Office of Audit, Compliance & Privacy

Slides:



Advertisements
Similar presentations
Independent Contractor Orientation HIPAA What Is HIPAA? Health Insurance Portability and Accountability Act of 1996 The Health Insurance Portability.
Advertisements

1 The Health Insurance Portability and Accountability Act (HIPAA) A guided tutorial for GVSU employees.
HIPAA: Privacy, Security, and HITECH, Oh My! Presented by Stephanie L. Ganucheau, Special Assistant Attorney General.
HIPAA Privacy Rule Training
COBB/DOUGLAS COMMUNITY SERVICES BOARD Confidentiality and Privacy of Consumer Information.
The Health Insurance Portability and Accountability Act Basic HIPAA Training For CMU workforce with access to PHI.
HIPAA – Privacy Rule and Research USCRF Research Educational Series March 19, 2003.
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
The Health Insurance Portability and Accountability Act of 1996– charged the Department of Health and Human Services (DHHS) with creating health information.
HIPAA Training for Pharmaceutical Industry Representatives University of Utah Hospitals & Clinics.
WORKFORCE CONFIDENTIALITY HIPAA Reminders. HIPAA 101 The Health Insurance Portability and Accountability Act (HIPAA) protects patient privacy. HIPAA is.
What is HIPAA? This presentation was created by The University of Arizona Privacy Office, The Office for the Responsible Conduct of Research on March 5,
Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna
NAU HIPAA Awareness Training
HIPAA Privacy Keys to Success Education for Nursing and all other Clinical Students Effective January 2010 HIPAA Job Specific Education1.
HIPAA Basics A Matter of Integrity. Introduction “A Matter of Integrity” defines HIPAA and protecting patient health information. Success depends on our.
Informed Consent.
 The Health Insurance Portability and Accountability Act of  Federal Law designed to protect sensitive information.  HIPAA violations are enforced.
HIPAA HIPAA Health Insurance Portability and Accountability Act of 1996.
Professional Nursing Services.  Privacy and Security Training explains:  The requirements of the federal HIPAA/HITEC regulations, state privacy laws.
Protecting Client Data HIPAA, HITECH and PIPA Part 1A
HIPAA Training Presentation for New Employees How did we get here? HIPAA Police 1.
Health information security & compliance
© Copyright 2014 Saul Ewing LLP The Coalition for Academic Scientific Computation HIPAA Legal Framework and Breach Analysis Presented by: Bruce D. Armon,
HIPAA COMPLIANCE FANTASTIC FOUR CASEY FORD MANINDER SINGH RANGER OLSOM Information Security in Real Business.
HIPAA Health Insurance Portability & Accountability Act of 1996.
Health Insurance Portability and Accountability Act (HIPAA)
University of Miami1 Privacy, Confidentiality & Security Marisabel Davalos, M.S.Ed., CIP Associate Director of Educational Initiatives November, 2008.
HIPAA Business Associates Leadership Group Meeting June 28, 2001.
1 Research & Accounting for Disclosures March 12, 2008 Leslie J. Pfeffer, BS, CHP Office of the Vice President for Research Administration Office of Compliance.
1 HIPAA OVERVIEW ETSU. 2 What is HIPAA? Health Insurance Portability and Accountability Act.
Health Insurance Portability and Accountability Act (HIPAA)
