G REATER H OUSTON H EALTHCONNECT. HIPAA/HITECH Privacy Compliance Manual

Size: px
Start display at page:

Download "G REATER H OUSTON H EALTHCONNECT. HIPAA/HITECH Privacy Compliance Manual"

Transcription

1 G REATER H OUSTON H EALTHCONNECT HIPAA/HITECH Privacy Compliance Manual Adopted by the Board of Directors on December 14, 2011and amended on September 12, 2012 and February 27, 2013

2 TABLE OF CONTENTS Page 1. DEFINITIONS PRIVACY OFFICER POLICY INDIVIDUAL AUTHORIZATION POLICY INDIVIDUAL ACCESS TO PHI POLICY AMENDMENT OF PHI POLICY POLICY AND PROCEDURE ON RESTRICTIONS BY INDIVIDUAL OR PARTICIPANT ON THE USE OF PHI ACCOUNTING TO INDIVIDUALS POLICY AND PROCEDURE DOCUMENTATION OF HEALTH OVERSIGHT AGENCY OR LAW ENFORCEMENT REQUEST TO TEMPORARILY SUSPEND AN ACCOUNTING TO AN INDIVIDUAL POLICY FOR MAINTAINING CONFIDENTIALITY OF PHI BY GHH CONFIDENTIALITY AGREEMENT FOR GHH WORKFORCE POLICY ON USES AND DISCLOSURES AUTHORIZED BY LAW MINIMUM NECESSARY POLICY AND PROCEDURE FOR GHH WORKFORCE GHH AND PARTICIPANT WORKFORCE TRAINING POLICY COMPLIANCE WITH TEXAS NOTICE REQUIREMENTS UNSECURED PHI BREACH NOTIFICATION POLICY BREACH NOTIFICATION RISK ASSESSMENT FORM INDIVIDUAL BREACH NOTIFICATION LETTER FORM DESTRUCTION/DISPOSAL OF INDIVIDUAL PHI BY GHH CERTIFICATE/RECORD OF DESTRUCTION TELEPHONE POLICY FOR GHH POLICY FOR DISCIPLINARY ACTION FOR GHH WORKFORCE SANCTIONS RECORD COMPLAINT POLICY POLICY FOR CHANGES TO POLICIES AND PROCEDURES PARTICIPANT AGREEMENT POLICY POLICY FOR BUSINESS ASSOCIATES OF GHH HIPAA/HITECH Privacy Compliance Manual, Table of Contents Page i

3 HIPAA/HITECH PRIVACY COMPLIANCE MANUAL Greater Houston Healthconnect ( GHH or Exchange ) is a health information exchange. This Manual is designed to be used when a Participant in the Exchange has agreed to participate in the Hub Services offered by GHH. This Manual is designed to assist GHH and such Participants in complying with the Health Insurance Portability and Accountability Act of 1996 ( HIPAA ) privacy standards, the Health Information Technology for Economic and Clinical Health Act ( HITECH ) (collectively referred to as HIPAA in this Manual), and Texas laws relating to patient privacy. GHH has a separate HIPAA Security Manual. GHH firmly believes the Protected Health Information ( PHI ) of individuals must be treated with the utmost confidentiality and security. If you have any questions or concerns at any time, please feel free to contact me directly. Sincerely, Phil Beckett GHH Privacy Officer HIPAA/HITECH Privacy Compliance Manual Page 2

4 1. DEFINITIONS 1. Designated Record Set: A designated record set includes: A. Records and billing records about individuals maintained by or for a covered health care provider; or B. A group of records used, in whole or in part, by or for the covered entity = to make decisions about individuals; or C. The enrollment, payment, claims adjudications, and case or medical management record systems maintained by or for a health plan. 2. Record: The term record means any item, collection, or grouping of information that includes PHI and is maintained, collected, used, or disseminated by or for a covered entity. 3. Disclosure: applies to the external release of information outside the covered entity. 4. Exchange: is the Greater Houston Healthconnect ( GHH ). 5. HUB: means the electronic system that is made available by GHH to Participants to enable Participants to exchange PHI between Participants. 6. Health Care Operations: any of the following activities of the covered entity to the extent that the activities are related to covered functions: A. Conducting quality assessment and improvement activities, including outcomes evaluation and development of clinical guidelines, provided that the obtaining of generalizable knowledge is not the primary purpose of any studies resulting from such activities; population-based activities relating to improving health or reducing health care costs, protocol development case management and care coordination, contacting of health care providers and individuals with information about treatment alternatives; and related functions that do not include treatment; B. Reviewing the competence or qualifications of health care professionals, evaluating professional performance, health plan performance, conducting training programs in which students, trainees, or practitioners in areas of health care learn under supervision to practice or improve their skills as health care providers, training on non-health care professionals, accreditation, certification, licensing, or credentialing activities; C. Underwriting, premium rating, and other activities relating to the creation, renewal or replacement of a contract of health insurance or health benefits, and ceding, securing, or placing a contract for reinsurance of risk relating HIPAA/HITECH Privacy Compliance Manual Page 3

5 to claims for health care (including stop-loss insurance and excess of loss insurance), provided that the requirements of (g) are met, if applicable; D. Conducting or arranging for medical review, legal services, and auditing functions, including fraud and abuse detection and compliance programs; E. Business planning and development, such as conducting cost-management and planning-related analyses related to managing and operating the entity, including formulary development and administration, development or improvement of methods of payment or coverage policies; and F. Business management and general administrative activities of the entity, including, but not limited to: a. Management activities relating to implementation of and compliance with the requirements of this subchapter; b. Customer service, including the provision of data analyses for policy holders, plan sponsors, or other customers provided that PHI is not disclosed to such policy holder, plan sponsor, or customer; and c. Resolution of internal grievances. G. The sale, transfer, merger, or consolidation of all or part of the covered entity with another covered entity, or an entity that following such activity will become a covered entity and due diligence related to such activity; and H. Consistent with the applicable requirements of , creating deidentified health information or a limited data set, and fundraising for the benefit of the covered entity. 7. Individually Identifiable Health Information: is information that is a subset of health information, including demographic information collected from an individual, and: A. Is created or received by a health care provider, health plan, employer or health care clearinghouse, B. Relates to the past, present, or future physical or mental health or condition of an individual; the provision of health care to an individual; or the past, present, or future payment for the provision of health care to an individual; C. That identifies the individual; or HIPAA/HITECH Privacy Compliance Manual Page 4

6 D. With respect to which there is a reasonable basis to believe the information can be used to identify the individual. 8. Minimum Necessary Standard: When using or disclosing PHI or requesting PHI from another covered entity, GHH must make reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose of the use, disclosure, or request. 9. Participant: means a health care provider, health care entity, or payer who enters into a Participation Agreement with GHH. 10. Payment: consists of those activities undertaken by GHH to obtain or provide reimbursement for the provision of health care. These activities relate to the individual to whom health care is provided and include: A. Determinations of eligibility of coverage (including coordination of benefits or the determination of cost sharing amounts), and the adjudication or subrogation of health benefit claims; B. Billing, claims management, collection activities; C. Review of health care services with respect to medical necessity, coverage under a health plan, appropriateness of care, or justification of charges; D. Utilization review activities, including pre-certification and preauthorization of services; and E. Disclosure to consumer reporting agencies for purposes related to collection of premiums or reimbursement. Only the following information may be disclosed: Name, address, date of birth, social security number, payment history, account number, and the name and address of the health care provider or health plan. 11. Protected Health Information ( PHI ): Protected Health Information is defined as individually identifiable health information that is transmitted by electronic media, and transmitted or maintained in any other form or medium. HIPAA considers the following personal identifiers PHI: A. Name B. All geographic subdivisions smaller than state of residence C. All elements of dates (except year) for dates directly related to an individual, including birth date; and all ages over 89 and all elements of dates (including year) indicative of such age, except that such ages and elements may be aggregated into a single category of age 90 or older HIPAA/HITECH Privacy Compliance Manual Page 5

