HIPAA TRIVIA Do you know HIPAA?. HIPAA was created by?  The Affordable Care Act  Health Insurance companies  United States Congress  United States.

Slides:



Advertisements
Similar presentations
The Department has declared itself to be a single covered entity. Thus, each and every one of our divisions is a covered entity and must comply with.
Advertisements

HIPAA: An Overview of Transaction, Privacy and Security Regulations Training for Providers and Staff.
HIPAA Training: Health Insurance Portability and Accountability Act.
Presented by Elena Chan, UCSF Pharm.D. Candidate Tiffany Jew, USC Pharm.D. Candidate March 14, 2007 P HARMACEUTICAL C ONSULTANTS, I NC. P RO P HARMA HIPAA.
1 The Health Insurance Portability and Accountability Act (HIPAA) A guided tutorial for GVSU employees.
HIPAA Basics Brian Fleetham Dickinson Wright PLLC.
1. As a Florida KidCare community partner families entrust you to not only help them navigate the Florida KidCare system but to keep the information they.
HIPAA Privacy Training. 2 HIPAA Background Health Insurance Portability and Accountability Act of 1996 Copyright 2010 MHM Resources LLC.
Health Insurance Portability and Accountability Act HIPAA Education for Volunteers and Students.
HIPAA Privacy Rule Training
HIPAA Privacy Training Your Name Here. © 2004 MHM Resources Inc.2 HIPAA Background Health Insurance Portability and Accountability Act of 1996.
National Health Information Privacy and Security Week Understanding the HIPAA Privacy and Security Rule.
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
The Health Insurance Portability and Accountability Act of 1996– charged the Department of Health and Human Services (DHHS) with creating health information.
HIPAA What’s New? What Is HIPAA Health Insurance Portability and Accountability Act of 1996 Health Insurance Portability and Accountability Act.
1 HIPAA Education CCAC Professional Development Training September 2006 CCAC Professional Development Training September 2006.
Key Changes to HIPAA from the Stimulus Bill (ARRA) Children’s Health System Department Leadership Meeting October 28, 2009 Kathleen Street Privacy Officer/Risk.
NAU HIPAA Awareness Training
HIPAA Health Insurance Portability and Accountability Act 1.
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996 (HIPAA)
HIPAA Privacy Rule Compliance Training for YSU April 9, 2014.
H IPAA PRIVACY WORK GROUP FOR EYE BANKS EBAA HIPAA PRIVACY WORK GROUP Christina W. Strong, Esq., Facilitator.
COMPLYING WITH HIPAA PRIVACY RULES Presented by: Larry Grudzien, Attorney at Law.
Health Insurance Portability & Accountability Act “HIPAA” To every patient, every time, we will provide the care that we would want for our own loved ones.
HIPAA THE PRIVACY RULE Reviewed December HISTORY In 2000, many patients that were newly diagnosed with depression received free samples of anti-
2014 HIPAA Refresher Omnibus Rule & HIPAA Security.
Are you ready for HIPPO??? Welcome to HIPAA
HIPAA HIPAA Health Insurance Portability and Accountability Act of 1996.
POP QUIZ!! What does CMS stand for? What does HIPAA stand for?
2 HIPAA, HITECH, and Medical Records. Learning Outcomes When you finish this chapter, you will be able to: 2.1Discuss the importance of medical records.
HIPAA COMPLIANCE IN YOUR PRACTICE MARIBEL VALENTIN, ESQUIRE.
HIPAA Health Insurance Portability & Accountability Act of 1996.
Columbia University Medical Center Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) Privacy & Information Security Training 2009.
HIPAA PRIVACY AND SECURITY AWARENESS.
Health Insurance Portability and Accountability Act (HIPAA)
