HIPAA PRIVACY AND SECURITY STANDARDS CITY COMPLIANCE

Size: px
Start display at page:

Download "HIPAA PRIVACY AND SECURITY STANDARDS CITY COMPLIANCE"

Transcription

1 Important: Conducting an assessment of your health plan(s) is the first step to determining HIPAA compliance. You will need to conduct a separate assessment for each of your health plans. (Please be aware that each numbered item below is explained in greater detail on the following sheet). Health plan being assessed: 1. Does the plan exist for purposes of providing or paying for the cost of medical care? Yes 2. Does the plan provide health benefits solely through a contract for insurance with a state licensed insurance carrier or HMO? Yes 5. Does the city receive more than enrollment / disenrollment YES and summary health information? Yes 3. Are there more than 50 participants? The plan is NOT a covered entity under HIPAA and is not required to comply with HIPAA s Privacy and Security Standards Yes 4. Is the health plan selfadministered? 7. The plan is a covered entity under HIPAA and is required to comply with all of HIPAA s Privacy Standards (fully-insured hands on or self-insured with full mandates). Proceed to Question 8 below regarding the HIPAA Security Standards. 8. Does the covered entity store, maintain or transmit PHI electronically? 6. The plan is a covered entity under HIPAA but has minimal responsibility for complying with HIPAA s Privacy Standards (fully-insured hands off with minimal mandates). Proceed to Question 8 regarding the HIPAA Security Standards. Yes 9. The plan is subject to applicable HIPAA Privacy Standards and all HIPAA Security Standards with respect to PHI and ephi. 10. The plan is subject to applicable HIPAA Privacy Standards but NOT subject to the HIPAA Security Standards.

2 FLOW CHART QUESTION AND ANSWERS 1. Does the plan exist for purposes of providing or paying for the cost of medical care? A health plan could be an individual or a group health plan for purposes of HIPAA. A health plan includes (but is not limited to) employer sponsored benefit plans like those covered under ERISA, health insurers, HMOs, group health plans, and many public benefit programs (Medicare and Medicaid). You would respond 'Yes' if your city has any of the following types of plans: Medical Dental Vision Prescription drug Behavioral Health Wellness plan that provides health benefits EAP that provides health benefits High Deductible Plan Health Reimbursement Arrangements (HRAs) including a Post Employment Health Care Savings Plan Flex Plan (medical reimbursement portion) Long-term care Examples of plans in which the city would respond include: Long term and short term disability (income replacement) Workers Compensation Life Insurance Flex plans (portions covering child care expenses) Other non-health plans 2. Does the plan provide health benefits through a contract for insurance with a state licensed insurance carrier or HMO? A contract for insurance is not a contract for administrative services it essentially means that the city is covered under a fully insured plan. See (a)(2) and related sections of the Final Privacy Rule for more detail. If the plan meets the criteria above (benefits provided through a contract for insurance with a state licensed carrier or HMO), the city would respond Yes. Unless the plan meets all the criteria, you would respond. For example: If the plan participates in a pool through a contract / joint powers agreement with an entity which is not a health insurance issuer or an HMO, you would answer (e.g. coverage through the Service Cooperatives). If the contract between the plan and the insurance issuer or HMO is for administrative services only (i.e. third party administrative services), you would answer.

3 If the plan pays any or all of the insurance claims of its members (essentially the plan is self-insured), you would respond. 3. Are there more than 50 participants in the health plan? HIPAA provides a limited exemption for those plans that (a) have less than 50 participants, (b) are self-insured, and (c) self-administer their own plan. All three requirements must be met. Health plans that have more than 50 participants and/or contract with a third party to administer the plan do not qualify for the exemption. A "plan participant" is an employee who is eligible for and actually participating in the health plan. However, cities that have close to 50 participants will need to be aware of the HIPAA requirements in the event that they go over 50 employees in the future. 4. Is the health plan self-administered? Again, HIPAA provides an exemption for those plans that have less than 50 participants and self-administer their own plan. Any other arrangements for services, such as a contract with a third party to administer claims processing, enrollment, billing, etc. (or plans with more than 50 eligible participants), do not qualify for the exemption. See Definitions of the Final Privacy Rule for more information. 5. Does the City receive more than enrollment / disenrollment and summary health information? Enrollment / disenrollment information is information regarding a person s eligibility for and election to participate under a HIPAA covered health plan. Summary Health Information is information that summarizes claims history, claims expenses, and types of claims experience by individuals under a health plan provided it has been de-identified with the exception that it may include five digit zip codes. Names Geographic units (e.g. Apt or house number, street address, city) Dates related to an individual, including birth date, admission date, discharge date, date of death Ages Telephone numbers and fax numbers addresses Social security numbers Medical record numbers, health plan beneficiary numbers, account numbers Certificate/license numbers Vehicle identifiers and serial numbers, including license plate numbers Device identifiers and serial numbers Web Universal Resource Locators (URLs) and Internet Protocol (IP) address numbers Biometric identifiers, including finger and voice prints Full face photographic images and any comparable images Any other unique identifying number, characteristic, or code All of these identifiers would have to be removed for you to answer. If you receive claims data with any of the identifiers listed above, you would respond Yes.

