ABA Privacy and Data Security Update May 14, 2013

Slides:



Advertisements
Similar presentations
Implementing the New HIPAA Rules
Advertisements

HITECH ACT Privacy & Security Requirements Cathleen Casagrande Privacy Officer July 23, 2009.
“Reaching across Arizona to provide comprehensive quality health care for those in need” Our first care is your health care Arizona Health Care Cost Containment.
HIPAA Update: The Omnibus Rule Kathleen Stillwell, MPA/HSA,RN,CPHRM Patient Safety Risk Management Account Executive Matthew L. Kinley, Esq., Partner -
Key Changes to HIPAA from the Stimulus Bill (ARRA) Children’s Health System Department Leadership Meeting October 28, 2009 Kathleen Street Privacy Officer/Risk.
WHAT IS HIPAA? The Health Insurance Portability and Accountability Act of 1996 (HIPAA) provides certain protections for any of your health information.
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996 (HIPAA)
2014 HIPAA Refresher Omnibus Rule & HIPAA Security.
Jill Moore April 2013 HIPAA Update: New Rules, New Challenges.
Health IT Privacy and Security Policy Jodi Daniel, J.D., M.P.H. Director, Office of Policy and Research, Office of the National Coordinator for Health.
March 19, 2009 Changes to HIPAA Privacy and Security Requirements Joel T. Kopperud Scott A. Sinder Rhonda M. Bolton.
HIPAA Update – Significant Omnibus Rule Changes Rose Willis Billee Lightvoet Ward Dickinson Wright PLLC.
Per Anders Eriksson
Notice of Privacy Practices Nebraska SNIP Privacy Subgroup July 18, 2002 Michael J. Brown, MHA, CPA Vice-President, Administrative & Regulatory Affairs,
HIPAA and HITECH The Latest Developments Presented By: Michele Madison Partner, Healthcare Practice Morris, Manning & Martin, LLP
Confidentiality, Consents and Disclosure Recent Legal Changes and Current Issues Presented by Pam Beach, Attorney at Law.
Overview of the Omnibus Final HIPAA Rule Kohler HealthCare Consulting, Inc. Deanna Turner
Computerized Networking of HIV Providers Workshop Data Security, Privacy and HIPAA: Focus on Privacy Joy L. Pritts, J.D. Assistant Research Professor Health.
HITECH Act and HIPAA: Important Compliance Update Susan E. Ziel Gerald “Jud” DeLoss.
Federal Trade Commission required to issue and enforce regulations concerning children’s online privacy. Initial COPPA Rule effective April 21, 2000;
Security of the Distributed Electronic Patient Record: A Case-Based Approach James G. Anderson, Ph.D. Purdue University.
HIPAA Michigan Cancer Registrars Association 2005 Annual Educational Conference Sandy Routhier.
Office of the Secretary Office for Civil Rights (OCR) The HITECH NPRM: Overview of Research Comments October 19, 2010 Christina Heide, JD HHS Office for.
Health Insurance Portability and Accountability Act (HIPAA) CCAC.
The Framework for Privacy Policies in the UK: Is telling people what information is gathered about them part of the framework? Does it need to be? Emma.
FleetBoston Financial HIPAA Privacy Compliance Agnes Bundy Scanlan Managing Director and Chief Privacy Officer FleetBoston Financial.
HIPAA THE PRIVACY RULE. 2 HISTORY In 2000, many patients that were newly diagnosed with depression received free samples of anti- depressant medications.
The American Recovery and Reinvestment Act of 2009: Changes to HIPAA Privacy and Security Requirements And its Impact on Hospitals Presented By: Michele.
HealthBridge is one of the nation’s largest and most successful health information exchange organizations. Tri-State REC: Privacy and Security Issues for.
Rhonda Anderson, RHIA, President  …is a PROCESS, not a PROJECT 2.
C HAPTER 34 Code Blue Health Sciences Edition 4. Confidentiality of sensitive information is an important issue in healthcare. Breaches of confidentiality.
HIPAA Privacy Rules: What Are Plan Sponsors Required to Do?
1 Changes to Privacy Regulations under ARRA May 4, 2009 Melissa Goldstein, J.D. The George Washington University School of Public Health and Health Services.
Top 10 Series Changes to HIPAA Devon Bernard AOPA Reimbursement Services Coordinator.
Finally, the Final HIPAA/HITECH Regulations are Here! By LYNDA M. JOHNSON Friday, Eldredge & Clark.
Final HIPAA-HITECH Rules, Cybersecurity, and Privacy Dino TsibourisMehmet Munur (614) (614)
Indiana’s Public Access Laws Heather Willis Neal Indiana Public Access Counselor Indiana Association of Cities and Towns Red Flag and Sunshine Workshop.
AND CE-Prof, Inc. January 28, 2011 The Greater Chicago Dental Academy 1 Copyright CE-Prof, Inc
Privacy and Security Considerations in Research and Clinical Trials February 28, 2013 Joanna K. Napp, J.D., M.P.H. Chief Privacy Officer and Compliance.
“Kids First, New Mexico Wins!” NMPED Data Conference Spring 2016 Dan Hill General Counsel, Public Education Department Randi Johnson General Counsel, State.
HIPAA Yesterday, Today and Tomorrow? Dianne S. Faup Office of HIPAA Standards Centers for Medicare & Medicaid Services.
Disclaimer This presentation is intended only for use by Tulane University faculty, staff, and students. No copy or use of this presentation should occur.
HIPAA: So You Think You’re Compliant September 1, 2011 Carolyn Heyman-Layne, J.D.
Juvenile Legislative Update 2013 Confidential Records and Protected Disclosures.
Understanding Privacy An Overview of our Responsibilities.
HIPAA Privacy Rule Positive Changes Affecting Hospitals’ Implementation of the Rule Melinda Hatton -- Oct. 31, 2002.
Main Line Hospitals Institutional Review Board HIPAA Policy Changes 2013 Anne Marie Hobson, BSN, JD, ORA Director.
HIPAA Training Workshop #3 Individual Rights Kaye L. Rankin Rankin Healthcare Consultants, Inc.
UNDERSTANDING WHAT HIPAA IS AND IS NOT
HIPAA THE PRIVACY RULE Reviewed December 2012.
Enforcement, Business Associates and Breach Notification. Oh my!
What is HIPAA? HIPAA stands for “Health Insurance Portability & Accountability Act” It was an Act of Congress passed into law in HEALTH INSURANCE.
HIPAA CONFIDENTIALITY
Final Amended COPPA Rule
HIPPA/HITECH Act Requirements Under the Business Associate Agreement Between CNI and Military Health Services.
Privacy Notice - Requirements
Notifiable data breaches Roundtable
GENERAL DATA PROTECTION REGULATION (GDPR)
Confidential Records and Protected Disclosures
Red Flags Rule An Introduction County College of Morris
Current Privacy Issues That May Affect Your Credit Union
HITECH’s Impact on Research
HIPAA Privacy and Security Summit 2018 HIPAA Privacy Rule: Compliance Plans, Training, Internal Audits and Patient Rights Widener University Delaware.
THE 13TH NATIONAL HIPAA SUMMIT HEALTH INFORMATION PRIVACY & SECURITY IN SHARED HEALTH RECORD SYSTEMS SEPTEMBER 26, 2006 Paul T. Smith, Esq. Partner,
Government Data Practices & Open Meeting Law Overview
Managing Privacy Risk in Your Commercial Practices
Analysis of Final HIPAA Privacy Modification Rule
Government Data Practices & Open Meeting Law Overview
If it's Subsidized, Get it Authorized: New Restrictions on the Sale and Use of PHI for Marketing Purposes Under HIPAA's Omnibus Rule Angela M. Rust This.
HIPAA Do’s and Don'ts: What is Really Behind Protected Health Information (PHI) and Health Care Privacy Rules Paul Sisler, Director, Information Services;
Presentation transcript:

ABA Privacy and Data Security Update May 14, 2013 David Keating Paul Martino Kim Peretti Bruce Sarkisian

Overview Cybersecurity Legislative Developments Health Privacy Privacy and Technology International

Cybersecurity Update

Understanding the threat From exploitation to disruption to destruction

DDOS Attacks - disruption

North Korea - destruction

Protecting against the threat Government response

Executive Order

EO process developments Framework development NIST RFI, responses, workshops Other areas of private sector input Integrated task force SSAs and Councils CIPAC Government tasks/timetable List of “greatest risk” critical infrastructure Incentives

Data Breach Update Investigations, regulatory inquires, litigation

Investigations

Breaches, Regulator Inquiries

Privacy class actions

HIPAA/HITECH Act Omnibus Final Rule Developments Since March

Rule Publication/Effective Date The Office of Civil Rights of the U.S. Department of Health and Human Services published the Omnibus Final Rule on January 25, 2013. The Omnibus Final Rule will became effective on March 26, 2013, and requires compliance 180 days later, on September 23, 2013.

New Statements Required In Notice of Privacy Practices (NPPs) The Omnibus Rule modified the Privacy Rule to require the addition of several statements: Where applicable, a statement indicating that most uses and disclosures of psychotherapy notes require authorization. A statement indicating uses and disclosures of PHI for marketing purposes, and disclosures that constitute a sale of PHI require authorization. A statement that other uses and disclosures not described in the NPP will be made only with authorization from the individual. If the covered entity intends to contact the individual for fundraising purposes, the NPP must include a statement informing the individual of the potential contact as well as the individual’s right to opt out of receiving fundraising communications. The covered entity is not required to state the mechanism for opting out of fundraising communications, but may do so. A statement informing the individual of his or her right to restrict disclosures of PHI to a health plan if the disclosure is for payment or health care operations and pertains to a health care item or service for which the individual has paid out of pocket in full. A statement explaining the right of affected individuals to be notified following a breach of unsecured PHI.

NPP Distribution Obligations for Health Plans When publishing the Final Rule, HHS confirmed that the Rule’s required revisions to NPPs constitute “material changes” to a covered entity’s NPPs. Accordingly, the material changes trigger distribution obligations. A health plan that currently posts its NPP on its website must Prominently post the material change or its revised NPP on its website by the effective date of the material change to the NPP; and Provide the revised NPP, or information about the material change and how to obtain the revised notice, in the health plan’s next annual mailing to individuals covered by the plan.

NPP Distribution Obligations for Other Health Care Providers The Omnibus Rule did not revise the current distribution obligations regarding revised NPPs of health care providers who have a direct treatment relationship with an individuals. Those providers must make the NPP available upon request or after the revision’s effective date, must have the NPP available at the delivery site and must post the notice in a clear and prominent location. HHS confirmed that health care providers need not hand out a revised NPP to all individuals.

The Privacy Rule’s Revised Definition of Marketing The new definition of “marketing” encompasses all treatment and health care operations communications where the covered entity (or business associate or subcontractor) receives financial remuneration for making such communications from a third party whose product or service is being marketed and, thus, requires prior authorization from the individual. These type of communications require advance authorization from the individual. Furthermore, all subsidized treatment communications that promote a health-related product or service will be treated as marketing communications that require authorization.

Privacy Rule Marketing Considerations The only exception to the definition of marketing that permits the covered entity to receive remuneration is for refill reminders and other communications about currently prescribed drugs, but only if the remuneration received in exchange for making the communication is reasonably related to the cost of making the communication. Recently, CVS announced that it would stop using data from its prescription drug records to mail prescription refill notices to customers on behalf of pharmaceutical manufacturers. CVS cited the Omnibus Rule as the reason for the change.

Privacy Developments Children’s Privacy Mobile Technologies Standards International

Privacy and Technology: Children’s Online Privacy FTC Publishes FAQs for Amended COPPA Rule Duties as to newly covered information collected prior to July 1 Level of due diligence required as to third-party services Mobile app standards FTC votes to retain July 1st effective date

Privacy and Technology: Mobile Device Privacy Landmark CalOPPA suit on FlyDelta app dismissed New FTC guidance on kids’ mobile apps Public forum on mobile devices scheduled for June 4 CNIL issues Statement on Article 29 WP Opinion on mobile apps

Privacy and Technology: NIST SP 800-53 Rev 4 First comprehensive update since 2005 Criticism Specifics: Cybersecurity hygiene Advanced Persistent Threats Mobile and cloud computing Supply chain threats

International Data Protection Status of Data Protection Regulation Art 29 Working Party Activities Secondary Processing BCRs and Processor Status Coordination with FTC DPA Activities

ABA Privacy and Data Security Update May 14, 2013 David Keating Paul Martino Kim Peretti Bruce Sarkisian