7 D. Telephone number E. Fax number F. Electronic mail addresses G. Social security number H. Record number I. Health plan beneficiary number J. Account number K. Certificate/license number L. Vehicle identification numbers such as serial and license numbers M. Device identifiers and serial number N. Web Universal Resource Locators (URLs) O. Internet Protocol (IP) address numbers P. Biometric identifiers, including finger and voice prints Q. Full Face photographic image R. Any other unique identifier, identifying number, characteristic, or code. 12. Treatment: means the provision, coordination, or management of health care and related services by one or more health care providers, including the coordination or management of health care by a health care provider with a third party; consultation between health care providers relating to an individual; or the referral of an individual for health care from one health care provider to another. 13. Use: means with respect to individually identifiable information, means the sharing, employment, application, utilization, examination, or analysis of such information within an entity that maintains such information. 14. Workforce: means employees, volunteers, and any other individual performing work for GHH or a Participant who is under the direct control of GHH or Participant (as applicable), regardless of whether paid or not. HIPAA/HITECH Privacy Compliance Manual Page 6

8 2. PRIVACY OFFICER POLICY POLICY AND PROCEDURES GHH Date issued: December 14, 2011; as amended September 12, 2012 DEPARTMENT: POSITION: 45 CFR Policy No: SUBJECT: Privacy Requests Privacy Officer Page: PURPOSE: To maintain accountability for privacy within GHH s practice. POLICY: 1. GHH designates Phil Beckett as the GHH Privacy Officer. The GHH Privacy Officer may be contacted at and all correspondence may be mailed to: Phil Beckett Greater Houston Healthconnect 1213 Hermann Drive, Suite 135 Houston, Texas Or by to Phil.Beckett@ghhconnect.org. 2. The GHH Privacy Officer will oversee GHH s Privacy Program, including: A. Developing and implementing privacy policies, in accordance with federal and Texas privacy requirements. B. Overseeing that all Participants of the Workforce who come into contact with PHI are properly trained. C. Providing Notice as required by state law. D. Mitigating the effects of all disclosures that are not compliant with federal or Texas law or that are contrary to GHH s Privacy Policies and Procedures. E. Conducting, at least annually, a review of GHH s access procedures for individuals. HIPAA/HITECH Privacy Compliance Manual Page 7

9 F. Guiding and assisting in the identification, implementation, and maintenance of privacy policies and procedures in coordination with GHH s management, GHH Participants and legal counsel. G. Reviewing all system-related information security plans in order to align security and privacy practices. H. Performing initial and periodic risk assessments or privacy audits and conducting ongoing compliance monitoring activities. I. Overseeing compliance with privacy practices and application of sanctions for failure to comply with privacy policies. J. Complying with HIPAA, HITECH and Texas law on disposal of PHI. This list provides an overview of the GHH Privacy Officer duties and is not meant to serve as an all-inclusive list. HIPAA/HITECH Privacy Compliance Manual Page 8

10 3. INDIVIDUAL AUTHORIZATION POLICY POLICY AND PROCEDURES GHH DEPARTMENT: POSITION: Cites: 45 CFR Date issued: December 14, 2011 Policy No: SUBJECT: Authorization Page: PURPOSE: To secure appropriate authorization from individuals prior to transmitting PHI through the Exchange POLICY: 1. No PHI will be transmitted through the Exchange until the individual has signed an authorization allowing his or her PHI to be transmitted through the Exchange. The authorization must have language approved by GHH. 2. The Exchange will use an opt-in process, and will not segment PHI. This means that all PHI about that individual will be available through the Exchange, including alcohol and substance abuse, HIV/Aids, mental health and psychotherapy notes, STDs, hepatitis and genetic testing. 3. Participants are responsible for complying with all state laws, THSA regulations, and HIPAA requirements governing authorization. Participants shall ensure that the authorization form incorporates all law and HIPAA requirements. Participants shall indemnify the Exchange against any and all causes of action and damages based on use by Participant of an authorization form that fails to comply with state and federal law. 4. When a Participant obtains an individual s written or electronic authorization to transmit his/her PHI through the Exchange, the Participant will be keep such authorization on file at the Participant office or facility. 5. An individual may revoke an authorization at any time, provided the revocation is in writing. GHH will stop transmitting information about that individual as soon as possible but at least within seventy-two (72) hours of receipt of written notice that an individual has revoked his/her authorization. GHH will not be liable for use or disclosure of an individual s PHI after a revocation if: GHH is not made aware that an individual revoked his/her authorization; or HIPAA/HITECH Privacy Compliance Manual Page 9

11 GHH, in good faith, based its actions upon a prior authorization, and has already acted in reliance on that authorization. APPROVAL: Privacy Officer Signature Date [Office (capacity)] Signature Date HIPAA/HITECH Privacy Compliance Manual Page 10

12 4. INDIVIDUAL ACCESS TO PHI POLICY POLICY AND PROCEDURES GHH Date issued: December 14, 2011 DEPARTMENT: POSITION: Cite(s): HITECH Act, Section 13405(e); NPRM July 10, 2010, amending 45 CFR SUBJECT: Access to PHI Section , Privacy Rule Regulations Policy No: PURPOSE: To refer all requests for access by an individual to his/her PHI to the applicable Participant(s). POLICY: 1. GHH is not a direct provider of care and does not maintain a Designated Record Set. 2. GHH acknowledges that individuals have a right to access, inspect and obtain a copy of PHI about them, with limited exclusions, for as long as the PHI is maintained in a designated record set. If GHH receives requests for access to PHI, GHH shall forward such requests, or inform requestors, to contact the applicable Participant(s). 3. Participant will inform individuals of the process for requesting access to information used and disclosed through the Exchange directly from the Participant in Participant s Notice of Privacy Practices. PROCEDURE: GHH will maintain a log record of all requests for access. HIPAA/HITECH Privacy Compliance Manual Page 11

13 5. AMENDMENT OF PHI POLICY POLICY AND PROCEDURES GHH Date issued: December 14, 2011 DEPARTMENT: POSITION: Cite(s): 45 CFR Policy No: SUBJECT: Amendment to Protected Health Information Page: PURPOSE: To clarify that only Participants will amend PHI used and disclosed to or through the Exchange. POLICY: 1. Individuals have the right to amend their PHI or information used and disclosed to or through the Exchange. Individuals must make requests for amendment in writing, directly to a Participant and must include the reason for making the request. 2. In the event that GHH receives a request for an amendment directly from an individual, GHH shall forward the written request, or refer the individual directly, to the applicable Participant(s). 3. GHH shall maintain a log of all requests for amendments made directly to GHH. HIPAA/HITECH Privacy Compliance Manual Page 12

14 6. POLICY AND PROCEDURE ON RESTRICTIONS BY INDIVIDUAL OR PARTICIPANT ON THE USE OF PHI POLICY AND PROCEDURES GHH Date issued: December 14, 2011 DEPARTMENT: POSITION: Cite(s): 45 CFR (c); 45 CFR (a) as amended by HITECH Act SUBJECT: Right of an Individual to Request Restriction of Uses and Disclosures 13405(a) and NPRM dated July 14, 2010 Policy No: A008 Page: PURPOSE: To clarify that participation with GHH is based on authorization signed by individuals agreeing to allow use and disclosure of all his/her PHI to and through the Exchange. PHI subject to restrictions will not be transferred through the Exchange by Participants. POLICY: 1. GHH will not restrict use and disclosure of an individual s PHI. 2. Because GHH will not segment PHI in the Exchange, upon notice from a Participant that he/she has agreed to a restriction, GHH will initiate procedures to shut down further use or disclose of that individual s PHI through the Exchange. 3. In the event GHH receives a request to restrict use and disclosure of PHI directly from an individual, GHH will forward the written request, or refer the patient who calls with such a request, to the Participant. 4. GHH shall maintain a log of all such requests for restrictions. HIPAA/HITECH Privacy Compliance Manual Page 13

