The House of Representativesunanimously passed a bill Tuesday, Oct. 20, that would exempt providers with fewer than 20 employees from complying with the FTC’s identity theft Red Flags Rule.
This certainly opens the door for a major sector of the healthcare provider market to not notifying individuals of potential identity theft as it relates to personal information.
One saving grace is that this employee number threshold doesn’t exist within the new HITECH Act requirements as they apply to covered entities.
A remaining development to be seen is whether the “harm threshold” will be eliminated. If not, this could provide another obstacle in patients learning about possible breaches give that the covered entity may deem the breach of such a nature that a notification is not required.
This certainly opens the door for a major sector of the healthcare provider market to not notifying individuals of potential identity theft as it relates to personal information.
One saving grace is that this employee number threshold doesn’t exist within the new HITECH Act requirements as they apply to covered entities.
A remaining development to be seen is whether the “harm threshold” will be eliminated. If not, this could provide another obstacle in patients learning about possible breaches give that the covered entity may deem the breach of such a nature that a notification is not required.
Very interesting to see how this will play out.
Frank