HIPAA: An Overview of Transaction, Privacy and Security Regulations Training for Providers and Staff.

Slides:



Advertisements
Similar presentations
HIPAA Health Insurance Portability and Accountability Act of 1996
Advertisements

HITECH ACT Privacy & Security Requirements Cathleen Casagrande Privacy Officer July 23, 2009.
Independent Contractor Orientation HIPAA What Is HIPAA? Health Insurance Portability and Accountability Act of 1996 The Health Insurance Portability.
HIPAA Training: Health Insurance Portability and Accountability Act.
1 The Health Insurance Portability and Accountability Act (HIPAA) A guided tutorial for GVSU employees.
HIPAA Basics Brian Fleetham Dickinson Wright PLLC.
1. As a Florida KidCare community partner families entrust you to not only help them navigate the Florida KidCare system but to keep the information they.
HIPAA Privacy Training. 2 HIPAA Background Health Insurance Portability and Accountability Act of 1996 Copyright 2010 MHM Resources LLC.
Health Insurance Portability and Accountability Act HIPAA Education for Volunteers and Students.
HIPAA. What Why Who How When What Is HIPAA? Health Insurance Portability & Accountability Act of 1996.
Confidentiality and HIPAA
HIPAA Privacy Rule Training
Copyright Eastern PA EMS Council February 2003 Health Information Portability and Accountability Act It’s the law.
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
The Health Insurance Portability and Accountability Act of 1996– charged the Department of Health and Human Services (DHHS) with creating health information.
HIPAA What’s New? What Is HIPAA Health Insurance Portability and Accountability Act of 1996 Health Insurance Portability and Accountability Act.
HIPAA PRIVACY REQUIREMENTS Dana L. Thrasher Constangy, Brooks & Smith, LLC (205) ; Victoria Nemerson.
WORKFORCE CONFIDENTIALITY HIPAA Reminders. HIPAA 101 The Health Insurance Portability and Accountability Act (HIPAA) protects patient privacy. HIPAA is.
What is HIPAA? This presentation was created by The University of Arizona Privacy Office, The Office for the Responsible Conduct of Research on March 5,
Health Insurance Portability and Accountability Act (HIPAA)HIPAA.
1 HIPAA Education CCAC Professional Development Training September 2006 CCAC Professional Development Training September 2006.
Key Changes to HIPAA from the Stimulus Bill (ARRA) Children’s Health System Department Leadership Meeting October 28, 2009 Kathleen Street Privacy Officer/Risk.
NAU HIPAA Awareness Training
 The Health Insurance Portability and Accountability Act of  Federal Law designed to protect sensitive information.  HIPAA violations are enforced.
COMPLYING WITH HIPAA PRIVACY RULES Presented by: Larry Grudzien, Attorney at Law.
HIPAA THE PRIVACY RULE Reviewed December HISTORY In 2000, many patients that were newly diagnosed with depression received free samples of anti-
2014 HIPAA Refresher Omnibus Rule & HIPAA Security.
Are you ready for HIPPO??? Welcome to HIPAA
Professional Nursing Services.  Privacy and Security Training explains:  The requirements of the federal HIPAA/HITEC regulations, state privacy laws.
HIPAA What’s Said Here – Stays Here…. WHAT IS HIPAA  Health Insurance Portability and Accountability Act  Purpose is to protect clients (patients)
HIPAA COMPLIANCE IN YOUR PRACTICE MARIBEL VALENTIN, ESQUIRE.
From HIPAA to HITECH OMH Briefing.
HIPAA PRIVACY AND SECURITY AWARENESS.
