AAMC Contact: Ivy Baer 202-828-0499 Accounting for Disclosures Under HIPAA Proposed Rule: 76 Federal Register 31426, May 31, 2011.

Slides:



Advertisements
Similar presentations
Protecting Patient Privacy:
Advertisements

1 The Health Insurance Portability and Accountability Act (HIPAA) A guided tutorial for GVSU employees.
HIPAA: Privacy, Security, and HITECH, Oh My! Presented by Stephanie L. Ganucheau, Special Assistant Attorney General.
HIPAA Privacy Training. 2 HIPAA Background Health Insurance Portability and Accountability Act of 1996 Copyright 2010 MHM Resources LLC.
Confidentiality and HIPAA
HIPAA Privacy Rule Training
The Health Insurance Portability and Accountability Act of 1996– charged the Department of Health and Human Services (DHHS) with creating health information.
Changes to HIPAA (as they pertain to records management) Health Information Technology for Economic Clinical Health Act (HITECH) – federal regulation included.
HIPAA Understanding Medical Privacy in the Work Place © Copyright 2005 The Nugent Law Firm, P.C. All Rights Reserved.
NAU HIPAA Awareness Training
North Carolina State University Health Information Privacy 4/16/03.
ITEC 6324 Health Insurance Portability and Accountability (HIPAA) Act of 1996 Instructor: Dr. E. Crowley Name: Victor Wong Date: 2 Sept
HIPAA Basics A Matter of Integrity. Introduction “A Matter of Integrity” defines HIPAA and protecting patient health information. Success depends on our.
 Original Intent: ◦ Act passed in 1996 with two main goals: 1.Ensure individuals would be able to maintain their health insurance between jobs (the “portability”
Topics Rule Changes Skagit County, WA HIPAA Magic Bullet HIPAA Culture of Compliance Foundation to HIPAA Privacy and Security Compliance Security Officer.
HIPAA Privacy Rule Compliance Training for YSU April 9, 2014.
H IPAA PRIVACY WORK GROUP FOR EYE BANKS EBAA HIPAA PRIVACY WORK GROUP Christina W. Strong, Esq., Facilitator.
COMPLYING WITH HIPAA PRIVACY RULES Presented by: Larry Grudzien, Attorney at Law.
HIPAA THE PRIVACY RULE Reviewed December HISTORY In 2000, many patients that were newly diagnosed with depression received free samples of anti-
2014 HIPAA Refresher Omnibus Rule & HIPAA Security.
Jill Moore April 2013 HIPAA Update: New Rules, New Challenges.
Health Insurance Portability and Accountability Act (HIPAA)
Health Insurance Portability and Accountability Act (HIPAA)
Privacy & Security Tiger Team: Accounting of Disclosures Recommendations November 18, 2013 Office of the National Coordinator for Health Information Technology.
Privacy and Security Tiger Team Today’s Discussion: Virtual Hearing on Accounting of Disclosures August 8, 2013.
August 10, 2001 NESNIP PRIVACY WORKGROUP HIPAA’s Minimum Necessary Standard Presented by: Mildred L. Johnson, J.D.
Your HIPAA rules Ben Burton, JD, MBA, RHIA, CHP, CHC Notice of Privacy Practices.
ELECTRONIC MEDICAL RECORDS By Group 5 members: Kinal Patel David A. Ronca Tolulope Oke.
California :: Delaware :: Florida :: New Jersey :: New York :: Pennsylvania :: Virginia :: Washington, D.C. :: 1 NEW OBLIGATIONS.
Confidentiality, Consents and Disclosure Recent Legal Changes and Current Issues Presented by Pam Beach, Attorney at Law.
Dealing with Business Associates Business Associates Business Associates are persons or organizations that on behalf of a covered entity: –Perform any.
Quality Integrity Stewardship Courtesy Care Accountability Medical Records ARMA Florida Gulf Coast Chapter Michael Spake Lakeland Regional Medical Center.
FERPA Questions and Answers Lenawee Data Camps June and August, 2009.
Computerized Networking of HIV Providers Workshop Data Security, Privacy and HIPAA: Focus on Privacy Joy L. Pritts, J.D. Assistant Research Professor Health.
Privacy & Security Tiger Team: Accounting of Disclosures Recommendations December 2, 2013 Office of the National Coordinator for Health Information Technology.
HIPAA (health insurance portability and accountability act)
H I P A A T R A I N I N G Self Directed Module 7 Research Disclosures For Data Custodians START Click to begin…
Health Insurance Portability and Accountability Act (HIPAA) CCAC.
Understanding HIPAA (Health Insurandce Portability and Accountability Act)
FleetBoston Financial HIPAA Privacy Compliance Agnes Bundy Scanlan Managing Director and Chief Privacy Officer FleetBoston Financial.
HIPAA BASIC TRAINING Presented by Anderson Health Information Systems, Inc.
HIPAA THE PRIVACY RULE. 2 HISTORY In 2000, many patients that were newly diagnosed with depression received free samples of anti- depressant medications.
HITECH and HIPAA Presented by Rhonda Anderson, RHIA Anderson Health Information Systems, Inc
HIPAA History March 3, HIPAA Ruling Health Insurance Portability Accountability Act Health Insurance Portability Accountability Act Passed by Congress.
HIPAA Training Workshop #1 Council of Community Clinics – San Diego February 7, 2003 by Kaye L. Rankin Rankin Healthcare Consultants, Inc.
Davis Wright Tremaine LLP The Seventh National HIPAA Summit HIPAA Privacy: Privacy Rule Compliance on Public Health Activities and Research Thomas E. Jeffry,
Top 10 Series Changes to HIPAA Devon Bernard AOPA Reimbursement Services Coordinator.
HIPAA HEALTH INSURANCE PORTABILITY ACOUNTABILITY ACT.
Table of Contents. Lessons 1. Introduction to HIPAA Go Go 2. The Privacy Rule Go Go.
AND CE-Prof, Inc. January 28, 2011 The Greater Chicago Dental Academy 1 Copyright CE-Prof, Inc
HIPAA Training. What information is considered PHI (Protected Health Information)  Dates- Birthdays, Dates of Admission and Discharge, Date of Death.
The Medical College of Georgia HIPAA Privacy Rule Orientation.
Health Insurance Portability and Accountability Act (HIPAA) © 2013 Project Lead The Way, Inc.Principles of Biomedical Science.
New Hire HIPAA Orientation. HIPAA Overview HIPAA is an acronym that stands for the Health Insurance Portability and Accountability Act of HIPAA.
Juvenile Legislative Update 2013 Confidential Records and Protected Disclosures.
HIPAA Training Workshop #3 Individual Rights Kaye L. Rankin Rankin Healthcare Consultants, Inc.
Health Insurance Portability and Accountability Act
HIPAA Privacy Rule Training
Health Insurance Portability and Accountability Act of 1996
UNDERSTANDING WHAT HIPAA IS AND IS NOT
HIPAA THE PRIVACY RULE Reviewed December 2012.
Health Insurance Portability and Accountability Act
10 Patient Confidentiality and HIPAA
The HIPAA Privacy Rule: Implications for Medical Research
HIPPA/HITECH Act Requirements Under the Business Associate Agreement Between CNI and Military Health Services.
Health Insurance Portability and Accountability Act
The Health Insurance Portability and Accountability Act
Objectives Describe the purposes of the Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009 Explore how the HITECH Act.
Health Insurance Portability and Accountability Act
Introduction to the PACS Security
Presentation transcript:

AAMC Contact: Ivy Baer Accounting for Disclosures Under HIPAA Proposed Rule: 76 Federal Register 31426, May 31, 2011

Proposed rule implements § 13405(c) of the Health Information Technology for Economic an Clinical Health (HITECH) Act Creates 2 separate rights: 1.Accounting for disclosures is extended to electronic health records 2.Access report Two Separate Rights 2

30 days to respond to request (30 day extension possible) Accounting goes back 3 years; must retain copy of the accounting for 6 years Applies to protected health information in a designated record set— hard copy or electronic—of a covered entity or business associate Limited to the following disclosures: breaches (unless individual already notified); public health activities (except for child abuse or neglect); judicial and administrative hearings; law enforcement purposes; to avert a serious threat to public health or safety; for military and veterans activities, Department of State’s medical suitability determinations, and government programs providing public benefit; and for workers’ compensation 1. Accounting for Disclosures 3

Currently, there is an exemption for disclosure for research purposes (45 § (i)) Proposal is to retain this exemption Research Exemption 4

What’s in the access report? Covers disclosures and uses of information, including uses by the workforce and business associates Applies to all electronic protected health information about an individual in any designated record set! There is no exemption for research Comment: The government believes this will not be overly burdensome because the HIPAA Security Rule already requires that logs of access to electronic PHI be maintained 2. Access Report 5

Proposal: If you have multiple systems that each maintains a separate access log, “our expectation is that data from each access log will be gathered and aggregated to generate a single access report (including data from business associates’ systems)” that is understandable to the individual Definition of access log: the raw data that an electronic system containing PHI collects each time a user accesses information Access Report Cover All Logs 6

Name of person accessing, if available Date and time of access Description of what information was accessed, if available Comments requested on: availability of this information in current access logs, importance of the information to individuals, potential administrative burden of requiring that access reports include description of information that was accessed Description of action taken by user of the information (created, modified, deleted, or just accessed record) For Inclusion in Access Report 7

Accounting for disclosures: Effective 60 days after publication 240 days after publication to comply Access report: For any electronic designated record set systems acquired after January 1, 2009: must produce a report starting January 1, 2013 For any electronic designated record set systems acquired before January 1, 2009: must produce a report starting January 1, 2014 Important Dates 8

Please contact Ivy Baer, if you have questions, concerns, or are willing to share information to be included in the AAMC comment letter in de- identified form, regarding issues such The difficulty of converting Security Rule Access Logs into information that will be understandable to a patient, focusing on cost and time. Other concerns, such as revealing the name of employees to patients For AAMC’s Comment Letter 9

If you send your own letter: Comments are due August 1, 2011 Submit to: Use RIN 0991-AB62 to identify your comments Please send a copy to: If you want to comment 10