Copyright ©2011 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved. Health Information Technology and Management Richard.
Computerized Networking of HIV Providers Workshop Data Security, Privacy and HIPAA: Focus on Privacy Joy L. Pritts, J.D. Assistant Research Professor Health.
HIPAA Training Developed for Ridgeview Institute 2012 Hospital Wide Orientation.
HIPAA (health insurance portability and accountability act)
HIPAA Michigan Cancer Registrars Association 2005 Annual Educational Conference Sandy Routhier.
Medical Law and Ethics, Third Edition Bonnie F. Fremgen Copyright ©2009 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved.
Building a Privacy Foundation. Setting the Standard for Privacy Health Insurance Portability and Accountability Act (HIPAA) Patient Bill of Rights Federal.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
© 2013 The McGraw-Hill Companies, Inc. All rights reserved. Ch 8 Privacy Law and HIPAA.
HIPAA BASIC TRAINING Presented by Anderson Health Information Systems, Inc.
HIPAA PRACTICAL APPLICATION WORKSHOP Orientation Module 1B Anderson Health Information Systems, Inc.
HIPAA THE PRIVACY RULE. 2 HISTORY In 2000, many patients that were newly diagnosed with depression received free samples of anti- depressant medications.
HealthBridge is one of the nation’s largest and most successful health information exchange organizations. Tri-State REC: Privacy and Security Issues for.
Rhonda Anderson, RHIA, President  …is a PROCESS, not a PROJECT 2.
C HAPTER 34 Code Blue Health Sciences Edition 4. Confidentiality of sensitive information is an important issue in healthcare. Breaches of confidentiality.
A Road Map to Research at Jefferson: HIPAA Privacy and Security Rules for Researchers Presented By: Privacy Officer/Office of Legal Counsel October 2015.
HIPAA Health Insurance Portability and Accountability Act.
1 Changes to Privacy Regulations under ARRA May 4, 2009 Melissa Goldstein, J.D. The George Washington University School of Public Health and Health Services.
HIPAA: Breach Notification By: Office of University Counsel For: Jefferson IRB Continuing Education September 2014.
HIPAA Overview Why do we need a federal rule on privacy? Privacy is a fundamental right Privacy can be defined as the ability of the individual to determine.
AND CE-Prof, Inc. January 28, 2011 The Greater Chicago Dental Academy 1 Copyright CE-Prof, Inc
Final HIPAA Rule Special Training What you need to know to remain compliant with the new regulations.
HIPAA Training. What information is considered PHI (Protected Health Information)  Dates- Birthdays, Dates of Admission and Discharge, Date of Death.
The Medical College of Georgia HIPAA Privacy Rule Orientation.
New Hire HIPAA Orientation. HIPAA Overview HIPAA is an acronym that stands for the Health Insurance Portability and Accountability Act of HIPAA.
Copyright © 2009 by The McGraw-Hill Companies, Inc. All Rights Reserved. McGraw-Hill/Irwin Chapter 6 The Privacy and Security of Electronic Health Information.
Health Insurance Portability and Accountability Act (HIPAA) Primer for Observers, Volunteers, Medical Students Dr. Michael Palumbo- Privacy Officer/ EVP.
Developed for Ridgeview Institute 2015 Hospital Wide Orientation
HIPAA Privacy Rule Training
HIPAA THE PRIVACY RULE Reviewed December 2012.
2015 Orientation to HIPAA Privacy Rule Compliance
What is HIPAA? HIPAA stands for “Health Insurance Portability & Accountability Act” It was an Act of Congress passed into law in HEALTH INSURANCE.
By: Eamon Callahan and Wilston Johnston
HIPAA PRIVACY AWARENESS, COMPLIANCE and ENFORCEMENT
Disability Services Agencies Briefing On HIPAA
Presentation transcript:

HIPAA TRIVIA Do you know HIPAA?

