Presentation on theme: "Anatomy of a HIPAA Breach"— Presentation transcript:
1Anatomy of a HIPAA Breach Maureen D’AgostinoSVP, Quality, Service and Performance ExcellenceColleen McCloreyAssociate General Counsel, University of Michigan Health System Legal Office
2I. Omnibus HIPAA Changes Breach notificationBusiness Associates and SubcontractorsAgencyEnforcementDetermining BreachDay to DayElectronic PerilsEMR; Laptops; Social MediaEncryptionAdministrative, Technical Physical SafeguardsOther Horror StoriesWhat To DoManagement StrategiesTraining Notice of Privacy PracticesData NeededPrivilege vs. Non-privilegeInvestigationOCR Response
3Important Dates – Omnibus Rule Published in Federal Register – January 25, 2013Effective Date – March 26, 2013Compliance Date – September 23, 2013Transition Period to Conform BA contracts – Up to September 22, 2014, for Qualifying Contracts
4Breach Notification Revised definition of breach Revised risk assessment approachCE or BA must rebut presumption of breachFocus on harm to data rather than to individualHow will this work??
5Considerations The nature and extent of the PHI involved The unauthorizied person who used access or received the PHIWhether the PHI was actually acquired or viewedThe extent to which the risk to the PHI has been mitigated
6Business Associates and Subcontractors Revised definition of “business associate”Subcontractors “all the way down the chain” are now BAsBAs and subcontractors directly liable under HIPAABAAs still required – but how to revise?Staggered deadlines for new BAAs
7Business Associates and Subcontractors Reassessment of existing BA relationshipsBAs with direct access to ePHIBA liability considerations“Satisfactory assurances” regarding safeguarding of PHI by subcontractors
8AgencyAgency relationship affects liability, breach notification timing for CEs and BAsUse federal common law of agencyWho controls conduct?Will more control = more liability?
9EnforcementMakes permanent the increased CMP amounts and tiered levels of culpability form 2009 IFRClarifies “reasonable cause” tierWillful neglect cases do not require informal resolutionIntentional wrongful disclosures may be subject to civil, rather than criminal, penaltiesAudit authority is added
10Common Breach Pitfalls Faxes can lead to extortion! Before faxing:Confirm you have the correct number and it is entered correctlyReview and update programmed numbers on a regularly basisUse an appropriate cover sheet with confidentiality clause on it and contact number at your siteAfter faxing:Confirm receipt by contacting party, do not simply rely on the fax machine transmission reportPromptly retrieve improperly faxed documents if possibleSpecial Alert: monitor and update auto fax numbers embedded in EHRs and other record systems/software – these are often easily forgotten – e.g., auto fax of record to PCP from specialists office, lab or radiology
11Common Breach Pitfalls Medical Record release can lead to extortion too and $’s:Record copy given/sent to wrong partyRecord copy sent contained another patient’s information that was not found or corrected from an entry error or registration errorIncorrect patient selection at registration due to common first and last names – train registration to ask patient for information and not simply recite file information to patient; registration should request photo id and compare information/picture to presenting patientDischarge instruction with demographic information given to wrong patientPatient wristband with some data present given to wrong patient due to registration error
12Common Breach Pitfalls - EMR Caution 1: The pitfalls mentioned are HIPPA/HITECH issues but even more important – clinical issues. Patient identification verification at all levels is critical to minimizing the impact of human error.Caution 2: OCR complaint investigator demanded copies of discharge instructions and sample of wristbands looking for demographic information to evaluate risk to patient.Caution 3: Bolt on systems/software and interfaces to the main EMR often make record correction difficult and labor intensive.Caution 4: Allegations of neglect and abuse require special handling of vulnerable adult and minor records to protect the patient post-hospitalization. Flagging sensitive records may be the only means of identifying these records such that the record service knows to take precautions before release.
13Common Breach Pitfalls – After the Elevator! Patient Bedside Verbal BreachesSpeaking with family or friends present without determining patient wishesAssuming all care conversations may occur in front of family or friends are ok based on past patient response - even ones with sensitive information?Not inquiring of person’s relationship to patient in surgical waiting – assuming person is family!Having clinical conversations while patient family in next bed are present never requesting politely for them to leave the roomStaff not asking the patient for permission to talk with family and friends present and later finding this was not acceptable when the OCR complaint inquiry comes
14Determining a Breach – FAX Case Analyze telephone/fax number and address used in “fax to” – authorized person (physician, clinic, etc) or not (commercial business, home). Reverse look-ups are often helpfulIdentify person who holds information if different from aboveIdentify type of document and contents; check audit trails if you have a staff nameWas demographic, clinical or other identification information accessed or released. Recall Medicare beneficiary number is the SS# with only modest change – a alphabetic letter typically!Locate where the fax or record was sent from (“fax from”) – not always easy with trunk lines and auto fax built into recordRetrieve incorrectly faxed information if possible, even if that means going to the home or business yourselfDetermine approx. length of time in wrong person’s possessionAssuming identifying or clinical data compromised was there opportunity for the unauthorized part to retain the documents and does this present risk to the patient – our latest interactions suggest OCR takes a near worst case scenario perspectiveFollowing the internal assessment that there is risk to the patient, notify the patient. What do you offer with notification (free credit checks)?Take and document remedial actions (policy, protocols, system changes, education, discipline) as appropriate.If unable to pinpoint fax locations have IT/Telecommunications disable the erroneous fax phone number – prevents call out. Effective disabling may require disabling the number in all trunk lines or “switches,” not just the one thought to be involvedDON’T PAY THE RANSOM! File your lawsuit to retrieve documents and get a retraining order to put risk on party if there is further disclosure! We did agree to pay for expense for ink and paper.Finally, don’t forget to file your report with OCR. FYI, in one case OCR in complaint notification letter advised they would expect a report to be filed.
15Determining a Breach - Basics Starts with the complaint or is raised by audit questionComplaint drives next steps in analysisAudit may reveal what appears to be excessive access, printing or ‘break the glass’ activity – little or no chartingEvaluate job duties, assignment, hours of work and/or work unitDetermine type of access was it for treatment, payment or operations (“TPO”)Was access/disclosure comply with ‘need to know’ and/or minimum necessary rule if applicableIf unauthorized access/disclosure occurred or likely occurred based on above, did the access/disclosure present risk or better, did the access/disclosure fit within the HIPAA/HITECH definition of breachIf yes, take action to minimize risk to patient and consistent with HIPAA/HITECH and organizational policy and past practiceBe mindful not to violate by policy or practice NRLA General Counsel opinions on ‘concerted activity.’ Focus only on the HIPAA/HITECH rule issues not on dialogue that ties to conditions of work or discussion of the work environmentFile OCR of the breach as required. Recommend doing breach reports including those that fall below the 500 person level at the time of the breach determination even though you may file an annual report. Data is readily at hand and facts are fresh in mind and doing filing on a case by case basis is more efficient than re-reviewing cases at year end
16Electronic Perils EMR; Laptops; Social Media (employees right in NLRA) GuidancePolicies and ProceduresSecurity ProtocolsBAAsAuditEncryption
17Administrative, Technical and Physical Safeguards Firewalls, tracking devices, strong password controls, tools that will activate to destroy hard drives
18Breaches Involving the Feds Government agency makes appointment to come in to talk to Compliance Officer who are wearing gunsPresents a subpoena for documentsGives little information about reasonDoes state that other government agencies are involvedPresents a list of patient names (300) to verify that yes, they were our patients
19Federal BreachesGives us 2 weeks to confirm patients and compile all documents of subpoena including sequestering the computer and do a “forensic” copy of all drives and memoryAn encrypted secured government for document delivery
20So How Did This Happen Management level employee As part of their job has access to patient demographicsSelectively based on diagnoses steals their demographics and passes the information on to a third party outside the organizationThird party submits fraudulent documents and receives government reimbursement
21ContinuedAdditional names begins to reach close to or may exceed the 500 required to do a report to the OCR. Question are these 500 distinct events or does this trigger the 500 rule in HIPAA/HITECH for OCR notification purposes let alone public noticeGovernment agency allows us to conduct our own internal investigation (beware of the obstruction argument) and to do whatever we thought appropriate with the employeeAlso told to record all conversations.Investigation is quickly done and employee is fired
22ContinuedEmployee office was searched and computer and files confiscated.All electronic sign-on’s were immediately closed down prior to termination.Multiple patient demographics found, that employee would have no reason to haveAs employee is exiting states, “ I guess I got caught up with the wrong crowd”
23Continued Open felony investigation Government agency states may take years to conclude.Also states, “that we are way down the road in the investigation for us to come here”So how did the agency pick up on this: a agent noticed the same name at the same address was too frequent and many were elderly!Internal investigation is on hold because we are not allowed to disturb the forensic information
24Strategies: How to Manage Training from entry level position to executives, including physicians which includes privacy and security policies and processMonitoring -audit trails of electronic information that is continuous such as, break the glass, same last name, address proximity locator, frequency and breath of access and printing quantificationHiring: entry into the workplace because of data access not because of healthcare interest-think, identity theft.Firewall protectionAttorney-Client Privileged information versus non-privileged-assess the potential damage, anticipate poor outcomes and negative results, media implications, regulatory implications and investigationsHow to determine if you need an investigation-start with a review or probe of information, if can’t conclude then full investigationHow to conduct one for EHR non Fax- audit reports, complaint typically received, who accessed and what they accessed along with their role, personnel who accessed, their organizational role (think in terms of TPO) treatment, payment and operations, conduct interviews, take action as appropriate with employee
25Notice of Privacy Practices Providers and plans must update NPPsAuthorization required for disclosure of psychotherapy notes, marketing communications, sale of PHIRight to breach notificationRight to opt out of fundraisingRight to restrict disclosure sot plansMost plans cannot use generic info to make underwriting decisions
26Notice of Privacy Practices -- General Clarifications on delivery of revised NPPs by providers and plansMore time likely required to change underlying policies and train than to revise NPPs