Compliance and Enforcement of the Privacy Rule

Slides:



Advertisements
Similar presentations
1 The Health Insurance Portability and Accountability Act (HIPAA) A guided tutorial for GVSU employees.
Advertisements

HIPAA Basics Brian Fleetham Dickinson Wright PLLC.
Dinsmore & Shohl, LLP Stacey Borowicz, Esq. Simi Botic, Esq. August 14, 2013.
1. As a Florida KidCare community partner families entrust you to not only help them navigate the Florida KidCare system but to keep the information they.
HIPAA. What Why Who How When What Is HIPAA? Health Insurance Portability & Accountability Act of 1996.
Confidentiality and HIPAA
HIPAA Privacy Rule Training
Navigating HIPAA & Recent Healthcare Reform: What You Need to Know.
HIPAA PRIVACY REQUIREMENTS Dana L. Thrasher Constangy, Brooks & Smith, LLC (205) ; Victoria Nemerson.
HIPAA POST-“HITECH”: Health Information Privacy Enforcement American Osteopathic Association of Medical Informatics November 4, :30 to 2:00 pm Ian.
HIPAA Health Insurance Portability and Accountability Act.
What is HIPAA? This presentation was created by The University of Arizona Privacy Office, The Office for the Responsible Conduct of Research on March 5,
Key Changes to HIPAA from the Stimulus Bill (ARRA) Children’s Health System Department Leadership Meeting October 28, 2009 Kathleen Street Privacy Officer/Risk.
WHAT IS HIPAA? The Health Insurance Portability and Accountability Act of 1996 (HIPAA) provides certain protections for any of your health information.
HIPAA Health Insurance Portability and Accountability Act.
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996 (HIPAA)
HIPAA Privacy Rule Compliance Training for YSU April 9, 2014.
HIPAA HIPAA Health Insurance Portability and Accountability Act of 1996.
Health Insurance Portability and Accountability Act (HIPAA)
1 Electronic Transactions and Code Sets Enforcement CMS Office of HIPAA Standards.
OCR HITECH Enforcement Tips: Prevent, Detect and Quickly Correct HIPAA COW 2010 Spring Conference Privacy/Security Session 1 HIPAA Privacy Best Practices:
March 19, 2009 Changes to HIPAA Privacy and Security Requirements Joel T. Kopperud Scott A. Sinder Rhonda M. Bolton.
HIPAA COMPLIANCE IN YOUR PRACTICE MARIBEL VALENTIN, ESQUIRE.
HIPAA Health Insurance Portability & Accountability Act of 1996.
Implementing and Enforcing the HIPAA Privacy Rule.
Health Sciences.  Principles  Code of Conduct for right and wrong  Values  Core of all health care decisions.
Office of the Secretary Office for Civil Rights (OCR) HIPAA Privacy and Security Rules Updates HIPAA COW 2010 Spring Conference April 16, 2010.
1 HIPAA Security Overview Centers for Medicare & Medicaid Services (CMS)
© 2009 The McGraw-Hill Companies, Inc. All rights reserved. 1 McGraw-Hill Chapter 5 HIPAA Enforcement HIPAA for Allied Health Careers.
HIPAA The Privacy Rule Health Insurance Portability and Accountability Act of 1996 (HIPAA) The 104 th Congress passed the Act, Public Law ,
1 HIPAA OVERVIEW ETSU. 2 What is HIPAA? Health Insurance Portability and Accountability Act.
Health Insurance Portability and Accountability Act (HIPAA)
Compliance and Enforcement of the Privacy Rule. HHS/OCR February/March Compliance Date  April 14, 2003 – Compliance for all but small health plans.
PRIVACY AND HIPAA THE RIGHT THING TO DO. WHAT’S WRONG WITH THIS PICTURE? ? “ Did you hear that Jane from the 5 th floor is in the hospital?” “No!! Let’s.
HIPAA Michigan Cancer Registrars Association 2005 Annual Educational Conference Sandy Routhier.
Speak HIPAA Like a Native A Guide to Common HIPAA Nomenclature University of Miami Ethics Programs.
Securing Patient-Related Data: The Impact of HIPAA Module VI NUR 603 Russ McGuire.
Health Insurance Portability and Accountability Act (HIPAA) CCAC.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
Understanding HIPAA (Health Insurandce Portability and Accountability Act)
PricewaterhouseCoopers 1 Administrative Simplification: Privacy Audioconference April 14, 2003 William R. Braithwaite, MD, PhD “Doctor HIPAA” HIPAA Today.
HIPAA PRACTICAL APPLICATION WORKSHOP Orientation Module 1B Anderson Health Information Systems, Inc.
1 HIPAA Administrative Simplification Standards Yesterday, Today, and Tomorrow Stanley Nachimson CMS Office of HIPAA Standards.
Copyright ©2014 by Saunders, an imprint of Elsevier Inc. All rights reserved 1 Chapter 02 Compliance, Privacy, Fraud, and Abuse in Insurance Billing Insurance.
C HAPTER 34 Code Blue Health Sciences Edition 4. Confidentiality of sensitive information is an important issue in healthcare. Breaches of confidentiality.
1 Privacy and Security Enforcement: An In-Depth Exploration of Federal Civil Enforcement Gerald “Jud” E. DeLoss Krahmer & Bishop, P.A. Fairmont, MN.
Top 10 Series Changes to HIPAA Devon Bernard AOPA Reimbursement Services Coordinator.
HIPAA Privacy Rule Implementation Status Report Richard M. Campanelli, J.D. Director, Office for Civil Rights Before the The Tenth National HIPAA Summit.
Finally, the Final HIPAA/HITECH Regulations are Here! By LYNDA M. JOHNSON Friday, Eldredge & Clark.
1 Eleventh National HIPAA Summit The New HIPAA Enforcement Rule Gerald “Jud” E. DeLoss, Esq. General Counsel Fairmont Orthopedics & Sports Medicine, P.A.
HIPAA Overview Why do we need a federal rule on privacy? Privacy is a fundamental right Privacy can be defined as the ability of the individual to determine.
HIPAA Privacy Rule Positive Changes Affecting Hospitals’ Implementation of the Rule.
Final PRIVACY RULE Presentation by Richard Campanelli, Director OCR/HHS at 5 th National HIPAA Summit Washington, D.C. October 31, 2002.
 Health Insurance and Accountability Act Cornelius Villalon Jr.
The Health Insurance Portability and Accountability Act of 1996 “HIPAA” Public Law
Office of the Secretary Office for Civil Rights (OCR) Enforcement and Policy Challenges in Health Information Privacy Linda Sanches HIPAA Summit Special.
HIPAA Privacy Rule Positive Changes Affecting Hospitals’ Implementation of the Rule Melinda Hatton -- Oct. 31, 2002.
HIPAA Privacy Rule Training
Health Insurance Portability and Accountability Act of 1996
UNDERSTANDING WHAT HIPAA IS AND IS NOT
Enforcement, Business Associates and Breach Notification. Oh my!
Patient Privacy for the Life Sciences Industry: 2012 Update Drew Gantt and David Sclar Cooley LLP 1.
What is HIPAA? HIPAA stands for “Health Insurance Portability & Accountability Act” It was an Act of Congress passed into law in HEALTH INSURANCE.
HIPAA CONFIDENTIALITY
HIPAA Administrative Simplification
HIPAA PRIVACY AWARENESS, COMPLIANCE and ENFORCEMENT
Disability Services Agencies Briefing On HIPAA
The Centers for Medicare & Medicaid Services
The Centers for Medicare & Medicaid Services
Enforcement and Policy Challenges in Health Information Privacy
Presentation transcript:

Compliance and Enforcement of the Privacy Rule

Compliance Date April 14, 2003 – Compliance for all but small health plans One year extension for small health plans No statutory extension available in Privacy Rule, unlike extension available for Transaction Rule through 10/16/03 HHS/OCR February/March 2003

Office for Civil Rights Among other things… Enforces Civil Rights laws and the Privacy Rule Technical Assistance: helping Covered Entities achieve voluntary compliance Investigation and Resolution of Complaints HHS/OCR February/March 2003

Voluntary Compliance HIPAA Statute and Privacy Rule Promote Voluntary Compliance: Education Cooperation Technical Assistance HHS/OCR February/March 2003

Why Voluntary Compliance? Promoted by HIPAA statute and Privacy Rule Permitted even after investigation commences If Civil Monetary Penalties (CMPs) apply, can mitigate penalties Most efficient way to promote privacy protections in the Rule HHS/OCR February/March 2003

Technical Assistance Integrated Rule and Preambles to Dec. 2000, Aug. 2002 Final Rules Covered Entity decision tool December 4, 2002 Guidance Targeted Technical Assistance materials under development Fact sheet on August 2002 modifications Sample Business Associate Contract FAQs on our website Federal Register Notices on addresses for filing complaints, exception determination requests more to come... http://www.hhs.gov/ocr/hipaa/ HHS/OCR February/March 2003

December 4, 2002 Guidance General Overview Incidental Uses and Disclosures Minimum Necessary Personal Representatives Business Associates Uses and Disclosures for Treatment, Payment and Health Care Operations Marketing Public Health Research Workers’ Compensation Laws Notice Government Access Miscellaneous FAQs HHS/OCR February/March 2003

Investigations & Compliance Reviews OCR may investigate complaints OCR may conduct compliance reviews to determine whether Covered Entities are in compliance HHS/OCR February/March 2003

Filing Complaints Any person or organization may file complaint with OCR by mail or electronically Only for possible violations occurring after compliance date Complaints should be filed within 180 days of when the complainant knew or should have known that the act or omission occurred Individuals may also file complaints with Covered Entity HHS/OCR February/March 2003

Complaint Process Informal review may resolve issue fully Many complaints will be resolved at this stage If not, investigation proceeds Voluntary resolution yet possible Technical Assistance may continue HHS/OCR February/March 2003

CMPs CMPs can be imposed by OCR: $100 per violation Capped at $25,000 for each calendar year for each identical requirement or prohibition that is violated Covered Entity has a right to notice and a hearing before a CMP becomes final HHS/OCR February/March 2003

No CMPs if: Person did not know – and by exercising reasonable diligence would not have known - of the violation If failure to comply is due to reasonable cause and not willful neglect and entity corrects within 30 day cure period Offense is punishable by criminal sanction HHS/OCR February/March 2003

Criminal Penalties for Wrongful Disclosures For knowingly obtaining or disclosing identifiable health information relating to an individual in violation of the Rule: Up to $50,000 & 1 year imprisonment Up to $100,000 & 5 years if done under false pretenses Up to $250,000 & 10 years if intent to sell, transfer, or use for commercial advantage, personal gain or malicious harm Enforced by DOJ HHS/OCR February/March 2003

CMP Flexibility Exceptions Potential extension of the 30 day cure period Technical Assistance if Covered Entity is “unable to comply” CMP reduction possible if: Amount excessive relative to violation Due to reasonable cause/not willful neglect HHS/OCR February/March 2003

Additional Information www.hhs.gov/ocr/hipaa/ HHS/OCR February/March 2003