Every healthcare organization should develop and implement a policy and a well-defined process that provides guidance for managing incident and breach response.
Q. Is it acceptable for admitting and patient registration staff to photograph patients upon check- in for identification purposes? Is it permissible to take pictures of behavioral health patients for the same purpose?
It's a brave new world out there for business associates (BA). BAs needed to comply with the HIPAA Security Rule and the use and disclosure provisions of the Privacy Rule in February 2010 as a result of the HITECH Act. However, the Office for Civil Rights (OCR) held off on any enforcement activities-that is, until recently.
Also known as the "mega rules," the omnibus final rules are clarifications and finalizations of the HIPAA rules of 2003, the HITECH rules of 2008, and the incorporation of the Genetic Information Nondiscrimination Act (GINA) rules into the Privacy and Security rules. These are not sweeping changes, as many describe, but clarifications. In most cases, what are now final rules are best practices that organizations should already be following.