HIPAA How It Is Affecting Information Systems Within Companies Around Us.

Slides:



Advertisements
Similar presentations
H = P = A = HIPAA DEFINED HIPAA … A Federal Law Created in 1996 Health
Advertisements

Todd Frech Ocius Medical Informatics 6650 Rivers Ave, Suite 137 North Charleston, SC Health Insurance Portability.
HIPAA: An Overview of Transaction, Privacy and Security Regulations Training for Providers and Staff.
1 The Health Insurance Portability and Accountability Act (HIPAA) A guided tutorial for GVSU employees.
Health Insurance Portability and Accountability Act HIPAA Education for Volunteers and Students.
HIPAA. What Why Who How When What Is HIPAA? Health Insurance Portability & Accountability Act of 1996.
Confidentiality and HIPAA
HIPAA Privacy Rule Training
National Health Information Privacy and Security Week Understanding the HIPAA Privacy and Security Rule.
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
HIPAA PRIVACY REQUIREMENTS Dana L. Thrasher Constangy, Brooks & Smith, LLC (205) ; Victoria Nemerson.
HIPAA Health Insurance Portability and Accountability Act.
What is HIPAA? This presentation was created by The University of Arizona Privacy Office, The Office for the Responsible Conduct of Research on March 5,
Health Insurance Portability and Accountability Act (HIPAA)HIPAA.
1 HIPAA Education CCAC Professional Development Training September 2006 CCAC Professional Development Training September 2006.
NAU HIPAA Awareness Training
HIPAA TRAINING to satisfy the training requirement for School District # 435 Staff.
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996 (HIPAA)
Topics Rule Changes Skagit County, WA HIPAA Magic Bullet HIPAA Culture of Compliance Foundation to HIPAA Privacy and Security Compliance Security Officer.
HIPAA Privacy Rule Compliance Training for YSU April 9, 2014.
© 2011 The McGraw-Hill Companies, Inc. All rights reserved. 2.5 HIPAA Legislation and its Impact on Physician Practices 2-15 The Health Insurance Portability.
Are you ready for HIPPO??? Welcome to HIPAA
HIPAA HIPAA Health Insurance Portability and Accountability Act of 1996.
HIPAA COMPLIANCE IN YOUR PRACTICE MARIBEL VALENTIN, ESQUIRE.
HIPAA Health Insurance Portability & Accountability Act of 1996.
The University of Kansas Medical Center Shadow Experience Training.
Copyright © 2005 Thomson Delmar Learning. ALL RIGHTS RESERVED.1 This product was funded by a grant awarded under the President’s Community-Based Job Training.
“ Technology Working For People” Intro to HIPAA and Small Practice Implementation.
HIPAA The Privacy Rule Health Insurance Portability and Accountability Act of 1996 (HIPAA) The 104 th Congress passed the Act, Public Law ,
1 Disclosures © HIPAA Pros 2002 All rights reserved.
HIPAA OBJECTIVES  Define HIPAA  Define PHI  Use of PHI  Your rights  Your responsibilities.
1 Secure Commonwealth Panel Health and Medical Subpanel Debbie Condrey - Chief Information Officer Virginia Department of Health December 16, 2013 Virginia.
HIPAA Michigan Cancer Registrars Association 2005 Annual Educational Conference Sandy Routhier.
Component 16-Professionalism/Customer Service in the Health Environment Unit 5-Regulatory Issues: HIPAA and Standard Precautions This material was developed.