HIPAA was created by?  The Affordable Care Act  Health Insurance companies  United States Congress  United States Supreme Court Click the box beside the correct answer

United States Congress  HIPAA was passed by Congress and signed into law by the President in  The HIPAA Privacy rule was effective in  The HIPAA Security rule was effective in  Both the HIPAA Privacy and Security rules govern our activities at ARHS. NEXT QUESTION

INCORRECT – Try Again  Click here to return to the question

“HIPAA” stands for?  Health Insurance Portability and Accountability Act  Health Information Protection and Accessibility Act  Health Information Portability and Accountability Act  Health Insurance Protection and Accessibility Act Click the box beside the correct answer

H ealth I nsurance P ortability and A ccountability A ct  The first section of HIPAA regulates the transfer or “portability” of health insurance when individuals move from one employer or insurance company to another.  At ARHS we are governed by the additional sections of HIPAA which regulate privacy and security of our patients’ health information. NEXT QUESTION

INCORRECT – Try Again  Click here to return to the question

The bill that was passed to strengthen HIPAA is commonly known as?  HIPAA 2  HITECH  PHIA  SSA Click the box beside the correct answer

HITECH  H ealth I nformation T echnology for E conomic and C linical H ealth Act  Strengthens and provides additional regulatory and enforcement support to the privacy and security rules established by HIPAA NEXT QUESTION

INCORRECT – Try Again  Click here to return to the question

In HIPAA and HITECH “PHI” stands for?  Patient Health Insurance  Patient Health Information  Protected Health Information  Personal Health Information Click the box beside the correct answer

P rotected H ealth I nformation  Name  Address  Date of Birth  Social Security Number  Insurance Information  Employer  Family member names  Photos  Medical history  Medical record  Any information that may be used to identify the patient is considered PHI NEXT QUESTION

INCORRECT – Try Again  Click here to return to the question

What is ePHI?  Electronic Protected Health Information  Eliminated Protected Health Information  Enforced Protected Health Information  Enhanced Protected Health Information Click the box beside the correct answer

Electronic Protected Health Information  ePHI is any Protected Health Information (PHI) stored or transmitted in an electronic format  ePHI includes PHI stored on Electronic Medical Records, computers, laptops, USB keys, cell phones or any other electronic media  ePHI includes PHI that is included in an  ed PHI must be encrypted unless the patient requests an unencrypted and is made aware of the risks of the PHI being sent unsecured  ePHI also includes PHI that has been faxed NEXT QUESTION

INCORRECT – Try Again  Click here to return to the question

Under HIPAA and HITECH ARHS and its facilities are a(n)?  Business Associate  Covered Entity  Clearinghouse  Insurance Provider Click the box beside the correct answer

Covered Entity  ARHS and all its facilities are Covered Entities under HIPAA and HITECH  Covered Entities are healthcare providers which treat patients and accumulate PHI for those patients including but not limited to hospitals, post- acute/long-term care facilities and physician practices. NEXT QUESTION

INCORRECT – Try Again  Click here to return to the question

Under HIPAA and HITECH a Business Associate of ARHS is?  Any organization that has access to PHI stored at ARHS  Any individual or organization that ARHS contracts with to access PHI when the PHI is to be used for the benefit of ARHS  Any individual who may have access to PHI  Any software company ARHS does business with Click the box beside the correct answer

Business Associate  Business Associates (BA) are entities or individuals to whom we release our patient’s PHI so they can use that PHI to perform a specific task for the benefit of ARHS such as attorneys, auditors, consultants and others.  ARHS is required to maintain a Business Associate Agreement (BAA) with all Business Associates. NEXT QUESTION

INCORRECT – Try Again  Click here to return to the question

HIPAA allows use and disclosure of PHI for?  Treatment  Payment  Operations  All of the above Click the box beside the correct answer

Treatment, Payment and Operations  HIPAA allows the use and disclosure of PHI only for the treatment of patients, the collection of payment and for operations of the organization.  Also referred to as “TPO” these are the only uses and disclosures allowed by HIPAA without the consent of the patient.  Additionally HIPAA’s “Minimum Necessary” rule restricts access, use or disclosure of PHI to only the minimum extent necessary for a provider or employee to perform his/her job responsibilities. NEXT QUESTION