4 te: If you receive information with these kinds of identifiers, then the city may want to evaluate whether or not they really need this information for purposes of sponsoring the health plan. If they don t need this information, then the city may want to discontinue receiving it. 6. The plan is a covered entity under HIPAA but has minimal responsibility for complying with the Administrative Simplification regulations. Based on the information provided, this plan has minimal responsibilities under HIPAA. The plan must: t require any member to waive their HIPAA rights as a condition for enrolling in a health plan, eligibility for benefits, treatment or payment of health care expenses. t discriminate on the basis of any health condition. Amend plan documents if you want access to protected health information from the group health plan (te: This may increase your responsibilities under HIPAA). Obtain authorization from the individual in cases where they may seek your assistance with a health claim or appeal involving the health insurer. Because the plan does receive protected health information (albeit limited PHI) such as enrollment and eligibility information, the plan must also get a Business Associate Agreement with their broker and anyone else doing anything on their behalf that receives PHI. Under HIPAA, the plan is not required to get a Business Associate Agreement with the carrier/hmo [fully insured plans only] or the plan's sponsor/employer. 7. The plan is a covered entity under HIPAA and is required to comply with all of the Administrative Simplification regulations. Based on the information provided, this plan must comply with all of HIPAA's Administrative Simplification requirements that relate to health plans, including: Modifying plan documents to permit information sharing between the group health plan and the plan sponsor, and institute procedures for complying with those amendments. Designating a privacy official. This individual is responsible for ensuring the procedures are followed and has the authority to make determinations about what and how information can be released. This could be the city s data practice official. Designating who may access Protected Health Information. Establishing firewalls to limit or restrict the flow of information between the group health plan and the employer as the plan sponsor. Creating and implementing policies and procedures and maintain documentation. Complying with the privacy rules regarding use and disclosure of protected health information obtain authorization or consent as required. Certifying to your carrier/hmo that you are HIPAA compliant. Issuing a tice of Privacy Practices to employees. Identifying Business Associates (such as third party administrators and/or the city s agent/broker) and amend contracts with each to ensure that these entities take steps to comply with HIPAA. Obtaining authorization or consent in order to receive or disclose protected health information.

5 Training employees who use or disclose protected health information on the plan s privacy policies and procedures. Developing a grievance procedure for individuals challenging or disputing the use or disclosure of health information. Tracking certain types of member information requests for six years. Allowing members to amend their medical records. Allowing members to restrict access to certain medical information. Please be aware that some of these functions may be delegated to the city s third party administrator through the business associate agreement, which should outline what responsibilities the city has as the covered entity in regards to HIPAA compliance and what responsibilities the TPA has as the business associate. Even if you delegate responsibilities to your business associate(s), the city is not entirely off the hook you still have an obligation to make sure that the business associate is complying with HIPAA. For instance, you should review the business associate agreement annually and/or request reports or documentation showing compliance activities on the part of the business associate (these reports could be requested annually, semi-annually or quarterly). 8. Does the covered entity store, maintain or transmit PHI electronically? In order to respond to this question, covered entities must conduct a risk assessment/analysis and document their determinations regarding whether the security measures apply to them or not. There is no exception for small health plans (other than the delayed effective date and the exception for small self-administered plans see FAQ #7). Therefore, all group health plans, whether self-administered, self-insured and administered by a third party administrator, or fully insured, must evaluate the extent to which they must comply (if at all) to the security standards. The security standards build upon the HIPAA privacy rules and are intended to protect the privacy and confidentiality of electronic protected health information (E-PHI) from improper access and interception. They are designed to ensure that electronic health information is accurate and accessible only to certain people. The security rules apply to protected health information that is electronically maintained or used in an electronic transmission, regardless of format (for a definition of protected health information, see #4 under the FAQ). E-PHI is PHI in electronic media such as through the Internet, leased lines, dial-up lines and private networks. Telephone voice response and faxback systems are covered under the security standards, but not paper-to-paper faxes, video conferencing or messages left on voic . There is no distinction between internal or external communications, so even internal transactions must meet the requirements. Examples of a Yes response may include: Conducting enrollment, disenrollment and/or billing online. communications with employees and/or the health insurance carrier or third party administrator that contains PHI. The city self-administers its health flexible spending account under the cafeteria plan and stores all claims information in a database on the computer system.

