<?xml version="1.0" encoding="utf-8"?>
	<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
	<title>An RSS Feed from melniklegal.com</title>
<description>melniklegal.com Blog</description>
<link>http://melniklegal.com/programs/weblog.cgi</link>
<category>e-commerce</category>
<copyright>Copyright melniklegal.com </copyright>
<language>en-us</language>
<lastBuildDate>Wed, 05 Aug 2026 20:05:47 EST</lastBuildDate>
<managingEditor>tatiana@melniklegal.com (Web Master)</managingEditor>
<pubDate>Wed, 05 Aug 2026 20:05:47 EST</pubDate>
<webMaster>tatiana@melniklegal.com (Tatiana)</webMaster>
<generator>e-commerce-inc.com sitebuilder blog press</generator>
<atom:link href="http://melniklegal.com/programs/blogrss.cgi" rel="self" type="application/rss+xml" />

			
<item>
<title><![CDATA[Does the HIPAA Security Rule Require Use of a Certain Operating System?]]></title>
<description><![CDATA[
 
 
 
 
   <div align="left"><font face="Arial"><font size="3">With the pending sunset for Windows XP support on April 8, 2014, many have started asking the question of whether the HIPAA Security Rule requires use of a certain operating system to be compliant. <br><br>The Department of Health and Human Services has addressed this issue in a FAQ answer:<br></font></font><blockquote><b><font face="Arial"><font size="3">Does the Security Rule mandate minimum operating system requirements for the personal computer systems used by a covered entity?</font></font></b><br><font face="Arial"><font size="3"><br></font></font><font face="Arial"><font size="3"><b>No.</b> The Security Rule was written to allow flexibility for covered entities to implement security measures that best fit their organizational needs. <b>The Security Rule does not specify minimum requirements for personal computer operating systems, but it does mandate requirements for information systems that contain electronic protected health information (e-PHI).</b> Therefore, as part of the information system, the security capabilities of the operating system may be used to comply with technical safeguards standards and implementation specifications such as audit controls, unique user identification, integrity, person or entity authentication, or transmission security.&nbsp; Additionally, <b>any known security vulnerabilities of an operating system should be considered in the covered entity’s risk analysis</b> (e.g., does an operating system include known vulnerabilities for which a security patch is unavailable, e.g., because the operating system is no longer supported by its manufacturer).</font></font><br></blockquote><font face="Arial"><font size="3"><i>See </i><a href="https://www.hhs.gov/ocr/privacy/hipaa/faq/securityrule/2014.html">https://www.hhs.gov/ocr/privacy/hipaa/faq/securityrule/2014.html</a>.<br><br></font></font><font face="Arial"><font size="3"><font face="Arial"><font size="3">The sunset means that Microsoft will no longer be providing new security updates, non-security hotfixes, free or paid assisted support options, or online technical content updates for Windows XP. But, the sunset dates are different for Windows Embedded Products that are based on the Windows XP OS.</font></font> As Microsoft explained in a recent blog post:<br></font></font><blockquote><font face="Arial"><font size="3">Windows Embedded products have their own distinct support lifecycles, based on when the product was released and made generally available. It is important for enterprises to understand the support implications for these products in order to ensure that systems remain up to date and secure. The following Windows Embedded products are based on Windows XP:</font></font><br><br><ul><li><font face="Arial"><font size="3">Windows XP Professional for Embedded Systems. This product is identical to Windows XP, and <b>Extended Support will end on April 8, 2014</b>.</font></font></li></ul><ul><li><font face="Arial"><font size="3">Windows XP Embedded Service Pack 3 (SP3). This is the original toolkit and componentized version of Windows XP. It was originally released in 2002, and <b>Extended Support will end on Jan. 12, 2016</b>.</font></font></li></ul><ul><li><font face="Arial"><font size="3">Windows Embedded for Point of Service SP3. This product is for use in Point of Sale devices. It’s built from Windows XP Embedded. It was originally released in 2005, and <b>Extended Support will end on April 12, 2016</b>.</font></font></li></ul><ul><li><font face="Arial"><font size="3">Windows Embedded Standard 2009. This product is an updated release of the toolkit and componentized version of Windows XP. It was originally released in 2008; and <b>Extended Support will end on Jan. 8, 2019</b>.</font></font></li></ul><ul><li><font face="Arial"><font size="3">Windows Embedded POSReady 2009. This product for point-of-sale devices reflects the updates available in Windows Embedded Standard 2009. It was originally released in 2009, and <b>Extended Support will end on April 9, 2019</b>.</font></font></li></ul></blockquote><font face="Arial"><font size="3"><i>See</i><a href=" https://blogs.msdn.com/b/windows-embedded/archive/2014/02/17/what-does-the-end-of-support-of-windows-xp-mean-for-windows-embedded.aspx"> https://blogs.msdn.com/b/windows-embedded/archive/2014/02/17/what-does-the-end-of-support-of-windows-xp-mean-for-windows-embedded.aspx.<br></a></font></font></div><a href=" https://blogs.msdn.com/b/windows-embedded/archive/2014/02/17/what-does-the-end-of-support-of-windows-xp-mean-for-windows-embedded.aspx"> </a><table style="border: 0px solid red;"><tbody><tr><td><br></td></tr></tbody></table> <br><font face="Arial"><br><br></font><table style="border: 1px solid red;"><tbody><tr><td><table border="0"><tbody><tr style="font-family: Arial;" align="center"><td><div style="text-align: left;" align="left"><font face="Arial" size="2">This FAQ post, and the information on this website, has been prepared for general information purposes only. The information on this website is not legal advice. Legal advice is dependent upon the specific circumstances of each situation and the jurisdiction of each state. The information contained here is not guaranteed to be up to date. Please consult legal counsel in your state to discuss your specific circumstances.</font></div><font size="3"></font></td></tr> </tbody></table></td></tr></tbody></table> <br>     
 
 
 
 
 
 ]]></description>
<link>http://melniklegal.com/weblog/1392823042_FAQ.html</link>
<guid>http://melniklegal.com/weblog/1392823042_FAQ.html</guid>
<pubDate>Wed, 19 Feb 2014 10:17:22 EST</pubDate>
</item>
			
			
			
<item>
<title><![CDATA[Throwing Medical Records into a Recycling Container is Not Proper Disposal]]></title>
<description><![CDATA[
 
 
 
