HIPAA Health Insurance Portability & Accountability Act of 1996.

Slides:



Advertisements
Similar presentations
Todd Frech Ocius Medical Informatics 6650 Rivers Ave, Suite 137 North Charleston, SC Health Insurance Portability.
Advertisements

HIPAA Privacy Rule “Standards for Privacy of Individually Identifiable Health Information” 45 CFR 160 and 164* *
Presented by Elena Chan, UCSF Pharm.D. Candidate Tiffany Jew, USC Pharm.D. Candidate March 14, 2007 P HARMACEUTICAL C ONSULTANTS, I NC. P RO P HARMA HIPAA.
1 The Health Insurance Portability and Accountability Act (HIPAA) A guided tutorial for GVSU employees.
HIPAA: Privacy, Security, and HITECH, Oh My! Presented by Stephanie L. Ganucheau, Special Assistant Attorney General.
HIPAA and Public Health 2007 Epi Rapid Response Team Conference.
Health Insurance Portability and Accountability Act HIPAA Education for Volunteers and Students.
HIPAA. What Why Who How When What Is HIPAA? Health Insurance Portability & Accountability Act of 1996.
Confidentiality and HIPAA
HIPAA Privacy Rule Training
COBB/DOUGLAS COMMUNITY SERVICES BOARD Confidentiality and Privacy of Consumer Information.
HIPAA – Privacy Rule and Research USCRF Research Educational Series March 19, 2003.
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
HIPAA Training for Pharmaceutical Industry Representatives University of Utah Hospitals & Clinics.
HIPAA PRIVACY REQUIREMENTS Dana L. Thrasher Constangy, Brooks & Smith, LLC (205) ; Victoria Nemerson.
HIPAA Health Insurance Portability and Accountability Act.
What is HIPAA? This presentation was created by The University of Arizona Privacy Office, The Office for the Responsible Conduct of Research on March 5,
Health Insurance Portability and Accountability Act (HIPAA)HIPAA.
1 HIPAA Education CCAC Professional Development Training September 2006 CCAC Professional Development Training September 2006.
Dr. Yaseen Hayajneh Health Insurance Portability and Accountability Act Yaseen HayajnehYaseen Hayajneh RN, MPH, PhD.
NAU HIPAA Awareness Training
TM The HIPAA Privacy Rule: Safeguarding Health Information in Research and Public Health Practice Centers for Disease Control and Prevention Beverly A.
HIPAA Privacy Keys to Success Education for Nursing and all other Clinical Students Effective January 2010 HIPAA Job Specific Education1.
HIPAA Health Insurance Portability and Accountability Act.
Informed Consent.
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996 (HIPAA)
HIPAA Privacy Rule Compliance Training for YSU April 9, 2014.
 The Health Insurance Portability and Accountability Act of  Federal Law designed to protect sensitive information.  HIPAA violations are enforced.
COMPLYING WITH HIPAA PRIVACY RULES Presented by: Larry Grudzien, Attorney at Law.
Are you ready for HIPPO??? Welcome to HIPAA
HIPAA HIPAA Health Insurance Portability and Accountability Act of 1996.
Medical Records in Court: Life after HIPAA North Carolina Conference of Superior Court Judges, October 2003 Presented by Jill Moore, UNC School of Government.
HIPAA: It Doesn’t Only Impact Medical Records Basic HIPAA Stuff and Overall Information Protection 1.
Health Insurance Portability and Accountability Act of 1996
Health Insurance Portability and Accountability Act (HIPAA)
HIPAA – Health Insurance Portability & Accountability Act and the Privacy Act MSgt Nechele M. Chambers Senior Enlisted Liaison TRICARE Area Office-Europe.
Proprietary and confidential and may not be reproduced or distributed without the express consent of Cap Gemini Ernst & Young U.S. LLC and Ernst & Young.
Paula Peyrani, MD Medical/Project Director, HIV Program at the 550 Clinic Assistant Director, Research Design and Development Clinical and Translational.
HIPAA PRIVACY AND SECURITY AWARENESS.
HIPAA Business Associates Leadership Group Meeting June 28, 2001.
HIPAA The Privacy Rule Health Insurance Portability and Accountability Act of 1996 (HIPAA) The 104 th Congress passed the Act, Public Law ,
1 HIPAA OVERVIEW ETSU. 2 What is HIPAA? Health Insurance Portability and Accountability Act.
Health Insurance Portability and Accountability Act (HIPAA)
PRIVACY AND HIPAA THE RIGHT THING TO DO. WHAT’S WRONG WITH THIS PICTURE? ? “ Did you hear that Jane from the 5 th floor is in the hospital?” “No!! Let’s.
HIPAA Michigan Cancer Registrars Association 2005 Annual Educational Conference Sandy Routhier.
Medical Law and Ethics, Third Edition Bonnie F. Fremgen Copyright ©2009 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved.
Speak HIPAA Like a Native A Guide to Common HIPAA Nomenclature University of Miami Ethics Programs.
Health Insurance Portability and Accountability Act (HIPAA) CCAC.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
Understanding HIPAA (Health Insurandce Portability and Accountability Act)
HIPAA Health Insurance Portability and Accountability Act of 1996.
HIPAA Health Insurance Portability and Accountability Act.
Configuring Electronic Health Records Privacy and Security in the US Lecture b This material (Comp11_Unit7b) was developed by Oregon Health & Science University.
HIPAA Overview Why do we need a federal rule on privacy? Privacy is a fundamental right Privacy can be defined as the ability of the individual to determine.
Final HIPAA Privacy Rule: The Research Provisions Julie Kaneshiro DHHS Office for Human Research Protections Phone: Fax:
Privacy: HIPAA Emerson Murphy-Hill. Rosie Callender, RHIA, web.msm.edu/hipaa/An%20Introduction%20to%20HIPAA.ppt What is HIPAA? A Federal Law Created in.
Developed for Ridgeview Institute 2015 Hospital Wide Orientation
HIPAA Privacy Rule Training
Health Insurance Portability and Accountability Act of 1996
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA)
What is HIPAA? HIPAA stands for “Health Insurance Portability & Accountability Act” It was an Act of Congress passed into law in HEALTH INSURANCE.
HIPAA CONFIDENTIALITY
HIPAA Administrative Simplification
HIPAA PRIVACY AWARENESS, COMPLIANCE and ENFORCEMENT
Disability Services Agencies Briefing On HIPAA
New School Violence Law; HIPAA Privacy Training
HIPAA & PHI TRAINING & AWARENESS
The Health Insurance Portability and Accountability Act
Presentation transcript:

HIPAA Health Insurance Portability & Accountability Act of 1996

HIPAA Administration Simplification Multi-phased law Enacted to reduce health care administrative costs through standardization of electronic health care transactions Need to protect security and privacy

Basic Principles of HIPAA Privacy Rules It gives individuals more control over their health information. It sets boundaries on the use and release of health information. It establishes safeguards that covered entities must achieve to protect the privacy of health information. It holds violators accountable, by imposing civil and criminal penalties if they violate an individual’s privacy rights.

Who Has to Comply with HIPAA? Each Covered Entity (CE) must comply Covered entity means: 1.A health plan 2.A health care clearinghouse 3.A health care provider that transmits any health information in electronic form in connection with a standard transaction.

What is PHI? Any information, oral or recorded in any form or medium, that: –Is created or received by a health plan, health care provider, healthcare clearing house; and –Relates to the past, present or future physical or mental health or condition of an individual, or the provision or payment for health care for an individual; and –Is individually identifiable (as defined)

Identifiers: Any of the following numbers: Social Security Medical Record Account & Health Plan beneficiary #’s Certificate/license Vehicle ID or plate URL or IP addresses Device identifiers Biometric identifiers Full face or comparable images Names Geographic units Dates (month/day relating to any individual including birth, treatment) Ages over 89 Phone, fax numbers addresses Any other unique identifiers

Use and Disclosure of PHI General Rule A covered entity may not use or disclose PHI, except as required or permitted by the regulations. Permitted Uses and Disclosures (TPO) Treatment Payment Health care Operations

Business Associate Agreement By law, the HIPAA privacy rule applies only to covered entities. However, most CEs do not conduct all business activities and functions alone. What is a Business Associate? A person who, on behalf of a covered entity: Uses/accesses/re-discloses PHI either –To perform or assist in the performance of a function –Provides services to a covered entity Must involve the use of individually identifiable health information An employee of the employer sponsoring the plan is not a business associate.

Health Care Operations - Business Associates provide Services involving disclosure Legal Accounting Data aggregation Administration Consultants Actuarial Accreditation Management Financial Services Third Party Administrators Contractors, vendors of covered entities Employers and other plan sponsors Any person relying on any covered entity as source of health information

Business Associates Business Associates may perform functions for covered entities with “satisfactory assurance” of appropriate safeguards for PHI. The satisfactory assurances must be in writing, whether in the form of a contract or other agreement between the covered entity and the business associate.

Business Associates Contracts Required Elements 45 CFR (e) Describe the permitted and required uses of PHI. Provide that the business associate will not use or further disclose the PHI other than as permitted or required by the contract or as required by law; and Require the business associate to use appropriate safeguards to prevent a use or disclosure of the PHI other than provided for by the contract.

Forms of Patient Permission to Use or Disclose PHI There are three possible forms of “permission” needed to use or disclose PHI: 1.For TPO or for “public purposes” (such as cooperating enforcement, public health agencies or courts). 2.Verbal Agreement – For disclosure to people involved in the health care of the patient, or for facility directory listings. 3.Authorization – For all other circumstances.

Authorizations Authorizations are required by the Privacy Rule 45 CFR (a) CE are required to obtain an authorization for use and disclosure of PHI. CE may use only authorizations that meet the requirements of 45 CFR (b) Any such use or disclosure will be lawful only to the extent it is consistent with the terms of such authorization.

Penalties for Non- Compliance $100 fine per day for each unmet standard (Up to $25,000 per person, per year, per standard). $50,000 fine PLUS one year in prison for knowingly disclosing health information for improper use or to unauthorized entities $100,000 fine PLUS five years in prison for obtaining health information under false pretenses. $250,000 fine PLUS ten years in prison for using health information to sell, transfer, or use for commercial advantage, personal gain or malicious harm.

Remember…. PHI should be seen only by those who are authorized to see it. PHI should be heard by only those who are authorized to hear it. PHI should be transmitted to or shared with only those who are authorized to receive it.