1 PUBLIC HEALTH DIVISION Health Promotion and Chronic Disease Prevention Privacy and Security Basics for Self-Management Participant Data Collection Laura.

Slides:



Advertisements
Similar presentations
FERPA - Sharing Student Information
Advertisements

Protect Our Students Protect Ourselves
Mandatory training for all Users who have access to Privacy Act Data
Privacy and Security Basics for CDSME Data Collection Sue Lachenmayr, MPH, CHES.
Overview of the Privacy Act
Privacy and Information Security Training ( ) VUMC Privacy Website
1. As a Florida KidCare community partner families entrust you to not only help them navigate the Florida KidCare system but to keep the information they.
HIPAA Privacy Training. 2 HIPAA Background Health Insurance Portability and Accountability Act of 1996 Copyright 2010 MHM Resources LLC.
HIPAA. What Why Who How When What Is HIPAA? Health Insurance Portability & Accountability Act of 1996.
HIPAA Basic Training for Privacy & Information Security Vanderbilt University Medical Center VUMC HIPAA Website:
HIPAA Privacy Rule Training
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
The Health Insurance Portability and Accountability Act of 1996– charged the Department of Health and Human Services (DHHS) with creating health information.
What is HIPAA? This presentation was created by The University of Arizona Privacy Office, The Office for the Responsible Conduct of Research on March 5,
NAU HIPAA Awareness Training
HIPAA Health Insurance Portability and Accountability Act 1.
Informed Consent.
 The Health Insurance Portability and Accountability Act of  Federal Law designed to protect sensitive information.  HIPAA violations are enforced.
Health Insurance Portability & Accountability Act “HIPAA” To every patient, every time, we will provide the care that we would want for our own loved ones.
A dialogue with FMUG: Sensitive Data & Filemaker MIT Policy and Data Classifications ** DRAFT ** Guidelines Feedback and Discussion Tim McGovern 2 June.
1 DEFENSE LOGISTICS AGENCY AMERICA’S COMBAT LOGISTICS SUPPORT AGENCY DEFENSE LOGISTICS AGENCY AMERICA’S COMBAT LOGISTICS SUPPORT AGENCY WARFIGHTER SUPPORT.
RVCC FACULTY FERPA WORKSHOP OCTOBER 2011 DAN PALUBNIAK REGISTRAR
Critical Data Management Indiana University HR Summit April 24, 2014.
SAFEGUARDING DHS CLIENT DATA PART 2 SAFEGUARDING PHI AND HIPAA Safeguards must: Protect PHI from accidental or intentional unauthorized use/disclosure.
ROLES & RESPONSIBILITIES PRIVACY ACT (PA) SYSTEMS OF RECORDS MANAGERS.
MINNESOTA GOVERNMENT DATA PRACTICES ACT How the law affects University employees and recordkeeping Susan McKinney Records & Information Management.
FERPA: Family Educational Rights and Privacy Act.
1 Enterprise Security Your Information Security and Privacy Responsibilities © 2008 Providence Health & Services This information may be replicated for.
Privacy and Security Basics for CDSME Data Collection Sue Lachenmayr, MPH, CHES Updated April 10, 2014.
CDSME Data Collection Requirements and Procedures January 9, 2014 update You Can! Live Well, Virginia!
FAMILY EDUCATIONAL RIGHTS AND PRIVACY ACT Electronic Signatures This work is the intellectual property of the author. Permission is granted for this material.
Created May 2, Division of Public Health Managing Records What is a Record? What is a Records Retention & Disposition Schedule? Why is this Important?
For Medication Certified Staff Members Only.   Governs how we give medications in a school setting  States that each parish will develop, follow and.
Columbia University Medical Center Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) Privacy & Information Security Training 2009.
CPS Acceptable Use Policy Day 2 – Technology Session.
HIPAA PRIVACY AND SECURITY AWARENESS.
Confidentiality and Public Information Act LISD Special Education Department Training SY
1 DEFENSE LOGISTICS AGENCY AMERICA’S COMBAT LOGISTICS SUPPORT AGENCY DEFENSE LOGISTICS AGENCY AMERICA’S COMBAT LOGISTICS SUPPORT AGENCY WARFIGHTER SUPPORT.
Next ETCH Confidentiality and HIPAA Annual Review What you need to know. The Privacy Rule 1.
How Hospitals Protect Your Health Information. Your Health Information Privacy Rights You can ask to see or get a copy of your medical record and other.
Privacy and Information Management ICT Guidelines.
HIPAA (health insurance portability and accountability act)
Family Educational Rights and Privacy Act. From the moment a child enters the school system, sensitive information is collected about the child (and even.
A Road Map to Research at Jefferson: HIPAA Privacy and Security Rules for Researchers Presented By: Privacy Officer/Office of Legal Counsel October 2015.
ISO/IEC 27001:2013 Annex A.8 Asset management
Aged and Disabled Waiver (ADW) Health Insurance Portability and Accountability Act (HIPAA) Training 2015 October 2015.
HIPAA Training. What information is considered PHI (Protected Health Information)  Dates- Birthdays, Dates of Admission and Discharge, Date of Death.
The Health Insurance Portability and Accountability Act (HIPAA) requires Plumas County to train all employees in covered departments about the County’s.
HIPAA Privacy What Every Staff Member Needs to Know.
POLICIES & PROCEDURES FOR HANDLING CONFIDENTIAL INFORMATION NOVEMBER 5 TH 2015.
Properly Safeguarding Personally Identifiable Information (PII) Ticket Program Manager (TPM) Social Security’s Ticket to Work Program.
HIPAA Privacy Rule Training
HIPAA Privacy and Security
Protecting PHI & PII 12/30/2017 6:45 AM
Privacy and Security Basics for Falls Evidence Based Programs Data Collection . October 2016.
Privacy Education Session CMHA-WECB/CCHC Volunteers/Students
Privacy and Security Basics for CDSME Data Collection
HIPAA Privacy & Security
Privacy & Confidentiality
ACL’s New Data Requirements (Administration on Community Living)
Disability Services Agencies Briefing On HIPAA
HIPAA Privacy & Security
HIPAA Overview.
The Health Insurance Portability and Accountability Act
Good Spirit School Division
Lesson 3: Medical Records
Handling Information Securely
TRACE INITIATIVE: Confidentiality, Data Security, and Procedures for Protocol Violation or Adverse Event.
Protecting Student Data
Presentation transcript:

1 PUBLIC HEALTH DIVISION Health Promotion and Chronic Disease Prevention Privacy and Security Basics for Self-Management Participant Data Collection Laura Chisholm, MPH, MCHES December 12, 2013

2 PUBLIC HEALTH DIVISION Health Promotion and Chronic Disease Prevention Training Overview  Purpose of the Privacy Act  Primary Features of the Act  Who Needs Privacy Training?  Master Trainers and Program Leaders  Program Coordinators  Anyone else involved with participant data collection or transfer  Types of Information Protected by the Act  Disclosure  Safeguarding, Transporting and Disposing of PII  Roles and Responsibilities  Test Questions  Certificate

3 PUBLIC HEALTH DIVISION Health Promotion and Chronic Disease Prevention Privacy Act of 1974 Public Law (5 U.S.C.A. 552a)  Purpose: to protect records that can be retrieved by personal identifiers such as a name, social security number, or other identifying number or symbol.  The act was created in response to concerns about how the use of computerized databases might impact individuals' privacy rights.  requires government agencies to show individuals any records kept on them  requires agencies to follow "fair information practices," when gathering and handling personal data.  places restrictions on how agencies can share an individual's data with other people and agencies.  lets individuals sue the government for violating of these provisions /

4 PUBLIC HEALTH DIVISION Health Promotion and Chronic Disease Prevention Who Needs to be Trained? If your work involves the management of sensitive information, PII (Personally Identifiable Information), or protected health information, you need to ensure you are taking precautions to protect it from unauthorized access/disclosure, theft, loss and improper disposal.

5 PUBLIC HEALTH DIVISION Health Promotion and Chronic Disease Prevention Who Needs to Be Trained?  Employees,  Managers,  Supervisors,  Coordinators,  Master trainers (MTs), and  Lay leaders (LLs), including volunteers who are involved in the collection, handling, and/or data entry of Personally Identifiable Information (PII) on individuals participating in CDSME.

6 PUBLIC HEALTH DIVISION Health Promotion and Chronic Disease Prevention What Type of Training is Needed?  Training for program coordinators and program implementers  The rights of individuals participating in CDSME  The appropriate protection of PII shared by CDSME participants at the workshop level  The appropriate storage and transfer of participant forms  Training for individuals completing data entry and data transfer  The appropriate protection of PII shared by CDSME participants at the workshop level  The appropriate storage, transfer and destruction of data forms  Security requirements for electronic data transfer, storing and degaussing (destruction)

7 PUBLIC HEALTH DIVISION Health Promotion and Chronic Disease Prevention Types of Information Covered by the Privacy Act Sensitive: if the loss of confidentiality, integrity, or availability could be expected to have a serious, severe or catastrophic adverse effect on organizational operations, organizational assets or individuals. Sensitive: Protected Health Information: Individually identifiable health information that relates to a person’s past/present/future physical/mental health, health care received, or payment. Protected Health Information:

8 PUBLIC HEALTH DIVISION Health Promotion and Chronic Disease Prevention Information Protected by the Privacy Act

9 PUBLIC HEALTH DIVISION Health Promotion and Chronic Disease Prevention Information Protected by the Privacy Act PERSONALLY IDENTIFIABLE INFORMATION (PII) "the term Personally Identifiable Information means any information about an individual maintained by an agency, including, but not limited to, education, financial transactions, medical history, and criminal or employment history and information which can be used to distinguish or trace an individual’s identity, such as their name, social security number, date and place of birth, mother’s maiden name, biometric records, etc., including any other personal information which is linked or linkable to an individual.“

10 PUBLIC HEALTH DIVISION Health Promotion and Chronic Disease Prevention Disclosure  No agency or person shall disclose: – any record – by any means of communication – to any person or another agency – without a written request or prior written consent of the individual to whom the record pertains  “any means of communication” includes oral (phone, in- person), written and electronic ( s, faxes, texts, tweets, pins, etc.)

11 PUBLIC HEALTH DIVISION Health Promotion and Chronic Disease Prevention Safeguarding PII  PII must always be treated as “FOR OFFICIAL USE ONLY” and must be marked accordingly.  This applies not only to paper records (including , faxes, etc., which must contain the cautionary marking “FOR OFFICIAL USE ONLY – FOUO”).  All records containing PII should be stored in locked filing cabinets or other secure containers to prevent unauthorized access.  Electronic records must be password protected and be transferred via encrypted .

12 PUBLIC HEALTH DIVISION Health Promotion and Chronic Disease Prevention Transporting PII  Hand Carrying  Use a Cover sheet to shield contents  Using Mail  Use manila or white envelopes  Mark the envelope to the attention of the authorized recipient  Never indicate on the outer envelope that it contains PII  Using  Password protect personal data placed on shared drives, the Internet or the Intranet  Use encrypted  Do not send PII to a personal, home or unencrypted address  Announce in the opening line of the text (NOT the subject line) that FOUO information is contained

13 PUBLIC HEALTH DIVISION Health Promotion and Chronic Disease Prevention Disposing of PII  A disposal method is considered adequate if it renders the information unrecognizable or beyond reconstruction.  Disposal methods may include:  Burning  Melting  Chemically decomposing  Pulping  Pulverizing  Shredding  Mutilating  Degaussing (erasing from magnetic field or disc)  Deleting/Emptying Recycle Bin

14 PUBLIC HEALTH DIVISION Health Promotion and Chronic Disease Prevention Your Role and Responsibility  Take privacy protection seriously  Respect the privacy of others  Ensure messages, faxes and s that contain personal information are properly marked and is encrypted  Make sure you have consent forms in place for PII  Don’t share PII with individuals who are not authorized  Have appropriate transfer, storage and disposal protocols in place for PII  Do not PII to personal, home or unencrypted accounts

15 PUBLIC HEALTH DIVISION Health Promotion and Chronic Disease Prevention Your Role and Responsibility  Advise all participants of their right to consent or refuse use of data about them  Provide participants with a blank copy of the participant information form  Read the leader welcome script

16 PUBLIC HEALTH DIVISION Health Promotion and Chronic Disease Prevention Master Trainers and Lay Leader Role  Use the CDSME Program Group Leader Script at a Class Zero pre-session or at the start of Session 1 and with any new participants who start at Session 2  The script explains why participant data is being collected and how it will be kept secure  Emphasize that completing the participant info form is voluntary  Individuals may skip any questions they do not want to answer  Individuals may choose to not complete the form, but they can still participate in the program

17 PUBLIC HEALTH DIVISION Health Promotion and Chronic Disease Prevention Leader Welcome Script This workshop is made possible by [a grant from the U.S. Administration on Community Living (ACL) and/or support from X funding agencies/ sponsors]. We hope that you will be willing to share information about yourself on the participant information form. This information is very valuable to us. We use it to learn who is taking the program and to improve our services. It also helps our funders show that they are spending their money wisely. Before you fill out the form, we want to explain how we will protect your information.