HIPAA & Public Schools New Federalism in a New Century The Challenges of Administering HIPAA in Public Schools ASTHO/NGA Center Joint Audioconference September.
HIPAA (health insurance portability and accountability act)
HIPAA Michigan Cancer Registrars Association 2005 Annual Educational Conference Sandy Routhier.
Medical Law and Ethics, Third Edition Bonnie F. Fremgen Copyright ©2009 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved.
Understanding HIPAA (Health Insurandce Portability and Accountability Act)
HIPAA BASIC TRAINING Presented by Anderson Health Information Systems, Inc.
HIPAA BASIC TRAINING MODULE 1C – Overview (For staff who do not generally create Protected Health Information) Anderson Health Information Systems, Inc.
HIPAA THE PRIVACY RULE. 2 HISTORY In 2000, many patients that were newly diagnosed with depression received free samples of anti- depressant medications.
Copyright ©2014 by Saunders, an imprint of Elsevier Inc. All rights reserved 1 Chapter 02 Compliance, Privacy, Fraud, and Abuse in Insurance Billing Insurance.
HIPAA Health Insurance Portability and Accountability Act of 1996.
Welcome….!!! CORPORATE COMPLIANCE PROGRAM Presented by The Office of Corporate Integrity 1.
Western Asset Protection
Top 10 Series Changes to HIPAA Devon Bernard AOPA Reimbursement Services Coordinator.
Configuring Electronic Health Records Privacy and Security in the US Lecture b This material (Comp11_Unit7b) was developed by Oregon Health & Science University.
Legal, Regulations, Investigations, and Compliance Chapter 9 Part 2 Pages 1006 to 1022.
HIPAA TRIVIA Do you know HIPAA?. HIPAA was created by?  The Affordable Care Act  Health Insurance companies  United States Congress  United States.
The Medical College of Georgia HIPAA Privacy Rule Orientation.
New Hire HIPAA Orientation. HIPAA Overview HIPAA is an acronym that stands for the Health Insurance Portability and Accountability Act of HIPAA.
The Health Insurance Portability and Accountability Act (HIPAA) requires Plumas County to train all employees in covered departments about the County’s.
Privacy: HIPAA Emerson Murphy-Hill. Rosie Callender, RHIA, web.msm.edu/hipaa/An%20Introduction%20to%20HIPAA.ppt What is HIPAA? A Federal Law Created in.
Junli M. Awit, RN.  Enacted by President Bill Clinton in 1996  Title I of HIPAA protects health insurance coverage for workers and their families when.
UC Riverside Health Training and Development
HIPAA Privacy Rule Training
Health Insurance Portability and Accountability Act of 1996
HIPAA PRIVACY & SECURITY TRAINING
HIPAA Privacy & Security
What is HIPAA? HIPAA stands for “Health Insurance Portability & Accountability Act” It was an Act of Congress passed into law in HEALTH INSURANCE.
Health Advocate HIPAA Privacy Information
Disability Services Agencies Briefing On HIPAA
The Health Insurance Portability and Accountability Act
HIPAA Privacy & Security
HIPAA Overview.
The Health Insurance Portability and Accountability Act
HIPAA & PHI TRAINING & AWARENESS
The Health Insurance Portability and Accountability Act
Office of the Vice President for Research Human Subjects Protection Program IRB Submission Process Module 4 - Health Insurance Portability and Accountability.
The Health Insurance Portability and Accountability Act
Presentation transcript:

Office of Audit, Compliance & Privacy HIPAA Office of Audit, Compliance & Privacy Division of Institutional Compliance & Privacy

Why should HIPAA matter to me? First of all, what is HIPAA? Health Insurance Portability and Accountability Act of 1996. Heath Information Technology for Economic & Clinical Health Act (HITECH) a part of the American Recovery and Reinvestment Act (ARRA) 2009 amended HIPAA. Created a number of regulations dealing with: Administrative Simplification (billing codes, etc.) Privacy Security Breach Division of Institutional Compliance & Privacy

Why should HIPAA matter to me? Do you work with Personally Identifiable Information, PII? Do you work with Protected Health Information, PHI? Conduct research with PII or PHI? or Work in a department that works with or conducts research with PII or PHI? Protected Health Information, PHI, is a specific type of Personally Identifiable Information, PII. If you do, it is important to understand HIPAA or know enough information to ask for help and guidance! There may be additional steps that you have to take to keep PHI private and secure as a part of your job or for your research project. If you are considered to be a covered entity under HIPAA, then you are currently involved in HIPAA compliance on a daily basis. Division of Institutional Compliance & Privacy

What is Protected Health Information, PHI? PHI is individually identifiable health information held or transmitted by a covered entity or a business associate, that relates to: The individual’s past, present or future physical or mental health or condition The provision of health care to the individual or The past, present, or future payment for the provision of health care to the individual. Reference: https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html. Division of Institutional Compliance & Privacy

What are examples of PHI? Names Addresses & geographic subdivisions DOB Telephone numbers VIN, DL number, Passport number Fax Number Email address Web Universal Resource Locator (URLs) Division of Institutional Compliance & Privacy

What are examples of PHI? Social security numbers Internet Protocol (IP) address Medical Record Number Biometric Identifiers Health plan beneficiary numbers Full face photos Account numbers Professional license numbers, or other unique identifiers Division of Institutional Compliance & Privacy

Doesn’t the university take care of privacy and security for me? The situation is a bit more complicated than “yes” or “no” The University does have multiple sites with resources on line: Vice President for Research and Development: https://cws.auburn.edu/ovpr/ AU Research Compliance: https://cws.auburn.edu/OVPR/pm/compliance/home Office of Audit, Compliance & Privacy http://www.auburn.edu/administration/oacp/orsc.php Division of Institutional Compliance & Privacy

Your Research partners may require additional documentation Depending on the nature of the PHI you receive, the entity providing the data may require additional documentation as to: Cyber insurance (a/k/a breach insurance); Computer security; HIPAA & Security training for your and your staff; and Signed verification that you will comply with the Privacy Rule and the Security Rule to the extent it applies to you by executing a Business Associate Agreement (BAA). Division of Institutional Compliance & Privacy

Division of Institutional Compliance & Privacy We Need you to be a partner in making sure PHI is maintained & used in a secure manner We are NOT asking you to be an expert on HIPAA regulations! We ARE asking you to: Understand major concepts about HIPAA & identify if you are working with PHI (PII); Reach out if you have questions regarding privacy & security; Also, if you are not sure if the information is protected by HIPAA or FERPA, please reach out to us! Division of Institutional Compliance & Privacy

Division of Institutional Compliance & Privacy We need you to be a partner in making sure PHI is maintained & used in a secure manner Understand that new IRB approvals may require additional questions to be answered regarding PHI & PII to comply with federal regulations; Allow us to be a resource for you and your department (and research partners); and If there is unauthorized access to PHI to reach out to us immediately. Or if you suspect there has been unauthorized access! Division of Institutional Compliance & Privacy

Commitment to Excellence You are a vital part of HIPAA Compliance! Your commitment to learning about HIPAA and reaching out for assistance; and We need your commitment to compliance with these regulations; If those values seem familiar, they are: “I believe in education, which gives me the knowledge to work wisely and trains my mind and hands to work skillfully”. “I believe in obedience to law because it protects the rights of all”. The Auburn Creed, George Petrie (1943). Division of Institutional Compliance & Privacy

Commitment to Excellence The University is committed to a culture of compliance and excellence-by leading and shaping the future of higher education. I welcome the opportunity to work with each of you. Division of Institutional Compliance & Privacy

Additional Reference Links Summary of the HIPAA Privacy Rule https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html Summary of the HIPAA Security Rule https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html HIPAA & Research https://www.hhs.gov/hipaa/for-professionals/special-topics/research/index.html NIH-Protecting PHI in Research https://privacyruleandresearch.nih.gov/pdf/HIPAA_Booklet_4-14-2003.pdf Division of Institutional Compliance & Privacy

Division of Institutional Compliance & Privacy Thank you! Ronda H. Lacey, J.D. Compliance Manager, HIPAA Privacy Officer Office of Audit, Compliance & Privacy/Division of Institutional Compliance & Privacy Division of Institutional Compliance & Privacy

Division of Institutional Compliance & Privacy Contact Information Ronda H. Lacey, J.D. Compliance Manager, HIPAA Privacy Officer Institutional Compliance & Privacy 022 James E. Foy Hall 1310 Wilmore Drive Auburn University, AL 36849 Office: 334-844-4319 laceyrh@auburn.edu Division of Institutional Compliance & Privacy