HIPAA Update: So what’s new with HIPAA?? And, what does it have to do with you? Ellen Cannon, WV DHHR HIPAA Privacy Officer WV Attorney General’s Office.

Slides:



Advertisements
Similar presentations
HITECH ACT Privacy & Security Requirements Cathleen Casagrande Privacy Officer July 23, 2009.
Advertisements

“Reaching across Arizona to provide comprehensive quality health care for those in need” Our first care is your health care Arizona Health Care Cost Containment.
Presented by Elena Chan, UCSF Pharm.D. Candidate Tiffany Jew, USC Pharm.D. Candidate March 14, 2007 P HARMACEUTICAL C ONSULTANTS, I NC. P RO P HARMA HIPAA.
HIPAA Basics Brian Fleetham Dickinson Wright PLLC.
Steps to Compliance: Managing Business Associates PRESENTED BY.
HIPAA Basics November 1, 2014.
HIPAA Privacy Training. 2 HIPAA Background Health Insurance Portability and Accountability Act of 1996 Copyright 2010 MHM Resources LLC.
HIPAA Privacy Rule Training
Navigating HIPAA & Recent Healthcare Reform: What You Need to Know.
HIPAA What’s New? What Is HIPAA Health Insurance Portability and Accountability Act of 1996 Health Insurance Portability and Accountability Act.
Changes to HIPAA (as they pertain to records management) Health Information Technology for Economic Clinical Health Act (HITECH) – federal regulation included.
1 Navigating the Privacy and Security Issues: HITECH Overview Rebecca L. Williams, RN, JD Partner Co-chair of HIT/HIPAA Practice Davis Wright Tremaine.
Key Changes to HIPAA from the Stimulus Bill (ARRA) Children’s Health System Department Leadership Meeting October 28, 2009 Kathleen Street Privacy Officer/Risk.
HIPAA CHANGES: HITECH ACT AND BREACH NOTIFICATION RULES February 3, 2010 Kristen L. Gentry, Esq. Catherine M. Stowers, Esq.
 July 10, 2013 Richard D. Sanders T HE S ANDERS L AW F IRM, P.C. 7 Piedmont Center, Suite Piedmont Road Atlanta, Georgia (404)
Thank You For Your Participation Kansas City   Omaha  Overland Park St. Louis  Jefferson City This Employer.
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996 (HIPAA)
Topics Rule Changes Skagit County, WA HIPAA Magic Bullet HIPAA Culture of Compliance Foundation to HIPAA Privacy and Security Compliance Security Officer.
HIPAA Regulations What do you need to know?.
COMPLYING WITH HIPAA PRIVACY RULES Presented by: Larry Grudzien, Attorney at Law.
2014 HIPAA Refresher Omnibus Rule & HIPAA Security.
Jill Moore April 2013 HIPAA Update: New Rules, New Challenges.
What You Don’t Know Can Cost You HIPAA in a HITECH World Alaina N. Crislip, Esq. October 10, 2013.
Professional Nursing Services.  Privacy and Security Training explains:  The requirements of the federal HIPAA/HITEC regulations, state privacy laws.
Health IT Privacy and Security Policy Jodi Daniel, J.D., M.P.H. Director, Office of Policy and Research, Office of the National Coordinator for Health.
Health Insurance Portability & Accountability Act (HIPAA)
OCR HITECH Enforcement Tips: Prevent, Detect and Quickly Correct HIPAA COW 2010 Spring Conference Privacy/Security Session 1 HIPAA Privacy Best Practices:
March 19, 2009 Changes to HIPAA Privacy and Security Requirements Joel T. Kopperud Scott A. Sinder Rhonda M. Bolton.
Security Breach Notification © 2009 Fox Rothschild A Webinar for the Medical Society of New Jersey October 28, 2009 Presented by Helen Oscislawski, Esq.
Walking Through the Breach Notification Process - Beginning to End HIPAA COW Presentation and Panel April 8, 2011.
© Copyright 2014 Saul Ewing LLP The Coalition for Academic Scientific Computation HIPAA Legal Framework and Breach Analysis Presented by: Bruce D. Armon,
HIPAA COMPLIANCE IN YOUR PRACTICE MARIBEL VALENTIN, ESQUIRE.
Implementing and Enforcing the HIPAA Privacy Rule.
