1 HIPAA Health Insurance Portability and Accountability Act Budgeting Effectively for Good Faith Compliance.

Slides:



Advertisements
Similar presentations
H = P = A = HIPAA DEFINED HIPAA … A Federal Law Created in 1996 Health
Advertisements

Presented by Elena Chan, UCSF Pharm.D. Candidate Tiffany Jew, USC Pharm.D. Candidate March 14, 2007 P HARMACEUTICAL C ONSULTANTS, I NC. P RO P HARMA HIPAA.
1 The Health Insurance Portability and Accountability Act (HIPAA) A guided tutorial for GVSU employees.
HIPAA Basics Brian Fleetham Dickinson Wright PLLC.
HIPAA: Privacy, Security, and HITECH, Oh My! Presented by Stephanie L. Ganucheau, Special Assistant Attorney General.
1. As a Florida KidCare community partner families entrust you to not only help them navigate the Florida KidCare system but to keep the information they.
HIPAA Privacy Training. 2 HIPAA Background Health Insurance Portability and Accountability Act of 1996 Copyright 2010 MHM Resources LLC.
HIPAA. What Why Who How When What Is HIPAA? Health Insurance Portability & Accountability Act of 1996.
Confidentiality and HIPAA
HIPAA Privacy Rule Training
Copyright Eastern PA EMS Council February 2003 Health Information Portability and Accountability Act It’s the law.
HIPAA Privacy Training Your Name Here. © 2004 MHM Resources Inc.2 HIPAA Background Health Insurance Portability and Accountability Act of 1996.
National Health Information Privacy and Security Week Understanding the HIPAA Privacy and Security Rule.
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
The Health Insurance Portability and Accountability Act of 1996– charged the Department of Health and Human Services (DHHS) with creating health information.
HIPAA PRIVACY REQUIREMENTS Dana L. Thrasher Constangy, Brooks & Smith, LLC (205) ; Victoria Nemerson.
HIPAA Health Insurance Portability and Accountability Act.
What is HIPAA? This presentation was created by The University of Arizona Privacy Office, The Office for the Responsible Conduct of Research on March 5,
Health Insurance Portability and Accountability Act (HIPAA)HIPAA.
Presented by the Office of the General Counsel An Overview of HIPAA.
NAU HIPAA Awareness Training
1 Louisiana Department of Health and Hospitals Basic HIPAA Privacy Training: Policies and Procedures 01/09/
TM The HIPAA Privacy Rule: Safeguarding Health Information in Research and Public Health Practice Centers for Disease Control and Prevention Beverly A.
ITEC 6324 Health Insurance Portability and Accountability (HIPAA) Act of 1996 Instructor: Dr. E. Crowley Name: Victor Wong Date: 2 Sept
HIPAA Health Insurance Portability and Accountability Act.
 Original Intent: ◦ Act passed in 1996 with two main goals: 1.Ensure individuals would be able to maintain their health insurance between jobs (the “portability”
HIPAA Privacy Rule Compliance Training for YSU April 9, 2014.
COMPLYING WITH HIPAA PRIVACY RULES Presented by: Larry Grudzien, Attorney at Law.
Are you ready for HIPPO??? Welcome to HIPAA
Privacy, Security and Compliance Concerns for Management and Boards November 15, 2013 Carolyn Heyman-Layne, Esq. 1.
Overview of HIPAA Administrative Simplification and Privacy Regulations Darrel J. Grinstead, Partner Amy B. Kiesel, Associate Hogan & Hartson L.L.P.
Health Insurance Portability Accountability Act of 1996 HIPAA for Researchers: IRB Related Issues HSC USC IRB.
Version 6.0 Approved by HIPAA Implementation Team April 14, HIPAA Learning Module The following is an educational Powerpoint presentation on the.
HIPAA Health Insurance Portability & Accountability Act of 1996.
Proprietary and confidential and may not be reproduced or distributed without the express consent of Cap Gemini Ernst & Young U.S. LLC and Ernst & Young.
HIPAA PRIVACY AND SECURITY AWARENESS.
“ Technology Working For People” Intro to HIPAA and Small Practice Implementation.
HIPAA The Privacy Rule Health Insurance Portability and Accountability Act of 1996 (HIPAA) The 104 th Congress passed the Act, Public Law ,
Privacy and Security of Protected Health Information NorthPoint Health & Wellness Center 2011.
1 HIPAA OVERVIEW ETSU. 2 What is HIPAA? Health Insurance Portability and Accountability Act.
Copyright Fleisher & Associates A HIPAA PRIMER FOR PUBLIC HEALTH PEOPLE CPHA-N Conference 2003 January 30, 2003 Presented by: Steven M. Fleisher,
Health Insurance Portability and Accountability Act (HIPAA)
Computerized Networking of HIV Providers Workshop Data Security, Privacy and HIPAA: Focus on Privacy Joy L. Pritts, J.D. Assistant Research Professor Health.
HIPAA Michigan Cancer Registrars Association 2005 Annual Educational Conference Sandy Routhier.
Medical Law and Ethics, Third Edition Bonnie F. Fremgen Copyright ©2009 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved.
Speak HIPAA Like a Native A Guide to Common HIPAA Nomenclature University of Miami Ethics Programs.
Securing Patient-Related Data: The Impact of HIPAA Module VI NUR 603 Russ McGuire.
Health Insurance Portability and Accountability Act (HIPAA) CCAC.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
Understanding HIPAA (Health Insurandce Portability and Accountability Act)
© 2013 The McGraw-Hill Companies, Inc. All rights reserved. Ch 8 Privacy Law and HIPAA.
FleetBoston Financial HIPAA Privacy Compliance Agnes Bundy Scanlan Managing Director and Chief Privacy Officer FleetBoston Financial.
HIPAA PRACTICAL APPLICATION WORKSHOP Orientation Module 1B Anderson Health Information Systems, Inc.
HIPAA THE PRIVACY RULE. 2 HISTORY In 2000, many patients that were newly diagnosed with depression received free samples of anti- depressant medications.
Copyright ©2014 by Saunders, an imprint of Elsevier Inc. All rights reserved 1 Chapter 02 Compliance, Privacy, Fraud, and Abuse in Insurance Billing Insurance.
HIPAA Privacy The Morning After Panel What do we do now? William R. Braithwaite, MD, PhD (moderator) Washington, DC Ross Hallberg, Corporate Compliance.
HIPAA Health Insurance Portability and Accountability Act of 1996.
1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.
HIPAA Overview Why do we need a federal rule on privacy? Privacy is a fundamental right Privacy can be defined as the ability of the individual to determine.
 Health Insurance and Accountability Act Cornelius Villalon Jr.
The Health Insurance Portability and Accountability Act of 1996 “HIPAA” Public Law
HIPAA TRIVIA Do you know HIPAA?. HIPAA was created by?  The Affordable Care Act  Health Insurance companies  United States Congress  United States.
The Medical College of Georgia HIPAA Privacy Rule Orientation.
HIPAA Privacy Rule Training
UNDERSTANDING WHAT HIPAA IS AND IS NOT
What is HIPAA? HIPAA stands for “Health Insurance Portability & Accountability Act” It was an Act of Congress passed into law in HEALTH INSURANCE.
HIPAA CONFIDENTIALITY
HIPAA Administrative Simplification
HIPAA PRIVACY AWARENESS, COMPLIANCE and ENFORCEMENT
Disability Services Agencies Briefing On HIPAA
Presentation transcript:

1 HIPAA Health Insurance Portability and Accountability Act Budgeting Effectively for Good Faith Compliance

2 Through HIPAA, Congress intended to: Overcome “job lock” – the reluctance of moving from one company to another for fear of losing health insurance Increase portability and access to health insurance Simplify health care administration

3 The Result of HIPAA was: Administrative Simplification = Uniformity of Electronic Transactions Standardized Electronic Transactions Highlighted the Need for: Patient Privacy Records Security

4 IMPACT Patient Privacy Records Security Significant Increases In Operating Costs U.S. Dept. of Health & Human Services estimates the industry cost for privacy compliance alone at $3.8 billion. The American Hospital Association estimates the cost of compliance at $22.5 billion over five years.

5 PENALTIES FOR NONCOMPLIANCE General Penalty for Failure to Comply – Each violation: $100. – Maximum penalty for violations per standard may not exceed $25,000. Wrongful Disclosure of Individual Health Information - Basic offense: $50,000, imprisonment of not more than one year or both. - False Pretenses: $100,000, imprisonment of not more than 5 years, or both. - Intent to Sell: $250,000, imprisonment of not more than 10 years, or both.

6 Establishing a “Good Faith” Compliance Effort Written compliance program/policies Employee training Revise vendor contracts Audit security procedures and upgrade as necessary

7 Covered Entities All health care providers and health plans are required to implement the standardized transactions and to comply with the new privacy and security rules. Employer group health plans with more than 50 participants are included.

8 Elimination of Local Codes Seven Required Standardized Transactions ProviderPayerPlan Sponsor Patient Info/ Eligibility Request (270) Response to Eligibility (271) Enrollment info (834) Authorizations & Referrals (Requesting Review 278) Authorization & Referrals (Response 278) Plan sponsors do not have to transmit information electronically. However, if they submit standard transactions 834 or 820 Payors and Providers will be required to accept such transactions Claims/Encounter (Claim 837) (Attachment 275 not yet mandated Claim/Encounter (Attachment Request 276 not yet mandated) Claim Status (Request 276) Claim Status (Response 277) Claim Payment (Remittance Advice 835) Premium PaidPremium Payment (820)

9 Protected Health Information (“PHI”) A convoluted regulatory definition: All health information created and/or received by provider, health plan, health care clearinghouse, employer, life insurer or school or university that relates to the physical or mental health or condition of an individual, the provision of health care to that person, or to the payment for that person ’ s health care, which is sufficiently specific to identify the person, that is transmitted or maintained by a covered entity in any form (orally, on paper or electronically).

10 Privacy Prohibits the USE or DISCLOSURE of PHI unless PERMITTED or REQUIRED by HIPAA

11 Patient Consents New requirements for format and content mandated. Old consent forms for treatment, payment or health care operations will not comply. New, broad-form consent now needed for peer reviews, medical training, quality assurance, etc.

12 Restricted Use of Patient Information Affects information used in patient directories. Affects consultations with and disclosures to family members. Numerous exceptions: child abuse, domestic violence, research, licensure and disciplinary actions. Note: HIPAA pre-empts state law unless state law is more restrictive, e.g. HIPAA would allow disclosure of a patient’s religious affiliation, but that is prohibited in Tennessee.

13 Written Authorization Required in Addition to Consent Any use or disclosure of Psychotherapy Notes requires written authorization. Use of PHI in marketing or fundraising activities may require written authorization.

14 Umbrella Rule Superimposed over all of the new HIPAA regulations is the concept that in using, disclosing or requesting PHI, all covered entities must make reasonable efforts to limit it to the “Minimum Necessary” Non-routine uses and disclosures will require case-by-case analysis

15 Vendor Contracts Covered Entities will be non-compliant unless they execute written agreements with their vendors which cover specific provisions concerning HIPAA compliance. -A general HIPAA compliance clause is not sufficient for contracts with Business Associates of Covered Entities. -Vendor contracts must specifically address the limited use and disclosure of PHI as well as other listed vendor obligations. - Indemnification provisions for failure to comply should be considered.

16 Notice of Privacy Practices Among the new “Patients’ Rights” created by HIPAA. Must be written in “plain language” and carefully worded. Important to include the ability to change a provider’s privacy practices. Providers may be required to comply with specific patient instructions, even if given orally or to non-medical office personnel. – e.g. sending patient information via or fax or to a specific address Additional Patients Rights include access to PHI, medical records accounting of disclosures. Computer system must be capable of creating an audit trail of all PHI disclosures and to retain records for 6 years.

17 Administrative Requirements: A Potential Budgetary Nightmare Appoint a privacy officer and complaint officer Overhaul compliance manual to require HIPAA Compliance Employee training: privacy and security awareness Institute a formal complaint mechanism Audit technical and physical safeguards Institute sanctions for failure to comply Include mitigation procedures to reduce harmful impact of known violations

18 INCREASED SECURITY OF PHI All Covered Entities must establish and maintain appropriate policies and procedures to safeguard the confidentiality of their patients’ health information. This includes: Administrative procedures Physical safeguards Technical security services and mechanisms

19 Review and Upgrade Administrative Procedures Revise written policies and procedures for each area or department (e.g., for physical security, personal security, procedural security, etc.) Require security training for all personnel Require “Chain of Trust Partner Agreements” with whom you share PHI

20 Review and Upgrade Physical Safeguards Restrict access to PHI - building/physical plant - work stations, files - computers, computer screens and printers

21 Review and Upgrade Technical Security Authentication – to verify the person transacting business electronically is in fact who they claim to be Encryption – to scramble data so it is non- recognizable Non-Repudiation – to prevent the person performing data transmission to deny that it was that person sending the data

22 Comprehensive Compliance Services Provided by Miller & Martin LLP  Phase I Package Includes: Vendor contract review and amendment Revision of written policies and procedures to include HIPAA compliance Revised patient privacy, notices, consents and authorization forms “Chain of Trust Partner Agreements” Employee training  Package Services also provided separately and additional services provided as needed

23 Joint Services Provided by Miller & Martin LLP and G.A. Sullivan Privacy procedures audits Security procedures audits Review and upgrade of computer systems for HIPAA compliance IT personnel training and assistance

24 HIPAA Practice Group  With 14 firm member representatives of each regional office, Miller & Martin’s HIPAA practice group includes attorneys who specialize in healthcare, corporate law, labor and employment, litigation and government relations.  We believe a cross-disciplinary approach will help you tackle the complexities of HIPAA in a more comprehensive and cost-effective manner.  For more information concerning the individual members of Miller & Martin’s HIPAA practice group, click on the HIPAA icon at

25 HIPAA For further information, please contact CLAY PHILLIPS ) or CHRISTIE GROT ) MILLER & MARTIN LLP