2005 MSEK White Papers are a publication of Meyer, Suozzi, English & Klein, P.C. and should not be construed as legal advice on any specific facts or

Size: px
Start display at page:

Download "2005 MSEK White Papers are a publication of Meyer, Suozzi, English & Klein, P.C. and should not be construed as legal advice on any specific facts or"

Transcription

1 2005 MSEK White Papers are a publication of Meyer, Suozzi, English & Klein, P.C. and should not be construed as legal advice on any specific facts or circumstances. The contents are intended for general information purposes only and may not be quoted or referred to in any other publication or proceeding without the prior written consent of the Firm, to be given or withheld at its discretion. The mailing of this publication is not intended to create, and receipt of it does not constitute, an attorney-client relationship.

2 Attorney Jules B. Levine says here s what every employer should know about the employee benefits funds to which it contributes 1

3 The purpose of the privacy rule is to require group health plans not to use or disclose individually identifiable health information for any purpose unless it is permitted under the Department of Health & Human Services ( HHS ) regulation governing the privacy of medical information. Permitted uses include activities related to eligibility, coverage determinations and billing. TRUSTEES COMPLIANCE EFFORTS SHOULD INCLUDE 3 Develop a budget. 4 Designate a Privacy Officer. Establishment of a Subcommittee of the Trustees, including Management and Union Trustees, Fund Counsel and Fund Administrator to be charged with developing a plan for HIPAA Privacy Compliance. There should be minutes of each of its meetings, and appropriate documentation concerning its activities. The Committee should develop a work plan for HIPAA Privacy Compliance. This should include the following: 1 Prepare a study of Fund Office operations to ascertain which employees require access to health 5 Prepare Participant s Privacy Notices, Fund Privacy Policy, consents and authorizations. 6 Fund counsel should review all plan documents and amend as required to comply with the HIPAA privacy requirements. 7 Develop a HIPAA Privacy training plan for Fund personnel. This will include who is to be trained, nature of the training, i.e., live training, videos. 8 Establish procedures to monitor HIPAA Privacy Compliance, including an internal audit by the Privacy Officer, etc. information, and how the information is utilized and stored. 2 Review all contracts with vendors and providers to assess need for HIPAA Privacy Compliance. 9 Fire walls may need to be established between Fund Office employees administering the group health plan and other employees who are not so involved. 2

4 WHAT IS PROTECTED HEALTH INFORMATION (PHI)? PHI is individually identifiable health information that is transmitted by electronic media, paper and/or oral communications. If the information received by the Fund and/or its claims administrator relates to a participant s health or payment for treatment of medical conditions, and the information identifies the individual or can be utilized to identify an individual, it is PHI. Included in PHI are enrollment and disenrollment functions. TREATMENT, PAYMENT OR HEALTH CARE OPERATIONS (TPO) Use and disclosure of PHI are permitted for TPO purposes as long as they are the minimum amount necessary to achieve the uses that are permitted by the regulation. with providing coverages and benefits. - Payment activities include eligibility or coverage determinations. It also includes coordination of benefits and subrogation. - Communications with stop loss carriers are considered part of payment. - Utilization Review. HEALTH CARE OPERATIONS - Quality Assurance. - Underwriting and Premium Determination. - Review of Claims. - Legal Services. If your Fund attorneys receive any PHI in connection with claims review, they are considered to be involved in a health care operation. - Auditing. TPO includes the following: TREATMENT - Is referred to as the provision and management of health care by one or more medical providers. - In the event PHI is not to be used for TPO as above, an individual authorization is required from the participant in order to use or disclose the participant s PHI. PAYMENT 3 - Plans may disclose PHI for premium determination or reimbursement or in connection

5 CONSENTS & AUTHORIZATIONS The regulation does not require consent to be obtained by a medical provider before treatment. Plans do not have to obtain a consent from their participants before using PHI for TPO purposes. However, I recommend that Plans prepare appropriate consent and authorization documents for signature by Participants. The authorization is particularly important since the Board of Trustees of a Taft- Hartley health fund is technically not a covered entity under HIPAA. Accordingly, the Participant should sign an authorization permitting the Fund Administrator to furnish PHI to the Board of Trustees in connection with TPO. In conjunction with this, the Board of Trustees will have to adopt a privacy policy protecting the confidentiality of the PHI. The policy is similar to that which business associates must adopt. I recommend that the Trustees do this by Resolution, and that the Trustees Privacy Policy on PHI be distributed to Participants as a summary of material modifications to the Summary Plan Description. It should also be included in the Summary Plan Description when it is revised. MINIMUM DISCLOSURE REQUIREMENT Plans may only use the minimum amount of PHI that is necessary to achieve the purpose of the use or disclosure. The Trustees should implement the following policies pertaining to this requirement: - Identify the persons in the plan workforce who require access to PHI to carry out their duties. - Delineate the categories of PHI which each of such persons requires to perform their assigned duties. The plan s privacy policy should, at a minimum, set forth the various types of PHI to be disclosed, the persons who have access to such PHI and the conditions applying to such access. NOTICES TO BE PROVIDED BY PLANS Self-insured plans must provide their participants with a notice concerning the use and disclosure of PHI. The notice must also indicate the individual s rights concerning PHI. Every three years participants must receive a notice of the availability of the privacy notice and how to obtain a copy. The notice should include at least the following: 1. The use and disclosure of PHI pursuant to the TPO exception with examples of each component of the TPO. 2. It must advise participants how to file complaints with the plan or the Department of Health & Human Services. The notice should identify the privacy officer at the plan as the person to contact. Trustees should establish conditions which apply to accessing PHI. 4

6 3. The notice should state how changes in the notice will be communicated to participants. 4. If your plan is insured, a notice need not be provided, as the insurer is required to furnish the notice. However, if the plan is insured, but still may receive PHI, it must maintain the notice and provide it to participants upon request. PARTICIPANT S RIGHTS AS TO PHI The plan must give participants access to health information that is utilized by the plan concerning such participant s coverage. Participants must have the right to inspect and copy plan health information concerning themselves. Participants have the right to request amendments to their health information and to restrict its use and disclosure. However, the plan is not required to restrict the use or disclosure of PHI. The plan must give a participant information concerning disclosure it has made of the participant s PHI for purposes other than TPO. VARIOUS REQUIREMENTS PLANS MUST COMPLY WITH The Plan s Privacy Policy should contain the following: 1. A procedure for Participants to file complaints about noncompliance with the privacy requirements. 2. Sanctions for employees violating the Privacy Policy. 3. Establish safeguards to prevent misuse of PHI. ACCOMMODATIONS OF FACILITIES TO ACHIEVE PRIVACY COMPLIANCE should review making adjustments in the facilities to minimize access to PHI. Some examples of minimizing access are as follows: 1. Isolating and locking file cabinets containing PHI, or record rooms, if applicable. 2. Having claims processors work in a separate room or separate area in the facility. 3. Provide additional security such as passwords on computers which contain PHI. 4. If necessary, the record systems containing PHI should be configured for employees to have the ability to access only certain fields as required for their job duties. 5. In many instances, Trustees should check with their computer consultants to see if there are available tools related to people s access to PHI, such as opaque computer screens. 5 Plans are not required to redesign their facilities to meet the minimum disclosure requirements. The Trustees