15 7. ACCOUNTING TO INDIVIDUALS POLICY AND PROCEDURE POLICY AND PROCEDURES GHH Date issued: December 14, 2011 DEPARTMENT: POSITION: Policy No: SUBJECT: Accountings of disclosures of PHI by GHH Page: PURPOSE: To establish a policy and procedure by which individuals are informed of certain disclosures made regarding their PHI by GHH. POLICY: 1 1. Upon written request, an individual has a right to receive an accounting of certain disclosures of PHI made by GHH and its Business Associates. 2. GHH must be able to provide an accounting of all transmissions made through GHH and its Business Associates per current law. 3. GHH must provide the individual with a written accounting that includes: A. The date of the disclosure; B. The name of the entity or person who received the PHI, and if known, the address of such entity or person; C. A brief description of the PHI disclosed; and D. A brief statement of the purpose of the disclosure pursuant to the Business Associate Agreement that reasonably informs the individual of the basis for the disclosure. 4. GHH must act on an individual s request for an accounting no later than sixty (60) days after the receipt of such a request. 5. If GHH is unable to comply within the sixty (60) days of the deadline, GHH may extend the deadline by no more than thirty (30) days. GHH must notify the individual, within the initial sixty (60) days, with a written statement of the 1 Section of the HITECH Act defines an EHR as an electronic record of health-related information on an individual that is created, gathered, managed and consulted by authorized health care clinicians and staff. HIPAA/HITECH Privacy Compliance Manual Page 14

16 reasons for the delay and the date by which the accounting will be provided. GHH is entitled to only one extension. 6. GHH shall provide the first accounting to an individual in any 12-month period without charge. GHH may impose a reasonable, cost-based fee for each subsequent request for an accounting by the same individual within the 12-month period. GHH may recoup reasonable retrieval and preparation costs, as well as any mailing costs incurred. GHH shall inform the individual in advance of the fee; and provide the individual with an opportunity to withdraw or modify the request for a subsequent accounting in order to avoid or reduce the fee. 7. GHH shall maintain documentation of all accountings required by current law. 8. If a health oversight agency or law enforcement official provides a written statement that an accounting will reasonably likely impede the agency s activities, GHH may temporarily suspend an individual s right to receive an accounting. 9. If a health oversight agency or law enforcement official orally requests that the accounting of disclosures be temporarily suspended, then GHH shall: A. Document the statement, including the identity of the agency or official making the statement; B. Temporarily suspend the individual s right to receive an accounting of such disclosures; and C. Limit the temporary suspension to no longer than thirty (30) days from the date of the oral statement, unless a written statement is submitted during that time. 10. GHH should contact its attorney when such requests are made. PROCEDURE: Maintaining Documentation of Disclosure of Information 1. GHH s Privacy Officer is responsible for receiving and responding to requests for accountings. 2. GHH will document and retain the information required to be included in an accounting for disclosures of PHI. 3. GHH will document and retain the written accounting provided to the individual as required by law. Initial Processing of Individual s Request 1. Requests for an accounting from GHH must be in writing. HIPAA/HITECH Privacy Compliance Manual Page 15

17 2. GHH provides up to two (2) accountings per individual without charge, within a 12-month period. Additional accountings requested within the same 12-month period will be provided at a cost of $5.00 each. If the individual chooses to withdraw his/her request, this should be noted on the request form and signed by both the Privacy Officer and the individual. 3. Once the signed request is received, GHH s Privacy Officer will enter the request in an Accounting Request Log. 4. Upon receipt of the individual s signed written request, GHH has sixty (60) days to process the request. HIPAA/HITECH Privacy Compliance Manual Page 16

18 8. DOCUMENTATION OF HEALTH OVERSIGHT AGENCY OR LAW ENFORCEMENT REQUEST TO TEMPORARILY SUSPEND AN ACCOUNTING TO AN INDIVIDUAL On (date), (name), (badge or ID number ), with (agency), in accordance with (law or safety regulation) orally requested that Greater Houston Healthconnect ( GHH ) temporarily suspend the accounting of disclosure of (individual s name). GHH shall comply with such request until (date 30 days from the date of the oral statement). The compliance date may be extended should a written statement be submitted. HIPAA/HITECH Privacy Compliance Manual Page 17

19 9. POLICY FOR MAINTAINING CONFIDENTIALITY OF PHI BY GHH POLICY AND PROCEDURES GHH Date issued: December 14, 2011 DEPARTMENT: POSITION: Policy No: SUBJECT: Confidentiality of PHI Page: PURPOSE: To implement procedures to protect an individual s PHI. POLICY: 1. Protection of PHI: All Workforce members, directors, officers, contractors, and agents of GHH are responsible for protecting the privacy and security of all PHI that is received, whether orally or recorded, in the course of their work. An individual s PHI shall be protected from the moment it is received, used, stored, and eventually destroyed. 2. Confidentiality Agreement: Each Workforce member, full-time employee, temporary employee, consultant, contracted employee, subcontractor, vendor, and business associate shall be required to sign a confidentiality agreement or, where applicable, a business associate agreement, upon commencing work or entering into a contractual relationship with GHH. A. All Workforce members, as a condition of employment, are required to sign the confidentiality agreement. B. Copies of the agreement shall be maintained in the Workforce member s personnel file. C. Where required by HIPAA or Texas law, contractors who meet the definition of a business associate shall be required to execute a business associate or chain of trust partner agreement. All other contractors must sign a confidentiality agreement if the service involves the incidental use or disclosure of PHI. 3. Protection of PHI Hard Copies: All PHI shall be maintained in a confidential manner that prevents unauthorized disclosure, either internally or to third parties. GHH shall make all reasonable efforts to secure records containing PHI. HIPAA/HITECH Privacy Compliance Manual Page 18

20 A. All PHI in hard copy form shall be kept in locked files with the number of keys limited to Workforce members whose work requires regular access to the information. B. Documents shall be destroyed in a method that induces complete destruction of the information when the information is no longer needed. 4. Procedure if a Breach is Alleged: All breaches of confidentiality shall be reported to the Privacy Officer. A. Any Workforce member receiving an allegation of a breach of confidentiality or having knowledge or a reasonable belief that a breach of confidentiality of PHI may have occurred shall immediately notify the Privacy Officer. B. If it is determined that a breach of confidentiality of PHI has occurred, disciplinary action shall be taken in accordance with GHH s disciplinary policy. C. The GHH Privacy Officer shall retain documentation of all allegations that have been made and any action taken in a master employee HIPAA complaint file and in the Workforce member s personnel file. A separate, secure file shall be maintained for documentation concerning violations by non-employees. HIPAA/HITECH Privacy Compliance Manual Page 19

21 10. CONFIDENTIALITY AGREEMENT FOR GHH WORKFORCE I have read and understand Greater Houston Healthconnect ( GHH ) Confidentiality Policies on the use, collection, disclosure, storage, and destruction of Protected Health Information ( PHI ). I agree to follow the Confidentiality Policies and all related policies. I agree that while I am employed or have a contract with GHH, I will not reveal or disclose PHI to any person except as authorized by this policy and Texas and federal law. I further understand that my obligations to maintain the confidentiality of PHI will continue after my employment or association with GHH ends. Finally, I understand that unauthorized use or disclosure of PHI may result in disciplinary action, which may include termination of employment or contract, the imposition of civil and criminal fines pursuant to Texas and federal laws, and reporting to any appropriate professional licensing board. Employee Signature Employee Name Date I have discussed GHH s Confidentiality Policies and the appropriate use, collection, disclosure, storage, and destruction of PHI with named employee or Workforce member. I have also discussed the consequences of a breach and provided an opportunity for questions. Privacy Officer s Signature HIPAA/HITECH Privacy Compliance Manual Page 20

22 11. POLICY ON USES AND DISCLOSURES AUTHORIZED BY LAW POLICY AND PROCEDURES GHH Date issued: December 14, 2011 DEPARTMENT: POSITION: Cites: 45 CFR Policy No: SUBJECT: Uses and Disclosure Authorized by Law Page: PURPOSE: To establish a procedure for releasing PHI when required by law. POLICY: GHH shall comply with state and federal laws that require GHH to release PHI when required by law to do so. PROCEDURE: Before releasing PHI as required by law, GHH must: 1. Verify Identification A. The identity of an individual/entity shall be verified by obtaining a written documentation, statement, or representation from the requesting individual. B. The presentation of an agency identification badge, other official credential, or other proof of government status if made in person shall be sufficient to verify a public official s identity. 2. Verify Authority. Prior to releasing PHI, GHH shall make good faith efforts to verify the legal authority of any person requesting protected information to have access to the PHI. 3. Limit Disclosure to the Minimum Necessary. All disclosures of PHI shall be limited to the minimum amount of PHI necessary to achieve the intended purpose of the release. 4. Uses and Disclosures Required 2 by Law. The release must be limited to the relevant requirements of such law. 2 Disclosures must be required as opposed to permitted or authorized by law. HIPAA/HITECH Privacy Compliance Manual Page 21

23 12. MINIMUM NECESSARY POLICY AND PROCEDURE FOR GHH WORKFORCE POLICY AND PROCEDURES GHH Date issued: December 14, 2011 DEPARTMENT: POSITION: 45 CFR (b), as Policy No: A004 amended by NPRM, July 14, 2010 SUBJECT: Minimum Necessary Requirements 45 CFR (d) Page: PURPOSE: To limit use and disclosure of PHI by all Workforce members of GHH to the minimum amount of information necessary to accomplish their job duties or functions. Further, to make reasonable efforts to limit use or disclosure of, and requests for, PHI to the minimum necessary to accomplish the intended purpose. POLICY: A. Uses. 1. GHH will identify: A. The persons or classes of persons in its Workforce who need access to PHI to carry out their job duties; B. The categories or types of PHI needed; and C. The conditions appropriate to such access. 2. Workforce members access to PHI shall be solely on a need to know basis. Workforce members use or disclosure of PHI shall be limited to that PHI needed to perform job responsibilities and duties. B. Routine or Recurring Requests and Disclosures. 1. For routine and recurring requests and disclosures, GHH will develop and implement standard protocols. 2. Non-routine requests for, and disclosures of, PHI shall be reviewed by the Privacy Officer individually or designee. GHH shall develop and implement criteria designed to limit its requests for PHI to the minimum necessary to satisfy the request or accomplish the intended purpose. B. Reasonable Reliance. GHH shall rely on a GHH Participant s request for PHI as the minimum necessary for the intended disclosure. HIPAA/HITECH Privacy Compliance Manual Page 22

State of Nevada Public Employees Benefits Program. Master Plan Document for the HIPAA Privacy and Security Requirements for PEBP Health Benefits

State of Nevada Public Employees Benefits Program. Master Plan Document for the HIPAA Privacy and Security Requirements for PEBP Health Benefits State of Nevada for the Requirements for PEBP Health Benefits Plan Year 2016 July 1, 2015 June 30, 2016 www.pebp.state.nv.us (775) 684-7000 Or (800) 326-5496 Amendments Amendment Log Any amendments, changes

More information

State of Connecticut Department of Social Services HIPAA Policies and Procedures Manual

State of Connecticut Department of Social Services HIPAA Policies and Procedures Manual State of Connecticut Department of Social Services HIPAA Policies and Procedures Manual Updated 9/17/13 1 Overview As of April 14, 2003, the State of Connecticut Department of Social Services (DSS) is

More information

Breach Notification Policy

Breach Notification Policy 1. Breach Notification Team. Breach Notification Policy Ferris State University ( Ferris State ), a hybrid entity with health care components, has established a Breach Notification Team, which consists

More information

Data Breach, Electronic Health Records and Healthcare Reform

Data Breach, Electronic Health Records and Healthcare Reform Data Breach, Electronic Health Records and Healthcare Reform (This presentation is for informational purposes only and it is not intended, and should not be relied upon, as legal advice.) Overview of HIPAA

More information

HIPAA BREACH RESPONSE POLICY

HIPAA BREACH RESPONSE POLICY http://dhmh.maryland.gov/sitepages/op02.aspx (OIG) DHMH POLICY 01.03.07 Effective Date: July 22, 2014 I. EXECUTIVE SUMMARY The Department of Health and Mental Hygiene (DHMH) is committed to protecting

More information

HIPAA 100 Training Manual Table of Contents. V. A Word About Business Associate Agreements 10

HIPAA 100 Training Manual Table of Contents. V. A Word About Business Associate Agreements 10 HIPAA 100 Training Manual Table of Contents I. Introduction 1 II. Definitions 2 III. Privacy Rule 5 IV. Security Rule 8 V. A Word About Business Associate Agreements 10 CHICAGO DEPARTMENT OF PUBIC HEALTH

More information

M E M O R A N D U M. Definitions

M E M O R A N D U M. Definitions M E M O R A N D U M DATE: November 10, 2011 TO: FROM: RE: Krevolin & Horst, LLC HIPAA Obligations of Business Associates In connection with the launch of your hosted application service focused on practice

More information

Table of Contents INTRODUCTION AND PURPOSE 1

Table of Contents INTRODUCTION AND PURPOSE 1 HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996 ( HIPAA ) COMPLIANCE PROGRAM Adopted December 2008: Revised February 2009, May, 2012, and August 2013 Table of Contents INTRODUCTION AND PURPOSE

More information

This presentation focuses on the Healthcare Breach Notification Rule. First published in 2009, the final breach notification rule was finalized in

This presentation focuses on the Healthcare Breach Notification Rule. First published in 2009, the final breach notification rule was finalized in This presentation focuses on the Healthcare Breach Notification Rule. First published in 2009, the final breach notification rule was finalized in the HIPAA Omnibus Rule of 2013. As part of the American

More information

Business Associates and Breach Reporting Under HITECH and the Omnibus Final HIPAA Rule

Business Associates and Breach Reporting Under HITECH and the Omnibus Final HIPAA Rule Business Associates and Breach Reporting Under HITECH and the Omnibus Final HIPAA Rule Patricia D. King, Esq. Associate General Counsel Swedish Covenant Hospital Chicago, IL I. Business Associates under

More information

SCHOOL DISTRICT OF BLACK RIVER FALLS HIPAA PRIVACY AND SECURITY POLICY

SCHOOL DISTRICT OF BLACK RIVER FALLS HIPAA PRIVACY AND SECURITY POLICY SCHOOL DISTRICT OF BLACK RIVER FALLS HIPAA PRIVACY AND SECURITY POLICY 1 School Board Policy 523.5 The School District of Black River Falls ( District ) is committed to compliance with the health information

More information

Business Associate Agreement

Business Associate Agreement Business Associate Agreement This Agreement is entered into as of ("Effective Date"), between ( Covered Entity ), and ( Business Associate ). RECITALS WHEREAS, Business Associate provides services on behalf

More information

The Health and Benefit Trust Fund of the International Union of Operating Engineers Local Union No. 94-94A-94B, AFL-CIO. Notice of Privacy Practices

The Health and Benefit Trust Fund of the International Union of Operating Engineers Local Union No. 94-94A-94B, AFL-CIO. Notice of Privacy Practices The Health and Benefit Trust Fund of the International Union of Operating Section 1: Purpose of This Notice Notice of Privacy Practices Effective as of September 23, 2013 THIS NOTICE DESCRIBES HOW MEDICAL

More information

Model Business Associate Agreement

Model Business Associate Agreement Model Business Associate Agreement Instructions: The Texas Health Services Authority (THSA) has developed a model BAA for use between providers (Covered Entities) and HIEs (Business Associates). The model

More information

CREATIVE SOLUTIONS IN HEALTHCARE, INC. Privacy Policy

CREATIVE SOLUTIONS IN HEALTHCARE, INC. Privacy Policy CREATIVE SOLUTIONS IN HEALTHCARE, INC. Privacy Policy Amended as of February 12, 2010 on the authority of the HIPAA Privacy Officer for Creative Solutions in Healthcare, Inc. TABLE OF CONTENTS ARTICLE

More information

Everett School Employee Benefit Trust. Reportable Breach Notification Policy HIPAA HITECH Rules and Washington State Law

Everett School Employee Benefit Trust. Reportable Breach Notification Policy HIPAA HITECH Rules and Washington State Law Everett School Employee Benefit Trust Reportable Breach Notification Policy HIPAA HITECH Rules and Washington State Law Introduction The Everett School Employee Benefit Trust ( Trust ) adopts this policy

