ALLcrimesfood&drugstaxestelecomcommercehealthconservationtransportationagricultureveteransbrowse all titles »
0

42 U.S.C. § 17953Studies, reports, guidance

submitted 17 years ago by Pub. L. 111-5 to r/title-42-THE-PUBLIC-HEALTH-AND-WELFARE · 1,046 words · no verdicts yet

in plain englishAI-generated · not legal advice

The Secretary must report each year to Congress on privacy and security complaints, and post that report online. The Secretary and FTC must also study privacy rules for non-HIPAA companies and report recommendations to Congress. Other studies cover de-identifying data, sharing records for treatment, this law's impact, and psychotherapy notes.

(a) Report on compliance (1) Starting with the first full year after February 17, 2009, and every year after that, the Secretary must send a report to the Senate Committee on Health, Education, Labor, and Pensions, and to the House Committees on Ways and Means and on Energy and Commerce. The report covers complaints received that year about possible violations of this subchapter and of the related federal privacy and security rules (45 C.F.R. part 164, subparts C and E, as they stood on February 17, 2009). Each report must include: (A) how many complaints came in; (B) how many were resolved informally, what kinds those were, and how many covered entities got technical help from the Secretary to fix problems, and what kind of help; (C) how many complaints led to civil penalties or paid settlements, what those complaints were about, and how much was paid in each case; (D) how many compliance reviews were done and what each one found; (E) how many subpoenas or inquiries were issued; (F) the Secretary's plan for improving compliance and enforcement the following year; and (G) how many audits were done under section 17940, and a summary of what they found. (2) The Secretary must post each year's report on HHS's website for the public to see. (b) Study and report on applying privacy and security rules to companies not covered by HIPAA (1) Within a year of February 17, 2009, the Secretary — working with the Federal Trade Commission — had to study what privacy, security, and breach-notification rules should apply to companies that are not HIPAA covered entities or business associates. This includes: personal health record vendors; companies that offer products or services through a PHR vendor's website; non-covered companies that offer products or services through a covered entity's website that offers personal health records; non-covered companies that access or send information to a personal health record; and third-party service providers that work for any of those companies. The study also had to look at whether an exemption from notification should apply when health information has been made unusable, unreadable, or undecipherable using recognized security methods, and had to figure out which federal agency is best suited to enforce these new rules, plus a timeframe for writing the regulations. (2) The Secretary had to send the results — including recommendations — to the Senate Finance, HELP, and Commerce Committees, and to the House Ways and Means and Energy and Commerce Committees. (c) Guidance on de-identifying health information Within 12 months of February 17, 2009, the Secretary — after consulting with stakeholders — had to issue guidance on the best way to meet the de-identification requirements in 45 C.F.R. § 164.514(b). (d) GAO report on sharing records for treatment Within a year of February 17, 2009, the Comptroller General had to report to the Senate HELP Committee and the House Ways and Means and Energy and Commerce Committees on best practices for health care providers sharing a patient's protected health information with each other for treatment purposes. The report had to look at practices used by states and by groups like health information exchanges, how well those practices actually improved care and how manageable they were for providers, and how electronic informed consent is being used when sharing records for treatment, payment, and health care operations. (e) Report on the law's overall impact Within 5 years of February 17, 2009, the Government Accountability Office had to report to Congress and the Secretary on how the Act's provisions affected health insurance premiums, overall health care costs, how many providers adopted electronic health records, and whether medical errors dropped and quality improved. (f) Study on the definition of "psychotherapy notes" The Secretary had to study the definition of "psychotherapy notes" in 45 C.F.R. § 164.501 — specifically, whether it should include test data such as direct responses, scores, items, forms, protocols, manuals, or other materials that are part of a mental health evaluation, as the treating or evaluating mental health professional decides. Based on that study, the Secretary may issue regulations revising the definition.
the actual law source: uscode.house.gov ↗public domain
(a) Report on compliance
(1) In general

For the first year beginning after February 17, 2009, and annually thereafter, the Secretary shall prepare and submit to the Committee on Health, Education, Labor, and Pensions of the Senate and the Committee on Ways and Means and the Committee on Energy and Commerce of the House of Representatives a report concerning complaints of alleged violations of law, including the provisions of this subchapter as well as the provisions of subparts C and E of part 164 of title 45, Code of Federal Regulations, (as such provisions are in effect as of February 17, 2009) relating to privacy and security of health information that are received by the Secretary during the year for which the report is being prepared. Each such report shall include, with respect to such complaints received during the year—

(A)

the number of such complaints;

(B)

the number of such complaints resolved informally, a summary of the types of such complaints so resolved, and the number of covered entities that received technical assistance from the Secretary during such year in order to achieve compliance with such provisions and the types of such technical assistance provided;

(C)

the number of such complaints that have resulted in the imposition of civil monetary penalties or have been resolved through monetary settlements, including the nature of the complaints involved and the amount paid in each penalty or settlement;

(D)

the number of compliance reviews conducted and the outcome of each such review;

(E)

the number of subpoenas or inquiries issued;

(F)

the Secretary’s plan for improving compliance with and enforcement of such provisions for the following year; and

(G)

the number of audits performed and a summary of audit findings pursuant to section 17940 of this title.

