Skip to content

Compliance Building

Doug Cornelius on compliance for private equity real estate

Menu
  • Home
  • About
    • About
    • About Doug
    • About This Website
    • Why I Blog
    • Speaking Engagements
    • Contact
    • Publications
  • Archives
    • Topic Archive
    • Book Reviews
    • Most Popular
  • Subscribe
  • Disclaimers
    • Disclaimers
    • Policies and Procedures
    • Use of Site Content
    • Comments
    • FTC Disclosure
Menu

The HITECH Act

Posted on July 23, 2009 by Doug Cornelius
Print Friendly, PDF & Email

Pillsbury Winthrop Shaw Pittman LLP

I sat in a webinar on CyberSecurity Law: The Best Offense is a Good Defense sponsored by Pillsbury Winthrop Shaw Pittman LLP.  One aspect of the presentation was the Health Information Technology for Economic and Clinical Health Act.

This created the first federal data breach notification law.  It also substantially revised HIPAA regulations regarding privacy and security.

A “Breach” means:

  • Unauthorized access, use or disclosure of Public Health Information
  • That compromises the security, privacy or integrity of the Public Health Information
  • Does not include unintentional disclosures if made in good faith and within course and scope of employment or business associate relationship, provided that the Public Health Information is not further acquired, accessed used or disclosed

The difference between the HITECH Act and the state date breach notification laws deals with encryption, not security. It focuses on medical information, not just financial/identification information. Only California and Texas include medical information in data breach notification law.

The regulations from the FTC are very detailed. You must notify each US citizen and resident whose information was acquired by an unauthorized person and FTC. The Burden is on the company to demonstrate that all required notifications are made

Sending the breach notification:

  • By 1st class mail to last known address
  • By email “if specified as preference by the individual” (express affirmative consent required – pre-checked boxes and disclosures in TOS/Privacy Policy are NOT sufficient)
  • May provide notice via telephone or other means if Breach is deemed to require urgency (e.g.,due to possible imminent misuse of PHI)

Notification may be delayed for law enforcement purposes consistent with HIPAA Privacy Rule

If more than 10 individuals, Covered Entity must:

  • post notice on home page (and “landing pages” for existing account holders (FTC))
  • provide notice to major print/broadcast media in relevant geographic area, including tollfree phone number
  • must be prominent, clear and conspicuous, stated in plain language and run multiple times

Jurisdiction is split between the FTC and Health and Human Services. You are still subject to state enforcement of data breaches under state law.

Share this:

  • Print (Opens in new window) Print
  • Share on Facebook (Opens in new window) Facebook
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on X (Opens in new window) X
  • Email a link to a friend (Opens in new window) Email

Leave a ReplyCancel reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Search for Stuff

Recent Stories

  • SEC’s Private Markets Roundtable
  • FINRA Raising Gift Limit
  • Residential Real Estate Reporting Has Begun
  • BlueSky Eagle and the Ghost Filing
  • Updates to the SEC Enforcement Manual
  • When Drug Lords Want Their Kids to Be Better Athletes
  • Insider Trading Before Bankruptcy
  • Relief for ’40 Act Funds
  • Artificial Intelligence Produced Materials are Not Protected by Privilege
  • FINRA Looks to Allow Projected Performance

Fight Cancer

Please support my Pan-Mass Challenge
Make a donation to fight cancer. donate.pmc.org/DC0176
pan-mass challenge badge

I am a lawyer, but I am not your lawyer. Since I’m a lawyer, this website may be considered attorney advertising under the ethical rules of certain jurisdictions. Please read my disclaimers page before taking any action. And then, don't take any action based on what I wrote.

Creative Commons logo with the text 'Some Rights Reserved' and three symbols representing attribution, non-commercial use, and share alike.

Compliance Building - by Doug Cornelius is licensed under a Creative Commons Attribution-Noncommercial 3.0 United States License.