DEED WorkForce Center Reception and Resource Area Certification Program Module 2 Unit 1b: WorkForce Center System II Learning Objectives III.

Slides:



Advertisements
Similar presentations
June Data Practices in Minnesota. June Outline for this presentation Minnesota data practices laws Classification of government data Government.
Advertisements

MN PRIMA: 2014 Data Practices Presentation Stacie Christensen, Director Information Policy Analysis Division, Admin.
The Minnesota Data Practices Act …and what it means to you.
Overview of the Privacy Act
Data Practices in Minnesota March Minnesota data practices laws Classification of government data Government entity responsibilities Rights of access.
National Science Foundation Division of Science Resources Statistics May The Confidential Information Protection and Statistical Efficiency Act.
HIPAA Privacy Training. 2 HIPAA Background Health Insurance Portability and Accountability Act of 1996 Copyright 2010 MHM Resources LLC.
Health Insurance Portability and Accountability Act HIPAA Education for Volunteers and Students.
HIPAA. What Why Who How When What Is HIPAA? Health Insurance Portability & Accountability Act of 1996.
HIPAA Basic Training for Privacy & Information Security Vanderbilt University Medical Center VUMC HIPAA Website:
Copyright Eastern PA EMS Council February 2003 Health Information Portability and Accountability Act It’s the law.
COBB/DOUGLAS COMMUNITY SERVICES BOARD Confidentiality and Privacy of Consumer Information.
National Health Information Privacy and Security Week Understanding the HIPAA Privacy and Security Rule.
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
The Health Insurance Portability and Accountability Act of 1996– charged the Department of Health and Human Services (DHHS) with creating health information.
What is HIPAA? This presentation was created by The University of Arizona Privacy Office, The Office for the Responsible Conduct of Research on March 5,
1 HIPAA Education CCAC Professional Development Training September 2006 CCAC Professional Development Training September 2006.
Before reviewing the following presentation click on the links below and print off the documents: NAM-43 The Bair Foundation HIPAA Policy NAM- 89 HIPAA.
COMPLYING WITH HIPAA PRIVACY RULES Presented by: Larry Grudzien, Attorney at Law.
Are you ready for HIPPO??? Welcome to HIPAA
PIPA PRESENTATION PERSONAL INFORMATION PROTECTION ACT.
DEED WorkForce Center Reception and Resource Area Certification Program Module 2 Unit 1b: WorkForce Center System II Learning Objectives II.
MINNESOTA GOVERNMENT DATA PRACTICES ACT How the law affects University employees and recordkeeping Susan McKinney Records & Information Management.
Data Classification & Privacy Inventory Workshop
HIPAA COMPLIANCE IN YOUR PRACTICE MARIBEL VALENTIN, ESQUIRE.
HIPAA Basic Training for Privacy and Information Security Vanderbilt University Medical Center VUMC HIPAA Website: HIPAA Basic.
HIPAA PRIVACY AND SECURITY AWARENESS.
Privacy and Security of Protected Health Information NorthPoint Health & Wellness Center 2011.
June Data Practices in Minnesota. June Outline for this presentation Minnesota data practices laws Classification of government data Government.
Privacy and Security Laws for Health Care Organizations Presented by Robert J. Scott Scott & Scott, LLP
How Hospitals Protect Your Health Information. Your Health Information Privacy Rights You can ask to see or get a copy of your medical record and other.
DEED WorkForce Center Reception and Resource Area Certification Program Module 2 Unit 1b: WorkForce Center System II Learning Objectives I.
Building a Privacy Foundation. Setting the Standard for Privacy Health Insurance Portability and Accountability Act (HIPAA) Patient Bill of Rights Federal.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
Understanding HIPAA (Health Insurandce Portability and Accountability Act)
PricewaterhouseCoopers 1 Administrative Simplification: Privacy Audioconference April 14, 2003 William R. Braithwaite, MD, PhD “Doctor HIPAA” HIPAA Today.
The right item, right place, right time. DLA Privacy Act Code of Fair Information Principles.
Rhonda Anderson, RHIA, President  …is a PROCESS, not a PROJECT 2.
Copyright ©2014 by Saunders, an imprint of Elsevier Inc. All rights reserved 1 Chapter 02 Compliance, Privacy, Fraud, and Abuse in Insurance Billing Insurance.
Confidentiality Region 7 Education Service Center Head Start Copyright 2013 by Region 7 Education Service Center. This document may be reproduced for educational.
A Road Map to Research at Jefferson: HIPAA Privacy and Security Rules for Researchers Presented By: Privacy Officer/Office of Legal Counsel October 2015.
1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.
Government Data Practices and the Open Meeting Law August 2014.
Data Practices in Minnesota December Outline for this presentation Minnesota data practices laws Classification of government data Government entity.
Copyright © 2015 by Saunders, an imprint of Elsevier Inc. All rights reserved. Chapter 3 Privacy, Confidentiality, and Security.
Personal data protection in research projects
HIPAA Overview Why do we need a federal rule on privacy? Privacy is a fundamental right Privacy can be defined as the ability of the individual to determine.
Privacy Compliance in Schools Darrebin A/P’s Network 7 May 2009.
Table of Contents. Lessons 1. Introduction to HIPAA Go Go 2. The Privacy Rule Go Go.
DON Code of Privacy Act Fair Information Principles DON has devised a list of principles to be applied when handling Protected Personal Information (PPI).
Taylor County Schools FERPA (Confidentiality) Training August 17, 2010.
Board of Directors – March 24, 2016 Denise Mannon, AHFI, CHPC Corporate Compliance Officer.
HIPAA Privacy What Every Staff Member Needs to Know.
Health Insurance Portability and Accountability Act (HIPAA) Primer for Observers, Volunteers, Medical Students Dr. Michael Palumbo- Privacy Officer/ EVP.
Properly Safeguarding Personally Identifiable Information (PII) Ticket Program Manager (TPM) Social Security’s Ticket to Work Program.
Nassau Association of School Technologists
Health Insurance Portability and Accountability Act of 1996
HIPAA Privacy & Security
HIPAA Administrative Simplification
Obligations of Educational Agencies: Parents’ Bill of Rights
Chapter 3: IRS and FTC Data Security Rules
Move this to online module slides 11-56
HIPAA PRIVACY AWARENESS, COMPLIANCE and ENFORCEMENT
Disability Services Agencies Briefing On HIPAA
HIPAA Privacy & Security
Government Data Practices & Open Meeting Law Overview
Good Spirit School Division
Government Data Practices & Open Meeting Law Overview
HIPAA Do’s and Don'ts: What is Really Behind Protected Health Information (PHI) and Health Care Privacy Rules Paul Sisler, Director, Information Services;
Presentation transcript:

DEED WorkForce Center Reception and Resource Area Certification Program Module 2 Unit 1b: WorkForce Center System II Learning Objectives III

Learning Objectives 3 Data Privacy Awareness  Awareness  The Data Practices Act  Customer Rights  Tennessen Warning Notice  Informed Consent  Data Protection and Security  Resources This information is based on from the Information Policy Analysis Division of the Minnesota Department of Administration in 2007.

AWARENESS

Awareness Anyone working in a WFC is responsible for properly handling customer data. Customers have rights to privacy and security. Tennessen Notice Warning Sharing customer information with others is restricted.

THE DATA PRACTICES ACT

The Data Practices Act Minnesota Statutes, Chapter 13 and Minnesota Rules, Chapter 1205 Presumes government data are public Classifies data that are not public Provides rights for the public and data subjects Requires that data on individuals are accurate, complete, current, and secure Defines government data

CUSTOMER RIGHTS

Customer’s Rights Data subjects: Limits on the government’s collection and storage of data on individuals Right to certain information prior to the collection of private or confidential data Right to consent to the new use of data Right to challenge the accuracy and/or completeness of data Expectation in the security of data

The Three Laws of Data Practices The Official Records Act  Minnesota Statutes, section The Records Management Statute  Minnesota Statutes, section The Minnesota Government Data Practices Act  Minnesota Statutes, Chapter 13 & Minnesota Rules, Chapter 1205

THE TENNESSEN WARNING NOTICE

Tennessen Warning Notice Tennessen Warning Notice, Minnesota 13.04, subdivision 2 covers: Private data collected from an individual on an individual Describes individual’s rights before data can be collected, stored, used, or disseminated Describes purpose and intended use of data Whether the individual may refuse or is legally required to provide the data Known consequences from supplying or refusing to supply the data Identity of other persons or entities with statutorily authorized access to the data

INFORMED CONSENT

Informed consent Permission for a new use or release of government data Informed consent is necessary for:  Entity to use data in a new or different way  A new release of data  Collection of data about an individual from another person or entity Informed consent must be in writing and cannot be coerced

DATA PROTECTION AND SECURITY

Data protection & security Appropriate security safeguards and appropriate destruction of not public data  Minnesota Statutes, section 13.05, subdivision 5 Disclosure of breach in security of data  Minnesota Statutes, section Protecting not public data

DEED WorkForce Center Reception and Resource Area Certification Program Module 2 Unit 1b: WorkForce Center System II Learning Objectives III

Learning Objectives 3 Data Privacy Awareness  Awareness  The Data Practices Act  Customer Rights  Tennessen Warning Notice  Informed Consent  Data Protection and Security  Resources This information is based on from the Information Policy Analysis Division of the Minnesota Department of Administration in 2007.

AWARENESS

Awareness Anyone working in a WFC is responsible for properly handling customer data. Customers have rights to privacy and security. Tennessen Notice Warning Sharing customer information with others is restricted.

THE DATA PRACTICES ACT

The Data Practices Act Minnesota Statutes, Chapter 13 and Minnesota Rules, Chapter 1205 Presumes government data are public Classifies data that are not public Provides rights for the public and data subjects Requires that data on individuals are accurate, complete, current, and secure Defines government data

CUSTOMER RIGHTS

Customer’s Rights Data subjects: Limits on the government’s collection and storage of data on individuals Right to certain information prior to the collection of private or confidential data Right to consent to the new use of data Right to challenge the accuracy and/or completeness of data Expectation in the security of data

The Three Laws of Data Practices The Official Records Act  Minnesota Statutes, section The Records Management Statute  Minnesota Statutes, section The Minnesota Government Data Practices Act  Minnesota Statutes, Chapter 13 & Minnesota Rules, Chapter 1205

THE TENNESSEN WARNING NOTICE

Tennessen Warning Notice Tennessen Warning Notice, Minnesota 13.04, subdivision 2 covers: Private data collected from an individual on an individual Describes individual’s rights before data can be collected, stored, used, or disseminated Describes purpose and intended use of data Whether the individual may refuse or is legally required to provide the data Known consequences from supplying or refusing to supply the data Identity of other persons or entities with statutorily authorized access to the data

Discussion Point 1.Do understand the purpose of the Tennessen Warning Notice?

INFORMED CONSENT

Informed consent Permission for a new use or release of government data Informed consent is necessary for:  Entity to use data in a new or different way  A new release of data  Collection of data about an individual from another person or entity Informed consent must be in writing and cannot be coerced

DATA PROTECTION AND SECURITY

Data protection & security Appropriate security safeguards and appropriate destruction of not public data  Minnesota Statutes, section 13.05, subdivision 5 Disclosure of breach in security of data  Minnesota Statutes, section Protecting not public data

Tips to Protect Not Public Data Lock the screen of your computer when leaving your desk Turn copies of not public data documents over or outside of view. Use locked file cabinets for not public data Do not leave not public data on a copier, printer, or fax machine. Do not discuss not public data with co-workers whose work does not require knowing about the data Create strong passwords for your computer, do not share it others, and change it periodically. Remove private data that you do not need to do your job from your laptop or briefcase. If you must use not public electronic data away from the office, consult with your technology person to discuss encryption options Do not access not public data using a web browser on a public computer Hide your laptop from plain view in your car; best to take it with you. Put it in the trunk before you reach your destiny.

Specific provisions of Chapter 13 General not public data Social Security numbers  Private (Minnesota Statutes, section ) Security information  Private/nonpublic (Minnesota Statutes, section 13.37) Trade secret data  Private/nonpublic (Minnesota Statutes, section 13.37)

Civil remedies & penalties Minnesota Statutes, sections & Civil suits against government entity or responsible authority allowed Penalties for willful violation  Misdemeanor  Suspension or dismissal

Data Practices Checklist 1. Does our government entity know what data we collect and keep? 2. Does our government entity understand how the data are classified? 3. Does our government entity have a “data practices compliance official” (DPCO) who can help citizens and our entity with data practices requests? 4. Does our government entity have a policy and/or procedure that discusses which employee or employees within our entity are responsible for handling data practices issues? 5. Does our government entity have the public document required by Minnesota Statutes, section 13.05, subdivision 1, that identifies our responsible authority and describes the private and confidential data on individuals we maintain?

Discussion Point 1.Do you have a Data Practice policy and procedure at your WFC?

RESOURCES

Resources Responsible Authority: Dan McElroy, Commissioner Data Practices Compliance Official: Deb Serum or Policy and Procedures Manual: intraweb.deed.state.mn.us/ref/ppm/ppm601.htm Find out who your Data Practice person is at your site.

Information & questions Information Policy Analysis Division (IPAD) Commissioner of Administration’s advisory opinions IPAD website and information materials IPAD listserv and Newsletter Informal advice from IPAD Information Policy Analysis Division   or   201 Administration Building 50 Sherburne Ave. St. Paul, MN 55155

Resource Area (RA) KEY POINTS 1. WFCs are responsible for appropriate security safeguards of public data and appropriate destruction of not public data. 2. One of the elements of the Data Practices Act provides for rights for the public and data subjects. 3. The Tennessen Notice Warning describes how and why data collected is intended to be use, collected and stored, sharing of information, rights and consequences of or not releasing information. 4. Any person who willfully – knowingly – violates Minnesota Statues Chapter 13 is guilty of a penalty.

This completes Learning Objective 3 of Module 2, Unit 1b and training for this unit. Learning Objective 1: Equal Opportunity Learning Objective 2: Complaint Process Leaning Objective 3: Data Privacy Awareness