Your Role in Corporate Compliance and HIPAA Confidentiality

Slides:



Advertisements
Similar presentations
HIPAA: An Overview of Transaction, Privacy and Security Regulations Training for Providers and Staff.
Advertisements

Independent Contractor Orientation HIPAA What Is HIPAA? Health Insurance Portability and Accountability Act of 1996 The Health Insurance Portability.
Privacy and Information Security Training ( ) VUMC Privacy Website
Hipaa privacy and Security
1. As a Florida KidCare community partner families entrust you to not only help them navigate the Florida KidCare system but to keep the information they.
HIPAA Privacy Training. 2 HIPAA Background Health Insurance Portability and Accountability Act of 1996 Copyright 2010 MHM Resources LLC.
Health Insurance Portability and Accountability Act HIPAA Education for Volunteers and Students.
HIPAA. What Why Who How When What Is HIPAA? Health Insurance Portability & Accountability Act of 1996.
HIPAA Basic Training for Privacy & Information Security Vanderbilt University Medical Center VUMC HIPAA Website:
HIPAA Privacy Rule Training
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
The Health Insurance Portability and Accountability Act of 1996– charged the Department of Health and Human Services (DHHS) with creating health information.
WORKFORCE CONFIDENTIALITY HIPAA Reminders. HIPAA 101 The Health Insurance Portability and Accountability Act (HIPAA) protects patient privacy. HIPAA is.
Health Insurance Portability and Accountability Act (HIPAA)HIPAA.
1 HIPAA Education CCAC Professional Development Training September 2006 CCAC Professional Development Training September 2006.
NAU HIPAA Awareness Training
1 Louisiana Department of Health and Hospitals Basic HIPAA Privacy Training: Policies and Procedures 01/09/
HIPAA Privacy Rule Compliance Training for YSU April 9, 2014.
Are you ready for HIPPO??? Welcome to HIPAA
Randy Benson RHQN Executive Director May, Compliance Issues During Survey Compliance Officers monitor healthcare facilities (hospitals and clinics)
HIPAA HIPAA Health Insurance Portability and Accountability Act of 1996.
2010 Region II Conference Corporate Compliance Panel June 3, 2010
HIPAA COMPLIANCE IN YOUR PRACTICE MARIBEL VALENTIN, ESQUIRE.
HIPAA Basic Training for Privacy and Information Security Vanderbilt University Medical Center VUMC HIPAA Website: HIPAA Basic.
The University of Kansas Medical Center Shadow Experience Training.
© 2009 The McGraw-Hill Companies, Inc. All rights reserved. 1 McGraw-Hill Chapter 5 HIPAA Enforcement HIPAA for Allied Health Careers.
HIPAA PRIVACY AND SECURITY AWARENESS.
Privacy and Security of Protected Health Information NorthPoint Health & Wellness Center 2011.
Copyright ©2011 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved. Health Information Technology and Management Richard.
CORPORATE COMPLIANCE PROGRAM The Office of Corporate Integrity
How Hospitals Protect Your Health Information. Your Health Information Privacy Rights You can ask to see or get a copy of your medical record and other.
Coding Compliance Plan July 12, Benefits of a compliance program  To demonstrate our commitment to honest and responsible conduct, decrease the.
HIPAA Training Developed for Ridgeview Institute 2012 Hospital Wide Orientation.
Group 3 Angela, Rachael, Misty, Kayelee, and Krysta.
HIPAA Michigan Cancer Registrars Association 2005 Annual Educational Conference Sandy Routhier.
Component 16-Professionalism/Customer Service in the Health Environment Unit 5-Regulatory Issues: HIPAA and Standard Precautions This material was developed.
Medical Law and Ethics, Third Edition Bonnie F. Fremgen Copyright ©2009 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved.
Page 1 of 23 DMC’S COMMITMENT TO COMPLIANCE: COMPLIANCE PROGRAM CODE OF CONDUCT 2009 DMC Corporate Audit and Compliance Department Detroit Medical Center©
Building a Privacy Foundation. Setting the Standard for Privacy Health Insurance Portability and Accountability Act (HIPAA) Patient Bill of Rights Federal.
Health Insurance Portability and Accountability Act (HIPAA) CCAC.
Copyright © 2009 by The McGraw-Hill Companies, Inc. All Rights Reserved. McGraw-Hill Chapter 6 The Privacy and Security of Electronic Health Information.
Copyright ©2014 by Saunders, an imprint of Elsevier Inc. All rights reserved 1 Chapter 02 Compliance, Privacy, Fraud, and Abuse in Insurance Billing Insurance.
A Road Map to Research at Jefferson: HIPAA Privacy and Security Rules for Researchers Presented By: Privacy Officer/Office of Legal Counsel October 2015.
Welcome….!!! CORPORATE COMPLIANCE PROGRAM Presented by The Office of Corporate Integrity 1.
Western Asset Protection
Copyright © 2015 by Saunders, an imprint of Elsevier Inc. All rights reserved. Chapter 3 Privacy, Confidentiality, and Security.
Flowers Hospital General Compliance Training-Students 2013.
HIPAA HEALTH INSURANCE PORTABILITY ACOUNTABILITY ACT.
HIPAA TRIVIA Do you know HIPAA?. HIPAA was created by?  The Affordable Care Act  Health Insurance companies  United States Congress  United States.
HIPAA Training. What information is considered PHI (Protected Health Information)  Dates- Birthdays, Dates of Admission and Discharge, Date of Death.
The Medical College of Georgia HIPAA Privacy Rule Orientation.
New Hire HIPAA Orientation. HIPAA Overview HIPAA is an acronym that stands for the Health Insurance Portability and Accountability Act of HIPAA.
The Health Insurance Portability and Accountability Act (HIPAA) requires Plumas County to train all employees in covered departments about the County’s.
HIPAA Privacy What Every Staff Member Needs to Know.
Copyright © 2009 by The McGraw-Hill Companies, Inc. All Rights Reserved. McGraw-Hill/Irwin Chapter 6 The Privacy and Security of Electronic Health Information.
Health Insurance Portability and Accountability Act (HIPAA) Primer for Observers, Volunteers, Medical Students Dr. Michael Palumbo- Privacy Officer/ EVP.
Developed for Ridgeview Institute 2015 Hospital Wide Orientation
HIPAA Privacy Rule Training
Health Insurance Portability and Accountability Act of 1996
HIPAA Privacy & Security
What is HIPAA? HIPAA stands for “Health Insurance Portability & Accountability Act” It was an Act of Congress passed into law in HEALTH INSURANCE.
HIPAA PRIVACY AWARENESS, COMPLIANCE and ENFORCEMENT
Disability Services Agencies Briefing On HIPAA
What Every Employee Should Know About Compliance.
LifeBridge Health Sinai Hospital Orientation.
HIPAA Privacy & Security
HIPAA SECURITY RULE Copyright © 2008, 2006, 2004 by Saunders an imprint of Elsevier Inc. All rights reserved.
The Health Insurance Portability and Accountability Act
The Health Insurance Portability and Accountability Act
Presentation transcript:

Your Role in Corporate Compliance and HIPAA Confidentiality

Part I: Understanding Your Role in Corporate Compliance

What is Compliance? The term compliance has different meanings. In terms of the healthcare industry, compliance means adhering to the requirements stated under the Medicare and Medicaid laws contained within the Social Security Act and the regulations from CMS (Centers for Medicare and Medicaid Services) and other respective federal and state agencies. Our employees’ behavior is a direct reflection on OSF Healthcare. We want to be known as the region’s best health-care system with employees who consistently display high standards of integrity, conduct and ethical behavior.

What Does Compliance Mean to You as an OSF Employee? The Vision of OSF Healthcare is that recognizing God’s great gift of life, we will be a community of caregivers pursuing perfection in healthcare quality, safety, service and financial integrity. Our Corporate Compliance Plan is located online at the following address, http://www.osfhealthcare.org/compliance) Our employees’ behavior is a direct reflection on OSF Healthcare. We want to be known as the region’s best health-care system with employees who consistently display high standards of integrity, conduct and ethical behavior..

Who is Big Brother? CMS (Centers for Medicare and Medicaid Services) works with the OIG (Office of the Inspector General) to investigate possible fraud and abuse cases. If CMS believes the hospital has participated in fraudulent activities either knowingly or unknowingly, the OIG investigate. The FBI is the organization that investigates and enforces healthcare compliance. The Department of Justice prosecutes healthcare organizations for healthcare fraud and abuse.

What is a Breach of Compliance? Understanding how these regulations apply in our daily lives can be difficult. An example of fraud is billing for services not provided. Even mistakenly violating these laws could be abuse and may also result in fines. Examples of possible abuse are repeatedly using the wrong billing codes or making the same error when filing claims.

What is in OSF’s Compliance Plan? Standard of Conduct: Each new employee signs a form located in the HR handbook that is given to them during orientation. The statement reads: Any OSF Healthcare employee who has knowledge of any activity or behavior which is unethical, immoral or illegal must report this activity or observed behavior to his/her immediate supervisor or to the Director of Human Resources. Identification of High Risk Areas: These are areas that are identified as a higher risk for potential fraud and abuse therefore require more frequent monitoring by the compliance department.

