An Introduction to Compliance and HIPAA Privacy RVHIMA Spring 2016 Meeting Joshua A. Lenavitt, MHA Regional Director of Compliance and Privacy Baptist.

Slides:



Advertisements
Similar presentations
HIPAA: An Overview of Transaction, Privacy and Security Regulations Training for Providers and Staff.
Advertisements

Red Flag Rules: What they are? & What you need to do
1 The Health Insurance Portability and Accountability Act (HIPAA) A guided tutorial for GVSU employees.
HIPAA Privacy Training. 2 HIPAA Background Health Insurance Portability and Accountability Act of 1996 Copyright 2010 MHM Resources LLC.
Health Insurance Portability and Accountability Act HIPAA Education for Volunteers and Students.
HIPAA Basic Training for Privacy & Information Security Vanderbilt University Medical Center VUMC HIPAA Website:
Confidentiality and HIPAA
HIPAA Privacy Rule Training
National Health Information Privacy and Security Week Understanding the HIPAA Privacy and Security Rule.
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
The Health Insurance Portability and Accountability Act of 1996– charged the Department of Health and Human Services (DHHS) with creating health information.
HIPAA What’s New? What Is HIPAA Health Insurance Portability and Accountability Act of 1996 Health Insurance Portability and Accountability Act.
What is HIPAA? This presentation was created by The University of Arizona Privacy Office, The Office for the Responsible Conduct of Research on March 5,
1 HIPAA Education CCAC Professional Development Training September 2006 CCAC Professional Development Training September 2006.
Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna
NAU HIPAA Awareness Training
WHAT IS HIPAA? The Health Insurance Portability and Accountability Act of 1996 (HIPAA) provides certain protections for any of your health information.
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996 (HIPAA)
HIPAA Regulations What do you need to know?.
HIPAA Privacy Rule Compliance Training for YSU April 9, 2014.
 The Health Insurance Portability and Accountability Act of  Federal Law designed to protect sensitive information.  HIPAA violations are enforced.
HIPAA THE PRIVACY RULE Reviewed December HISTORY In 2000, many patients that were newly diagnosed with depression received free samples of anti-
2014 HIPAA Refresher Omnibus Rule & HIPAA Security.
Are you ready for HIPPO??? Welcome to HIPAA
HIPAA HIPAA Health Insurance Portability and Accountability Act of 1996.
RMG:Red Flags Rule 1 Regal Medical Group Red Flags Rule Identify Theft Training.
© Copyright 2014 Saul Ewing LLP The Coalition for Academic Scientific Computation HIPAA Legal Framework and Breach Analysis Presented by: Bruce D. Armon,
HIPAA COMPLIANCE IN YOUR PRACTICE MARIBEL VALENTIN, ESQUIRE.
HIPAA Basic Training for Privacy and Information Security Vanderbilt University Medical Center VUMC HIPAA Website: HIPAA Basic.
Columbia University Medical Center Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) Privacy & Information Security Training 2009.
HIPAA PRIVACY AND SECURITY AWARENESS.
Privacy and Security of Protected Health Information NorthPoint Health & Wellness Center 2011.
Health Insurance Portability and Accountability Act (HIPAA)
CORPORATE COMPLIANCE PROGRAM The Office of Corporate Integrity
HIPAA (health insurance portability and accountability act)
Established in 1996 to enforce standards for electronic health information & enhance the security and privacy of health information.
Building a Privacy Foundation. Setting the Standard for Privacy Health Insurance Portability and Accountability Act (HIPAA) Patient Bill of Rights Federal.
Copyright © 2009 by The McGraw-Hill Companies, Inc. All Rights Reserved. McGraw-Hill Chapter 6 The Privacy and Security of Electronic Health Information.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
Understanding HIPAA (Health Insurandce Portability and Accountability Act)
Mr. Fleming.  Law passed by Congress in  Right to Privacy ◦ Medical information of patient can only be shared with doctor and professionals administering.
© 2013 The McGraw-Hill Companies, Inc. All rights reserved. Ch 8 Privacy Law and HIPAA.
HIPAA BASIC TRAINING Presented by Anderson Health Information Systems, Inc.
HIPAA BASIC TRAINING MODULE 1C – Overview (For staff who do not generally create Protected Health Information) Anderson Health Information Systems, Inc.
HIPAA PRACTICAL APPLICATION WORKSHOP Orientation Module 1B Anderson Health Information Systems, Inc.
HIPAA THE PRIVACY RULE. 2 HISTORY In 2000, many patients that were newly diagnosed with depression received free samples of anti- depressant medications.
Rhonda Anderson, RHIA, President  …is a PROCESS, not a PROJECT 2.
Copyright ©2014 by Saunders, an imprint of Elsevier Inc. All rights reserved 1 Chapter 02 Compliance, Privacy, Fraud, and Abuse in Insurance Billing Insurance.
A Road Map to Research at Jefferson: HIPAA Privacy and Security Rules for Researchers Presented By: Privacy Officer/Office of Legal Counsel October 2015.
Welcome….!!! CORPORATE COMPLIANCE PROGRAM Presented by The Office of Corporate Integrity 1.
Western Asset Protection
Flowers Hospital General Compliance Training-Students 2013.
HIPAA Overview Why do we need a federal rule on privacy? Privacy is a fundamental right Privacy can be defined as the ability of the individual to determine.
HIPAA/HITECH TRAINING. Why are we here?  HIPAA  HITECH  PHI  Minimum Necessary “Need to Know”  Breaches and Fines.
HIPAA TRIVIA Do you know HIPAA?. HIPAA was created by?  The Affordable Care Act  Health Insurance companies  United States Congress  United States.
HIPAA Training. What information is considered PHI (Protected Health Information)  Dates- Birthdays, Dates of Admission and Discharge, Date of Death.
New Hire HIPAA Orientation. HIPAA Overview HIPAA is an acronym that stands for the Health Insurance Portability and Accountability Act of HIPAA.
Disclaimer This presentation is intended only for use by Tulane University faculty, staff, and students. No copy or use of this presentation should occur.
HIPAA Privacy Rule Training
Health Insurance Portability and Accountability Act of 1996
HIPAA THE PRIVACY RULE Reviewed December 2012.
What is HIPAA? HIPAA stands for “Health Insurance Portability & Accountability Act” It was an Act of Congress passed into law in HEALTH INSURANCE.
Use of BMC Patient Information Privacy & Security
Health Insurance Portability and Accountability Act of 1996 (HIPAA)
Red Flags Rule An Introduction County College of Morris
HIPAA PRIVACY AWARENESS, COMPLIANCE and ENFORCEMENT
Disability Services Agencies Briefing On HIPAA
Move this to online module slides 11-56
HIPAA Do’s and Don'ts: What is Really Behind Protected Health Information (PHI) and Health Care Privacy Rules Paul Sisler, Director, Information Services;
Presentation transcript:

An Introduction to Compliance and HIPAA Privacy RVHIMA Spring 2016 Meeting Joshua A. Lenavitt, MHA Regional Director of Compliance and Privacy Baptist Health Louisville/La Grange

Disclaimer This presentation is for general education purposes only. The information contained in these materials, lecture, ideas and concepts presented is not intended to be, and is not, legal advice or even particular business advice relevant to your personal circumstances. The laws and regulations presented in this lecture are open to interpretation. 2

Disclaimer Continued I am not a lawyer… I know several lawyers… They were not available today… That’s why you have me today! 3

Objectives Define Compliance and discuss in terms of Ethics and Values Gain an understanding of basic HIPAA (Health Insurance Portability and Accountability Act) law, Discuss protection of Protected Health Information (PHI) and Identity Theft/Red Flags Briefly discuss Social Media and Healthcare Discuss Texting of PHI 4

Compliance How would you define Compliance? 5

What is Compliance? Compliance may be described as….. Adhering to federal and state laws Following policies and rules Monitoring medical documentation and billing practices Observing the HIPAA Privacy Rule 6

What is Ethics? Ethics may be described as ….. Core beliefs and convictions Values about what is right and good Doing the right thing 7

Compliance & Ethics Taken together, they define the essence of the Corporate Responsibility A values-based culture that guides our actions in the workplace so that our daily activities are performed with honesty, integrity, and in support of organizational Mission, Vision and Values Statements. 8

Quick Poll – TRUE or FALSE? FRAUD is a deception, a hoax, or a lie that is made for personal or corporate gain. TRUE 9

Industry and Governmental news A dialysis center illegally paid physicians for referrals and settled with the government for $389 million. A hospital allegedly submitted false or fraudulent claims for doing unnecessary heart procedures and settled with the government for $16.5 million. A clinic operator fraudulently billed Medicare for medications that were never given to patients, or were at incorrect dosages, or were unnecessary. A plea agreement included re-payment of $12 million. 10

