The final rule is significant for any organization that is considered to be a HIPAA covered entity (“CE”) (health systems, health care providers, health plans, etc.) or the more broadly defined business associate (“BA”). During our initial analysis of the final rule, we note significant changes to the way a breach is defined and we will be discussing some of those changes during a webinar on January 23, 2013.
There are several ways CEs and BAs can prepare. We have prepared a redlined version of the final rule as a way to help CEs and BAs sift through the changes and prepare for the March 26, 2013 effective date. The Department of Human Services (HHS) Office for Civil Rights (OCR) has referred to these as “sweeping changes” that better enable them to “vigorously” enforce the HIPAA Privacy and Security Rules.