111 Alegent Health is a faith-based health ministry sponsored by Catholic Health Initiatives and Immanuel Health Systems. HIPAA Privacy & Information Security.

Slides:



Advertisements
Similar presentations
Protect Our Students Protect Ourselves
Advertisements

Online Course Privacy Contacting Patients and Verification START Click to begin…
Independent Contractor Orientation HIPAA What Is HIPAA? Health Insurance Portability and Accountability Act of 1996 The Health Insurance Portability.
1 The Health Insurance Portability and Accountability Act (HIPAA) A guided tutorial for GVSU employees.
And the finer details of patient privacy TCH Confidential Understanding HIPAA.
HIPAA Privacy Training. 2 HIPAA Background Health Insurance Portability and Accountability Act of 1996 Copyright 2010 MHM Resources LLC.
Health Insurance Portability and Accountability Act HIPAA Education for Volunteers and Students.
HIPAA. What Why Who How When What Is HIPAA? Health Insurance Portability & Accountability Act of 1996.
HIPAA Basic Training for Privacy & Information Security Vanderbilt University Medical Center VUMC HIPAA Website:
Confidentiality and HIPAA
HIPAA Training for the MDAA Preceptorship Program Health Insurance Portability and Accountability Act.
Copyright Eastern PA EMS Council February 2003 Health Information Portability and Accountability Act It’s the law.
LMC WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996.
National Health Information Privacy and Security Week Understanding the HIPAA Privacy and Security Rule.
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
The Health Insurance Portability and Accountability Act of 1996– charged the Department of Health and Human Services (DHHS) with creating health information.
The HIPAA Privacy Training Video for EMS Field Providers
What is HIPAA? This presentation was created by The University of Arizona Privacy Office, The Office for the Responsible Conduct of Research on March 5,
1 HIPAA Education CCAC Professional Development Training September 2006 CCAC Professional Development Training September 2006.
NAU HIPAA Awareness Training
HIPAA Health Insurance Portability and Accountability Act 1.
1 Louisiana Department of Health and Hospitals Basic HIPAA Privacy Training: Policies and Procedures 01/09/
WHAT IS HIPAA? The Health Insurance Portability and Accountability Act of 1996 (HIPAA) provides certain protections for any of your health information.
 The Health Insurance Portability and Accountability Act of  Federal Law designed to protect sensitive information.  HIPAA violations are enforced.
Health Insurance Portability & Accountability Act “HIPAA” To every patient, every time, we will provide the care that we would want for our own loved ones.
Are you ready for HIPPO??? Welcome to HIPAA
HIPAA How can you maintain patient privacy and confidentiality? General Medicine LCCA.
HIPAA HIPAA Health Insurance Portability and Accountability Act of 1996.
Professional Nursing Services.  Privacy and Security Training explains:  The requirements of the federal HIPAA/HITEC regulations, state privacy laws.
HIPAA COMPLIANCE IN YOUR PRACTICE MARIBEL VALENTIN, ESQUIRE.
HIPAA Health Insurance Portability & Accountability Act of 1996.
HIPAA – Health Insurance Portability & Accountability Act and the Privacy Act MSgt Nechele M. Chambers Senior Enlisted Liaison TRICARE Area Office-Europe.
HIPAA Basic Training for Privacy and Information Security Vanderbilt University Medical Center VUMC HIPAA Website: HIPAA Basic.
Columbia University Medical Center Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) Privacy & Information Security Training 2009.
HIPAA PRIVACY AND SECURITY AWARENESS.
Next ETCH Confidentiality and HIPAA Annual Review What you need to know. The Privacy Rule 1.
Copyright ©2011 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved. Health Information Technology and Management Richard.
HIPAA Training Developed for Ridgeview Institute 2012 Hospital Wide Orientation.
Medical Law and Ethics, Third Edition Bonnie F. Fremgen Copyright ©2009 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved.
Building a Privacy Foundation. Setting the Standard for Privacy Health Insurance Portability and Accountability Act (HIPAA) Patient Bill of Rights Federal.
Understanding HIPAA (Health Insurandce Portability and Accountability Act)
Mr. Fleming.  Law passed by Congress in  Right to Privacy ◦ Medical information of patient can only be shared with doctor and professionals administering.
Privacy & Confidentiality
HIPAA BASIC TRAINING Presented by Anderson Health Information Systems, Inc.
HIPAA BASIC TRAINING MODULE 1C – Overview (For staff who do not generally create Protected Health Information) Anderson Health Information Systems, Inc.
HIPAA Pre-Clerkship Review Dr. Maryann Skrabal, Pharm.D., CDE.
HIPAA THE PRIVACY RULE. 2 HISTORY In 2000, many patients that were newly diagnosed with depression received free samples of anti- depressant medications.
C HAPTER 34 Code Blue Health Sciences Edition 4. Confidentiality of sensitive information is an important issue in healthcare. Breaches of confidentiality.
A Road Map to Research at Jefferson: HIPAA Privacy and Security Rules for Researchers Presented By: Privacy Officer/Office of Legal Counsel October 2015.
1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.
HIPAA Overview Why do we need a federal rule on privacy? Privacy is a fundamental right Privacy can be defined as the ability of the individual to determine.
CH 10. Confidentiality A. Confidentiality about sensitive medical information is necessary to preserve the patient’s dignity. B. In order to receive payment.
Aged and Disabled Waiver (ADW) Health Insurance Portability and Accountability Act (HIPAA) Training 2015 October 2015.
HIPAA for Students Health Insurance Portability and Accountability Act.
HIPAA HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT UI EMS Training Dept.
HIPAA TRIVIA Do you know HIPAA?. HIPAA was created by?  The Affordable Care Act  Health Insurance companies  United States Congress  United States.
HIPAA Training. What information is considered PHI (Protected Health Information)  Dates- Birthdays, Dates of Admission and Discharge, Date of Death.
The Medical College of Georgia HIPAA Privacy Rule Orientation.
New Hire HIPAA Orientation. HIPAA Overview HIPAA is an acronym that stands for the Health Insurance Portability and Accountability Act of HIPAA.
HIPAA Privacy What Every Staff Member Needs to Know.
Health Insurance Portability and Accountability Act (HIPAA) Primer for Observers, Volunteers, Medical Students Dr. Michael Palumbo- Privacy Officer/ EVP.
HIPAA Privacy & Security
And the finer details of patient privacy
HIPAA Basic Training for Privacy and Information Security
Disability Services Agencies Briefing On HIPAA
HIPAA Privacy & Information Security
Move this to online module slides 11-56
HIPAA Privacy & Security
The Health Insurance Portability and Accountability Act
Presentation transcript:

111 Alegent Health is a faith-based health ministry sponsored by Catholic Health Initiatives and Immanuel Health Systems. HIPAA Privacy & Information Security

HIPAA Privacy & Info Security Overview What is HIPAA and why should I care?  HIPAA is the Health Insurance Portability and Accountability Act of This presentation will focus on those sections of the law related to Privacy and Information Security as it applies to Alegent Health. HIPAA:  Provides patients with more control over their health information  Sets boundaries on the use and disclosure of medical records  Establishes safeguards for the protection of PHI  Holds violators accountable with civil and criminal penalties

HIPAA Privacy & Info Security Overview The consequences for non-compliance can be serious, including termination of contracts with our vendors, restriction of access for physicians offices and performance improvement for our workforce, including termination and criminal charges. The financial and personal consequences for violators are also serious including fines up to $250, and up to 10 years imprisonment. Several individuals have already been prosecuted for breach of medical privacy. Lastly, the practice of healthcare is founded on our patients’ trust in us, including safeguarding private information and sharing only what is necessary with those who have a need to know. Patient trust encourages the free flow of information between patient and provider – without it, patient care will suffer.

HIPAA Privacy & Info Security PHI – What is it? HIPAA Privacy rules protect individually identifiable protected health information (PHI) from inappropriate use, request or disclosure. PHI includes:  Name  Address  Contact Information  Diagnosis  Lab results  Patient Status  Billing Information  EOBs  Medical Records  Blood type  Symptoms  Relatives  Appointment schedule  Photographs And any other information that can be tied to a patient’s past, present or future health status and is created or maintained by Alegent Health.

HIPAA Privacy & Info Security Summary of the Regulations 1.You must not use, request or disclose PHI except as permitted or required by these regulations 2.You must make reasonable efforts to limit the use, request or disclosure of PHI to the minimum necessary 3.You must not use or disclose PHI for marketing/fundraising purposes without specific authorization 4.You must obtain satisfactory assurance that business associates will safeguard PHI 5.You must recognize that de-identified data is not covered by HIPAA 6.You must recognize and protect the 5 qualified privacy specific patient rights under this rule 7.You must designate a Privacy Officer to ensure compliance with HIPAA guidelines, train the workforce and provide a mechanism to address concerns.

HIPAA Privacy & Info Security What does HIPAA allow? We may NOT use, request or disclose PHI unless HIPAA allows it – which is in varying degrees for:  Treatment purposes PHI can be shared freely with other covered entities  Payment activities (including collections) Minimum Necessary  Bona fide healthcare operations (Performance Improvement activities, etc.) Minimum Necessary  As required by law (gunshot wounds, STDs) Minimum Necessary  OR if the patient “says” to do so!

HIPAA Privacy & Info Security Patient Rights under HIPAA Under HIPAA, patients have 5 qualified rights:  The right to notice about how their PHI will be used and disclosed The Notice of Privacy Practices given to each patient  The right to have access to their PHI Usually a request to the Medical Records dept to get a copy for themselves or another provider  The right to request that access be restricted As with No Info patients  The right to know who has accessed their PHI A request for an Accounting of Disclosures via Medical Records  The right to request amendment to their PHI Also managed through the Medical Records department

HIPAA Privacy & Info Security Communicating patient information “General” patient information  Unless a patient instructs us otherwise, if someone asks about them by name, we can disclose: That the patient is in the facility The patient’s location (room #) Their condition in general terms (undetermined, good, fair, serious, critical)  This information can only be disclosed in response to a request – we cannot offer it to anyone without them asking us for it.  If patients do NOT want “general information” available, they can notify Registration or their caregivers at any time and become a “No Info” patient

HIPAA Privacy & Info Security Communicating patient information Releasing more detailed information to those involved in the patient’s care or payment (lab results, insurance info, treatment plan, prognosis)…  Disclosures of this nature should be directed by the patient whenever possible. As long as an adult patient is awake and competent, it is best to simply ask them for permission to discuss/disclose the information, and document the permission.  We are also allowed to use professional judgment to determine whether it is appropriate, based on the person’s involvement in the patient’s current care or payment  If the patient objects at any time, discontinue

HIPAA Privacy & Info Security Shhhh! Privacy regulations include oral communication as well as paper and electronic.  Be aware of your surroundings.  Avoid conversations about protected health information where others may overhear.  Take reasonable steps to avoid being overheard whether you are talking face-to-face or on the telephone. If there is an office or private area available, use it. Offices, clinics and hospital rooms are NOT soundproof and being a patient or visiting family member does not in itself negatively impact hearing  REMEMBER - It’s a small world. Discussion at restaurants, bars and ballgames have found their way back to our patients.

HIPAA Privacy & Info Security The basics… Do NOT Access, use, request, review or disclose protected health information in any form whether paper, electronic or verbal unless you need to do so to do your job. Then access, use, request, review or disclose only the minimum necessary to achieve your legitimate purpose.

HIPAA Privacy & Info Security Safeguarding PHI If you are given electronic access to patient information, you are subject to the following rules to safeguard PHI;  Use only your own login and password, and never let anyone else use them. Protect them as you would if they accessed your bank account!  Never sign into an application on a computer where someone else is logged in. This will cause your logins to be linked and could lead to inappropriate access on their part being attributed to you.  Log off or “flag out” when you walk away from the computer. Flagging out (by holding down the Windows flag and clicking on the letter “L”) will pop up the login screen. You need only enter your password to be back where you were. + L = Flag Out

HIPAA Privacy & Info Security Safeguarding PHI Do not put PHI onto unencrypted devices!  Amazing the number of time PHI has been lost or stolen in the last few years – it’s in the news all the time. Laptops are stolen out of cars, thumb drives and backup tapes lost. Maintaining or moving PHI while it is encrypted and password protected will also protect you if something unfortunate happens! Do not PHI unless it is encrypted! Protect records by keeping them in secure locations. Do not leave them unattended where passers-by can look at them!

HIPAA Privacy & Info Security Auditing One of the requirements of HIPAA is that we monitor employee activity within our system  The rule requires that we “Implement procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking reports.” At Alegent Health, everyone who accesses our clinical and billing software & systems should be aware that we do audit and review activity. The primary systems will show:  Whose record you accessed  What was done, including simple review of patient info, edits, updates, printing, screen changes, which screens were viewed, etc.  The date and time of each activity

HIPAA Privacy & Info Security Consequences Remember that an audit showing that you inappropriately accessed records that you did not need to access – including your own records, or those of friends or family - will be addressed. Inappropriate access may lead to a suspension or termination of access to the system – and may lead to criminal or civil charges as well. Before you access – be sure it’s worth it!

HIPAA Privacy & Info Security Quick Quiz Joe heard that his grandmother was in the hospital. He called the hospital to find out her condition. Can her condition be disclosed? Yes. As long as Mrs. Jones hasn’t decided to be a No Info patient, we can disclose the room number and condition in general terms such as good, fair, serious or critical.

HIPAA Privacy & Info Security Quick Quiz A person calls you, identifying themselves as the spouse of a patient. Can we provide detailed patient information based only on the fact that they are married? No. Even if we are able to verify the callers identity as the spouse, a person is not entitled to a spouse’s PHI based on marriage alone. (As with any other caller, they can get Facility Directory info - if the patient isn’t No Info). If the patient has not communicated a desire to have their spouse informed – either verbally or in written form - you would need to determine if the spouse is involved in the patient’s care or payment for that care, and to what extent prior to any disclosure.

HIPAA Privacy & Info Security Quick Quiz Is it ok to discuss patient information in public areas as long as you do not use the patient’s name? No. Even without saying the name, others may be able to determine who you are discussing – or think they know. This is not an appropriate way to find out about a loved one’s prognosis. Even in an appropriate area, maintain professionalism. We have had investigated several complaints stemming from patients overhearing their caregivers making derisive comments about them.

HIPAA Privacy & Info Security Quick Quiz Is looking up patient information out of concern or curiosity ok, as long as you don’t disclose what you see to others? No. Access patient information only when you have a legitimate, work related need to know. Similarly, it is not appropriate to “just check” whether someone is or has been a patient because of something you’ve heard in the media.

HIPAA Privacy & Info Security Quick Quiz You are at work and see a friend as you walk down the hall. You stop and say hello. They tell you that they are in for tests and you wish them well and go on your way. When you get home, can you tell anyone about your friend’s tests? No. Any information that you gain while you are working as a member of Alegent Health’s workforce or while visiting one of our sites must be treated confidentially.  Consider your friend’s situation – they may not have expected to see you and (short of hiding behind a plant) could not avoid speaking to you.  In this type of situation, avoid direct questions about their reason for being there and if your friend does give you details, ask if it ok to share with others before doing so. Then be sure to say you have permission when you share!

HIPAA Privacy & Info Security Certificate of Completion Thank you for completing Alegent Health’s HIPAA Privacy & Information Security Training online. NameDate Please print this page for documentation purposes.