Physicians have new duties to protect patients’ protected health information (“PHI”) under the Health Information Technology for Economic and Clinical Health Act (the "HITECH ACT").
The HITECH Act requires physicians, as well as hospitals and insurance companies, to notify patients, the Department of Health and Human Services, and in some cases the news media of security breaches involving “unsecured” PHI.
“Unsecured” PHI means PHI that is usable, readable or decipherable by unauthorized individuals, for example, unencrypted electronic PHI.
A security breach is the unauthorized acquisition, access, use, or disclosure of PHI that compromises its security or privacy and poses a significant risk of financial, reputational, or other harm to the patient.
When PHI is accessed, acquired, or disclosed for a purpose authorized by law, e.