Office of the Secretary Office for Civil Rights (OCR) Indian Health Service HIPAA Training Hosted by the Aberdeen Area Office July 24, 2012.

Slides:



Advertisements
Similar presentations
HIPAA Privacy Practices. Notice A copy of the current DMH Notice must be posted at each service site where persons seeking DMH services will be able to.
Advertisements

 What is the Privacy Rule? The Standards for Privacy of Individually Identifiable Health Information (Privacy Rule) governs the use and disclosure of.
1 The HIPAA Privacy Rule and Research This presentation will probably involve audience discussion, which will create action items. Use PowerPoint to keep.
HIPAA Privacy Training. 2 HIPAA Background Health Insurance Portability and Accountability Act of 1996 Copyright 2010 MHM Resources LLC.
Confidentiality and HIPAA
HIPAA Privacy Rule Training
National Health Information Privacy and Security Week Understanding the HIPAA Privacy and Security Rule.
The Health Insurance Portability and Accountability Act of 1996– charged the Department of Health and Human Services (DHHS) with creating health information.
P E N N S Y L V A N I A C O A L I T I O N A G A I N S T D O M E S T I C V I O L E N C E P E N N S Y L V A N I A C O A L I T I O N A G A I N S T RAPE HIPAA.
HIPAA PRIVACY REQUIREMENTS Dana L. Thrasher Constangy, Brooks & Smith, LLC (205) ; Victoria Nemerson.
What is HIPAA? This presentation was created by The University of Arizona Privacy Office, The Office for the Responsible Conduct of Research on March 5,
North Carolina State University Health Information Privacy 4/16/03.
WHAT IS HIPAA? The Health Insurance Portability and Accountability Act of 1996 (HIPAA) provides certain protections for any of your health information.
TM The HIPAA Privacy Rule: Safeguarding Health Information in Research and Public Health Practice Centers for Disease Control and Prevention Beverly A.
Copyright 2006 Rubin Law Firm, LLC Drafting HIPAA Compliant Subpoenas & Discovery Presented by:RACHEL B. RUBIN Kansas Bar Association Annual Meeting June.
HIPAA Regulations What do you need to know?.
COMPLYING WITH HIPAA PRIVACY RULES Presented by: Larry Grudzien, Attorney at Law.
HIPAA THE PRIVACY RULE Reviewed December HISTORY In 2000, many patients that were newly diagnosed with depression received free samples of anti-
Jill Moore April 2013 HIPAA Update: New Rules, New Challenges.
Health Insurance Portability and Accountability Act (HIPAA)
Health Insurance Portability Accountability Act of 1996 HIPAA for Researchers: IRB Related Issues HSC USC IRB.
August 10, 2001 NESNIP PRIVACY WORKGROUP HIPAA’s Minimum Necessary Standard Presented by: Mildred L. Johnson, J.D.
Version 6.0 Approved by HIPAA Implementation Team April 14, HIPAA Learning Module The following is an educational Powerpoint presentation on the.
HIPAA COMPLIANCE IN YOUR PRACTICE MARIBEL VALENTIN, ESQUIRE.
Notice of Privacy Practices Nebraska SNIP Privacy Subgroup July 18, 2002 Michael J. Brown, MHA, CPA Vice-President, Administrative & Regulatory Affairs,
HIPAA PRIVACY AND SECURITY AWARENESS.
1 Disclosures © HIPAA Pros 2002 All rights reserved.
Health Information Privacy and Accountability Act
Confidentiality, Consents and Disclosure Recent Legal Changes and Current Issues Presented by Pam Beach, Attorney at Law.
1 HIPAA OVERVIEW ETSU. 2 What is HIPAA? Health Insurance Portability and Accountability Act.
Dealing with Business Associates Business Associates Business Associates are persons or organizations that on behalf of a covered entity: –Perform any.
