Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

Slides:



Advertisements
Similar presentations
Tamtron Users Group April 2001 Preparing Your Laboratory for HIPAA Compliance.
Advertisements

Presented by Elena Chan, UCSF Pharm.D. Candidate Tiffany Jew, USC Pharm.D. Candidate March 14, 2007 P HARMACEUTICAL C ONSULTANTS, I NC. P RO P HARMA HIPAA.
1 The Health Insurance Portability and Accountability Act (HIPAA) A guided tutorial for GVSU employees.
HIPAA Basics Brian Fleetham Dickinson Wright PLLC.
HIPAA: Privacy, Security, and HITECH, Oh My! Presented by Stephanie L. Ganucheau, Special Assistant Attorney General.
HIPAA Privacy Training. 2 HIPAA Background Health Insurance Portability and Accountability Act of 1996 Copyright 2010 MHM Resources LLC.
Health Insurance Portability and Accountability Act HIPAA Education for Volunteers and Students.
HIPAA. What Why Who How When What Is HIPAA? Health Insurance Portability & Accountability Act of 1996.
HIPAA Privacy Rule Training
Copyright Eastern PA EMS Council February 2003 Health Information Portability and Accountability Act It’s the law.
HIPAA Privacy Training Your Name Here. © 2004 MHM Resources Inc.2 HIPAA Background Health Insurance Portability and Accountability Act of 1996.
National Health Information Privacy and Security Week Understanding the HIPAA Privacy and Security Rule.
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
The Health Insurance Portability and Accountability Act of 1996– charged the Department of Health and Human Services (DHHS) with creating health information.
P E N N S Y L V A N I A C O A L I T I O N A G A I N S T D O M E S T I C V I O L E N C E P E N N S Y L V A N I A C O A L I T I O N A G A I N S T RAPE HIPAA.
HIPAA Training for Pharmaceutical Industry Representatives University of Utah Hospitals & Clinics.
Health Insurance Portability and Accountability Act (HIPAA)HIPAA.
1 HIPAA Education CCAC Professional Development Training September 2006 CCAC Professional Development Training September 2006.
Presented by the Office of the General Counsel An Overview of HIPAA.
NAU HIPAA Awareness Training
CHAPTER © 2011 The McGraw-Hill Companies, Inc. All rights reserved. 2 The Use of Health Information Technology in Physician Practices.
Reviewing the World of HIPAA Stephanie Anderson, CPC October 2006.
HIPAA Privacy Rule Compliance Training for YSU April 9, 2014.
Are you ready for HIPPO??? Welcome to HIPAA
HIPAA HIPAA Health Insurance Portability and Accountability Act of 1996.
Privacy, Security and Compliance Concerns for Management and Boards November 15, 2013 Carolyn Heyman-Layne, Esq. 1.
Privacy, Security, Confidentiality, and Legal Issues
2 The Use of Health Information Technology in Physician Practices.
HIPAA COMPLIANCE IN YOUR PRACTICE MARIBEL VALENTIN, ESQUIRE.
HIPAA – Health Insurance Portability & Accountability Act and the Privacy Act MSgt Nechele M. Chambers Senior Enlisted Liaison TRICARE Area Office-Europe.
The Use of Health Information Technology in Physician Practices
HIPAA PRIVACY AND SECURITY AWARENESS.
“ Technology Working For People” Intro to HIPAA and Small Practice Implementation.
1 HIPAA OVERVIEW ETSU. 2 What is HIPAA? Health Insurance Portability and Accountability Act.
Copyright Fleisher & Associates A HIPAA PRIMER FOR PUBLIC HEALTH PEOPLE CPHA-N Conference 2003 January 30, 2003 Presented by: Steven M. Fleisher,
Health Insurance Portability and Accountability Act (HIPAA)
The Implementation of HIPAA Joan M. Kiel, Ph.D., C.H.P.S. Duquesne University Pittsburgh, Pennsylvania.
Copyright ©2011 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved. Health Information Technology and Management Richard.
How Hospitals Protect Your Health Information. Your Health Information Privacy Rights You can ask to see or get a copy of your medical record and other.
Working with Health IT Systems Protecting Privacy, Security, and Confidentiality in HIT Systems Lecture a This material (Comp7_Unit7a) was developed by.
HIPAA Michigan Cancer Registrars Association 2005 Annual Educational Conference Sandy Routhier.
Medical Law and Ethics, Third Edition Bonnie F. Fremgen Copyright ©2009 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved.
Building a Privacy Foundation. Setting the Standard for Privacy Health Insurance Portability and Accountability Act (HIPAA) Patient Bill of Rights Federal.
Health Insurance Portability and Accountability Act (HIPAA) CCAC.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
Understanding HIPAA (Health Insurandce Portability and Accountability Act)
© 2013 The McGraw-Hill Companies, Inc. All rights reserved. Ch 8 Privacy Law and HIPAA.
HIPAA BASIC TRAINING Presented by Anderson Health Information Systems, Inc.
HIPAA PRACTICAL APPLICATION WORKSHOP Orientation Module 1B Anderson Health Information Systems, Inc.
Rhonda Anderson, RHIA, President  …is a PROCESS, not a PROJECT 2.
Working with HIT Systems
Copyright ©2014 by Saunders, an imprint of Elsevier Inc. All rights reserved 1 Chapter 02 Compliance, Privacy, Fraud, and Abuse in Insurance Billing Insurance.
HIPAA Health Insurance Portability and Accountability Act of 1996.
1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.
Copyright © 2015 by Saunders, an imprint of Elsevier Inc. All rights reserved. Chapter 3 Privacy, Confidentiality, and Security.
Configuring Electronic Health Records Privacy and Security in the US Lecture b This material (Comp11_Unit7b) was developed by Oregon Health & Science University.
HIPAA HEALTH INSURANCE PORTABILITY ACOUNTABILITY ACT.
HIPAA Overview Why do we need a federal rule on privacy? Privacy is a fundamental right Privacy can be defined as the ability of the individual to determine.
Human Subjects Update E. Wethington, Chair, UCHS.
What is HIPAA? Health Insurance Portability and Accountability Act of HIPAA is a major law primarily concentrating on the prolongation of health.
The Health Insurance Portability and Accountability Act (HIPAA) requires Plumas County to train all employees in covered departments about the County’s.
HIPAA Training Workshop #3 Individual Rights Kaye L. Rankin Rankin Healthcare Consultants, Inc.
HIPAA Privacy Rule Training
UNDERSTANDING WHAT HIPAA IS AND IS NOT
What is HIPAA? HIPAA stands for “Health Insurance Portability & Accountability Act” It was an Act of Congress passed into law in HEALTH INSURANCE.
HIPAA CONFIDENTIALITY
HIPAA PRIVACY AWARENESS, COMPLIANCE and ENFORCEMENT
Disability Services Agencies Briefing On HIPAA
Enforcement and Policy Challenges in Health Information Privacy
HIPAA Policy & Procedure Strategies
Presentation transcript:

Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna

The Law HIPAA: Health Insurance Portability & Accountability Act HITECH: Health Information Technology Economic & Clinical Health Act

HIPAA is Eleven Parts And what were you doing on July 30, 2004?

Six Parts Are Set 1. T & C 2. Privacy 3. Standard Unique Identifier for Employers 4. Security 5. Standard Unique HC Provider Identifier (NPI) 6. Enforcement Rule

HIPAA Information HIPAA covers: Oral Written (and beyond the medical record) Electronic [key: can the individual be identified] You will hear the term PHI- patient health information

Keep in Mind Minimum Necessary [45CFR (b)(1)] Emergency Situation [45CFR (3)] ∙ Incidental Disclosure [45CFR (a)(1)(iii)]

Are You HIPAA or Not? YES NO

Covered Entity Status Health Plan: individual or group plan that provides or pays the cost of medical care Healthcare Clearinghouse: public or private entity that does billing, repricing, community health management or information systems, etc. functions

Covered Entity Status Healthcare Provider: transmits any health information in electronic form in connection with a transaction covered by HIPAA

Sample HIPAA Transactions Health care claims or equivalent encounter information Health care payment and remittance advice Coordination of benefits Health care claims status

Who Do You Treat Students (and how are they defined; ie. LOA) Non-Students For organizations under FERPA, student records are under FERPA (loophole) even with transactions, but non student records are under HIPAA, so you are a covered entity. But most strict law generally takes precedent

You Are HIPAA If… You are one or more of the three covered entities You conduct one or more of the eleven transactions You treat non-students

College Assessment Also look at these areas: Student, Faculty, and Employee Training *Nursing *Pharmacy *Allied Health *Music Therapy *Business (I.T.)

College Assessment Health Services & Related Clinics Institutional Review Board; research Human Resources Athletics Vendors as business associates

Hybrid Entity A single legal entity whose business activities include both covered and non- covered functions (ie. education & healthcare provider or health plan

Creating a Culture of HIPAA Are the policies and procedures set? Are they enforced or do they ‘sit on the shelf”

Compliance Officer Role Privacy Officer [45CFR (a)(1)(i)] Security Officer [45CFR (a)(2)] The Federal Government mandates that covered entities have both a privacy officer and a security officer If the same person, generally titled, Compliance Officer

1. HIPAA Committee Representatives from records, information technology, student services and management.

2. Policies & Procedures For the six HIPAA Rules to date, develop policies from the law, not secondary sources Do not take from the Internet

3. Training & Awareness Live or on-line Staff meeting awareness Integrate awareness to daily activities

4. Documentation Establish a system, on- site or off-site. Documentation must be retained for six years

5. Risk Assessments & Audits Quarterly Authentication: most likely passwords Data integrity checks Act on the findings

6. Complaint Process Omsbudsman for confidentiality Post process to file complaints Complaints are only to be HIPAA related Act on the complaints

7. Sanction Process Sanction only for the HIPAA violation Internal investigation or OCR Civil and criminal penalties per Enforcement Rule & HITECH Follow-up on the sanction and charge

8. Web Site If the covered entity has a web site, the Notice of Health Information Privacy Practices must be prominently displayed on the web site. Keep the web site updated

9. Formage Develop forms from the laws. May or may not be able to use from other covered entities (ie. addressable Security Rule policies) Educate staff on the formage

10. Business Associate Agreements Assess all those external to the workforce who have access to the covered entity’s PHI Both the Privacy Rule and the Security Rule mandate BAA’s

11. Research Play an integral role with the covered entity’s Institutional Review Board Ensure minimum necessary standards for data used in research

Determination of HIPAA Research Status Does the research involve the collection, use, or dissemination of PHI? Is the PHI from a healthcare provider, clearinghouse, or healthcare plan? Does the healthcare provider, clearinghouse, or healthcare plan perform one of the eleven covered electronic transactions? If yes to these, then HIPAA

Privacy Rule Notice & Notice Verification Internet Notice Amend Records Authorization Accounting Information Destruction Business Associate Agreements

The Notice Tells the rights of the organization and the rights of the patient Document that is considered the guideline.

Security Rule Technical Security Administrative Security Physical Security Disaster Manual Access Controls Log-in Audit Warning Termination of Access

Faculty & Staff Access Have access to minimum necessary information to accomplish the intended purpose of the request given their role Must have an established need to know prior to requesting the information Ex. How long absent, but not the condition as it would not change the situation

Advising Faculty, Staff, & Students Is the condition directly academically related such as ADHD But must always only request what is minimum necessary Have the student only submit and talk on what is minimum necessary Ex. Operating room reports, procedures notes, consultation reports, prescriptions Ensure who student allows one to talk to

Summary Follow the Law Keep it simple Thank you