7 REQUIREMENTS FOR PLAN S BUSINESS ASSOCIATES A Business Associate is an entity who utilizes or discloses health information in furtherance of performing a function on behalf of the plan. An example of such services are legal, actuarial, accounting, consulting, administrative and accreditation Contracts with Business Associates should contain, at a minimum, the Business Associate s provisions set forth in the Privacy Regulation. The Trustees need not monitor the action of Business Associates. If the Trustees become aware of a violation, they have a duty to take reasonable measures to cure the violation, or if not cured, to terminate the contract. If the disclosure was done with an intent to sell for commercial advantage or personal gain, the fine may be up to $250,000 with a prison term up to 10 years. AMENDMENTS TO PLAN DOCUMENTS The Plan documents should be amended in the following respects relating to PHI: Set forth the permitted uses and disclosures of PHI. Since, in many instances, there is no actual plan document, the Fund s Privacy Policy should be distributed to Participants as a summary of material modifications of the Summary Plan Description. The Fund s Privacy Policy should also be included in the Summary Plan Description when it is revised. HEALTH FUND S EMPLOYEES CHECKLIST FOR COMPLIANCE WITH THE HIPAA PRIVACY & SECURITY REGULATIONS PENALTIES FOR NON-COMPLIANCE Civil penalties are $100 for each violation of a requirement, with a cap of $25,000 for all violations during a calendar year. The purpose of the HIPAA Privacy and Security Regulations are to require group health plans not to use or disclose individually identifiable health information for any purpose unless it is permitted under the Department of Health & Human Services ( HHS ) regulation governing the privacy of medical information. Penalties will not be imposed if the plan demonstrates reasonable cause and not willful neglect, and if the infraction is corrected within a 30-day period after the plan should have known that the failure to comply occurred. Criminal penalties are predicated upon the degree of intent. A fine of up to $50,000 and one year imprisonment is applicable for use or disclosure of individually identifiable health information. If the use or disclosure was done under false pretenses, the fine may be up to $100,000 and a prison term of up to 5 years. WHAT IS PROTECTED HEALTH INFORMATION (PHI)? PHI is individually identifiable health information that is transmitted by electronic media, paper and/or oral communications. If the information received by the Fund Office relates to a participant s health or payment for treatment of medical conditions, and the information identifies an individual or can be utilized to identify an individual, it is PHI for purposes of the Fund s Privacy Rule. 6

8 7 TREATMENT, PAYMENT OR HEALTH CARE OPERATIONS (TPO) Use and disclosure of PHI are permitted for TPO purposes as long as they are the minimum amount necessary to achieve the uses that are permitted by the regulation. Review of claims is considered part of Health Care Operations. The Minimum Disclosure Requirement is to be utilized by the Fund Office. Employees may only use the minimum amount of PHI that is necessary to achieve the purpose of the use or disclosure. The Fund should identify the persons in the Fund Office who require access to PHI to carry out their duties and the conditions applying to such access. The Fund should also designate the categories of PHI each person requires to perform their assigned duties. Staff shall only be able to access PHI in accordance with the requirements of their job description. Employees who violate the privacy and/or security policy of the Fund will be sanctioned, including possible termination. SECURITY REGULATION EPHI, Electronic Protected Health Information, is the same as PHI as used under the Privacy Rule except it is limited to electronic form. The Security Rule requires two-step action -- risk analysis management, and documentation thereof. The previously appointed Privacy Officer may be appointed the Security Officer pursuant to the Security Regulation. Compliance Date is April 21, Encryption is not required, but will be implemented if the risk analysis indicates it should be. EMPLOYEE S EFFORTS TO ACHIEVE PRIVACY & SECURITY COMPLIANCE Employees must isolate and lock file cabinets containing PHI or record rooms, if applicable. Employees must not leave claims files on their desk when they leave their desk. The employee s computer terminal, if the screen contains PHI, shall be provided with an opaque screen so third parties cannot read the matters on the screen. The computer system containing health claims should be configured so that you will need special passwords and/or keys to access the fields required for your job description. There should be no conversation between employees about health claims unless the conversation is required in connection with treatment, payment or review of such claims. The Fund Office should designate an employee to open mail containing claims, and such mail shall only be distributed to employees who have to review the correspondence in connection with treatment, payment or administration of the Fund. Similarly, employees phone conversations concerning participants PHI should only be conducted if you have reasonable grounds to believe that you are talking to a person that has the right to access the information. Employees should maintain a log of phone calls containing the date, time, who made the call and the nature of the conversation concerning PHI. The claims files shall be locked in the evening with only designated persons with the access key. Employees must make a reasonable attempt to keep any PHI as private as possible, except in connection with the use of such information for treatment, payment or Fund administration. The Fund should establish a separate area for consultation with Participants concerning PHI.

9 A unique user identification number is required. The Fund must implement an emergency access procedure. The Fund should review its procedures to control access to the Fund Office. The Fund should implement a procedure for disposing of its hardware and electronic media. The Fund should prepare a procedure to allow employees temporary authorization to obtain access to the Fund Office and equipment in emergencies to restore lost data. The Fund must implement a schedule for testing the Fund's emergency plan. The Fund should implement procedures for denying access to EPHI of terminated employees. The Fund should document its formal practices to manage the selection and execution of security measures to protect data and the conduct of personnel in relation to the protection thereof. The Fund must provide for protection of physical computer systems and equipment from fire and other natural hazards, as well as from intrusion. These safeguards should include, but are not limited to, locks, keys and measures to control access to computer systems and facilities. The Fund will have to implement technical security services to protect, control and monitor information access. The Fund must initiate technical security mechanisms to prevent unauthorized access to data that is transmitted over a communications network. The Fund must establish a contingency plan which includes data backup, disaster recovery, emergency-mode operation and must show evidence of testing for the emergency-mode operation. The foregoing must be evidenced by documented policies and procedures for the storage and dissemination of EPHI.. The Fund should adopt a procedure for an internal audit and review of records to detect unauthorized user activity. I recommend that the Fund enter into employee confidentiality agreements pertaining to HIPAA privacy and security. It is essential that a Fund documents its rules and procedures concerning HIPAA security. The Fund must obtain a risk analysis study. I recommend that on the termination of an employee: 1. If applicable, locks should be changed. 2. Terminated employees should be removed from access lists. 3. Any keys or token cards should be returned. The staff should be trained in workstation physical safeguards to minimize the possibility of unauthorized access. The Fund should install locking devices to prevent theft of equipment or other assets. The Fund should establish automatic log off to protect unattended computers from unauthorized access. A log should be maintained of each computer user s activities. HEALTH FUND SUBROGATION The Supreme Court in the case of Great- West Annuity & Life Insurance v. Knudson restricted the ability of Health Benefit Funds to enforce the subrogation provisions of health benefit funds relating to benefits paid to or on behalf of a Participant when the Participant recovers monetary damages in a lawsuit against a third party who caused the injury to the Participant. Health Benefit Funds should adopt the following procedures to reduce the impact of the Great-West decision: 8

