Privacy and Information Security Training (2006-07) VUMC Privacy Website www.mc.vanderbilt.edu/privacy.

Slides:



Advertisements
Similar presentations
Privacy and Information Security Training ( )
Advertisements

CONFIDENTIALITY / PRIVACY. Federal Laws Privacy Act of 1974 PII (Personally Identifiable Information)….Protection of social security numbers……….
Independent Contractor Orientation HIPAA What Is HIPAA? Health Insurance Portability and Accountability Act of 1996 The Health Insurance Portability.
WRSU Customer Service The Beauty of Change. Privacy and Confidentiality.
And the finer details of patient privacy TCH Confidential Understanding HIPAA.
System Security & Patient Confidentiality General Lesson 1.
1. As a Florida KidCare community partner families entrust you to not only help them navigate the Florida KidCare system but to keep the information they.
Health Insurance Portability and Accountability Act HIPAA Education for Volunteers and Students.
HIPAA. What Why Who How When What Is HIPAA? Health Insurance Portability & Accountability Act of 1996.
HIPAA Basic Training for Privacy & Information Security Vanderbilt University Medical Center VUMC HIPAA Website:
Copyright Eastern PA EMS Council February 2003 Health Information Portability and Accountability Act It’s the law.
The Health Insurance Portability and Accountability Act Basic HIPAA Training For CMU workforce with access to PHI.
LMC WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996.
National Health Information Privacy and Security Week Understanding the HIPAA Privacy and Security Rule.
The Health Insurance Portability and Accountability Act of 1996– charged the Department of Health and Human Services (DHHS) with creating health information.
The HIPAA Privacy Training Video for EMS Field Providers
 Privacy Act of 1974 PII (Personally Identifiable Information)….Protection of social security numbers……….
WORKFORCE CONFIDENTIALITY HIPAA Reminders. HIPAA 101 The Health Insurance Portability and Accountability Act (HIPAA) protects patient privacy. HIPAA is.
1 HIPAA Education CCAC Professional Development Training September 2006 CCAC Professional Development Training September 2006.
NAU HIPAA Awareness Training
1 Louisiana Department of Health and Hospitals Basic HIPAA Privacy Training: Policies and Procedures 01/09/
Before reviewing the following presentation click on the links below and print off the documents: NAM-43 The Bair Foundation HIPAA Policy NAM- 89 HIPAA.
Health Insurance Portability & Accountability Act “HIPAA” To every patient, every time, we will provide the care that we would want for our own loved ones.
HIPAA How can you maintain patient privacy and confidentiality? General Medicine LCCA.
SAFEGUARDING DHS CLIENT DATA PART 2 SAFEGUARDING PHI AND HIPAA Safeguards must: Protect PHI from accidental or intentional unauthorized use/disclosure.
HIPAA What’s Said Here – Stays Here…. WHAT IS HIPAA  Health Insurance Portability and Accountability Act  Purpose is to protect clients (patients)
Privacy and Information Security Non-VUMC Training Vanderbilt University Medical Center Information Privacy & Security Website:
HIPAA COMPLIANCE IN YOUR PRACTICE MARIBEL VALENTIN, ESQUIRE.
HIPAA Basic Training for Privacy and Information Security Vanderbilt University Medical Center VUMC HIPAA Website: HIPAA Basic.
HIPAA Privacy & Security EVMS Health Services 2004 Training.
Columbia University Medical Center Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) Privacy & Information Security Training 2009.
PRIVACY AND INFORMATION SECURITY
HIPAA PRIVACY AND SECURITY AWARENESS.
Next ETCH Confidentiality and HIPAA Annual Review What you need to know. The Privacy Rule 1.
HIPAA Training Developed for Ridgeview Institute 2012 Hospital Wide Orientation.
Group 3 Angela, Rachael, Misty, Kayelee, and Krysta.
Medical Law and Ethics, Third Edition Bonnie F. Fremgen Copyright ©2009 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved.
Building a Privacy Foundation. Setting the Standard for Privacy Health Insurance Portability and Accountability Act (HIPAA) Patient Bill of Rights Federal.
Mr. Fleming.  Law passed by Congress in  Right to Privacy ◦ Medical information of patient can only be shared with doctor and professionals administering.
Privacy & Confidentiality
Why Respect Privacy and Confidentiality? Access to Confidential Information (OP ) Protection and Security of Protected Health Information (OP.
HIPAA PRACTICAL APPLICATION WORKSHOP Orientation Module 1B Anderson Health Information Systems, Inc.
Rhonda Anderson, RHIA, President  …is a PROCESS, not a PROJECT 2.
A Road Map to Research at Jefferson: HIPAA Privacy and Security Rules for Researchers Presented By: Privacy Officer/Office of Legal Counsel October 2015.
HIPAA Overview Why do we need a federal rule on privacy? Privacy is a fundamental right Privacy can be defined as the ability of the individual to determine.
2015 Privacy & Security Refresher. Presenters  Dana Williams  Privacy Officer  (501)  Stephen Yarberry  Chief Information Security Officer.
HIPAA Training. What information is considered PHI (Protected Health Information)  Dates- Birthdays, Dates of Admission and Discharge, Date of Death.
The Medical College of Georgia HIPAA Privacy Rule Orientation.
New Hire HIPAA Orientation. HIPAA Overview HIPAA is an acronym that stands for the Health Insurance Portability and Accountability Act of HIPAA.
The Health Insurance Portability and Accountability Act (HIPAA) requires Plumas County to train all employees in covered departments about the County’s.
HIPAA Privacy What Every Staff Member Needs to Know.
Properly Safeguarding Personally Identifiable Information (PII) Ticket Program Manager (TPM) Social Security’s Ticket to Work Program.
Developed for Ridgeview Institute 2015 Hospital Wide Orientation
HIPAA Privacy and Security
Health Insurance Portability and Accountability Act of 1996
WHAT IS HIPAA AND HOW TO COMPLY WITH IT?
HIPAA Privacy & Security
And the finer details of patient privacy
HIPAA Online Student Orientation
HIPAA Basic Training for Privacy and Information Security
WHAT IS HIPAA AND HOW TO COMPLY WITH IT?
Move this to online module slides 11-56
HIPAA PRIVACY AWARENESS, COMPLIANCE and ENFORCEMENT
Disability Services Agencies Briefing On HIPAA
HIPAA Privacy & Security
HIPAA SECURITY RULE Copyright © 2008, 2006, 2004 by Saunders an imprint of Elsevier Inc. All rights reserved.
The Health Insurance Portability and Accountability Act
Move this to online module slides 11-56
HIPAA Do’s and Don'ts: What is Really Behind Protected Health Information (PHI) and Health Care Privacy Rules Paul Sisler, Director, Information Services;
Presentation transcript:

Privacy and Information Security Training ( ) VUMC Privacy Website

The Most Common Privacy/Security Incidents Reported I. Unauthorized access or disclosure of patient information II. Sharing passwords, and electronic signatures III. Failure to secure workstations IV. Failure to properly dispose of documents containing confidential information V. Careless handling of personal or confidential information

I.Unauthorized Access or Disclosure of Patient Information  Have you been concerned about a co-worker in the hospital and looked up their medical record?  Have you looked up your spouse’s record without formal authorization? These are considered Level III violations and will result in at least final written warning or Final PIC. Patient information shall be accessed and disclosed only as authorized, on a need-to-know basis, or as required by law.

Accessing and Disclosing Patient Information Things You Need to Know An “Authorization to Access Medical Records” form (MC1814) must be signed and placed into the patient’s record for you to have permission to access a record. You can obtain this form in Star Panel, by going to e-docs, or calling the Privacy Office. The Privacy Office conducts audits each month on the records of staff and faculty.

Accessing and Disclosing Patient Information Things You Need to Know Entering a patient’s room and proceeding to discuss information with the patient in front of family members/visitors has resulted in inappropriate disclosures. Remember to ask family members/visitors to leave the room prior to discussing information. If the patient says it’s okay for them to stay then you can proceed with the discussion.

Accessing and Disclosing Patient Information Things You Need to Know The following behaviors are considered privacy breaches under the current sanctions policy? Gossiping about a faculty/staff member’s health information resulting in a complaint being filed is considered a Level I violation. Gossiping/sharing PHI secured through your role at VUMC is considered a Level III violation. VUMC Sanctions Policy: Manual/Hpolicy.nsf/AllDocs/F4FAEAD3EEB0D9C986256FE7006DE2A2

II. Sharing Passwords and Electronic Signatures  What if a manager shares the password to her account with her Administrative Assistant?  What if a resident shares her SecurID token with another resident who is having problems with his own token? Both of these are privacy/security violations and will result in disciplinary action. Individual user names and passwords, as well as electronic signatures, must be kept confidential and shall not be shared.

Sharing Passwords and Electronic Signatures Things You Need to know Sharing your VU-net user name and password with another person gives that person access to your personnel records. You are able to delegate access to your account to someone else without sharing your password. Contact your computer support person if you need help to give someone access to your account.

III. Failure to Secure Workstations Things You Need to Know  Failure to lock the computer screen may result in others documenting in the electronic medical record under your user-id.  Failure to lock the computer screen when you walk away allows unauthorized individuals to view confidential information. Be sure to lock the computer screen or log off anytime you need to walk away from the computer to protect confidentiality and data integrity.

IV. Failure to Dispose of Documents Containing Confidential Information Things You Need to Know  Always dispose of confidential information in a shredder bin.  Be sure to clear your desk of any documents containing confidential information or remove them from view when leaving your desk for an extended period of time.  Photos of patients for treatment purposes must be stored in the patient’s record or in a secure database in accordance with the revised policy “Consent for Patient Photographs/Videos” OP Medical records, reports or other documents or information shall not be left unattended in a way that exposes confidential information.

V. Careless handling of personal or confidential information Things You Need to Know When faxing:  Always use a cover sheet  Confirm the fax number before you send  Double check to make sure you enter the correct fax number. Personal or confidential information misdirected to the wrong person verbally or by fax or is considered a privacy breach.

Careless handling of personal or confidential information Things You Need to Know  When sending electronic messages  Use MyHealthatVanderbilt.com (a secure web-based portal) to securely communicate with patients, as opposed to standard  If you use , confirm the address before sending and limit the personal information sent  When discussing confidential information  Avoid being overheard by others  Just leave a name and call back number in phone messages

Conclusion Some privacy/security breaches occur from individuals being careless while others occur from deliberate actions. Follow the practices set forth in this training presentation and you will avoid committing the most frequent type of breaches that occur at VUMC. If you have any questions or need to report a concern, please contact the Privacy or

Final Instructions To complete the training you must print off the HIPAA Test and submit it to the manager in your department for filing in your personnel file. HIPAA Test Any questions related to this training may be submitted to the Privacy Office at or call