INCORRECT – Try Again  Click here to return to the question

The office that enforces HIPAA and HITECH is?  United States Department of Justice  United States Centers for Medicare and Medicaid  North Carolina Department of Health and Human Services  Office for Civil Rights Click the box beside the correct answer

Office for Civil Rights  The United States Department of Health and Human Services (HHS) assigned enforcement of HIPAA to the Office for Civil Rights (OCR)  The OCR has completed Phase I of a program to audit Covered Entity’s and Business Associate’s compliance with HIPAA and HITECH.  The second phase of audits will begin in 2016 and ARHS could be chosen to be audited. NEXT QUESTION

INCORRECT – Try Again  Click here to return to the question

HIPAA gives patients the right to?  Request a copy of their medical record  Request a list of providers and others the Covered Entity has disclosed their PHI to.  Request limited access to their PHI.  All of the above. Click the box beside the correct answer

All of these and many others  HIPAA grants patients all the rights listed as well as many additional rights.  Every patient has the right to a copy of his/her medical record which ARHS must provide upon request.  ARHS is required to maintain a list of disclosures of patient PHI and provide that list upon request by the patient.  Our patients have the right to request limited access to their PHI, however ARHS may determine it is unreasonable or we are unable to honor their request.  All patient rights are listed in the Notice of Patient Rights given to patients upon registration. NEXT QUESTION

INCORRECT – Try Again  Click here to return to the question

What disclosure(s) may be determined a breach of PHI?  A fax sent to the wrong phone number  Posting a picture or information about a patient on social media  Notifying a family member that a patient is in an ARHS facility when the patient has not authorized you to do so  Discussing patient information in the hospital cafeteria  All of the above Click the box beside the correct answer

All of these and more!!  Any incident or communication where it can be determined that there is more than a low probability that the PHI could be used for purposes other than those allowed by HIPAA is a breach  A breach may involve PHI of one patient or PHI of thousands of patients  Breaches of PHI by staff of ARHS could result in disciplinary action up to and including termination. NEXT QUESTION

INCORRECT – Try Again  Click here to return to the question

Who are HIPAA breaches reported to?  The patient whose PHI was breached  The Office for Civil Rights  The patient and the Office for Civil Rights  HIPAA breaches are not reported Click the box beside the correct answer

The patient and the Office for Civil Rights  All breaches must be reported to the patient whose PHI was breached regardless of when or how the breach occurred.  Breaches involving 500 or more individuals’ PHI must be reported to the Office for Civil Rights and local media in addition to notifying the patient.  Breaches involving 1 – 499 individuals’ PHI must be reported to the Office for Civil Rights in addition to notifying the patient. NEXT QUESTION

INCORRECT – Try Again  Click here to return to the question

Who is the Privacy Officer at ARHS?  Randy Dow  Nathan White  Kevin May  Amy Crabbe Click the box beside the correct answer

Randy Dow  Randy Dow is the Compliance and Privacy Officer at ARHS.  Compliance is responsible for monitoring and auditing HIPAA at ARHS and its facilities.  Compliance is also responsible for HIPAA breach determination and notification at ARHS and its facilities.  Randy Dow is assisted in Compliance by Sherrie King, ARHS Compliance Auditor NEXT QUESTION

INCORRECT – Try Again  Click here to return to the question

How do you notify Compliance of any HIPAA concerns you may have?  Contact Randy Dow at or  Contact Sherrie King at or  Call the Hotline at  All of the above Click the box beside the correct answer

You may report HIPAA concerns or violations to:  Randy Dow at or  Sherrie King at or  Compliance Concepts Hotline  Hotline calls are answered by a company outside ARHS and you do not have to give your name when calling the hotline  You cannot be punished by your supervisor or ARHS for reporting HIPAA violations.

INCORRECT – Try Again  Click here to return to the question