Privacy Laws & Higher Education. Agenda 1.Five Privacy Laws a.FERPA b.HIPAA c.GLB d.FACTA Disposal Rule e.CAN-SPAM 2.Overview of the Laws a.What does.

Slides:



Advertisements
Similar presentations
HIPAA In Relation to Other Federal Laws Professor Peter P. Swire Ohio State University Consultant, Morrison & Foerster LLP Glasser LegalWorks/HIPAA Conference.
Advertisements

FERPA - Sharing Student Information
HIPAA: An Overview of Transaction, Privacy and Security Regulations Training for Providers and Staff.
Presented by Elena Chan, UCSF Pharm.D. Candidate Tiffany Jew, USC Pharm.D. Candidate March 14, 2007 P HARMACEUTICAL C ONSULTANTS, I NC. P RO P HARMA HIPAA.
1. As a Florida KidCare community partner families entrust you to not only help them navigate the Florida KidCare system but to keep the information they.
HIPAA Privacy Training. 2 HIPAA Background Health Insurance Portability and Accountability Act of 1996 Copyright 2010 MHM Resources LLC.
Health Insurance Portability and Accountability Act HIPAA Education for Volunteers and Students.
Confidentiality and HIPAA
HIPAA Privacy Rule Training
Copyright Eastern PA EMS Council February 2003 Health Information Portability and Accountability Act It’s the law.
The Health Insurance Portability and Accountability Act of 1996– charged the Department of Health and Human Services (DHHS) with creating health information.
HIPAA PRIVACY REQUIREMENTS Dana L. Thrasher Constangy, Brooks & Smith, LLC (205) ; Victoria Nemerson.
What is HIPAA? This presentation was created by The University of Arizona Privacy Office, The Office for the Responsible Conduct of Research on March 5,
Health Insurance Portability and Accountability Act (HIPAA)HIPAA.
© 2014 ACA International. All Rights Reserved. Obtaining Optimum Compliance Performance Foundational Training on ACA’s Professional Practices Management.
Regulatory Issues in Campus Computing Privacy and Security in a Digital World Presented by David Gleason, Esq. University Counsel University of Maryland,
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996 (HIPAA)
COMPLYING WITH HIPAA PRIVACY RULES Presented by: Larry Grudzien, Attorney at Law.
School-Based Health Centers & Confidentiality: Understanding FERPA & HIPAA Laurie Mesibov & Jill Moore UNC School of Government December 2012.
HIPAA HIPAA Health Insurance Portability and Accountability Act of 1996.
Health Insurance Portability Accountability Act of 1996 HIPAA for Researchers: IRB Related Issues HSC USC IRB.
© 2004 Property Casualty Insurers Association of America The Alphabet of Federal Legislation Kathleen Jensen Property and Casualty Insurers Association.
What is FERPA? Family Educational Rights and Privacy Act.
2/16/2010 The Family Educational Records and Privacy Act.
HIPAA COMPLIANCE IN YOUR PRACTICE MARIBEL VALENTIN, ESQUIRE.
HIPAA Health Insurance Portability & Accountability Act of 1996.
HIPAA – Health Insurance Portability & Accountability Act and the Privacy Act MSgt Nechele M. Chambers Senior Enlisted Liaison TRICARE Area Office-Europe.
HIPAA Basic Training for Privacy and Information Security Vanderbilt University Medical Center VUMC HIPAA Website: HIPAA Basic.
Banks and the Privacy of Medical Information 8 th National HIPAA Summit March 8, 2004 Joy Pritts, JD Health Policy Institute Georgetown University
Electronic Records Management: What Management Needs to Know May 2009.
HIPAA PRIVACY AND SECURITY AWARENESS.
HIPAA The Privacy Rule Health Insurance Portability and Accountability Act of 1996 (HIPAA) The 104 th Congress passed the Act, Public Law ,
Privacy Issues in Healthcare Xintao Wu University of North Carolina at Charlotte Nov 1, 2012.
Computerized Networking of HIV Providers Workshop Data Security, Privacy and HIPAA: Focus on Privacy Joy L. Pritts, J.D. Assistant Research Professor Health.
Student Confidentiality: The FERPA/HIPAA Facts AISD Policy Student Records AISD Procedure AP. 11.
HIPAA Michigan Cancer Registrars Association 2005 Annual Educational Conference Sandy Routhier.
Family Educational Rights and Privacy Act (FERPA) UNION COLLEGE.
New Identity Theft Rules Rodney J. Petersen, J.D. Government Relations Officer Security Task Force Coordinator EDUCAUSE.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
Understanding HIPAA (Health Insurandce Portability and Accountability Act)
© 2013 The McGraw-Hill Companies, Inc. All rights reserved. Ch 8 Privacy Law and HIPAA.
FleetBoston Financial HIPAA Privacy Compliance Agnes Bundy Scanlan Managing Director and Chief Privacy Officer FleetBoston Financial.
HIPAA THE PRIVACY RULE. 2 HISTORY In 2000, many patients that were newly diagnosed with depression received free samples of anti- depressant medications.
STANFORD UNIVERSITY INFORMATION TECHNOLOGY SERVICES 1 The Technical Services Stuff in IT Services A brief tour of the technical and service offering plethora.
Approved for Public Release. Distribution Unlimited. 1 Government Privacy Rick Newbold, JD, MBA, CIPP/G Futures Branch 28.
Copyright © 2015 by Saunders, an imprint of Elsevier Inc. All rights reserved. Chapter 3 Privacy, Confidentiality, and Security.
HIPAA Vs. Family Educational Rights and Privacy Act (FERPA) How do these laws impact Educational Settings?
HIPAA Overview Why do we need a federal rule on privacy? Privacy is a fundamental right Privacy can be defined as the ability of the individual to determine.
Safeguarding Sensitive Information. Agenda Overview Why are we here? Roles and responsibilities Information Security Guidelines Our Obligation Has This.
Legal, Regulations, Investigations, and Compliance Chapter 9 Part 2 Pages 1006 to 1022.
Copyright © 2012, Big I Advantage®, Inc., and Swiss Re Corporate Solutions. All rights reserved. (Ed. 08/12 -1) E&O RISK MANAGEMENT: MEETING THE CHALLENGE.
Table of Contents. Lessons 1. Introduction to HIPAA Go Go 2. The Privacy Rule Go Go.
The Health Insurance Portability and Accountability Act of 1996 “HIPAA” Public Law
Taylor County Schools FERPA (Confidentiality) Training August 17, 2010.
The Medical College of Georgia HIPAA Privacy Rule Orientation.
New Hire HIPAA Orientation. HIPAA Overview HIPAA is an acronym that stands for the Health Insurance Portability and Accountability Act of HIPAA.
The Health Insurance Portability and Accountability Act (HIPAA) requires Plumas County to train all employees in covered departments about the County’s.
1 HIPAA’s Impact on Depository Financial Institutions 2 nd National Medical Banking Institute Rick Morrison, CEO Remettra, Inc.
HIPAA Privacy Rule Training
Federal Agencies and Laws for Consumer Rights
What is HIPAA? HIPAA stands for “Health Insurance Portability & Accountability Act” It was an Act of Congress passed into law in HEALTH INSURANCE.
Privacy principles Individual written policies
Student Confidentiality: The FERPA/HIPAA Facts
E&O Risk Management: Meeting the Challenge of Change
Disability Services Agencies Briefing On HIPAA
Current Privacy Issues That May Affect Your Credit Union
Health Care: Privacy in a Digital Age
UCA Gramm-Leach Bliley Act (GLBA) Safeguards Rule Compliance Training Effective June 12, 2018 Adapted from materials published by the Federal Trade Commission.
Student Confidentiality: The FERPA/HIPAA Facts
Presentation transcript:

Privacy Laws & Higher Education

Agenda 1.Five Privacy Laws a.FERPA b.HIPAA c.GLB d.FACTA Disposal Rule e.CAN-SPAM 2.Overview of the Laws a.What does the law protect? b.Who does the law apply to? c.Where are potential risk areas at UW? d.What does the law require? 3.Privacy Laws & Audits 4.References/Questions

FERPA Family Educational Rights & Privacy Act  Law:  Protects student educational records, including documents that contain information directly related to the student  Includes records maintained by the University or a person/entity acting on its behalf.  Educational institutions may not release educational records without the student’s consent. This includes prospective employers, government agencies, credit bureaus and others.  Exception: Student Directory Information  Applies to: Educational institutions

FERPA Family Educational Rights & Privacy Act  Potential Risk Areas at UW:  Registrars’ Offices;  Admissions’ Offices;  Financial Aid Offices;  Deans’ Offices;  Hall Health;  Sports Medicine Clinic;  Others  Requires: Students’ Consent Annual Publication of FERPA Policy Complaint Process School Directory Opt-out Provision

HIPAA Health Insurance Portability & Accountability Act  Law:  Protects privacy & security of personally identifiable health information.  Privacy Rule: Pertains to Oral, Paper & Electronic Information  Security Rule: Pertains to Only Electronic Information  Limits use & disclosure of health information to treatment, payment & healthcare operations.  FERPA Exception  Applies to:  Health care providers,  Health care plans, and  Health care clearinghouses

HIPAA Health Insurance Portability & Accountability Act  Potential Risk Areas at UW:  HMC, UWMC  UWP, CUMG  Dental Clinics  Hall Health Services; Sports Medicine Clinic  UW Group Health Plans (Plan Administration) Note: HIPAA may also impact research with human subjects, SOM Library, some development activities  Requires: Administrative Safeguards Privacy Officer Privacy Notice Amendment of Plans Policies & Procedures Training Business Associate Agreements Complaint Process

GLBA: Gramm Leach Bliley Act  Law:  Protects privacy & security of personally identifiable, non-public, financial information.  Privacy provision has a FERPA exception, but safeguards rule does not.  Applies to:  Businesses that provide financial services or products  Examples: Brokering or servicing loans, Transferring or safeguarding money, Providing financial advice, Collecting consumer debt

GLBA: Gramm Leach Bliley Act  Potential Risk Areas at UW:  Central Administration:  Financial: Student Financial Services  Administration: Huskies Card  Development: Planned Giving  Schools:  Financial Aid Offices  Deans Emergency Loans  Pro Bono Tax Program  Requires: Oversight Risk Assessment Written Safeguards Program Monitoring of Safeguards Contract Provisions with Service Providers

FACTA: Disposal Rule Fair & Accurate Credit Transactions Act  Law:  Ensures proper disposal of confidential, personally identifiable, financial reports.  Applies to:  Individuals & companies that obtain consumer reports, including credit reports & other information related to employment background checks  Includes employers, lenders, insurers, mortgage brokers, debt collectors.

FACTA: Disposal Rule Fair & Accurate Credit Transactions Act  Potential Risk Areas at UW:  Office of Human Resources  Other departments responsible for conducting background checks, such as Finance.  Possibly Student Financial Services and Student Financial Aid  Requires: Reasonable disposal policies & practices Due diligence in selecting of a disposal company’s operations

CAN-SPAM Controlling the Assault of Non-Solicited Pornography & Marketing Act  Law:  Protects communications from SPAM (non-solicited pornography & marketing materials)  Applies to:  Commercial communications  Includes any message where the primary purpose is to promote a product or service  Also includes any message that promotes content on a Website operated for a commercial purpose.

CAN-SPAM Controlling the Assault of Non-Solicited Pornography & Marketing Act  Potential Risk Areas at UW: Revenue generating centers or operations Commerce related activities Hosted programs Advertisements or promotions of product or service Examples:  Products offered by UW to 3 rd parties  Trips organized by a UW office  Tickets for sporting or cultural events  Subscriptions to journals, magazines or newsletters  Requires: Valid return address Mechanism for recipients to opt-out Notice that is an advertisement or solicitation Valid physical postal address of sender No false or misleading transmission information

Privacy Laws & Audit Services Privacy Compliance & Audit Services: Include Privacy Laws in Operational Self Assessment Consider Types of Information in Scoping Process Health Information (HIPAA) Financial Information (GLB) Credit Information (FACTA Disposal Rule) Student Information (FERPA) (CAN SPAM) Develop Audit Programs Refer to legal requirements for appropriate internal controls Refer to University policies, which may be more stringent than the law Educate & Counsel Clients

References  HHS Website:  HIPAA  FTC Website:  GLB  FACTA Disposal Rule  CAN-SPAM  DOE Website:  FERPA  UW Websites  Privacy Law.Net