More information

Statement of Policy. Reason for Policy

Statement of Policy. Reason for Policy Table of Contents Statement of Policy 2 Reason for Policy 2 HIPAA Liaison 2 Individuals and Entities Affected by Policy 2 Who Should Know Policy 3 Exclusions 3 Website Address for Policy 3 Definitions

More information

Business Associate Agreement

Business Associate Agreement This Business Associate Agreement Is Related To and a Part of the Following Underlying Agreement: Effective Date of Underlying Agreement: Vendor: Business Associate Agreement This Business Associate Agreement

More information

HIPAA Policy, Protection, and Pitfalls ARTHUR J. GALLAGHER & CO. BUSINESS WITHOUT BARRIERS

HIPAA Policy, Protection, and Pitfalls ARTHUR J. GALLAGHER & CO. BUSINESS WITHOUT BARRIERS HIPAA Policy, Protection, and Pitfalls Overview HIPAA Privacy Basics What s covered by HIPAA privacy rules, and what isn t? Interlude on the Hands-Off Group Health Plan When does this exception apply,

More information

Business Associate Agreement Involving the Access to Protected Health Information

Business Associate Agreement Involving the Access to Protected Health Information School/Unit: Rowan University School of Osteopathic Medicine Vendor: Business Associate Agreement Involving the Access to Protected Health Information This Business Associate Agreement ( BAA ) is entered

More information

HIPAA AND MEDICAID COMPLIANCE POLICIES AND PROCEDURES

HIPAA AND MEDICAID COMPLIANCE POLICIES AND PROCEDURES SALISH BHO HIPAA AND MEDICAID COMPLIANCE POLICIES AND PROCEDURES Policy Name: HIPAA BREACH NOTIFICATION REQUIREMENTS Policy Number: 5.16 Reference: 45 CFR Parts 164 Effective Date: 03/2016 Revision Date(s):

More information

HIPAA BUSINESS ASSOCIATE AGREEMENT

HIPAA BUSINESS ASSOCIATE AGREEMENT HIPAA BUSINESS ASSOCIATE AGREEMENT This HIPAA Business Associate Agreement ("BA AGREEMENT") supplements and is made a part of any and all agreements entered into by and between The Regents of the University

More information

Guidance Specifying Technologies and Methodologies DEPARTMENT OF HEALTH AND HUMAN SERVICES

Guidance Specifying Technologies and Methodologies DEPARTMENT OF HEALTH AND HUMAN SERVICES DEPARTMENT OF HEALTH AND HUMAN SERVICES 45 CFR PARTS 160 and 164 Guidance Specifying the Technologies and Methodologies That Render Protected Health Information Unusable, Unreadable, or Indecipherable

More information

Reporting of Security Breach of Protected Health Information including Personal Health Information 3364-100-90-15 Hospital Administration

Reporting of Security Breach of Protected Health Information including Personal Health Information 3364-100-90-15 Hospital Administration Name of Policy: Policy Number: Department: Reporting of Security Breach of Protected Health Information including Personal Health Information 3364-100-90-15 Hospital Administration Approving Officer: Interim

More information

Test Procedure for 170.302 (w) Optional. Accounting of Disclosures

Test Procedure for 170.302 (w) Optional. Accounting of Disclosures Test Procedure for 170.302 (w) Optional. Accounting of Disclosures This document describes the test procedure for evaluating conformance of complete EHRs or EHR modules 1 to the certification criteria

More information

HIPAA and the HITECH Act Privacy and Security of Health Information in 2009

HIPAA and the HITECH Act Privacy and Security of Health Information in 2009 HIPAA and the HITECH Act Privacy and Security of Health Information in 2009 What is HIPAA? Health Insurance Portability & Accountability Act of 1996 Effective April 13, 2003 Federal Law HIPAA Purpose:

More information

ADMINISTRATIVE REGULATION EFFECTIVE DATE: 1/1/2016

ADMINISTRATIVE REGULATION EFFECTIVE DATE: 1/1/2016 Page 1 of 9 CITY OF CHESAPEAKE, VIRGINIA NUMBER: 2.62 ADMINISTRATIVE REGULATION EFFECTIVE DATE: 1/1/2016 SUPERCEDES: N/A SUBJECT: HUMAN RESOURCES DEPARTMENT CITY OF CHESAPEAKE EMPLOYEE/RETIREE GROUP HEALTH

More information

Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Standards. and. Privacy Policies and Procedures. for. Birkam Health Center

Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Standards. and. Privacy Policies and Procedures. for. Birkam Health Center Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Standards and Privacy Policies and Procedures for Birkam Health Center Ferris State University Table of Contents Introduction...

More information

INDIANA UNIVERSITY SCHOOL OF OPTOMETRY HIPAA COMPLIANCE PLAN TABLE OF CONTENTS. I. Introduction 2. II. Definitions 3

INDIANA UNIVERSITY SCHOOL OF OPTOMETRY HIPAA COMPLIANCE PLAN TABLE OF CONTENTS. I. Introduction 2. II. Definitions 3 INDIANA UNIVERSITY SCHOOL OF OPTOMETRY HIPAA COMPLIANCE PLAN TABLE OF CONTENTS I. Introduction 2 II. Definitions 3 III. Program Oversight and Responsibilities 4 A. Structure B. Compliance Committee C.

More information

The ReHabilitation Center. 1439 Buffalo Street. Olean. NY. 14760

The ReHabilitation Center. 1439 Buffalo Street. Olean. NY. 14760 Procedure Name: HITECH Breach Notification The ReHabilitation Center 1439 Buffalo Street. Olean. NY. 14760 Purpose To amend The ReHabilitation Center s HIPAA Policy and Procedure to include mandatory breach

More information

Test Procedure for 170.314(d)(9) Optional Accounting of disclosures

Test Procedure for 170.314(d)(9) Optional Accounting of disclosures Test Procedure for 170.314(d)(9) Optional Accounting of disclosures This document describes the test procedure for evaluating conformance of complete EHRs or EHR modules to the certification criteria defined

More information

SDC-League Health Fund

SDC-League Health Fund SDC-League Health Fund 1501 Broadway, 17 th Floor New York, NY 10036 Tel: 212-869-8129 Fax: 212-302-6195 E-mail: health@sdcweb.org NOTICE OF PRIVACY PRACTICES THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION

More information

Heather L. Hughes, J.D. HIPAA Privacy Officer U.S. Legal Support, Inc. hhughes@uslegalsupport.com www.uslegalsupport.com

Heather L. Hughes, J.D. HIPAA Privacy Officer U.S. Legal Support, Inc. hhughes@uslegalsupport.com www.uslegalsupport.com Heather L. Hughes, J.D. HIPAA Privacy Officer U.S. Legal Support, Inc. hhughes@uslegalsupport.com www.uslegalsupport.com HIPAA Privacy Rule Sets standards for confidentiality and privacy of individually

More information

POLICY AND PROCEDURE MANUAL

POLICY AND PROCEDURE MANUAL Pennington Biomedical POLICY NO. 412.22 POLICY AND PROCEDURE MANUAL Origin Date: 02/04/2013 Impacts: ALL PERSONNEL Effective Date: 03/17/2014 Subject: HIPAA BREACH NOTIFICATION Last Revised: Source: LEGAL

More information

Five Rivers Medical Center, Inc. 2801 Medical Center Drive Pocahontas, AR 72455. Notification of Security Breach Policy

Five Rivers Medical Center, Inc. 2801 Medical Center Drive Pocahontas, AR 72455. Notification of Security Breach Policy Five Rivers Medical Center, Inc. 2801 Medical Center Drive Pocahontas, AR 72455 Notification of Security Breach Policy Purpose: This policy has been adopted for the purpose of complying with the Health

More information

GLENN COUNTY HEALTH AND HUMAN SERVICES AGENCY. HIPAA Policies and Procedures 06/30/2014

GLENN COUNTY HEALTH AND HUMAN SERVICES AGENCY. HIPAA Policies and Procedures 06/30/2014 GLENN COUNTY HEALTH AND HUMAN SERVICES AGENCY HIPAA Policies and Procedures 06/30/2014 Glenn County Health and Human Services Agency HIPAA Policies and Procedures TABLE OF CONTENTS HIPAA Policy Number

More information

HIPAA Privacy Rule Policies and Procedures

HIPAA Privacy Rule Policies and Procedures County of Sacramento Health Insurance Portability and Accountability Act HIPAA Privacy Rule Policies and Procedures Issue Date: April 14, 2003 Effective Date: April 14, 2003 Revised Date: September 23,

More information

Barnes & Thornburg LLP HIPAA Update: HITECH Act Breach Notification Rule

Barnes & Thornburg LLP HIPAA Update: HITECH Act Breach Notification Rule HEALTHCARE October 2009 Barnes & Thornburg LLP HIPAA Update: HITECH Act Breach Notification Rule This HIPAA Update provides a detailed description of the new breach notification requirements for HIPAA

More information

HIPAA Privacy & Breach Notification Training for System Administration Business Associates

HIPAA Privacy & Breach Notification Training for System Administration Business Associates HIPAA Privacy & Breach Notification Training for System Administration Business Associates Barbara M. Holthaus privacyofficer@utsystem.edu Office of General Counsel University of Texas System April 10,

More information

HIPAA Privacy Breach Notification Regulations

HIPAA Privacy Breach Notification Regulations Technical Bulletin Issue 8 2009 HIPAA Privacy Breach Notification Regulations On August 24, 2009 Health and Human Services (HHS) issued interim final regulations implementing the HIPAA Privacy Breach Notification

More information

HIPAA. Privacy and Security Frequently Asked Questions for Employers. Gallagher Benefit Services, Inc.

HIPAA. Privacy and Security Frequently Asked Questions for Employers. Gallagher Benefit Services, Inc. 2013 HIPAA Privacy and Security Frequently Asked Questions for Employers Gallagher Benefit Services, Inc. Disclaimer We share this information with our clients and friends for general informational purposes

More information

HIPAA 101: Privacy and Security Basics

HIPAA 101: Privacy and Security Basics HIPAA 101: Privacy and Security Basics Purpose This document provides important information about Kaiser Permanente policies and state and federal laws for protecting the privacy and security of individually

More information

COMPLIANCE ALERT 10-12

COMPLIANCE ALERT 10-12 HAWAII HEALTH SYSTEMS C O R P O R A T I O N "Touching Lives Every Day COMPLIANCE ALERT 10-12 HIPAA Expansion under the American Recovery and Reinvestment Act of 2009 The American Recovery and Reinvestment

More information

CMA BUSINESS ASSOCIATE AGREEMENT WITH CMA MEMBERS

CMA BUSINESS ASSOCIATE AGREEMENT WITH CMA MEMBERS CMA BUSINESS ASSOCIATE AGREEMENT WITH CMA MEMBERS Dear Physician Member: Thank you for contacting the California Medical Association and thank you for your membership. In order to advocate on your behalf,

More information

BUSINESS ASSOCIATE AGREEMENT HIPAA Protected Health Information

BUSINESS ASSOCIATE AGREEMENT HIPAA Protected Health Information BUSINESS ASSOCIATE AGREEMENT HIPAA Protected Health Information I. PREAMBLE ( Covered Entity ) and ( Business Associate ) (jointly the Parties ) wish to enter into an Agreement to comply with the requirements

More information

Notice of Privacy Practices

Notice of Privacy Practices Notice of Privacy Practices This notice describes how medical information about you may be used and disclosed and how you can get access to this information. Please review it carefully. This Notice of

More information

AVE MARIA UNIVERSITY HIPAA PRIVACY NOTICE

AVE MARIA UNIVERSITY HIPAA PRIVACY NOTICE AVE MARIA UNIVERSITY HIPAA PRIVACY NOTICE This Notice of Privacy Practices describes the legal obligations of Ave Maria University, Inc. (the plan ) and your legal rights regarding your protected health

More information

BREVIUM HIPAA BUSINESS ASSOCIATE TERMS AND CONDITIONS

BREVIUM HIPAA BUSINESS ASSOCIATE TERMS AND CONDITIONS BREVIUM HIPAA BUSINESS ASSOCIATE TERMS AND CONDITIONS The following HIPAA Business Associate Terms and Conditions (referred to hereafter as the HIPAA Agreement ) are part of the Brevium Software License

More information

BUSINESS ASSOCIATE AGREEMENT BETWEEN LEWIS & CLARK COLLEGE AND ALLEGIANCE BENEFIT PLAN MANAGEMENT, INC. I. PREAMBLE

BUSINESS ASSOCIATE AGREEMENT BETWEEN LEWIS & CLARK COLLEGE AND ALLEGIANCE BENEFIT PLAN MANAGEMENT, INC. I. PREAMBLE BUSINESS ASSOCIATE AGREEMENT BETWEEN LEWIS & CLARK COLLEGE AND ALLEGIANCE BENEFIT PLAN MANAGEMENT, INC. I. PREAMBLE Lewis & Clark College and Allegiance Benefit Plan Management, Inc., (jointly the Parties

More information

HHS announces sweeping changes to the HIPAA Privacy and Security Rules in the final HIPAA Omnibus Rule

HHS announces sweeping changes to the HIPAA Privacy and Security Rules in the final HIPAA Omnibus Rule JANUARY 23, 2013 HHS announces sweeping changes to the HIPAA Privacy and Security Rules in the final HIPAA Omnibus Rule By Linn Foster Freedman, Kathryn M. Sylvia, Lindsay Maleson, and Brooke A. Lane On

More information

Gaston County HIPAA Manual

Gaston County HIPAA Manual Gaston County HIPAA Manual Includes Gaston County IT Manual Action Date Reviewed and Revised December 2012 Gaston County HIPAA Policy Manual has be updated and combined with the Gaston County IT Manual.

More information

HHS Finalizes HIPAA Privacy and Data Security Rules, Including Stricter Rules for Breaches of Unsecured PHI

HHS Finalizes HIPAA Privacy and Data Security Rules, Including Stricter Rules for Breaches of Unsecured PHI January 23, 2013 HHS Finalizes HIPAA Privacy and Data Security Rules, Including Stricter Rules for Breaches of Unsecured PHI Executive Summary HHS has issued final regulations that address recent legislative

More information

UNDERSTANDING THE HIPAA/HITECH BREACH NOTIFICATION RULE 2/25/14

UNDERSTANDING THE HIPAA/HITECH BREACH NOTIFICATION RULE 2/25/14 UNDERSTANDING THE HIPAA/HITECH BREACH NOTIFICATION RULE 2/25/14 RULES Issued August 19, 2009 Requires Covered Entities to notify individuals of a breach as well as HHS without reasonable delay or within

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT THIS BUSINESS ASSOCIATE AGREEMENT ( Agreement ) is entered into by and between (the Covered Entity ), and Iowa State Association of Counties (the Business Associate ). RECITALS

More information

New HIPAA Breach Notification Rule: Know Your Responsibilities. Loudoun Medical Group Spring 2010

New HIPAA Breach Notification Rule: Know Your Responsibilities. Loudoun Medical Group Spring 2010 New HIPAA Breach Notification Rule: Know Your Responsibilities Loudoun Medical Group Spring 2010 Health Information Technology for Economic and Clinical Health Act (HITECH) As part of the Recovery Act,

More information

UNIVERSITY HOSPITAL POLICY

UNIVERSITY HOSPITAL POLICY SUBJECT: COMPLIANCE AND PRIVACY UNIVERSITY HOSPITAL POLICY TITLE: CODING: 831-200-958 ADOPTED: July 1, 2013 DISCLOSURES OF PERSONALLY IDENTIFIABLE HEALTH INFORMATION TO BUSINESS ASSOCIATES AMENDED/ REVIEWED:

More information

STANDARD ADMINISTRATIVE PROCEDURE

STANDARD ADMINISTRATIVE PROCEDURE STANDARD ADMINISTRATIVE PROCEDURE 16.99.99.M0.26 Investigation and Response to Breach of Unsecured Protected Health Information (HITECH) Approved October 27, 2014 Next scheduled review: October 27, 2019

