HIPAA Security Implementation, Version 1.0

5.4 ENFORCEMENT RULE

The Department of Health and Human Services expects that most covered entities will voluntarily comply with the HIPAA rule and correct all violations as soon as they are made aware of the violation. When compliance is not voluntary, the Office for Civil Rights and the Center for Medicaid and Medicare Services will follow the Office of Inspector General's (OIG) procedures to enforce regulatory compliance. This decision is made based on the level of experience the OIG has in regulatory compliance issues.

5.4.1 Process if Covered Entity Discovers Violation

5.4.2 Process if Individual Discovers Violation

Scenario One

Scenario Two

Scenario Three

These high-level overviews are for illustrative purposes only and should in no way be used by a covered entity to plan a course of action. The interim Enforcement Rule sets forth the discovery process, penalty implementation and collection process, and the authority vested to the Secretary of HHS under the HIPAA rule. Covered entities are encouraged to review this rule with their legal representative to decide how best to handle complaints when they cannot be satisfied through the organization's established complaint system. The text of the interim rule can be found at http://www.hhs.gov/ocr/moneypenalties.html

Категории