10 If the proceeds of the third-party action have been disbursed to the Participant, the Fund should commence an action in State Court to recoup the benefits from the participant. Funds, in order to protect their interests, should intervene in the third-party tort actions brought by the participant/ beneficiary. Funds may commence an action under ERISA against the personal injury defendant s insurer or the participant s personal injury attorney seeking to obtain a constructive trust on any monetary recovery to avoid disbursement of the monies prior to the Fund obtaining payment. allegedly receive from drug manufacturers. In point of fact, when Health Benefit Funds negotiate for average wholesale price, it is fictitious since the major pharmaceutical manufacturers set the average wholesale price on a daily basis. Efforts should be made to provide audits of pharmacy benefit managers to ascertain that they are not retaining too much from the discount off the average wholesale price. Pharmaceutical manufacturers are striving not to disclose the rebate deals they make on formularies with the Pharmacy Benefit Managers. A formulary plan is when the Fund receives rebates if participants use specific drugs that are manufactured by the prescription manufacturers. Medicare Part D is effective for prescription drug benefits in The Medicare Prescription Drug, Improvement, and Modernization Act of 2003 ( MMA ) will establish a standard drug benefit. Benefit plans have two primary options for their retiree groups for prescription coverage. They may be primary with a subsidy or provide a supplemental drug coverage. 9 HEALTH FUND PRESCRIPTION BENEFIT The importation of Canadian drugs at lower cost has been negatively targeted by the Federal Food & Drug Administration. In a submission that I made for a Benefit Fund, I was advised by the Employee Benefit Security Administration to withdraw it because they said that their opinion would be that the importation would be illegal. Growth in prescription drug spending has been in double digits for the last several years. Major pharmaceutical benefits managers have been sued for the kickbacks they Plans may seek to be designated by Medicare as a qualified Rx plan in which they directly manage the prescription benefit for retirees and receive direct subsidies. Plans must demonstrate that the Plan s retiree prescription drug benefit is actuarially equivalent to the Medicare Part D standard benefit. The deadline for applying for the subsidy is September 30, The average annual subsidy is projected to be 28% of the allowable retiree drug costs between $250 and $5,000 (indexed annually). Some plans may be changed to encourage or require retirees to enroll in a Part D Plan. The Plan can then pay a portion of the members costs and coordinate with Medicare. DEFINED BENEFIT PENSION PLAN PENSION FUNDING ACT OF 2004

11 Effective for the first plan year beginning after December 31, 2004, each defined benefit pension plan is required to furnish each contributing employer with an annual funding notice that discloses the financial status of the plan. The Notice must contain the following: A statement of the plan s funded current liability percentage for the plan year. A statement of the value of the plan assets, the amount of benefit payments and the ratio of the assets to the benefit payments for the plan year. A summary of the rules governing the insolvency of the multiemployer defined benefit plan. A general description of the plan benefits which are eligible for coverage by the Pension Benefit Guaranty Corporation (PBGC). The notice must be furnished no later than two (2) months after the plan s filing of its Form 5500 or any extension thereof. EMPLOYER WITHDRAWAL LIABILITY IN THE CONSTRUCTION INDUSTRY Withdrawal in the construction industry means not just discontinuance of contributions. The liability is incurred only if the employer is no longer obligated to contribute, but continues or within five (5) years resumes the same type of work in the same area as was covered by the employer s collective bargaining agreement and does not contribute to the pension fund for that work. In the construction industry, the liability is determined pursuant to the presumptive rule which assigns a share of the pension fund s unfunded liability to the employer that has withdrawn. In substance, each employer is assigned a pro rata share of the unfunded vested liabilities that were incurred while that employer was obligated to contribute. Each year the change in the fund s unfunded vested liability, either upwards or downwards, is allocated among the employers that were required to contribute in that year Employer contributions. predicated upon what they were obligated to 10 contribute over the preceding five (5) years. An employer that withdraws is required to pay its liability in annual amounts based on its contributions in the preceding ten (10) years. An employer s payments can continue up to but not more than twenty (20) years. There is a de minimus rule if the liability is less than $50,000, there is no withdrawal liability, but the $50,000 deductible vanishes as the liability exceeds $100,000. In substance, the deductible is reduced by one dollar for each dollar of the excess liability over $100,000. There is a partial withdrawal in the construction industry if the employer continues under the plan for an insubstantial portion of its work in the craft and area jurisdiction of the collective bargaining agreement. BENEFIT FUNDS TRUSTEES COLLECTION POLICY The Trustees are required, pursuant to ERISA, to have a collection policy and to attempt to collect delinquent Employer contributions. Delinquent Employer contributions are treated as loans from the Fund to a delinquent Employer and are, thus, prohibited transactions. The Trustees must arduously implement their collection policy, as the typical Trustees fiduciary insurance policy does not cover litigation against the Trustees for their failure to collect

12 The Trustees, pursuant to ERISA, have the right to obtain information relating to employer contributions, including the right to audit. Typically, pursuant to the ERISA statute and Case Law, Funds may not file liens against the owners of property where there are delinquent contributions for work performed by Union employees on the property. However, Funds attorney can avoid the lien restriction by filing individual liens for the workers who worked on the property for delinquent contributions and thereafter assign the individual liens to the Benefit Funds. BENEFIT FUNDS UNIFORMED SERVICES EMPLOYMENT & REEMPLOYMENT RIGHTS ACT OF 1994 (USERRA) USERRA impacts your Benefit Plans as follows: Pension and Annuity Plans Pursuant to the Act, the liability for retroactive contributions to the Plan is allocated to the last Employer. Plans are permitted to provide that any contributions required by USERRA can be made from the assets of the Pension and/or Annuity Plan. This also applies to Health Plans. Health Plans: The service person is entitled to maintain COBRA. Reemployment: If the person serves 181 days or more, he must apply for reemployment no later than ninety (90) days after completion of his military service, except if he cannot apply because of a disability incurred or aggravated during the period of military service. 11

SCHOOL DISTRICT OF BLACK RIVER FALLS HIPAA PRIVACY AND SECURITY POLICY

SCHOOL DISTRICT OF BLACK RIVER FALLS HIPAA PRIVACY AND SECURITY POLICY SCHOOL DISTRICT OF BLACK RIVER FALLS HIPAA PRIVACY AND SECURITY POLICY School Board Policy 523.5 The School District of Black River Falls ( District ) is committed to compliance with the health information

More information

HIPAA Privacy Overview

HIPAA Privacy Overview May 21, 2003 HIPAA Privacy Overview Presented to the California State University Agenda Introduction HIPAA privacy regulations HIPAA privacy impact on CSU Next steps/action items Mercer Human Resource

More information

Alert. Client PROSKAUER ROSE LLP. HIPAA Compliance Update: Employers, As Group Health Plan Sponsors, Will Be Affected By HIPAA Privacy Requirements

Alert. Client PROSKAUER ROSE LLP. HIPAA Compliance Update: Employers, As Group Health Plan Sponsors, Will Be Affected By HIPAA Privacy Requirements PROSKAUER ROSE LLP Client Alert HIPAA Compliance Update: Employers, As Group Health Plan Sponsors, Will Be Affected By HIPAA Privacy Requirements The U.S. Department of Health and Human Services published

