Albuquerque Housing Authority. EIV Security and Procedure Policy
|
|
|
- Gwen Dixon
- 10 years ago
- Views:
Transcription
1 APPENDIX V Albuquerque Housing Authority EIV Security and Procedure Policy Date Adopted By Resolution Number 1/2012
2 Definitions Administrator Authorized User: EIV Improper Disclosure Intranet Need-to Know Proper Disposal Secure System WASS User ID Security Officer WASS The AHA employee, designated by the Division Manager who is responsible for authorizing access to WASS. Note: this person is not allowed to obtain EIV information under any circumstances. An authorized user is one who is employed by AHA, and has been granted authorized WASS access by the Division Manager or his/her designated representative who is the (Administrator/Coordinator). Enterprise Income Verification System. The release of EIV data to an unauthorized individual. A privately maintained computer network that can be accessed only by authorized persons, especially members or employees of the organization that owns it. A criterion used in security procedures that requires the custodians of secure information to establish, prior to disclosure, that the intended recipient must have access to the information to perform his or her official duties. The disposal of EIV information by destroying documents 3 years after EOP date. A secure ID issued to a user enabling access to the system. The AHA employee so designated by the Division Manager to monitor and insure users EIV/UIV compliance. Note: this person is not allowed to obtain EIV/UIV information. HUD s Web Access Security System (Secure connection/secure systems) 1
3 AHA Use and Confidential Policy The U.S. Department of Housing and Urban Development (HUD) Enterprise Income Verification (EIV) system will be used by AHA as the method of verifying income of Low Rent Public Housing and Section 8 Housing Choice Voucher program participants. EIV information is to be considered strictly confidential and may only be utilized for the intended purpose of verifying income for initial eligibility and continued eligibility. The EIV data is subject to the provisions of the federal Privacy Act (5 U.S.C. 552, as amended by Public Law No , 110 Stat. 3048), the Freedom of Information Act, also know as FOIA, (5 U.S.C. 552, as amended by Public Law No , 110 Stat. 3048), and any related future amendments. Privacy Act Requirements Whenever AHA requests information about a participant tenant, AHA will ensure the following: 1. The data will only be used for verification of tenant income to determine: a. A tenant s eligibility for participation in a federal rental assistance program; and b. The level of housing assistance that they are entitled to receive. 2. The data is NOT disclosed in any way that would violate the privacy of the individuals represented in the system 3. ALL participating tenants will be notified of the following: a. HUD or AHA authorization and purpose for collecting the information b. The uses that may be made of the data collected, and c. The consequences if the tenant fails to provide the required information 4. Upon request, a tenant will be provided with access to EIV generated records pertaining to them and with the opportunity to correct or challenge the contents of the records. Criminal Penalties Associated with violation of the Privacy Act An AHA employee can be charged and possibly be found guilty of a federal misdemeanor or felony crime, if that employee knowingly and/or willfully: 1. Discloses a tenant or tenants records to an unauthorized party. 2. Fraudulently represents himself/herself to obtain another individual s record. Reporting Improper Disclosures Security Officer will report any evidence of unauthorized access or known security breaches to the Division Manager; and Security Officer shall document all improper disclosures in writing; and Security Officer shall report all security violations regardless of whether the security violation was intentional or unintentional. 2
4 AHA Staff Responsibilities EIV Access 1. Division Manager: The Division Manager shall appoint an EIV Administrator / Security Officer whose responsibilities are defined herein. 2. EIV Administrator: The Administrator shall provide each authorized user a HUD/PHA Access Authorization Form and the rules of Behavior and User Agreement form and the user will apply for a User ID and Password. Administrator will facilitate this process. 3. Security Officer (EIV Administrator): The Security Officer shall be responsible to insure that all authorized users are utilizing and safeguarding the EIV information. This includes but is not limited to: a. Maintain a log of all authorized users. The log shall be updated on a quarterly or more frequent basis as may be required. b. Distribute all User Guides and Security policies and procedures to ALL staff using EIV system s data. c. Record and report improper disclosure in accordance with the improper disclosure procedure. d. Monitoring EIV system utilization reports. 4. EIV Staff Monitor (AHA section Housing Program Coordinator): a. Insuring confidentially of information displayed on monitors. b. Insuring the confidentially of printed EIV reports. c. Monitoring storage areas. d. Monitoring the disposal of EIV information. e. Maintain a log of employees receiving keys to controlled areas. f. Insure keys are returned when employees are no longer employed by AHA. g. Coordinate staff training and/or perform a review of the EIV Security procedures on a regular basis, but not less than annually and maintain a log of all AHA staff who have attended required trainings. 1. Certified Users: EIV users are authorized by the Division Manager or by his/her designee and shall have access to the system. Authorized users must safeguard and insure the confidentiality of User Codes and Passwords. EIV Users must complete a User Access Authorization Form and execute the Rules of Behavior and User Agreement prior to being given access to the EIV system. Once an authorized user is no longer employed by AHA, access will be terminated the date of termination. AHA has established the following classes of authorized personnel: a. Employees who must determine income for rent computation purposes for the Public Housing and Section 8 Housing Choice Voucher, Single Room Occupancy (SRO) and Moderate Rehabilitation programs. 3
5 b. Employees who must determine income for internal quality control purposes. Training 1. Initial EIV System All NEW users MUST first view the Initial EIV System Training before they are granted access to the EIV System. 2. Annual Security Awareness All EIV System users, views and handlers will attend an EIV Security Awareness Training annually. Disclosure of EIV System Information Security 1. At public housing placement or housing voucher certification and annual recertifications, AHA will disclose its intent to make use of the EIV system. This will include the following: a. An explanation of the EIV procedure. b. What action(s) AHA may seek after determining that income has been unreported or underreported. c. Signatures of all adult household members on the What you should Know About EIV Form. 2. All tenant files shall contain a properly completed and current HUD-9886 Form. 3. Requests for EIV information by the tenant will require a signed Release of EIV Form. 4. AHA will send EIV report information to all receiving portability Housing Authorities. EIV data will be safeguarded at all times: 1. Monitors EIV information displayed on Monitors will be safeguarded by: a. Insuring that EIV data monitor displays are only active (e.g., visible) when the information is being solicited for verification purposes and only when no other unauthorized persons are within viewing range. b. When user exits their office, even for short periods, users will either screen protect or blank the monitor screen. 3. Printed Reports: Employees will insure that all EIV information in printed format are: 4
6 a. immediately removed from printer trays. Especially if the printer utilized is in an unsecured common use area; and b. at no time left unattended where it is visible or in viewing distance of unauthorized staff or visitors; and c. filed in tenant files with all re-certification and interim calculations; and d. files filed in a secure location when not in use 4. Discussing EIV Information: a. EIV information can only be discussed with other authorized staff on a needs-to know basis. b. EIV information is protected at the individual household member level. Specific information pertaining to one family member cannot be discussed in the presence of other family members or other individuals. 5. Disposition: EIV data will be disposed of by: a. Destroyed 3 years after EOP date. Note: Shredding will be performed by an authorized AHA staff and/or contract shredding firm. Resolving Discrepancies AHA requires that all household income is reported by the family as specified in the Admissions and Continued Occupancy Policy (ACOP), lease, and the Section 8 Administrative Plan (Admin Plan). These documents are made a part of this policy by reference. When EIV information is substantially different from what the tenant reported and/or what was reported by a third party, the following procedures will be followed: 1. In any case where the tenant disputed the EIV data documenting the discrepant income, staff shall submit a third-party verification form to the income source(s); and 2. Staff shall refer the tenant disputing data to: a. Social Security b. Identity Theft Staff shall discuss the discrepancy with the tenant and the tenant shall be given the opportunity to resolve the discrepancy. Such discussion shall be either verbally or in writing. a. Although the tenant shall be given the opportunity to resolve the discrepancy, the final authority shall be either third-party verification or EIV data, whichever is accurate, unless the tenant can provide documentation that one or both parties data is incorrect. 5
