Privacy Breach Rules Require Practices To Report Only Harm Done
Physicians won't have to notify patients of every breach of privacy regarding their records, under a rule finalized by the Dept. of Health and Human Services. Two consumer groups, Consumer Watchdog and the Center for Democracy and
Technology, argue that placing the onus on a breached organization to
determine the level of risk and whether notification is necessary is
not good policy. "In other words, the company responsible for protecting the sensitive
data gets to decide if it needs to bother to tell anyone that sensitive
health data was breached. This is simply outrageous," wrote John
Simpson, who drafted Consumer Watchdog's letter to Sebelius.
