Industry Note:
2 States Expand Patient Privacy Breach Notification Requirements
Published on Tue Sep 27, 2011
If you live in certain states, you may need to tighten up your patient privacy practices. "California and Texas have both significantly expanded statutes that require notifications in the event of a data breach," warns law firm Sidley Austin in an update on its website. Texas also created "significant new protections for health information," Sidley notes. The new California law mandates notification to the California Attorney General when a breach involves more than 500 Californians, Sidley explains. The law also contains new content requirements for notification letters. Under Texas' new law, providers now must notify affected Texans plus affected residents of other states that lack breach notification laws, Sidley says. The notification of other states' residents is "novel," the law firm observes. Remember: Stricter state law requirements trump federal HIPAA rules, legal experts point out.