 
     <div align="left"><div><table border="0"><tbody><tr><td align="left" valign="top"><font face="Arial"><img src="https://melniklegal.com/images/no_phi_in_recycle.png"><br></font></td><td align="left" valign="top"><font face="Arial"><i><b>Oregon Fines a Medical Clinic for Violating the State's ID Theft Law</b></i> - The Oregon Department of Consumer and Business Services announced on November 1, 2013 that it fined Samaritan Health Services, Inc., a regional health system, $5,000 (reduced to $1,000) for violating Oregon's identity theft law by improperly discarding business records and patient files with patient names and social security numbers. A patient discovered approximately 1,222 patient files in an unlocked recycling container outside of Samaritan's Family Medicine Clinic in Corvallis, Oregon in July 2013. Of the 1,222 about 20 files included patient names and unredacted social security numbers. [1] The Oregon Department learned of the incident from the press. [2]<br></font></td></tr></tbody></table><font face="Arial"><br><a href="#few">[Jump to Take-a-Ways]</a><br><br></font><div><font face="Arial">Samaritan "operates a non-profit network of hospitals, physician clinics, health plans, and senior care facilities in Albany, Corvallis, Lebanon, Lincoln City, Newport, and Sweet Home, Oregon." [3]<br><br>The action was based on the Oregon Consumer Identity Theft Protection Act (ORS 646A.600) ("ID Theft Law"), which, among other things, requires companies to notify consumers in the event of a data breach,&nbsp; permits impacted consumers to put a security freeze on their credit report, prohibits companies from printing and otherwise displaying social security numbers, and requires companies to develop, implement and maintain reasonable safeguards to protect personally identifiable information. The Act also provides that violators may be subject to a civil penalty of not more than $1,000 for <i>every</i> violation.<br><br>Samaritan was charged with violating several sections of the ID Theft Law for improper disposal of the records and ordered to pay a civil penalty of $5,000 "for publicly posting, displaying or otherwise making available to the public, files bearing consumer names and unredacted Social Security numbers in violation of ORS 646A.620 (1)(c)." [4]<br><br>But, Patrick M. Allen, Director of the Department, agreed to suspend $4,000 of the $5,000 penalty provided that Samaritan "complies with all terms and conditions set out in this Consent Order and commits no new violations of the Identity Theft law, ORS chapter 646A, or Oregon Administrative Rules chapter 441, division 646" for <u><b>five years</b></u>.<br></font></div><font face="Arial"><br><br></font><div><div><font face="Arial"><b><a name="few">Take-a-Ways</a>...</b><br></font></div><div><ul><li><font face="Arial">The Oregon action serves to remind healthcare providers and those that manage protected health information (PHI) that, when disposing of records containing patient data, they must comply with both HIPAA and state data disposal laws. As of December 2013, at least 30 states have enacted laws setting forth disposal requirements for business records that contain personally identifying information. [5]</font></li></ul><ul><li><font face="Arial">The Oregon Consumer Identity Theft Protection Act may be changing. Oregon House Bill 3411 proposed changes to a number of the sections including section 646A.622, which addresses the requirement to develop safeguards for personal information. But, entities subject to HIPAA and the Gramm-Leach-Bliley Act are deemed to comply with section 646A.622 of the Oregon Act if they comply with the respective federal regulations. [6]</font></li></ul><ul><li><font face="Arial">Identity theft continues to be of great concern to both state and federal regulators and this concern tends to drive enforcement activity. Healthcare providers and group practices are particularly attractive targets to thieves and fraudsters because these companies have access to a lot of personally identifying information (e.g., names, phone numbers, social security numbers, credit card numbers, etc.) and may not have the proper security measures in place. Providers should be particularly cognizant of these concerns and take appropriate steps to minimize risks to their patients. Proof of identity theft often fulfills the damages requirement in a data breach class action.<br></font></li></ul><ul><li><font face="Arial">Training workforce members on the proper handling and disposal of patient records must be an ongoing effort. As of December 31, 2013, two of the top complaints received by the Office of Civil Rights, the federal enforcer of HIPAA, is impermissible uses and disclosures of PHI and lack of PHI safeguards. [7]</font></li></ul><ul><li><font face="Arial">For many people, a report to the press is the first stop. Negative publicity can cause great damage the goodwill and the bottom line of an organization. Moreover, as clear from this incident, state regulators are paying attention to press reports. The Office of Civil Rights pays attention as well. For example, OCR entered into a settlement agreement with Shasta Regional Medical Center for $275,000 after OCR learned from media reports that senior leaders at the company met with members of the press to discuss medical services provided to a patient. "When senior level executives intentionally and repeatedly violate HIPAA by disclosing identifiable patient information, OCR will respond quickly and decisively to stop such behavior," said OCR Director Leon Rodriguez. [8]<br></font></li></ul></div></div></div><font face="Arial"><br></font><div><font face="Arial">------------------<br><font size="2">[1] <i>In re</i> Samaritan Health Services, Oregon Department of Consumer and Business, Division of Finance and Corporate Securities, <a href="https://melniklegal.com/av/2014_Oregon_Consent_Decree.pdf">Consent Order No. 13-0570</a> (11/1/13) [hereinafter Consent Order].</font><br><br><font size="2">[2] Bloomberg BNA Health Law Resource Center, Oregon Regulator Fines Health System</font><br><font size="2">After Records Discovered in Recycling Bin, 22 HLR 1674 (Nov. 5, 2013) ("Diane Childs, a spokeswoman for the Division of Finance and Corporate Securities, told Bloomberg BNA Nov. 5 that the agency found out about the breach through an article in a local newspaper.")</font><br><br><font size="2">[3] Consent Order at para. 1.</font><br><br><font size="2">[4] Id. at para. 10.</font><br><br><font size="2">[5] A list may be obtained from the National Conference of State Legislatures, <a href="https://www.ncsl.org/research/telecommunications-and-information-technology/data-disposal-laws.aspx">https://www.ncsl.org/research/telecommunications-and-information-technology/data-disposal-laws.aspx</a> (last visited Jan. 14, 2014). </font><br><br><font size="2">[6] <a href="https://melniklegal.com/av/Oregon_House_Bill_3411.pdf">77th Oregon Legislative Assembly, 2013 Regular Session, House Bill 3411</a> (Sponsored by Representative Gomberg, Representatives Boone, Gallegos, Lovely, and Senator Roblan.</font><br><br><font size="2">[7] Office of Civil Rights, <a href="https://www.hhs.gov/ocr/privacy/hipaa/enforcement/highlights/">https://www.hhs.gov/ocr/privacy/hipaa/enforcement/highlights/</a> (last visited Jan. 14, 2014).<br><br>[8] Press Release, Office of Civil Rights, HHS Requires California Medical Center to Protect Patients’ Right to Privacy, June 13, 2013, <a href="https://www.hhs.gov/ocr/privacy/hipaa/enforcement/examples/shasta-agreement-press-release.html">https://www.hhs.gov/ocr/privacy/hipaa/enforcement/examples/shasta-agreement-press-release.html</a>.</font><br></font></div></div><font face="Arial"> </font>    
 
 
 
 
 
 ]]></description>
<link>http://melniklegal.com/weblog/1389717685_Data-Breach.html</link>
<guid>http://melniklegal.com/weblog/1389717685_Data-Breach.html</guid>
<pubDate>Tue, 14 Jan 2014 11:41:25 EST</pubDate>
</item>
			
			
			
<item>
<title><![CDATA[Telemedicine is Coming to Florida (Slowly but Surely)]]></title>
<description><![CDATA[
 
 
 
