
You Thought HIPAA Was Tough? Try GDPR
Wondering what GDPR is? An attorney breaks down everything you need to know about the new data security law.
With the effective date of the European General Data Protection Rule (GDPR) looming, it's important for all U.S. companies including physician practices, regardless of size, to appreciate and understand the law.
It's easy to know something is a "big deal" when a click on a website reveals a count-down timer.
Such is the case with
There is good news and bad news associated with GDPR. First, if your organization is HIPAA and HITECH Act complaint, aside from changes in contracts and a few policies, the security standards should be met – this is the good news.
The bad news is that GDPR is
We know that HIPAA and the HITECH Act can carry significant penalties. GDPR makes those fines look like the cost of an ice cream cone. Like HIPAA and the HITECH Act, breach notification is mandatory and a tiered penalty approach is used. However, the timeframe for reporting a breach under GDPR is significantly less – within 72 hours of becoming aware of the incident. Organizations found in breach of GDPR, by way of contrast, potentially face up to 4 percent of annual global turnover or 20 million Euros – whichever is greater.
For physicians and other providers, the first step is to see who is accessing your website. Where are the perpetrators located? Is data being collected? The next step is to look at all business associates and subcontractors, including cloud providers and data centers, to see where they are located and where the data of any EU citizens is being processed, housed, collected or transmitted.
Next, the following items need to be considered: contracts, business associate agreements, right to access, right to be forgotten, data portability, privacy by design and data protection officers. This should provide a starting point for a law that should not be ignored, given the jurisdictional reach of the EU.
Newsletter
Optimize your practice with the Physicians Practice newsletter, offering management pearls, leadership tips, and business strategies tailored for practice administrators and physicians of any specialty.













