To run in Slide Show mode If using PowerPoint 2003 click Slide Show, View Show from the Menu Bar. If using PowerPoint 2010 click the Slide Show tab, then.

Slides:



Advertisements
Similar presentations
HIPAA: An Overview of Transaction, Privacy and Security Regulations Training for Providers and Staff.
Advertisements

1 The Health Insurance Portability and Accountability Act (HIPAA) A guided tutorial for GVSU employees.
HIPAA Privacy Training. 2 HIPAA Background Health Insurance Portability and Accountability Act of 1996 Copyright 2010 MHM Resources LLC.
Health Insurance Portability and Accountability Act HIPAA Education for Volunteers and Students.
HIPAA. What Why Who How When What Is HIPAA? Health Insurance Portability & Accountability Act of 1996.
HIPAA Basic Training for Privacy & Information Security Vanderbilt University Medical Center VUMC HIPAA Website:
Confidentiality and HIPAA
HIPAA Privacy Rule Training
Copyright Eastern PA EMS Council February 2003 Health Information Portability and Accountability Act It’s the law.
COBB/DOUGLAS COMMUNITY SERVICES BOARD Confidentiality and Privacy of Consumer Information.
The Health Insurance Portability and Accountability Act Basic HIPAA Training For CMU workforce with access to PHI.
National Health Information Privacy and Security Week Understanding the HIPAA Privacy and Security Rule.
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
The Health Insurance Portability and Accountability Act of 1996– charged the Department of Health and Human Services (DHHS) with creating health information.
Page 1 of 16 DMC HIPAA Privacy and Security DMC’S COMMITMENT TO COMPLIANCE: HIPAA PRIVACY and SECURITY DMC Corporate Audit and Compliance Department Detroit.
HIPAA Security Training 2005
WORKFORCE CONFIDENTIALITY HIPAA Reminders. HIPAA 101 The Health Insurance Portability and Accountability Act (HIPAA) protects patient privacy. HIPAA is.
HIPAA Health Insurance Portability and Accountability Act.
What is HIPAA? This presentation was created by The University of Arizona Privacy Office, The Office for the Responsible Conduct of Research on March 5,
1 HIPAA Education CCAC Professional Development Training September 2006 CCAC Professional Development Training September 2006.
NAU HIPAA Awareness Training
1 Louisiana Department of Health and Hospitals Basic HIPAA Privacy Training: Policies and Procedures 01/09/
HIPAA Basics A Matter of Integrity. Introduction “A Matter of Integrity” defines HIPAA and protecting patient health information. Success depends on our.
HIPAA Health Insurance Portability and Accountability Act.
HIPAA Privacy Rule Compliance Training for YSU April 9, 2014.
 The Health Insurance Portability and Accountability Act of  Federal Law designed to protect sensitive information.  HIPAA violations are enforced.
Health Insurance Portability & Accountability Act “HIPAA” To every patient, every time, we will provide the care that we would want for our own loved ones.
Are you ready for HIPPO??? Welcome to HIPAA
HIPAA HIPAA Health Insurance Portability and Accountability Act of 1996.
Professional Nursing Services.  Privacy and Security Training explains:  The requirements of the federal HIPAA/HITEC regulations, state privacy laws.
Protecting Client Data HIPAA, HITECH and PIPA Part 1A
HIPAA Training Presentation for New Employees How did we get here? HIPAA Police 1.