 
   <div align="left"><font face="Arial"><i><b>The Florida Boards of Medicine and Osteopathic Medicine are Moving Closer to Proposing a Rule on Standards for Telemedicine Practice. </b></i><br><br>In a joint meeting of the Florida Boards of Medicine and Osteopathic Medicine on November 14, 2013, the Telemedicine Subcommittee moved closer to proposing a rule aimed at setting the standards for telemedicine practice in Florida.</font><br><br><font face="Arial">The Telemedicine Subcommittee was established during the August 2013 Board of Medicine meeting to address Florida's growing telemedicine field. The Subcommittee is comprised of six Board of Medicine members and three Board of Osteopathic Medicine members.<a href="#one">[1]</a> </font><br><br><font face="Arial">The current telemedicine rule for each of the Florida Board of Medicine and Osteopathic Medicine is limited to Internet prescribing.<a href="#two">[2]</a> But, as Dr. Orr, the Chair of the Telemedicine Subcommittee, explained during the first meeting on September 9, 2013, the Subcommittee's goal is to examine current uses of telemedicine and to amend the Board's rules to address the use of telemedicine <a href="#three">[3]</a> in a more comprehensive manner.</font><br><br><font face="Arial">The Subcommittee has proposed to define telemedicine as "the practice of medicine by a licensed Florida physician or physician assistant where patient care, treatment, or services are provided through the use of medical information exchanged from one site to another via electronic communications. Telemedicine shall not include the provision of health care services only through an audio only telephone, email messages, text messages, facsimile transmission, U.S. Mail or other parcel service, or any combination thereof." <a href="#four">[4]</a></font><br><br><font face="Arial">Additionally, "[t]he standard of care, as defined in s. 456.50(1)(e), F.S., shall remain the same regardless of whether a Florida licensed physician or physician assistant provides health care services in person or by telemedicine." <a href="#five">[5]</a></font><br><br><font face="Arial">Some members of the public expressed concern during the November 14 meeting that the proposed rule did not provide adequate clarity that use of telemedicine would be subject to compliance with HIPAA and other data privacy and security requirements similar to in-person patient encounters.&nbsp; But, the subcommittee expressed concerns regarding including an express reference to HIPAA because of Florida's requirements with respect to incorporating other statutes and regulations. That is, under Florida law, a Board may incorporate only the current version of a federal regulation or statute. So, when that regulation or statute changes, the Board must convene to incorporate the new version. This may be problematic if a particular regulation or statute is routine modified. </font><br><br><font face="Arial">However, the Subcommittee agreed that language should be added to clarify obligations with respect to patient confidentiality and proposed language that, "[t]he practice of medicine by telemedicine does not alter any obligation of the physician or the physician assistant regarding patient confidentiality or recordkeeping."</font><br><br><font face="Arial">One issue that was raised, but not yet addressed, is whether Florida will permit out of state doctors to treat Florida patients via telemedicine. That is, several other states do have limited telemedicine licenses.&nbsp; Texas, for example, provides that:</font><br><blockquote><font face="Arial">(a) For a person to be eligible for an out-of-state telemedicine license to practice medicine across state lines under the Medical Practice Act, §151.056, and §163.1 of this title (relating to Definitions), the person must: <br>&nbsp; (1) be 21 years of age or older; <br>&nbsp; (2) be actively licensed to practice medicine in another state which is recognized by the board for purposes of licensure, and not the recipient of a previous disciplinary action by any other state or jurisdiction; <br>&nbsp; (3) not be the subject of a pending investigation by a state medical board or another state or federal agency; <br>&nbsp; (4) be currently certified by a member board of the American Board of Medical Specialties or Bureau of Osteopathic Specialists, or by the American Board of Oral and Maxillofacial Surgery, obtained by passing, within the ten years prior to date of applying for licensure, a monitored:&nbsp; (A) specialty certification examination; (B) maintenance of certification examination; or (C) continuous certification examination; <br>&nbsp; (5) have passed the Texas Medical Jurisprudence Examination; <br>&nbsp; (6) complete a board-approved application for an out-of-state telemedicine license for the practice of medicine across state lines and submit the requisite initial fee; and <br>&nbsp; (7) not be determined ineligible for licensure under subsection (b) of this section.<br></font></blockquote><font face="Arial">Texas Administrative Code, 22-9-172(C) Rule §172.12.</font><br><br><font face="Arial">The Subcommittee advised that it would research the licensure issue and further discuss it at a later meeting.</font><br><br><font face="Arial">The Subcommittee made clear that it was eager to move quickly on developing telemedicine rule.</font><br><br><font face="Arial">Nonetheless, for now, reimbursement for telemedicine (or telehealth) services in Florida remains an issue because it is limited to a very narrow set of circumstances under the Medicaid program and no state law requires reimbursement by private insurers. </font><br><br><u><font face="Arial" size="2"><br>References and Resources</font></u><br><br><font face="Arial" size="2"><a name="one">[1]</a> Florida Board of Medicine, <a href="https://melniklegal.com/av/2013_Fl_Board_Medicine_Updates_on_Telemedicine_09252013.pdf">Newsletter: Updates on Telemedicine</a>, Sept. 25, 2013. (PDF)</font><font size="2"><br><br><font face="Arial"><a name="two">[2]</a><a> For Florida Board of Medicine, <i>see</i> Rule 64B8-9.014. <i>Standards for Telemedicine Prescribing Practice</i>. For Florida Board of Osteopathic Medicine, <i>see </i>Rule 64B15-14.008 <i>Standards for Telemedicine Practice</i>.</a></font><a><br><br><font face="Arial"></font></a><font face="Arial"><a name="three">[3]</a> Florida Board of Medicine, <a href="https://ww10.doh.state.fl.us/pub/medicine/Agenda_Info/Public_Information/Public_Minutes/September2013/09092013_TeleMed_Minutes.pdf">Joint Meeting of the Florida Boards of Medicine &amp; Osteopathic</a></font><br><font face="Arial"><a href="https://ww10.doh.state.fl.us/pub/medicine/Agenda_Info/Public_Information/Public_Minutes/September2013/09092013_TeleMed_Minutes.pdf">Medicine Telemedicine Subcommittee Meeting Report</a>, Sept. 9, 2013 (opening comments by Dr. Orr). (PDF)</font><br><br><font face="Arial"><a name="four">[4]</a> For a full record of the materials, see the <a href="https://ww10.doh.state.fl.us/pub/medicine/Agenda_Info/Public_Information/Public_Books/November2013/11142013_TelemedicineSubcommittee_AgendaBook.pdf">Public Book for the Nov. 14, 2013 Telemedicine Subcommittee Meeting</a>. (PDF). The Rules as proposed are <a href="https://melniklegal.com/av/2013_Pages_from_11142013_Telemed_PublicBook.pdf">Rule 64B8-9.0141 (Medicine) and Rule 64B15-14.0081 (Osteopathic Medicine) and are available here</a>. <i>See also</i> <a href="https://ww10.doh.state.fl.us/pub/medicine/Agenda_Info/Public_Information/Public_Books/September2013/09092013_Telemed_PublicBook.pdf">Telemedicine Subcommittee, Public Book</a>, Sept. 9, 2013 for the full materials and <a href="https://melniklegal.com/av/2013_Pages_from_09092013_Telemed_PublicBook.pdf">click here for the rules as proposed on Sept. 9</a>. (PDF)</font><br><br><font face="Arial"><a name="five">[5]</a> <a href="https://ww10.doh.state.fl.us/pub/medicine/Agenda_Info/Public_Information/Public_Books/November2013/11142013_TelemedicineSubcommittee_AgendaBook.pdf">Telemedicine Subcommittee, Public Book</a>, Nov. 14, 2013. (PDF)</font></font><br><br><br><br><br><br><font face="Arial"> </font></div>    
 
 
 
 
 
 ]]></description>
<link>http://melniklegal.com/weblog/1384531131_Telemedicine.html</link>
<guid>http://melniklegal.com/weblog/1384531131_Telemedicine.html</guid>
<pubDate>Fri, 15 Nov 2013 10:58:51 EST</pubDate>
</item>
			
			
			
<item>
<title><![CDATA[OCR Reminds Covered Entities to Choose Friends Carefully]]></title>
<description><![CDATA[
 
 
 
