HIPAA Privacy Compliance Initiative: Final Rules Impact Employer Health Plans

Similar documents
The New UK Regime on Bribery: An Introduction

HOW IS THE NLRB S NEW ELECTION PROCESS AFFECTING CAMPUS ORGANIZING?

Zubulake Judge Defines Discovery Duties and Spoliation Negligence Standards. January 29, 2010

January

MOVING EMPLOYEES GLOBALLY:

ARB Ruling Takes Broad View of Scope of Protected Activity Under SOX. June 6, 2011

MOVING EMPLOYEES GLOBALLY

Patient Privacy and Security: Data Breach Reporting and other HIPAA Changes

M&A REGULATORY DEVELOPMENTS AT FERC 2016 ANNUAL REVIEW. Mark C. Williams J. Daniel Skees Heather L. Feingold December 15, 2016

H I P AA B U S I N E S S AS S O C I ATE AGREEMENT

Wal-Mart v. Dukes What s Next for Employment Class/Collective Actions

Government Investigations Into Cybersecurity Breaches In Healthcare

Delaware Chancery Court Confirms the Invalidity of Fee-Shifting Bylaws for Stock Corporations

340B Update: HRSA Finalizes 340B Pricing & Penalties for Drug Manufacturers

BUSINESS ASSOCIATE AGREEMENT WITH COVERED ENTITY

Security of Payment Legislation and Set-Off Under Commonwealth Insolvency Laws

California Consumer Privacy Act: European-Style Privacy With a California Enforcement Twist

HIPAA BUSINESS ASSOCIATE AGREEMENT. ( BUSINESS ASSOCIATE ) and is effective as of ( Effective Date ). RECITALS

UNDERSTANDING THE HIPAA/HITECH BREACH NOTIFICATION RULE 2/25/14

Pharmaceutical Pay for Delay Settlements

Model Business Associate Agreement

Background. 21 August Practice Group: Public Policy and Law. By Raymond P. Pepe

Breach Notification and Enforcement

BUSINESS ASSOCIATE AGREEMENT (BETWEEN GIOSTARCHICAGO.COM AND GIOSTARORTHOPEDICS.COM AND GODADDY)

HIPAA Compliance During Litigation and Discovery

BEGINNING A DEAL: NONDISCLOSURE AGREEMENTS AND LETTERS OF INTENT

Freedom of Information Act Request: Mobile Biometric Devices and Applications

Private Equity and Tax Reform: Fund, Transactions and Portfolio Company Strategies

Design Life Warranties and Fitness for Purpose in Construction Contracts: the Position in Australia and England

Grasping for a Hold on Ascertainability : The Implicit Requirement for Class Certification and its Evolving Application

NIH Revises Rules Governing Inventions Developed Under Bayh-Dole Act

the Patent Battleground:

HITECH Omnibus Business Associate Agreement DU Hybrid CE ra FINAL

BUSINESS ASSOCIATE AGREEMENT

2011: Healthcare Policy in the New Congress. January 7, 2011

Adapting to a New Era of Strict Criminal Liability Enforcement under Pennsylvania s Environmental Laws

COMMONWEALTH OF MASSACHUSETTS. ) COMMONWEALTH OF MASSACHUSETTS, ) ) Plaintiff, ) ) v. ) ) SOUTH SHORE HOSPITAL, INC., ) ) Defendant.

Venture-Ready Entrepreneur Workshop: Keeping Foreign Entrepreneurs (and Their Startups) in the United States. Overview

BUSINESS ASSOCIATE AGREEMENT

February 6, Practice Groups: Class Action Litigation Defense; Financial Institutions and Services Litigation

Eagle Take Permit Program Revamped Longer Permits and Clearer Mitigation Requirements

Site Access Agreement. (hereinafter referred to as the

A Compliance Guide for Covered Entities and Business Associates

Sales Order (Processing Services)

Peg Schmidt, RHIA CHPS and Amy Derlink, RHIA, CHA April 10, 2015

HOT TOPICS IN M&A PUBLIC COMPANY LITIGATION

Current Developments in Privacy and Security Rule Enforcement

Investigating Privacy Breaches under HITECH and HIPAA

Case 1:18-cr DLF Document 7-1 Filed 05/04/18 Page 1 of 6 ATTACHMENT A

The Eyes of Texas are upon a Subsurface Trespass Case

LAW FIRM BUSINESS ASSOCIATE TERMS AND CONDITIONS. North Carolina Society of Healthcare Attorneys

