it does make one thing about being more cautious with releasing personal and private information.
v
Here is a press release issued by the ACLU discussing the online pizza delivery privacy video.
Posted by Oliver at 8:18 PM 0 comments