BUSINESSSafeguard records to comply with HIPAA security ruleContract Language. By Steven M. Harris, amednews contributor. Jan. 3/10, 2005. The increasing number of Internet health care activities and transactions has significantly changed how many physicians practice medicine. While the term e-health has not been specifically defined, legally, it is generally used to identify "Internet medicine" and the provision of health care information, products or services via the Internet. The emergence of e-health has raised issues regarding when the physician-patient relationship begins; licensing requirements for physicians who provide medical care across state lines; the standard of care for telemedicine; and liability exposure.
There have been several court decisions on these issues, and case law continues to evolve in conjunction with e-health's growth. Congress is also considering proposed legislation related to monitoring various aspects of e-health, including Internet prescription drug sales. Many physicians began using electronic medical records to improve their ability to share patient information, thereby improving quality of care. Physicians have voiced concerns about EMR security and access to patient information by unauthorized users. It is imperative that you comply with the Health Insurance Portability and Accountability Act regulations, including the security rule that becomes effective in April, when you transmit EMRs via the Internet. HIPAA regulations, including the security rule, address the use and disclosure of protected health information via the Internet. A key component of the HIPAA regulations has been the development of electronic data interchange. EDI is the transfer of information, including electronic media health claims, in a standard format between health care entities and others to protect patient confidentiality and eliminate the unauthorized disclosure of protected health information. EDI allows entities within the health care system to exchange medical, billing, and other information and to process transactions in a manner that is fast and cost-effective. The security rule protects an individual's health information while permitting appropriate access and use of the information by physicians, hospitals, clearinghouses, health plans and others. If you are transmitting electronic medical records and using EDI, you must protect and safeguard your EMRs. You should consider taking the following steps to ensure protection of health information and EMRs in compliance with the HIPAA regulations and the new security rule:
Harris, a partner at McDonald Hopkins in Chicago, concentrates on health care law and has counseled physicians, physician networks and health care groups nationally. The author and publisher are not rendering professional advice and assume no liability in connection with its use. He can be reached at 312-280-0111, or by email (sharris@mcdonaldhopkins.com). Copyright 2005 American Medical Association. All rights reserved.
|