On May 16, the Office of Inspector General (OIG) of the Department of Health and Human Services (HHS) issued two reports critical of the government’s efforts to build and enforce a federal information security framework for protecting individuals’ electronic protected health information (ePHI).  Of particular interest to health care providers and health plans, these reports signal that heightened enforcement efforts appear likely in the future, making information security a top priority when developing and operating interoperable health care information technology (HIT).

The first OIG report, which assessed the Centers for Medicare and Medicaid Services’  (CMS’) and Office of Civil Rights’  (OCR’s) oversight of the Security Standards under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), found shortcomings in hospital information security implementation, and criticized a perceived lack of effective of oversight of such Security Standards by CMS and OCR.  The OIG audit examined information security systems at seven large hospitals located in several states.  The report found 151 security vulnerabilities, ranging from insufficient password strength and unencrypted laptops containing ePHI, to lack of physical protections (e.g., locks) for computer storage rooms, inadequate encryption methods, and incomplete policies and procedures to address audit controls, backup plans and disaster contingencies.  The majority of findings were rated as “high impact”, which means posing a significant risk of harm to the individuals whose ePHI was transmitted or stored in such facilities.  The report concluded that the OCR needs to significantly improve oversight and enforcement of data security under HIPAA, including continuation of the compliance oversight reviews of covered entities begun in 2009 at the direction of CMS.  The OIG report also referred to exercise of the specific HIPAA enforcement measures and larger penalties enacted under the 2009 American Recovery and Reinvestment Act’s Health Information Technology for Economic and Clinical Health Act (HITECH) provisions.

The second OIG report criticized the Office of the National Coordinator for Health Information Technology (ONC), the agency created under ARRA/HITECH to administer and oversee federal incentives for the adoption and meaningful use of interoperable electronic health records (EHRs), and other related national HIT initiatives.  That report found that the ONC failed to incorporate general information security requirements in the measures required for certified EHRs under HITECH.  While certain application security controls were included in the HIT standards, the OIG found that general security requirements for the overall security structure, policies and procedures to be specifically applied to EHR systems, were lacking.

In light of these OIG reports, and of ongoing news of misappropriation of patients’ health information and wide-scale security breaches, health care providers and health plans should consider reassessing their security risk exposure and preparedness to address information security lapses and HIPAA enforcement likely to be at the forefront of the national HIT trend.

Photo of John Mulhollan John Mulhollan

John Mulhollan has actively served a variety of business and healthcare clients in Ohio and California, with a particular emphasis on the healthcare industry, for nearly ten years.

Mr. Mulhollan has experience counseling clients in a variety of substantive areas, including healthcare transactions…

John Mulhollan has actively served a variety of business and healthcare clients in Ohio and California, with a particular emphasis on the healthcare industry, for nearly ten years.

Mr. Mulhollan has experience counseling clients in a variety of substantive areas, including healthcare transactions and contractual negotiations involving Medicare and Medicaid fraud and abuse compliance, physician referral compliance under the Stark law and professional and facility licensing. He has assisted both nonprofit and for-profit clients with legal analysis and documentation of healthcare private offerings, joint venture agreements, leases and corporate governance matters in connection with complex transactions. Focused on providing sound, yet practical, advice, Mr. Mulhollan strives to understand and promote each client’s healthcare mission by providing legally compliant solutions to the challenges of today’s complex healthcare environment.

Mr. Mulhollan has represented large and small healthcare providers such as healthcare systems, individual hospitals and clinics, as well as physicians and ancillary healthcare businesses. The complex transactions he has handled range from single contractual services arrangements to large healthcare mergers and acquisitions. Examples include the acquisition of a county-owned community hospital by a nonprofit health system, shareholder relations and combinations with respect to private physician practices, and compliance and documentation support for a variety of healthcare ventures involving ambulatory surgery, diagnostic imaging and laboratory services. In addition to providing thorough legal analysis of business issues, Mr. Mulhollan is able to guide clients through complex issues ranging from Medicare/Medicaid certification, change of ownership and reimbursement implications of such transactions to detailed analysis and preparation of professional and vendor services agreements. He also provides guidance and support in the areas of operational restructuring of provider, supplier and medical group operations, including the expansion or contraction of services, outsourcing, marketing and development compliance and complex facility and vendor relationships.

Mr. Mulhollan has advised clients on a variety of organizational compliance efforts, including fraud and abuse and Stark law compliance and corporate policy development. He advises clients on physician professional services and on-call arrangements, medical director agreements, physician recruitment, graduate medical education and medical office leasing. Mr. Mulhollan has advised both healthcare and business clients on implementing the many requirements and compliance issues arising under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), as well as compliance with state medical privacy and professional licensing laws.

In addition, Mr. Mulhollan’s business practice includes general business advice to healthcare and non-healthcare clients, including mergers and acquisitions, governance, shareholder transactions, professional entity formation and compliance with government regulations.

Mr. Mulhollan is a member of the American, Ohio and Cleveland Metropolitan (Health Law Section) Bar Associations, as well as the American Health Lawyers Association.