Quality Integrity Stewardship Courtesy Care Accountability Medical Records ARMA Florida Gulf Coast Chapter Michael Spake Lakeland Regional Medical Center.
Computerized Networking of HIV Providers Workshop Data Security, Privacy and HIPAA: Focus on Privacy Joy L. Pritts, J.D. Assistant Research Professor Health.
Established in 1996 to enforce standards for electronic health information & enhance the security and privacy of health information.
HIPAA Michigan Cancer Registrars Association 2005 Annual Educational Conference Sandy Routhier.
HIPAAand Disaster Situations By LYNDA M. JOHNSON Friday, Eldredge & Clark.
© 2009 The McGraw-Hill Companies, Inc. All rights reserved. 1 McGraw-Hill Chapter 2 The HIPAA Privacy Standards HIPAA for Allied Health Careers.
Speak HIPAA Like a Native A Guide to Common HIPAA Nomenclature University of Miami Ethics Programs.
Health Insurance Portability and Accountability Act (HIPAA) CCAC.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
© 2013 The McGraw-Hill Companies, Inc. All rights reserved. Ch 8 Privacy Law and HIPAA.
Chapter 7—Privacy Law and HIPAA
PricewaterhouseCoopers 1 Administrative Simplification: Privacy Audioconference April 14, 2003 William R. Braithwaite, MD, PhD “Doctor HIPAA” HIPAA Today.
FleetBoston Financial HIPAA Privacy Compliance Agnes Bundy Scanlan Managing Director and Chief Privacy Officer FleetBoston Financial.
HIPAA PRACTICAL APPLICATION WORKSHOP Orientation Module 1B Anderson Health Information Systems, Inc.
HIPAA THE PRIVACY RULE. 2 HISTORY In 2000, many patients that were newly diagnosed with depression received free samples of anti- depressant medications.
Rhonda Anderson, RHIA, President  …is a PROCESS, not a PROJECT 2.
Copyright ©2014 by Saunders, an imprint of Elsevier Inc. All rights reserved 1 Chapter 02 Compliance, Privacy, Fraud, and Abuse in Insurance Billing Insurance.
A Road Map to Research at Jefferson: HIPAA Privacy and Security Rules for Researchers Presented By: Privacy Officer/Office of Legal Counsel October 2015.
HIPAA Privacy Rule Implementation Status Report Richard M. Campanelli, J.D. Director, Office for Civil Rights Before the The Tenth National HIPAA Summit.
HIPAA: Breach Notification By: Office of University Counsel For: Jefferson IRB Continuing Education September 2014.
HIPAA Overview Why do we need a federal rule on privacy? Privacy is a fundamental right Privacy can be defined as the ability of the individual to determine.
Final PRIVACY RULE Presentation by Richard Campanelli, Director OCR/HHS at 5 th National HIPAA Summit Washington, D.C. October 31, 2002.
The Medical College of Georgia HIPAA Privacy Rule Orientation.
Health Insurance Portability and Accountability Act (HIPAA) © 2013 Project Lead The Way, Inc.Principles of Biomedical Science.
Disclaimer This presentation is intended only for use by Tulane University faculty, staff, and students. No copy or use of this presentation should occur.
HIPAA Training Workshop #2 Trainer: Kaye L. Rankin Rankin Healthcare Consultants, Inc.
Juvenile Legislative Update 2013 Confidential Records and Protected Disclosures.
HIPAA Training Workshop #3 Individual Rights Kaye L. Rankin Rankin Healthcare Consultants, Inc.
HIPAA Privacy Rule Training
HIPAA THE PRIVACY RULE Reviewed December 2012.
Enforcement, Business Associates and Breach Notification. Oh my!
HIPAA CONFIDENTIALITY
HIPAA Administrative Simplification
Health Insurance Portability and Accountability Act
HIPAA Pros - Disclosures
Disability Services Agencies Briefing On HIPAA
Health Insurance Portability and Accountability Act
National Congress on Health Care Compliance
Presentation transcript:

Office of the Secretary Office for Civil Rights (OCR) Indian Health Service HIPAA Training Hosted by the Aberdeen Area Office July 24, 2012

OCR 2 Who must follow the Privacy Rule? Three categories of covered entities: –Health plans –Health care clearinghouses –Health care providers who transmit health information electronically in connection with certain administrative and financial transactions

OCR HIPAA Regulation - Coverage “Covered entities” - health care providers who electronically transmit health information in connection with a standard transaction; health plans; health care clearinghouses Hybrid entities (e.g., HHS) Business associates (contract usually required) 3

OCR Business Associates Provides that a business associate may use or disclose PHI only if such use or disclosure is in accordance with the HIPAA Privacy Rule’s required terms for business associate contracts. 4

OCR Scope: What is Covered? Not PHI: –De-identified information –Employment records –FERPA records 5

OCR 6 Uses and Disclosures: Key Points No use or disclosure of PHI unless permitted or required by the Privacy Rule. Required Disclosures: –To the individual who is the subject of the PHI. –To the Secretary of HHS in order to determine compliance.

OCR Uses and Disclosures: Key Points All other uses and disclosures in the Privacy Rule are permissive. Covered Entities may provide greater protections. 7

OCR 8 HIPAA Privacy Rule and Mental Health Information Most mental health information protected to same degree and manner as other PHI Exception for psychotherapy notes that are maintained separate from the rest of the patient’s medical record

OCR 9 To Individuals Besides making required disclosures, Covered Entities may also disclose PHI to their patients or enrollees. For example: –Health plans may contact their enrollees. –Providers may contact or speak with their patients. Covered Entities must treat a personal representative -- person who has authority to make decision related to health care -- as an individual

OCR 10 Sharing Information under the HIPAA Privacy Rule Relevant permissible disclosures of PHI under the Privacy Rule may include: –With authorization of patient or personal representative Without authorization, subject to conditions: For treatment Involved in care or payment for care

OCR 11 Sharing Information under the HIPAA Privacy Rule –Without authorization, subject to conditions: To parents, family, or others involved in care (with the opportunity to agree or object) To avert a serious and imminent threat to health or safety To law enforcement As required by other law

OCR Permissive Uses and Disclosures To the individual or personal representative For specific public priorities “Incident to” Limited data sets As authorized by the individual 12

OCR Permissive Uses and Disclosures For treatment, payment, and health care operations (TPO) Treatment also includes the coordination or management of health care by a health care provider with a third party, which could include others responsible for following the care of the individual after discharge 13

OCR 14 To Parents, Family, or Others Involved in Care PHI may be disclosed to parents or other persons who are involved in care personal representatives of the patient

OCR Incidental Use and Disclosures The Privacy Rule permits uses and disclosures incidental to an otherwise permitted use or disclosure, provided minimum necessary and reasonable safeguard standards are met. –Examples: talking to a patient in a semi- private room; talking to other providers if passers-by are present; waiting-room sign-in sheets; patient charts at bedside. Allows for common practices if reasonably performed 15

OCR Opportunity to Agree or Object To disclose PHI to persons involved in care or payment for care and for notification purposes. For example: –Friends may pick up prescriptions. –Hospitals may notify family members of a patient’s condition. –Covered entities may notify disaster relief agencies. 16

OCR 17 To Parents, Family, or Others Involved in Care If the patient does not object, relevant PHI also may be disclosed to family members or other persons identified by the patient as involved in the patient’s care or payment (may not be personal representatives)

OCR 18 Public Priorities Covered entities may use or disclose PHI under these provisions if required conditions are met: –As required by law –For public health activities –About victims of abuse, neglect or domestic violence –For health oversight activities –For judicial and administrative proceedings

OCR Public Priorities –For law enforcement purposes –To coroners, medical examiners, funeral directors –For cadaveric organ, eye, or tissue donation purposes –For research purposes –To avert a serious threat to health & safety –For specialized government functions –For workers’ compensation 19

OCR 20 Minimum Necessary Standard Covered entities must make reasonable efforts to use, disclose, or request the minimum necessary PHI based on purpose. Exceptions to the minimum necessary standard: e.g., disclosure of PHI for the purpose of treatment

OCR 21 Minimum Necessary Standard Covered entities must develop criteria to limit disclosures of and requests for PHI to the minimum necessary.

OCR 22 With Authorization PHI may be disclosed with written, signed authorization of patient or patient’s personal representative Authorization must meet requirements of Privacy Rule

OCR 23 With Authorization Personal representatives are: –For adults/emancipated minors, persons with legal authority to make health care decisions on behalf of patient –For unemancipated minors, parent or guardian generally

OCR 24 Individual Rights Notice of Privacy Practices Access: inspect and copy Amendment Accounting Alternative communications Request restriction Complaints to Covered Entity and Secretary

OCR Individual Rights Individual has the right to written notice of the uses and disclosures of PHI that may be made by CE, CE’s legal duties with regard to PHI, and individual rights. Required elements in Privacy Rule 25

OCR Individual Rights In most cases, Covered Entity must post and provide a copy to the individual on first contact with providers and upon enrollment with health plan and upon request. Covered provider must document “good faith effort” to obtain acknowledgement. 26

OCR Alternative Communication A covered health care provider must permit the individual to request and must accommodate reasonable requests to receive communications of PHI by alternative means and at alternative locations. The requirement applies to health plans if the individual clearly states that the disclosure could endanger the individual. 27

OCR 28 Access Individual has a right to inspect and obtain a copy of PHI about the individual in a designated record set (“DRS”) for as long as the DRS is maintained. Reasonable fees are allowed for copying and postage only (no retrieval fees allowed).