“ Technology Working For People” Intro to HIPAA and Small Practice Implementation.
Privacy and Security of Protected Health Information NorthPoint Health & Wellness Center 2011.
Health Insurance Portability and Accountability Act (HIPAA)
Quality Integrity Stewardship Courtesy Care Accountability Medical Records ARMA Florida Gulf Coast Chapter Michael Spake Lakeland Regional Medical Center.
How Hospitals Protect Your Health Information. Your Health Information Privacy Rights You can ask to see or get a copy of your medical record and other.
HIPAA Michigan Cancer Registrars Association 2005 Annual Educational Conference Sandy Routhier.
Building a Privacy Foundation. Setting the Standard for Privacy Health Insurance Portability and Accountability Act (HIPAA) Patient Bill of Rights Federal.
LeToia Crozier, Esq., CHC Vice President, Compliance & Regulatory Affairs Corey Wilson Director of Technical Services & Security Officer Interactive Think.
Understanding HIPAA (Health Insurandce Portability and Accountability Act)
HIPAA BASIC TRAINING Presented by Anderson Health Information Systems, Inc.
HIPAA BASIC TRAINING MODULE 1C – Overview (For staff who do not generally create Protected Health Information) Anderson Health Information Systems, Inc.
HIPAA THE PRIVACY RULE. 2 HISTORY In 2000, many patients that were newly diagnosed with depression received free samples of anti- depressant medications.
A Road Map to Research at Jefferson: HIPAA Privacy and Security Rules for Researchers Presented By: Privacy Officer/Office of Legal Counsel October 2015.
Western Asset Protection
Copyright © 2015 by Saunders, an imprint of Elsevier Inc. All rights reserved. Chapter 3 Privacy, Confidentiality, and Security.
Top 10 Series Changes to HIPAA Devon Bernard AOPA Reimbursement Services Coordinator.
HIPAA: Breach Notification By: Office of University Counsel For: Jefferson IRB Continuing Education September 2014.
HIPAA Overview Why do we need a federal rule on privacy? Privacy is a fundamental right Privacy can be defined as the ability of the individual to determine.
HIPAA TRIVIA Do you know HIPAA?. HIPAA was created by?  The Affordable Care Act  Health Insurance companies  United States Congress  United States.
HIPAA Training. What information is considered PHI (Protected Health Information)  Dates- Birthdays, Dates of Admission and Discharge, Date of Death.
The Medical College of Georgia HIPAA Privacy Rule Orientation.
The Health Insurance Portability and Accountability Act (HIPAA) requires Plumas County to train all employees in covered departments about the County’s.
Health Insurance Portability and Accountability Act (HIPAA) Primer for Observers, Volunteers, Medical Students Dr. Michael Palumbo- Privacy Officer/ EVP.
HIPAA Privacy Rule Training
Health Insurance Portability and Accountability Act of 1996
HIPAA PRIVACY & SECURITY TRAINING
UNDERSTANDING WHAT HIPAA IS AND IS NOT
HIPAA Privacy & Security
What is HIPAA? HIPAA stands for “Health Insurance Portability & Accountability Act” It was an Act of Congress passed into law in HEALTH INSURANCE.
HIPAA.
HIPAA PRIVACY AWARENESS, COMPLIANCE and ENFORCEMENT
Disability Services Agencies Briefing On HIPAA
Employee Privacy and Privacy of Employee Information
HIPAA Privacy & Security
The Health Insurance Portability and Accountability Act
The Health Insurance Portability and Accountability Act
Presentation transcript:

HIPAA: An Overview of Transaction, Privacy and Security Regulations Training for Providers and Staff

HIPAA BASICS HIPAA stands for Health Insurance Portability and Accountability Act The law sets standards for the transmission of information in order to provide uniformity between the many healthcare systems The law also sets strong privacy protections to protect the consumer’s health information

Enforcement Responsibility Centers for Medicare and Medicaid (CMS) is responsible for the security standards The Department of Health and Human Service’s Office of Civil Rights is responsible for the privacy rules.

Penalties for Noncompliance The Federal government holds the agency liable for violations. Agency Penalties: $100 - $50,000 per violation up to 1.5 million per year; Exclusion from participating with Medicare/Medicaid and possible prison time. Entitities contracted with Pines: $50,000 per violation up to 1.5 million per year; Exclusion from participating with Medicare/Medicaid (loss of contract with Pines) and possible prison time. Staff Sanctions: Disciplinary up to and including termination per policy.

Who is Subject to HIPAA? You are if: You transmit health information (bills) electronically You receive third party reimbursement You bill Medicare or Medicaid You receive money from Pines who is a covered entity and subject to HIPAA rules If you receive faxes with health information that may have been computer generated If you serve even 1 consumer affected by the above, you are liable to comply with HIPAA regulations

Three Parts to HIPAA Privacy Rule: Establishes standards to protect the confidentiality of personal health information (PHI) Transaction Rule: Requires compliance to standards for electronic transmission of health information (ie. standard billing formats) Security Rule: Sets standards related to the safeguard of health information.

Privacy Rules Requires staff training on privacy rules Requires the designation of a privacy officer Requires that all consumers know the agency’s disclosure of health information (Privacy Notices) Requires a clear protocol for handling complaints regarding HIPAA compliance Requires a “need to know” limit – only that information that is needed to be known can be released to only those people that need to know with proper consent (authorization). Allows consumers to request an amendment to their records.

HIPAA vs. Mental Health Code and/or Public Health Code The federal government allows state law to pre-empt HIPAA regulations if the state laws are more stringent than HIPAA. In many cases, the mental health code and/or public health code for substance abuse is more stringent than HIPAA.

HIV Information Be very careful regarding releasing HIV information. Michigan highly regulates the confidentiality of HIV information. A person’s HIV status (positive or negative) cannot be disclosed without their express, written permission unless a medical personnel is exposed to their blood in an emergency situation. Be just as concerned about accidental disclosure as you are with accidental transmission.

Transactions Rules Applies to agencies that transmit insurance bills/claims electronically or uses billing services. Organizations must use HIPAA compliant software and test transactions with third party payors.

Security Rules Covers every type of storage or transmission of public health information that might take place. Requires a risk assessment to be undertaken Requires policies and procedures to address the security of records Requires the staff responsibility for security policies and procedures (Security Officer) Requires technology security such as data backups, passwords that expire frequently, monitoring of computer network activity Requires limits on physical access to equipment or locations to assure security of information: Location of fax machine Screen protectors needed on computers Shred receptacles available

Practical Security Steps Control the physical access to your building. Visitors should not be allowed to access areas in which confidential information is kept. Conversations involving sensitive information should not occur where it can be overheard Sensitive documents should not be left in view Sensitive telephone conversations should not be conducted where they can be overheard Processes should be in place to assure that faxes coming in are safeguarded Computers should be positioned so that confidential information cannot be seen by others. Passwords are meant to secure information. They should be hard to guess and not shared. Portable computers (laptops, flash drives, PDAs, etc.) should be kept secure. Avoid keeping sensitive information on them if they need to leave the office. is not under your control once you push send. Make sure messages have a confidential information at the end, and rule of thumb should be never include sensitive information in the if using the internet.

Common Breaches ing consumer names or other protected health information across the internet Giving out more information than minimally necessary Discussing consumer information where others can hear *New regulations regarding breaching information created for citizen protection – see next slide

HITECH – Expansion of HIPAA American Recovery and Reinvestment Act (Stimulus Pkg): HIPAA Breach Notification Rule Breach: the acquisition, access, use or disclosure of unsecured PHI Determine a breach based on assessment of financial, reputational or other harm risk to individual If determined a breach, must notify individual within 60 days. If more than one, you may need to notify the media Annually, breach logs must go to HHS, and a client may ask to view their personal disclosure log All disclosures of PHI must be tracked and provided upon request to a client

Documenting and Reporting HIPAA complaints Staff: Report to the Pines Recipient Rights Officer (Norma Wojack) or Report to the Privacy Officer (Cathie Sutton) Providers: Report to your supervisor or other internal personnel that would be responsible for ensuring compliance to HIPAA