Overview of the Privacy Act

Slides:



Advertisements
Similar presentations
H = P = A = HIPAA DEFINED HIPAA … A Federal Law Created in 1996 Health
Advertisements

PRIVACY ACT OF 1974 OVERVIEW. FAIR INFORMATION PRACTICES The Privacy Act is primarily concerned with fair information practices. The Privacy Act is primarily.
HIPAA Privacy Practices. Notice A copy of the current DMH Notice must be posted at each service site where persons seeking DMH services will be able to.
The Legal Foundation TRICARE Management Activity HEALTH AFFAIRS 2009 Data Protection Seminar TMA Privacy Office.
Mandatory training for all Users who have access to Privacy Act Data
HIPAA: An Overview of Transaction, Privacy and Security Regulations Training for Providers and Staff.
HIPAA Privacy Training. 2 HIPAA Background Health Insurance Portability and Accountability Act of 1996 Copyright 2010 MHM Resources LLC.
HIPAA Privacy Rule Training
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
HIPAA PRIVACY REQUIREMENTS Dana L. Thrasher Constangy, Brooks & Smith, LLC (205) ; Victoria Nemerson.
What is HIPAA? This presentation was created by The University of Arizona Privacy Office, The Office for the Responsible Conduct of Research on March 5,
1 HIPAA Education CCAC Professional Development Training September 2006 CCAC Professional Development Training September 2006.
NAU HIPAA Awareness Training
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996 (HIPAA)
HIPAA THE PRIVACY RULE Reviewed December HISTORY In 2000, many patients that were newly diagnosed with depression received free samples of anti-
HIPAA HIPAA Health Insurance Portability and Accountability Act of 1996.
1 Office of the General Counsel FERPA  Family Educational Rights and Privacy Act (20 U.S.C § 1232g)
FAR P ART 24. This part prescribes policies and procedures that apply requirements of the Privacy Act of 1974 (5 U.S.C. 552a) (the Act) and OMB Circular.
Defense Privacy Office 1 Budget Documentation and Justification Writing Class The Privacy Act of 1974: What Senior Leaders Need to Know.
ROLES & RESPONSIBILITIES PRIVACY ACT (PA) SYSTEMS OF RECORDS MANAGERS.
PRIVACY ACT OVERVIEW The Basic Concepts of the Act United States Pacific Command (USPACOM) FOIA & Privacy Act Conference presented by Samuel P. Jenkins,
PA/FOIA INTERFACE OSD/JS Privacy Office (703)
 Freedom of Information Act General Background. Access to Army Records. Exemptions. Exclusions. Procedural Rules for Processing FOIA Requests for Army.
FERPA 2008 New regulations enact updates from over a decade of interpretations.
PRIVACY ACT Federal Workers’ Compensation Conference 2014 Department of Labor.
FERPA Overview for CANR Business Managers Rob Kent, MSU Assistant General Counsel October 7, 2014.
The Family Educational Rights and Privacy Act (FERPA) The Importance of Protecting Student Records This session will help you better understand the law.
HIPAA COMPLIANCE IN YOUR PRACTICE MARIBEL VALENTIN, ESQUIRE.
DEED WorkForce Center Reception and Resource Area Certification Program Module 2 Unit 1b: WorkForce Center System II Learning Objectives III.
DEFENSE PRIVACY & CIVIL LIBERTIES OFFICE Safeguarding Personally Identifiable Information (PII) Samuel P. Jenkins Director for Privacy Defense Privacy.
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
The Privacy Act of 1974: An Introduction The Privacy Act of 1974: An Introduction September 2010 For Official Use Only 0.
DEFENSE PRIVACY & CIVIL LIBERTIES OFFICE Privacy Foundations Samuel P. Jenkins Director for Privacy Defense Privacy and Civil Liberties Office Identity.
CUI Statistical: Collaborative Efforts of Federal Statistical Agencies Eve Powell-Griner National Center for Health Statistics.
PRIVACY SAFEGUARDS ANNUAL TRAINING FY 2011 previous next Office of Management Privacy, Information and Records Management Services Privacy Safeguards Division.
HIPAA PRIVACY AND SECURITY AWARENESS.
Confidentiality, Consents and Disclosure Recent Legal Changes and Current Issues Presented by Pam Beach, Attorney at Law.
Privacy and Security of Protected Health Information NorthPoint Health & Wellness Center 2011.
Ames Laboratory Privacy and Personally Identifiable Information (PII) Training Welcome to the Ames Laboratory’s training on Personally Identifiable Information.
FERPA: What you Need to Know The Family Educational Rights and Privacy Act & SEI.
HIPAA Michigan Cancer Registrars Association 2005 Annual Educational Conference Sandy Routhier.
Medical Law and Ethics, Third Edition Bonnie F. Fremgen Copyright ©2009 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
The right item, right place, right time. DLA Privacy Act Code of Fair Information Principles.
HIPAA BASIC TRAINING Presented by Anderson Health Information Systems, Inc.
HIPAA THE PRIVACY RULE. 2 HISTORY In 2000, many patients that were newly diagnosed with depression received free samples of anti- depressant medications.
FAMIS CONFERENCE Mari M. Presley, Assistant General Counsel Florida Department of Education June 12, 2012.
A Road Map to Research at Jefferson: HIPAA Privacy and Security Rules for Researchers Presented By: Privacy Officer/Office of Legal Counsel October 2015.
Data Practices in Minnesota December Outline for this presentation Minnesota data practices laws Classification of government data Government entity.
Research & Economic Development Office of Grants and Contracts Administration Data Security Presented by Debbie Bolick September 24, 2015.
An Introduction to the Privacy Act Privacy Act 1993 Promotes and protects individual privacy Is concerned with the privacy of information about people.
Copyright © 2015 by Saunders, an imprint of Elsevier Inc. All rights reserved. Chapter 3 Privacy, Confidentiality, and Security.
Privacy Act United States Army (Managerial Training)
Slide 1 of 9. Slide 2 of 9 The Privacy Act of 1974 (Pub.L , 88 Stat. 1896, enacted December 31, 1974, 5 U.S.C. Section 552a) establishes a Code.
Sharing Information (FERPA) FY07 REMS Initial Grantee Meeting December 5, 2007, San Diego, CA U.S. Department of Education, Office of Safe and Drug-Free.
FERPA for the Financial Aid Office NCASFAA Fall Conference November 2012.
FOIA Processing and Privacy Awareness at NOAA Prepared by Mark H. Graff NOAA FOIA Officer OCIO/GPD (301)
For Official Use Only (FOUO) and Similar Designations NPS Security Office
Welcome to Workforce 3 One U.S. Department of Labor Employment and Training Administration Webinar Date: Thursday, October 23, 2014 Presented by: Division.
POLICIES & PROCEDURES FOR HANDLING CONFIDENTIAL INFORMATION NOVEMBER 5 TH 2015.
HIPAA Training Workshop #3 Individual Rights Kaye L. Rankin Rankin Healthcare Consultants, Inc.
HIPAA Privacy Rule Training
Nassau Association of School Technologists
Wyoming Statutes §§ through
Move this to online module slides 11-56
Disability Services Agencies Briefing On HIPAA
The Privacy Act of 1974: An Introduction September 2010
State of florida tax information sharing Paula Barfield August 5, 2015
Confidentiality Training 2014
Presentation transcript:

Overview of the Privacy Act United States Army

Overview After completing this training course, you should be knowledgeable on: The purpose of the Privacy Act and policy objectives Who is covered by the Privacy Act Restrictions on disclosing Privacy Act records Civil and criminal penalties Safeguarding Personally Identifiable Information (PII)

What is the Privacy Act? The Privacy Act balances the government’s need to maintain information about individuals with the right of individuals to be protected against unwarranted invasion of their privacy. This: Regulates the collection, maintenance, use, and dissemination of Personally Identifiable Information (PII) by Federal Executive Branch Agencies Limits the unnecessary collection of information about individuals

What is PII? Personally Identifiable Information (PII) is defined as: Information which can be used to distinguish or trace an individual’s identity, such as their name, social security number, DOD ID, biometric records alone, or when combined with other personal or identifying information which is linked or linkable to a specific individual, such as date and place of birth, mother’s maiden name, and so forth. (OMB M-07-16)

Privacy Act Objectives To restrict disclosure of information and records maintained by agencies To grant individuals the right to seek amendment of agency records maintained on themselves To grant individuals increased rights of access to agency records maintained on themselves Establishes rules that govern the collection and use of personal data

Who is covered by the Privacy Act? The Privacy Act applies to: Federal Agencies Living U.S. Citizens Legal aliens lawfully admitted for permanent residence The Privacy Act regulates the way individuals’ personal information is handled. As an individual, the Privacy Act gives you greater control over the way that your personal information is handled.