More information

HIPAA. HIPAA and Group Health Plans

HIPAA. HIPAA and Group Health Plans HIPAA HIPAA and Group Health Plans CareFirst BlueCross BlueShield is the business name of CareFirst of Maryland, Inc. and is an independent licensee of the Blue Cross and Blue Shield Association. Registered

More information

SPECIMEN. (1) advising, counseling or giving notice to employees, participants or beneficiaries with respect to any Plan;

SPECIMEN. (1) advising, counseling or giving notice to employees, participants or beneficiaries with respect to any Plan; In consideration of payment of the premium and subject to the Declarations, limitations, conditions, provisions and other terms of this Policy, the Company and the Insureds agree as follows: I. INSURING

More information

HIPAA Privacy Summary for Fully-insured Employer Groups

HIPAA Privacy Summary for Fully-insured Employer Groups HIPAA Privacy Summary for Fully-insured Employer Groups I. Overview The Privacy Regulations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) regulate the uses and disclosures

More information

HIPAA Privacy Summary for Self-insured Employer Groups

HIPAA Privacy Summary for Self-insured Employer Groups I. Overview HIPAA Privacy Summary for Self-insured Employer Groups The Privacy Regulations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) regulate the uses and disclosures of

More information

University Healthcare Physicians Compliance and Privacy Policy

University Healthcare Physicians Compliance and Privacy Policy Page 1 of 11 POLICY University Healthcare Physicians (UHP) will enter into business associate agreements in compliance with the provisions of the Health Insurance Portability and Accountability Act of

More information

The MC Academy The Employee Benefits and Executive Compensation Series. HIPAA PRIVACY AND SECURITY The New Final Regulations

The MC Academy The Employee Benefits and Executive Compensation Series. HIPAA PRIVACY AND SECURITY The New Final Regulations The MC Academy The Employee Benefits and Executive Compensation Series HIPAA PRIVACY AND SECURITY The New Final Regulations June 18, 2013 Overview Background Recent Changes to HIPAA Identifying Business

More information

Health Information Privacy Refresher Training. March 2013

Health Information Privacy Refresher Training. March 2013 Health Information Privacy Refresher Training March 2013 1 Disclosure There are no significant or relevant financial relationships to disclose. 2 Topics for Today State health information privacy law Federal

More information

HIPAA 100 Training Manual Table of Contents. V. A Word About Business Associate Agreements 10

HIPAA 100 Training Manual Table of Contents. V. A Word About Business Associate Agreements 10 HIPAA 100 Training Manual Table of Contents I. Introduction 1 II. Definitions 2 III. Privacy Rule 5 IV. Security Rule 8 V. A Word About Business Associate Agreements 10 CHICAGO DEPARTMENT OF PUBIC HEALTH

More information

Why Lawyers? Why Now?

Why Lawyers? Why Now? TODAY S PRESENTERS Why Lawyers? Why Now? New HIPAA regulations go into effect September 23, 2013 Expands HIPAA safeguarding and breach liabilities for business associates (BAs) Lawyer is considered a business

More information

The Health and Benefit Trust Fund of the International Union of Operating Engineers Local Union No. 94-94A-94B, AFL-CIO. Notice of Privacy Practices

The Health and Benefit Trust Fund of the International Union of Operating Engineers Local Union No. 94-94A-94B, AFL-CIO. Notice of Privacy Practices The Health and Benefit Trust Fund of the International Union of Operating Section 1: Purpose of This Notice Notice of Privacy Practices Effective as of September 23, 2013 THIS NOTICE DESCRIBES HOW MEDICAL

More information

AVE MARIA UNIVERSITY HIPAA PRIVACY NOTICE

AVE MARIA UNIVERSITY HIPAA PRIVACY NOTICE AVE MARIA UNIVERSITY HIPAA PRIVACY NOTICE This Notice of Privacy Practices describes the legal obligations of Ave Maria University, Inc. (the plan ) and your legal rights regarding your protected health

More information

Business Associate Agreement

Business Associate Agreement This Business Associate Agreement Is Related To and a Part of the Following Underlying Agreement: Effective Date of Underlying Agreement: Vendor: Business Associate Agreement This Business Associate Agreement

More information

Heather L. Hughes, J.D. HIPAA Privacy Officer U.S. Legal Support, Inc. hhughes@uslegalsupport.com www.uslegalsupport.com

Heather L. Hughes, J.D. HIPAA Privacy Officer U.S. Legal Support, Inc. hhughes@uslegalsupport.com www.uslegalsupport.com Heather L. Hughes, J.D. HIPAA Privacy Officer U.S. Legal Support, Inc. hhughes@uslegalsupport.com www.uslegalsupport.com HIPAA Privacy Rule Sets standards for confidentiality and privacy of individually

More information

FOR USE WITH A CA FULLY INSURED HEALTH CONTRACT

FOR USE WITH A CA FULLY INSURED HEALTH CONTRACT AGREEMENT FOR HEALTH REIMBURSEMENT ACCOUNTS This AGREEMENT (this Agreement ) is made effective as of the date set forth on [enter date here] (the "Effective Date") between {group name here} (hereinafter

More information

HIPAA BUSINESS ASSOCIATE AGREEMENT

HIPAA BUSINESS ASSOCIATE AGREEMENT HIPAA BUSINESS ASSOCIATE AGREEMENT This HIPAA Business Associate Agreement ("BA AGREEMENT") supplements and is made a part of any and all agreements entered into by and between The Regents of the University

More information

SAMPLE BUSINESS ASSOCIATE AGREEMENT

SAMPLE BUSINESS ASSOCIATE AGREEMENT SAMPLE BUSINESS ASSOCIATE AGREEMENT THIS AGREEMENT IS TO BE USED ONLY AS A SAMPLE IN DEVELOPING YOUR OWN BUSINESS ASSOCIATE AGREEMENT. ANYONE USING THIS DOCUMENT AS GUIDANCE SHOULD DO SO ONLY IN CONSULT

More information

Connecticut Pipe Trades Health Fund Privacy Notice. 2013 Restatement

Connecticut Pipe Trades Health Fund Privacy Notice. 2013 Restatement Connecticut Pipe Trades Health Fund Privacy Notice 2013 Restatement Section 1: Purpose of This Notice and Effective Date THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED

More information

Medicare Coverage Gap Discount Program (Filling the Donut Hole)

Medicare Coverage Gap Discount Program (Filling the Donut Hole) Medicare Coverage Gap Discount Program (Filling the Donut Hole) Summary: Requires drug manufacturers to provide a 50 percent discount to Part D beneficiaries for brand name drugs and biologics purchased

More information

Health Insurance Portability and Accountability Act (HIPAA) and Health Information Technology for Economic and Clinical Health Act (HITECH)

Health Insurance Portability and Accountability Act (HIPAA) and Health Information Technology for Economic and Clinical Health Act (HITECH) Health Insurance Portability and Accountability Act (HIPAA) and Health Information Technology for Economic and Clinical Health Act (HITECH) Table of Contents Introduction... 1 1. Administrative Safeguards...

More information

HIPAA: In Plain English

HIPAA: In Plain English HIPAA: In Plain English Material derived from a presentation by Kris K. Hughes, Esq. Posted with permission from the author. The Health Insurance Portability and Accountability Act of 1996 (HIPAA), Pub.