More information

ELKIN & ASSOCIATES, LLC. HIPAA Privacy Policy and Procedures INTRODUCTION

ELKIN & ASSOCIATES, LLC. HIPAA Privacy Policy and Procedures INTRODUCTION ELKIN & ASSOCIATES, LLC HIPAA Privacy Policy and Procedures INTRODUCTION The Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations restrict a Covered Entity

More information

HIPAA POLICIES & PROCEDURES AND ADMINISTRATIVE FORMS TABLE OF CONTENTS

HIPAA POLICIES & PROCEDURES AND ADMINISTRATIVE FORMS TABLE OF CONTENTS HIPAA POLICIES & PROCEDURES AND ADMINISTRATIVE FORMS TABLE OF CONTENTS 1. HIPAA Privacy Policies & Procedures Overview (Policy & Procedure) 2. HIPAA Privacy Officer (Policy & Procedure) 3. Notice of Privacy

More information

NACHC Issue Brief Changes to the Health Insurance Portability and Accountability Act Included in ARRA. March 2010

NACHC Issue Brief Changes to the Health Insurance Portability and Accountability Act Included in ARRA. March 2010 NACHC Issue Brief Changes to the Health Insurance Portability and Accountability Act Included in ARRA March 2010 Prepared By: Marisa Guevara and Marcie H. Zakheim Feldesman Tucker Leifer Fidell, LLP 2001

More information

BUSINESS ASSOCIATE AGREEMENT Tribal Contract

BUSINESS ASSOCIATE AGREEMENT Tribal Contract DEPARTMENT OF HEALTH SERVICES Division of Enterprise Services F-00714 (08/2013) STATE OF WISCONSIN BUSINESS ASSOCIATE AGREEMENT Tribal Contract This Business Associate Agreement is made between the Wisconsin

More information

Updated HIPAA Regulations What Optometrists Need to Know Now. HIPAA Overview

Updated HIPAA Regulations What Optometrists Need to Know Now. HIPAA Overview Updated HIPAA Regulations What Optometrists Need to Know Now The U.S. Department of Health & Human Services Office for Civil Rights recently released updated regulations regarding the Health Insurance

More information

SaaS. Business Associate Agreement

SaaS. Business Associate Agreement SaaS Business Associate Agreement This Business Associate Agreement ( BA Agreement ) becomes effective pursuant to the terms of Section 5 of the End User Service Agreement ( EUSA ) between Customer ( Covered

More information

HIPAA 101. March 18, 2015 Webinar

HIPAA 101. March 18, 2015 Webinar HIPAA 101 March 18, 2015 Webinar Agenda Acronyms to Know HIPAA Basics What is HIPAA and to whom does it apply? What is protected by HIPAA? Privacy Rule Security Rule HITECH Basics Breaches and Responses

More information

UNIVERSITY PHYSICIANS OF BROOKLYN, INC. POLICY AND PROCEDURE. No: Supersedes Date: Distribution: Issued by:

UNIVERSITY PHYSICIANS OF BROOKLYN, INC. POLICY AND PROCEDURE. No: Supersedes Date: Distribution: Issued by: UNIVERSITY PHYSICIANS OF BROOKLYN, INC. POLICY AND PROCEDURE Subject: ACCOUNTING OF DISCLOSURES Page 1 of 4 No: Prepared by: Shoshana Milstein Original Issue Date: NEW Reviewed by: HIPAA Policy & Procedure

More information

Salt Lake Community College Employee Health Care Benefits Plan Notice of Privacy Practices

Salt Lake Community College Employee Health Care Benefits Plan Notice of Privacy Practices THIS NOTICE DESCRIBES HOW HEALTH INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY. Date: June 1, 2014 Salt Lake Community College

More information

Graphic Communications National Health and Welfare Fund. Notice of Privacy Practices

Graphic Communications National Health and Welfare Fund. Notice of Privacy Practices Notice of Privacy Practices Section 1: Purpose of This Notice and Effective Date THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION.

More information

HIPAA Privacy and Security Rules: A Refresher. Marilyn Freeman, RHIA California Area HIPAA Coordinator California Area HIM Consultant

HIPAA Privacy and Security Rules: A Refresher. Marilyn Freeman, RHIA California Area HIPAA Coordinator California Area HIM Consultant HIPAA Privacy and Security Rules: A Refresher Marilyn Freeman, RHIA California Area HIPAA Coordinator California Area HIM Consultant Objectives Provide overview of Health insurance Portability and Accountability

More information

Health Partners HIPAA Business Associate Agreement

Health Partners HIPAA Business Associate Agreement Health Partners HIPAA Business Associate Agreement This HIPAA Business Associate Agreement ( Agreement ) by and between Health Partners of Philadelphia, Inc., the Covered Entity (herein referred to as

More information

SCHOOL DISTRICT OF BLACK RIVER FALLS HIPAA PRIVACY AND SECURITY POLICY

SCHOOL DISTRICT OF BLACK RIVER FALLS HIPAA PRIVACY AND SECURITY POLICY SCHOOL DISTRICT OF BLACK RIVER FALLS HIPAA PRIVACY AND SECURITY POLICY School Board Policy 523.5 The School District of Black River Falls ( District ) is committed to compliance with the health information

More information

NCHICA HITECH Act Breach Notification Risk Assessment Tool. Prepared by the NCHICA Privacy, Security & Legal Officials Workgroup

NCHICA HITECH Act Breach Notification Risk Assessment Tool. Prepared by the NCHICA Privacy, Security & Legal Officials Workgroup NCHICA HITECH Act Breach Notification Risk Assessment Tool Prepared by the NCHICA Privacy, Security & Legal Officials Workgroup NORTH CAROLINA HEALTHCARE INFORMATION AND COMMUNICATIONS ALLIANCE, INC August

More information

Winthrop-University Hospital

Winthrop-University Hospital Winthrop-University Hospital Use of Patient Information in the Conduct of Research Activities In accordance with 45 CFR 164.512(i), 164.512(a-c) and in connection with the implementation of the HIPAA Compliance

More information

Connecticut Carpenters Health Fund Privacy Notice

Connecticut Carpenters Health Fund Privacy Notice Connecticut Carpenters Health Fund Privacy Notice THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

More information

Connecticut Pipe Trades Health Fund Privacy Notice. 2013 Restatement

Connecticut Pipe Trades Health Fund Privacy Notice. 2013 Restatement Connecticut Pipe Trades Health Fund Privacy Notice 2013 Restatement Section 1: Purpose of This Notice and Effective Date THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED

More information

HIPAA PRIVACY POLICY FOR OPTICAL LABS TABLE OF CONTENTS. Exhibit B Notice of Privacy Practices pages B-1 to B-4

HIPAA PRIVACY POLICY FOR OPTICAL LABS TABLE OF CONTENTS. Exhibit B Notice of Privacy Practices pages B-1 to B-4 HIPAA PRIVACY POLICY FOR OPTICAL LABS TABLE OF CONTENTS HIPAA Privacy Policy pages 2 to 12 Exhibit A HIPAA Privacy Regulations pages A-1 to A-89 Exhibit B Notice of Privacy Practices pages B-1 to B-4 Exhibit

More information

FirstCarolinaCare Insurance Company Business Associate Agreement

FirstCarolinaCare Insurance Company Business Associate Agreement FirstCarolinaCare Insurance Company Business Associate Agreement THIS BUSINESS ASSOCIATE AGREEMENT ("Agreement"), is made and entered into as of, 20 (the "Effective Date") between FirstCarolinaCare Insurance

More information

Effective Date: March 23, 2016

Effective Date: March 23, 2016 AIG COMPANIES Effective Date: March 23, 2016 HIPAA NOTICE OF PRIVACY PRACTICES THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION.