18 PUBLIC HEALTH DIVISION Health Promotion and Chronic Disease Prevention Leader Welcome Script At the top of the form, we ask for your initials. We only use these to match your information to an Attendance Log. This helps us to track how many times you come to class. Please do not write your name on this form. Any information you choose to share (minus your initials) will be entered into secure state and national databases. Your information will be combined with information from other participants, and only combined information will be used. This information will not be linked to your name or initials in any way. We will follow very strict rules to protect your information and to keep it private. We will maintain these paper forms securely. After a trained person enters your information into a secure computer, we will destroy the paper forms.

19 PUBLIC HEALTH DIVISION Health Promotion and Chronic Disease Prevention Leader Welcome Script You do not have to complete the form. You may skip any questions that you do not want to answer. If you decide not to complete the form, you can still participate in this workshop. While filling out the form, you may ask us to explain any questions that you find confusing. Thank you again for taking a few minutes to complete this important participant information form.

20 PUBLIC HEALTH DIVISION Health Promotion and Chronic Disease Prevention Your Role and Responsibility  Collect participant information forms from individuals who choose to fill them out  Discourage people from writing their name on forms  Collect forms individually – don’t allow them to be passed around  Store forms in sealed envelope and give to your program coordinator (or mail to Susan at OHA)

21 PUBLIC HEALTH DIVISION Health Promotion and Chronic Disease Prevention  All individuals involved in providing Living Well or Tomando Control programs should sign Non-Disclosure Agreements  All individuals involved in data collection, data transfer and/or data entry should sign Non-Disclosure Agreements  Non-Disclosure Agreements should be sent to OHA with the program packet. We will store them for three years as required by law. Non-Disclosure Agreements

22 PUBLIC HEALTH DIVISION Health Promotion and Chronic Disease Prevention I will not disclose any personally identifiable information provided by Chronic Disease Self-Management workshop participants. More specifically I will not disclose any data provided in the Participant Information Form. I will follow all standard safeguards for protecting this information, including transmitting the forms in sealed envelopes and storing them in secure, locked locations. I understand that unauthorized disclosure of any sensitive participant data may subject me to disciplinary and adverse administrative action. Non-Disclosure Agreement Text

23 PUBLIC HEALTH DIVISION Health Promotion and Chronic Disease Prevention Test Questions – Circle all correct answers 1.Information about an individual that is unique, or identifies or describes him or her (such as Social Security Number, medical history, date of birth, home address) is called: a.Interesting b.Record c.Data d.Personally Identifiable Information

24 PUBLIC HEALTH DIVISION Health Promotion and Chronic Disease Prevention Test Questions – Circle all correct answers 2. Disposal methods may include all except: a.Burning b.Shredding c.Tearing in half and putting in the garbage can d.Melting

25 PUBLIC HEALTH DIVISION Health Promotion and Chronic Disease Prevention Test Questions – Circle all correct answers 3. The Group Leader Script: a.Describes what participants will learn in the workshop b.Requests participants to share their birth date, address and sex c.Explains how participant privacy is protected and why data is being collected d.Emphasizes that participants are required to complete all survey forms

26 PUBLIC HEALTH DIVISION Health Promotion and Chronic Disease Prevention Test Answer Code 1.d - Personally Identifiable Information 2.c - Tearing in half and putting in the garbage can 3.c - Explains how participant privacy is protected and why data is being collected

27 PUBLIC HEALTH DIVISION Health Promotion and Chronic Disease Prevention Privacy and Security Basics Training Certificate ________________________________________ (Name) I have successfully completed the Privacy and Security Basics Training for Chronic Disease Self-Management Program Implementation and Data Collection ______________________________________________________ (Signature) (Date) ________________________________________ (Name) I have successfully completed the Privacy and Security Basics Training for Chronic Disease Self-Management Program Implementation and Data Collection ______________________________________________________ (Signature) (Date)

28 PUBLIC HEALTH DIVISION Health Promotion and Chronic Disease Prevention Congratulations! You’ve completed the Privacy and Information Security Basics Webinar. Please print the certificate of completion (slide #27) and send the signed, dated original or a scan to OHA: OHA/Oregon Public Health Division, attn: Susan Miles Health Promotion & Chronic Disease Prevention 800 NE Oregon Street, Suite 730 Portland, OR Fax: