Practicing In Harmony with HIPAA The views and opinions expressed in the presentation are those of the presenter, and not necessarily official positions.

Slides:



Advertisements
Similar presentations
HIPAA for Governments & Municipalities Rebecca L. Williams, RN, JD Partner, Co-Chair of HIT/HIPAA Practice Davis Wright Tremaine LLP Seattle, WA
Advertisements

SIMPLIFYING PRIVACY: HIPAA PRIVACY STANDARDS AND RESEARCH Angela M. Vieira General Counsel Childrens Hospital and Health Center June 5, 2004.
Responding to Subpoenas and Law Enforcement Demands for PHI: An Overview Janet A. Newberg Chair, Health Law Section Felhaber Larson Fenlon & Vogt, P.A.
I.G. Subpoenas and the HIPAA Privacy Rule The views and opinions expressed in the presentation are those of the presenter, and not necessarily official.
 What is the Privacy Rule? The Standards for Privacy of Individually Identifiable Health Information (Privacy Rule) governs the use and disclosure of.
HIPPA Overview Jeffrey A. Walker Walker & Mann Laurel Street, Suite 204, Rancho Cucamonga, CA Phone: Fax:
Anne Arundel County Fire Department
Confidentiality and HIPAA
P E N N S Y L V A N I A C O A L I T I O N A G A I N S T D O M E S T I C V I O L E N C E P E N N S Y L V A N I A C O A L I T I O N A G A I N S T RAPE HIPAA.
HIPAA PRIVACY REQUIREMENTS Dana L. Thrasher Constangy, Brooks & Smith, LLC (205) ; Victoria Nemerson.
HIPAA for Lawyers Kim C. Stanger (9/11).
THE HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) (known as THE PRIVACY RULE)
North Carolina State University Health Information Privacy 4/16/03.
 Original Intent: ◦ Act passed in 1996 with two main goals: 1.Ensure individuals would be able to maintain their health insurance between jobs (the “portability”
Copyright 2006 Rubin Law Firm, LLC Drafting HIPAA Compliant Subpoenas & Discovery Presented by:RACHEL B. RUBIN Kansas Bar Association Annual Meeting June.
HEALTH INSURANCE PORTABILITY AND ACCOUNTIBILITY ACT PAUL D. FRIEDMAN, M.A., J.D. 300 W. Clarendon, Ste. 400 Phoenix, Arizona (602)
School-Based Health Centers & Confidentiality: Understanding FERPA & HIPAA Laurie Mesibov & Jill Moore UNC School of Government December 2012.
Health Insurance Portability and Accountability Act (HIPAA)
Information Sharing and Cross-System Collaboration John Petrila, J.D., LL.M. Professor, University of South Florida
Objectives  Review federal statutes (HIPAA, FERPA)  Discuss state guidelines  Review local procedures
Responding to Requests for Information Kimberly J. Ruppel Billee Lightvoet Ward Dickinson Wright PLLC.
1 Office of the General Counsel FERPA  Family Educational Rights and Privacy Act (20 U.S.C § 1232g)
HIPAA: Surrogate Decision Making and Advance Health Care Directives Carolyn Heyman-Layne, Esq. Dorsey & Whitney LLP December 20, 2007.
August 10, 2001 NESNIP PRIVACY WORKGROUP HIPAA’s Minimum Necessary Standard Presented by: Mildred L. Johnson, J.D.
Access to Mental Health Records and Related Issues Social Services Attorneys’ Conference March 10, 2006 Mark Botts School of Government, UNC.
Who Must Comply? When is a patient authorization NOT required?  As needed for the protection of federal and state elective constitutional officers and.
Medical Records in Court: Life after HIPAA North Carolina Conference of Superior Court Judges, October 2003 Presented by Jill Moore, UNC School of Government.
1 Disclosing Student Personal Information to the Queensland Police Service 1-2 July 2008 RED/EDS Business Meeting.
Army Family Advocacy Program 1 of R APR 06 Restricted Reporting Policy for Incidents of Domestic Abuse.
© 2009 The McGraw-Hill Companies, Inc. All rights reserved. 1 McGraw-Hill Chapter 5 HIPAA Enforcement HIPAA for Allied Health Careers.
Privacy, Confidentiality and Duty to Warn in School Guidance Services March 2006 Disclaimer - While the information in these slides are designed to reflect.
HIPAA The Privacy Rule Health Insurance Portability and Accountability Act of 1996 (HIPAA) The 104 th Congress passed the Act, Public Law ,
1 Disclosures © HIPAA Pros 2002 All rights reserved.
HIPAA OBJECTIVES  Define HIPAA  Define PHI  Use of PHI  Your rights  Your responsibilities.
Office of the Secretary Office for Civil Rights (OCR) Indian Health Service HIPAA Training Hosted by the Aberdeen Area Office July 24, 2012.
Privacy and Security Laws for Health Care Organizations Presented by Robert J. Scott Scott & Scott, LLP
TRICARE Health Insurance Portability & Accountability Act (HIPAA) Project HEALTH AFFAIRS TRICARE Management Activity.
Computerized Networking of HIV Providers Workshop Data Security, Privacy and HIPAA: Focus on Privacy Joy L. Pritts, J.D. Assistant Research Professor Health.
Michael R. Costa, Esq., M.P.H. Greenberg Traurig, LLP One International Place, 3 rd Floor Boston, MA (fax)
ICU and Forensics. 1.Describe information which should be consistently communicated by healthcare providers for those patients thought to be injured due.
Family Educational Rights and Privacy Act (FERPA) Also known as the Buckley Amendment Statute: 20 U.S.C. § 1232(g) Regulations: 34 CFR Part 99.
Medical Law and Ethics, Third Edition Bonnie F. Fremgen Copyright ©2009 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved.
Speak HIPAA Like a Native A Guide to Common HIPAA Nomenclature University of Miami Ethics Programs.
Health Insurance Portability and Accountability Act (HIPAA) CCAC.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
GW&T © 2006 Garfunkel, Wild & Travis, P.C. RESPONDING TO GOVERNMENT SUBPOENAS AND OTHER OFFICIAL INQUIRIES UNDER HIPAA September 25, 2006 Judith A. Eisen,
1 Tenth National HIPAA Summit HIPAA in the Real World: The Application of HIPAA to Physician Practices Gerald E. DeLoss, Esq. General Counsel Fairmont.
UMBC POLICY ON ESH MANAGEMENT & ENFORCEMENT UMBC Policy #VI
School District Records Lindsay Hale David Wheelus Assistant Attorneys General Open Records Division Views expressed are those of the presenter, do not.
HIPAA Privacy: Those Nagging Issues That Don’t Seem to Go Away Rebecca L. Williams, RN, JD Partner; Co-Chair of HIT/HIPAA Practice Group Davis Wright.
Davis Wright Tremaine LLP The Seventh National HIPAA Summit HIPAA Privacy: Privacy Rule Compliance on Public Health Activities and Research Thomas E. Jeffry,
Healthcare Privacy and Security After September 11 The HIPAA Colloquium At Harvard University August 20, 2002 Presented by: Lauren Steinfeld Privacy Consultant,
Sharing Information (FERPA) FY07 REMS Initial Grantee Meeting December 5, 2007, San Diego, CA U.S. Department of Education, Office of Safe and Drug-Free.
FERPA for the Financial Aid Office NCASFAA Fall Conference November 2012.
Board of Directors – March 24, 2016 Denise Mannon, AHFI, CHPC Corporate Compliance Officer.
HIPAA Training Workshop #2 Trainer: Kaye L. Rankin Rankin Healthcare Consultants, Inc.
Juvenile Legislative Update 2013 Confidential Records and Protected Disclosures.
HIPAA Training Workshop #3 Individual Rights Kaye L. Rankin Rankin Healthcare Consultants, Inc.
Also known as the Buckley Amendment Regulations: 34 CFR Part 99.
Health Insurance Portability and Accountability Act of 1996
Protecting access to healthcare for immigrants
10 Patient Confidentiality and HIPAA
What is HIPAA? HIPAA stands for “Health Insurance Portability & Accountability Act” It was an Act of Congress passed into law in HEALTH INSURANCE.
HIPAA CONFIDENTIALITY
HIPAA Administrative Simplification
HIPAA Pros - Disclosures
Confidential Records and Protected Disclosures
National Congress on Health Care Compliance
New School Violence Law; HIPAA Privacy Training
South Jordan City Fire Department
Presentation transcript:

Practicing In Harmony with HIPAA The views and opinions expressed in the presentation are those of the presenter, and not necessarily official positions of the United States Department of Justice.