More information

Section C: Data Use Agreement. Illinois Department of Healthcare and Family Services. And DATA USE AGREEMENT

Section C: Data Use Agreement. Illinois Department of Healthcare and Family Services. And DATA USE AGREEMENT Section C: Data Use Agreement Illinois Department of Healthcare and Family Services And DATA USE AGREEMENT This Data Use Agreement (the Agreement ) is effective as of (the Agreement Effective Date ) by

More information

HIPAA-P06 Use and Disclosure of De-identified Data and Limited Data Sets

HIPAA-P06 Use and Disclosure of De-identified Data and Limited Data Sets HIPAA-P06 Use and Disclosure of De-identified Data and Limited Data Sets FULL POLICY CONTENTS Scope Policy Statement Reason for Policy Definitions ADDITIONAL DETAILS Web Address Forms Related Information

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement ( Agreement ) by and between (hereinafter known as Covered Entity ) and Office Ally, LLC. (hereinafter known as Business Associate ), and

More information

HIPAA Policies and Procedures

HIPAA Policies and Procedures HIPAA Policies and Procedures William T. Chen, MD, Inc. General Rule 164.502 A Covered Entity may not use or disclose PHI except as permitted or required by the privacy regulations. Permitted Disclosures:

More information

ARKANSAS OFFICE OF HEALTH INFORMATION TECHNOLOGY (OHIT) PRIVACY POLICIES

ARKANSAS OFFICE OF HEALTH INFORMATION TECHNOLOGY (OHIT) PRIVACY POLICIES ARKANSAS OFFICE OF HEALTH INFORMATION TECHNOLOGY (OHIT) PRIVACY POLICIES OHIT wishes to express its gratitude to Connecting for Health and the Markel Foundation for their work in developing the Common

More information

HIPAA PRIVACY POLICY AND PROCEDURES FOR PROTECTED HEALTH INFORMATION

HIPAA PRIVACY POLICY AND PROCEDURES FOR PROTECTED HEALTH INFORMATION HIPAA PRIVACY POLICY AND PROCEDURES FOR PROTECTED HEALTH INFORMATION HILLSDALE COLLEGE HEALTH AND WELLNESS CENTER Policy Preamble This privacy policy ( Policy ) is designed to address the Use and Disclosure

More information

HIPAA Data Use Agreement Policy R&G Template Updated for Omnibus Rule HIPAA DATE USE AGREEMENT 1

HIPAA Data Use Agreement Policy R&G Template Updated for Omnibus Rule HIPAA DATE USE AGREEMENT 1 HIPAA DATE USE AGREEMENT 1 This Data Use Agreement (the "Agreement") is effective as of (the "Agreement Effective Date") by and between ("Covered Entity") and ("Data User"). RECITALS WHEREAS, Covered Entity

More information

BUSINESS ASSOCIATE AGREEMENT. Recitals

BUSINESS ASSOCIATE AGREEMENT. Recitals BUSINESS ASSOCIATE AGREEMENT This Agreement is executed this 8 th day of February, 2013, by BETA Healthcare Group. Recitals BETA Healthcare Group consists of BETA Risk Management Authority (BETARMA) and

More information

DEPARTMENT: POLICY DESCRIPTION: HealthTrust Ethics and Compliance. PHI: Managing Protected Health Information

DEPARTMENT: POLICY DESCRIPTION: HealthTrust Ethics and Compliance. PHI: Managing Protected Health Information PAGE: 1 of 15 SCOPE: All departments within HealthTrust Purchasing Group, L.P. ( HealthTrust LP ); Invivolink LLC; and to the extent applicable, direct and indirect subsidiaries or affiliates of HealthTrust

More information

Guidelines Relating to Implementation of the Privacy Regulations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA)

Guidelines Relating to Implementation of the Privacy Regulations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) HUMAN RESOURCES Index No. VI-35 PROCEDURES MEMORANDUMS TO: FROM: SUBJECT: MCC Personnel Office of the President Guidelines Relating to Implementation of the Privacy Regulations of the Health Insurance

More information

HIPAA Privacy Manual

HIPAA Privacy Manual California State University HIPAA Privacy Manual Revised February 17, 2010 As prepared by Mercer Human Resource Consulting 2010 California State University The HIPAA Privacy Manual was drafted for the

More information

DETAILED NOTICE OF PRIVACY AND SECURITY PRACTICES OF THE Trustees of the Stevens Institute of Technology Health & Welfare Plan

DETAILED NOTICE OF PRIVACY AND SECURITY PRACTICES OF THE Trustees of the Stevens Institute of Technology Health & Welfare Plan DETAILED NOTICE OF PRIVACY AND SECURITY PRACTICES OF THE Trustees of the Stevens Institute of Technology Health & Welfare Plan THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED

More information

District of Columbia Health Information Exchange Policy and Procedure Manual

District of Columbia Health Information Exchange Policy and Procedure Manual District of Columbia Health Information Exchange Policy and Procedure Manual HIPAA Privacy & Direct Privacy Policies (Version 1 November 27, 2012) Table of Contents Policy # Policy/Procedure Description

More information

HIPAA OVERVIEW ETSU 1

HIPAA OVERVIEW ETSU 1 HIPAA OVERVIEW ETSU 1 What is HIPAA? Health Insurance Portability and Accountability Act. 2 PURPOSE - TITLE II ADMINISTRATIVE SIMPLIFICATION To increase the efficiency and effectiveness of the entire health

More information

Infinedi HIPAA Business Associate Agreement RECITALS SAMPLE

Infinedi HIPAA Business Associate Agreement RECITALS SAMPLE Infinedi HIPAA Business Associate Agreement This Business Associate Agreement ( Agreement ) is entered into this day of, 20 between ( Company ) and Infinedi, LLC, a Limited Liability Corporation, ( Contractor

More information

Neera Agarwal-Antal, M.D. HIPAA Policies and Procedures

Neera Agarwal-Antal, M.D. HIPAA Policies and Procedures Neera Agarwal-Antal, M.D. HIPAA Policies and Procedures HIPAA POLICIES & PROCEDURES This packet includes the following HIPAA policies, procedures and model forms: HIPAA General Operating Policy...1 Authorization

More information

Business Associates Agreement

Business Associates Agreement Business Associates Agreement This Business Associate Agreement (the Agreement ) between Customer,( Covered Entity ) and Kareo ( Business Associate ) will be in effect during any such time period that

More information

HIPAA Compliance Manual

HIPAA Compliance Manual HIPAA Compliance Manual HIPAA Compliance Manual 1 This Manual is provided to assist your efforts to comply with the federal privacy and security rules mandated under HIPAA and HITECH, specifically as said

More information

Tulane University. Tulane University Business Associates Agreement SCOPE OF POLICY STATEMENT OF POLICY IMPLEMENTATION OF POLICY

Tulane University. Tulane University Business Associates Agreement SCOPE OF POLICY STATEMENT OF POLICY IMPLEMENTATION OF POLICY Tulane University DEPARTMENT: General Counsel s POLICY DESCRIPTION: Business Associates Office -- HIPAA Agreement PAGE: 1 of 1 APPROVED: April 1, 2003 REVISED: November 29, 2004, December 1, 2008, October

More information

A How-To Guide for Updating HIPAA Policies & Procedures to Align with ARRA Health Care Provider Edition Version 1

A How-To Guide for Updating HIPAA Policies & Procedures to Align with ARRA Health Care Provider Edition Version 1 A How-To Guide for Updating HIPAA Policies & Procedures to Align with ARRA Health Care Provider Edition Version 1 Policy and Procedure Templates Reflects modifications published in the Federal Register

More information

Disclaimer: Template Business Associate Agreement (45 C.F.R. 164.308)

Disclaimer: Template Business Associate Agreement (45 C.F.R. 164.308) HIPAA Business Associate Agreement Sample Notice Disclaimer: Template Business Associate Agreement (45 C.F.R. 164.308) The information provided in this document does not constitute, and is no substitute

More information

New HIPAA regulations require action. Are you in compliance?

New HIPAA regulations require action. Are you in compliance? New HIPAA regulations require action. Are you in compliance? Mary Harrison, JD Tami Simon, JD May 22, 2013 Discussion topics Introduction Remembering the HIPAA Basics HIPAA Privacy Rules HIPAA Security

More information

Information Privacy and Security Program. Title: EC.PS.01.02

Information Privacy and Security Program. Title: EC.PS.01.02 Page: 1 of 9 I. PURPOSE: The purpose of this standard is to ensure that affected individuals, the media, and the Secretary of Health and Human Services (HHS) are appropriately notified of any Breach of

More information