OCR Administrative Requirements Covered Entities must: –Designate a Privacy Officer; –Designate a contact person or office to receive complaints and provide further information; –Provide privacy training to all workforce members; –Develop and apply sanction policy for workforce members who fail to comply; 29

OCR Administrative Requirements Implement policies and procedures designed to comply with standards. –Implement administrative, technical and physical safeguards to protect privacy of PHI; –Mitigate any harmful effect of a violation known to the covered entity to the extent practicable; 30

OCR Administrative Requirements –Provide an internal complaint process for individuals; –Refrain from intimidating and retaliatory acts; –Not require individuals to waive their rights. 31

OCR Safeguards Common IHS Safeguards concern: Sending PHI by - Heather McClane 32

OCR Security Rule Part 164 – Security Rule and Privacy Rule 33

OCR HITECH and HIPAA 1996 HIPAA Administrative Simplification –Standards for administrative/financial transactions for efficiency/cost savings –Standards for security and privacy to protect patient identifiable information 34

OCR HITECH and HIPAA 2009 HITECH Act –Standards for electronic records and data sharing in clinical setting, for quality reporting, and other population health purposes –Subpart D for privacy protections and security for patient identifiable information 35

OCR Breach Notification Covered entities must notify each affected individual of breach of “unsecured protected health information.” Business associate must notify covered entity of breach 36

OCR Breach Notification Notice to media if more than 500 people affected. Notifications to be provided without unreasonable delay (but no later than within 60 days) of discovery of breach. Notice to Secretary of breach and posting on HHS Website. 37

OCR 38 Compliance and Enforcement Any person or organization can file complaints with OCR (generally within 180 days) OCR may investigate complaints and may conduct compliance reviews Covered entity must provide OCR with access to records; subpoena authority OCR shall attempt to resolve noncompliance by informal means

OCR 39 Complaint Investigations Every complaint received by OCR is reviewed and allegations analyzed. An investigation is launched when warranted by the facts and circumstances presented by the complaint.

OCR 40 Complaint Investigations OCR investigations have resulted in changes in privacy practices and other corrective actions in over 7,861 cases since April Corrective action obtained by HHS from covered entities has resulted in systemic change that benefits all individuals they serve.

OCR Most Common Complaints The compliance issues investigated most frequently, in order, are: Impermissible use or disclosure of an individual’s identifiable health information 41

OCR Most Common Complaints example of impermissible use: viewing your own PHI, that of a coworker or of a family member example of impermissible disclosure: telling PHI from work to someone outside of work 42

OCR Most Common Complaints The compliance issues investigated most frequently, in order, are: The lack of adequate safeguards to protect identifiable health information Refusal or failure to provide the individual with access to or a copy of his/her records 43

OCR Most Common Complaints The compliance issues investigated most frequently, in order, are: The disclosure of more information than is minimally necessary to satisfy a particular request for information Failure to have the individual’s valid authorization for a disclosure that requires one 44

OCR Our Mutual Goal Ensuring the privacy and security of each individual’s health information in accordance with the standards and requirements of the HIPAA Privacy Rule 45

OCR Indications of Noncompliance 45 CFR : If investigation or compliance review indicates noncompliance, HHS will attempt to reach resolution satisfactory to the Secretary by “informal means.” 46

OCR Indications of Noncompliance “Informal means” includes: –Demonstrated compliance; –Completed corrective action plan; or –Other agreement. 47

OCR 48 OCR Web Site Privacy:

OCR Additional Information On HIPAA Privacy Rule protections and requirements: rstanding/index.html rstanding/index.html 49

OCR Additional Information On HIPAA Privacy Rule resolution agreements and other enforcement actions: cement/examples/index.html cement/examples/index.html 50

OCR 51 OCR Web Site Karel Hadacek, J.D. Equal Opportunity Specialist