Medical Law and Ethics, Third Edition Bonnie F. Fremgen Copyright ©2009 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved.
Speak HIPAA Like a Native A Guide to Common HIPAA Nomenclature University of Miami Ethics Programs.
Building a Privacy Foundation. Setting the Standard for Privacy Health Insurance Portability and Accountability Act (HIPAA) Patient Bill of Rights Federal.
LeToia Crozier, Esq., CHC Vice President, Compliance & Regulatory Affairs Corey Wilson Director of Technical Services & Security Officer Interactive Think.
Securing Patient-Related Data: The Impact of HIPAA Module VI NUR 603 Russ McGuire.
Health Insurance Portability and Accountability Act (HIPAA) CCAC.
Understanding HIPAA (Health Insurandce Portability and Accountability Act)
© 2013 The McGraw-Hill Companies, Inc. All rights reserved. Ch 8 Privacy Law and HIPAA.
HIPAA BASIC TRAINING Presented by Anderson Health Information Systems, Inc.
HIPAA BASIC TRAINING MODULE 1C – Overview (For staff who do not generally create Protected Health Information) Anderson Health Information Systems, Inc.
Working with HIT Systems
Copyright ©2014 by Saunders, an imprint of Elsevier Inc. All rights reserved 1 Chapter 02 Compliance, Privacy, Fraud, and Abuse in Insurance Billing Insurance.
HIPAA Health Insurance Portability and Accountability Act of 1996.
Copyright © 2015 by Saunders, an imprint of Elsevier Inc. All rights reserved. Chapter 3 Privacy, Confidentiality, and Security.
HIPAA Overview Why do we need a federal rule on privacy? Privacy is a fundamental right Privacy can be defined as the ability of the individual to determine.
Human Subjects Update E. Wethington, Chair, UCHS.
Table of Contents. Lessons 1. Introduction to HIPAA Go Go 2. The Privacy Rule Go Go.
The Health Insurance Portability and Accountability Act of 1996 “HIPAA” Public Law
The Medical College of Georgia HIPAA Privacy Rule Orientation.
What is HIPAA? Health Insurance Portability and Accountability Act of HIPAA is a major law primarily concentrating on the prolongation of health.
The Health Insurance Portability and Accountability Act (HIPAA) requires Plumas County to train all employees in covered departments about the County’s.
BlueCross BlueShield of Tennessee, Inc., an Independent Licensee of the BlueCross BlueShield Association. This document has been classified as public Information.
Public Health IT Privacy, Confidentiality and Security of Public Health Information This material (Comp13_Unit2) was developed Columbia University, funded.
HIPAA Privacy Rule Training
What is HIPAA? HIPAA stands for “Health Insurance Portability & Accountability Act” It was an Act of Congress passed into law in HEALTH INSURANCE.
By: Eamon Callahan and Wilston Johnston
HIPAA Pros - Disclosures
HIPAA PRIVACY AWARENESS, COMPLIANCE and ENFORCEMENT
Disability Services Agencies Briefing On HIPAA
County HIPAA Review All Rights Reserved 2002.
HIPAA Privacy and Security Summit 2018 HIPAA Privacy Rule: Compliance Plans, Training, Internal Audits and Patient Rights Widener University Delaware.
Lesson 1  7 Basic Components of an Effective Compliance Plan
HIPAA SECURITY RULE Copyright © 2008, 2006, 2004 by Saunders an imprint of Elsevier Inc. All rights reserved.
Enforcement and Policy Challenges in Health Information Privacy
The Health Insurance Portability and Accountability Act
Presentation transcript:

HIPAA How It Is Affecting Information Systems Within Companies Around Us

Team Lexi Marlene Reischman Marlene Reischman Denise Pope Denise Pope Johnny Lepschat Johnny Lepschat Jared Cheney Jared Cheney William Paugh William Paugh

Why HIPAA Came About Define HIPAA Define HIPAA –Health Information Portability and Accountability Act (1996) –Healthcare related companies –Non-healthcare related companies

Steps To Compliance Does the Legislation Apply? Does the Legislation Apply? Appoint a “Privacy Official” Appoint a “Privacy Official” Privacy Policy Privacy Policy –Who –When –What –Why –How Instructions Instructions Verification Verification

Steps to Compliance, Cont. Training Training –Regulations –Documentation Process –Computers Procedures Procedures –Protected –Identifiable –IS department

Electronic Compliancy Constantly Changing Legislation Constantly Changing Legislation Modifications to Existing Systems Modifications to Existing Systems Systems Must: Systems Must: –Monitor and control access to protected information –Include security features such as passwords and regulated access –Have extra security and monitoring of electronic transfers of information to another entity –Have easy access to complete medical records at patient’s request –Be easy to upgrade

HIPAA Compliance Impact Impact on Becoming Compliant Impact on Becoming Compliant –Capital Outlay –Security Development –Departmental Changes

Capital Outlay Medium to Large Organizations Can Spend Tens of Thousands of Dollars This Year Medium to Large Organizations Can Spend Tens of Thousands of Dollars This Year Some Small Organizations Unable to Handle the Added Expense Some Small Organizations Unable to Handle the Added Expense Federal Aid Funding Stretched Thin Federal Aid Funding Stretched Thin

Penalties For Non Compliance $100 Per Offense $100 Per Offense $25,000 Maximum Penalty $25,000 Maximum Penalty If Misused With Intent, If Misused With Intent, –$50,000 to $250,000 Fine –1 to 10 Years in Prison

Security Development The Four Major Areas of Security Development The Four Major Areas of Security Development –Administrative Procedures –Physical Safeguards –Technical Security Services –Technical Security Mechanisms

Security Continued All Electronic Information Has to Be Secured in All of the Following Ways: All Electronic Information Has to Be Secured in All of the Following Ways: –Access –Transmission –Maintenance –Storage

Departmental Changes IT Challenges IT Challenges HR Restructuring HR Restructuring Other Departments Other Departments

IT Challenges Assess Needs Assess Needs Implement New Systems Implement New Systems Implement New Procedures Implement New Procedures Develop New Security Strategies Develop New Security Strategies

HR Restructuring Change in Database to Dissociate Name From Information Change in Database to Dissociate Name From Information Change in Forms Change in Forms Change in Information Gathering Process Change in Information Gathering Process Change in Staff Training Change in Staff Training

Other Departments New Procedures New Procedures –Require Training For Many Employees New Policies New Policies –Require Attention By All Employees

Real World Cases Bank Bank Rehab Facility Rehab Facility Other Organizations Other Organizations

Bank Hybrid Entity Hybrid Entity –Provides Medical Insurance –Provides Employee Assistance Program (EAP) Bank Requests Information (Insurance Company) Bank Requests Information (Insurance Company) –Formal Documentation Bank Provides Information (EAP) Bank Provides Information (EAP) –Requests Documentation

Rehab Facility Staff Training Staff Training Information System Security Information System Security Physical Security Physical Security New Policies and Procedures New Policies and Procedures

Other Organizations Healthcare Related Healthcare Related Non-Healthcare Related Non-Healthcare Related

HIPAA Privacy Rule and Public Health: Balancing Individual Needs with Those of Society U.S. Department of Health and Human Services: Office for Civil Rights has responsibility for enforcing the Privacy Rule U.S. Department of Health and Human Services: Office for Civil Rights has responsibility for enforcing the Privacy Rule Center for Disease Control and Severe Acute Respiratory Syndrome (SARS): When can information be released? Center for Disease Control and Severe Acute Respiratory Syndrome (SARS): When can information be released?

Protected Health Information (PHI) That Does Not Require Authorization Under the Privacy Rule: Reporting of disease, injury, and vital events Reporting of disease, injury, and vital events Conducting public health surveillance, investigations and interventions Conducting public health surveillance, investigations and interventions Report child abuse or neglect to public health Report child abuse or neglect to public health A person subject to jurisdiction of the Food and Drug Administration (FDA) A person subject to jurisdiction of the Food and Drug Administration (FDA)

PHI, Cont. Exposure to a communicable disease, or at risk for contracting or spreading a disease or condition Exposure to a communicable disease, or at risk for contracting or spreading a disease or condition An employer, as needed to meet the requirements of the Occupational Safety and Health Administration, Mine Safety and Health Administration, or a similar state law An employer, as needed to meet the requirements of the Occupational Safety and Health Administration, Mine Safety and Health Administration, or a similar state law Source: Adapted from [45CFR § (b)]

Questions to answer Are companies being successful at being compliant with HIPAA? Are companies being successful at being compliant with HIPAA? What emphasis changes may need to happen to push compliance? What emphasis changes may need to happen to push compliance? Is the goal of HIPAA being met? Is the goal of HIPAA being met?