HIPAA PRACTICAL APPLICATION WORKSHOP Orientation Module 1B Anderson Health Information Systems, Inc.

Slides:



Advertisements
Similar presentations
HIPAA Privacy Practices. Notice A copy of the current DMH Notice must be posted at each service site where persons seeking DMH services will be able to.
Advertisements

Minimum Necessary Standard Version 1.0
Independent Contractor Orientation HIPAA What Is HIPAA? Health Insurance Portability and Accountability Act of 1996 The Health Insurance Portability.
Protecting Enrollees’ Health Information under HIPAA Presented by the Michigan Department of Civil Service Employee Benefits Division Employee Benefits.
Confidentiality and HIPAA
Copyright Eastern PA EMS Council February 2003 Health Information Portability and Accountability Act It’s the law.
COBB/DOUGLAS COMMUNITY SERVICES BOARD Confidentiality and Privacy of Consumer Information.
HIPAA Privacy Training Your Name Here. © 2004 MHM Resources Inc.2 HIPAA Background Health Insurance Portability and Accountability Act of 1996.
National Health Information Privacy and Security Week Understanding the HIPAA Privacy and Security Rule.
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
P E N N S Y L V A N I A C O A L I T I O N A G A I N S T D O M E S T I C V I O L E N C E P E N N S Y L V A N I A C O A L I T I O N A G A I N S T RAPE HIPAA.
HIPAA PRIVACY REQUIREMENTS Dana L. Thrasher Constangy, Brooks & Smith, LLC (205) ; Victoria Nemerson.
1 HIPAA Education CCAC Professional Development Training September 2006 CCAC Professional Development Training September 2006.
Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna
NAU HIPAA Awareness Training
WHAT IS HIPAA? The Health Insurance Portability and Accountability Act of 1996 (HIPAA) provides certain protections for any of your health information.
Health Insurance Portability and Accountability Act (HIPAA) Presented by: APS Healthcare Southwestern PA Health Care Quality Unit (HCQU) December 2010.
COMPLYING WITH HIPAA PRIVACY RULES Presented by: Larry Grudzien, Attorney at Law.
Jill Moore April 2013 HIPAA Update: New Rules, New Challenges.
Are you ready for HIPPO??? Welcome to HIPAA
HIPAA HIPAA Health Insurance Portability and Accountability Act of 1996.
August 10, 2001 NESNIP PRIVACY WORKGROUP HIPAA’s Minimum Necessary Standard Presented by: Mildred L. Johnson, J.D.
Walking Through the Breach Notification Process - Beginning to End HIPAA COW Presentation and Panel April 8, 2011.
Version 6.0 Approved by HIPAA Implementation Team April 14, HIPAA Learning Module The following is an educational Powerpoint presentation on the.
TELECARE CORP HIPAA AND THE AMENDMENT PROCESS Updated 11/17/09.
Notice of Privacy Practices Nebraska SNIP Privacy Subgroup July 18, 2002 Michael J. Brown, MHA, CPA Vice-President, Administrative & Regulatory Affairs,
HIPAA PRIVACY AND SECURITY AWARENESS.
“ Technology Working For People” Intro to HIPAA and Small Practice Implementation.
1 Disclosures © HIPAA Pros 2002 All rights reserved.
Confidentiality, Consents and Disclosure Recent Legal Changes and Current Issues Presented by Pam Beach, Attorney at Law.
Confidentiality and Public Information Act LISD Special Education Department Training SY
Office of the Secretary Office for Civil Rights (OCR) Indian Health Service HIPAA Training Hosted by the Aberdeen Area Office July 24, 2012.
The Implementation of HIPAA Joan M. Kiel, Ph.D., C.H.P.S. Duquesne University Pittsburgh, Pennsylvania.
Copyright ©2011 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved. Health Information Technology and Management Richard.
“HIPAA Beyond April 14, 2003” n “BUILDING HIPAA COMPLIANCE” Beyond April 14, 2003”
Computerized Networking of HIV Providers Workshop Data Security, Privacy and HIPAA: Focus on Privacy Joy L. Pritts, J.D. Assistant Research Professor Health.
HIPAA PRIVACY AND SECURITY CONFIDENTIALITY. Before we begin… Have the printed Power Point Notes pages in front of you on the left Have attachments 1 and.
HIPAA Michigan Cancer Registrars Association 2005 Annual Educational Conference Sandy Routhier.
Privacy and the Civil Commitment Process Allyson K. Tysinger Assistant Attorney General June 4-5, 2008.
© 2009 The McGraw-Hill Companies, Inc. All rights reserved. 1 McGraw-Hill Chapter 2 The HIPAA Privacy Standards HIPAA for Allied Health Careers.
Medical Law and Ethics, Third Edition Bonnie F. Fremgen Copyright ©2009 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved.
Building a Privacy Foundation. Setting the Standard for Privacy Health Insurance Portability and Accountability Act (HIPAA) Patient Bill of Rights Federal.
Health Insurance Portability and Accountability Act (HIPAA) CCAC.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
Understanding HIPAA (Health Insurandce Portability and Accountability Act)
PricewaterhouseCoopers 1 Administrative Simplification: Privacy Audioconference April 14, 2003 William R. Braithwaite, MD, PhD “Doctor HIPAA” HIPAA Today.
FleetBoston Financial HIPAA Privacy Compliance Agnes Bundy Scanlan Managing Director and Chief Privacy Officer FleetBoston Financial.
HIPAA BASIC TRAINING Presented by Anderson Health Information Systems, Inc.
HIPAA BASIC TRAINING MODULE 1C – Overview (For staff who do not generally create Protected Health Information) Anderson Health Information Systems, Inc.
Rhonda Anderson, RHIA, President  …is a PROCESS, not a PROJECT 2.
C HAPTER 34 Code Blue Health Sciences Edition 4. Confidentiality of sensitive information is an important issue in healthcare. Breaches of confidentiality.
HIPAA Privacy Rules: What Are Plan Sponsors Required to Do?
1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.
HIPAA Privacy Rule Implementation Status Report Richard M. Campanelli, J.D. Director, Office for Civil Rights Before the The Tenth National HIPAA Summit.
HIPAA Overview Why do we need a federal rule on privacy? Privacy is a fundamental right Privacy can be defined as the ability of the individual to determine.
HIPAA TRIVIA Do you know HIPAA?. HIPAA was created by?  The Affordable Care Act  Health Insurance companies  United States Congress  United States.
Disclaimer This presentation is intended only for use by Tulane University faculty, staff, and students. No copy or use of this presentation should occur.
What is HIPAA? Health Insurance Portability and Accountability Act of HIPAA is a major law primarily concentrating on the prolongation of health.
The Health Insurance Portability and Accountability Act (HIPAA) requires Plumas County to train all employees in covered departments about the County’s.
HIPAA Privacy What Every Staff Member Needs to Know.
HIPAA Training Workshop #3 Individual Rights Kaye L. Rankin Rankin Healthcare Consultants, Inc.
HIPAA Administrative Simplification
Requests to Restrict Use or Disclosure
Privacy Notice - Requirements
Paul T. Smith Davis Wright Tremaine LLP
HIPAA PRIVACY AWARENESS, COMPLIANCE and ENFORCEMENT
Disability Services Agencies Briefing On HIPAA
HIPAA Policy & Procedure Strategies
HIPAA Do’s and Don'ts: What is Really Behind Protected Health Information (PHI) and Health Care Privacy Rules Paul Sisler, Director, Information Services;
Presentation transcript:

HIPAA PRACTICAL APPLICATION WORKSHOP Orientation Module 1B Anderson Health Information Systems, Inc.

“HIPAA COMPLIANCE… …is a PROCESS, not a PROJECT

WHO SHOULD ATTEND Nursing Staff Nursing Assistants Staff from other depts. Generalized information for staff

PRESENTED Anderson Health Information Systems, Inc.

OBJECTIVES Will identify requirements for: –Notice of Privacy Practices –Personnel Designations –Minimum Necessary –What needs to be done, when and by who

OBJECTIVES -2 Will leave the workshop with information to protect the residents health information as that is your responsibility as an employee known in HIPAA as a member of the workforce. What Does HIPAA INCLUDE? PRIVACY PRACTICES –Notice of PRIVACY PRACTICES Resident RIGHTS –New Resident RIGHTS –Minimum Necessary –Minimum Necessary Policies and Procedures to use for training your staff –Privacy Official – Medical Record Designee

REFERENCE PRIVACY PRACTICES Notice of PRIVACY PRACTICES Use and Disclosures of Protected Health Information – Minimum Necessary – HIM Manual #7003 Use and Disclosures of Protected Health Information – Minimum Necessary – HIM Manual #7003

HIPAA CALENDAR You were in substantial compliance with the Privacy Rules before April 14, DOES THAT MEAN TO YOUR ORGANIZATION? –What DOES THAT MEAN TO YOUR ORGANIZATION? You now must stay in compliance. You now must stay in compliance. –Are you updating new staff in orientation? Are you holding at least annual update for all staff??? ASK FOR HELP FROM YOUR Consultant!! ASK FOR HELP FROM YOUR Consultant!!

PRIVACY

COMPONENTS OF THE RULE Notice of Privacy Practices Acknowledgment Process Minimum Necessary Authorization for Disclosure of PHI Administrative Requirements Business Associate Agreement MRD – Privacy Official

PRIVACY PRIORITIES Get to know the Rules Awareness –Are you training new staff as part of orientation? –Are you conducting or arranging for in- service for ALL staff with the HIM/Record Consultant at least annually??

PRIVACY PRIORITIES -2 Prepare Notice of Privacy Practices – given to the resident as part of the admission process. This is audited by MRD as part of the admission audit.

NOTICE OF PRIVACY PRACTICES Allows the individual control over how PHI is used and disclosed Describes practices related to use and disclosure of PHI Provide individuals with a privacy notice written in plain language

PRIVACY NOTICE -2 Notice must include: –Information regarding uses and disclosures –Explanation of individual’s privacy rights –Covered entities responsibilities under HIPAA

PRIVACY NOTICE -3 Indicates how the use and disclosure will be used for treatment, payment and operations. –How to file a complaint (Covered entity or Health and Human Services - Office for Civil Rights has been delegated as the responsible office) –Name, title and phone of contact person, privacy official –Effective date of notice

NOTICE - PROCEDURE REQUIREMENTS Post Notice at the facility, on the web Make copies available May use if Resident agrees Attempt to obtain acknowledgment of Notice of Privacy Practice -- at admit Provide notice for current residents

“SIX NEW Resident RIGHTS” Notice of Organizations “PHI” Privacy Practices Request Restrictions on Disclosures to Others of their “PHI” Request alternative means of communicating “PHI”

“SIX NEW Resident RIGHTS” -2 May inspect and get a copy of “PHI” May request Amendments to their “PHI” Must be given an accounting of organization’s disclosures of their “PHI”

ACKNOWLEDGEMENT Make good faith efforts to obtain written acknowledgment of Receipt of Notice of Privacy Practices – at time of ADMIT –“I ACKNOWLEDGE THAT I HAVE BEEN PROVIDED A COPY OF THE NOTICE OF PRIVACY PRACTICES, DATE, SIGN”

MINIMUM NECESSARY The facility shall limit the amount of PHI: –Disclosed or requested to documentation/related to protected health information that is reasonably necessary to carry out the job or fulfill the request for information. JOB DUTIES [what does this mean to you??] –To employees only to the extent they need the information to carry out their JOB DUTIES [what does this mean to you??]

MINIMUM NECESSARY -2 WHAT DOES THIS MEAN TO YOU? WHAT DOES THIS MEAN TO YOU? –Discuss those items that would be needed to know for different jobs, ie., Social Services needs access to all information that would impact the decisions re: advanced decisions for health care, transportation, family involvement health condition, etc., also as a team member she/he needs access too --- specify ….(identify additional info. needed)

MINIMUM NECESSARY -3 Examples –As a team member you would need access to the health information to make resident care plan decisions. –Certified Nursing Assistant – What information do you need to do your job?

MINIMUM NECESSARY -4 The facility shall limit the amount of PHI available to each employee –Employees shall be identified and a grid done as to what information they have available to them and under what circumstances.

MINIMUM NECESSARY -5 The facility shall limit the amount of PHI: –Used or disclosed…and only the entire record will be sent to the requestor only when needed and reasonably necessary to accomplish the request, ie., attorney requests information. –Also, all responses to requests shall consider – release of minimum necessary to carry out the specific reason for the request.

MINIMUM NECESSARY -6 Does NOT apply: –When sending to another health care provider; however, you only need to give the information that is needed! –Disclosure to the individual –Uses and disclosures made pursuant to an authorization –To Dept. of Public Health L & C, required for compliance, otherwise required by law, ie., law enforcement, public health, Office of Inspector General

PERSONNEL REQUIREMENTS

PRIVACY OFFICIAL Addressed in the Administrative Requirements 45 C.F.R –COVERED ENTITY (CE) must designate a privacy official who is responsible for the development and implementation of the privacy policies and procedures of the entity

PRIVACY OFFICIAL -2 Health Information Designee Administrator, alternate DSD – Provides training and orientation with assistance from the ‘MRD’ an the HIM Consultant HIM-CONSULTANT The AHIS HIM-CONSULTANT

PRIVACY COMPLAINTS requires Facility to –Provide a process for individuals to make complaints regarding privacy violations(d) –File complaints without fear of retaliation (g) –Designate a contact person for receiving complaints(a)(1)(ii) –Document complaints received and their disposition

PRIVACY COMPLAINTS -2 Cooperate with Federal Investigations of complaints Sanction Members of the Workforce who violate privacy(e) Mitigate to the extent feasible any harm caused by the violation( f)

PRIVACY COMPLAINTS -3 What are other complaints that are happening in the facility from your residents/family, etc., that may extend to Privacy complaints. How are they handled? Are they discussed at standup? How are complaints reported? Are complaints followed up/resolution doc?

EXERCISES Conduct exercise here…

IMPLEMENTATION STRATEGIES TOGETHER WE PROTECT PHI

IMPLEMENTATION -2 Ongoing training, and specific training to key personnel as it relates to their duties NEW EMPLOYEES

DO YOU COMPLY???