HIPAA Privacy Keys to Success Education for Nursing and all other Clinical Students Effective January 2010 HIPAA Job Specific Education1.

Slides:



Advertisements
Similar presentations
Independent Contractor Orientation HIPAA What Is HIPAA? Health Insurance Portability and Accountability Act of 1996 The Health Insurance Portability.
Advertisements

HIPAA/HITECH Training (Clinical Non - Patient Care Areas)
HIPAA Privacy Training. 2 HIPAA Background Health Insurance Portability and Accountability Act of 1996 Copyright 2010 MHM Resources LLC.
Health Insurance Portability and Accountability Act HIPAA Education for Volunteers and Students.
HIPAA. What Why Who How When What Is HIPAA? Health Insurance Portability & Accountability Act of 1996.
HIPAA Privacy Keys to Success Education for Health Care Professionals.
HIPAA Basic Training for Privacy & Information Security Vanderbilt University Medical Center VUMC HIPAA Website:
COBB/DOUGLAS COMMUNITY SERVICES BOARD Confidentiality and Privacy of Consumer Information.
The Health Insurance Portability and Accountability Act Basic HIPAA Training For CMU workforce with access to PHI.
HIPAA Job Specific Education1 HIPAA Privacy Keys to Success Updated January 2010.
HIPAA – Privacy Rule and Research USCRF Research Educational Series March 19, 2003.
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
HIPAA PRIVACY REQUIREMENTS Dana L. Thrasher Constangy, Brooks & Smith, LLC (205) ; Victoria Nemerson.
WORKFORCE CONFIDENTIALITY HIPAA Reminders. HIPAA 101 The Health Insurance Portability and Accountability Act (HIPAA) protects patient privacy. HIPAA is.
HIPAA Health Insurance Portability and Accountability Act.
What is HIPAA? This presentation was created by The University of Arizona Privacy Office, The Office for the Responsible Conduct of Research on March 5,
1 HIPAA Education CCAC Professional Development Training September 2006 CCAC Professional Development Training September 2006.
NAU HIPAA Awareness Training
 Health Care Information Portability and Accountability Act  Passed in 1996  2 objectives 1) Ensure people could maintain health insurance between.
 The Health Insurance Portability and Accountability Act of  Federal Law designed to protect sensitive information.  HIPAA violations are enforced.
Health Insurance Portability & Accountability Act “HIPAA” To every patient, every time, we will provide the care that we would want for our own loved ones.
HIPAA Job Specific Education1 HIPAA Privacy Keys to Success Education for Students Updated February 2010.
HIPAA HIPAA Health Insurance Portability and Accountability Act of 1996.
Professional Nursing Services.  Privacy and Security Training explains:  The requirements of the federal HIPAA/HITEC regulations, state privacy laws.
HIPAA Training Presentation for New Employees How did we get here? HIPAA Police 1.
HIPAA COMPLIANCE IN YOUR PRACTICE MARIBEL VALENTIN, ESQUIRE.
HIPAA Health Insurance Portability & Accountability Act of 1996.
Columbia University Medical Center Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) Privacy & Information Security Training 2009.
Protected Health Information (PHI). Privileged Communication An exchange of information between two individuals in a confidential relationship. (Examples:
Paula Peyrani, MD Medical/Project Director, HIV Program at the 550 Clinic Assistant Director, Research Design and Development Clinical and Translational.
HIPAA PRIVACY AND SECURITY AWARENESS.
1 Research & Accounting for Disclosures March 12, 2008 Leslie J. Pfeffer, BS, CHP Office of the Vice President for Research Administration Office of Compliance.
HIPAA OBJECTIVES  Define HIPAA  Define PHI  Use of PHI  Your rights  Your responsibilities.
1 HIPAA OVERVIEW ETSU. 2 What is HIPAA? Health Insurance Portability and Accountability Act.
Health Insurance Portability and Accountability Act (HIPAA)
HIPAA Training Developed for Ridgeview Institute 2012 Hospital Wide Orientation.
HIPAA Michigan Cancer Registrars Association 2005 Annual Educational Conference Sandy Routhier.
© 2009 The McGraw-Hill Companies, Inc. All rights reserved. 1 McGraw-Hill Chapter 2 The HIPAA Privacy Standards HIPAA for Allied Health Careers.
Building a Privacy Foundation. Setting the Standard for Privacy Health Insurance Portability and Accountability Act (HIPAA) Patient Bill of Rights Federal.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
Understanding HIPAA (Health Insurandce Portability and Accountability Act)
HIPAA BASIC TRAINING Presented by Anderson Health Information Systems, Inc.
Copyright ©2014 by Saunders, an imprint of Elsevier Inc. All rights reserved 1 Chapter 02 Compliance, Privacy, Fraud, and Abuse in Insurance Billing Insurance.
HIPAA Health Insurance Portability and Accountability Act of 1996.
Top 10 Series Changes to HIPAA Devon Bernard AOPA Reimbursement Services Coordinator.
Configuring Electronic Health Records Privacy and Security in the US Lecture b This material (Comp11_Unit7b) was developed by Oregon Health & Science University.
Medical Documentation
HIPAA Overview Why do we need a federal rule on privacy? Privacy is a fundamental right Privacy can be defined as the ability of the individual to determine.
HIPAA HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT UI EMS Training Dept.
 Health Insurance and Accountability Act Cornelius Villalon Jr.
The Medical College of Georgia HIPAA Privacy Rule Orientation.
Health Insurance Portability and Accountability Act (HIPAA) Primer for Observers, Volunteers, Medical Students Dr. Michael Palumbo- Privacy Officer/ EVP.
Developed for Ridgeview Institute 2015 Hospital Wide Orientation
HIPAA PRIVACY & SECURITY TRAINING
HIPAA THE PRIVACY RULE Reviewed December 2012.
HIPAA Privacy & Security
What is HIPAA? HIPAA stands for “Health Insurance Portability & Accountability Act” It was an Act of Congress passed into law in HEALTH INSURANCE.
HIPAA/HITECH Training Administrative Staff
HIPAA/HITECH Training
HIPAA/HITECH Training
HIPAA PRIVACY AWARENESS, COMPLIANCE and ENFORCEMENT
Disability Services Agencies Briefing On HIPAA
Safety and Security of Electronic Health Records
The Health Insurance Portability and Accountability Act
HIPAA Privacy & Security
The Health Insurance Portability and Accountability Act
HIPAA & PHI TRAINING & AWARENESS
The Health Insurance Portability and Accountability Act
The Health Insurance Portability and Accountability Act
Presentation transcript:

HIPAA Privacy Keys to Success Education for Nursing and all other Clinical Students Effective January 2010 HIPAA Job Specific Education1

HIPAA and Its Purpose What is HIPAA?  Health Insurance Portability and Accountability Act of 1996  Title II – Administrative Simplification  It’s a federal law  HIPAA is mandatory, penalties for failure to comply Purpose:  Protect health insurance coverage, improve access to healthcare  Reduce fraud and abuse  Improve quality of healthcare in general  Reduce healthcare administrative costs (electronic transactions) HIPAA Job Specific Education2

HITECH and Its Purpose What is HITECH?  Health Information Technology for Economic and Clinical Health Act  Subtitle D of the American Recovery and Reinvestment Act of 2009 (ARRA)  It’s a federal law Purpose:  Makes massive changes to privacy and security laws  Applies to covered entities and business associates  Creates a nationwide electronic health record  Increases penalties for privacy and security violations HIPAA Job Specific Education3

Key HITECH Changes ◦Breach Notification requirements ◦AOD for treatment, payment, and healthcare operations in electronic health record (EHR) environment ◦Business Associate Agreements ◦Restrictions ◦Right to access ◦Criminal provisions ◦Penalties ◦OCR Privacy Audits ◦Copy charges for providing copies from EHR ◦HIPAA preemption applies to new provisions ◦Private cause of action ◦Sharing of civil monetary penalties with harmed individuals HIPAA Job Specific Education4

Civil Penalties for Non-compliance* HIPAA Job Specific Education5 Violation CategoryEach ViolationAll such violations of an identical provision in a calendar year Did Not Know$100 - $50,000$1,500,000 Reasonable Cause$1,000 – $50,000$1,500,000 Willful Neglect – Corrected$10,000 - $50,000$1,500,000 Willful Neglect – Not Corrected $50,000$1,500,000 *As of 2/17/10

Criminal Penalties for Non-compliance For health plans, providers, clearinghouses and business associates that knowingly and improperly disclose information or obtain information under false pretenses. These penalties can apply to any “person”.  Penalties higher for actions designed to generate monetary gain  up to $50,000 and one year in prison for obtaining or disclosing protected health information  up to $100,000 and up to five years in prison for obtaining protected health information under "false pretenses"  up to $250,000 and up to 10 years in prison for obtaining or disclosing protected health information with the intent to sell, transfer or use it for commercial advantage, personal gain or malicious harm HIPAA Job Specific Education6

Facility Privacy Official (FPO) Your FPO is: Susan Armstrong, HIM Director Responsible for: ◦Implementation of Privacy and Information Security Program ◦Privacy Rights of patients ◦Requests for Privacy Restrictions ◦Facilitating the training and education of workforce members HIPAA Job Specific Education7

HIPAA Terminology HITECH: Health Information Technology for Economic and Clinical Health Act HIPAA: Health Insurance Portability and Accountability Act PHI: Protected Health Information CE: Covered Entity (Hospital) OHCA: Organized Health Care Arrangement (The hospital and medical staff will be considered an Organized Health Care Arrangement) DRS: Designated Record Set (medical record and billing record) Directory: Hospital census list used by volunteers and operators with name and room TPO: Treatment, Payment and Healthcare Operations HIPAA Job Specific Education8

What is Protected by HIPAA (PHI)? Name Address including street, city, county, zip code and equivalent geocodes Names of relatives Name of employers Birth date Telephone numbers Fax Numbers Electronic addresses Social Security Number Medical record number Health plan beneficiary number Account number Certificate/license number Any vehicle or other device serial number Web Universal Resource Locator (URL) Internet Protocol (IP) address number Finger or voice prints Photographic images Any other unique identifying number, characteristic, code HIPAA Job Specific Education9

How will HIPAA affect you? Coversheets with confidential statement need to be used on all external faxes. Patient charts will need to be placed in secure area PHI will need to be placed in Cintas Shred containers for disposal Unless specifically authorized by the patient, patient family members should only be told the basic condition and location Patient information should only be accessed if there is a need to know Never discuss patient care in front of visitors– politely ask the visitors to step out for a moment – if the patient states they can stay be sure to document this in the chart. HIPAA Job Specific Education10

How will HIPAA affect you? Do not write down any names or identifiable patient information in your student notes – if in doubt check with your instructor Patient charts need to be placed in secure areas PHI will need to be placed in Cintas Shred containers for disposal – NOT IN TRASH CANS Patient information should only be accessed if there is a need to know Patients have a right to a copy of their medical record but they must go to medical records and sign a release and only after the chart is completed after discharge HIPAA Job Specific Education11

Patient Privacy Complaints FPO must maintain complaint log in accordance with the complaint process ALL privacy complaints must be routed to the FPO Responses cannot be accompanied by retaliatory actions by the hospital Disposition of complaint must be consistent with the facility’s Sanctions for Privacy Violations HIPAA Job Specific Education12

Notice of Privacy Practices Patient will receive a Notice upon each registration The Notice outlines patient’s privacy rights as: ◦Right to access your PHI ◦Right to amend (append or add to) your PHI – if you disagree with the information ◦Confidential Communication-alternative means or to an alternative location ◦Right to Privacy Restriction-use or disclosures of your PHI ◦Right to Opt out of Directory-no disclosure of patient’s name, location, condition of patient, or religious affiliation ◦Right to an accounting for disclosures – where your information went without your authorization HIPAA Job Specific Education13

Breach Notification HITECH provisions require the following notifications when breaches (as defined in the regulations) occur: ◦To the patient ◦To the Department of Health and Human Services ◦To the media when the breach involves more than 500 individuals in the same state or jurisdiction HIPAA Job Specific Education14

Ensuring Security Compliance Ensure users log off computer systems and medical devices when not in use. PC’s should have screen savers whenever possible. Computer screens should be positioned so information (PHI) is not readable by the public or other unauthorized viewers Printers should be positioned in protected locations so that printed information is not accessible or viewable by an unauthorized person. PHI must be properly disposed. HIPAA Job Specific Education15

Common Exposures Discussions of patient information in public places such as hallways and cafeterias Printed or electronic information left in public view (e.g., charts left on counters) Discussing patient information on social networking sites (e.g., Facebook, Twitter) PHI in regular trash Records that are accessed without need to know in order to perform job duties Unauthorized individuals hearing patient sensitive information such as diagnosis or treatment HIPAA Job Specific Education16