NEFF CORP FORM S-8. (Securities Registration: Employee Benefit Plan) Filed 11/21/14

Instant Messaging: Vote-A-Rama Provides Rare Insight into Tax Reform

Use and abuse of anti-arbitration injunctions: strategies in dealing with anti-arbitration injunctions

Congress Passes Historic Patent Reform Legislation

Case3:12-mc CRB Document88 Filed10/04/13 Page1 of 5. October 4, Chevron v. Donziger, 12-mc CRB (NC) Motion to Compel

EXHIBIT G PRIVACY AND INFORMATION SECURITY PROVISIONS

Corporate Governance Reforms and Proposed Amendments to NYSE Governance Disclosures. Contacts.

Law Introducing Rules for Localization of Personal Data of Russian Citizens

In Site UK Construction and Engineering Newsletter

Is Inter Partes Review Set for Supreme Court Review?

BUSINESS ASSOCIATE AGREEMENT

Spansion v. Apple The Intersection of the Bankruptcy Code and Intellectual Property AIPLA Spring Meeting May 2, 2013

Sedona Provides Updated, Practical Guidance for Legal Holds

Fact or Fiction? U.S. Government Surveillance in a Post-Snowden World

Latham & Watkins Environment, Land & Resources Department

LEGAL SUPERHEROES: VOL 2. MAKING YOU A LEGAL SUPERHERO!

Who can create jobs in america? The American Worker Perspective on U.S. Job Creation

Litigation Strategies in Europe MIP Global IP & Innovation Summit

Basic Upheld in Halliburton: Defendants May Rebut Price Impact

Commonwealth of Massachusetts County of Suffolk The Superior Court NOTICE OF DOCKET ENTRY

Latham & Watkins Health Care Practice

October Edition of Notable Cases and Events in E-Discovery

Texas July pm ET

Delaware Bankruptcy Court Confirms Lock-Up Agreements Are a Valuable Tool Not a Violation of the Bankruptcy Code

Appeals Court Resoundingly Affirms Scope and Breadth of Shipping Act Antitrust Exemption

ALERT. Government Law & Policy May 2014

The Telephone Consumer Protection Act Overview

December 15, Dear Justice Singh: VIA ECF LITIGATION

PENNSYLVANIA BAR ASSOCIATION COMMITTEE ON LEGAL ETHICS AND PROFESSIONAL RESPONSIBILITY FORMAL OPINION

AMERICAN RECOVERY & REINVESTMENT ACT OF 2009 TITLE XIII HEALTH INFORMATION TECHNOLOGY ANALYSIS OF PRIVACY AND SECURITY REQUIREMENTS (SUBPART D)

ARBITRATION IS BACK ON THE DOCKET: THE SUPREME COURT TO REVIEW THE ENFORCEABILITY OF CLASS-ACTION WAIVERS IN EMPLOYMENT ARBITRATION AGREEMENTS

AGREEMENT BETWEEN KIDS IN DISTRESS, INC., AND BROWARD COUNTY FOR SUBSTANCE ABUSE SERVICES Contract Number: KID-BARC-CFS-2017

Private action for contempt of court?

Challenging Government decisions in the UK. An introduction to judicial review

In Site. Delivery of an adjudicator s decision what happens if it is not delivered in time?

Paying for the Wall: Will President Trump s Administration Scrutinize, Tax, or Seize Remittances?

BUSINESS ASSOCIATE AGREEMENT

Terms of Use for the REDCap Non-Profit End-User License Agreement

MIP International Patent Forum 2013 Russia Focus

Health Information Technology for Economic and Clinical Health (HITECH) Act Privacy and Security Provisions

HIPAA DATA USE AGREEMENT

KAISER FOUNDATION HOSPITALS ON BEHALF OF KAISER FOUNDATION HEALTH PLAN OF THE MID-ATLANTIC STATES, INC.

