Hindsight · review build · data not yet validated
Privacy issues concerning access to these records (as with many other data bases of personal information) have emerged as a major issue.
Grader A: hit
Privacy of electronic medical records was a major issue in 2009. The HITECH Act of 2009 extended HIPAA privacy and security rules to business associates, created breach notification for incidents affecting 500+ people and tiered penalties.
Test: Policy-salience test: federal legislation on health-record privacy enacted in 2009 (HITECH privacy provisions).
Grader B: hit
Health-record privacy was a major policy issue by 2009. The HITECH Act (2009) extended HIPAA privacy and security rules to business associates. It required breach notification to HHS, the media and affected people for breaches of 500 or more records. It set tiered penalties up to $1.5 million a year per provision. This followed the HIPAA Privacy Rule, and the national debate over electronic records tied spending on EHRs to privacy protections.
Test: Not an adoption claim. Test: medical-record privacy is a major legislative issue by 2009. HITECH (2009) added breach notification and stronger HIPAA enforcement.