Presented by Capture Billing and Consulting, Inc. Katie Jennings, RN and Michelle Ivanchukov, CPC, CCS-P www.CaptureBilling.com 703.327.1800.

Slides:



Advertisements
Similar presentations
Presented by Elena Chan, UCSF Pharm.D. Candidate Tiffany Jew, USC Pharm.D. Candidate March 14, 2007 P HARMACEUTICAL C ONSULTANTS, I NC. P RO P HARMA HIPAA.
Advertisements

1 The Health Insurance Portability and Accountability Act (HIPAA) A guided tutorial for GVSU employees.
HIPAA and Public Health 2007 Epi Rapid Response Team Conference.
1. As a Florida KidCare community partner families entrust you to not only help them navigate the Florida KidCare system but to keep the information they.
HIPAA Privacy Training. 2 HIPAA Background Health Insurance Portability and Accountability Act of 1996 Copyright 2010 MHM Resources LLC.
HIPAA. What Why Who How When What Is HIPAA? Health Insurance Portability & Accountability Act of 1996.
Confidentiality and HIPAA
HIPAA Privacy Rule Training
COBB/DOUGLAS COMMUNITY SERVICES BOARD Confidentiality and Privacy of Consumer Information.
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
The Health Insurance Portability and Accountability Act of 1996– charged the Department of Health and Human Services (DHHS) with creating health information.
HIPAA PRIVACY REQUIREMENTS Dana L. Thrasher Constangy, Brooks & Smith, LLC (205) ; Victoria Nemerson.
HIPAA Health Insurance Portability and Accountability Act.
What is HIPAA? This presentation was created by The University of Arizona Privacy Office, The Office for the Responsible Conduct of Research on March 5,
Health Insurance Portability and Accountability Act (HIPAA)HIPAA.
NAU HIPAA Awareness Training
TM The HIPAA Privacy Rule: Safeguarding Health Information in Research and Public Health Practice Centers for Disease Control and Prevention Beverly A.
HIPAA Basics A Matter of Integrity. Introduction “A Matter of Integrity” defines HIPAA and protecting patient health information. Success depends on our.
Reviewing the World of HIPAA Stephanie Anderson, CPC October 2006.
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996 (HIPAA)
HIPAA Privacy Rule Compliance Training for YSU April 9, 2014.
 The Health Insurance Portability and Accountability Act of  Federal Law designed to protect sensitive information.  HIPAA violations are enforced.
COMPLYING WITH HIPAA PRIVACY RULES Presented by: Larry Grudzien, Attorney at Law.
Are you ready for HIPPO??? Welcome to HIPAA
HIPAA HIPAA Health Insurance Portability and Accountability Act of 1996.
Health Insurance Portability & Accountability Act (HIPAA)
HIPAA COMPLIANCE IN YOUR PRACTICE MARIBEL VALENTIN, ESQUIRE.
HIPAA Health Insurance Portability & Accountability Act of 1996.
Implementing and Enforcing the HIPAA Privacy Rule.
Columbia University Medical Center Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) Privacy & Information Security Training 2009.
HIPAA PRIVACY AND SECURITY AWARENESS.
HIPAA The Privacy Rule Health Insurance Portability and Accountability Act of 1996 (HIPAA) The 104 th Congress passed the Act, Public Law ,
HIPAA OBJECTIVES  Define HIPAA  Define PHI  Use of PHI  Your rights  Your responsibilities.
1 HIPAA OVERVIEW ETSU. 2 What is HIPAA? Health Insurance Portability and Accountability Act.