Office of the Secretary Office for Civil Rights (OCR) HIPAA Privacy and Security Rules Updates HIPAA COW 2010 Spring Conference April 16, 2010.
Health Information Technology for Economic and Clinical Health Act (HITECH)
HIPAA PRIVACY AND SECURITY AWARENESS.
California :: Delaware :: Florida :: New Jersey :: New York :: Pennsylvania :: Virginia :: Washington, D.C. :: 1 NEW OBLIGATIONS.
HIPAA and HITECH The Latest Developments Presented By: Michele Madison Partner, Healthcare Practice Morris, Manning & Martin, LLP
Quality Integrity Stewardship Courtesy Care Accountability Medical Records ARMA Florida Gulf Coast Chapter Michael Spake Lakeland Regional Medical Center.
LAW SEMINARS INTERNATIONAL CLOUD COMPUTING: LAW, RISKS AND OPPORTUNITIES Developing Effective Strategies for Compliance With the HITECH Act and HIPAA’s.
Update on Federal HIT Legislation Kirsten Beronio Mental Health America.
HITECH Act and HIPAA: Important Compliance Update Susan E. Ziel Gerald “Jud” DeLoss.
David G. Schoolcraft Ogden Murphy Wallace, PLLC
HIPAA Michigan Cancer Registrars Association 2005 Annual Educational Conference Sandy Routhier.
Office of the Secretary Office for Civil Rights (OCR) The HITECH NPRM: Overview of Research Comments October 19, 2010 Christina Heide, JD HHS Office for.
Privacy and Security Risks to Rural Hospitals John Hoyt, Partner December 6, 2013.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
HIPAA BASIC TRAINING Presented by Anderson Health Information Systems, Inc.
HIPAA PRACTICAL APPLICATION WORKSHOP Orientation Module 1B Anderson Health Information Systems, Inc.
The American Recovery and Reinvestment Act of 2009: Changes to HIPAA Privacy and Security Requirements And its Impact on Hospitals Presented By: Michele.
Configuring Electronic Health Records Privacy and Security in the US Lecture c This material (Comp11_Unit7c) was developed by Oregon Health & Science University.
HealthBridge is one of the nation’s largest and most successful health information exchange organizations. Tri-State REC: Privacy and Security Issues for.
Rhonda Anderson, RHIA, President  …is a PROCESS, not a PROJECT 2.
HITECH and HIPAA Presented by Rhonda Anderson, RHIA Anderson Health Information Systems, Inc
1 Changes to Privacy Regulations under ARRA May 4, 2009 Melissa Goldstein, J.D. The George Washington University School of Public Health and Health Services.
Top 10 Series Changes to HIPAA Devon Bernard AOPA Reimbursement Services Coordinator.
Finally, the Final HIPAA/HITECH Regulations are Here! By LYNDA M. JOHNSON Friday, Eldredge & Clark.
HIPAA: Breach Notification By: Office of University Counsel For: Jefferson IRB Continuing Education September 2014.
HIPAA Privacy Rule Positive Changes Affecting Hospitals’ Implementation of the Rule.
AND CE-Prof, Inc. January 28, 2011 The Greater Chicago Dental Academy 1 Copyright CE-Prof, Inc
1 Kansas Health Solutions July 9, 2009 HIPAA Goes HITECH Martie Ross Lathrop & Gage LLP (913)
 Health Insurance and Accountability Act Cornelius Villalon Jr.
HIPAA TRIVIA Do you know HIPAA?. HIPAA was created by?  The Affordable Care Act  Health Insurance companies  United States Congress  United States.
HIPAA: So You Think You’re Compliant September 1, 2011 Carolyn Heyman-Layne, J.D.
PHI Breach PHI Breach Dealing Breach With HIPAA Guidelines Guidelines.
HIPAA Administrative Simplification
HIPAA PRIVACY AWARENESS, COMPLIANCE and ENFORCEMENT
Disability Services Agencies Briefing On HIPAA
HITECH’s Impact on Research
Objectives Describe the purposes of the Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009 Explore how the HITECH Act.
Presentation transcript:

HIPAA Update: So what’s new with HIPAA?? And, what does it have to do with you? Ellen Cannon, WV DHHR HIPAA Privacy Officer WV Attorney General’s Office Consumer Protection Division

