Thursday, April 8, 2010

Virginia Passes MEDICAL Breach Notification Law

The state of Virginia has passed a breach notice law requiring notice of security breaches involving medical information.  The law does not apply to persons or entities that must report the breach under the HITech Act.

MIAOULIS NOTE:  Not exactly sure what this means for Business Associates, but Healthcare Facilities appear to not be affected since they fall under the HITECH notification requirements.  Remember BA's under HITECH must only report to the Covered Entity.  This may require them to also report to the individual.

No comments: