Federal Identity Theft Laws
FACTA passed 2005, applies to every facility/company that employs atleast one person. The
focus is on proper destruction and or storage of PII and PHI. You need a written specific plan and employee training.
Gramm Leach Bliley passed May 2003. Requires you to show that you are safeguarding information.
You must have a written plan, train employees on that plan and conduct walk through assessments.
NEW*
Red Flag Rules, passed in January 2008, It states that you must have an "Identity Theft
Prevention Program". You must create a "culture of security." This law was put in place so that we can "identify red
flags" that should indicate that the patient that you are treating is really that patient.
For example: The patient has already stolen an identity and using another persons health insurance
and other information.
If you did not know about the laws don't feel isolated a recent study shows that even in large medical faciliites
only 30% of the compliance and risk management team understood that these laws apply to them.