One of the biggest changes in the Omnibus final rule is in the way healthcare organizations will determine whether they need to notify affected individuals of a security breach.
Privacy officers must ensure their hospital removes potential patient identifiers from data sets used for reasons outside of treatment, payment, and healthcare operations, privacy experts say.