More information

HIPAA Security Rule Compliance

HIPAA Security Rule Compliance HIPAA Security Rule Compliance Caryn Reiker MAXIS360 HIPAA Security Rule Compliance what is it and why you should be concerned about it Table of Contents About HIPAA... 2 Who Must Comply... 2 The HIPAA

More information

EMPLOYEE BENEFITS LIABILITY COVERAGE

EMPLOYEE BENEFITS LIABILITY COVERAGE POLICY NUMBER: COMMERCIAL GENERAL LIABILITY CG 04 35 12 07 THIS ENDORSEMENT CHANGES THE POLICY. PLEASE READ IT CAREFULLY. EMPLOYEE BENEFITS LIABILITY COVERAGE THIS ENDORSEMENT PROVIDES CLAIMS-MADE COVERAGE.

More information

Graphic Communications National Health and Welfare Fund. Notice of Privacy Practices

Graphic Communications National Health and Welfare Fund. Notice of Privacy Practices Notice of Privacy Practices Section 1: Purpose of This Notice and Effective Date THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION.

More information

C.T. Hellmuth & Associates, Inc.

C.T. Hellmuth & Associates, Inc. Technical Monograph C.T. Hellmuth & Associates, Inc. Technical Monographs usually are limited to only one subject which is treated in considerably more depth than is possible in our Executive Newsletter.

More information

HIPAA and Mental Health Privacy:

HIPAA and Mental Health Privacy: HIPAA and Mental Health Privacy: What Social Workers Need to Know Presenter: Sherri Morgan, JD, MSW Associate Counsel, NASW Legal Defense Fund and Office of Ethics & Professional Review 2010 National Association

More information

HIPAA RISKS & STRATEGIES. Health Insurance Portability and Accountability Act of 1996

HIPAA RISKS & STRATEGIES. Health Insurance Portability and Accountability Act of 1996 HIPAA RISKS & STRATEGIES Health Insurance Portability and Accountability Act of 1996 REGULATORY BACKGROUND Health Information Portability and Accountability Act (HIPAA) was enacted on August 21, 1996 Title

More information

HIPAA and Privacy Policy Training

HIPAA and Privacy Policy Training HIPAA and Privacy Policy Training July 2015 1 This training addresses the requirements for maintaining the privacy of confidential information received from HFS and DHS (the Agencies). During this training

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT The parties to this ( Agreement ) are, a _New York_ corporation ( Business Associate ) and ( Client ) you, as a user of our on-line health record system (the "System"). BY

More information

Member s Name First M.I. Last Dependent s Name (if enrolling in Medicare) First M.I. Last

Member s Name First M.I. Last Dependent s Name (if enrolling in Medicare) First M.I. Last Oklahoma State and Education Employees Group Insurance Board A Division of the Office of State Finance APPLICATION FOR MEDICARE SUPPLEMENT WITH PART D Member ID # *MCENRL* Phone ( ) Member s Name First

More information

Policies and Procedures Audit Checklist for HIPAA Privacy, Security, and Breach Notification

Policies and Procedures Audit Checklist for HIPAA Privacy, Security, and Breach Notification Policies and Procedures Audit Checklist for HIPAA Privacy, Security, and Breach Notification Type of Policy and Procedure Comments Completed Privacy Policy to Maintain and Update Notice of Privacy Practices

More information

An Employer s Introduction to HIPAA Prepared by Ballard, Rosenberg Golper & Savitt, LLP

An Employer s Introduction to HIPAA Prepared by Ballard, Rosenberg Golper & Savitt, LLP An Employer s Introduction to HIPAA Prepared by Ballard, Rosenberg Golper & Savitt, LLP Important Disclaimer: Practice limited to labor and employment law on behalf of management and related litigation.

More information

DETAILED NOTICE OF PRIVACY AND SECURITY PRACTICES OF THE Trustees of the Stevens Institute of Technology Health & Welfare Plan

DETAILED NOTICE OF PRIVACY AND SECURITY PRACTICES OF THE Trustees of the Stevens Institute of Technology Health & Welfare Plan DETAILED NOTICE OF PRIVACY AND SECURITY PRACTICES OF THE Trustees of the Stevens Institute of Technology Health & Welfare Plan THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED

More information

VALPARAISO UNIVERSITY NOTICE OF PRIVACY PRACTICES. Health, Dental and Vision Benefits Health Care Reimbursement Account

VALPARAISO UNIVERSITY NOTICE OF PRIVACY PRACTICES. Health, Dental and Vision Benefits Health Care Reimbursement Account VALPARAISO UNIVERSITY NOTICE OF PRIVACY PRACTICES THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

More information

HIPAA NOTICE OF PRIVACY PRACTICES

HIPAA NOTICE OF PRIVACY PRACTICES HIPAA NOTICE OF PRIVACY PRACTICES THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY. Protected

More information

HIPAA PRIVACY FOR EMPLOYERS A Comprehensive Introduction. HIPAA Privacy Regulations-General

HIPAA PRIVACY FOR EMPLOYERS A Comprehensive Introduction. HIPAA Privacy Regulations-General HIPAA PRIVACY FOR EMPLOYERS A Comprehensive Introduction HIPAA Privacy Regulations-General The final HIPAA Privacy regulation was released on December 20, 2000 and was effective for compliance on April

More information

BENCHMARK MEDICAL LLC, BUSINESS ASSOCIATE AGREEMENT

BENCHMARK MEDICAL LLC, BUSINESS ASSOCIATE AGREEMENT BENCHMARK MEDICAL LLC, BUSINESS ASSOCIATE AGREEMENT This BUSINESS ASSOCIATE AGREEMENT ( Agreement ) dated as of the signature below, (the Effective Date ), is entered into by and between the signing organization

More information

Infinedi HIPAA Business Associate Agreement RECITALS SAMPLE

Infinedi HIPAA Business Associate Agreement RECITALS SAMPLE Infinedi HIPAA Business Associate Agreement This Business Associate Agreement ( Agreement ) is entered into this day of, 20 between ( Company ) and Infinedi, LLC, a Limited Liability Corporation, ( Contractor

More information

OPERATING ENGINEERS LOCAL 66 ANNUITY AND SAVINGS FUND

OPERATING ENGINEERS LOCAL 66 ANNUITY AND SAVINGS FUND OPERATING ENGINEERS LOCAL 66 ANNUITY AND SAVINGS FUND Summary Plan Description REVISED 1-1-2009 BOOKLET 4 OPERATING ENGINEERS LOCAL 66 ANNUITY AND SAVINGS FUND UNION TRUSTEES James T. Kunz, Jr., Chairman

More information

Effective Date: March 23, 2016

Effective Date: March 23, 2016 AIG COMPANIES Effective Date: March 23, 2016 HIPAA NOTICE OF PRIVACY PRACTICES THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION.

More information

Plan Sponsor Guide HIPAA Privacy Rule

Plan Sponsor Guide HIPAA Privacy Rule Plan Sponsor Guide HIPAA Privacy Rule Plan Sponsor s Guide to the HIPAA Privacy Rule Compliments of Aetna 00.02.108.1A (5/05) Compliments of Aetna You have likely heard a great deal about the HIPAA Privacy

More information

Fiduciary Liability Coverage Part

Fiduciary Liability Coverage Part Fiduciary Liability Coverage Part In consideration of the payment of the premium and subject to all terms, conditions and limitations of this Coverage Part and the General Terms and Conditions for Liability

More information

CHAPTER 267. BE IT ENACTED by the Senate and General Assembly of the State of New Jersey:

CHAPTER 267. BE IT ENACTED by the Senate and General Assembly of the State of New Jersey: CHAPTER 267 AN ACT concerning third party administrators of health benefits plans and third party billing services and supplementing Title 17B of the New Jersey Statutes. BE IT ENACTED by the Senate and

More information

City of Portland HEALTH EXPENSE REIMBURSEMENT ACCOUNT

City of Portland HEALTH EXPENSE REIMBURSEMENT ACCOUNT EXHIBIT C City of Portland HEALTH EXPENSE REIMBURSEMENT ACCOUNT S U M M A R Y P L A N D E S C R I P T I O N Effective January, 2016 City of Portland Health Expense Reimbursement Account Summary Plan Description

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement (the Agreement ), is made effective as of the sign up date on the login information page of the CarePICS.com website, by and between CarePICS,

More information

HIPAA Privacy and Business Associate Agreement

HIPAA Privacy and Business Associate Agreement HR 2011-07 ATTACHMENT D HIPAA Privacy and Business Associate Agreement This Agreement is entered into this day of,, between [Employer] ( Employer ), acting on behalf of [Name of covered entity/plan(s)

More information

SERVICES AGREEMENT. 2. Term. This Agreement will commence and expire. Medical Center Representative: Name and Title

SERVICES AGREEMENT. 2. Term. This Agreement will commence and expire. Medical Center Representative: Name and Title This Services Agreement ( Agreement ) dated is made by and between [INSERT CONTRACTOR S NAME AND ADDRESS] (hereinafter called "Contractor"), and UMass Memorial Medical Center, Inc., Worcester, MA (hereinafter

More information

Agent Instruction Sheet for PriorityHRA Plan Document

Agent Instruction Sheet for PriorityHRA Plan Document Agent Instruction Sheet for PriorityHRA Plan Document Thank you for choosing PriorityHRA! Here are some instructions as to what to do with each PriorityHRA document. Required Documents: HRA Application

More information

SURA/JEFFERSON SCIENCE ASSOCIATES, LLC COMPREHENSIVE HEALTH AND WELFARE BENEFIT PLAN. Amended and Restated

SURA/JEFFERSON SCIENCE ASSOCIATES, LLC COMPREHENSIVE HEALTH AND WELFARE BENEFIT PLAN. Amended and Restated SURA/JEFFERSON SCIENCE ASSOCIATES, LLC COMPREHENSIVE HEALTH AND WELFARE BENEFIT PLAN Amended and Restated Effective June 1, 2006 SURA/JEFFERSON SCIENCE ASSOCIATES, LLC COMPREHENSIVE HEALTH AND WELFARE

More information

Department of Health and Human Services Policy ADMN 004, Attachment A

Department of Health and Human Services Policy ADMN 004, Attachment A WASHINGTON COUNTY Department of Health and Human Services Policy ADMN 004, Attachment A HHS Confidentiality Agreement Including HIPAA (Health Information Portability and Accessibility Act of 1996) OREGON

More information

HEALTH REIMBURSEMENT ARRANGEMENT

HEALTH REIMBURSEMENT ARRANGEMENT HEALTH REIMBURSEMENT ARRANGEMENT C O M M U N I T Y C O L L E G E S Y S T E M O F N E W H A M P S H I R E S U M M A R Y P L A N D E S C R I P T I O N Copyright 2005 SunGard Inc. 04/01/05 TABLE OF CONTENTS

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement (the Agreement ) is entered into by and between Professional Office Services, Inc., with principal place of business at PO Box 450, Waterloo,

More information

IAC 11/18/09 Insurance[191] Ch 58, p.1 CHAPTER 58 THIRD-PARTY ADMINISTRATORS

IAC 11/18/09 Insurance[191] Ch 58, p.1 CHAPTER 58 THIRD-PARTY ADMINISTRATORS IAC 11/18/09 Insurance[191] Ch 58, p.1 CHAPTER 58 THIRD-PARTY ADMINISTRATORS 191 58.1(510) Purpose. The purpose of this chapter is to administer the provisions of Iowa Code chapter 510 relating to the

More information

HIPAA PRIVACY AND SECURITY AWARENESS

HIPAA PRIVACY AND SECURITY AWARENESS HIPAA PRIVACY AND SECURITY AWARENESS Introduction The Health Insurance Portability and Accountability Act (known as HIPAA) was enacted by Congress in 1996. HIPAA serves three main purposes: To protect

More information

HIPAA PRIVACY AND SECURITY FOR EMPLOYERS

HIPAA PRIVACY AND SECURITY FOR EMPLOYERS HIPAA PRIVACY AND SECURITY FOR EMPLOYERS Agenda Background and Enforcement HIPAA Privacy and Security Rules Breach Notification Rules HPID Number Why Does it Matter HIPAA History HIPAA Title II Administrative

More information

HIPAA, HIPAA Hi-TECH and HIPAA Omnibus Rule

HIPAA, HIPAA Hi-TECH and HIPAA Omnibus Rule HIPAA, HIPAA Hi-TECH and HIPAA Omnibus Rule NYCR-245157 HIPPA, HIPAA HiTECH& the Omnibus Rule A. HIPAA IIHI and PHI Privacy & Security Rule Covered Entities and Business Associates B. HIPAA Hi-TECH Why

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT THIS BUSINESS ASSOCIATE AGREEMENT is made and entered into as of the day of, 2013 ( Effective Date ), by and between [Physician Practice] on behalf of itself and each of its

More information

HIPAA Compliance Manual

HIPAA Compliance Manual HIPAA Compliance Manual HIPAA Compliance Manual 1 This Manual is provided to assist your efforts to comply with the federal privacy and security rules mandated under HIPAA and HITECH, specifically as said

More information

APPENDIX 1: Frequently Asked Questions

APPENDIX 1: Frequently Asked Questions APPENDIX 1: Frequently Asked Questions Practice Name Q: What is the HIPAA Privacy Rule? A: The HIPAA Privacy Rule controls the use and disclosure of what is known as Protected Health Information (PHI).

More information

State of Florida Employees' Group Health Insurance Privacy Notice

State of Florida Employees' Group Health Insurance Privacy Notice This notice describes how medical information about you may be used and disclosed and how you can get access to this information. Please review it carefully. The Health Insurance Portability and Accountability

More information

NOTICE OF PRIVACY PRACTICES for the HARVARD UNIVERSITY MEDICAL, DENTAL, VISION AND MEDICAL REIMBURSEMENT PLANS

NOTICE OF PRIVACY PRACTICES for the HARVARD UNIVERSITY MEDICAL, DENTAL, VISION AND MEDICAL REIMBURSEMENT PLANS NOTICE OF PRIVACY PRACTICES for the HARVARD UNIVERSITY MEDICAL, DENTAL, VISION AND MEDICAL REIMBURSEMENT PLANS THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW

More information

HIPAA NOTICE OF PRIVACY PRACTICES

HIPAA NOTICE OF PRIVACY PRACTICES HIPAA NOTICE OF PRIVACY PRACTICES THIS NOTICE DESCRIBES HOW YOUR MEDICAL INFORMATION MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY. This HIPAA Notice

More information

NOTICE OF HIPAA PRIVACY AND SECURITY PRACTICES

NOTICE OF HIPAA PRIVACY AND SECURITY PRACTICES SCHOOL DISTRICT OF BLACK RIVER FALLS 523.5 Exhibit NOTICE OF HIPAA PRIVACY AND SECURITY PRACTICES PRIVACY NOTICE This notice describes how medical information about you may be used and disclosed and how

More information

HIPAA Compliance for Employers. What is HIPAA? Common HIPAA Misperception. The Penalties. Chapter I HIPAA Overview. The Privacy Regulations Why?

