In response to HealthLeaders' inquiry about the prominence of the site, OCR wrote, "The OCR HIPAA Privacy Web site is one of the most visited Web sites in the department, and the link to the new breach Web site is prominently available from the home page."
Borten says she "respectfully disagrees."
"Only someone who is determined to find the site and knows it must be there is likely to find it by drilling down," she says.
Frank Ruelas, director of compliance and risk management at Maryvale Hospital and principal of HIPAA Boot Camp in Casa Grande, AZ, says he too feels the Web site is hard to track.
"I didn't necessarily see the Web-based notices all that easy to find," Ruelas says. "I would have expected them to be a bit more prominently displayed."
Borten says she hopes OCR will reconsider "where and how it posts breaches so that the full intent and impact of the law is met."
But OCR stands by its method, telling HealthLeaders, "The posting of breaches affecting over 500 individuals, as with other provisions in HITECH, has brought a strong refocus on compliance with the HIPAA Privacy and Security rules."