7 Adverse Actions b. If the tenant is able to produce sufficient documentation of incorrect third party and/or EIV data, tenant shall be instructed to contact the proper staff person in charge of this data for resolution. Should AHA find, after a review of all of the information, that the tenant has failed to fully disclose all family income, AHA will: 1. Offer the tenant the opportunity to repay all retroactive rent overpayments/charges in accordance with AHA' established repayment policies. 2. If the family is unable or unwilling to repay, seek eviction or termination of the housing assistance; and At Least But Less Than Action $1 $4, Turn over to collection agency $5,000 or More Turn over to Office of the Inspector General (OIG) at HUD 6
*125* Last First MI Maiden. Street Address or P.O. Box City State Zip Code. Home Work Message. Disabled or Handicapped. Full Time
SEATTLE HOUSING AUTHORITY MOD REHAB SRO HOUSING APPLICATION *125* Head of Household Social Security Number Building Name: - - Approval for housing is subject to meeting all eligibility and suitability
ENTERPRISE INCOME VERIFICATION (EIV) SECURITY AWARENESS TRAINING QUESTIONNAIRES
ENTERPRISE INCOME VERIFICATION (EIV) SECURITY AWARENESS TRAINING QUESTIONNAIRES FOR MULTIFAMILY HOUSING PROGRAMS Background EIV contains personal information that is covered by the Privacy Act such as
MODEL LEASE FOR SUBSIDIZED PROGRAMS. 1. Parties and The parties to this Agreement are, referred to as the Landlord, and
MODEL LEASE FOR SUBSIDIZED PROGRAMS (A) 1. Parties and The parties to this Agreement are Dwelling, referred to as the Unit: Landlord, and (B), referred to as the Tenant. The Landlord leases (C) to the
CHANGE REPORT FORM HEAD OF HOUSEHOLD S EMAIL. Mark all that apply
Stamp(COCHA office use only) CHANGE REPORT FORM INFORMATION Pre Application F : NAME SOCIAL SECURITY NUMBER PHONE NUMBER ADDRESS HEAD OF HOUSEHOLD S EMAIL Mark all that apply I am a waiting list applicant
In order to adjudicate an appeal, OPM requires claimants or their authorized representatives to submit the following information:
SYSTEM NAME: Health Claims Disputes External Review Services. SYSTEM LOCATION: Office of Personnel Management, 1900 E Street NW., Washington, DC 20415. CATEGORIES OF INDIVIDUALS COVERED BY THE SYSTEM:
SCHOOL DISTRICT OF BLACK RIVER FALLS HIPAA PRIVACY AND SECURITY POLICY
SCHOOL DISTRICT OF BLACK RIVER FALLS HIPAA PRIVACY AND SECURITY POLICY School Board Policy 523.5 The School District of Black River Falls ( District ) is committed to compliance with the health information
ACCG Identity Theft Prevention Program. ACCG 50 Hurt Plaza, Suite 1000 Atlanta, Georgia 30303 (404)522-5022 (404)525-2477 www.accg.
ACCG Identity Theft Prevention Program ACCG 50 Hurt Plaza, Suite 1000 Atlanta, Georgia 30303 (404)522-5022 (404)525-2477 www.accg.org July 2009 Contents Summary of ACCG Identity Theft Prevention Program...
New HIPAA Breach Notification Rule: Know Your Responsibilities. Loudoun Medical Group Spring 2010
New HIPAA Breach Notification Rule: Know Your Responsibilities Loudoun Medical Group Spring 2010 Health Information Technology for Economic and Clinical Health Act (HITECH) As part of the Recovery Act,
HOUSING AUTHORITY OF THE CITY AND COUNTY OF DENVER VIOLENCE AGAINST WOMEN ACT PROCEDURE
HOUSING AUTHORITY OF THE CITY AND COUNTY OF DENVER VIOLENCE AGAINST WOMEN ACT PROCEDURE I. Purpose and Applicability The purpose of this policy (herein called Policy ) is to implement the applicable provisions
Personal Information Protection Act (PIPA) Privacy & Landlord - Tenant Matters Frequently Asked Questions
Personal Information Protection Act (PIPA) Privacy & Landlord - Tenant Matters Frequently Asked Questions Are landlords in Alberta bound by privacy law? Yes. The Personal Information Protection Act (PIPA)
APPLICATION FOR ADMISSION TO RIVERWALK PLACE. If you need assistance with filling out this application, please contact the office of RiverWalk Place.
RIVERWALK PLACE 431 E. EAGLE FLATS PARKWAY--APPLETON, WISCONSIN 54915 Phone: (920) 733-5046 Fax: 882-9427 TDD: 731-2406 Office Hours: Mon-Thurs 8am-4pm, Fri. 7:30am-3:30pm APPLICATION FOR ADMISSION TO
PBGC Information Security Policy
PBGC Information Security Policy 1. Purpose. The Pension Benefit Guaranty Corporation (PBGC) Information Security Policy (ISP) defines the security and protection of PBGC information resources. 2. Reference.
HIPAA Policy, Protection, and Pitfalls ARTHUR J. GALLAGHER & CO. BUSINESS WITHOUT BARRIERS
HIPAA Policy, Protection, and Pitfalls Overview HIPAA Privacy Basics What s covered by HIPAA privacy rules, and what isn t? Interlude on the Hands-Off Group Health Plan When does this exception apply,
8.03 Health Insurance Portability and Accountability Act (HIPAA)
Human Resource/Miscellaneous Page 1 of 5 8.03 Health Insurance Portability and Accountability Act (HIPAA) Policy: It is the policy of Licking/Knox Goodwill Industries, Inc., to maintain the privacy of
HUD HANDBOOK 4350.3: OCCUPANCY REQUIREMENTS OF SUBSIDIZED MULTIFAMILY HOUSING PROGRAMS SUMMARY FOR PROPERTY OWNER
HUD HANDBOOK 4350.3: OCCUPANCY REQUIREMENTS OF SUBSIDIZED MULTIFAMILY HOUSING PROGRAMS SUMMARY FOR PROPERTY OWNER TABLE OF CONTENTS Purpose of the Handbook and This Summary... 1 I. Introduction... 1 II.
CHAPTER 7. RECERTIFICATION, UNIT TRANSFERS, AND GROSS RENT CHANGES
CHAPTER 7. RECERTIFICATION, UNIT TRANSFERS, AND GROSS RENT CHANGES 7-1 Introduction A. As discussed in Chapter 5, a family s eligibility for assistance is based on its income, as determined in accordance
Privacy Policy. 30 January 2015
Privacy Policy 30 January 2015 Table of Contents 1 Overview 3 Purpose 3 Scope 3 2 Collection 3 What information do we collect? 3 What if you do not give us the information we request? 4 3 Use of information
U.S. DEPARTMENT OF HOUSING AND URBAN DEVELOPMENT WASHINGTON, DC 20410-8000
U.S. DEPARTMENT OF HOUSING AND URBAN DEVELOPMENT WASHINGTON, DC 20410-8000 ASSISTANT SECRETARY FOR HOUSING- FEDERAL HOUSING COMMISSIONER Special Attention of: NOTICE: H 2013-06 Multifamily Hub Directors
Frequently Asked Questions. PIH Notice 2013-3: Public Housing and Housing Choice Voucher Programs Temporary Compliance Assistance
Frequently Asked Questions PIH Notice 2013-3: Public Housing and Housing Choice Voucher Programs Temporary Compliance Assistance 1. Question: To what programs does this Notice apply? Answer: This Notice
CREATIVE SOLUTIONS IN HEALTHCARE, INC. Privacy Policy
CREATIVE SOLUTIONS IN HEALTHCARE, INC. Privacy Policy Amended as of February 12, 2010 on the authority of the HIPAA Privacy Officer for Creative Solutions in Healthcare, Inc. TABLE OF CONTENTS ARTICLE
MONTSERRAT COLLEGE OF ART WRITTEN INFORMATION SECURITY POLICY (WISP)
MONTSERRAT COLLEGE OF ART WRITTEN INFORMATION SECURITY POLICY (WISP) 201 CMR 17.00 Standards for the Protection of Personal Information Of Residents of the Commonwealth of Massachusetts Revised April 28,
INITIAL APPROVAL DATE INITIAL EFFECTIVE DATE
TITLE AND INFORMATION TECHNOLOGY RESOURCES DOCUMENT # 1107 APPROVAL LEVEL Alberta Health Services Executive Committee SPONSOR Legal & Privacy / Information Technology CATEGORY Information and Technology
PHI- Protected Health Information
HIPAA Policy 2014 The Health Insurance Portability and Accountability Act is a federal law that protects the privacy and security of patients health information and grants certain rights to patients. Clarkson
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) TERMS AND CONDITIONS FOR BUSINESS ASSOCIATES
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) TERMS AND CONDITIONS FOR BUSINESS ASSOCIATES I. Overview / Definitions The Health Insurance Portability and Accountability Act is a federal law
Enterprise Income Verification (EIV 9.3)
Enterprise Income Verification (EIV 9.3) System User Manual For Multifamily Housing Program Users Note to the reader of this document: In some cases, screen shots have been carried over from the previous
31-R-11 A RESOLUTION ADOPTING THE CITY OF EVANSTON IDENTITY PROTECTION POLICY. WHEREAS, The Fair and Accurate Credit Transactions Act of 2003,
5/23/2011 31-R-11 A RESOLUTION ADOPTING THE CITY OF EVANSTON IDENTITY PROTECTION POLICY WHEREAS, The Fair and Accurate Credit Transactions Act of 2003, Public Law 108-159, requires municipalities to promulgate
Index .700 FORMS - SAMPLE INCIDENT RESPONSE FORM.995 HISTORY
Information Security Section: General Operations Title: Information Security Number: 56.350 Index POLICY.100 POLICY STATEMENT.110 POLICY RATIONALE.120 AUTHORITY.130 APPROVAL AND EFFECTIVE DATE OF POLICY.140
UNIVERSITY PHYSICIANS OF BROOKLYN HIPAA BUSINESS ASSOCIATE AGREEMENT CONTRACT NO(S):
UNIVERSITY PHYSICIANS OF BROOKLYN HIPAA BUSINESS ASSOCIATE AGREEMENT CONTRACT NO(S): THIS AGREEMENT is made by and between UNIVERSITY PHYSICIANS OF BROOKLYN, INC., located at 450 Clarkson Ave., Brooklyn,
HOME RENTAL REHABILITATION PROGRAM
HOME RENTAL REHABILITATION PROGRAM The Rental Rehabilitation Program The City of Amsterdam is operating a housing rehabilitation program for rental properties located anywhere within the City limits. Program
HIPAA Information Security Overview
HIPAA Information Security Overview Security Overview HIPAA Security Regulations establish safeguards for protected health information (PHI) in electronic format. The security rules apply to PHI that is
BUSINESS ASSOCIATE AGREEMENT. Business Associate. Business Associate shall mean.
BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement is made as of the day of, 2010, by and between Methodist Lebonheur Healthcare, on behalf of itself and all of its affiliates ( Covered Entity
Subject: U.S. Department of Housing and Urban Development (HUD) Privacy Protection Guidance for Third Parties
U.S. Department of Housing and Urban Development Office of Public and Indian Housing SPECIAL ATTENTION OF: NOTICE PIH-2014-10 Directors of HUD Regional and Field Offices of Public Housing; Issued: April
CHAPTER 2. OCCUPANCY AUDIT PROCEDURES. Section 1. Scope of the Audit
CHAPTER 2. OCCUPANCY AUDIT PROCEDURES Section 1. Scope of the Audit 2-1. OVERVIEW. The occupancy audit includes a review of PHA admission and occupancy policies, tenant selection, leasing practices, rent
HIPAA and Privacy Policy Training
HIPAA and Privacy Policy Training July 2015 1 This training addresses the requirements for maintaining the privacy of confidential information received from HFS and DHS (the Agencies). During this training
BUSINESS ASSOCIATE AGREEMENT
BUSINESS ASSOCIATE AGREEMENT 1. The terms and conditions of this document entitled Business Associate Agreement ( Business Associate Agreement ), shall be attached to and incorporated by reference in the
HIPAA Business Associate Agreement
HIPAA Business Associate Agreement User of any Nemaris Inc. (Nemaris) products or services including but not limited to Surgimap Spine, Surgimap ISSG, Surgimap SRS, Surgimap Office, Surgimap Ortho, Surgimap
VILLAGE REHAB PROGRAM
I N T E R I O R R E G I O N A L H O U S I N G A U T H O R I T Y 8 2 8 2 7 T H A v e n u e F a i r b a n k s, A l a s k a 9 9 7 0 1 P h o n e : ( 9 0 7 ) 1-8 0 0-4 7 8-4 7 4 2 F a x : ( 9 0 7 ) 4 5 2-8
Gaston County HIPAA Manual
Gaston County HIPAA Manual Includes Gaston County IT Manual Action Date Reviewed and Revised December 2012 Gaston County HIPAA Policy Manual has be updated and combined with the Gaston County IT Manual.