Show me the money! $2B to ONC $17.2B for EHR incentives through Medicare/Medicaid $4.7B for Nat’l Telecommunications and Information Administration’s Broadband Technology Opportunities Program $2.5B for USDA’s Distance Learning, Telemedicine and Broadband Program

Even More Money! $1.5B for health centers from HRSA $1.1B for Comparative effectiveness research within AHRQ, NIH and HHS $85M for Health IT within Indian Health Svs $500M for SSA $50M for IT within the VA

New HIPAA Provisions Major impact on HIPAA Business Associates New breach notification requirements Greater patient and consumer rights More aggressive enforcement Note: most provisions effective February 2010

When you leave here, will you know all of the new HIPAA Requirements? NO! Do you have 5 hours?? HHS is still in interpretive process Guidance and regs are forthcoming

New HIPAA Business Associate Requirements Feds have increased control over BAs (vendors to HIPAA covered entities, such as a billing company) Civil and criminal penalties now apply directly Makes certain HIPAA privacy and security regs apply directly to BAs Makes clear that PHR and HIE vendors are BAs Requires BA to notify covered entity of a breach, without unreasonable delay, but no longer than 60 days

New Breach Notification Requirements for Covered Entities and PHRs Must notify impacted individuals without unreasonable delay, but no longer than 60 days If more than 500 individuals are impacted, the Secretary of HHS and media must be given notice. If less than 500, annual reports must be made to HHS HHS will “out” those involved in breaches >500 on a website and to notify Congress New breach notification requirements for PHRs

New Consumer Rights Covered entities, such as a primary care center, hospital, physician or health plan, will need to be able to restrict disclosure of health information for payment or operations, if a consumer requests the restriction and pays out of pocket. For many medical care providers this one may be difficult. Coding may be needed to prevent billing information from going to insurance plans

New Consumer Rights Cont’d For covered entities that have an EHR, they, or their vendor will need to respond to a consumer’s request for an accounting of all disclosures for TPO for 3 years prior. For entities with EHR prior to January 2009, applies to disclosures after January Regulations interpret EHRs to be more than physician records.

New Consumer Rights Cont’d For covered entities that have an EHR, they will also have to provide an individual with a copy of their health information in electronic format, upon request OCR will develop national and regional initiatives to support consumer education around privacy and security requirements and uses of health information

New Requirements Prohibits a covered entity or business associate from receiving remuneration in exchange for PHI, without individual authorization. Exceptions: public health, research, treatment, sale of a business, BA activities, individual access, etc. New restrictions around marketing and fundraising. Targets communications paid by 3d parties, such as from drug companies. OCR will issue new guidance regarding limitation of uses, disclosures and requests for PHI to a limited data set, or if necessary, to the minimum necessary information. Existing exceptions still in force.

Enforcement Changes Individuals can be prosecuted for criminal violations Creates 4 tiers of violations: from where an individual did not know, to willful neglect not corrected Penalties range from $100 to $50K+. Limit of $1.5M State AG can now bring suit HHS will develop a process to share money penalties or settlements with harmed individuals Periodic audits of covered entities and BAs by HHS

Covered Entities Should Develop an Action Plan Conduct self assessment about new requirements Update risk assessment Update policies and procedures; revise breach reporting and notification procedures Evaluate impact of HHS guidance re encryption, etc. and determine how PHI will be secured Update business associate agreements Conduct staff training

Enforcement Changes Four categories of violations - increasing levels of culpability; Four corresponding tiers of penalty amounts that significantly increase the minimum penalty amount for each violation; and A maximum penalty amount of $1.5 million for all violations of an identical provision. Striking the previous bar on the imposition of penalties if the covered entity did not know and with the exercise of reasonable diligence would not have known of the violation (such violations are now punishable under the lowest tier of penalties); and Prohibition on the imposition of penalties for any violation that is corrected within a 30-day time period, as long as the violation was not due to willful neglect. All of the above effective on February 18, 2009

Civil Monetary Penalties The CMP are significantly increased. From $100 for each violation to $1,000 per violation for a violation due to "reasonable cause and not to willful neglect" (with a maximum penalty of $100,000); $10,000 for each violation that was due to willful neglect and is corrected (subject to a $250,000 maximum penalty); and $50,000 for each violation if the violation is not corrected properly (subject to a maximum penalty of $1,500,000 during a calendar year).

HITECH Act Rulemaking and Implementation Update 3/15/10 urb.htmlhttp:// urb.html OCR will implement important privacy and security provisions of the Health Information Technology for Economic and Clinical Health (HITECH) Act through notice and comment rulemaking, as required by the Administrative Procedure Act. These provisions include: business associate liability; new limitations on the sale of protected health information, marketing, and fundraising communications; and stronger individual rights to access electronic medical records and restrict the disclosure of certain information. OCR continues work on a Notice of Proposed Rulemaking (NPRM) regarding these provisions. Although the effective date (February 17, 2010) for many of these HITECH Act provisions has passed, the NPRM and the final rule that follows will provide specific information regarding the expected date of compliance and enforcement of these new requirements.

HITECH Act Rulemaking and Implementation Update 3/15/10 (Cont.) However, interim final rules implementing HITECH Act provisions in two areas have already been issued and are currently in effect: enforcement and breach notification. New civil money penalty amounts apply to HIPAA Privacy and Security Rule violations occurring after February 17, Covered entities and business associates must comply now with breach notification obligations for breaches that are discovered on or after September 23, OCR announced previously that it would use its enforcement discretion not to impose fiscal sanctions with regard to breaches discovered before February 22, Since that date has passed, OCR will enforce the Breach Notification Interim Final Rule, including with the possible imposition of sanctions, as it does with the HIPAA Privacy and Security Rule requirements.

Breach Notification Rules have been published A breach is, generally, an impermissible use or disclosure under the Privacy Rule that compromises the security or privacy of the protected health information such that the use or disclosure poses a significant risk of financial, reputational, or other harm to the affected individual. OCR Breach Notification web site ive/breachnotificationrule/index.htmlOCR Breach Notification web site ive/breachnotificationrule/index.html

Breach Does Not Mean unintentional acquisition, access, or use of protected health information by an employee or individual acting under the authority of a covered entity or business associate if such acquisition, access, or use was made in good faith and within the course and scope of the employment or other professional relationship of such employee or individual, respectively, with the covered entity or business associate; and such information is not further acquired, accessed, used, or disclosed by any person;

Breach Does Not Mean or any inadvertent disclosure from an individual who is otherwise authorized to access protected health information at a facility operated by a covered entity or business associate to another similarly situated individual at same facility; and any such information received as a result of such disclosure is not further acquired, accessed, used, or disclosed without authorization by any person

Breach Does Not Mean if the covered entity or business associate has a good faith belief that the unauthorized individual, to whom the impermissible disclosure was made, would not have been able to retain the information.

Unsecured Protected Health Information Covered entities and business associates must only provide the required notification if the breach involved unsecured protected health information. Unsecured protected health information is protected health information that has not been rendered unusable, unreadable, or indecipherable to unauthorized individuals through the use of a technology or methodology specified by the Secretary in guidance.

Guidance Unsecured Protected Health Information and Guidance This guidance was issued in April nistrative/breachnotificationrule/brguidanc e.htmlhttp:// nistrative/breachnotificationrule/brguidanc e.html

Use Encryption Data in Transit –Use the encryption program. Data at Rest – Use whole drive encryption. Data at Rest – Use encryption for CDs, DVDs, and jump or thumb drives. You need to be aware of data use and manage the security of the data. Consider the cost of notification against the purchase price of security.

CLIA Program and HIPAA Privacy Rule; Patients’ Access to Test Reports NPRM open for comment until no later than 5 p.m. on November 14, HITECH created a Federal advisory committee known as the Health Information Technology (HIT) Policy Committee which can look at barriers to implementation an interoperable, nationwide health information infrastructure. The committee recommended that the CLIA exemption from provision of information to the patient is barrier exchange of data and should be taken down. Amends (CLIA) regulations to specify that, upon a patient’s request, the laboratory may provide access to completed test reports that, using the laboratory’s authentication process, can be identified as belonging to that patient. Removes an exemption from HIPAA so that CLIA labs that are HIPAA covered entities must comply with HIPAA.

Ellen Cannon, HIPAA Privacy Officer Phone FAX WV DHHR State Capitol Complex Bldg 3 Room 215 Charleston WV Original presentation prepared by Sallie Milam, JD, CIPP/G Samantha Stamper