HIPAA Compliance for Employers. What is HIPAA? Common HIPAA Misperception. The Penalties. Chapter I HIPAA Overview. The Privacy Regulations Why? Chapter I HIPAA Overview HIPAA Compliance for Employers What is it? What is it supposed to do? Why should you care? Who does it apply to? What does it cover? Patricia C. Shea, Esq. 717.231.5870 2 What

More information

Connecticut Carpenters Health Fund Privacy Notice

Connecticut Carpenters Health Fund Privacy Notice Connecticut Carpenters Health Fund Privacy Notice THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

More information

HIPAA BUSINESS ASSOCIATE AGREEMENT

HIPAA BUSINESS ASSOCIATE AGREEMENT HIPAA BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement ( BAA ) is effective ( Effective Date ) by and between ( Covered Entity ) and Egnyte, Inc. ( Egnyte or Business Associate ). RECITALS

More information

NOTICE OF HEALTH INFORMATION PRACTICES

NOTICE OF HEALTH INFORMATION PRACTICES NOTICE OF HEALTH INFORMATION PRACTICES Effective Date: April 14, 2003 Date Amended: 9/5/13 THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO

More information

CHAPMAN UNIVERSITY DEFINED CONTRIBUTION RETIREMENT PLAN

CHAPMAN UNIVERSITY DEFINED CONTRIBUTION RETIREMENT PLAN CHAPMAN UNIVERSITY DEFINED CONTRIBUTION RETIREMENT PLAN Summary Plan Description This document is a summary of the provisions of Chapman University Defined Contribution Retirement Plan (the Plan ) as in

More information

City of Pittsburgh Operating Policies. Policy: HIPAA Privacy Policies Original Date: 1/2005 and Procedures Revised Date: 3/22/2010

City of Pittsburgh Operating Policies. Policy: HIPAA Privacy Policies Original Date: 1/2005 and Procedures Revised Date: 3/22/2010 City of Pittsburgh Operating Policies Policy: HIPAA Privacy Policies Original Date: 1/2005 and Procedures Revised Date: 3/22/2010 PURPOSE: To establish internal policies and procedures to ensure compliance

More information

Management Liability Insurance Policy Fiduciary Liability Insurance Coverage Part ( FLI Coverage Part )

Management Liability Insurance Policy Fiduciary Liability Insurance Coverage Part ( FLI Coverage Part ) In consideration of the premium charged and in reliance upon the statements made by the Insureds in the Application, which forms a part of this Policy, the Insurer agrees as follows: I. Insuring Agreements

More information

TABLE OF CONTENTS. University of Northern Colorado

TABLE OF CONTENTS. University of Northern Colorado TABLE OF CONTENTS University of Northern Colorado HIPAA Policies and Procedures Page # Development and Maintenance of HIPAA Policies and Procedures... 1 Procedures for Updating HIPAA Policies and Procedures...

More information

Salt Lake Community College Employee Health Care Benefits Plan Notice of Privacy Practices

Salt Lake Community College Employee Health Care Benefits Plan Notice of Privacy Practices THIS NOTICE DESCRIBES HOW HEALTH INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY. Date: June 1, 2014 Salt Lake Community College

More information

HIPAA PRIVACY AND EDI RULES

HIPAA PRIVACY AND EDI RULES The Health and Human Services (HHS) issued final HIPAA privacy regulations on August 14, 2002. These rules govern how individually identifiable medical information must be protected. HIIPAA also requires

More information

HIPAA Security. 5 Security Standards: Organizational, Policies. Security Topics. and Procedures and Documentation Requirements

HIPAA Security. 5 Security Standards: Organizational, Policies. Security Topics. and Procedures and Documentation Requirements HIPAA Security S E R I E S Security Topics 1. Security 101 for Covered Entities 2. Security Standards - Administrative Safeguards 3. Security Standards - Physical Safeguards 4. Security Standards - Technical

More information

HIPAA Compliance Review

HIPAA Compliance Review HIPAA Compliance Review For HR and IT Presented by: Linda Railton, PHR HR Consultant Leavitt Group linda.railton@leavitt.com Discussion Points HIPAA Final Rule (effective March 26, 2013) Overview of HIPAA

More information

AGREEMENT FOR ACCESS TO PROTECTED HEALTH INFORMATION BETWEEN WAKE FOREST UNIVERSITY BAPTIST MEDICAL CENTER AND

AGREEMENT FOR ACCESS TO PROTECTED HEALTH INFORMATION BETWEEN WAKE FOREST UNIVERSITY BAPTIST MEDICAL CENTER AND AGREEMENT FOR ACCESS TO PROTECTED HEALTH INFORMATION BETWEEN WAKE FOREST UNIVERSITY BAPTIST MEDICAL CENTER AND THIS AGREEMENT for Access to Protected Health Information ( PHI ) ( Agreement ) is entered

More information

HIPAA and the HITECH Act Privacy and Security of Health Information in 2009

HIPAA and the HITECH Act Privacy and Security of Health Information in 2009 HIPAA and the HITECH Act Privacy and Security of Health Information in 2009 What is HIPAA? Health Insurance Portability & Accountability Act of 1996 Effective April 13, 2003 Federal Law HIPAA Purpose:

More information

HIPAA BUSINESS ASSOCIATE AGREEMENT

HIPAA BUSINESS ASSOCIATE AGREEMENT HIPAA BUSINESS ASSOCIATE AGREEMENT This HIPAA Business Associate Agreement and is made between BEST Life and Health Insurance Company ( BEST Life ) and ( Business Associate ). RECITALS WHEREAS, the U.S.