6 Examples of a NO response might include: The city faxes an explanation of benefits that they received from an employee on a claim issue to the health insurance carrier [Caution: Still HIPAA privacy concerns]. The city receives quarterly claims information that is provided in aggregate form with no individually identifiable information. The city does not store any PHI on the computer (all information is kept in hard copy in locked file cabinets) note: one to the health insurance carrier or TPA that contains PHI will likely subject the city to the security standards. 9. The plan is subject to the HIPAA security standards. The good news is that the security rules allow covered entities some flexibility to determine which of the security measures are appropriate for their circumstances. The security standards are designed to be general and flexible enough to be used in varying degrees according to the size of the covered entity, sophistication and financial capability. The security requirements can be broken down into five categories: Administrative safeguards Physical safeguards Technical safeguards Organizational requirements Policies, procedures and documentation requirements More information about each of these requirements can be found by going to the HIPAA Security Overview information sheet. The League is also working to develop templates of policies and procedures relating to the security standards. Member cities may contact the League s HR & Benefits Department at or to request a copy of this additional tool. 10. The plan is NOT subject to the HIPAA security standards. Even if you determine that your city is not subject to the HIPAA security standards, it is important that you first conduct the risk analysis and document your determination regarding the city s need to comply (or not) with the security standards. It is also important to realize that a simple containing PHI may subject the city to the security standards. Cities currently not subject to the security standards may need to monitor and evaluate this matter on an ongoing basis to ensure that the city is ready to comply at any given point and time during the year if necessary.

7 FREQUENTLY ASKED QUESTIONS 1. What is HIPAA? Congress passed the Health Insurance Portability and Accountability Act (HIPAA) in 1996 to reform health care. It is intended to streamline industry inefficiencies, reduce paper work, make it possible for workers to switch jobs even if they or a family member has a pre-existing condition and to protect the privacy of individual medical information. HIPAA's administrative simplification regulations affect healthcare providers, clearinghouses, and health plans including insurance companies, HMOs and employer-sponsored health plans. These regulations require standardized electronic transactions, improved privacy and security methods, and greater access to and rights for individuals regarding their health information. HIPAA is a federal law that creates a starting point for protecting individual health information. To the extent other laws already apply, they are still applicable (e.g. Data Privacy Act). 2. Who does HIPAA affect? HIPAA affects virtually all health care providers in the United States who conduct certain financial and administrative transactions electronically; health care clearinghouses; health plans, including insurance companies, HMOs and most employer-sponsored health plans; and any business associates of any of the aforementioned groups, such as third party administrators and/or the city s agent, broker and/or benefit consultant. For more detailed definitions about what entities are considered to be covered entities under HIPAA, see Applicability and Definitions of the HIPAA privacy rule. 3. What are the HIPAA privacy rules? The HIPAA privacy rules mandate that a covered entity (e.g. a group health plan) must implement policies and procedures with respect to protected health information (PHI). The policies and procedures must be reasonably designed, taking into account the size and type of activities that relate to PHI undertaken by the covered entity to ensure compliance. 4. What is protected health information? Protected health information (PHI) is individually identifiable information, which is created, modified, received or maintained by a covered entity that relates to an individual s past, present or future physical or mental condition, treatment or payment for care. This information is protected if transmitted in electronic, written or oral form. The following information may be considered PHI or may contain PHI: Medical records Diagnosis of a certain condition Procedure codes on claim forms Claims data or information Explanation of Benefits (EOB) Pre-authorization forms

8 Crime reports Coordination of benefit forms Enrollment Election forms Reimbursement request forms Records indicating payment Claims denial and appeal information Protected health information does not necessarily need to provide an individual s name, address or social security number to be considered individually identifiable information a high dollar claim report that contains only diagnoses or procedures and amounts paid during a specific period might contain individually identifiable information if the city has a relatively small number of participants in the health plan. Therefore, small cities may need to take extra precautions to ensure that they are protecting employee health information even if the information is provided on an aggregate/group basis. 5. What is E-PHI? Where the privacy standards cover all PHI regardless of the form it takes (whether it is written, verbal, electronic), the security standards cover only PHI that is in electronic form (i.e. PHI that is electronically maintained or transmitted regardless of form). E-PHI is PHI in electronic form, including storage media such as hard drives and disks, as well as transmission media such as through the Internet, leased lines, dial-up lines and private networks. Telephone voice response and faxback systems are covered under the security standards but not paper-to-paper faxes, video conferencing or messages left on voic . There is no distinction between internal or external communications, so even internal transactions within an organization must meet the requirements. 6. How can protected health information be used? A health plan that is subject to the HIPAA privacy and security standards may generally use or disclose PHI without obtaining an individual authorization for purposes of payment, treatment or healthcare operations; or for public policy purposes (e.g. as required by law or to avert a serious health or safety issue). However, use or disclosure of PHI generally must be kept to the minimum necessary to accomplish the task. This applies both internally and externally. 7. As an employer is my city subject to the HIPAA privacy and security rules?. As an employer, the city is not subject to the HIPAA privacy and security rules. However, keep in mind that many cities sponsor a group health plan of some sort, so the city as a sponsor of those plans would likely be a covered entity. The city will also need to make sure that there is adequate separation between its employment-related functions and the group health plan functions to ensure that information from the group health plan is not used for making employment related decisions. Many cities conduct certain functions that may fall under HIPAA and other functions that do not fall under HIPAA (e.g. health plan functions and employer/hr functions). Each of these functions may be treated separately in what is called a hybrid entity. A hybrid entity is an entity that has some covered and some non-covered functions ( discusses hybrid entities

