CMS has taken "limited actions" to ensure that health care providers are effectively protecting patients' medical records, but the agency's efforts fall short of ensuring compliance with the HIPAA security rule, according to a report from HHS Office of the Inspector General, Government Health IT reports (Moore, Government Health IT, 10/31).
The report states OIG found that CMS has "no effective mechanism" to ensure that health care providers are complying with the HIPAA security rule or that electronic health records are being protected adequately.
Although OIG concluded that CMS' system to handle complaints is adequate, the report calls for CMS to adopt compliance reviews as a more proactive method of verifying that health care organizations are complying with the HIPAA security rule.
CMS Response
In its formal response, CMS argued that its complaint-driven enforcement process is effective and has advanced voluntary compliance efforts but agreed with a recommendation to develop standards and procedures for conducting compliance reviews.
The report notes that CMS had moved forward with compliance reviews before the report was released on Oct. 27 (Manos, Healthcare IT News, 10/31).