 
     <font face="Arial"> <i><b>Lack of Technical Controls Leads to Two Settlements with OCR for $4.8M.</b></i> <br><br>On May 8, 2014, the Office of Civil Rights (OCR) announced a settlement with New York and Presbyterian Hospital (NYP) and Columbia University (CU) involving allegation of violations of the HIPAA Privacy and Security Rules. Under the Resolution Agreements, NYP will pay $3 million and CU will pay $1.5 million to settle the investigations.<br></font><br><table style="text-align: left; margin-left: auto; margin-right: auto;" border="0"><tbody><tr><td style="border: 1px solid #edad27; padding:3px;" color="#FFFFFF" size="3" bgcolor="#001c31" valign="top"><font face="Arial"><font face="Arial"><font color="#FFCC00"><b><i>A few preliminary comments....</i> </b></font><font color="#FFFFFF">This settlement is a good reminder that covered entities, business associates, and subcontractors must choose their partners carefully. As more organizations implement data sharing agreements, form strategic healthcare IT partnerships (e.g., those involving big data, analytics, etc.), and otherwise store their data with vendors, data breach issues are inevitable. Healthcare providers and vendors must carefully review their agreements to ensure that each party bears the appropriate amount of risk. Provisions related to indemnification, limitation of liability, damages caps, and insurance requirements should be reviewed with special attention.</font></font></font><br></td></tr></tbody></table><br><font face="Arial">NYP and CU are separate covered entities, but have an affiliation - generally called New York Presbyterian Hospital/Columbia University Medical Center - where CU faculty members serve as attending physicians at NYP.&nbsp; Under this arrangement, "NYP and CU operate a shared data network and a shared network firewall that is administered by employees of both entities. The shared network links to NYP patient information systems containing ePHI."[1]<br><br>NYP and CU filed a joint breach report in September 27, 2010 (<b>yes, 2010</b> - compare that to the 2014 settlement date!) following notification that the information of 6,800 patients, including patient status, vital signs, medications, and laboratory results, was available online. Specifically, according to the OCR Press Release:<br></font><blockquote><font face="Arial">The investigation revealed that the breach was caused when a physician employed by CU who developed applications for both NYP and CU attempted to deactivate a personally-owned computer server on the network containing NYP patient ePHI.&nbsp; Because of a lack of technical safeguards, deactivation of the server resulted in ePHI being accessible on internet search engines.&nbsp; <b>The entities learned of the breach after receiving a complaint by an individual who found the ePHI of the individual's deceased partner, a former patient of NYP, on the internet</b>.</font></blockquote><font face="Arial">OCR notified each of the entities on November 5, 2010 that it would launching an investigation. According to the Resolution Agreement with each of the entities, the OCR found the following conduct problematic:<br><br></font><table style="border: 1px solid #000000;" cellpadding="5" cellspacing="5"><tbody><tr><td align="center" valign="top"><font face="Arial"><b>New York Presbyterian Hospital</b></font></td><td align="center" valign="top"><font face="Arial"><b>Columbia University Medical Center<br></b></font></td></tr><tr><td align="left" valign="top"><div align="left"><font face="Arial">a. NYP impermissibly disclosed the ePHI of 6,800 patients to Google and other Internet search engines when a computer server that had access to NYP ePHI information systems was errantly reconfigured.</font><br><br><font face="Arial">b. NYP failed to conduct an accurate and thorough risk analysis that incorporates all IT equipment, applications, and data systems utilizing ePHI.</font><br><br><font face="Arial">c. NYP failed to implement processes for assessing and monitoring all IT equipment, applications, and data systems that were linked to NYP patient databases prior to the breach incident, and failed to implement security measures sufficient to reduce the risks and vulnerabilities to its ePHI to a reasonable and appropriate level.</font><br><br><font face="Arial">d. NYP failed to implement appropriate policies and procedures for authorizing access to its NYP patient data bases, <u>and it failed to comply with its own policies on information access management</u>.<font size="2">[2] (emphasis added)<br><br></font></font><div align="left"><font face="Arial"><font color="#993399"><b>NYP settlement: $3 million</b></font>.<br></font></div></div><font face="Arial"></font></td><td align="left" valign="top"> <font face="Arial">a. CU failed to conduct an accurate, and thorough risk analysis that incorporates all IT equipment, applications and data systems utilizing ePHI, including the server accessing NYP-ePHI.<br><br>b. CU failed to implement processes for assessing and monitoring IT equipment, applications and data systems that were linked to NYP patient data bases prior to the breach incident and failed to implement security measures sufficient to reduce the risks of inappropriate disclosure to an acceptable level.<font size="2">[3]<br><br></font></font><font face="Arial"><font color="#993399"><b>CU settlement: $1.5 million</b></font>.</font></td></tr></tbody></table><font face="Arial"><br></font><font face="Arial"><font face="Arial">As is the usual course, each Resolution Agreement includes a Corrective Action Plan. Each of the parties must take the following steps:</font></font><br><font face="Arial"><font face="Arial"><br></font></font><table style="border: 1px solid #000000;" border="0" cellpadding="5" cellspacing="5"><tbody><tr><td align="center" valign="top"><font face="Arial"><b>New York Presbyterian Hospital</b></font></td><td align="center" valign="top"><font face="Arial"><b>Columbia University Medical Center<br></b></font></td></tr><tr><td align="left" valign="top"><font face="Arial"><b>Modify Existing Risk Analysis Process.</b><br>. . . NYP shall conduct a comprehensive and thorough risk analysis of security risks and vulnerabilities that incorporates all electronic equipment, data systems, and applications controlled, administered or owned by NYP, its workforce members, and affiliated staff that contains, stores, transmits or receives NYP ePHI. NYP shall develop a complete inventory of all electronic equipment, data systems, and applications that contain or store ePHI which will then be incorporated in its Risk Analysis. . . . <br><br><b>Develop and Implement a Risk Management Plan</b>.<br>Within ninety (90) calendar days of the completion of the Risk Analysis . . . , NYP shall develop an organization-wide risk management plan to address and mitigate any security risks and vulnerabilities found in its risk analysis. The plan shall include a process and timeline for implementation, evaluation, and revision. The plan shall be forwarded to HHS for its review . . . <br><br><b><br>Review and Revise Policies and Procedures on Information Access Management. </b><br>. . . NYP shall review, and to the extent necessary, revise its internal policies and procedures for authorizing access to NYP ePHI. The revised policies and procedures shall include a specific process to be followed by workforce members and affiliated staff for requesting authorization to access NYP ePHI (including criteria for granting such access), obtaining approval of such request, documenting such request, and conducting periodic monitoring of ePHI usage. NYP shall forward its policies and procedures for authorizing access to all NYP ePHI to HHS for its review . . . <br><b><br><br>Implement Process for Evaluating Environmental and Operational Changes.</b><br>. . . NYP shall develop a process to evaluate any environmental or operational changes that affect the security of NYP ePHI.<br><br><b>Review and Revise Policies and Procedures on Device and Media Controls.</b><br>. . . NYP shall review, and to the extent necessary, revise its policies and procedures related to the use of hardware and electronic media including, but not limited to laptops, servers, tablets, mobile phones, USB drives, external hard drives, DVDs and CDs that may be used to access, store, download, or transmit NYP ePHI. The revised policies shall identify criteria for the use of such hardware and electronic media and procedures for obtaining authorization for the use of personal devices and media that utilize NYP ePHI systems. The policies shall also address security responsibilities, including disposal and reuse of personal devices and media and regular compliance monitoring. NYP shall forward its policies and procedures to HHS for its review . . .<br><br><b>Develop an Enhanced Privacy and Security Awareness Training Program.</b><br>1. . . NYP shall augment its existing mandatory Health Information Privacy and Security Awareness Training Program (for workforce members and affiliated staff that have access to protected health information including ePHI, to train on the necessity and existence of prohibitions on the purchase, use or administration of computer equipment that accesses NYP ePHI, except under the explicit management of NYP IT personnel ("the Training Program"). As before, the Training Program shall also include general instruction on compliance with the HIPAA Privacy, Security, and Breach Notification Rules and NYP health information security policies and procedures, and shall also include training on new policies and procedures, if any, developed as required by . . . this CAP.<br><br>2. Under the Training Program, NYP shall provide training to all workforce members and affiliated staff as soon as possible but no later than one year of the Effective Date and yearly thereafter. Any workforce member or affiliated staff that commences working for NYP, or that are given access to ePHI, after the development of the Training Program shall be trained within thirty (30) calendar days of the commencement of their employment or affiliation with NYP.<br><br>3. Each individual who is required to attend training shall certify, in writing or in electronic form, that he or she has received the required training and the date training was received. NYP shall retain copies of such certifications for no less than six years following the date training was provided.<br><br>4. NYP shall review the Training Program, including all training materials developed as part of the program, annually, and, where appropriate, update the training to reflect changes in Federal law or HHS guidance, any issues discovered during audits or reviews, and any other relevant developments.</font><br></td><td align="left" valign="top"><b> </b><font face="Arial"><b>Conduct a thorough Risk Analysis.</b><br>. . . CU shall conduct a comprehensive and thorough risk analysis of security risks and vulnerabilities that incorporates all electronic equipment, data systems and applications controlled, administered or owned by CU, its workforce members that contains, stores, transmits or receives CU ePHI. CU shall develop a complete inventory of all electronic equipment, data systems, and applications that contain or store ePHI which will then be incorporated in its Risk Analysis. . . .<br><br><b><br>Develop and Implement a Risk Management Plan.</b><br>Within ninety (90) calendar days of completion of the Risk Analysis . . . , CU shall develop an organization-wide risk management plan to address and mitigate any security risks and vulnerabilities found in its risk analysis. The plan shall include a process and timeline for implementation, evaluation, and revision. The plan shall be forwarded to HHS for its review . . .<br><br><b>Review and Revise Policies and Procedures on Information Access Management.</b><br>. . . CU shall review and to the extent necessary revise its internal policies and procedures for authorizing access to CU ePHI. The revised policies and procedures shall include a process to be followed by workforce members for requesting authorization to access CU ePHI (including criteria for granting such access), obtaining approval of such request, documenting such request, and conducting periodic monitoring of ePHI usage. CU shall forward its policies and procedures for authorizing access to all CU ePHI to HHS for its review . . . <br><br><br><b>Compliance with Evaluation Standard.</b><br>. . . CU shall develop a process to evaluate any environmental or operational changes that affect the security of CU ePHI. <br><br><b><br>Review and Revise Policies and Procedures on Device and Media Controls.</b><br>. . . CU shall review and to the extent necessary, revise its policies and procedures related to the use of hardware and electronic media including, but not limited to laptops, servers, tablets, mobile phones, USB drives, external hard drives, DVDs and CDs that may be used to access, store, download or transmit CU ePHI. The revised policies shall identify criteria for the use of such hardware and electronic media and procedures for obtaining authorization for the use of personal devices and media that utilized CU ePHI systems. The policies shall also address security responsibilities, including disposal and reuse of personal devices and media and regular compliance monitoring. CU shall forward its policies and procedures to HHS for its review . . . <br><br><b>Develop a Privacy and Security Awareness Training Program.</b><br>1. . . . CU shall develop a mandatory Health Information Privacy and Security Awareness Training Program (the Training Program) for workforce members that have access to protected health information including ePHI. The Training Program shall include instruction on compliance with the HIPAA Privacy, Security, and Breach Notification Rules and CU health information security policies and procedures, and shall particularly include training on the policies and procedures developed as required by . . .&nbsp; this CAP.<br><br>2. Under the Training Program, CU shall provide training to all workforce members as soon as possible but no later than one year of the Effective Date and yearly thereafter. Any workforce member that commence working for CU after the development of the Training Program shall be trained within thirty (30) calendar days of the commencement of their employment with CU.<br><br>3. Each individual who is required to attend training shall certify, in writing or in electronic form, that he or she has received the required training and the date train ing was received. CU shall retain copies of such certifications for no less than six years following the date training was provided.<br><br>4. CU shall review the Training Program, including all training materials developed as part of the program, annually, and, where appropriate, update the training to reflect changes in Federal law or HHS guidance, any issues discovered during audits or reviews, and any other relevant developments. </font><br></td></tr></tbody></table><font face="Arial"><br>For a chart summary of the OCR fines as well as other HIPAA related litigation, please see<a href="https://melniklegal.com/list_of_HIPAA_fines_and_penalties.html"> </a></font><font face="Arial"><a href="https://melniklegal.com/list_of_HIPAA_fines_and_penalties.html">https://melniklegal.com/list_of_HIPAA_fines_and_penalties.html</a>. <br><br><font size="2">---------------------<br>[1] Press Release, Office of Civil Rights (May 8, 2014), <i>available at</i> <a href="https://www.hhs.gov/ocr/privacy/hipaa/enforcement/examples/jointbreach-agreement.html">https://www.hhs.gov/ocr/privacy/hipaa/enforcement/examples/jointbreach-agreement.html</a>.<br><br>[2] <a href="https://melniklegal.com/av/2014_OCR-ny-and-presbyterian-hospital-settlement-agr.pdf">Resolution Agreement between HHS Office of Civil Rights and </a></font></font><font face="Arial"><font size="2"><a href="https://melniklegal.com/av/2014_OCR-ny-and-presbyterian-hospital-settlement-agr.pdf"><font face="Arial">New York and Presbyterian Hospital</font></a><font face="Arial"> (agr. undated, press release from May 8, 2014).</font><br><br>[3] <a href="https://melniklegal.com/av/2014_OCR-columbia-university-resolution-agr.pdf">Resolution Agreement between HHS Office of Civil Rights and Columbia University</a> (agr. undated, press release from May 8, 2014).<br></font></font><font face="Arial"><font size="2"><font face="Arial"><font size="2">---------------------<br></font></font></font></font><br><font face="Arial"><font size="2"><font face="Arial"><font size="2"><font face="Arial"><font size="2">Posted by: Tatiana Melnik on May 8, 2014</font></font><br></font></font></font> </font>    
 