(2) Availability to public

Each report under paragraph (1) shall be made available to the public on the Internet website of the Department of Health and Human Services.

(b) Study and report on application of privacy and security requirements to non-HIPAA covered entities
(1) Study

Not later than one year after February 17, 2009, the Secretary, in consultation with the Federal Trade Commission, shall conduct a study, and submit a report under paragraph (2), on privacy and security requirements for entities that are not covered entities or business associates as of February 17, 2009, including—

(A)

requirements relating to security, privacy, and notification in the case of a breach of security or privacy (including the applicability of an exemption to notification in the case of individually identifiable health information that has been rendered unusable, unreadable, or indecipherable through technologies or methodologies recognized by appropriate professional organization or standard setting bodies to provide effective security for the information) that should be applied to—

(i)

vendors of personal health records;

(ii)

entities that offer products or services through the website of a vendor of personal health records;

(iii)

entities that are not covered entities and that offer products or services through the websites of covered entities that offer individuals personal health records;

(iv)

entities that are not covered entities and that access information in a personal health record or send information to a personal health record; and

(v)

third party service providers used by a vendor or entity described in clause (i), (ii), (iii), or (iv) to assist in providing personal health record products or services;

(B)

a determination of which Federal government agency is best equipped to enforce such requirements recommended to be applied to such vendors, entities, and service providers under subparagraph (A); and

(C)

a timeframe for implementing regulations based on such findings.

(2) Report

The Secretary shall submit to the Committee on Finance, the Committee on Health, Education, Labor, and Pensions, and the Committee on Commerce of the Senate and the Committee on Ways and Means and the Committee on Energy and Commerce of the House of Representatives a report on the findings of the study under paragraph (1) and shall include in such report recommendations on the privacy and security requirements described in such paragraph.

(c) Guidance on implementation specification to de-identify protected health information

Not later than 12 months after February 17, 2009, the Secretary shall, in consultation with stakeholders, issue guidance on how best to implement the requirements for the de-identification of protected health information under section 164.514(b) of title 45, Code of Federal Regulations.

(d) GAO report on treatment disclosures

Not later than one year after February 17, 2009, the Comptroller General of the United States shall submit to the Committee on Health, Education, Labor, and Pensions of the Senate and the Committee on Ways and Means and the Committee on Energy and Commerce of the House of Representatives a report on the best practices related to the disclosure among health care providers of protected health information of an individual for purposes of treatment of such individual. Such report shall include an examination of the best practices implemented by States and by other entities, such as health information exchanges and regional health information organizations, an examination of the extent to which such best practices are successful with respect to the quality of the resulting health care provided to the individual and with respect to the ability of the health care provider to manage such best practices, and an examination of the use of electronic informed consent for disclosing protected health information for treatment, payment, and health care operations.

(e) Report required

Not later than 5 years after February 17, 2009, the Government Accountability Office shall submit to Congress and the Secretary of Health and Human Services a report on the impact of any of the provisions of this Act on health insurance premiums, overall health care costs, adoption of electronic health records by providers, and reduction in medical errors and other quality improvements.

(f) Study

The Secretary shall study the definition of “psychotherapy notes” in section 164.501 of title 45, Code of Federal Regulations, with regard to including test data that is related to direct responses, scores, items, forms, protocols, manuals, or other materials that are part of a mental health evaluation, as determined by the mental health professional providing treatment or evaluation in such definitions and may, based on such study, issue regulations to revise such definition.

Source credit: (Pub. L. 111–5, div. A, title XIII, § 13424, Feb. 17, 2009, 123 Stat. 276.)

history & why it existsrecord from the source credit
  • 2009Enacted · Pub. L. 111-5 · 123 Stat. 276

A history note hasn’t been published yet. The record shows enactment by Pub. L. 111-5 on 2009-02-17.

all 0 arguments · sorted by: best

0/280

no arguments yet — make the first case