Health and Human Services (HHS), Office of Civil Rights (OCR) in Action Starting in January of 2016, HHS, OCR started issuing monthly messages as it relates to HIPAA and PHI. The subject matter to date includes: –Patients’ right to access health information and clarifies appropriate fees for copies –Understanding Some of HIPAA’s Permitted Uses and Disclosures –Improper disclosure of research participants’ protected health information results HIPAA settlement professionals/privacy/guidance/access/index.html 11

HIPAA 12

HIPAA The Office for Civil Rights enforces the HIPAA Privacy Rule: HIPAA – Health Insurance Portability and Accountability Act of 1996 –Security Rule, national standards for the security of electronic protected Health information (published in 2003) –Breach Notification Rule, requires covered entities to provide notification of HIPAA breaches (published in 2009) HITECH – Health Information Technology for Economic and Clinical Health Act, 2009 HIPAA Final Omnibus Rule

What is PHI? Protected Health Information (PHI) can be in any form (electronic, paper, or oral), and includes: 1)Demographic data 2)Past / present / future physical or mental health or condition(s) 3)The provision of health care to the individual 4)The past, present, or future payment for the provision of health care services 14

Permitted Uses of PHI Treatment Payment –Audits / Requests from payors –Worker’s compensation Healthcare operations –Quality Assessments –Business Management, such as customer service and resolution of grievances 15

Quick Poll – TRUE or FALSE? HIPAA was not designed to interfere with patient care. TRUE The HIPAA Privacy Rule allows medical staff to access information necessary for patient treatment. 16

Quick Poll – TRUE or FALSE? Under the HIPAA Rules, we must protect our patients’ information (PHI) which includes: - Name, address, and phone number - Social Security number - Insurance information - Medical record or account number - Patient’s picture TRUE 17

Identity Theft Identity Theft Prevention Programs are designed to detect, prevent and mitigate identity theft. Definitions Identity Theft – fraud committed or attempted using the identifying information of another person without authority. Red Flag – a pattern, practice or specific activity that indicates the possible existence of identity theft. 18

Identity Theft Identification of Relevant “Red Flags” The presentation of suspicious documents. The presentation of suspicious personal identifying information. Suspicious activity related to a covered account. Complaint or question is received from a patient based on their receipt of suspicious documents. Notice of address discrepancy. 19

Our Responsibilities Obtain the patient’s permission before discussing PHI in the presence of visitors (including family members). Refer all requests for medical records to the Health Information Management (HIM) Department or your organizations Release of Information Office. Refrain from casual conversation. Hold discussion of PHI in confidential and secure areas. Do not leave charts, files, or computer screens open and within public view. 20

Our Responsibilities (cont.) Never share passwords. Always lock your computer when stepping away from your work station. Do not PHI from work to your personal address. Do not text PHI unless using a secure and approved platform. 21

Our Responsibilities (cont.) PHI should not be taken off Baptist property unless secure transport is approved by your manager. Do not leave messages concerning a patient’s condition or test results on a patient’s voic . Report suspicious behavior, people, or situations to your manager, security, or the compliance officer. 22

Quick Poll – TRUE or FALSE? Employees are encouraged to share medical advice with patients and families via social media (such as Facebook, Twitter, blogs). FALSE 23

24

Social Media General Guidance Use caution when having online social contact with patients, former patients, and their family members. Avoid posts related to work as these discussions also have the potential to inadvertently disclose PHI. At Baptist Health, we do not use or post patient information or pictures without prior approval from Executive Management. 25

Texting of PHI Healthcare providers and covered entities should be aware of the potential consequences under HIPAA for unsecure and/or misdirected text messages. Baptist Health has a policy that governs the use of text messaging as a means of communicating PHI between providers. –Only a secure application is acceptable i.e.. Tiger, MicroBloggingMD, etc. 26

Key Takeaways Compliance impacts all functional areas of the hospital or organization. We all have a responsibility to carry out our activities in a manner that is ethical, legal, and in support of the behaviors outlined in your organizations standards of conduct, professional organizations guidelines, and laws. Let someone know if you have a compliance question or concern. When you speak up, we have an opportunity to improve our programs and resolve issues before they become more serious. 27

Joshua Lenavitt Regional Director of Compliance and Privacy Baptist Hospital Louisville & La Grange (502) phone 28