What is in the Compliance Plan? Disciplinary Guidelines: The Corporate Compliance Plan identifies employee obligations to government investigations, compliance chain of command and compliance plan discipline.

The OSF Healthcare System Corporate Compliance Program promotes: The requirement of a facility compliance officer The identification of a facility compliance officer The identification of chain of command The identification of Integrity Hotline The provision of education to staff regarding compliance The identification of Standards of Conduct

In Summary..... Compliance means adhering to the requirements stated under the Medicare and Medicaid laws contained within the Social Security Act and the regulations from CMS (Centers for Medicare and Medicaid Services) and other respective federal and state agencies. Doing the right thing, the right way, the first time, all the time! Non-compliance means fraud and/or abuse, penalties, disciplinary action, and public distrust.

Part II: HIPAA Awareness Training Privacy and Security Rules OSF Healthcare System HIPAA Awareness Training – explaining the Privacy and Security Rules.

What is HIPAA? HIPAA stands for: Insurance Portability and Health Insurance Portability and Accountability Act of 1996 HIPAA stands for Health Insurance Portability and Accountability Act of 1996. No, it’s not short for hippopotamus.

What is HIPAA? HIPAA is a federal regulation that OSF Healthcare System has to comply with that protects the privacy, security and confidentiality of a patient’s health information. So because of these reasons, a federal regulation that OSF Healthcare System has to comply with that protects the privacy, security and confidentiality of a patient’s health information.

HIPAA Privacy Rule The HIPAA Privacy Rule Standards to protect the privacy of medical records and other patient specific information. Making sure protected health information (PHI) is properly handled by the facility. So – then read slide.

HIPAA Privacy What is protected health information? - Information that could be used to identify an individual - Examples would be: name, social security number, (demographic information) - Transmitted or maintained in any form such as oral, written, or electronic information Protected health information, known as PHI, is defined as individually identifiable health information. Individually identifiable health information identifies the individual where there is a reasonable basis to believe that the information can be used to identify the individual. Some examples of individually identifiable health information include: name, address, social security number, drivers license number, etc. The HIPAA Privacy Rule is to protect information in any format – whether it be oral, written or electronic.

Corporate Compliance/Privacy Officer HIPAA HIPAA requires that all health care organizations have a Privacy Officer. Corporate Compliance/Privacy Officer John Evancho 309-655-2872 Each OSF entity has their own Privacy Officer. OSFSFMC – Dan Blunier (655-2734) Read Slide

Privacy Officers Responsibilities include: Overseeing the privacy functions at the facility. Serve as a resource for questions and concerns. Handle any privacy related complaints. Develop privacy policies and procedures. Provide training to staff. Read slide.

HIPAA – Why is training necessary? Confidentiality is so important, that OSF requires that: All employees and workforce members be informed of their responsibility to protect confidentiality. Proven violation of the confidentiality of patient information shall include immediate disciplinary action up to and including termination. Confidentiality is so important that OSF requires that all employees and workforce members, which includes not only employees, but also volunteers, consultants, students, and business partners, be informed of their responsibility to protect patient confidentiality. A proven violation of the confidentiality of patient information shall include immediate disciplinary action up to and including termination as described in our Positive Discipline Policy.

HIPAA – Policy Our policy states that patient protected health information (PHI) will be kept private and confidential Our policy also guides us on who should have access to patient information Direct access to patient information shall only be permitted to those employees who have a “need to know” to perform their job functions. Minimum necessary information to perform their jobs. So what is OSF Healthcare system’s policy regarding confidentiality and our patient’s protected health information? Our policy states that patient protected health information (PHI) will be kept private and confidential. Our policy also guides us on who should have access to patient information: Direct access to patient information shall only be permitted to those employees who have a “Need to know” to perform their job functions. This means that if you don’t need a patients PHI to perform your job –you will not have access to it – nor should you ask for it.

HIPAA - Policy What patient information does OSF require me to keep confidential? Demographic information Examples: Name, social security number, date of birth, address, etc. Information about injury, illness or condition – including symptoms, diagnosis or treatment Conversations between the patient and health care workers What patient information does OSF require me to keep confidential? We ask you to keep a patients demographic information confidential – that includes their name, address, date of birth, etc. We also request that you keep confidential any information about an injury, illness or any condition – and that includes symptoms, diagnosis or treatment. Also, conversations between the patient and health care workers must also be kept confidential.

