HIPAA Privacy What Every Staff Member Needs to Know.

Slides:



Advertisements
Similar presentations
HIPAA Privacy Practices. Notice A copy of the current DMH Notice must be posted at each service site where persons seeking DMH services will be able to.
Advertisements

Protect Our Students Protect Ourselves
Independent Contractor Orientation HIPAA What Is HIPAA? Health Insurance Portability and Accountability Act of 1996 The Health Insurance Portability.
Privacy and Information Security Training ( ) VUMC Privacy Website
1. As a Florida KidCare community partner families entrust you to not only help them navigate the Florida KidCare system but to keep the information they.
HIPAA Privacy Training. 2 HIPAA Background Health Insurance Portability and Accountability Act of 1996 Copyright 2010 MHM Resources LLC.
Health Insurance Portability and Accountability Act HIPAA Education for Volunteers and Students.
HIPAA. What Why Who How When What Is HIPAA? Health Insurance Portability & Accountability Act of 1996.
HIPAA Basic Training for Privacy & Information Security Vanderbilt University Medical Center VUMC HIPAA Website:
Confidentiality and HIPAA
HIPAA Privacy Rule Training
COBB/DOUGLAS COMMUNITY SERVICES BOARD Confidentiality and Privacy of Consumer Information.
HIPAA Privacy Training Your Name Here. © 2004 MHM Resources Inc.2 HIPAA Background Health Insurance Portability and Accountability Act of 1996.
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
The Health Insurance Portability and Accountability Act of 1996– charged the Department of Health and Human Services (DHHS) with creating health information.
The HIPAA Privacy Training Video for EMS Field Providers
HIPAA Health Insurance Portability & Accountability Act.
HIPAA 101 Education. WHAT IS HIPAA??? WHAT IS HIPAA? The Health Insurance Portability and Accountability Act The Health Insurance Portability and Accountability.
What is HIPAA? This presentation was created by The University of Arizona Privacy Office, The Office for the Responsible Conduct of Research on March 5,
1 HIPAA Education CCAC Professional Development Training September 2006 CCAC Professional Development Training September 2006.
NAU HIPAA Awareness Training
1 Louisiana Department of Health and Hospitals Basic HIPAA Privacy Training: Policies and Procedures 01/09/
Before reviewing the following presentation click on the links below and print off the documents: NAM-43 The Bair Foundation HIPAA Policy NAM- 89 HIPAA.
Are you ready for HIPPO??? Welcome to HIPAA
HIPAA How can you maintain patient privacy and confidentiality? General Medicine LCCA.
HIPAA HIPAA Health Insurance Portability and Accountability Act of 1996.
Professional Nursing Services.  Privacy and Security Training explains:  The requirements of the federal HIPAA/HITEC regulations, state privacy laws.
Protecting Client Data HIPAA, HITECH and PIPA Part 1A
RVCC FACULTY FERPA WORKSHOP OCTOBER 2011 DAN PALUBNIAK REGISTRAR
SAFEGUARDING DHS CLIENT DATA PART 2 SAFEGUARDING PHI AND HIPAA Safeguards must: Protect PHI from accidental or intentional unauthorized use/disclosure.
V OLUNTEER P RIVACY AND INFORMATION SECURITY T RAINING VA San Diego Healthcare System.
HIPAA What’s Said Here – Stays Here…. WHAT IS HIPAA  Health Insurance Portability and Accountability Act  Purpose is to protect clients (patients)
HIPAA COMPLIANCE IN YOUR PRACTICE MARIBEL VALENTIN, ESQUIRE.
HIPAA Basic Training for Privacy and Information Security Vanderbilt University Medical Center VUMC HIPAA Website: HIPAA Basic.
HIPAA Privacy & Security EVMS Health Services 2004 Training.
Protected Health Information (PHI). Privileged Communication An exchange of information between two individuals in a confidential relationship. (Examples:
HIPAA PRIVACY AND SECURITY AWARENESS.
Privacy and Security of Protected Health Information NorthPoint Health & Wellness Center 2011.
HIPAA OBJECTIVES  Define HIPAA  Define PHI  Use of PHI  Your rights  Your responsibilities.
Next ETCH Confidentiality and HIPAA Annual Review What you need to know. The Privacy Rule 1.
HIPAA Training Developed for Ridgeview Institute 2012 Hospital Wide Orientation.
HIPAA (health insurance portability and accountability act)
Medical Law and Ethics, Third Edition Bonnie F. Fremgen Copyright ©2009 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved.
Building a Privacy Foundation. Setting the Standard for Privacy Health Insurance Portability and Accountability Act (HIPAA) Patient Bill of Rights Federal.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
Mr. Fleming.  Law passed by Congress in  Right to Privacy ◦ Medical information of patient can only be shared with doctor and professionals administering.
PricewaterhouseCoopers 1 Administrative Simplification: Privacy Audioconference April 14, 2003 William R. Braithwaite, MD, PhD “Doctor HIPAA” HIPAA Today.
HIPAA BASIC TRAINING Presented by Anderson Health Information Systems, Inc.
HIPAA BASIC TRAINING MODULE 1C – Overview (For staff who do not generally create Protected Health Information) Anderson Health Information Systems, Inc.
HIPAA PRACTICAL APPLICATION WORKSHOP Orientation Module 1B Anderson Health Information Systems, Inc.
Rhonda Anderson, RHIA, President  …is a PROCESS, not a PROJECT 2.
A Road Map to Research at Jefferson: HIPAA Privacy and Security Rules for Researchers Presented By: Privacy Officer/Office of Legal Counsel October 2015.
HIPAA Overview Why do we need a federal rule on privacy? Privacy is a fundamental right Privacy can be defined as the ability of the individual to determine.
Table of Contents. Lessons 1. Introduction to HIPAA Go Go 2. The Privacy Rule Go Go.
Aged and Disabled Waiver (ADW) Health Insurance Portability and Accountability Act (HIPAA) Training 2015 October 2015.
HIPAA HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT UI EMS Training Dept.
The Health Insurance Portability and Accountability Act (HIPAA) requires Plumas County to train all employees in covered departments about the County’s.
Health Insurance Portability and Accountability Act (HIPAA) Primer for Observers, Volunteers, Medical Students Dr. Michael Palumbo- Privacy Officer/ EVP.
Health Insurance Portability and Accountability Act of 1996
HIPAA Privacy & Security
HIPAA PRIVACY AWARENESS, COMPLIANCE and ENFORCEMENT
Disability Services Agencies Briefing On HIPAA
CONTRACTS PRIVILEGED COMMUNICATION PRIVACY ACT
HIPAA Privacy & Security
The Health Insurance Portability and Accountability Act
HIPAA & PHI TRAINING & AWARENESS
CONTRACTS PRIVILEGED COMMUNICATION PRIVACY ACT
HIPAA Do’s and Don'ts: What is Really Behind Protected Health Information (PHI) and Health Care Privacy Rules Paul Sisler, Director, Information Services;
The Health Insurance Portability and Accountability Act
Presentation transcript:

HIPAA Privacy What Every Staff Member Needs to Know

Goals of Training Define HIPAA law Define HIPAA law Clarify what things need to be kept private Clarify what things need to be kept private Determine your role in maintaining privacy at Paraquad Determine your role in maintaining privacy at Paraquad Inform you of who to contact on issues related to privacy Inform you of who to contact on issues related to privacy Consequences of not maintaining privacy Consequences of not maintaining privacy

What is HIPAA? Health Insurance Portability and Accountability Act of 1996 Health Insurance Portability and Accountability Act of 1996 Federal Law: Public Law (in 2003) Federal Law: Public Law (in 2003) Privacy Rule issued by the U.S. Dept of Health and Human Services Privacy Rule issued by the U.S. Dept of Health and Human Services

HIPAA Enforcement What is the penalty for not enforcing HIPAA? Minimum $100 fine per person (civil). Minimum $100 fine per person (civil). You can be personally liable! You can be personally liable! In some cases, jail time and steeper fines may apply. In some cases, jail time and steeper fines may apply.

The HIPAA law applies to ALL forms of communication – even ORAL.

What is PHI? Protected Health Information

Examples of PHI Name Name Address Address Telephone # Telephone # Date of Birth Date of Birth SSN SSN Names of Relatives Names of Relatives Case File # Occupation Diagnosis Treatment Procedures Plan of Care

Where do we find PHI? Case files Case files In paper that needs shredding In paper that needs shredding On the computer; in PRISM On the computer; in PRISM In people’s cubicles and offices In people’s cubicles and offices Left on the printer (remove print-outs promptly) Left on the printer (remove print-outs promptly) On drivers’ pick up sheets On drivers’ pick up sheets

How Can You Maintain Confidentiality Don’t discuss private information in public settings. Don’t discuss private information in public settings. Don’t talk so loud that others hear you. Don’t talk so loud that others hear you. Do not use speaker phone in an open area. Do not use speaker phone in an open area. Don’t leave participant information where others can view it or access the information. Don’t leave participant information where others can view it or access the information. Keep diagnosis and disability-related information private. Keep diagnosis and disability-related information private.

