1 HIPAA OVERVIEW ETSU. 2 What is HIPAA? Health Insurance Portability and Accountability Act.

Slides:



Advertisements
Similar presentations
SIMPLIFYING PRIVACY: HIPAA PRIVACY STANDARDS AND RESEARCH Angela M. Vieira General Counsel Childrens Hospital and Health Center June 5, 2004.
Advertisements

HIPAA Privacy Rule “Standards for Privacy of Individually Identifiable Health Information” 45 CFR 160 and 164* *
HIPAA and Public Health 2007 Epi Rapid Response Team Conference.
HIPAA Privacy Keys to Success Education for Health Care Professionals.
Confidentiality and HIPAA
COBB/DOUGLAS COMMUNITY SERVICES BOARD Confidentiality and Privacy of Consumer Information.
The Health Insurance Portability and Accountability Act Basic HIPAA Training For CMU workforce with access to PHI.
HIPAA – Privacy Rule and Research USCRF Research Educational Series March 19, 2003.
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
HIPAA Health Insurance Portability and Accountability Act.
What is HIPAA? This presentation was created by The University of Arizona Privacy Office, The Office for the Responsible Conduct of Research on March 5,
1 HIPAA Education CCAC Professional Development Training September 2006 CCAC Professional Development Training September 2006.
Dr. Yaseen Hayajneh Health Insurance Portability and Accountability Act Yaseen HayajnehYaseen Hayajneh RN, MPH, PhD.
HIPAA Requirements for Patient Oriented Research
HIPAA Privacy Keys to Success Education for Nursing and all other Clinical Students Effective January 2010 HIPAA Job Specific Education1.
HIPAA Health Insurance Portability and Accountability Act.
Informed Consent.
 The Health Insurance Portability and Accountability Act of  Federal Law designed to protect sensitive information.  HIPAA violations are enforced.
Health Insurance Portability & Accountability Act “HIPAA” To every patient, every time, we will provide the care that we would want for our own loved ones.
HIPAA HIPAA Health Insurance Portability and Accountability Act of 1996.
Professional Nursing Services.  Privacy and Security Training explains:  The requirements of the federal HIPAA/HITEC regulations, state privacy laws.
HIPAA Training Presentation for New Employees How did we get here? HIPAA Police 1.
Training In HIPAA Privacy Regulations for Researchers and Research Staff Adapted from a presentation prepared by Human Subjects Division, University of.
Health Insurance Portability Accountability Act of 1996 HIPAA for Researchers: IRB Related Issues HSC USC IRB.
August 10, 2001 NESNIP PRIVACY WORKGROUP HIPAA’s Minimum Necessary Standard Presented by: Mildred L. Johnson, J.D.
University of Miami1 HIPAA Survival Skills An Introduction to HIPAA and Research University of Miami Human Subjects Research Office October 31, 2006 Evelyne.
1 HIPAA, Researchers and the IRB: Part Two Alan Homans, IRB Chair and Nancy Stalnaker, IRB Administrator.
HIPAA, Researchers and the IRB Alan Homans, IRB Chair and Nancy Stalnaker, IRB Administrator.
Health Insurance Portability and Accountability Act of 1996
HIPAA Health Insurance Portability & Accountability Act of 1996.
Health Insurance Portability and Accountability Act (HIPAA)
Protected Health Information (PHI). Privileged Communication An exchange of information between two individuals in a confidential relationship. (Examples:
Proprietary and confidential and may not be reproduced or distributed without the express consent of Cap Gemini Ernst & Young U.S. LLC and Ernst & Young.
Paula Peyrani, MD Medical/Project Director, HIV Program at the 550 Clinic Assistant Director, Research Design and Development Clinical and Translational.
HIPAA PRIVACY AND SECURITY AWARENESS.
HIPAA Business Associates Leadership Group Meeting June 28, 2001.
1 Research & Accounting for Disclosures March 12, 2008 Leslie J. Pfeffer, BS, CHP Office of the Vice President for Research Administration Office of Compliance.
HIPAA The Privacy Rule Health Insurance Portability and Accountability Act of 1996 (HIPAA) The 104 th Congress passed the Act, Public Law ,
Revised February 4, Health Insurance Portability and Accountability Act (HIPAA) HIPAA Privacy Rule: UCSF Education Module for Researchers, Research.
HIPAA Privacy and Research August 21, 2015
Health Insurance Portability and Accountability Act (HIPAA)
PwC Tissue Banking and Repositories – Human Subject Protections Privacy Protections Medical Research Summit Tom Puglisi, Ph.D. Friday March 7 – 9:15 am.
HIPAA – How Will the Regulations Impact Research?.
HIPAA Michigan Cancer Registrars Association 2005 Annual Educational Conference Sandy Routhier.
© 2009 The McGraw-Hill Companies, Inc. All rights reserved. 1 McGraw-Hill Chapter 2 The HIPAA Privacy Standards HIPAA for Allied Health Careers.
Medical Law and Ethics, Third Edition Bonnie F. Fremgen Copyright ©2009 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved.
Health Insurance Portability and Accountability Act (HIPAA) CCAC.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
Understanding HIPAA (Health Insurandce Portability and Accountability Act)
Health Insurance portability and Accountability Act (HIPAA)‏
Configuring Electronic Health Records Privacy and Security in the US Lecture b This material (Comp11_Unit7b) was developed by Oregon Health & Science University.
HIPAA Overview Why do we need a federal rule on privacy? Privacy is a fundamental right Privacy can be defined as the ability of the individual to determine.
PwC Issues in HIPAA Research Compliance William R. Braithwaite, MD, PhD “Dr. HIPAA” HIPAA Summit 6 Washington, DC 27 March 2003.
Final HIPAA Privacy Rule: The Research Provisions Julie Kaneshiro DHHS Office for Human Research Protections Phone: Fax:
HIPAA and RESEARCH 5 th Thursday May 31, Page 2.
ELECTRONIC HEALTH RECORD PRIVACY TRAINING
HIPAA PRIVACY & SECURITY TRAINING
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA)
What is HIPAA? HIPAA stands for “Health Insurance Portability & Accountability Act” It was an Act of Congress passed into law in HEALTH INSURANCE.
HIPAA Administrative Simplification
Disability Services Agencies Briefing On HIPAA
The Health Insurance Portability and Accountability Act Basic HIPAA Training For CMU workforce with access to PHI.
The Health Insurance Portability and Accountability Act
New School Violence Law; HIPAA Privacy Training
HIPAA & PHI TRAINING & AWARENESS
Issues in HIPAA Research Compliance
The Health Insurance Portability and Accountability Act
Office of the Vice President for Research Human Subjects Protection Program IRB Submission Process Module 4 - Health Insurance Portability and Accountability.
The Health Insurance Portability and Accountability Act
Presentation transcript:

1 HIPAA OVERVIEW ETSU

2 What is HIPAA? Health Insurance Portability and Accountability Act.

3 PURPOSE – TITLE II ADMINISTRATIVE SIMPLIFICATION To increase the efficiency and effectiveness of the entire health care system through: The electronic exchange of information The standardization of that information To enhance the security and privacy of Protected Health Information (PHI) throughout the entire health system

4 PRIVACY RULE: WHAT DOES IT DO? HIPAA regulates the use or disclosure of Protected Health Information (PHI)

5 WHAT IS PHI? Health and demographic information about an individual that is transmitted or maintained in any medium where the information: Is created or received by a health care provider, health plan, employer, or health care clearinghouse; and Relates to the past, present, or future Physical or mental health condition of an individual, or Provision of health care to an individual, or Payment for the provision of health care to an individual

6 INDIVIDUAL IDENTIFIERS 1. Name 2. Geographic subdivisions smaller than a State – Street Address – City – County – Precinct – Zip Code & their equivalent geocodes, except for the initial three digits 3. Dates, except year – Birth date – Admission date – Discharge date – Date of death 4. Telephone numbers 5. Fax number 6. Address 7. Social security numbers 8. Medical record numbers 9. Health plan beneficiary numbers 10. Account numbers 11. Certificate/license numbers 12. Vehicle identifiers and serial numbers, including license plate numbers 13. Device identifiers and serial numbers 14. Web universal resource locations (URLs) 15. Internet Protocol (IP) address numbers 16. Biometric identifiers, including finger and voice prints 17. Full face photographic images and any comparable images 18. Any other unique identifying number, characteristic, or code

7 PERMITTED USES & DISCLOSURES HIPAA permits the use or disclosure only for the following purposes: Treatment Payment Health Care Operations (These are referred to as “TPO”)

8 MANDATED USES & DISCLOSURES HIPAA mandates the disclosure of PHI for certain purposes such as: Health oversight activities Judicial and administrative proceedings Law enforcement purposes Organ donation All other uses or disclosures require an authorization

9 HEALTH CARE OPERATIONS Any of the following activities of a Covered Entity: Quality assessment and improvement and population- based activities Peer review and credentialing activities Underwriting, premium rating, and other activities related to the creation, renewal, or replacement of a contract of health insurance Medical review, legal services, and auditing Business planning and development Business management and general administrative activities

10 AUTHORIZATION Authorization must be obtained for ALL uses and disclosures other than TPO or those mandated under law Authorizations must include: A description of the information to be disclosed The name of the person or entities to whom the information will be disclosed An expiration date Information regarding right to revoke Date and signature

11 PRIVACY NOTICE Privacy Notices Must: Be in plain language Contain a description and example of TPO Contain a description and example of other uses and disclosures not requiring Authorization Include statements about an individual’s rights Include statements about the Covered Entity’s duties Describe the complaint process Provide other specific requirements

12 MINIMUM NECESSARY A requirement that only “minimum necessary disclosures” may be made to accomplish the intended purpose of the use, disclosure, or request for PHI.

13 MINIMUM NECESSARY Internal Requirements: Identify workforce who need to access PHI For each class, category or person identified, limit access based on need-to-know External Requirements: Limit access to what is needed to accomplish the purpose for which the request was made Each request that is non-routine should be reviewed to determine whether it is reasonably necessary

14 RESEARCH To use or disclose PHI for research purposes, Covered Entities must obtain either: Written authorization from the research subject. Permission from the Institutional Review Board (IRB) or Privacy Board to waive the authorization.

15 IRB WAIVER OF AUTHORIZATION The following criteria must be met before the IRB can waive the patient authorization requirement for research: Use of PHI will pose minimal risks to the subject’s welfare and privacy rights. Research can not practically be conducted without the waiver or access to PHI. Covered entity must protect PHI from inappropriate use or disclosure. Researcher must provide written assurances that PHI will not be reused or disclosed, except as required by law.

16 INDIVIDUAL RIGHTS Individuals have the right to: Receive written notice of privacy practices Request restrictions on uses & disclosures Access, inspect & copy their PHI Request amendment or correction of their PHI Receive an accounting of disclosures of their PHI (except those related to treatment, payment, & operations)

17 ADMINISTRATIVE REQUIREMENTS Designate a privacy officer with primary responsibility for ensuring compliance with the regulations Establish training programs for all members of the workforce Implement appropriate policies & procedures to prevent intentional and accidental disclosures of PHI

18 ADMINISTRATIVE REQUIREMENTS Establish a system for receiving and responding to complaints regarding the Covered Entity’s privacy practices Implement appropriate sanctions for violations of the privacy guidelines Make reasonable efforts to limit information to minimum necessary to accomplish a person’s purpose/job

19 ENFORCEMENT The Public. The public will be educated about their privacy rights and will not tolerate violations to their privacy! Expect Class Action lawsuits. Office For Civil Rights (OCR). Designated the enforcement agency concerning privacy regulations. They will provide guidance and monitor compliance. Department of Justice (DOJ). Involved in criminal privacy violations. Expect fines and penalties to be high.

20 PENALTIES - FAILURE TO COMPLY Civil $100 per violation per person up to a maximum of $25,000 per person per year per standard violated Criminal Up to $50,000, 1 year in prison, or both, for inappropriate use of PHI Up to $100,000, 5 years in prison, or both for using PHI under false pretenses Up to $250,000, 10 years in prison or both, for the intent to sell or use PHI for commercial advantage, personal gain, or malicious harm

21 HIPAA/Confidentiality Accountability Form Click here for the link to the HIPAA/Confidentiality Accountability Form HIPAA/Confidentiality Accountability Form Print this form, complete it and submit it to Academic Programs and Student Services in Nicks Hall, Room 230.

22 RESOURCES ETSU Privacy Officer – Sharron Stevens at http.// – For frequently asked questions, links to other HIPAA sites, and information on the law, regulations, and enforcement http.// - U.S. Department of Health and Human Services’ Office for Civil Rights frequently asked questions http.// – Interim final rule: Civil Money Penalties