Compliance Strategies for Records Management

Slides:



Advertisements
Similar presentations
Protect Our Students Protect Ourselves
Advertisements

FERPA: Family Educational Rights and Privacy Act
HIPAA Basic Training for Privacy & Information Security Vanderbilt University Medical Center VUMC HIPAA Website:
Copyright Eastern PA EMS Council February 2003 Health Information Portability and Accountability Act It’s the law.
HIPAA Privacy Training Your Name Here. © 2004 MHM Resources Inc.2 HIPAA Background Health Insurance Portability and Accountability Act of 1996.
National Health Information Privacy and Security Week Understanding the HIPAA Privacy and Security Rule.
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
The Health Insurance Portability and Accountability Act of 1996– charged the Department of Health and Human Services (DHHS) with creating health information.
What is HIPAA? This presentation was created by The University of Arizona Privacy Office, The Office for the Responsible Conduct of Research on March 5,
1 HIPAA Education CCAC Professional Development Training September 2006 CCAC Professional Development Training September 2006.
HIPAA Privacy Rule Compliance Training for YSU April 9, 2014.
Are you ready for HIPPO??? Welcome to HIPAA
Rebecca Boughamer Ethics and Accountability in Advancement Services.
FERPA: Family Educational Rights and Privacy Act.
1 GRAND VALLEY STATE UNIVERSITY FAMILY EDUCATIONAL RIGHTS & PRIVACY ACT (FERPA) TRAINING OFFICES OF THE REGISTRAR AND UNIVERSITY COUNSEL JANUARY 20, 2009.
What is FERPA? Family Educational Rights and Privacy Act.
Family Educational Rights & Privacy Act (FERPA) An Overview for University Faculty and Staff.
FERPA The Family Educational Rights and Privacy Act.
DATA SECURITY Social Security Numbers, Credit Card Numbers, Bank Account Numbers, Personal Health Information, Student and/or Staff Personal Information,
1 FERPA and Student Privacy in Records of University Research ECURE March 1, 2005 Richard Rainsberger, Ph.D. Consultant, Education Records Law and Privacy.
Informed Consent and HIPAA Tim Noe Coordinating Center.
HIPAA What’s Said Here – Stays Here…. WHAT IS HIPAA  Health Insurance Portability and Accountability Act  Purpose is to protect clients (patients)
HIPAA Basic Training for Privacy and Information Security Vanderbilt University Medical Center VUMC HIPAA Website: HIPAA Basic.
Columbia University Medical Center Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) Privacy & Information Security Training 2009.
Protected Health Information (PHI). Privileged Communication An exchange of information between two individuals in a confidential relationship. (Examples:
FERPA at The Catholic University of America Presented by Laura Jacobs Anderson Associate Registrar Office of Enrollment Services.
HIPAA PRIVACY AND SECURITY AWARENESS.
Privacy and Security of Protected Health Information NorthPoint Health & Wellness Center 2011.
Confidentiality and Public Information Act LISD Special Education Department Training SY
FERPA Questions and Answers Lenawee Data Camps June and August, 2009.
Copyright ©2011 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved. Health Information Technology and Management Richard.
HIPAA (health insurance portability and accountability act)
FERPA: What you Need to Know The Family Educational Rights and Privacy Act & SEI.
Group 3 Angela, Rachael, Misty, Kayelee, and Krysta.
© 2009 The McGraw-Hill Companies, Inc. All rights reserved. 1 McGraw-Hill Chapter 2 The HIPAA Privacy Standards HIPAA for Allied Health Careers.
Confidentiality for Transportation Personnel  Family Educational Rights and Privacy Act (FERPA)  Kentucky Family Educational Rights and Privacy Act.
Family Educational Rights and Privacy Act (FERPA) UNION COLLEGE.
HIPAA PRACTICAL APPLICATION WORKSHOP Orientation Module 1B Anderson Health Information Systems, Inc.
HIPAA THE PRIVACY RULE. 2 HISTORY In 2000, many patients that were newly diagnosed with depression received free samples of anti- depressant medications.
Confidentiality for Foodservice.  Family Educational Rights and Privacy Act (FERPA)  Kentucky Family Educational Rights and Privacy Act  Protection.
Rhonda Anderson, RHIA, President  …is a PROCESS, not a PROJECT 2.
HIPAA LAWS.  Under the privacy rule, the patient must give consent to use his or her Protected Health Information.  Examples in which consent must be.
A Road Map to Research at Jefferson: HIPAA Privacy and Security Rules for Researchers Presented By: Privacy Officer/Office of Legal Counsel October 2015.
When Can You Redact Information Without Requesting an Attorney General Decision? Karen Hattaway Assistant Attorney General Open Records Division Views.
FERPA AND HIPAA COMPLIANCE AS COMMUNITY PARTNERS Written and presented by Nicole M. Thompson School Board Attorney, School Board of the City of Richmond.
Unit 7 Seminar.  According to Sanderson (2009), the problems with the current paper-based health record system have been well documented. The author.
Copyright © 2015 by Saunders, an imprint of Elsevier Inc. All rights reserved. Chapter 3 Privacy, Confidentiality, and Security.
Prepared by The Office of the Registrar Youngstown State University February, 2009.
HIPAA Overview Why do we need a federal rule on privacy? Privacy is a fundamental right Privacy can be defined as the ability of the individual to determine.
CONFIDENTIALITY. Three Confidentiality Laws 1.FERPA-Family Education Rights and Privacy Act (State Policy 4350: Procedures for the Collection, Maintenance.
HIPAA for Students Health Insurance Portability and Accountability Act.
HIPAA TRIVIA Do you know HIPAA?. HIPAA was created by?  The Affordable Care Act  Health Insurance companies  United States Congress  United States.
The Medical College of Georgia HIPAA Privacy Rule Orientation.
New Hire HIPAA Orientation. HIPAA Overview HIPAA is an acronym that stands for the Health Insurance Portability and Accountability Act of HIPAA.
The Health Insurance Portability and Accountability Act (HIPAA) requires Plumas County to train all employees in covered departments about the County’s.
HIPAA Privacy What Every Staff Member Needs to Know.
HIPAA Training Workshop #3 Individual Rights Kaye L. Rankin Rankin Healthcare Consultants, Inc.
Denise Chrysler, JD Director, Mid-States Region
Protect Our Students Protect Ourselves
FERPA AND HIPAA COMPLIANCE AS COMMUNITY PARTNERS
HIPAA Privacy & Security
Privacy & Confidentiality
Health Insurance Portability and Accountability Act of 1996 (HIPAA)
Disability Services Agencies Briefing On HIPAA
Family Educational Rights & Privacy Act (FERPA)
HIPAA Privacy & Security
The Health Insurance Portability and Accountability Act
Privacy & Security ABC Family Practice.
School of Medicine Orientation Information Security Training
Presentation transcript:

Compliance Strategies for Records Management Michelle Ryder

Agenda Introduction Higher Education Records Management Scenario Healthcare Records Management Q&A

Introduction BS in Business Administration; UMW MBA and MS in Healthcare Management; Marymount Marymount Advancement since 2010 Constituent Management Gift Processing Receipts / Tax Compliance Acknowledgements Data Maintenance (Ellucian) Prospect Research Prospect Reports Prospect Management Campaign Research

Higher Education Confidentiality Agreements Employees Usually held by HR and IT departments Protect the institution andconstituents of the institution Students Usually held by Manager of the student worker Certain access granted; protects the institution and constituents and the student! Example for Student Agreement

Higher Education Maintenance vs. Inquiry Marymount = Ellucian All Databases have some form of Inquiry vs. Maintenance Inquiry Access Access to view specific information through the system Maintenance Actual maintenance of data; access to change information and run reports Why does this matter? You should not give maintenance access to more than one or two individuals in a department Procedures as to who updates what are needed

Higher Education In-Office Information Privacy Credit Card Numbers PCI Compliance DO NOT keep cc numbers in office (black out) DO NOT send cc through email unless secure Prospect Files Under lock and key No medical or health information Available to prospects at any time

Higher Education Pledge Agreements Verbal vs. Written Verbal cannot be entered as a technical pledge and cannot be enforced Written pledge agreements should be kept as you keep your gift files Should specify exactly what the donor and institution have agreed on (time, contingencies, programs, etc.) Example of our Gift/Pledge Agreement

Higher Education Campaign Planning and Campaigns Campaign Consultants Interviews with Potential Donors Accounting for Pledges vs. Gifts They effect the bottom line differently Record keeping outside of the official gift numbers Excel Spreadsheets Naming Opportunities Presentation to Donor Pledge Releases Anonymous Donors

Higher Education FERPA Rights of Parents Prior Consent for disclosure of information Donor Information FAFSA Information Rights of Students Directory Information Education Records

Higher Education Scenario 1 An alumnus calls in looking for contact information for his college girlfriend. He knows her name and grad year. He would like for you to give him her phone number. What should you do?

Higher Education Scenario 2 A donor has generously worked out an agreement to donate $1 million to your Catholic University. It turns out, the donor is also a heavy supporter of Planned Parenthood. Should you continue with the agreement or turn down the gift?

Healthcare Physical Records Universal switch to digital records Kept under lock and key Need for more privacy in healthcare; break-ins, stealing, etc.

Healthcare Digital Records Requirements Now required to switch Must be on compatible devices that are password protected Confidentiality All confidentiality laws still apply to digital record keeping Patient Access Patient’s can still request to see their information at any time Websites are being created for Patient’s to login to their own accounts and access their information and request appointments Must be encrypted and password protected

Healthcare Confidentiality Agreements and Training (Optima Health) Each employee is required to sign an updated confidentiality agreement annually Each employee is required to read and sign off on compliance agreements annually Each employee is required to participate in annual webinars based on confidentiality, compliance and workplace ethics

Healthcare Computer Restrictions Insurance companies should restrict access to all organization computers Each employee should have a password and be required to logout of their system anytime they are away from their computer Passwords should be changed regularly Each employee should have independent access based on their needs Employees should only have access to individual patient files if needed

Healthcare Digital Copies / Scanning Password Protected Documents Shared Drives with access granted to individual departments Network Secure System Outside emails are secured by typing {SECURE} in subject line

Healthcare Confidential Shredding Most companies are switching to electronic record keeping systems All physical records should be shredded by an organization that specializes in confidential shredding Ex: IronMountain Records should never be placed in trashcans

Healthcare Governing body is HIPAA Healthcare HIPAA Healthcare Governing body is HIPAA “The HIPAA Privacy Rule provides federal protections for individually identifiable health information held by covered entities and their business associates and gives patients an array of rights with respect to that information. At the same time, the Privacy Rule is balanced so that it permits the disclosure of health information needed for patient care and other important purposes.” Covers rights of physicians, insurance agencies, patients, patient’s family, etc. HHS.gov

Healthcare Scenario 1 A young woman named Erin is about to attend college. Her stepmother calls your physician’s office to get copies of all needed forms to send to the school. After checking Erin’s record you see that her next of kin are only listed as her mother and father. Her stepmother is persistent. What should you do?

Healthcare Scenario 2 You work for a Health Insurance Company. In a staff meeting, someone brings up the need to streamline the process of sending payment information to patients. They want to institute an automated calling system that will notify patients of their upcoming payments. Do you see anything wrong with this? For example, what if you have an incorrect telephone number?

QUESTIONS