“Need to Know” Principles How much do you need to know? How much do you need to know? How much do other people need to know? How much do other people need to know?

HIPAA Consumer Protections Notice of Privacy Practices Notice of Privacy Practices –Participants must know when we share their information with someone outside of Paraquad. –Must be written in plain language. –Must be provided at the time of first service or assessment for eligibility.

HIPAA Consumer Protections Amendment Amendment –Participants can request to change information in their files –That request may be made to Paraquad’s Privacy Officer. –Paraquad may either grant OR deny the request.

HIPAA Consumer Protections Restrictions Restrictions –Participants can request certain parts of their health information not be shared with others. –Paraquad is NOT required to accept the request. –If restriction is accepted, then Paraquad has to follow it.

HIPAA Consumer Protections Access Access –Participants can request to see or copy their information. –Request for access MUST be in writing. –If access is denied, the participant can appeal. –Consumer must appeal to Paraquad’s Privacy Officer.

HIPAA Disclosure Protections Authorization Authorization –Participants must give written permission for their information to be shared with anyone outside of Paraquad. –You must be specific:  What PHI is to be shared;  With whom;  For what purpose.

When No Authorization is Needed… Key examples: Key examples: –Abuse or neglect reports –Court Orders –Police need information –To help keep someone else safe

HIPAA Consumer Protections Accounting of Disclosures Accounting of Disclosures –Participant can ask who their information was shared with. –Applies to both verbal and written disclosure. –All disclosures are to be noted in the participant file.

HIPAA Consumer Protections Verification Verification –Paraquad must verify the person or agency requesting the information is who they say they are.

HIPAA Consumer Protections Complaint Procedure Complaint Procedure –Allows participant to file a complaint if it is felt that PHI has been improperly used or disclosed. –That complaint is to be filed with Paraquad’s Privacy Officer.

What Else Does HIPAA Require? Research Research –HIPAA still allows research to be conducted. –Proper authorizations must be in place.

QUESTIONS? If you are ever in doubt, always ask your Privacy Officer. If you are ever in doubt, always ask your Privacy Officer.

Summary We must all protect participant records. We must all protect participant records. Share only the information necessary for people to do their jobs. Share only the information necessary for people to do their jobs. Participants have the right to ask about use and disclosure of PHI. Participants have the right to ask about use and disclosure of PHI. Paraquad has a HIPAA policy that you need to know and follow. Paraquad has a HIPAA policy that you need to know and follow.

Security: Integration with HIPAA Privacy

Purpose of Security Purpose of Security To protect the computer system and information from unauthorized access To protect the computer system and information from unauthorized access To protect the computer system and information from misuse To protect the computer system and information from misuse

General Security Awareness Building/Physical Security Building/Physical Security –Building/Work Area Sign-in  All participants and visitors must sign in at the front desk and must be escorted around the building. If person is unescorted (EMC, bathroom) they must stay in the main hallway, not to enter any work areas. Do not ask the front desk to ‘send them back’ to you. –Locks and Keys  Keep keys in secure location or carry it on your person. –Front Door Code  Do not share with anyone. –Key Fob  Keep it on your person. You will be charged $10.00 for a replacement. –Printers/Copiers/Fax Machines  Pick up print-outs/copies promptly

General Security Awareness Computer/Electronic Security Computer/Electronic Security –Computers  Do not allow participants to use your computer. Assist them in using the computer lab pc’s. Lock your computer (Windows key + L) each time you leave your desk. –  Limit personal so that outsiders do not have access to our addresses.  Don’t open attachments from friends.

Password Management When you have a special Password: When you have a special Password: –Don’t tell anyone your password. –Don’t write your password down. –Change your password if others know it. –Pick a password you can remember.

Remember! Remember! Computer System security impacts privacy Computer System security impacts privacy Both building and computer security are essential! Both building and computer security are essential!

THE END Please take HIPAA quiz now. Please take HIPAA quiz now.