<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">
    <title>Web-Tones</title>
    
    <link rel="alternate" type="text/html" href="http://www.lawtechtv.com/home/" />
    <id>tag:typepad.com,2003:weblog-269685</id>
    <updated>2009-07-15T14:44:03-04:00</updated>
    <subtitle>res ipsa loquitur (the web speaks for itself and loudly)</subtitle>
    <generator uri="http://www.typepad.com/">TypePad</generator>
    <link rel="self" href="http://feeds.feedburner.com/Web-tones" type="application/atom+xml" /><entry>
        <title>HIPAA, HITECH &amp; FTC Red Flags Rule</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Web-tones/~3/8WQVwJuZWCU/hipaa-hitech-ftc-red-flags-rule.html" />
        <link rel="replies" type="text/html" href="http://www.lawtechtv.com/home/2009/07/hipaa-hitech-ftc-red-flags-rule.html" />
        <id>tag:typepad.com,2003:post-6a00d8341e18e853ef011571153eff970c</id>
        <published>2009-07-15T14:44:03-04:00</published>
        <updated>2009-07-16T08:56:19-04:00</updated>
        <summary>HealthBlawg: Red Flags Rule: The FTC piles on, because HIPAA, ARRA and overlapping state laws just weren't enough. David has an excellent post summarizing the impact that the FTC's Red Flags Rule may have on healthcare providers. As I have...</summary>
        <author>
            <name>Carlos Leyva</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Red Flags" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="HIPAA" />
        <category scheme="http://sixapart.com/ns/types#tag" term="HITECH" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Internet Lawyer" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Privacy Lawyer" />
        
<content type="html" xml:lang="en-US" xml:base="http://www.lawtechtv.com/home/">&lt;p&gt;&lt;a href="http://healthblawg.typepad.com/healthblawg/2009/07/red-flags-rule-ftc-hipaa-and-arra.html" title="HealthBlawg: Red Flags Rule: The FTC piles on, because HIPAA, ARRA and overlapping state laws just weren't enough"&gt;HealthBlawg: Red Flags Rule: The FTC piles on, because HIPAA, ARRA and overlapping state laws just weren't enough&lt;/a&gt;. David has an excellent post summarizing the impact that the FTC's Red Flags Rule may have on healthcare providers.&lt;/p&gt;&lt;p&gt;As I have written about previously, there is a &lt;a href="http://www.lawtechtv.com/home/2009/07/european-privacy-law-and-social-networking-privacy-law-blog.html"&gt;regulatory freight train coming&lt;/a&gt; that few in the healthcare industry see, although many are starting to get a sense that there is something "out there" heading their way. As a &lt;a href="http://www.digitalbusinesslawgroup.com"&gt;privacy lawyer&lt;/a&gt;, I help clients deal with these kinds of regulatory issues, not only within healthcare, but across industry sectors. &lt;/p&gt;&lt;p&gt;As a veteran of the technology industry it is clear to me that there is a convergence of law, policy and technology happening on a daily basis. It helps to have "bi lingual" partners due to the number of organizational stakeholders that need to weigh in on compliance issues. &lt;/p&gt;&lt;p&gt;Privacy and data security compliance is fast becoming a board room issue.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Web-tones?a=8WQVwJuZWCU:XSpHWKkV5NM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Web-tones?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://www.lawtechtv.com/home/2009/07/hipaa-hitech-ftc-red-flags-rule.html</feedburner:origLink></entry>
    <entry>
        <title>HITECH / HIPAA Compliance is Serious Business!</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Web-tones/~3/e0g_RZcSzT8/hitech-hipaa-compliance-is-serious-business.html" />
        <link rel="replies" type="text/html" href="http://www.lawtechtv.com/home/2009/07/hitech-hipaa-compliance-is-serious-business.html" />
        <id>tag:typepad.com,2003:post-6a00d8341e18e853ef011571120dc3970c</id>
        <published>2009-07-14T22:21:27-04:00</published>
        <updated>2009-07-15T12:33:05-04:00</updated>
        <summary>Well yes it is but, then again we all need a little levity, and no one needs it more than a HIPAA lawyer or a HIPAA compliance officer. Without a little humor, the HITECH alphabet soup might just drive you...</summary>
        <author>
            <name>Carlos Leyva</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="HIPAA" />
        
        
<content type="html" xml:lang="en-US" xml:base="http://www.lawtechtv.com/home/">
&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;&lt;object width="560" height="340"&gt;&lt;param name="movie" value="http://www.youtube.com/v/Gv1s8fM3mMk&amp;amp;hl=en&amp;amp;fs=1&amp;amp;"&gt;&lt;param name="allowFullScreen" value="false"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;embed allowfullscreen="false" allowscriptaccess="always" src="http://www.youtube.com/v/Gv1s8fM3mMk&amp;amp;hl=en&amp;amp;fs=1&amp;amp;" type="application/x-shockwave-flash" width="475" height="340"&gt;&lt;/object&gt;

Well yes it is but, then again we all need a little levity, and no one needs it more than a &lt;a href="http://www.digitalbusinesslawgroup.com/ps-hipaa-audit.html"&gt;HIPAA lawyer&lt;/a&gt; or a HIPAA&amp;nbsp; compliance officer.&lt;/p&gt;&lt;p&gt;Without a little humor, the HITECH alphabet soup might just drive you over the HIPAA edge. Listen and enjoy.&lt;/p&gt;&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Web-tones?a=e0g_RZcSzT8:HKKGsKB5mw4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Web-tones?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://www.lawtechtv.com/home/2009/07/hitech-hipaa-compliance-is-serious-business.html</feedburner:origLink></entry>
    <entry>
        <title>Copyright Holders Beware!</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Web-tones/~3/6HFtCJepy74/copyright-holders-beware.html" />
        <link rel="replies" type="text/html" href="http://www.lawtechtv.com/home/2009/07/copyright-holders-beware.html" />
        <id>tag:typepad.com,2003:post-6a00d8341e18e853ef0115711033c3970c</id>
        <published>2009-07-14T17:13:00-04:00</published>
        <updated>2009-07-14T17:13:00-04:00</updated>
        <summary>Are You Gambling With Your Copyright By Entering That Photography Contest? : Owners, Borrowers &amp; Thieves 2.0. Lots of copyright traps to fall into for the unwary. Most small businesses and independent contractors simply do not pay enough attention to...</summary>
        <author>
            <name>Carlos Leyva</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Copyright" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Copyright Lawyer" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Internet Lawyer" />
        
<content type="html" xml:lang="en-US" xml:base="http://www.lawtechtv.com/home/">&lt;p&gt;&lt;a href="http://iplitigator.huschblackwell.com/2009/07/articles/copyright/are-you-gambling-with-your-copyright-by-entering-that-photography-contest/" title="Are You Gambling With Your Copyright By Entering That Photography Contest? : Owners, Borrowers &amp;amp; Thieves 2.0"&gt;Are You Gambling With Your Copyright By Entering That Photography Contest? : Owners, Borrowers &amp;amp; Thieves 2.0&lt;/a&gt;. Lots of copyright traps to fall into for the unwary. Most small businesses and independent contractors simply do not pay enough attention to the basics. A little education can go a long ways. &lt;/p&gt;&lt;p&gt;As an I&lt;a href="http://digitalbusinesslawgroup.com"&gt;nternet Lawyer&lt;/a&gt; education is a big part of what I do.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Web-tones?a=6HFtCJepy74:RoST44ndkWQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Web-tones?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://www.lawtechtv.com/home/2009/07/copyright-holders-beware.html</feedburner:origLink></entry>
    <entry>
        <title>HITECH/HIPAA Timelines?</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Web-tones/~3/LXqlnrHf2Ok/hitechhipaa-timeline.html" />
        <link rel="replies" type="text/html" href="http://www.lawtechtv.com/home/2009/07/hitechhipaa-timeline.html" />
        <id>tag:typepad.com,2003:post-6a00d8341e18e853ef011570ffb511970c</id>
        <published>2009-07-11T11:14:15-04:00</published>
        <updated>2009-07-14T12:28:10-04:00</updated>
        <summary>Here are some of the relevant timelines for HITECH/HIPAA compliance. Refer to the Subtitle-D table of contents below for a quick reference to the respective sections. HITECH enactment (February 17, 2009) Tiered civil penalties based on the nature of HIPAA...</summary>
        <author>
            <name>Carlos Leyva</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Privacy &amp; Data Security" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="HIPAA" />
        <category scheme="http://sixapart.com/ns/types#tag" term="HITECH" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Privacy Lawyer" />
        
<content type="html" xml:lang="en-US" xml:base="http://www.lawtechtv.com/home/">
&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;Here are some of the relevant timelines for HITECH/HIPAA compliance. Refer to the Subtitle-D table of contents below for a quick reference to the respective sections.&lt;/p&gt;&lt;ul&gt;
&lt;li&gt;HITECH enactment (February 17, 2009) Tiered civil penalties based on the nature of HIPAA violations, up to $50,000 per violation and an annual maximum of $1.5 million (&lt;strong&gt;Section 13410&lt;/strong&gt;).&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;180 days post enactment (August 17, 2009) HHS and the FTC will promulgate interim regulations on notification of breaches. The FTC rules will apply to breach notification by PHRs that are not covered by HIPAA (i.e. because generally the organization that produces the PHR is not a &amp;quot;covered entity&amp;quot;) or business associate agreements (Section &lt;strong&gt;13402, 13407&lt;/strong&gt;).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;/p&gt;&lt;ul&gt;
&lt;li&gt;24 months post-enactment (February 17, 2011) HHS clarification regarding ability to pursue civil penalties when criminal penalties are not pursued (Section &lt;strong&gt;13405&lt;/strong&gt;).&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;36 months post-enactment (February 17, 2012) HHS is obligated to establish regulations that will allow individuals harmed by privacy and security violations to receive a percentage of any HHS monies collected related to civil fines regarding such violations.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;span style="font-size: 20px; font-family: Helvetica;"&gt;&lt;br /&gt;DIVISION A: TITLE XIII—HEALTH INFORMATION TECHNOLOGY&lt;/span&gt;&lt;/p&gt;&lt;p&gt;SUBTITLE D-PRIVACY.&lt;/p&gt;



&lt;p class="MsoNormal"&gt;Sec. 13400. Definitions.&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;strong&gt;PART 1—IMPROVED PRIVACY PROVISIONS AND SECURITY PROVISIONS&lt;/strong&gt;&lt;/p&gt;





&lt;p class="MsoNormal"&gt;Sec. 13401. Application of security provisions and penalties
to business associates of covered entities; annual guidance on security provisions.&lt;/p&gt;

&lt;p class="MsoNormal"&gt;Sec. 13402. Notification in the case of breach.&lt;/p&gt;

&lt;p class="MsoNormal"&gt;Sec. 13403. Education on health information privacy.&lt;/p&gt;



&lt;p class="MsoNormal"&gt;Sec. 13404. Application of privacy provisions and penalties
to business associates of covered entities.&lt;/p&gt;





&lt;p class="MsoNormal"&gt;Sec. 13405. Restrictions on certain disclosures and sales of
health information; accounting of certain protected health information disclosures; access
to certain information in electronic format.&lt;/p&gt;

&lt;p class="MsoNormal"&gt;Sec. 13406. Conditions on certain contacts as part of health
care operations.&lt;/p&gt;



&lt;p class="MsoNormal"&gt;Sec. 13407. Temporary breach notification requirement for
vendors of personal health records and other non-HIPAA covered entities.&lt;/p&gt;

&lt;p class="MsoNormal"&gt;Sec. 13408. Business associate contracts required for
certain entities.&lt;/p&gt;

&lt;p class="MsoNormal"&gt;Sec. 13409. Clarification of application of wrongful
disclosures criminal penalties.&lt;/p&gt;