Purpose Underscore the commitment of DOJ to facilitate covered entity compliance with HIPAA while pursuing its legitimate governmental functions Discuss the different functions of DOJ with reference to HIPAA disclosures

The Multiple Hats of DOJ Health Oversight Law Enforcement Representing Government Entities –VA Hospital, Rural Health Clinic, Government Employees Prosecuting Criminal Violations of 42 USC 1320d-6 The activity will dictate the applicable HIPAA provision which permits disclosure DOJ is NOT a covered entity

Which HIPAA Exception Permits Disclosure to DOJ? Least restrictive exception applies: Health Oversight (45 CFR § (d)) –(Essentially preserved the pre-HIPAA landscape on disclosures) Law enforcement (45 CFR § (f) Representing a government agency (45 CFR § )

Informing the Covered Entity Informing the covered entity which provision of HIPAA permits the requested disclosure May be written, may be oral

Permitted Disclosures to Law Enforcement Pursuant to Process and Required by law (f)(1) –Court Orders, Warrants, Judicial Subpoenas –Grand Jury Subpoenas –Administrative Request/Demand/Subpoena, provided that Relevant and material to legitimate L.E. inquiry Specific & limited in scope to extent reasonably practicable in light of the purpose De-identified information could not reasonably be used Covered entity can rely on representations on the face of the administrative subpoena ( (h)(2)(A))

Permitted Disclosures to Law Enforcement Other Provisions of § (f) –8 items for Identification and Location of suspects, material witness, missing person –Victims of crime, but unless required by law or process, certain limitations for victims of abuse, neglect or domestic violence –Decedents, if under suspicious circumstances –Crime on premises –Reporting crime in an emergency

One Health Oversight Note Health oversight has been discussed by Anne MacArthur of the OIG Special Note About Administrative Subpoenas used in furtherance of health oversight activity When a health oversight activity, § (d) governs – the limitations in (f)(a) are irrelevant (including restrictions on L.E. administrative subpoenas) – only apply to law enforcement activity

Some Other Special Circumstances Avert serious threat to health or safety – § (j) Specialized government functions - § (k) –National Security and Intelligence –Protective Services for President and others –Correctional institutions and other law enforcement custodial situations

Suspension of Audit Trail Disclosure A covered entity must suspend an individual’s right to an account when an oral or written request is made by a health oversight or law enforcement official for the length of time requested by the official. 45 CFR § (a)(2) Oral request (good for up to 30 days) followed by written request Document the request. “Reasonably likely to impede the agency’s activities”

Preemption of State Privacy Law A HIPAA standard, requirement or implementation specification, preempts a state law concerning the privacy of protected health information, unless the state law: –Is contrary to HIPAA, and –Relates to the privacy of Individually Identifiable Health Information, and –Is more stringent than a provision of the HIPAA medical privacy rules U.S. Constitution supremacy clause

Criminal Violations of HIPAA Privacy Rules HIPAA create a criminal violation for improper disclosure or receipt of protected health information – 42 U.S.C. 1320d-6 DOJ investigates and prosecutes criminal violations of this statute; primarily investigated by FBI 3-levels of escalating penalties keyed to egregiousness of the offense conduct Direct complaints, or referrals from HHS-OCR

Conclusion We are committed to facilitating the disclosure of protected health information for health oversight and law enforcement purposes in compliance with HIPAA We will firmly resist efforts by covered entities to constrict the exceptions which HIPAA permits We will investigate complaints of criminal HIPAA violations and prosecute where appropriate. Ian DeWaal, Senior Counsel Department of Justice, Criminal Division, Fraud Section