 
 
 
 
 ]]></description>
<link>http://melniklegal.com/weblog/1399561833_Data-Breach.html</link>
<guid>http://melniklegal.com/weblog/1399561833_Data-Breach.html</guid>
<pubDate>Thu, 08 May 2014 11:10:33 EST</pubDate>
</item>
			
			
			
<item>
<title><![CDATA[Alabama Board of Optometry Makes Final a Rule on Telemedicine]]></title>
<description><![CDATA[
 
 
 
 <div align="left"><font face="Arial">The Alabama Board of Optometry recently made final a Rule on the "Practice of Optometry Through Telemedicine." In making this Rule final, it repealed the <span>"Practice of Optometry Across State Line" Rule, which has been in place since 1998.</span><br><span></span><br></font></div><table style="text-align: left; margin-left: auto; margin-right: auto;" class="linkcolorchange" align="left" border="0"><tbody><tr><td style="border: 1px solid #edad27; padding:3px;" color="#FFFFFF" size="3" bgcolor="#001c31" valign="top"><font color="#FFCC00" face="Arial"><b><i>A few preliminary comments....</i></b></font><font color="#FFFFFF" face="Arial">Under the new Rule, a physician-patient relationship may be established through the use of telemedicine. But, patients must be present at an "Established Treatment Site" to receive services. The Rule defines "Established Treatment Site" as:</font><font face="Arial"><br></font><div align="justify"><blockquote><font color="#FFFFFF" face="Arial">A location where a patient shall present to seek optometric care 
 (through telemedicine). <b>An established treatment site shall have an 
 optometrist licensed by the Alabama Board of Optometry present on site 
 during the provision of any telemedicine to a patient</b>, and there <b>must 
 exist between said optometrist and patient an optometrist-patient 
 relationship</b>. There shall be sufficient equipment and technology present
  at any established treatment site to allow for an adequate physical 
 evaluation as appropriate for the patient's presenting complaint. <b>A 
 patient's home is not considered an established treatment site</b>.</font><font face="Arial"><br></font></blockquote></div><font color="#FFFFFF" face="Arial">The Rule also provides greater flexibility for the means of providing services via telemedicine as compared to other states. Under the Rule, "Telemedicine" is defined as:<br></font><div align="justify"><blockquote><font color="#FFFFFF" face="Arial"><p>
 	(7) Telemedicine. As used in these regulations, a health service that 
 is delivered by a licensed optometrist acting within the scope of his or
  her license and that requires the use of telecommunications technology 
 other than telephone or facsimile. Telecommunications technology as used
  herein shall include, but not be limited to:</p>
 </font><blockquote><font color="#FFFFFF" face="Arial"><p>
 	(a) compressed digital interactive video, audio, or data transmission;</p></font></blockquote><font color="#FFFFFF" face="Arial">
 </font><blockquote><font color="#FFFFFF" face="Arial"><p>
 	(b) clinical data transmission using computer imaging by way of still image capture and store and forward;</p></font></blockquote><font color="#FFFFFF" face="Arial">
 </font><blockquote><font color="#FFFFFF" face="Arial"><p>
 	(c) other technology that facilitates access to health care services or optometric specialty services.</p></font></blockquote></blockquote></div><font color="#FFFFFF" face="Arial"><font color="#FFFFFF">Finally, the Rule also sets out security requirements for communicating with patients, including requiring that providers implement written policies and procedures. The security requirements cover "</font></font><font color="#FFFFFF" face="Arial"><font color="#FFFFFF"><font color="#FFFFFF"><font color="#FFFFFF">all patient 
 communications through electronic mail</font></font>," which includes "</font></font><font color="#FFFFFF" face="Arial"><font color="#FFFFFF">any type-written 
 communication that is transferred via the Internet, telephone or cable 
 line, or cellular telephone service, but shall not include facsimile, or 'fax' communications." </font></font><font color="#FFFFFF" face="Arial"><font color="#FFFFFF">The Rule enumerates a number of required policies and procedures that are not required under HIPAA and therefore not typically included in a HIPAA manual:<br></font></font><blockquote><font color="#FFFFFF" face="Arial">The written policies and procedures for such security measures for electronic mail shall address all of the following:
 </font><blockquote><font color="#FFFFFF" face="Arial"><p>
 	(1) Confidentiality and integrity of patient-identifiable information;</p>
 <p>
 	(2) The identity—by position or title—of health care personnel who will
  process or otherwise have access to information sent by electronic 
 mail;</p>
 <p>
 	(3) Hours of operation and availability of the provider and distant site provider;</p>
 <p>
 	(4) Types of transaction which shall be permitted electronically;</p>
 <p>
 	(5) The type of information to be included in the communication, such 
 as patient name, identification number, and type of transaction;</p>
 <p>
 	(6) How and when electronic mail will be archived and retrieved;</p>
 <p>
 	(7) Mechanisms for the oversight of the processing, handling, storage, and archival of electronic mail.</p></font></blockquote></blockquote><font color="#FFFFFF" face="Arial"><font color="#FFFFFF">Alabama optometrists providing services via telemedicine must carefully review their existing policies and procedures and bring them in line with these new requirements.<br><br><font color="#FFCC33"><b>This new Final Rule becomes effective on March 13, 2015</b></font></font></font><font color="#FFFFFF" face="Arial"><font color="#FFFFFF"><font color="#FFFFFF"><br></font></font></font></td></tr></tbody></table><div align="left"><font face="Arial"><br></font></div><div align="left"><font face="Arial"><br><u><b><br><font color="#333399"><span><font size="4">New Rule</font></span></font></b></u><font size="2"> (scroll down for Rule that was repealed)</font><u><b><br></b></u><br>PUBLICATION DATE: 03/04/2015</font> 
                 <div><font face="Arial">ACTION DATE: 02/06/2015</font></div>                                      
                 <div><font face="Arial">EFFECTIVE DATE: 03/13/2015</font></div>
                 <div><font face="Arial"><b><br>ALABAMA BOARD OF OPTOMETRY</b><b><br>Chapter 630-X-13</b><br>Practice of Optometry Through Telemedicine <b>(New Chapter)</b><br></font><div><font face="Arial"><br><b>Chapter 630 x 13</b><br>630 x 13.01 Definitions<br>630 x 13.02 Optometric Telemedicine<br>630 x 13.03 On-site Optometrist<br>630 x 13.04 Security Measures for Electronic Mail<br>630 x 13.05 Communication in Patient Records<br>630 x 13.06 Alternative Forms of Communication<br>630 x 13.07 Patient Records<br>630 x 13.08 Emergency Telemedicine<br><br><u><b>630 x 13.01 Definitions</b></u><br><b>&nbsp; <br>&nbsp;&nbsp; (1) Distant Site Provider.</b> A provider of optometric services through 
 telemedicine from a site other than the patient's then current location.
  A distant site provider shall hold an active Alabama optometry license 
 as set out in § 34-22-20 and § 34-22-21 of the Alabama Code.</font></div></div>
 <p><font face="Arial">&nbsp;&nbsp;&nbsp;
 	<b>(2) Emergency.</b> A situation or condition where failure to provide 
 immediate treatment poses a threat of loss of sight to a person. For the
  purposes hereof, routine visual care shall not be an emergency.</font></p>
 <p><font face="Arial">&nbsp;&nbsp;&nbsp;
 	<b>(3) Established Treatment Site. </b>A location where a patient shall 
 present to seek optometric care (through telemedicine). An established 
 treatment site shall have an optometrist licensed by the Alabama Board 
 of Optometry present on site during the provision of any telemedicine to
  a patient, and there must exist between said optometrist and patient an
  optometrist-patient relationship. There shall be sufficient equipment 
 and technology present at any established treatment site to allow for an
  adequate physical evaluation as appropriate for the patient's 
 presenting complaint. A patient's home is not considered an established 
 treatment site.</font></p>
 <p><font face="Arial">&nbsp;&nbsp;&nbsp;
 	<b>(4) Face-to-face Visit.</b> An evaluation or appointment for treatment at 
 which both the provider and patient are at the same physical location, 
 or where the patient is at an established treatment site and the 
 provider is a distant site provider.</font></p>
 <p><font face="Arial">&nbsp;&nbsp;&nbsp;
