With all of the attention garnered by healthcare reform, it would be easy to overlook the new HIPAA rules (the "Rules") applicable to covered entities under HIPAA, which include employer group health plans. Compliance with the Rules is generally required by September 23, 2013. The Rules modify the HIPAA privacy, security, enforcement and breach notification rules by expanding individual rights and strengthening enforcement. The major changes affecting group health plans are summarized below. In addition, health plan documents and SPDs along with HIPAA policies and procedures may need to be updated, and the workforce may need to be retrained in the Rules.
1. Privacy Notice. Privacy Notices must be revised to include the following:
a) A description of the types of uses and disclosures that require an authorization with respect to psychotherapy notes, marketing, and sale of protected health information (PHI)...
Please see full publication below for more information.