Depository Financial Institution Liability: Tough Lessons Learned About Fraudulent Electronic Funds Transfers

Secured Services Web Site Administrator Agreement

September s Notable Cases and Events in E-Discovery

Client Alert. Circuit Courts Weigh In on Treatment of Trademark License Agreements in Bankruptcy

EEA and Swiss national. Children and their rights to British citizenship

Latham & Watkins Corporate Department. The Lessons of Slayton v. American Express for Forward-Looking Statements

Data Processing Agreement. <<Health Service Provider>> The National Message Broker Service known as Healthlink

Transcription:

HIPAA Privacy Compliance Initiative: Final Rules Impact Employer Health Plans www.morganlewis.com Presenters: Sage Fattahian Lauren Licastro Georgina O Hara Date: February 8, 2013 Time: 12:30-1:30 p.m. ET

Agenda History of HIPAA & HITECH Omnibus Regulations Business Associates Breach Notification Notice of Privacy Practices Enforcement Other Changes Next Steps Questions? 2

History of HIPAA & HITECH Act Health Insurance Portability & Accountability Act of 1996 (HIPAA) Privacy (effective 2003) & Security (effective 2005) Health Information Technology for Economic and Clinical Health (HITECH) Act Effective February 2010 Omnibus Regulations Effective date: March 26, 2013 Compliance date: September 23, 2013 (w/ exception) Marks the most sweeping changes to the HIPAA Privacy & Security Rules since they were first implemented. 3

Omnibus Regulations Business Associates (BA) Extends direct liability to BAs for Security & certain Privacy compliance Expands definition of BA e.g., Subcontractor of BA Additional guidance planned Affirms liability for acts of agents Modifies content of BA Agreements (BAAs) Comply by September 23, 2013, or September 23, 2014 if No additional time for BAs to comply 4

Omnibus Regulations Breach Notification Eliminates subjective significant risk of harm threshold Presumes breach requiring notification Unless CE/BA demonstrates low probability that PHI [protected health information] has been compromised Consider at least 4 factors Objective standard Likely to increase breach reporting Additional guidance planned Note: Methodology for counting violations remains unclear 5

Omnibus Regulations Other Changes Genetic Information Prohibits plans from using or disclosing genetic info for underwriting purposes Marketing & Sale of PHI Only permitted with authorization Individual Rights Restrict disclosure to plan when paying out of pocket Access to PHI in the form and format requested 6

Omnibus Regulations Notice of Privacy Practices (NPP) Revise for: Certain uses & disclosures requiring authorization Fundraising Breach Notice GINA Redistribution Post by September 23, 2013 & provide in next annual mailing 7

Omnibus Regulations Enforcement Retains 4 tiers of penalties Did not know $100 - $50,000 Due to reasonable cause $1,000 - $50,000 Due to willful neglect & timely corrected $10,000- $50,000 Due to willful neglect & not timely corrected $50,000 - $1.5M Secretary of Labor required to investigate complaint or to conduct compliance review where willful neglect probable Factors used in determining amount of civil money penalty 8

Next Steps Perform Gap Analysis/Self-Audit Now Revise Policies & Procedures Revise & Post/Distribute Notice of Privacy Practices Revise Business Associates/Subcontractor Agreements Consider approach Train Privacy Employees Consider Encryption 9

How We Can Help? Morgan Lewis Benefits Solutions HIPAA Privacy Initiative Self-Audit Assistance Includes detailed audit questionnaire Identification of potential violations Training May be recorded for future use Privacy Officer Assistance 10

Polling Question If you are interested in learning more about our HIPAA compliance services, please answer the polling question on the right-hand side of your screen and we will give you a call. 11

DISCLAIMER This material is provided as a general informational service to clients and friends of Morgan, Lewis & Bockius LLP. It should not be construed as, and does not constitute, legal advice on any specific matter, nor does this message create an attorney-client relationship. These materials may be considered Attorney Advertising in some states. Please note that the prior results discussed in the material do not guarantee similar outcomes. Links provided from outside sources are subject to expiration or change. 2013 Morgan, Lewis & Bockius LLP. All Rights Reserved. IRS Circular 230 Disclosure To ensure compliance with requirements imposed by the IRS, we inform you that any U.S. federal tax advice contained in this communication (including any attachments) is not intended or written to be used, and cannot be used, for the purpose of (i) avoiding penalties under the Internal Revenue Code or (ii) promoting, marketing, or recommending to another party any transaction or matter addressed herein. For information about why we are required to include this legend, please see http://www.morganlewis.com/circular230. 27

Contact Information Lauren Licastro Pittsburgh 412.560.3383 llicastro@morganlewis.com Sage Fattahian Chicago 312.324.1744 sfattahian@morganlewis.com Georgina O Hara Philadelphia 215.963.5188 go'hara@morganlewis.com 14

international presence Almaty Beijing Boston Brussels Chicago Dallas Frankfurt Harrisburg Houston Irvine London Los Angeles Miami Moscow New York Palo Alto Paris Philadelphia Pittsburgh Princeton San Francisco Tokyo Washington Wilmington 15