Privacy and Security of Protected Health Information NorthPoint Health & Wellness Center 2011
Privacy and Security of Protected Health Information This presentation is intended to provide general background information regarding the privacy and security of protected health information. This presentation is intended to provide general background information regarding the privacy and security of protected health information. Questions regarding the protection, use or disclosure of protected health information should be resolved consistent with Chapter 4 of the NorthPoint Master Policy Manual. Questions regarding the protection, use or disclosure of protected health information should be resolved consistent with Chapter 4 of the NorthPoint Master Policy Manual. Employee issues/concerns about the protection, use or disclosure of protected health information can be reported to either your immediate supervisor or the NorthPoint Compliance Officer. Employee issues/concerns about the protection, use or disclosure of protected health information can be reported to either your immediate supervisor or the NorthPoint Compliance Officer.
What is Protected Health Information? Protected Health Information (PHI) is individually identifiable health information that is: Protected Health Information (PHI) is individually identifiable health information that is: Transmitted by electronic media; Transmitted by electronic media; Maintained in any electronic medium Maintained in any electronic medium Transmitted or maintained in any other form or medium Transmitted or maintained in any other form or medium
Okay, So What is Individually Identifiable Health Information? Individually Identifiable Health Information is any information, including demographic information, that: Individually Identifiable Health Information is any information, including demographic information, that: Relates to the past, present or future physical or mental health of an individual; Relates to the past, present or future physical or mental health of an individual; Relates to the provision of health care to an individual Relates to the provision of health care to an individual Relates to the past, present or future payment for the provision of health care to an individual Relates to the past, present or future payment for the provision of health care to an individual And that identifies the individual or there is reason to believe that the information can be used to identify the individual And that identifies the individual or there is reason to believe that the information can be used to identify the individual
Why Do We Protect Health Information? Our patients expect that their medical and health information will be treated confidentially Our patients expect that their medical and health information will be treated confidentially We want to build trust in our relationships with our patients We want to build trust in our relationships with our patients It’s the right thing to do It’s the right thing to do Federal and state law require it Federal and state law require it
Privacy and Security Under Law Health Insurance Portability and Accountability Act of 1996 (HIPAA): Health Insurance Portability and Accountability Act of 1996 (HIPAA): Sets a baseline for safeguarding the privacy and security of protected health information; Sets a baseline for safeguarding the privacy and security of protected health information; Preempts state law unless the state law is more stringent on its protection of the individual Preempts state law unless the state law is more stringent on its protection of the individual State and other laws may provide more protection to the individual, e.g. issues of reproductive health, the provision of mental health services, services to minors, services to students, etc. State and other laws may provide more protection to the individual, e.g. issues of reproductive health, the provision of mental health services, services to minors, services to students, etc.
What are Patient Expectations Regarding Their Protected Health Information? Health information will be treated confidentially Health information will be treated confidentially The information will be used only for authorized purposes The information will be used only for authorized purposes I will have access to my health information (with some restrictions) I will have access to my health information (with some restrictions) I will consent to the release, disclosure and use of my health information I will consent to the release, disclosure and use of my health information I can restrict the release, disclosure and use of my health information in certain circumstances I can restrict the release, disclosure and use of my health information in certain circumstances Only the minimum necessary amount of my health information will be released, disclosed or used to accomplish a legitimate and intended purpose Only the minimum necessary amount of my health information will be released, disclosed or used to accomplish a legitimate and intended purpose Any unauthorized release, disclosure or use of my health information will be noted and steps will be taken to mitigate any damage Any unauthorized release, disclosure or use of my health information will be noted and steps will be taken to mitigate any damage I am entitled to an accounting of any unauthorized release, disclosure or use of my health information I am entitled to an accounting of any unauthorized release, disclosure or use of my health information
What Does This Mean for NorthPoint? We provide patients a notice of our privacy practices We provide patients a notice of our privacy practices We treat their health information with respect, as if it were our own We treat their health information with respect, as if it were our own We ask patients for their consent to release their health information We ask patients for their consent to release their health information We take practical and effective steps to protect the privacy and security of health information We take practical and effective steps to protect the privacy and security of health information When requested and consistent with our own policies and procedures, we provide patients with access to their health information; we correct any discrepancies in their health information When requested and consistent with our own policies and procedures, we provide patients with access to their health information; we correct any discrepancies in their health information If protected health information is improperly released, used or disclosed, we take steps to mitigate any possible damage If protected health information is improperly released, used or disclosed, we take steps to mitigate any possible damage We need to be able to account for any improper release, use or disclosure to patients We need to be able to account for any improper release, use or disclosure to patients We constantly seek to improve our own actions and processes as they relate to the privacy and security of protected health information We constantly seek to improve our own actions and processes as they relate to the privacy and security of protected health information We work with our supervisors and the Chief Compliance Officer to solve problems which may arise We work with our supervisors and the Chief Compliance Officer to solve problems which may arise
Practical and Effective Steps to Protect the Privacy and Security of Protected Health Information What does our Department do to protect the privacy and security of protected health information? What does our Department do to protect the privacy and security of protected health information? Periodically assess the risk of improper use, disclosure or release of information Periodically review our own processes and behaviors as they relate to the use, disclosure or release of information Orient computer screens so that staff and patients cannot view protected health information Use privacy screens on our computers Comply with password and security rules for the use of our computers Close open computer programs when we will be away form our desks or work stations more than momentarily Store written materials securely when we are away from our desks for more than a few minutes…or at the end of the work day Take special care to ensure accurate use of the fax machine in the transmission and receipt of patient information
Practical and Effective Steps to Protect the Privacy and Security of Protected Health Information What does our Department do to protect the privacy and security of protected health information? What does our Department do to protect the privacy and security of protected health information? Discuss patient specific information quietly and, as appropriate, behind closed doors Take special care in the use of the copy machine to ensure that patient information is not left behind, nor left unattended for more than a few minutes Use secure fax and copying machines where available Adhere to guidelines on the use of and the transmission of protected health information Shred paper/dispose of electronic media in the appropriate fashion Secure our work stations Lock file cabinets Other ?
Practical and Effective Steps to Protect the Privacy and Security of Protected health Information What will our Department do in 2012 to improve how we protect the privacy and security of protected health information? What will our Department do in 2012 to improve how we protect the privacy and security of protected health information? 1.? 2.? 3.? 4.?