Who needs to comply with the HIPAA Security Rule?
Any company/covered entity that has medical patient information in any type of electronic form that is identifiable is required by law to comply with the HIPAA Security Rule. This applies even to companies that are not in the medical industry but are just providing services like document scanning and billing, also known as business associates. The HIPAA enforcement has been put into action since July, 2006, which allows them to fully enforce the security rule and to issue fines and penalties for covered entities that are not in compliance. Many companies have already undergone audits and surveys. Some companies have already had to pay huge fines for not being in compliance with the HIPAA laws. About the Security Rule The Final Rule on Security Standards was issued on Februry 20, 2003. It took effect on April 21,2003 with a compliance date of April 21,2005 for most covered entities and April 21, 2006 for “small plans”. The Security Rule complements the Privacy Rule. While the Privacy Ru