HIPAA Overview.

Slides:



Advertisements
Similar presentations
HIPAA and Public Health 2007 Epi Rapid Response Team Conference.
Advertisements

HIPAA Privacy Training. 2 HIPAA Background Health Insurance Portability and Accountability Act of 1996 Copyright 2010 MHM Resources LLC.
COBB/DOUGLAS COMMUNITY SERVICES BOARD Confidentiality and Privacy of Consumer Information.
HIPAA – Privacy Rule and Research USCRF Research Educational Series March 19, 2003.
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
The Health Insurance Portability and Accountability Act of 1996– charged the Department of Health and Human Services (DHHS) with creating health information.
WORKFORCE CONFIDENTIALITY HIPAA Reminders. HIPAA 101 The Health Insurance Portability and Accountability Act (HIPAA) protects patient privacy. HIPAA is.
HIPAA Health Insurance Portability and Accountability Act.
1 HIPAA Education CCAC Professional Development Training September 2006 CCAC Professional Development Training September 2006.
NAU HIPAA Awareness Training
HIPAA Health Insurance Portability and Accountability Act 1.
Informed Consent.
HIPAA Privacy Rule Compliance Training for YSU April 9, 2014.
 The Health Insurance Portability and Accountability Act of  Federal Law designed to protect sensitive information.  HIPAA violations are enforced.
Health Insurance Portability & Accountability Act “HIPAA” To every patient, every time, we will provide the care that we would want for our own loved ones.
Are you ready for HIPPO??? Welcome to HIPAA
HIPAA HIPAA Health Insurance Portability and Accountability Act of 1996.
Professional Nursing Services.  Privacy and Security Training explains:  The requirements of the federal HIPAA/HITEC regulations, state privacy laws.
Protecting Client Data HIPAA, HITECH and PIPA Part 1A
HIPAA Training Presentation for New Employees How did we get here? HIPAA Police 1.
HEAVEN’S HANDS COMMUNITY SERVICE H.I.P.A.A. What is HIPAA? HIPAA stands for the Health Insurance Portability and Accountability Act, which was passed.
HIPAA What’s Said Here – Stays Here…. WHAT IS HIPAA  Health Insurance Portability and Accountability Act  Purpose is to protect clients (patients)
HIPAA COMPLIANCE IN YOUR PRACTICE MARIBEL VALENTIN, ESQUIRE.
Health Insurance Portability and Accountability Act (HIPAA)
HIPAA – Health Insurance Portability & Accountability Act and the Privacy Act MSgt Nechele M. Chambers Senior Enlisted Liaison TRICARE Area Office-Europe.
HIPAA Privacy & Security EVMS Health Services 2004 Training.
The University of Kansas Medical Center Shadow Experience Training.
Protected Health Information (PHI). Privileged Communication An exchange of information between two individuals in a confidential relationship. (Examples:
Paula Peyrani, MD Medical/Project Director, HIV Program at the 550 Clinic Assistant Director, Research Design and Development Clinical and Translational.
HIPAA PRIVACY AND SECURITY AWARENESS.
Privacy and Security of Protected Health Information NorthPoint Health & Wellness Center 2011.
1 HIPAA OVERVIEW ETSU. 2 What is HIPAA? Health Insurance Portability and Accountability Act.
HIPAA (health insurance portability and accountability act)
HIPAA – How Will the Regulations Impact Research?.
Health Insurance Portability and Accountability Act (HIPAA) CCAC.
Copyright © 2009 by The McGraw-Hill Companies, Inc. All Rights Reserved. McGraw-Hill Chapter 6 The Privacy and Security of Electronic Health Information.
HIPAA Pre-Clerkship Review Dr. Maryann Skrabal, Pharm.D., CDE.
A Road Map to Research at Jefferson: HIPAA Privacy and Security Rules for Researchers Presented By: Privacy Officer/Office of Legal Counsel October 2015.
HIPAA and Human Subjects Research IRB Member CE May 2014 Slideshow by Sean Horkheimer.
Configuring Electronic Health Records Privacy and Security in the US Lecture b This material (Comp11_Unit7b) was developed by Oregon Health & Science University.
HIPAA Overview Why do we need a federal rule on privacy? Privacy is a fundamental right Privacy can be defined as the ability of the individual to determine.
HIPAA Training. What information is considered PHI (Protected Health Information)  Dates- Birthdays, Dates of Admission and Discharge, Date of Death.
Final HIPAA Privacy Rule: The Research Provisions Julie Kaneshiro DHHS Office for Human Research Protections Phone: Fax:
The Health Insurance Portability and Accountability Act (HIPAA) requires Plumas County to train all employees in covered departments about the County’s.
Properly Safeguarding Personally Identifiable Information (PII) Ticket Program Manager (TPM) Social Security’s Ticket to Work Program.
Reviewed by: Gunther Kohn Chief Information Officer, UB School of Dental Medicine Date: October 20, 2015 Approved by: Sarah L. Augustynek Compliance Officer,
UC Riverside Health Training and Development
Developed for Ridgeview Institute 2015 Hospital Wide Orientation
Health Insurance Portability and Accountability Act
HIPAA Privacy Rule Training
Protecting PHI & PII 12/30/2017 6:45 AM
HIPAA PRIVACY & SECURITY TRAINING
HIPAA Privacy & Security
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA)
Privacy & Confidentiality
Privacy Notice - Requirements
Health Insurance Portability and Accountability Act
Disability Services Agencies Briefing On HIPAA
The Health Insurance Portability and Accountability Act
Health Insurance Portability and Accountability Act
HIPAA Privacy & Security
HIPAA SECURITY RULE Copyright © 2008, 2006, 2004 by Saunders an imprint of Elsevier Inc. All rights reserved.
The Health Insurance Portability and Accountability Act
HIPAA & PHI TRAINING & AWARENESS
The Health Insurance Portability and Accountability Act
Health Insurance Portability and Accountability Act
HIPAA Do’s and Don'ts: What is Really Behind Protected Health Information (PHI) and Health Care Privacy Rules Paul Sisler, Director, Information Services;
Health Insurance Portability and Accountability Act
The Health Insurance Portability and Accountability Act
Presentation transcript:

HIPAA Overview

Summary What is HIPPA? HIPPA & Patient Privacy Patient Privacy PHI at Medtronic What can you do?

What is HIPAA? The Health Insurance Portability and Accountability Act (HIPAA) was enacted August 21st, 1996. Its purpose is to assure that individuals’ health information is protected.

What is HIPAA? HIPAA is a federal law that affects: The way Medtronic obtains medical information from Health Care providers and how we provide technical support, product safety, and quality. How Medtronic uses, discloses, and maintains the information.

HIPAA & Patient Privacy So what exactly is private information? HIPAA describes it as “protected health information (PHI).” PHI is individually identifiable health information in any form, oral or written; and Is created or received by a health care provider, health plan, employer, or health care clearinghouse; and Relates to the past, present or future physical or mental health of condition of an individual; the provision of health care to an individual; or the past, present or future payment for the provision of health care to an individual; and Identifies the individual; or with respect to which there is a reasonable basis to believe the information can be used to identify the individual.

HIPAA & Patient Privacy Individually identifiable information includes: Names Location - including street address, zip code, etc. Dates (except year) Ages over 89 - including years Telephone numbers Fax numbers Email addresses SSNs Medical record numbers Health plan numbers Account numbers Certification/License numbers Device identifiers/serial numbers URLs IP address numbers Biometric identifiers Photographic images

HIPAA & Patient Privacy Medtronic U.S. Patient Privacy Principles: Preservation of, and respect for, our customers’ trust is critical to our continued success. We will always treat such patient information: -Confidentially, according to applicable laws -Appropriately, according to the promises we make to our customers -Respectfully, in honor of the patients’ willingness to trust us to use the sensitive information to oversee the quality, safety and effectiveness of the devices that they make part of their daily lives

PHI at Medtronic Appropriate Uses: Device Tracking Field Actions or other Quality Investigations Therapy and Technical Support for Patient’s Device Other MDT Legal Requirements Medtronic Operations and Audit Support *If ever in doubt contact the legal department.

PHI at Medtronic Inappropriate uses: Marketing purposes -Privacy laws allow certain limited exceptions, approval from legal is required for any use of PHI for marketing Any use or access of PHI information beyond your job function.

What can you do? PREVENT THEFT RESTRICT E-MAIL OF PATIENT INFORMATION Secure your laptop, PDA, and any programmers you have in your possession. Keep them with you at all times and do not leave them in cars or other locations unattended RESTRICT E-MAIL OF PATIENT INFORMATION Only use email to send patient-identifiable information if the transmission is encrypted, or within the Medtronic email network. If you need to communicate procedure-related information for billing purposes or limited, logistical information (appointments, mailings, etc.), do not include the patient’s SSN, use only patient initials and do not include patient medical information such as medical condition or historical diagnosis When faxing confidential information, call ahead to confirm the recipient will be standing by to receive your fax. DON’T USE PORTABLE STORAGE Do not copy and store patient personal or health information on portable storage devices or public or remote computers, and do not send patient information via unencrypted email or other open networks (subject to above guidance)

What can you do? Electronically stored PHI Keep only for as long as absolutely necessary Delete as soon as possible Most data on MDT laptops is encrypted. Do not tamper with it! Use standard folders to store sensitive records (i.e. My Documents)

What can you do? Prominently mark confidential information as “MEDTRONIC BUSINESS CONFIDENTIAL” or “MEDTRONIC PERSONAL CONFIDENTIAL” Do not produce copies of MDT Confidential information unless necessary. Dispose of confidential information in designated shredder bins or according to procedures outlined for your specific location or function. If you think you may have leaked information, contact your manager immediately to begin remediation of exposed information. If someone is requesting confidential information (i.e. patient records), refer them to your Compliance/Legal Department to ensure appropriate processes are followed.

What can you do? Be aware of and comply with: MDT Information Risk Management Information Classification Standard This categorizes MDT Information into personal confidential (includes PHI), Business Confidential and Controlled (all other) information. It also proscribes minimal security requirements for protecting each classification of data.