Documentation Needed for Rehabilitation Program:
Documentation Needed for Rehabilitation Program: 1. Completed and Signed Home Rehabilitation Application (7 pages) 2. 2 Current Tax Returns (must sign 2 nd page), for everyone over 18 in household with
DEALERSHIP IDENTITY THEFT RED FLAGS AND NOTICES OF ADDRESS DISCREPANCY POLICY
DEALERSHIP IDENTITY THEFT RED FLAGS AND NOTICES OF ADDRESS DISCREPANCY POLICY This Plan we adopted by member, partner, etc.) on Our Program Coordinator (date). (Board of Directors, owner, We have appointed
Disclaimer: Template Business Associate Agreement (45 C.F.R. 164.308)
HIPAA Business Associate Agreement Sample Notice Disclaimer: Template Business Associate Agreement (45 C.F.R. 164.308) The information provided in this document does not constitute, and is no substitute
Form HUD-9634 10/09 Appendix 15-1
SAMPLE USE AGREEMENT Mark-up-to-Market Where a For-Profit Owner is Transferring the Property to a Non-Profit Owner or Budget-Based Rent Increase for Capital Repairs for a Nonprofit Owner This Agreement
BUSINESS ASSOCIATE AND DATA USE AGREEMENT NAME OF COVERED ENTITY: COVERED ENTITY FEIN/TAX ID: COVERED ENTITY ADDRESS:
BUSINESS ASSOCIATE AND DATA USE AGREEMENT NAME OF COVERED ENTITY: COVERED ENTITY FEIN/TAX ID: COVERED ENTITY ADDRESS:, City State Zip This Business Associate and Data Use Agreement ( Agreement ) is effective
FirstCarolinaCare Insurance Company Business Associate Agreement
FirstCarolinaCare Insurance Company Business Associate Agreement THIS BUSINESS ASSOCIATE AGREEMENT ("Agreement"), is made and entered into as of, 20 (the "Effective Date") between FirstCarolinaCare Insurance
[FACILITY NAME] IDENTITY THEFT PREVENTION PROGRAM. Effective May 1, 2009
[FACILITY NAME] IDENTITY THEFT PREVENTION PROGRAM Effective May 1, 2009 Because [FACILITY NAME] offers and maintains covered accounts, as defined by 16 C.F.R. Part 681 (the Regulations ), [FACILITY NAME]
OFFICE OF AUDIT REGION 9 LOS ANGELES, CA. Marina Village Apartments Sparks, NV. Section 221(d)(4) Multifamily Insurance Program
OFFICE OF AUDIT REGION 9 LOS ANGELES, CA Marina Village Apartments Sparks, NV Section 221(d)(4) Multifamily Insurance Program 2014-LA-1001 OCTOBER 24, 2013 Issue Date: October 24, 2013 Audit Report Number:
HIPAA Training for Hospice Staff and Volunteers
HIPAA Training for Hospice Staff and Volunteers Hospice Education Network Objectives Explain the purpose of the HIPAA privacy and security regulations Name three patient privacy rights Discuss what you
Patient Privacy and HIPAA/HITECH
Patient Privacy and HIPAA/HITECH What is HIPAA? Health Insurance Portability and Accountability Act of 1996 Implemented in 2003 Title II Administrative Simplification It s a federal law HIPAA is mandatory,
We will not collect, use or disclose your personal information without your consent, except where required or permitted by law.
HSBC Privacy Notice HSBC's Privacy Principles HSBC Bank Canada is a subsidiary of HSBC Holdings plc which, together with its subsidiaries and affiliates, is one of the world s largest banking and financial
Section 5 Identify Theft Red Flags and Address Discrepancy Procedures Index
Index Section 5.1 Purpose.... 2 Section 5.2 Definitions........2 Section 5.3 Validation Information.....2 Section 5.4 Procedures for Opening New Accounts....3 Section 5.5 Procedures for Existing Accounts...
Health Insurance Portability and Accountability Act (HIPAA) and Health Information Technology for Economic and Clinical Health Act (HITECH)
Health Insurance Portability and Accountability Act (HIPAA) and Health Information Technology for Economic and Clinical Health Act (HITECH) Table of Contents Introduction... 1 1. Administrative Safeguards...