What is covered by the Privacy Act? The Privacy Act allows you to: know why your personal information is being collected, how it will be used, and who it will be disclosed to ask for access to your personal information (including your health information) ask for your personal information that is incorrect to be corrected make a complaint about an entity covered by the Privacy Act, if you consider that they have mishandled your personal information

Disclosing Personally Identifiable Information No agency or person shall disclose any record that is contained in a system of records by any means of communication to any person, except pursuant to: a written request by the individual to whom the record pertains, or the written consent of the individual to whom the record pertains

Restrictions on disclosing Privacy Act Records There are twelve (12) exceptions to “No disclosure to Third Parties Without Consent” rule.

Twelve Exceptions Allow Agencies to Disclose PII Without a Consent 1. To employees with a legitimate need-to-know 2. When the FOIA requires release

Twelve Exceptions Allow Agencies to Disclose PII Without a Consent 3. For a “routine use” identified in the System of Records Notice (SORN) that has been published in the Federal Register 4. To the Census Bureau for purpose of conducting the census

Twelve Exceptions Allow Agencies to Disclose PII Without a Consent 5. For statistical research and reporting in which individuals will not be identified 6. To the National Archives and Records Administration

Twelve Exceptions Allow Agencies to Disclose PII Without a Consent 7. To civil or criminal law enforcement under U.S. control 8. For circumstances affecting the health or safety of the individual

Twelve Exceptions Allow Agencies to Disclose PII Without a Consent 9. To either House of Congress 10. To the Comptroller General

Twelve Exceptions Allow Agencies to Disclose PII Without a Consent 11. Pursuant to a court order (a subpoena signed by a judge) 12. To a consumer reporting agency in accordance with the Debt Collection Act

Information Sharing Concerns Having a specific need-to-know means that access to the information in question is absolutely required to perform one’s official duties Need-to-know may be established for official business, statutory law, and information sharing For example: A person working in a finance division does not have a need-to-know about another person’s medical information

Information Sharing Concerns If a need-to-know has not been or cannot be established, the following actions should be taken: Do not share the information in question If information has already been inappropriately released, notify your manager immediately; this is a PII breach

Information Sharing Concerns To avoid the most common types of breaches, utilize the following best practices: Use a Privacy Cover Sheet as a cover when handling PII Always encrypt emails containing PII Avoid sending faxes containing PII when possible Dispose of documents containing PII properly

Civil and Criminal Penalties Failure to comply with any Privacy Act provision or agency rule that results in an adverse effect on the subject of the record may have different consequences: Civil penalties: (Applying to the Agency) The cost of actual damages suffered ($1,000 minimum) Costs and reasonable attorney’s fees

Civil and Criminal Penalties Failure to comply with any Privacy Act provision or agency rule that results in an adverse effect on the subject of the record may have different consequences: Accidental infringement will result in discretionary discipline depending on the severity of the offense The “willful violation” of any Privacy Act provisions will result in Criminal Penalties including: A misdemeanor charge A maximum fine of $5,000

Safeguarding Personally Identifiable Information Administrative - Procedures implemented at the administrative level to protect private information. Technical - Technology-based instruments and procedures used to protect private information. Physical - The physical protections implemented for protecting private information

Safeguarding Personally Identifiable Information Administrative Safeguards Ensure that every recipient of PII has a need-to-know Validate the use of information against the purpose of collection documented in the System of Records Notice (SORN) SORN Managers keep SORNs up to date by reviewing them every two years

Safeguarding Personally Identifiable Information Administrative Safeguards Ensure telephone conversations are private Consult your Component Privacy Officer before collecting PII Include a Privacy Act Data Cover Sheet with all copies of documents containing PII Collect, use, maintain, and disseminate data that is accurate, complete, relevant, and timely

Safeguarding Personally Identifiable Information Technical Safeguards Encrypt all emails that contain PII Use only DoD-approved software on your computer Do not use flash (thumb) drives for transporting PII Never use personal equipment to store PII Ensure that information is from a government authorized source

Safeguarding Personally Identifiable Information Physical Safeguards Use locks to secure PII when stored Dispose of records according to established schedules in the SORN or procedures established by The National Archives and Records Administration System Managers should maintain a record of the movement of hardware and electronic media in their control, including to whom the equipment was issued, the date of issuance, and the date of return Implement policies and procedures to safeguard the facility and the equipment therein from unauthorized physical access, tampering, and theft

References Defense Privacy and Civil Liberties Office – http://dpclo.defense.gov DoD Directive 5400.11, “DoD Privacy Program,” DoD Regulation 5400.11-R, “Department of Defense Privacy Program,” DA&M Memorandum, “Safeguarding Against and Responding to the Breach of Personally Identifiable Information,”