One of the things that I have always not understood about HIPAA is what teeth do these regulations have and who is going to enforce them. There are plenty of firms willing to take your money and rubber stamp you HIPAA compliant, but who is going to say your not HIPAA compliant and why should you care. Finally reading this article in Security Bytes it looks like the federal government has stepped up to enforce HIPAA and have put some bite behind the bark. Providence Health in Seattle was fined 100k by US Department of Heath and Human Services for losing data containing patients information.
I say good for the HHS! A few well publicized fines where people had to pay real money will go further in getting people to take HIPAA seriously than all of the other dog barking and warnings that have taken place to date. The same goes for other regulations and statues on compliance as well. Lets hear about some financial sanctions or penalties around PCI and you will see a drastic rise in compliance there as well. Rules and regulations without enforcement serve no purpose at all and hurt more than they help.






