Upcoming Events

Executive conference

Cloud Connect March 16-18

Comprehensive thought leadership for executives, IT professionals and developers. Topics include: the ROI, cost and economics of on-demand computing; Migration strategies to move from on-premise to cloud-based IT; Vertical cloud specialization, tailoring features and architectures to specific applications, industries, and customer ecosystems

More Events »

Subscribe to Newsletter

  • Keep up with all of the latest news and analysis on the fast-moving IT industry with Network Computing newsletters.
Sign Up
Column
 
Legal Eagle: Wanna Buy the Brooklyn Bridge?

  December 1, 2002
 


TOC Issue TOC
Printer Print this article
E-Mail E-Mail this URL
flame author Flame the author

What if a vendor tried to sell you a piece of "industry-compliant" software it claims provides secure standards-based transaction processing, digital signatures and privacy controls that allay customer concerns and keep the government at bay? Better yet, what if a vendor tried to sell you a 1U appliance with the same features? You'd think the vendor was peddling some panacea for Web services running on Linux, right? Still, you'd probably ask what business problems the product solves and what standards it supports. You might even demand to know what the vendor means by industry-compliant.


Now, what if a vendor tried to sell you hardware or software it claims is "HIPAA (Health Insurance Portability and Accountability Act)-compliant"? You could ask a truckload of questions but you wouldn't like the answers: There's no such thing as an HIPAA-compliant product, at least not yet.

HIPAA (aka Public Law 104-191) is a federal law intended to combat fraud and abuse in health care, standardize health-care transactions and implement privacy controls on patient records. It applies to all health-care providers that conduct electronic transactions for health claims and related information, such as eligibility and enrollment in health plans, payment and remittance advice, claim status and benefits coordination, and to clearinghouses that process such transactions. It covers all private sector health plans, including HMO and ERISA (Employee Retirement Income Security Act) plans, as well as government health plans such as Medicare and Medicaid. Small, self-administered health-care providers are excluded from HIPAA, but it's difficult for them to ignore a law that's destined to have such a tremendous impact on their industry.

HIPAA includes more than 70,000 words: Title I is designed to ensure ongoing health coverage for people who lose or change jobs; Title II is designed to simplify and improve health-care administration by encouraging the electronic interchange of health-care data. The law also requires the Department of Health and Human Services to establish national standards for health-care- provider identifiers, security and electronic signatures, transaction code sets for health claims, and privacy of individually identifiable health information, such as patient records.

But while the rules for privacy in patient records and transaction code sets for health claims have been finalized and are scheduled for implementation in April and October 2003, respectively, the rules for provider identifiers and security and electronic signatures are still in the proposal stages.

How, then, can PoliVec claim that PoliVec Builder walks you through an entire HIPAA-compliant security scheme? How can Medinex Systems bill MxMail as an HIPAA secure electronic messaging system for hospitals? And how can Blue Ridge Networks boast that HIPAAGuard is the first network to exceed all federal requirements for secure electronic health-care transactions? These products may comply with some parts of HIPAA, but they are far from comprehensive solutions.

Take just the privacy rules that will go into effect April 14. They require health providers and clearinghouses to inform patients of their privacy rights and how their personal data is used; adopt clear privacy procedures and implement them in their practices, hospitals or plans; train employees to understand the privacy procedures; designate an individual to oversee the adoption and implementation of those privacy procedures; and secure patient records that contain individually identifiable health information so those records can't be accessed by anyone inappropriate. Granted, authentication and encryption schemes may provide secure access to patient records. But secure access is only one aspect of one rule under the big HIPAA umbrella.

So don't buy into the HIPAA hype. Don't take any wooden nickels and don't buy any bridges, either.

Sean Doherty

Best of the Web

Data deduplication: Declawing the clones

Data deduplication is emerging as a critically important new arrow in the storage administrator's quiver to answer hard questions about the increasing problem in storage growth costs.

Quick Read

Compression, Encryption, Deduplication, and Replication: Strange Bedfellows

One of the great ironies of storage technology is the inverse relationship between efficiency and security: Adding performance or reducing storage requirements almost always results in reducing the confidentiality, integrity, or availability of a system.

Quick Read

WAN Optimization Whitelists and Blacklists

Optimization is a fantastic way of saving money and creating really happy customers at the same time, but it doesn't work flawlessly for all applications.

Quick Read

WAN Optimization as a Managed Service: It's Not About the Cost

This insight examines how organizations outsourcing their WAN optimization initiatives to a third-party go about achieving their goals for application performance, reducing operational costs, and streamlining enterprise infrastructure.

Quick Read

  Sponsored Links

Premium Content

Next Generation Data Center, Delivered, November 17th
NWC


Salary

Video