1 min read

HIPAA Privacy Rule revised under Hurricane Harvey

Digital privacy concept with code and encryption symbols

In response to Hurricane Harvey, the secretary of the U.S. Department of Health and Human Services (HHS), Tom Price, M.D., declared a public health emergency in Texas and Louisiana. Along with the declaration, he exercised his authority to waive sanctions and penalties against a Texas or Louisiana covered hospital that does not comply with certain provisions of the HIPAA Privacy Rule.

 

Changes to HIPAA's Privacy Rule under extreme circumstances

 

The following provisions of HIPAA's Privacy Rule has been waived for Texas or Louisiana covered hospitals:

 

  • The requirements to obtain a patient's agreement to speak with family members or friends involved in the patient’s care
  • The requirement to honor a request to opt out of the facility directory
  • The requirement to distribute a notice of privacy practices
  • The patient's right to request privacy restrictions
  • The patient's right to request confidential communications

 

Other provisions of the Privacy Rule continue to apply, even during the waiver period.

When the Secretary issues such a waiver, it only applies:

  1. In the emergency area and for the emergency period identified in the public health emergency declaration
  2. To hospitals that have instituted a disaster protocol
  3. With respect to the provisions identified above
  4. For up to 72 hours from the time the hospital implements its disaster protocol

What happens when the waiver declaration ends?

 

When the President's or Secretary's declaration terminates, a hospital must then comply with all the requirements of the Privacy Rule for any patient still under its care, even if 72 hours have not elapsed since implementation of its disaster protocol. All other provisions of the HIPAA regulations, including the Security Rule and the Breach Notification Rule, remain in effect. As emergency personnel and medical facilities undertake immediate action to ensure the safety of those affected, the OCR continues to highlight how the HIPAA Privacy Rule allows patient information to be shared to assist in disaster relief efforts and to assist patients in receiving the care they need, regardless of whether a waiver is granted. For more detailed information regarding HIPAA privacy and disclosures in emergency situations, click here. For more detailed information regarding emergency situation preparedness, planning, and response, click here. To utilize the Disclosures for Emergency Preparedness Decision Tool, click here. Please view the Civil Rights Emergency Preparedness page to learn how nondiscrimination laws apply during an emergency.

 

Try Paubox Email Suite for FREE today.
Microscopic illustration of virus particles with spike proteins

HHS declares limited waiver of HIPAA sanctions due to COVID-19

The Secretary of the U.S. Department of Health and Human Services (HHS) has issued a limited waiver of HIPAA sanctions and penalties due to the...

Read More
Healthcare worker in protective gear conducting medical testing

The HIPAA Privacy Rule during public health emergencies

According to HIPAA and Disasters: What Emergency Professionals Need to Know, “The HIPAA Privacy Rule is not suspended during a public health or other...

Read More
Tornado touching down over a rural landscape

Is HIPAA waived during natural disasters?

HIPAA is not waived during natural disasters, and healthcare organizations must still comply with HIPAA regulations.

Read More

Subscribe to Paubox Weekly

Every Friday we bring you the most important news from Paubox. Our aim is to make you smarter, faster.