Bill Would Fix Privacy Loophole
December 20, 2007
Jim Jacobson, co-chair of Holland & Knight's Health Law & Life Sciences Team, is quoted on the impact of a new bill on health services companies covered by HIPAA.
The Personal Data Privacy and Security Act of 2007 would require customer notification of data security breaches and establish penalties and the creation of an Office of Federal Identity Protection.
"Within the scope of the information that the Act is trying to cover, there is no mention of personal health information, genetic information or medical records,” Jacobson said. “It seems that companies covered by HIPAA are required to report a breach, but only when it comes to specific personally identifiable information. Also, they would not be exempt from the criminal penalties for fraudulent actions.”