1. For the final rule adopting the HIPAA standards for the security of electronic health information, see Federal Register 68 , no. 34 (20 February 2003 ). http://www.cms.hhs.gov/SecurityStandard/Downloads/securityfinalrule.pdf (accessed 29 December 2008 )
2. . For the Proposed Rule, see Federal Register 63 , no. 155 (12 August 1998 ), http://www.cms.hhs.gov/SecurityStandard/Downloads/securityproposedrule.pdf (accessed 29 December 2008 ).
3. L. Fernandez and M. O’Connor, “The Future of Patient Identification,” Journal of AHIMA 77 , no. 1 ( 2006 ): 36 –40, http://library.ahima.org/xpedio/groups/public/documents/ahima/bok1_029033.hcsp?dDocName=bok1_029033 (accessed 29 December 2008 ).
4. See 45 CFR 160(b), for the section of the rule describing federal preemption of state privacy law. Federal Register 65 , no. 250 (28 December 2000 ), http://www.hhs.gov/ocr/part1.pdf (accessed 29 December 2008).