SAMPLE BUSINESS ASSOCIATE AGREEMENT
SAMPLE BUSINESS ASSOCIATE AGREEMENT This is a draft business associate agreement based on the template provided by HHS. It is not intended to be used as is and you should only use the agreement after you
BUSINESS ASSOCIATE ADDENDUM
BUSINESS ASSOCIATE ADDENDUM This BA Agreement, effective as of the effective date of the Terms of Use, adds to and is made part of the Terms of Use by and between Business Associate and Covered Entity.
U.S. Department of Housing and Urban Development Office of Public and Indian Housing
U.S. Department of Housing and Urban Development Office of Public and Indian Housing Special Attention: NOTICE: PIH 2016-08 (HA) Public Housing Agencies; Public Housing Directors Issued: May 6, 2016 Expires:
Order. Directive Number: IM 10-3. Stephen E. Barber Chief Management Officer
Pension Benefit Guaranty Corporation Order Subject: Protecting Sensitive Information Directive Number: IM 10-3 Effective Date: 4/23/08 Originator: OGC Stephen E. Barber Chief Management Officer 1. PURPOSE:
Exhibit 2. Business Associate Addendum
Exhibit 2 Business Associate Addendum This Business Associate Addendum ( Addendum ) governs the use and disclosure of Protected Health Information by EOHHS when functioning as a Business Associate in performing
2014 Core Training 1
2014 Core Training 1 Course Agenda Review of Key Privacy Laws/Regulations: Federal HIPAA/HITECH regulations State privacy laws Privacy & Security Policies & Procedures Huntsville Hospital Health System
Approved By: Agency Name Management
Policy Title: Effective Date: Revision Date: Approval(s): LASO: CSO: Agency Head: Media Protection Policy Every 2 years or as needed Purpose: The intent of the Media Protection Policy is to ensure the
Policies and Procedures Audit Checklist for HIPAA Privacy, Security, and Breach Notification
Policies and Procedures Audit Checklist for HIPAA Privacy, Security, and Breach Notification Type of Policy and Procedure Comments Completed Privacy Policy to Maintain and Update Notice of Privacy Practices
Statement of Policy. Reason for Policy
Table of Contents Statement of Policy 2 Reason for Policy 2 HIPAA Liaison 2 Individuals and Entities Affected by Policy 2 Who Should Know Policy 3 Exclusions 3 Website Address for Policy 3 Definitions
BUSINESS ASSOCIATE AGREEMENT ( BAA )
BUSINESS ASSOCIATE AGREEMENT ( BAA ) Pursuant to the terms and conditions specified in Exhibit B of the Agreement (as defined in Section 1.1 below) between EMC (as defined in the Agreement) and Subcontractor
EXHIBIT C BUSINESS ASSOCIATE AGREEMENT
EXHIBIT C BUSINESS ASSOCIATE AGREEMENT THIS AGREEMENT is made and entered into by and between ( Covered Entity ) and KHIN ( Business Associate ). This Agreement is effective as of, 20 ( Effective Date
Health Information Privacy Refresher Training. March 2013
Health Information Privacy Refresher Training March 2013 1 Disclosure There are no significant or relevant financial relationships to disclose. 2 Topics for Today State health information privacy law Federal
INFORMATION EXCHANGE AGREEMENT BETWEEN THE SOCIAL SECURITY ADMINISTRATION AND THE STATE OF [NAME OF STATE], [NAME OF STATE AGENCY]
2012 MODEL STC AGREEMENT INFORMATION EXCHANGE AGREEMENT BETWEEN THE SOCIAL SECURITY ADMINISTRATION AND THE STATE OF [NAME OF STATE], [NAME OF STATE AGENCY] AS THE STATE TRANSMISSION/TRANSFER COMPONENT
COLUMBUS STATE COMMUNITY COLLEGE POLICY AND PROCEDURES MANUAL
PAYMENT CARD INDUSTRY COMPLIANCE (PCI) Effective June 1, 2011 Page 1 of 6 (1) Definitions a. Payment Card Industry Data Security Standards (PCI-DSS): A set of standards established by the Payment Card
Compliance Training for Medicare Programs Version 1.0 2/22/2013
Compliance Training for Medicare Programs Version 1.0 2/22/2013 Independence Blue Cross is an independent licensee of the Blue Cross and Blue Shield Association. 1 The Compliance Program Setting standards
ADDITIONAL SUMMARY OF RIGHTS
