AHA Urges HHS to Retain Risk of Harm Standard for Health Information Breach Notifications

The American Hospital Association has urged the Department of Health and Human Services to retain its “risk of harm” standard in its final rule on breach notification for unsecured protected health information, according to a report by AHANews.

Advertisement

In a letter to HHS, the AHA argued that notifying individuals of breaches, when it has been determined that there is “no reasonable likelihood of harm to the individuals,” serves “no useful purpose.”

The AHA further stated that including a risk of harm standard is consistent with language in the HITECH Act, as well as with state laws and federal agency policies.

While the AHA generally supports the HHS’ rule that would require providers to notify individuals of breaches, the group is opposed to the HHS’ guidance that “covered entities must determine whether their business associates are agents in order to understand when a business associate’s knowledge of a breach will be imputed directly to covered entities,” according to the report.

Read the AHANews’ report on the AHA’s stance on retaining the risk of harm standard.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Advertisement

Next Up in Legal & Regulatory Issues

Advertisement

Comments are closed.