HealthBlawg

David Harlow's Health Care Law Blog

  • About
  • Archives
  • Podcast
  • Press
  • Awards/Reviews
  • HIPAA
  • HCSM

GAO says HHS is on the road to a coordinated privacy policy, but not there yet

February 2, 2007

GAO testimony before a Senate subcommittee yesterday provides a concise overview of the past few years’ developments in the realms of privacy and interoperability as they relate to HIT — both in terms of regulations and the superstructure necessary to implement them.

HHS believes that it is further down the road to developing an integrated approach to ensuring the protection of privacy of patient information than does GAO. 

It has certainly cooked up another big batch of alphabet soup — ONCHIT, NHIN, NCVHS, etc.  But per the GAO,

HHS is in the early stages of its efforts and has therefore not yet defined an overall approach for integrating its various privacy-related initiatives and addressing key privacy principles, nor has it defined milestones for integrating the results of these activities. GAO identified key challenges associated with protecting electronic personal health information in four areas (see table).

Update 2/5/07:  All of the testimony from the hearing is up on the subcommittee’s website.  Pay special attention to Mark Rothstein’s statement.  He chairs the privacy and confidentiality subcommittee of the National Committee on Vital and Health Statistics (NCVHS), and is rightfully steamed over HHS’s sitting on his recommendations for six months.  He began:

In my testimony today, I want to make only two points. First, HHS has made very little meaningful progress in developing and implementing measures to protect the privacy of health information in electronic health networks. Second, time is of the essence. HHS must begin to act immediately on the key privacy issues, and Congress needs to hold HHS accountable.

Here’s hoping that the regulatory structure can catch up with the realities of the marketplace.

— David Harlow

Related Posts

  • Smile! Privacy Policy Snapshot ~ Model Privacy Notice

    In thinking about patient privacy, many folks assume that HIPAA is the first and last…

  • PHR privacy breakthrough?

    Connecting for Health. a broad industry coalition organized by the Markle Foundation, announced yesterday a…

  • HIMSS Privacy and Security Forum: Managing Social Media While Protecting Privacy and Security

    I spoke at this week's HIMSS Privacy and Security Forum in Boston on the privacy…

Filed Under: Ehealth, EHR, Health care policy, Health Law, HIPAA, HIT, Privacy

« Value-driven health care: Premier HQID demonstration yields improved performance, HSAs may as well — but there's a limit to these things
Reminder: Health Wonk Review #25 in this space soon »

Threads

Follow me on: Threads

Mastodon

Follow me on: Mastodon

HIPAAtools

Hipaatools

The HIPAA Compliance Toolkit

The Walking Gallery

The Walking Gallery

Quick Links

  • Home
  • Categories
  • Archives
  • Podcast Interviews
  • HIPAAtools
  • HIPAA Compliance
  • Health Care Social Media
  • Speaking
  • In the Press
  • Blogroll

David Harlow

David Harlow

HealthcareNOW Radio

  • Subscribe
  • Contact
  • Book Me: Speaking
  • About
  • The Harlow Group LLC
Copyright © 2006–2025
HealthBlawg is a publication of The Harlow Group LLC. See Copyright notice and disclaimer.
Fair use with attribution and a link is encouraged. Click for more on David Harlow.
[footer_backtotop text="Back to top" href="#"]