Health Insurance Portability and Accountability Act (HIPAA)
HIPAA Michigan Cancer Registrars Association 2005 Annual Educational Conference Sandy Routhier.
© 2009 The McGraw-Hill Companies, Inc. All rights reserved. 1 McGraw-Hill Chapter 2 The HIPAA Privacy Standards HIPAA for Allied Health Careers.
Medical Law and Ethics, Third Edition Bonnie F. Fremgen Copyright ©2009 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved.
Building a Privacy Foundation. Setting the Standard for Privacy Health Insurance Portability and Accountability Act (HIPAA) Patient Bill of Rights Federal.
Health Insurance Portability and Accountability Act (HIPAA) CCAC.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
Understanding HIPAA (Health Insurandce Portability and Accountability Act)
© 2013 The McGraw-Hill Companies, Inc. All rights reserved. Ch 8 Privacy Law and HIPAA.
HIPAA BASIC TRAINING Presented by Anderson Health Information Systems, Inc.
HIPAA PRACTICAL APPLICATION WORKSHOP Orientation Module 1B Anderson Health Information Systems, Inc.
HIPAA THE PRIVACY RULE. 2 HISTORY In 2000, many patients that were newly diagnosed with depression received free samples of anti- depressant medications.
Rhonda Anderson, RHIA, President  …is a PROCESS, not a PROJECT 2.
C HAPTER 34 Code Blue Health Sciences Edition 4. Confidentiality of sensitive information is an important issue in healthcare. Breaches of confidentiality.
HIPAA Health Insurance Portability and Accountability Act of 1996.
Prepared by The Office of the Registrar Youngstown State University February, 2009.
HIPAA: Breach Notification By: Office of University Counsel For: Jefferson IRB Continuing Education September 2014.
HIPAA Overview Why do we need a federal rule on privacy? Privacy is a fundamental right Privacy can be defined as the ability of the individual to determine.
CH 10. Confidentiality A. Confidentiality about sensitive medical information is necessary to preserve the patient’s dignity. B. In order to receive payment.
Medical Law and Ethics, Second Edition Bonnie F. Fremgen ©2006 Pearson Education, Inc. Pearson Prentice Hall Upper Saddle River, NJ HS101 Seminar.
 Health Insurance and Accountability Act Cornelius Villalon Jr.
The Health Insurance Portability and Accountability Act of 1996 “HIPAA” Public Law
HIPAA TRIVIA Do you know HIPAA?. HIPAA was created by?  The Affordable Care Act  Health Insurance companies  United States Congress  United States.
Public Health IT Privacy, Confidentiality and Security of Public Health Information This material (Comp13_Unit2) was developed Columbia University, funded.
HIPAA Training Workshop #3 Individual Rights Kaye L. Rankin Rankin Healthcare Consultants, Inc.
HIPAA Privacy Rule Training
Health Insurance Portability and Accountability Act of 1996
10 Patient Confidentiality and HIPAA
What is HIPAA? HIPAA stands for “Health Insurance Portability & Accountability Act” It was an Act of Congress passed into law in HEALTH INSURANCE.
HIPAA Administrative Simplification
HIPAA PRIVACY AWARENESS, COMPLIANCE and ENFORCEMENT
Disability Services Agencies Briefing On HIPAA
The Health Insurance Portability and Accountability Act
Compliance and Enforcement of the Privacy Rule
The Health Insurance Portability and Accountability Act
Presentation transcript:

Presented by Capture Billing and Consulting, Inc. Katie Jennings, RN and Michelle Ivanchukov, CPC, CCS-P

10/1/20152 Health Insurance Portability and Accountability Act (HIPAA) HIPAA Refresher 101 The Health Insurance Portability and Accountability Act of 1996 (HIPAA) was established to improve the efficiency and effectiveness of our healthcare system by establishing federal standards and requirements. It is an amendment to the Internal Revenue Service Code of Established federal portability requirements for all group health plans, non-discrimination requirements and restricted preexisting condition exclusion limitations. Designed to prevent inappropriate use and disclosure of individual health information and to require those organizations which use it to protect that information and their systems that store, transmit and process it.

10/1/20153 Health Insurance Portability and Accountability Act (HIPAA) Health care access, portability and renewability (requires employers and health plans to allow a new employee’s medical coverage to remain continuous without regard to pre-existing conditions) Title I: Preventing health care fraud and abuse; administrative simplification, medical liability reform (defines new requirements for privacy and security of individually identifiable patient information) Administrative simplification (reduces the administrative component of health care costs through the implementation of electronic data interchange (EDI) standards) Title II: Tax-related health provisions (standardizes the savings amount per person in a pre-tax medical savings account) Title III: Application and enforcement of group health plan requirements (broadened information on insurance provisions) Title IV: Revenue offsets (regulations on how employers can deduct company-owned life insurance premiums for income tax purposes) Title V: HIPAA Legislative Act HIPAA Public Law is composed of the following:

10/1/20154 Health Insurance Portability and Accountability Act (HIPAA) The provisions of the Administration Simplification required the Department of Health and Human Services (HHS) to adopt the following: Electronic Health Care Transactions and Data Standardization of Medical Code Sets Unique Health Identifiers (Standard Unique Employer Identifiers (EINs) and National Provider Identifiers (NPIs) Security Administrative Simplification

10/1/20155 Health Insurance Portability and Accountability Act (HIPAA) In order to maintain the privacy of health information utilizing electronic transmission, Congress incorporated mandated Federal privacy protections for individually identifiable health information. Privacy Rule: National standards for the protection of individually identifiable health information by covered entities Security Rule: National standards for protecting confidentiality, integrity and availability of electronic protected health information Administrative Simplification These rules are enforced by the Office for Civil Rights (OCR) of the HHS

10/1/20156 Health Insurance Portability and Accountability Act (HIPAA) The HIPAA Privacy and Security Rules provide specific requirements that must be followed by the following covered entities who transmit health information in electronic form: Health Care Providers Doctors, Psychologists, Dentists, Chiropractors (and their billing services) Clinics, Nursing Homes Pharmacies Health Plans Health Insurance Companies HMOs Company Health Plans Government programs (Medicare, Medicaid, Military/Veterans) Health Care Clearinghouses Entities that process and convert information they receive from another entity Business Associates Person or organization that performs certain functions or activities on behalf of a covered entity (including legal, accounting, consulting, data aggregation, accreditation) Covered Entities

According to the HHS “a major goal of the Privacy Rule is to assure that individuals’ health information is properly protected while allowing the flow of health information needed to provide and promote high quality health care and to protect the public’s health and well being”. Finalized December 28, 2000 with final modifications published August 14, 2002 Requires appropriate safeguards to protect the privacy of personal health information (protected health information [PHI]) Sets limits and conditions on the uses and disclosures that may be made of such information without patient authorization Provides patients rights concerning their health information, including ability to examine, obtain a copy and request corrections 10/1/20157 Health Insurance Portability and Accountability Act (HIPAA) HIPAA Standards for Privacy of Individually Identifiable Health Information (Privacy Rule)

10/1/20158 Health Insurance Portability and Accountability Act (HIPAA) PHI is considered individually identifiable health information held or transmitted by a covered entity or its business associate. Individually identifiable health information is any information including demographic data that relates to: The individual’s past, present or future physical or mental health or condition The provision of health care to the individual The past, present, or future payment for the provision of health care to the individual Protected Health Information (PHI)

10/1/20159 Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule limits the circumstances in which an individual’s PHI may be used or disclosed by covered entities Covered entity may not use or disclose PHI unless Covered entity may not use or disclose PHI unless : As the Privacy Rule permits or requires As the individual or personal representative authorizes use or disclosure in writing To the HHS in the event of a compliance investigation or review or enforcement action Use and Disclosure Limitations

10/1/ Health Insurance Portability and Accountability Act (HIPAA) A Covered Entity is permitted to use and disclose PHI without an individual’s authorization for the following purposes or situations: To the Individual Treatment, Payment and Health Care Operations (provider coordination of care, reimbursement) Opportunity to Agree or Object (directory of patient contact information or location in a facility, family disclosure/coordinat ion of care) Incident to an otherwise permitted use and disclosure (ex. Hospital visitor may overhear a provider discussing information with another provider in order to provide prompt and effective healthcare) Public Interest and Benefit Activities (required by law/court order, FDA, abuse, law enforcement) Limited Data Set for the purposes of research, public health or health care operations (with a data use agreement) Permitted Use and and Disclosure Disclosure

10/1/ Health Insurance Portability and Accountability Act (HIPAA) Notice of Policy Practices Use and disclosure of PHI permitted and used by the covered entity Duties to protect privacy Notice of Privacy Practices and terms to abide by Individual’s rights and grievance process if rights have been violated Point of contact for further information and to receive complaints Must distribute to each individual no later than the first service encounter, by automatic and contemporaneo us electronic response, by prompt mailing Posted on covered entity website Covered Entities must provide a notice of its Privacy Practices to include:

10/1/ Health Insurance Portability and Accountability Act (HIPAA) Guidelines vary depending on the size of the covered entity but should include some of the following solutions: Written Privacy Policies and Procedures (policy manual) Designated Privacy Official or Security Officer to designate and implement policies and procedures Workforce Training and Management Mitigation (disclosure of any harmful effect of violation of privacy policy) Data Safeguards (encryption, shredding) Complaint procedure Retaliation and Waiver Documentation and Record Retention (must maintain for at least six years after creation of record) Administrative Requirements

10/1/ Health Insurance Portability and Accountability Act (HIPAA) De-identification Individually Identifiable Health Information can be de-identified to ensure compliance and reducing risk by removing identifiers such as: Name Geographic identifiers smaller than a state (except for the first 3 digits of the zip code) Telephone or fax numbers, addresses Birth date (except year) Admission or discharge dates Social Security or Medical Record Numbers Account numbers

10/1/ Health Insurance Portability and Accountability Act (HIPAA) Enforcement and Compliance The OCR is responsible for administering and enforcing standards and may conduct complaint investigations and compliance reviews Covered Entities that fail to comply voluntarily may be subject to Civil Money Penalties Violations occurring on or after 2/18/2009:  Penalty Amount $100 to $50,000 or more per violation  Calendar Year Cap of $1,500,000  Penalties may not be imposed in certain circumstances Failure to comply was not due to willful neglect and was corrected during a 30-day period after entity knew or should have known failure to comply occurred Department of Justice has imposed a criminal penalty for failure to comply

10/1/ Health Insurance Portability and Accountability Act (HIPAA) Criminal Prosecution Violations of the Privacy Rule may be subject to criminal prosecution. A person who knowingly obtains or discloses PHI in violation of the Privacy Rule may face a criminal penalty of up to $50,000 and up to one year imprisonment. Criminal penalties increase up to $100,000 and up to five years imprisonment if wrongful conduct involves false pretenses Can increase up to $250,000 and up to 10 years imprisonment if wrongful conduct involves the intent to sell, transfer or use identifiable PHI for commercial advantage, personal gain or malicious harm

10/1/ Health Insurance Portability and Accountability Act (HIPAA) HHS Case Examples Hospital staff person left a message on a patient’s home phone answering machine failing to accommodate patient’s request that PHI communication be made via her cell or work phone. Hospital had to retrain an entire Department with Privacy Rule requirements. Complainant both an employee and patient of a hospital filed a complaint that her PHI was disclosed to her supervisor. Further investigation revealed that it was impermissible disclosure and staff was disciplined and retrained. Patient was not given access to her medical records because of an outstanding balance. Practice did not release records. Privacy Rule states that the covered entity must provide an individual access within 30 days of the request.

10/1/ Health Insurance Portability and Accountability Act (HIPAA) HIPAA Violations Found on the web… Nurses Fired Over Cell Phone Photos Of Patient – Case Referred To FBI For Possible HIPAA Violations Team 4 Uncovers HIPAA Records Violations Cignet fined $4M for HIPAA violation  Cignet Health of Prince George’s County has been fined a total of $4.3 million for alleged violations of the Health Insurance Portability and Accountability Act of The Department of Health and Human Services Office of Civil Rights alleges Cignet violated 41 patients’ rights in 2008 and 2009 by not providing them access to their medical records in a reasonable amount of time. Two to plead guilty to fraud, HIPAA violations UCLA Medical Center agrees to settle HIPAA violation charges for $865K Local psychiatrist faces federal charges in HIPAA case

10/1/ References Department of Health and Human Services: Department of Medical Assistance Services: h ttp:// Highmark Blue Cross Blue Shield: Department of Labor: