Ryn Coleridge, Director of Enterprise Systems and Analytics and HIPAA Privacy and Security Officer, presented annual HIPAA training for board members, highlighting the top five violations (including unencrypted lost devices and database breaches), recent HHS inflation adjustments to civil-penalty tiers and new HHS guidance on online tracking technologies affecting covered entities and business associates.
Coleridge outlined likely federal changes that may be finalized in 2023–24: faster response times for PHI requests (potentially reducing the response window to 15 days), allowing patients to review PHI in person and take photos, enabling transfers of PHI to personal health applications, and broader definitions of health-care operations to facilitate care coordination. The officer said covered entities will also need to post estimated fee schedules for PHI access and provide individualized fee estimates on request.
Separately, the board considered governance-policy revisions recommended by its governance committee. Chair Follinsbee summarized four categories of revisions and presented redlined drafts; after discussion and public comment the board unanimously approved revisions to terms of reference and governance policy changes, including an updated contingency reserve policy (2-10) and a new policy (2-13) specifying how legal settlements will be handled going forward following receipt of settlement funds related to a Sutter Health class-action matter.
Board members asked practical questions about future HIPAA fee estimates and verifying identity for PHI requests; staff said fee setting will be internal and the member-services process will be used to validate identity, including use of demographics and identifiers and redaction where needed.