More information

How To Understand The Health Care Plan

How To Understand The Health Care Plan TEXAS CHILDREN'S HOSPITAL EMPLOYEE MEDICAL CLINIC AND EMPLOYEE ASSISTANCE PROGRAM (Amended and Restated Effective as of January 1, 2012) Every effort has been made to provide you with clear, accurate,

More information

Population Health Management Program Notice of Privacy Practices

Population Health Management Program Notice of Privacy Practices Population Health Management Program Notice of Privacy Practices Premier Health provides population health management services to its health plan members. Services include wellness program tools and technology,

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT Express Scripts, Inc. and one or more of its subsidiaries ( ESI ), and Sponsor or one of its affiliates ( Sponsor ), are parties to an agreement ( PBM Agreement ) whereby ESI

More information

California Department of Corrections and Rehabilitation (CDCR) BUSINESS ASSOCIATES AGREEMENT (HIPAA)

California Department of Corrections and Rehabilitation (CDCR) BUSINESS ASSOCIATES AGREEMENT (HIPAA) California Department of Corrections and Rehabilitation (CDCR) BUSINESS ASSOCIATES AGREEMENT (HIPAA) IN PRISON SUBSTANCE USE DISORDER TREATMENT PROGRAM WHEREAS, Provider, hereinafter referred to in this

More information

NATIONAL CONFERENCE OF INSURANCE LEGISLATORS (NCOIL) Proposed Consumer Legal Funding Model Act

NATIONAL CONFERENCE OF INSURANCE LEGISLATORS (NCOIL) Proposed Consumer Legal Funding Model Act NATIONAL CONFERENCE OF INSURANCE LEGISLATORS (NCOIL) Proposed Consumer Legal Funding Model Act To be considered by the NCOIL Property-Casualty Insurance Committee on July 13, 2012. Sponsored by Rep. Charles

More information

SCHOOL DISTRICT OF BLACK RIVER FALLS HIPAA PRIVACY AND SECURITY POLICY

SCHOOL DISTRICT OF BLACK RIVER FALLS HIPAA PRIVACY AND SECURITY POLICY SCHOOL DISTRICT OF BLACK RIVER FALLS HIPAA PRIVACY AND SECURITY POLICY 1 School Board Policy 523.5 The School District of Black River Falls ( District ) is committed to compliance with the health information

More information

Michie's Legal Resources. This part shall be known and may be cited as the Tennessee Identity Theft Deterrence Act of 1999. [Acts 1999, ch. 201, 2.

Michie's Legal Resources. This part shall be known and may be cited as the Tennessee Identity Theft Deterrence Act of 1999. [Acts 1999, ch. 201, 2. http://www.michie.com/tennessee/lpext.dll/tncode/12ebe/13cdb/1402c/1402e?f=templates&... Page 1 of 1 47-18-2101. Short title. This part shall be known and may be cited as the Tennessee Identity Theft Deterrence

More information

Case 2:15-cv-03432-DDP-AGR Document 1 Filed 05/07/15 Page 1 of 15 Page ID #:1 UNITED STATES DISTRICT COURT FOR THE CENTRAL DISTRICT OF CALIFORNIA

Case 2:15-cv-03432-DDP-AGR Document 1 Filed 05/07/15 Page 1 of 15 Page ID #:1 UNITED STATES DISTRICT COURT FOR THE CENTRAL DISTRICT OF CALIFORNIA Case :-cv-0-ddp-agr Document Filed 0/0/ Page of Page ID #: 0 Matthew T. Walsh, Esq. (Bar No. ) CARROLL, McNULTY & KULL LLC 00 North Riverside Plaza, Suite 00 Chicago, Illinois 00 Telephone: () 00-000 Facsimile:

More information

Business Associate Agreement Involving the Access to Protected Health Information

Business Associate Agreement Involving the Access to Protected Health Information School/Unit: Rowan University School of Osteopathic Medicine Vendor: Business Associate Agreement Involving the Access to Protected Health Information This Business Associate Agreement ( BAA ) is entered

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement (the "Agreement") is made and entered into this day of,, by and between Quicktate and idictate ("Business Associate") and ("Covered Entity").

More information

CHAPTER 179. BE IT ENACTED by the Senate and General Assembly of the State of New Jersey: 1. R.S.34:15-104 is amended to read as follows:

CHAPTER 179. BE IT ENACTED by the Senate and General Assembly of the State of New Jersey: 1. R.S.34:15-104 is amended to read as follows: CHAPTER 179 AN ACT concerning the workers' compensation security funds and amending and repealing various sections of chapter 15 of Title 34 of the Revised Statutes. BE IT ENACTED by the Senate and General

More information

By Ross C. D Emanuele, John T. Soshnik, and Kari Bomash, Dorsey & Whitney LLP Minneapolis, MN

By Ross C. D Emanuele, John T. Soshnik, and Kari Bomash, Dorsey & Whitney LLP Minneapolis, MN Major Changes to HIPAA Security and Privacy Rules Enacted in Economic Stimulus Package By Ross C. D Emanuele, John T. Soshnik, and Kari Bomash, Dorsey & Whitney LLP Minneapolis, MN The HITECH Act is the

More information

Rule and Regulation 43 UNFAIR CLAIMS SETTLEMENT PRACTICES

Rule and Regulation 43 UNFAIR CLAIMS SETTLEMENT PRACTICES Rule and Regulation 43 UNFAIR CLAIMS SETTLEMENT PRACTICES Section 1. Purpose. 2. Authority. 3. Applicability and scope. 4. Effective Date. 5. Definitions. 6. File and record documentation. 7. Failure to

More information

WASHINGTON STATE EMPLOYEES CREDIT UNION ONLINE BANKING AGREEMENT

WASHINGTON STATE EMPLOYEES CREDIT UNION ONLINE BANKING AGREEMENT WASHINGTON STATE EMPLOYEES CREDIT UNION ONLINE BANKING AGREEMENT This Agreement is the contract which covers your and our rights and responsibilities concerning Online Banking services ("Online Banking")

More information

HIPAA Compliance Guide

HIPAA Compliance Guide HIPAA Compliance Guide Important Terms Covered Entities (CAs) The HIPAA Privacy Rule refers to three specific groups as covered entities, including health plans, healthcare clearinghouses, and health care

More information

BUSINESS ASSOCIATE AGREEMENT FOR ATTORNEYS

BUSINESS ASSOCIATE AGREEMENT FOR ATTORNEYS BUSINESS ASSOCIATE AGREEMENT FOR ATTORNEYS This Business Associate Agreement (this Agreement ), is made as of the day of, 20 (the Effective Date ), by and between ( Business Associate ) and ( Covered Entity

More information

Health Insurance Portability and Accountability Act of 1996 (HIPAA)

Health Insurance Portability and Accountability Act of 1996 (HIPAA) HIPAA Privacy Rule Health Insurance Portability and Accountability Act of 1996 (HIPAA) Transactions Standards 1. Health claims 2. Health claim attachments 3. Healthcare payment and remittance advice 4.

More information

HIPAA Security. 1 Security 101 for Covered Entities. Security Topics

HIPAA Security. 1 Security 101 for Covered Entities. Security Topics HIPAA SERIES Topics 1. 101 for Covered Entities 2. Standards - Administrative Safeguards 3. Standards - Physical Safeguards 4. Standards - Technical Safeguards 5. Standards - Organizational, Policies &

More information

9129 Monroe Rd. Suite 100, Charlotte, NC 28270

9129 Monroe Rd. Suite 100, Charlotte, NC 28270 9129 Monroe Rd. Suite 100, Charlotte, NC 28270 THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE READ IT CAREFULLY.

More information

HIPAA Employee Compliance Program TRAINING MANUAL

HIPAA Employee Compliance Program TRAINING MANUAL HIPAA Employee Compliance Program TRAINING MANUAL Training Manual to Assist Employees in HIPAA Compliance January 2013 Program For HIPAA Compliance Plan Goal The purpose of this manual is to instruct our

More information