 	<b>(5) In-person Evaluation.</b> A patient evaluation conducted by a provider 
 who is at the same physical location as the location of the client.</font></p>
 <p><font face="Arial">&nbsp;&nbsp;&nbsp;
 	<b>(6) Provider.</b> As used in this chapter the term "provider" shall mean an
  optometrist holding an active license to practice optometry granted by 
 the Alabama Board of Optometry in accordance with § 34-22-20 and § 
 34-22-21 of the Alabama Code.</font></p>
 <p><font face="Arial">&nbsp;&nbsp;&nbsp;
 	<b>(7) Telemedicine.</b> As used in these regulations, a health service that 
 is delivered by a licensed optometrist acting within the scope of his or
  her license and that requires the use of telecommunications technology 
 other than telephone or facsimile. Telecommunications technology as used
  herein shall include, but not be limited to:</font></p>
 <blockquote><p>
 	<font face="Arial"><b>(a)</b> compressed digital interactive video, audio, or data transmission;</font></p></blockquote>
 <blockquote><p>
 	<font face="Arial"><b>(b)</b> clinical data transmission using computer imaging by way of still image capture and store and forward;</font></p></blockquote>
 <blockquote><p>
 	<font face="Arial"><b>(c)</b> other technology that facilitates access to health care services or optometric specialty services.</font></p></blockquote>
 <p>
 	<font face="Arial"><u><b>630 x 13.02 Optometric Telemedicine</b></u></font></p>
 <p><font face="Arial"><b>&nbsp;&nbsp; (1)</b> The provision of optometric diagnosis, treatment, or other services
  to a patient through telemedicine at an established treatment site may 
 be used for all patient visits, including initial evaluations to 
 establish an optometrist-patient relationship between a provider and a 
 patient.</font></p>
 <p><font face="Arial"><b>&nbsp;&nbsp; </b>
 	<b>(2) </b>A distant site provider who provides telemedicine services to a 
 patient that is not present at an established treatment site shall 
 ensure that a proper provider-patient relationship is established, which
  shall include at least the following:</font></p>
 <blockquote><p><font face="Arial"><b>
 	(a) </b>Having had at least one face-to-face meeting, either In person, or 
 at an established treatment site via telecommunications technology as 
 set out in 630 x 13.01 (7);</font></p></blockquote>
 <blockquote><p>
 	<font face="Arial"><b>(b)</b> Confirming the identity of the person requesting treatment by 
 establishing that the person requesting the treatment Is in fact whom he
  or she claims to be.</font></p></blockquote>
 <p><font face="Arial"><b>&nbsp;&nbsp; </b><b>
 	(3)</b> Evaluation, treatment, and consultation recommendations made via 
 telemedicine, including, but not limited to the issuance of 
 prescriptions, shall be held to the same standards of practice as those 
 in traditional in-person clinical settings. The provision of optometric 
 diagnosis, treatment, or other services through telemedicine shall 
 comply with the requirements of the Alabama Code, this chapter, ana 
 these regulations. Failure to comply with such requirements shall be 
 considered a failure to meet standard of care as required by 
 630-X-12-.06 herein.</font></p>
 <p><font face="Arial"><b>&nbsp;&nbsp; </b><b>
 	(4) </b>Distant site providers shall obtain an adequate and complete 
 medical history for the patient before providing treatment and shall 
 document the medical history In the patient record.</font></p>
 <p>
 	<font face="Arial"><u><b>630 x 13.03 On-site Optometrist</b></u></font></p>
 <p><font face="Arial">
 	A provider may delegate tasks and activities at an established 
 treatment site to an assistant who Is properly trained, supervised, and 
 directed. There shall be, however, an Alabama-licensed optometrist 
 present and available to assist with the provision of care at any 
 established treatment site during the provision of optometric 
 telemedicine.</font></p>
 <p>
 	<font face="Arial"><u><b>630 x 13.04 Security Measures for Electronic Mail</b></u></font></p>
 <p><font face="Arial">
 	Adequate measures shall be taken to ensure the security of all patient 
 communications through electronic mail, and that said information 
 remains confidential. Electronic mail includes any type-written 
 communication that is transferred via the Internet, telephone or cable 
 line, or cellular telephone service, but shall not include facsimile, or
  "fax" communications. Providers of optometric telemedicine shall, prior
  to providing optometric telemedicine services, establish and adopt 
 written policies and procedures to ensure the security of patient 
 communications, recordings, and records transferred by electronic mail. 
 Policies shall be evaluated periodically so that they remain up-to-date.
  The written policies and procedures for such security measures for 
 electronic mail shall address all of the following:</font></p>
 <blockquote><p>
 	<font face="Arial"><b>(1)</b> Confidentiality and integrity of patient-identifiable information;</font></p>
 <p>
 	<font face="Arial"><b>(2)</b> The identity—by position or title—of health care personnel who will
  process or otherwise have access to information sent by electronic 
 mail;</font></p>
 <p>
 	<font face="Arial"><b>(3) </b>Hours of operation and availability of the provider and distant site provider;</font></p>
 <p>
 	<font face="Arial"><b>(4)</b> Types of transaction which shall be permitted electronically;</font></p>
 <p>
 	<font face="Arial"><b>(5)</b> The type of information to be included in the communication, such 
 as patient name, identification number, and type of transaction;</font></p>
 <p>
 	<font face="Arial"><b>(6)</b> How and when electronic mail will be archived and retrieved;</font></p>
 <p>
 	<font face="Arial"><b>(7)</b> Mechanisms for the oversight of the processing, handling, storage, and archival of electronic mail.</font></p></blockquote>
 <p><font face="Arial"><u><b>
 	630 x 13.05 Communication in Patient Records</b></u></font></p>
 <p><font face="Arial">
 	All relevant provider-patient electronic communications, including 
 recordings and electronic mail shall be stored and filed in or with the 
 patient's record in addition to any other storage methods.</font></p>
 <p>
 	<font face="Arial"><u><b>630 x 13.06 Alternative Forms of Communication</b></u></font></p>
 <p><font face="Arial">
 	All patients who are served through optometric telemedicine shall be 
 informed of alternative forms of contacting their provider for urgent 
 matters. Conventional telephone numbers used by a provider for 
 traditional on-site optometry shall be sufficient[.]</font></p>
 <p>
 	<font face="Arial"><u><b>630 x 13.07 Patient Records</b></u></font></p><p><font face="Arial"><b>&nbsp;&nbsp; </b><b>(1) </b>Patient records shall be maintained for 
 all telemedicine services. The provider or distant site provider shall 
 maintain the records created at any site where treatment or evaluation 
 is provided.</font></p>
 <p><font face="Arial"><b>&nbsp;&nbsp; </b><b>
 	(2)</b> Patient records shall include copies of all relevant 
 patient-related electronic communications, including relevant 
 provider-patient email, prescriptions, laboratory and rest results, 
 evaluations and consultation, records of past care, medical histories, 
 and instructions. If possible, telemedicine encounters that are recorded
  electronically shall also be included in the patient record. Where 
 means of storage will not allow for the storage of electronically 
 recorded encounters with or in the patient record, the patient record 
 shall include a notation or entry that the recording exists and the 
 location and means of storage of such recording.</font></p>
 <p>
 	<font face="Arial"><u><b>630 x 13.08 Emergency Telemedicine</b></u></font></p>
 <p><font face="Arial"><b>&nbsp;&nbsp; </b><b>
 	(1) </b>An optometrist who is licensed by another state to practice 
 optometry, but who is not licensed in the state of Alabama pursuant to 
 §§ 34-22-20 or 34-22-21, who utilizes telemedicine to provide optometric
  services in the state of Alabama from a distant site outside of the 
 state of Alabama during a state of emergency is not subject to the 
 requirements of this article. For the purposes of this section 13.08(1),
  a state of emergency means a natural or man-made disaster for which the
  Governor of the State of Alabama has declared or proclaimed a state of 
 emergency or where the President of the United States has declared a 
 disaster in accordance with the Disaster Relief and Emergency Assistance
