Enforcement and Policy Challenges in Health Information Privacy

Slides:



Advertisements
Similar presentations
Tamtron Users Group April 2001 Preparing Your Laboratory for HIPAA Compliance.
Advertisements

H = P = A = HIPAA DEFINED HIPAA … A Federal Law Created in 1996 Health
HIPAA Privacy Practices. Notice A copy of the current DMH Notice must be posted at each service site where persons seeking DMH services will be able to.
1. As a Florida KidCare community partner families entrust you to not only help them navigate the Florida KidCare system but to keep the information they.
Confidentiality and HIPAA
National Health Information Privacy and Security Week Understanding the HIPAA Privacy and Security Rule.
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
HIPAA What’s New? What Is HIPAA Health Insurance Portability and Accountability Act of 1996 Health Insurance Portability and Accountability Act.
HIPAA PRIVACY REQUIREMENTS Dana L. Thrasher Constangy, Brooks & Smith, LLC (205) ; Victoria Nemerson.
Information Risk Management Key Component for HIPAA Security Compliance Ann Geyer Tunitas Group
What is HIPAA? This presentation was created by The University of Arizona Privacy Office, The Office for the Responsible Conduct of Research on March 5,
Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna
WHAT IS HIPAA? The Health Insurance Portability and Accountability Act of 1996 (HIPAA) provides certain protections for any of your health information.
TM The HIPAA Privacy Rule: Safeguarding Health Information in Research and Public Health Practice Centers for Disease Control and Prevention Beverly A.
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996 (HIPAA)
HIPAA Privacy Rule Compliance Training for YSU April 9, 2014.
Walking Through the Breach Notification Process - Beginning to End HIPAA COW Presentation and Panel April 8, 2011.
Informed Consent and HIPAA Tim Noe Coordinating Center.
HIPAA COMPLIANCE IN YOUR PRACTICE MARIBEL VALENTIN, ESQUIRE.
Implementing and Enforcing the HIPAA Privacy Rule.
1 HIPAA Security Overview Centers for Medicare & Medicaid Services (CMS)
HIPAA PRIVACY AND SECURITY AWARENESS.
“ Technology Working For People” Intro to HIPAA and Small Practice Implementation.
Office of the Secretary Office for Civil Rights (OCR) Indian Health Service HIPAA Training Hosted by the Aberdeen Area Office July 24, 2012.
Health Insurance Portability and Accountability Act (HIPAA)
Compliance and Enforcement of the Privacy Rule. HHS/OCR February/March Compliance Date  April 14, 2003 – Compliance for all but small health plans.
Copyright ©2011 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved. Health Information Technology and Management Richard.
Update on Federal HIT Legislation Kirsten Beronio Mental Health America.
How Hospitals Protect Your Health Information. Your Health Information Privacy Rights You can ask to see or get a copy of your medical record and other.
HIPAA Michigan Cancer Registrars Association 2005 Annual Educational Conference Sandy Routhier.
Medical Law and Ethics, Third Edition Bonnie F. Fremgen Copyright ©2009 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved.
Health Insurance Portability and Accountability Act (HIPAA) CCAC.
Copyright © 2009 by The McGraw-Hill Companies, Inc. All Rights Reserved. McGraw-Hill Chapter 6 The Privacy and Security of Electronic Health Information.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
Understanding HIPAA (Health Insurandce Portability and Accountability Act)
© 2013 The McGraw-Hill Companies, Inc. All rights reserved. Ch 8 Privacy Law and HIPAA.
Reflections on the State of Privacy Risk Management in Health Care Benefits Administration (one year and counting …) Mark Lutes, Esq. Partner Epstein Becker.
FleetBoston Financial HIPAA Privacy Compliance Agnes Bundy Scanlan Managing Director and Chief Privacy Officer FleetBoston Financial.
Policies for Information Sharing April 10, 2006 Mark Frisse, MD, MBA, MSc Marcy Wilder, JD Janlori Goldman, JD Joseph Heyman, MD.
Rhonda Anderson, RHIA, President  …is a PROCESS, not a PROJECT 2.
Copyright ©2014 by Saunders, an imprint of Elsevier Inc. All rights reserved 1 Chapter 02 Compliance, Privacy, Fraud, and Abuse in Insurance Billing Insurance.
C HAPTER 34 Code Blue Health Sciences Edition 4. Confidentiality of sensitive information is an important issue in healthcare. Breaches of confidentiality.
HIT Policy Committee NHIN Workgroup HIE Trust Framework: HIE Trust Framework: Essential Components for Trust April 21, 2010 David Lansky, Chair Farzad.
Copyright © 2015 by Saunders, an imprint of Elsevier Inc. All rights reserved. Chapter 3 Privacy, Confidentiality, and Security.
HIPAA Privacy Rule Implementation Status Report Richard M. Campanelli, J.D. Director, Office for Civil Rights Before the The Tenth National HIPAA Summit.
HIT Policy Committee Meeting Nationwide Health Information Network Governance June 25, 2010 Mary Jo Deering, PhD ONC, Office of Policy and Planning NHIN.
HIPAA Overview Why do we need a federal rule on privacy? Privacy is a fundamental right Privacy can be defined as the ability of the individual to determine.
 Health Insurance and Accountability Act Cornelius Villalon Jr.
The Health Insurance Portability and Accountability Act of 1996 “HIPAA” Public Law
Office of the Secretary Office for Civil Rights (OCR) Update: Enforcement of the HIPAA Privacy Rule HIPAA Summit August 19, 2008.
Office of the Secretary Office for Civil Rights (OCR) Enforcement and Policy Challenges in Health Information Privacy Linda Sanches HIPAA Summit Special.
Health Insurance Portability and Accountability Act
HIPAA Privacy Rule Training
Health Insurance Portability and Accountability Act of 1996
HIPAA THE PRIVACY RULE Reviewed December 2012.
HIPAA CONFIDENTIALITY
HIPAA Administrative Simplification
Health Insurance Portability and Accountability Act
HIPAA PRIVACY AWARENESS, COMPLIANCE and ENFORCEMENT
Disability Services Agencies Briefing On HIPAA
HIPAA Pros - Minimum Necessary
American Health Information Management Association
National Congress on Health Care Compliance
HIPAA Policy & Procedure Strategies
THE 13TH NATIONAL HIPAA SUMMIT HEALTH INFORMATION PRIVACY & SECURITY IN SHARED HEALTH RECORD SYSTEMS SEPTEMBER 26, 2006 Paul T. Smith, Esq. Partner,
Objectives Describe the purposes of the Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009 Explore how the HITECH Act.
Compliance and Enforcement of the Privacy Rule
Update: Enforcement of the HIPAA Privacy Rule
HIPAA Privacy and Security Update - 5 Years After Implementation
Presentation transcript:

Enforcement and Policy Challenges in Health Information Privacy The Privacy Symposium August 22, 2007

Topics Privacy Rule enforcement Other challenges Emergency preparedness Patient Safety Act Nationwide Health Information Network Genetic non-discrimination legislation Technical assistance

Complaint Investigations Every complaint received by OCR is reviewed An investigation is conducted where warranted by the facts and circumstances presented by the complaint Privacy investigations have resulted in changes in privacy practices and other corrective actions in over 4,800 cases since April 2003 Corrective action obtained by HHS from covered entities has resulted in systemic change that affects all the individuals they serve OCR investigates all complaints that are timely filed, describes a possible violation of the PR, and complainant consents (when necessary).

OCR refers complaints alleging actions that would violate the Security Rule to the Office of E-health Standards and Services (OESS) of CMS There is a coordinated investigative and enforcement process for complaints that allege facts that may be potential violations of the Privacy Rule and Security Rule For example, notification letter to the CE will mention both rules and indicate that OCR is the lead agency for communications (such as data requests) with CE Each agency retains its own authority to investigate compliance with its rule and make its own determination (e.g., no violation, informal resolution, or CMP)

Pie Chart: All Complaints

Pie Chart: Total Investigated

Investigated Resolutions

Case Example An employee of a major health insurer impermissibly disclosed the protected health information of one of its members without following the insurer’s authorization and verification procedures. Among other corrective actions to resolve the specific issues in the case, OCR required the health insurer to train its staff on the applicable policies and procedures and to mitigate the harm to the individual apply sanctions to employee who made the disclosure

Nationwide Health Information Network Privacy and Security Are Integral to NHIN Necessary for Public Trust Public Participation Is Engine for Adoption HIPAA Levels Playing Field Nationally Accepted Standards for Privacy and Security Already in Place Uniform National Baseline of Protection – More Is Still Good

NHIN & Privacy HIPAA Privacy Rule as Facilitator – Not Obstacle to Health IT adoption Standards Reflect Many Hard Choices Balancing Privacy and Access in Healthcare Setting Narrows Privacy Debate to New Areas of Risk and Opportunity for Consumers Flexibility Allows Rules to Adapt to HIE Needs without Lowering Baseline for All Personal Health Record (PHR) Good Illustration for Assessing New Risks and Opportunities

Opportunities for PHR Personal Health Record (PHR) = Opportunities for the Consumer to Engage in NHIN and Take Advantage of Health IT 24/7 Access to Their Health Information Ability to Migrate Information into PHR to Create a Longitudinal Health Record Ability to Consolidate Health Information from Multiple Providers to Better Manage Their Own Care Capability to Control Access by Others Requires Interoperable, Portable, Secure PHR

Gaps for Privacy & NHIN Accountability New Players Typically Not Covered by HIPAA Certain Health Care Providers Providers of Network Services Providers of Data Management Services Providers of PHR Services Can Business Associate Contracts Work and Provide Adequate Accountability in the NHIN?

Gaps for Privacy & NHIN Uniformity – How Much Is Really Needed Preemption Harmonizing Federal and State Laws Ex: Consents “Flexible and Scalable” Standards Harmonizing Business Practices Ex: Minimum Necessary Privacy and Security Solutions for Interoperable Health Information Exchange Looking for Answers

GINA Genetic Information Non-Discrimination Act –passed House April 2007 Companion bill in Senate to protect individuals from discrimination in health insurance and employment on the basis of genetic information Calls for changes to Privacy Rule to prevent use of genetic information for underwriting, eligibility determinations Many policy, definitional issues to iron out

Patient Safety and Quality Improvement Act Establishes voluntary reporting system to enhance the data available to assess and resolve patient safety and quality issues Provides Federal privilege & confidentiality protections for "patient safety work product” OCR to enforce confidentiality provisions In close coordination with AHRQ, OCR will develop and operate the Act's enforcement program

Emergency Preparedness Emergency preparedness and recovery planners are interested in the availability of protected health information (PHI) Disasters and emergencies National Disaster Medical System Pandemic and All-Hazards Preparedness Act implementation The HIPAA Privacy Rule permits covered entities to disclose PHI for a variety of public health and other purposes OCR providing technical assistance Web tool addresses avenues of information flow that could apply to emergency preparedness activities

Getting out the message Targeting outreach Assisting entities with compliance through technical assistance Informing the public about how the Privacy Rule applies in emerging issues

Other Program Challenges Strategic management of enforcement portfolio Policy development—balanced & workable Rule

OCR Web Site http://www.hhs.gov/ocr/hipaa/ The full text of the Privacy Rule HIPAA Privacy Rule summary Covered entity "decision tool" to assist individuals and entities in making these determinations Over 200 frequently asked questions Fact sheets Information about the OCR enforcement program