Study: Providers Come Up Short on HIPAA Privacy Compliance

Study: Providers Come Up Short on HIPAA Privacy Compliance

Written By
M.L. Baker
M.L. Baker
Apr 14, 2005
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Most health care providers are mostly compliant with the privacy rule of the Health Insurance Portability and Accountability Act, but fewer than half of them are fully compliant, according to a survey released Monday by the American Health Information Management Association. The deadline for compliance passed about two years ago.

At a public teleconference Wednesday, CMS (Centers for Medicare & Medicaid Services) officials said enforcement would be “complaint-driven” and that they generally expected to work with entities covered by HIPAA to obtain compliance when complaints were filed.

On the other hand, the 40 percent of fully compliant institutions is almost twice the 23 percent that reported being compliant a year ago.

For the upcoming HIPAA security deadline, three-fifths of institutions rated themselves as 85 percent or more compliant, and 12 percent said they were less than 50 percent compliant.

However, the AHIMA survey (PDF file) was conducted in January, and commentary accompanying the survey said these figures were “not surprising.”

Mervat Abdelhak, president of the American Health Information Management Association, said the level of compliance was encouraging, but stressed that “privacy and security are ongoing issues that require continued commitment and fine-tuning and cant be forgotten beyond initial compliance.”

A smaller survey, conducted in January by HIMSS (Healthcare Information Management and Systems Society) and Phoenix Health Systems came to more alarming conclusions: “This development raises a flag of concern–how can patient privacy be preserved and the use of electronic transactions proliferate without adequate hardware and software security protections?”

The HIMSS survey of 318 professionals at health care providers and 82 payers found that security compliance had improved since June 2004, but that the number of organizations that expect to be compliant by the deadline had declined since then. In June, 87 percent of providers and 91 percent of payers thought they would be compliant. By January, those figures had fallen to 74 percent and 80 percent, respectively.

But Don Rode, AHIMAs vice president of policy and government relations, was much less worried. “Any organization thats doing a decent job on its privacy side is probably doing OK because security is a subset of privacy.”

Part of the calm is that the government has made known that it will not actively seek out noncomplying institutions unless someone files a complaint. Even then, Rode said the government would be inclined to consider the context if a breach had occurred.

“Theyd be looking to see how you handled the situation and what youre doing to fix it. Its not an adversary situation, its a good-faith attempt to get things working right.” He said the government would rather prosecute deliberate and flagrant violations.

/zimages/6/28571.gifRead the full story on CIOInsight.com: Study: Providers Come Up Short on HIPAA Privacy Compliance

/zimages/6/28571.gifCheck out eWEEK.coms for the latest news, views and analysis of technologys impact on health care.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.