Privacy and Security Basics for Falls Evidence Based Programs Data Collection . October 2016.

Slides:



Advertisements
Similar presentations
FERPA: Family Educational Rights and Privacy Act
Advertisements

Mandatory training for all Users who have access to Privacy Act Data
Privacy and Security Basics for CDSME Data Collection Sue Lachenmayr, MPH, CHES.
Overview of the Privacy Act
Gaucho Round-Up FAQ’s This presentation covers some of the FAQ’s about campus clean-up day. Presentation #4 2/3/
1. As a Florida KidCare community partner families entrust you to not only help them navigate the Florida KidCare system but to keep the information they.
Office of Health, Safety and Security
HIPAA Privacy Training. 2 HIPAA Background Health Insurance Portability and Accountability Act of 1996 Copyright 2010 MHM Resources LLC.
HIPAA. What Why Who How When What Is HIPAA? Health Insurance Portability & Accountability Act of 1996.
HIPAA Basic Training for Privacy & Information Security Vanderbilt University Medical Center VUMC HIPAA Website:
HIPAA – Privacy Rule and Research USCRF Research Educational Series March 19, 2003.
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
The Health Insurance Portability and Accountability Act of 1996– charged the Department of Health and Human Services (DHHS) with creating health information.
What is HIPAA? This presentation was created by The University of Arizona Privacy Office, The Office for the Responsible Conduct of Research on March 5,
Informed Consent.
 The Health Insurance Portability and Accountability Act of  Federal Law designed to protect sensitive information.  HIPAA violations are enforced.
1 DEFENSE LOGISTICS AGENCY AMERICA’S COMBAT LOGISTICS SUPPORT AGENCY DEFENSE LOGISTICS AGENCY AMERICA’S COMBAT LOGISTICS SUPPORT AGENCY WARFIGHTER SUPPORT.
RVCC FACULTY FERPA WORKSHOP OCTOBER 2011 DAN PALUBNIAK REGISTRAR
Critical Data Management Indiana University HR Summit April 24, 2014.
C YBER S ECURITY FOR E DUCATIONAL L EADERS : A G UIDE TO U NDERSTANDING AND I MPLEMENTING T ECHNOLOGY P OLICIES Chapter 10 Privacy Policy © Routledge Richard.
ROLES & RESPONSIBILITIES PRIVACY ACT (PA) SYSTEMS OF RECORDS MANAGERS.
FERPA: Family Educational Rights and Privacy Act.
Privacy and Security Basics for CDSME Data Collection Sue Lachenmayr, MPH, CHES Updated April 10, 2014.
CDSME Data Collection Requirements and Procedures January 9, 2014 update You Can! Live Well, Virginia!
FAMILY EDUCATIONAL RIGHTS AND PRIVACY ACT Electronic Signatures This work is the intellectual property of the author. Permission is granted for this material.
Columbia University Medical Center Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) Privacy & Information Security Training 2009.
Health Budgets & Financial Policy Privacy and HIPAA Security 15 December & December, & 1600 Bridge Number:
PRIVACY SAFEGUARDS ANNUAL TRAINING FY 2011 previous next Office of Management Privacy, Information and Records Management Services Privacy Safeguards Division.
1 PUBLIC HEALTH DIVISION Health Promotion and Chronic Disease Prevention Privacy and Security Basics for Self-Management Participant Data Collection Laura.
HIPAA PRIVACY AND SECURITY AWARENESS.
HIPAA Business Associates Leadership Group Meeting June 28, 2001.
PRIVACY AND INFORMATION SECURITY ESSENTIALS Information Security Policy Essentials Melissa Short, IT Specialist Office of Cyber Security- Policy.
Ames Laboratory Privacy and Personally Identifiable Information (PII) Training Welcome to the Ames Laboratory’s training on Personally Identifiable Information.
INFORMATION TECHNOLOGY SERVICES Privacy 101 Information Security and Privacy Office.
Privacy and Information Management ICT Guidelines.
HIPAA (health insurance portability and accountability act)
Family Educational Rights and Privacy Act. From the moment a child enters the school system, sensitive information is collected about the child (and even.
Ticket Training Tuesday Properly Safeguarding Personally Identifiable Information (PII)
HIPAA Privacy What Every Staff Member Needs to Know.
POLICIES & PROCEDURES FOR HANDLING CONFIDENTIAL INFORMATION NOVEMBER 5 TH 2015.
Properly Safeguarding Personally Identifiable Information (PII) Ticket Program Manager (TPM) Social Security’s Ticket to Work Program.
Information Security and Privacy Office
HIPAA Privacy and Security
Protecting PHI & PII 12/30/2017 6:45 AM
Privacy Education Session CMHA-WECB/CCHC Volunteers/Students
Privacy and Security Basics for CDSME Data Collection
HIPAA Privacy & Security
Records Retention NYS Magistrates’ Association
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA)
Office of Health, Safety and Security
Privacy principles Individual written policies
Privacy & Confidentiality
Privacy of Client Data.
Dining with Diabetes IRB Training 2017.
ACL’s New Data Requirements (Administration on Community Living)
Disability Services Agencies Briefing On HIPAA
CONTRACTS PRIVILEGED COMMUNICATION PRIVACY ACT
Information management and communication
HIPAA Privacy & Security
HIPAA SECURITY RULE Copyright © 2008, 2006, 2004 by Saunders an imprint of Elsevier Inc. All rights reserved.
HIPAA Overview.
The Health Insurance Portability and Accountability Act
Good Spirit School Division
Lesson 3: Medical Records
Handling Information Securely
TRACE INITIATIVE: Confidentiality, Data Security, and Procedures for Protocol Violation or Adverse Event.
The Health Insurance Portability and Accountability Act
Family Educational Rights and Privacy Act of 1974
Presentation transcript:

Privacy and Security Basics for Falls Evidence Based Programs Data Collection . October 2016

Overview Purpose of the Privacy Act Primary features of the Act Who needs privacy training? Master trainers and lay leaders Program coordinators and data collection/data entry personnel Types of information protected by the Act Disclosure Safeguarding, transporting and disposing of PII Roles and responsibilities Test questions Certificate

Privacy Act of 1974 Protects records that can be retrieved by personal identifiers such as a name, social security number, or other identifying number or symbol. Created in response to concerns about how the use of computerized databases might impact individuals' privacy rights. Requires government agencies to show individuals any records kept on them Requires agencies to follow "fair information practices" when gathering and handling personal data. Places restrictions on how agencies can share an individual's data with other people and agencies. Lets individuals sue the government for violating of these provisions http://www.hhs.gov/foia/privacy/

Who Needs to be Trained? If your work involves the management of sensitive information, Personally Identifiable Information (PII), or protected health information, you need to ensure you are taking precautions to protect it from unauthorized access/disclosure, theft, loss, and improper disposal.

Who Needs to be Trained? Anyone involved in the collection, handling and/or data entry of PII on individuals participating in Falls EBPs, including: Managers Coordinators Other employees Master trainers (MTs) Lay leaders (LLs) Volunteers

What Type of Training is Needed? Training for program coordinators and program implementers The rights of individuals participating in Falls The appropriate protection of PII shared by Falls participants at the workshop level The appropriate storage and transfer of participant forms Training for individuals completing data entry and data transfer The appropriate storage, transfer, and destruction of data forms Security requirements for electronic data transfer, storing, and degaussing (destruction)

Types of Information Covered by the Privacy Act Sensitive: If the loss of confidentiality, integrity, or availability could be expected to have a serious, severe, or catastrophic adverse effect on organizational operations, organizational assets, or individuals. Protected Health Information: Individually identifiable health information that relates to a person’s past/present/future physical/mental health, health care received, or payment. http://irtsectraining.nih.gov/publicUser.aspx

Information Protected by the Privacy Act PERSONALLY IDENTIFIABLE INFORMATION (PII) "the term Personally Identifiable Information means any information about an individual maintained by an agency, including, but not limited to, education, financial transactions, medical history, and criminal or employment history and information which can be used to distinguish or trace an individual’s identity, such as their name, social security number, date and place of birth, mother’s maiden name, biometric records, etc., including any other personal information which is linked or linkable to an individual.“ http://www.gsa.gov/portal/content/104256

Information Protected by the Privacy Act Personally Identifiable Information (PII) Home address Home telephone number Complete date of birth Personal medical information Social Security Number (including just the last four digits of SSN) Personal/private information (if the information can uniquely identify the individual) Photographs Education records Financial transactions Employment history

Disclosure No agency or person shall disclose: any record by any means of communication to any person or another agency without a written request or prior written consent of the individual to whom the record pertains “Any means of communication” includes oral (phone, in-person), written, and electronic (emails, faxes, texts, tweets, pins, etc.)

Safeguarding PII Must always be treated as “FOR OFFICIAL USE ONLY” and must be marked accordingly Applies not only to paper records but also includes email, faxes, etc., which must contain the cautionary marking “FOR OFFICIAL USE ONLY – FOUO” Should be stored in locked filing cabinets or other secure containers to prevent unauthorized access Electronic records must be password protected and be transferred via encrypted email

Transporting PII Hand carrying Using mail Using email: Use a cover sheet to shield contents Using mail Use manila or white envelopes Mark the envelope to the attention of the authorized recipient Never indicate on the outer envelope that it contains PII Using email: Password protect personal data placed on shared drives, the Internet, or the Intranet Use encrypted email Do not send PII to a personal, home, or unencrypted e-mail address Announce in the opening line of the text (NOT the subject line) that FOUO information is contained

Disposing of PII A disposal method is considered adequate if it renders the information unrecognizable or beyond reconstruction. Disposal methods may include: Burning Melting Chemically decomposing Pulping Pulverizing Shredding Mutilating Degaussing (erasing from magnetic field or disc) Deleting/emptying recycle bin

Your Role and Responsibility Take privacy protection seriously Respect the privacy of others Ensure messages, faxes, and emails that contain personal information are properly marked and email is encrypted Don’t share PII with individuals who are not authorized Have appropriate transfer, storage, and disposal protocols in place for PII Do not email PII to personal, home, or unencrypted accounts Read the Group Leader Script to advise all participants of their right to consent or refuse use of data about them

Your Role and Responsibility All individuals involved in providing Falls prevention programs must sign Non-Disclosure Agreements All individuals involved in data collection, data transfer, and/or data entry must sign Non-Disclosure Agreements Non-Disclosure Agreements should be maintained for three years after the end of the grant and stored by the grantee or the grantee’s designee for data collection/data entry Non-Disclosure Agreements do not contain PII, so they can be faxed, e-mailed, or mailed without encryption or privacy restrictions

Master Trainer and Lay Leader Role Use the Falls Program Group Leader Script at a Session Zero pre-session or at the start of Session 1 and with any new participants who start at Session 2 The script explains why participant data is being collected and how it will be kept secure Emphasize that completing the survey is voluntary Individuals may skip any questions they do not want to answer Individuals may choose to not complete the Survey, but they can still participate in the program Store surveys in sealed envelope and mail to the program coordinator

Program Coordinator/Data Entry Roles Store completed Falls forms in a secure, locked cabinet when not in use Enter data into secure, password protected database such as the Falls database Destroy participant data forms after data entry

Test Questions – Circle all correct answers Information about an individual that is unique, or identifies or describes him or her (such as Social Security Number, medical history, date of birth, home address), is called: Interesting Record Data Personally Identifiable Information

Test Questions – Circle all correct answers 2. Disposal methods may include all except: Burning Shredding Tearing in half and putting in the garbage can Melting

Test Questions – Circle all correct answers 3. The Falls Group Leader Script: Describes what participants will learn in the workshop Requests participants to share their birth date, address, and sex Explains how participant privacy is protected and why data is being collected Emphasizes that participants are required to complete all survey forms

Privacy and Security Basics Training Certificate ________________________________________ (Name) Has Successfully Completed the Privacy and Security Basics Training for Falls Program Implementation and Data Collection _____________ Date

Test Answer Code d - Personally Identifiable Information c - Tearing in half and putting in the garbage can c - Explains how participant privacy is protected and why data is being collected