&lt;p class="MsoNormal"&gt;Sec. 13410. Improved enforcement.&lt;/p&gt;



&lt;p class="MsoNormal"&gt;Sec. 13411. Audits.&lt;o:p&gt;&lt;br /&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;br /&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;strong&gt;PART 2—RELATIONSHIP TO OTHER LAWS; REGULATORY REFERENCES; EFFECTIVE
DATE; REPORTS&lt;/strong&gt;&lt;/p&gt;



&lt;p class="MsoNormal"&gt;Sec. 13421. Relationship to other laws.&lt;/p&gt;&lt;p class="MsoNormal"&gt;To learn more about HITECH and HIPAA see the &lt;a href="http://www.hipaasurvivalguide.com"&gt;HIPAA Survival Guide&lt;/a&gt;.&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Web-tones?a=LXqlnrHf2Ok:Y43IAEzsva0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Web-tones?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://www.lawtechtv.com/home/2009/07/hitechhipaa-timeline.html</feedburner:origLink></entry>
    <entry>
        <title>FTC Red Flags Rule &amp; Health Care Providers?</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Web-tones/~3/K-3w1KpYqJg/ftc-red-flags-rule-health-care-providers.html" />
        <link rel="replies" type="text/html" href="http://www.lawtechtv.com/home/2009/07/ftc-red-flags-rule-health-care-providers.html" />
        <id>tag:typepad.com,2003:post-6a00d8341e18e853ef011571f42b7b970b</id>
        <published>2009-07-11T10:01:54-04:00</published>
        <updated>2009-07-11T10:01:54-04:00</updated>
        <summary>Many health care providers probably do not realize that they may be considered "creditors" under the FTC's Red Flags Rule, designed to prevent identity theft, usually involved with financial transactions, but which is increasingly spreading into other domains. This is...</summary>
        <author>
            <name>Carlos Leyva</name>
        </author>
        
        <category scheme="http://sixapart.com/ns/types#tag" term="FTC" />
        <category scheme="http://sixapart.com/ns/types#tag" term="HIPAA" />
        <category scheme="http://sixapart.com/ns/types#tag" term="HITECH" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Privacy Lawyer" />
        
<content type="html" xml:lang="en-US" xml:base="http://www.lawtechtv.com/home/">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;&lt;span size="2" style="font-family: Arial,Helvetica,Geneva,Swiss,SunSans-Regular;"&gt;Many health care providers probably do not realize that they may be considered "creditors" under the FTC's &lt;/span&gt;&lt;a href="http://www.google.com/url?q=http%3A%2F%2Fwww.ftc.gov%2Fredflagsrule&amp;amp;sa=D&amp;amp;sntz=1&amp;amp;usg=AFrqEzc2Jg0iiEOZpXkW5Lcxv78ivSvPYA" target="_blank"&gt;Red Flags&lt;/a&gt; Rule&lt;span size="2" style="font-family: Arial,Helvetica,Geneva,Swiss,SunSans-Regular;"&gt;, designed to prevent identity theft, usually involved with financial transactions, but which is increasingly spreading into other domains.&lt;br&gt;&lt;br&gt;This is yet one more sign that protected health information (PHI) is going to be getting more attention as HHS pushes for the adoption of electronic health records. &lt;/span&gt;&lt;font face="Arial,Helvetica,Geneva,Swiss,SunSans-Regular" size="2"&gt;"The red flags rule is intended to address all forms of identity theft,&#xD;
including those involving the provision of health care," according to&#xD;
an FTC document.&lt;/font&gt;&lt;br&gt;&lt;font face="Arial,Helvetica,Geneva,Swiss,SunSans-Regular" size="2"&gt;&lt;br&gt;&lt;br&gt;&#xD;
													&lt;/font&gt;&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Web-tones?a=K-3w1KpYqJg:SX92kbCa8yQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Web-tones?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://www.lawtechtv.com/home/2009/07/ftc-red-flags-rule-health-care-providers.html</feedburner:origLink></entry>
 
</feed><!-- ph=1 --><!-- nhm:dynamic-ssi -->
