Medicare Compliance & Reimbursement

HIPAA:

CMS UNVEILS LONG-AWAITED HIPAA SECURITY RULE

After months of delays, the Centers for Medicare & Medicaid Services Feb. 13 finally unveiled its much-anticipated final rule on the Health Insurance Portability and Accountability Act security rule.

The 289-page rule works hand-in-hand with the HIPAA privacy standard. Privacy compliance is at the top of virtually every health care compliance officer’s to-do list. While the privacy rule sets standards for how protected health information can be used and when it can be disclosed, the security standards “define administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of electronic protected health information,” CMS explains in the rule.

Acknowledging the close link between the privacy and security standards, CMS says it crafted the two rules to employ similar terminology to make compliance easier. “We took great care to address every detail and produce a rule that health care providers will find easy to understand and implement,” says CMS chief Tom Scully.

In related news, CMS also finalized modifications to the HIPAA transaction standards, which define uniform, mandatory technical specs for electronic health care transactions. Both the security and transactions rules are slated to be published in the Federal Register Feb. 20.

When does it hit? For most organizations, the deadline for compliance with the security standards will be April 21, 2005 (small health plans will have another year to comply). The compliance deadline for the privacy rule is April 14, 2003 — less than two months away — for most organizations covered by the rule. The zero hour for the transaction standards is Oct. 16, 2003.

To see advance copies of the security and transaction standards, go to http://cms.hhs.gov.

• Interested parties can dial in to a Friday, Feb. 28 conference call from CMS on Health Insurance Portability and Accountability Act implementation. The call is from 2:00 to 3:30 pm EST and a playback is available for three days starting the following Monday.

To access the live call, dial 1-877-381-6315 with conference ID number 8096358. For the playback, dial 1-800-642-1687 with ID number 8096358, CMS instructs.

Other Articles in this issue of

Medicare Compliance & Reimbursement

View All