  Act of 1988 as amended. For the exemption contained in this section to 
 apply, the patient receiving telemedicine services from the distant site
  must be located within the geographical boundaries established In the 
 governor's declaration of a state of emergency or the president's 
 disaster declaration.</font></p>
 <p><font face="Arial"><b>&nbsp;&nbsp; </b><b>
 	(2) </b>A provider who is contacted in an emergency shall not be subject to
  the notice and security provisions of this article, the provisions of 
 this section 13.08(2) shall not apply to any non-emergency optometric 
 services provided to the patient as a continuation of treatment 
 initiated in the emergency or for a different condition or issue which 
 arises later. For the purposes of this section 13.08(2), an emergency 
 shall have the meaning and definition set out in section 13.01(2) above.</font></p>
 <p>
 	<font face="Arial"><b>Author:</b> Dr. Fred Wallace<b><br></b><b>Statutory Authority:</b> Code of Ala., 1975, §34-22-80 through 87<b>.</b><b><br></b><b>History: New Rule:</b> Filed February 6, 2015<span>; effective March 13, 2015 .</span><br></font></p></div><div align="left"><br><br><font face="Arial"><u><b><font color="#333399" size="4">Old Rule</font></b></u></font><br><div><b><font face="Arial">Alabama Board of Optometry</font></b><font face="Arial"><br>Chapter 630-X-13</font><font face="Arial"><span><br>Practice of Optometry Across State Lines <b>(Repealed)</b></span></font><font face="Arial"><span><br></span></font><div><font face="Arial"><br><span>630-X-13-.01 Definition Of Distance-Based Optometrist</span></font><font face="Arial"><span><br>630-X-13-.02 Definition Of Alabama Patient</span></font><font face="Arial"><span><br>630-X-13-.03 Definition Of The Practice Of Optometry Across State Lines</span></font><font face="Arial"><span><br>630-X-13-.04 Special Purpose License To Practice Optometry Across State Lines</span></font><font face="Arial"><span><br>630-X-13-.05 Issuance Of Certificate Of Qualification</span></font><font face="Arial"><span><br>630-X-13-.06 Issuance Of Special Purpose License To Practice Optometry Across State Lines</span></font><font face="Arial"><span><br>630-X-13-.07 Renewal Of Special Purpose License To Practice Optometry Across State Lines</span></font><font face="Arial"><span><br>630-X-13-.08 Revocation or Suspension Of Special Purpose License To Practice Optometry Across State Lines</span></font><font face="Arial"><span><br>630-X-13-.09 Exemptions</span><span><br>630-X-13-.10 Reciprocity</span><u><b><br><br>630-X-13-.01 Definition Of Distance-Based Optometrist</b></u><br>For the purpose 
 of these regulations, a distance-based optometrist is defined as an 
 optometrist located outside the boundaries of the State of Alabama who 
 does not have a full, unrestricted and current license to practice 
 optometry in Alabama.<br></font><blockquote><font face="Arial">History: Author, Dr. William Sullins; Filed December 11, 1998</font><br></blockquote><font face="Arial"><b><u>630-X-13-.02 Definition Of Alabama Patient. </u></b><br>For the purposes of these 
 regulations, an Alabama patient is an Individual whose physical location
  is within the boundaries of the State of Alabama.<br></font><blockquote><font face="Arial">History: Author, Dr. William Sullins; Filed December 11, 1998</font><br></blockquote><font face="Arial"><u><b>630-X-13-.03 Definition of The Practice Of Optometry Across State Lines. </b></u><br>The practice of optometry across state lines means the 
 examination of, or consultation regarding, an Alabama patient by a 
 distance-based optometrist and shall include:<br></font><blockquote><font face="Arial"><b>(1) </b>The rendering by a distance-based optometrist of a professional 
 opinion, either written or otherwise documented, concerning the 
 diagnosis or treatment of an Alabama patient as a result of transmission
  of individual patient data by electronic or other means to such 
 distance-based optometrist or his or her agent, or</font><br></blockquote><blockquote><font face="Arial"><b>(2)</b> The rendering by a distance-based optometrist of treatment to an 
 Alabama patient as a result of transmission of individual patient data 
 by electronic or other means to such distance-based optometrist or his 
 or her agent, but</font></blockquote></div></div></div><div align="left"><align="left"><div align="left"><font face="Arial">
 </font></div></align="left"></div><blockquote><align="left"><p align="left"><font face="Arial">
 	<b>(3)</b> This definition shall not include an informal consultation 
 regarding an Alabama patient between an Alabama licensed optometrist and
  a distance-based optometrist provided that the consultation does not 
 result in either:</font></p></align="left"></blockquote><align="left"><div align="left"><font face="Arial">
 </font></div></align="left"><blockquote><blockquote><align="left"><p align="left"><font face="Arial">
 	<b>(a)</b> compensation or the expectation of compensation by either optometrist, or</font></p></align="left"></blockquote></blockquote><align="left"><div align="left"><font face="Arial">
 </font></div></align="left"><blockquote><blockquote><align="left"><p align="left"><font face="Arial">
 	<b>(b)</b> the format rendering of a written or otherwise documented 
 professional opinion concerning the diagnosis or treatment of said 
 patient by the distance-based optometrist.</font></p></align="left"></blockquote></blockquote><align="left"><div align="left"><font face="Arial">
 </font></div></align="left"><blockquote><align="left"><p align="left"><font face="Arial">
 	History: Author, Dr. William Sullins; Filed December 11, 1998</font></p></align="left"></blockquote><align="left"><div align="left"><font face="Arial">
 </font></div><p align="left"><font face="Arial">
 	<b><u>630-X-13-.04 Special Purpose License To Practice Optometry Across State
  Lines.</u></b> </font></p></align="left"><br><align="left"><p align="left"><font face="Arial">A special purpose license issued by the Alabama Board of 
 Optometry shall be required for the practice of optometry across state 
 lines in Alabama.</font></p><div align="left"><font face="Arial">
 </font></div></align="left"><blockquote><align="left"><p align="left"><font face="Arial">
 	History: Author, Dr. William Sullins; Filed December 11, 1998</font></p></align="left"></blockquote><align="left"><div align="left"><font face="Arial">
 </font></div><p align="left"><font face="Arial">
 	<u><b>630-X-13-.05 Issuance Of Certificate Of Qualification.</b></u> </font></p></align="left"><br><align="left"><p align="left"><font face="Arial">An individual 
 may apply to the Alabama Board of Optometry for the issuance of a 
 certificate of qualification for a special purpose license to practice 
 optometry across state lines. Such application shall be on a form 
 provided by the Board upon request and shall include an application fee 
 in the amount of $600.00. The Board shall issue such certificate of 
 qualification providing the following requirements are met:</font></p><div align="left"><font face="Arial">
 </font></div></align="left"><blockquote><align="left"><p align="left"><font face="Arial">
 	<b>(1)</b> The applicant holds a current full and unrestricted license to 
 practice optometry in a state or territory of the United States.</font></p><div align="left"><font face="Arial">
 </font></div><p align="left"><font face="Arial">
 	<b>(2)</b> The applicant has no previous or pending disciplinary action or 
 other action taken against the applicant by any state or other licensing
  jurisdiction, provided, however, that the Board may issue a certificate
  of qualification in such cases where the previous or pending 
 disciplinary action or other action does not indicate that the applicant
  is a potential threat to the public.</font></p><div align="left"><font face="Arial">
 </font></div><p align="left"><font face="Arial">
 	<b>(3) </b>The applicant shall affirm his or her intent and willingness to 
 report to the Alabama Board of Optometry in writing the initiation of 
 any disciplinary action against him or her by any state or territory in 
 which he or she is licensed. Said report shall be submitted to the 
 Alabama Board of Optometry within 15 days of the Initiation of such 
 disciplinary action.</font></p><div align="left"><font face="Arial">
 </font></div><p align="left"><font face="Arial">
 	History; Author, Dr. William Sullins; Filed December 11, 1998. Amended effective February 20, 2008.</font></p></align="left"></blockquote><align="left"><div align="left"><font face="Arial">