ADDITIONAL SUMMARY OF RIGHTS For Texas Residents: Under the Fair Credit Reporting Act (FCRA), all consumers are entitled to one free annual file disclosure in any twelve month period. You may be charged
Physical Access Control System
for the Physical Access Control System DHS/ALL 039 June 9, 2011 Contact Point David S. Coven Chief, Access Control Branch (202) 282-8742 Reviewing Official Mary Ellen Callahan Chief Privacy Officer (703)
SUBJECT: Identity Theft / Patient Misidentification POLICY NUMBER: Page 1 of 16 GENERATED BY: Integrity Compliance Office APPROVED BY:
SUBJECT: Identity Theft / Patient Misidentification POLICY NUMBER: ISSUED: 11/7/06 REVISED: 3/16/07; 5/6/08 (web reference updates only) Page 1 of 16 GENERATED BY: Integrity Compliance Office APPROVED
William D. Tamburrino, Director, Baltimore Public Housing Program Hub, 3BPH
Issue Date December 19, 2007 Audit Report Number 2008-PH-1004 TO: William D. Tamburrino, Director, Baltimore Public Housing Program Hub, 3BPH FROM: SUBJECT: John P. Buck, Regional Inspector General for
Professional Solutions Insurance Company. Business Associate Agreement re HIPAA Rules
Professional Solutions Insurance Company Business Associate Agreement re HIPAA Rules I. Purpose of Agreement This Agreement reflects Professional Solutions Insurance Company s agreement to comply with
NC DPH: Computer Security Basic Awareness Training
NC DPH: Computer Security Basic Awareness Training Introduction and Training Objective Our roles in the Division of Public Health (DPH) require us to utilize our computer resources in a manner that protects
APPENDIX 1: Frequently Asked Questions
APPENDIX 1: Frequently Asked Questions Practice Name Q: What is the HIPAA Privacy Rule? A: The HIPAA Privacy Rule controls the use and disclosure of what is known as Protected Health Information (PHI).
BERKELEY COLLEGE DATA SECURITY POLICY
BERKELEY COLLEGE DATA SECURITY POLICY BERKELEY COLLEGE DATA SECURITY POLICY TABLE OF CONTENTS Chapter Title Page 1 Introduction 1 2 Definitions 2 3 General Roles and Responsibilities 4 4 Sensitive Data
The Bureau of the Fiscal Service. Privacy Impact Assessment
The Bureau of the Fiscal Service Privacy Impact Assessment The mission of the Bureau of the Fiscal Service (Fiscal Service) is to promote the financial integrity and operational efficiency of the federal
6-8065 Payment Card Industry Compliance
0 0 0 Yosemite Community College District Policies and Administrative Procedures No. -0 Policy -0 Payment Card Industry Compliance Yosemite Community College District will comply with the Payment Card
Frequently Asked Questions for Condominium Corporations
Frequently Asked Questions for Condominium Corporations This document will be updated periodically as other questions are raised regarding the Personal Information Protection Act (PIPA). This document
HIPAA Happenings in Hospital Systems. Donna J Brock, RHIT System HIM Audit & Privacy Coordinator
HIPAA Happenings in Hospital Systems Donna J Brock, RHIT System HIM Audit & Privacy Coordinator HIPAA Health Insurance Portability and Accountability Act of 1996 Title 1 Title II Title III Title IV Title
If you would like to review the property selection policy please request a copy from the Site Manager.
Thank you for your interest in applying at one of our apartment communities. Cascade Management, Inc. (CMI) is committed to Fair Housing and follows the laws of Equal Opportunity Housing, the Fair Housing
HIPAA. New Breach Notification Risk Assessment and Sanctions Policy. Incident Management Policy. Focus on: For breaches affecting 1 3 individuals
HIPAA New Breach Notification Risk Assessment and Sanctions Policy Incident Management Policy For breaches affecting 1 3 individuals +25 individuals + 500 individuals Focus on: analysis documentation PHI
HIPAA Compliance. 2013 Annual Mandatory Education
HIPAA Compliance 2013 Annual Mandatory Education What is HIPAA? Health Insurance Portability and Accountability Act Federal Law enacted in 1996 that mandates adoption of Privacy protections for health