What information can I provide to persons seeking information about a patient? Facility Directory information: 1. The patient’s location with the facility; 2. The patient’s condition stated in general terms (i.e. good, fair, poor); 3. The patient’s religious affiliation (available only to clergy). If someone asks for information about a patient – what information can I provide? According to the Privacy Rule, you can provide information that is included in the facility directory. That includes the patient’s location in the facility, and the patient’s conditions stated in general terms – such as good, fair, poor, critical. A patients religious affiliation is also available to the clergy .

HIPAA - Policy Our Confidentiality Policy also guides us on when and where we can discuss patient information. Discuss patient information privately; never in elevators, lobbies, cafeterias, or corridors Make sure requisitions, forms, and computer screens with patient names and information are not easily viewed by others Dispose of unnecessary patient information in proper receptacles for shredding, not ordinary trash bins Read slide.

HOW do I protect the privacy of my co-workers? Take special care to respect the privacy of co-workers and colleagues who are patients. Do NOT discuss the health care services of your co-workers with anyone who is not directly involved in their care. - Do NOT access their private health information unless it is for patient care purposes So, how do you protect the privacy of a co-worker? Remember to take special care to respect the privacy of co-workers and colleagues who are patients. Do not discuss the health care services of your co-workers with anyone who is not directly involved in their care. Do not ask co-workers why they are a patient, or their reasons for being in the hospital or clinic. Do not access their private health information ( look at their chart) unless it is for patient care purposes.

HIPAA – How do our patient’s know their Privacy Rights? We are required to provide a Notice of Privacy Practices to all patients that describes their rights over their PHI Patients will sign an acknowledgement form stating that they received a copy of the Privacy Notice The HIPAA privacy rules tells us how we must protect a patients health information. How do our patients know how we protect their health information? We are required to provide a Notice of Privacy Practices to all patients that describes their rights over their protected health information. Patients will sign an acknowledgement form stating that they have received a copy of the Privacy Notice.

Reporting Possible Violations Can employees report possible violations of the privacy rule? Employees are encouraged to report possible violations of the privacy rule to us. Employees should feel comfortable to know that we will not take any retaliatory action when employees file complaints Submit complaints to your immediate supervisor, Privacy Officer or the Integrity Line at 1 - 800 – 547 – 2822. Read slide.

Why Comply With the HIPAA Rule? Ethics – it’s the right thing to do Civil Penalties – fines of $100 for every accidental violation Criminal Penalties – up to $250,000 for violations committed knowingly/purposefully and up to 10 years in federal prison Besides the government telling us we have to comply with the HIPAA rules, OSF wants to comply because it is the right thing to do. HIPAA is serious about patient privacy. Failure to comply can results in civil penalties with fines of $100 for every accidental violation not to exceed $25,000 during a calendar year. For criminal penalties, the fines go up to $250,000 for violations committed knowingly and purposefully and up to 10 years in a federal prison.

HIPAA Security Rule The Privacy Rules identifies what information is protected, whether it be in electronic, oral or paper form, and who may have access to that information (PHI). The Security Rules identifies steps for ensuring that only those who should have access to electronic PHI (ePHI) will actually have access. Read Slide

Administrative Safeguards The Administrative Safeguards require that facilities develop processes, policies and procedures to prevent, detect, contain, and correct security violations. Read slide.

Physical Safeguards The purpose of physical safeguards is to help protect the physical computer systems and related buildings and equipment from: - Fire - Other natural and environmental hazards - Unauthorized access. Read Slide. Among the physical safeguards that we need to address to comply with the security rules are: Facility access controls – policies and procedures relating to the physical security of the facility Workstation use and security – practices that protect work areas and computer systems from unauthorized use Device and media controls – procedures to handle computers and other items that contain electronic PHI, such as CD-ROMs and floppy diskettes.

Technical Safeguards Some of the processes used to promote compliance with the Technical Safeguard rule include: Computer system access, such as passwords Assigning security levels based on user identify or job responsibility Proper identification of individuals requesting access to ePHI Audit trails that record system activity as it occurs Read slide

Security Safeguards Passwords - don’t share and don’t post . Workstations - secure your workstation, use screen savers, lock your computer if unattended, log off when not in use, log off at night. E-mail - avoid sending sensitive/confidential patient information. Removable media (disks, CDs,) - lock up and store, dispose/destroy properly. Internet - firewalls, monitor and audit usage, utilize virus protection. Here are some examples of security safeguards. Read slide.

Remember Patient confidentiality is: Everybody’s job Read slide.