HIPAA What’s Said Here – Stays Here…. WHAT IS HIPAA  Health Insurance Portability and Accountability Act  Purpose is to protect clients (patients)
HIPAA Health Insurance Portability & Accountability Act of 1996.
HIPAA Basic Training for Privacy and Information Security Vanderbilt University Medical Center VUMC HIPAA Website: HIPAA Basic.
HIPAA Privacy & Security Kay Carolin Barbara Ann Karmanos Cancer Center March 2009.
HIPAA PRIVACY AND SECURITY AWARENESS.
Privacy and Security of Protected Health Information NorthPoint Health & Wellness Center 2011.
HIPAA OBJECTIVES  Define HIPAA  Define PHI  Use of PHI  Your rights  Your responsibilities.
1 HIPAA OVERVIEW ETSU. 2 What is HIPAA? Health Insurance Portability and Accountability Act.
Next ETCH Confidentiality and HIPAA Annual Review What you need to know. The Privacy Rule 1.
How Hospitals Protect Your Health Information. Your Health Information Privacy Rights You can ask to see or get a copy of your medical record and other.
HIPAA Michigan Cancer Registrars Association 2005 Annual Educational Conference Sandy Routhier.
© 2009 The McGraw-Hill Companies, Inc. All rights reserved. 1 McGraw-Hill Chapter 2 The HIPAA Privacy Standards HIPAA for Allied Health Careers.
Medical Law and Ethics, Third Edition Bonnie F. Fremgen Copyright ©2009 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved.
Building a Privacy Foundation. Setting the Standard for Privacy Health Insurance Portability and Accountability Act (HIPAA) Patient Bill of Rights Federal.
Health Insurance Portability and Accountability Act (HIPAA) CCAC.
Copyright © 2009 by The McGraw-Hill Companies, Inc. All Rights Reserved. McGraw-Hill Chapter 6 The Privacy and Security of Electronic Health Information.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
Understanding HIPAA (Health Insurandce Portability and Accountability Act)
A Road Map to Research at Jefferson: HIPAA Privacy and Security Rules for Researchers Presented By: Privacy Officer/Office of Legal Counsel October 2015.
HIPAA Overview Why do we need a federal rule on privacy? Privacy is a fundamental right Privacy can be defined as the ability of the individual to determine.
Aged and Disabled Waiver (ADW) Health Insurance Portability and Accountability Act (HIPAA) Training 2015 October 2015.
HIPAA TRIVIA Do you know HIPAA?. HIPAA was created by?  The Affordable Care Act  Health Insurance companies  United States Congress  United States.
HIPAA Training. What information is considered PHI (Protected Health Information)  Dates- Birthdays, Dates of Admission and Discharge, Date of Death.
The Health Insurance Portability and Accountability Act (HIPAA) requires Plumas County to train all employees in covered departments about the County’s.
HIPAA Privacy What Every Staff Member Needs to Know.
Copyright © 2009 by The McGraw-Hill Companies, Inc. All Rights Reserved. McGraw-Hill/Irwin Chapter 6 The Privacy and Security of Electronic Health Information.
Health Insurance Portability and Accountability Act of 1996
HIPAA PRIVACY & SECURITY TRAINING
HIPAA Privacy & Security
HIPAA PRIVACY AWARENESS, COMPLIANCE and ENFORCEMENT
Disability Services Agencies Briefing On HIPAA
The Health Insurance Portability and Accountability Act
HIPAA Privacy & Security
The Health Insurance Portability and Accountability Act
HIPAA & PHI TRAINING & AWARENESS
The Health Insurance Portability and Accountability Act
The Health Insurance Portability and Accountability Act
Presentation transcript:

To run in Slide Show mode If using PowerPoint 2003 click Slide Show, View Show from the Menu Bar. If using PowerPoint 2010 click the Slide Show tab, then click From Beginning button

Health Insurance Portability and Accountability Act HIPAA Patient Privacy & Security Allison Martin & Kimberly Segal Barbara Ann Karmanos Cancer Center February 2013

HIPAA Module Objectives After completing this training module, you should be able to: 1.Understand key HIPAA terms. 2.Apply general HIPAA rules that apply to your every day work at Karmanos. 3.Know where to turn for help if you have questions or concerns to report regarding patient privacy.

Karmanos’ Commitment to Protecting our Patient’s Privacy Under HIPAA HIPAA stands for the Health Insurance Portability and Accountability Act. HIPAA is a federal law that sets standards regarding protection of confidential patient data. Who is responsible to comply with HIPAA? –Covered Entities: health care provider, health plan, or a clearing house that submits bills electronically. –All Covered Entities (Karmanos is a Covered Entity) along with their Business Associates (that use or access patient information on the Covered Entity’s behalf) Karmanos is committed to protecting the confidential and private information of our patients. Remember that employees, friends and family members who are treated at Karmanos are our patients too! If you have had testing or treatment at Karmanos, you were a patient! These records may only be accessed as a part of your routine job duties. Protecting the privacy of our patients is EVERYONE’S job.

Protected Health Information (PHI) Includes the Following Identifiers: Name Street Address, City, County, Zip Code Dates: Birth Admission Discharge Death Numbers: Social Security Medical Record Account (FIN) Health Plan Beneficiary License Vehicle Identification Telephone or Fax Address Biometric Identifiers Full Face Photos Any Other Unique Identifying Number, Characteristic, or Code

Protected Health Information Protected Health Information (PHI) includes information: –On paper –In a computer –Orally communicated –In any other form Electronically Protected Health Information (EPHI) includes information: –On your computer hard drive –On floppy disks, CDs or magnetic tapes –Sent via the Internet: By Other means

PHI Use Under HIPAA Treatment, Payment & Operations (TPO): –Treatment: Various activities related to patient care. –Payment: Various activities related to paying for or getting paid for health care services. –Operations: Generally refers to day-to-day activities of a covered entity, such as planning, management, training, quality-improvement, education. Note: Research is not considered TPO. Written patient authorization is required to access PHI for research.

Notice of Privacy Practices (NPP) As a Covered Entity under HIPAA, Karmanos has developed a Notice of Privacy Practices (NPP) for distribution to our patients. The NPP states Karmanos practices for use of personal health information. The NPP allows patients to be informed of their privacy rights with respect to their personal health information. The NPP provides a detailed description of the uses and disclosures of PHI that are permissible without obtaining a patient’s authorization. The NPP is intended to focus individuals on privacy issues and concerns, and to prompt them to have discussions with their health care providers.

Business Associate Agreement (BAA) Business Associates are usually vendors who perform some function or service for Karmanos that requires them to have access to our patients’ information. A Business Associate Agreement (BAA) is a signed agreement promising to keep PHI confidential in accordance with HIPAA. Karmanos, a Covered Entity under HIPAA, is required to sign Business Associate Agreements with certain organizations and individuals to whom they share Protected Health Information (PHI). If you are working with a vendor and are not sure if you need a BAA, you may contact Materials Management or the Compliance Department at

Authorization (Release of Information) Authorization to Release Information is signed permission allowing Karmanos to use or disclose a patient’s PHI for reasons generally not related to Treatment, Payment or Healthcare Operations (TPO). The Authorization must include: a detailed description of the PHI to be disclosed, who will make the disclosure, to whom the disclosure will be made, expiration date, and the purpose of the disclosure. See Policy HIM020, Release of Information Contact Health Information Management (HIM) to determine the appropriate authorization form needed for your purpose.

Highly Confidential Information Michigan law provides even more protection than HIPAA in some cases. This applies to highly confidential areas which include: –Mental Health and Substance Abuse –HIV/AIDS Testing or Treatment –Psychotherapy Notes (which are not part of the medical record) –If you have questions about handling highly confidential information: Ask your supervisor Contact Health Information Management (HIM) the Compliance Department at

Types of Disclosures No Authorization Required: to disclose PHI to the patient, to use or disclose PHI for treatment, payment or healthcare operations (TPO) and certain other disclosures required by law (for example, public health reporting of diseases, abuse/neglect cases, etc.) No Authorization Required, BUT Must Offer Opportunity to Object: a patient must be offered an opportunity to object BEFORE discussing PHI with a patient’s family or friends. Authorization IS Required: for research, and when conducting certain fundraising or marketing activities.

Incidental Disclosures HIPAA recognizes that some disclosures are not completely avoidable. These are called “Incidental Disclosures.” For example, visitors may overhear a clinical discussion as they are walking down the hallway of an inpatient unit or a visitor may hear a patient’s name called out in a waiting room. HIPAA requires that reasonable safeguards be put in place to limit incidental disclosures. –Speak in soft tones when discussing PHI in open areas. –Do not discuss PHI in public hallways, elevators or other public locations –Only use the minimum amount of information necessary to carry out the intended purpose

Every Day Practices For Securing PHI Do: –log-off your computer when you will be away for a period of time. –position monitors out of view of the public eye. –change your password as defined in policy. –choose passwords that are not easily guessed. –use password protected screensavers and keyboard locks. –place disks or tapes in a secure location. –immediately report anyone outside of KCC asking for your password.

Every Day Practices For Securing PHI Do not: –share passwords or login ID. –write down passwords where others may access them. –open any unknown attachments, files or unrecognizable s. –install unapproved software/hardware –use unapproved , such as Hotmail, Yahoo, etc.

Every Day Practices For Securing PHI Use caution and respect patients’ privacy when discussing protected health information in public. Read and understand the policies and procedures relating to HIPAA Privacy & Security. When using or disclosing protected health information, limit the PHI to the minimum necessary to accomplish the intended use. Workers should only access or use the PHI necessary to conduct their job responsibilities. All electronic systems are audited –a log of all accesses is maintained and is designed to protect patient privacy. For Fax's: Double check fax number. Use cover page which includes your contact information. If fax is received by the wrong location, have the fax destroyed or returned to you.

Protecting your Computer & PHI Report any suspicious activity, such as new software or hardware appearing on your computer to the Help Desk. Contact your supervisor or the Help Desk if you believe someone may have logged onto your computer. Secure PDA’s and Laptops: –Always use a password protected screen saver. –Back-up data. –Install and use virus protection software. –Lock devices in a secure location when not in use. –If device is stolen, an incident report should be filed.

and PHI to transmission within the Karmanos System is secure from the Karmanos system to any other system is NOT considered secure unless encrypted (Note: this includes DMC and WSU addresses – sent from Karmanos is not secure unless encrypted) Encryption can be forced for containing PHI from a Karmanos to a non-Karmanos address by typing [SECURE] in the subject line In all cases, use the minimum necessary PHI

Emergency Downtime Karmanos Cancer Center has a contingency plan to address system access during power failures, disasters, weather hazards or other situations limiting access to patient data: –Know the recovery plan as it relates to your job –Know the related policies –Know how to report emergencies –Know how the emergency may impact patient care

Penalties Disciplinary action up to and including termination. Exclusion from participation in Medicare and Medicaid programs. NOTE: Individuals (This Means You!) can be subject to criminal prosecution, fines and imprisonment. HIPAA Specific: –Up to one year / $50,000 for misuse of protected health information. –Up to five years / $100,000 for misuse of PHI under false pretenses. –Up to ten years / $250,000 for misuse with intent to sell, transfer or use PHI for commercial advantage, personal gain or malicious harm.

HIPAA Reporting You are required to understand the law, and how it affects your job. Even an “accidental” disclosure could have consequences. As a condition of employment, employees agree to read and abide by the policies and procedures covering HIPAA. Individuals should immediately report any observed or suspected HIPAA breach to: –Your supervisor –Compliance Office: –Compliance Hotline (Anonymous Reporting) at: Not Sure?Report It Anyway. Too Late? Report It Anyway. Already Told Us?Report It Again! YOU CAN NEVER BE RETALIATED AGAINST FOR REPORTING A CONCERN! Safeguarding PHI is everyone’s job.

HIPAA Resources Internal Karmanos Resources –Kim Segal – Director-Compliance & Privacy, –Allison Martin, VP Compliance & Regulatory,

Summary We hope this Computer Based Learning course has been both informative and helpful. Feel free to review this course until you are confident about your knowledge of the material presented. Click the Take Test button on the left side when you are ready to complete the requirements for this course. Click on the My Records button to return to your CBL Courses to Complete list. Click the Exit button on the left to close the Student Interface.