 </font></div><p align="left"><font face="Arial">
 	<u><b>630-X-13-.06 Issuance OF Special Purpose License to Practice Optometry 
 Across State Lines. </b></u></font></p></align="left"><br><align="left"><p align="left"><font face="Arial">The Alabama Board of Optometry shall issue a special
  purpose license to practice optometry across state lines upon 
 presentation by a distance-based optometrist of a certificate of 
 qualification issued by the Alabama Board of Optometry in accordance 
 with this chapter. Special purpose licenses to practice across state 
 lines limit the holders thereof solely to the practice of optometry 
 across state lines as defined herein and does not confer the authority 
 to practice optometry while said licensee is within the physical 
 boundaries of the state of Alabama.</font></p><div align="left"><font face="Arial">
 </font></div></align="left"><blockquote><align="left"><p align="left"><font face="Arial">
 	History: Author, Dr. William Sullins; Filed December 11, 1998</font></p></align="left"></blockquote><align="left"><div align="left"><font face="Arial">
 </font></div><p align="left"><font face="Arial">
 	<u><b>630-X-13-.07 Renewal Of Special Purpose License To Practice Optometry 
 Across State Lines.</b></u></font></p><p align="left"><font face="Arial"> The special purpose license to practice optometry 
 across state lines is valid for a period of three years. Such special 
 purpose license may be renewed for additional three year terms upon 
 receipt of a renewal fee of $260.00.</font></p><div align="left"><font face="Arial">
 </font></div></align="left"><blockquote><align="left"><p align="left"><font face="Arial">
 	History: Author, Dr. William Sullins; Filed December 11, 1998. Amended effective February 20, 2008.</font></p></align="left"></blockquote><align="left"><div align="left"><font face="Arial">
 </font></div><p align="left"><font face="Arial">
 	<u><b>630-X-13-.08 Revocation Or Suspension of Special Purpose License To Practice Optometry Across State Lines.</b></u></font></p><div align="left"><font face="Arial">
 </font></div></align="left"><blockquote><align="left"><p align="left"><font face="Arial">
 	<b>(1)</b> A special purpose license to practice optometry across state lines 
 may be revoked or suspended, or other disciplinary action may be 
 imposed, by the Alabama Board of Optometry for any of the following 
 causes:</font></p><div align="left"><font face="Arial">
 </font></div></align="left"><blockquote><align="left"><p align="left"><font face="Arial">
 	<b>(a)</b> Failure to renew special purpose license according to the renewal 
 schedule established by the Board shall result in the automatic 
 revocation of said license.</font></p><div align="left"><font face="Arial">
 </font></div><p align="left"><font face="Arial">
 	<b>(b)</b> Failure to comply with rules and regulations of the Alabama Board 
 of Optometry shall be cause for the Board to initiate disciplinary 
 actions as set forth in Sections 34-22-1 to 34-22-43, inclusive, Code of
  Alabama 1975,</font></p><div align="left"><font face="Arial">
 </font></div><p align="left"><font face="Arial">
 	<b>(c) </b>Failure to comply with rules and regulations governing optometrists
  in any other state or territorial licensing jurisdiction in which the 
 licensee holds a license to practice optometry shall be cause for the 
 Board to initiate disciplinary actions in Alabama and to impose the same
  discipline it would have imposed had the violation been committed by an
  Alabama licensee in the course of practice in Alabama.</font></p></align="left"></blockquote><align="left"><div align="left"><font face="Arial">
 </font></div><p align="left"><font face="Arial">
 	<b>(2)</b> The Alabama Board of Optometry is authorized to temporarily suspend
  a special purpose license to practice optometry across state lines 
 without a hearing on either of the following grounds:</font></p><div align="left"><font face="Arial">
 </font></div></align="left"><blockquote><align="left"><p align="left"><font face="Arial">
 	<b>(a) </b>The failure of the licensee to appear or produce records or materials as requested by the Board.</font></p><div align="left"><font face="Arial">
 </font></div><p align="left"><font face="Arial">
 	<b>(b)</b> The initiation of a disciplinary action against the licensee by any
  state or territorial licensing jurisdiction in which the licensee holds
  a license to practice optometry. The temporary suspension provided 
 hereby shall remain in effect until the temporary suspension is 
 terminated by written order of the Alabama Board of Optometry, finding 
 that any violation of the rules or regulations governing optometrists 
 committed by the licensee, or any failure by the licensee to honor 
 requests of the Board, does not indicate that the licensee is a 
 potential threat to the public.</font></p></align="left"></blockquote></blockquote><align="left"><div align="left"><font face="Arial">
 </font></div></align="left"><blockquote><align="left"><p align="left"><font face="Arial">
 	History: Author, Dr. William Sullins; Filed December 11, 1998</font></p></align="left"></blockquote><align="left"><div align="left"><font face="Arial">
 </font></div><p align="left"><font face="Arial">
 	<u><b>630-X-13-.09 Exemptions.</b></u></font></p><div align="left"><font face="Arial">
 </font></div><p align="left"><font face="Arial">&nbsp; <b>(1) </b>A distance-based optometrist who engages in the practice of 
 optometry across state lines in an emergency, is not subject to this 
 rule.</font></p><div align="left"><font face="Arial">
 </font></div><p align="left"><font face="Arial">&nbsp; <b>(2) </b>A distance-based optometrist who engages in the practice of 
 optometry across state lines on an irregular or infrequent basis is not 
 subject to this rule. Irregular or infrequent practice of optometry 
 across state lines is defined as such practice involving fewer than 10 
 patients, occurring less than 10 times in a calendar year, or comprising
  less than one percent of the distance-based optometrist's diagnostic or
  therapeutic practice of optometry.</font></p><div align="left"><font face="Arial">
 </font></div></align="left"><blockquote><align="left"><p align="left"><font face="Arial">
 	History: Author, Dr. William Sullins; Filed December 11, 1998. Amended effective February 20, 2008.</font></p></align="left"></blockquote><align="left"><div align="left"><font face="Arial">
 </font></div><p align="left"><font face="Arial">
 	<u><b>630-X-13-.10 Reciprocity.</b></u></font></p><div align="left"><font face="Arial">
 </font></div><p align="left"><font face="Arial">
 	Notwithstanding any provision of this regulation, the Board shall only 
 issue a special purpose license to practice optometry across state lines
  to an applicant whose principal optometric practice location and 
 license to practice optometry is located in a state or territory of the 
 United States whose laws permit or allow for the issuance of a special 
 purpose license to practice optometry across state lines or similar 
 license to an optometrist whose principal practice location Is within 
 the boundaries of the State of Alabama.</font></p></align="left"><div align="left"><align="left"><font face="Arial">
 	<b>History</b>: Author, Dr. William Sullins</font></align="left"><br><align="left"><font face="Arial"><b>Statutory Authority:</b> Code of Ala., 1975, §34-22-80 through 87.</font></align="left"><br><align="left"><font face="Arial"><b>Filed December 11, 1998<br><br><br></b></font></align="left"></div><align="left"></align="left"><align="left"><div align="left"><div align="left"><font face="Arial">For additional details, see: <a href="https://www.optometry.alabama.gov/AdminCode.htm">https://www.optometry.alabama.gov/AdminCode.htm</a></font></div></div></align="left"><br><align="left"></align="left"><br><align="left"></align="left"><br><align="left"><div align="left"><font face="Arial"><font size="2">-------------------------------------</font></font></div></align="left"><br><align="left"><div align="left"><font face="Arial"><font size="2">Posted by Tatiana Melnik on March 9, 2015</font></font></div></align="left"><br><align="left"><div align="left">
   
 
 </div></align="left">
 
 
 
 ]]></description>
<link>http://melniklegal.com/weblog/1425904258_Telemedicine.html</link>
<guid>http://melniklegal.com/weblog/1425904258_Telemedicine.html</guid>
<pubDate>Mon, 09 Mar 2015 08:30:58 EST</pubDate>
</item>
			
			
</channel>
</rss>