9 and their responsibilities). HIPAA dictates that the covered functions must act (in regards to protected health information) as if they were a separate company, requiring the same separation and controls as if they were actually separate legal entities. 8. Is there an exception for small health plans? The HIPAA privacy and security rules do not apply to a city s group health plan that is selfinsured, has fewer than 50 participants AND is self-administered it is important to realize that all three conditions must be met in order for the city to be exempt from all of the privacy and security requirements. 9. Does my city need to do a separate assessment for each of the health plans that we sponsor? Yes. Each city should identify the health plans that it sponsors and conduct an assessment for each one. Since HIPAA applies to the separate plans, it is important to think about the role of the plan, not the employer, when conducting this assessment. For example, if you have a separate dental, medical and flex plan, they may each have different requirements under HIPAA, so you need to run separate assessments for each one. Once each plan has been identified, the city should go through the flow chart on the previous page to identify whether or not each plan is a covered entity and if so, to what degree it will need to comply with the HIPAA privacy standards. It is also important to document your city s assessment for each plan. If you do not think that you are a covered entity under HIPAA, we recommend that you document the fact that you conducted the assessment and the reasons for why you think you are not subject to HIPAA s requirements. 10. What if I only receive summary health information and conduct enrollment / disenrollment activities? A health plan, regardless of size, is exempt from many of the HIPAA privacy requirements if (1) the plan provides health benefits only through an insurance contract with a health insurer or an HMO, and (2) the plan does not create or receive any individually identifiable protected health information other than summary health information (I.e. information which has had all identifiers deleted from it other than some geographic information) and basic enrollment and disenrollment information. te: This same exemption does not apply to the security standards. Because the plan does receive some limited protected health information, such as enrollment and eligibility information, the plan should get a business associate agreement with their agent/broker or anyone else doing anything on their behalf that receives PHI. te: Under HIPAA, the plan is not required to get a business associate agreement with the insurance carrier/hmo (e.g. Medica, HealthPartners, BCBS) or the plans sponsor/employer (e.g. the city). 11. Our city offers a fully insured health plan, but we also self-insure some of the benefits (e.g. we reimburse employees for their out of pocket costs, such as deductibles or copays). Is this a covered entity? In this situation, you have two separate plans that you must assess individually to determine the level of compliance responsibility. If you do not meet the small group exception, then you will have to comply with the HIPAA privacy standards. See questions 6 and 7 under the flow

10 chart Q & A section for the administrative requirements necessary to comply with these standards. 12. We are part of a self-insured pool through a Joint Powers Agreement (such as the Service Cooperatives). To what extent does the city need to comply with HIPAA. As part of a Joint Powers Agreement, you are considered to be a self-insured plan that would have to comply with HIPAA s privacy standards even if you do not receive protected health information. You will need to enter into a business associate agreement with the joint powers organization or third party administrator to ensure that they take steps to comply with HIPAA and to outline which party will be responsible for certain compliance activities. You will want to carefully review what functions the city will perform and what functions the business associate (i.e. joint powers organization or third party administrator) will perform. An argument could be made that the joint powers organization or third party administrator would have a bulk of the responsibility for complying with HIPAA. A city might be able to minimize its obligations under HIPAA by delegating many of the compliance activities to the third party administrator or joint powers organization, such as modifying plan documents, providing privacy notices to employees, etc. However, even if the city delegates many of the responsibilities to the third party, the city ultimately is responsible for making sure those entities are HIPAA compliant. In other words, your obligation under HIPAA doesn t cease to exist by delegating compliance responsibilities to a third party. 13. What if the city has more than one health plan that falls under the HIPAA privacy requirements essentially, the city has more than one covered entity? HIPAA allows multiple health plans that are covered entities and maintained by the same plan sponsor to work together as if it were just one covered entity. This is referred to as an Organized Health Care Arrangement (OHCA). An OHCA allows a city to satisfy the HIPAA requirements just once rather than multiple times. In other words, if a city has two health plans (e.g. a self-insured medical plan and a medical reimbursement plan), the city could bundle those plans together and form an OHCA. Therefore, the city would only have to comply once rather than two separate times. Please note that this OHCA designation is only allowed under HIPAA and does not extend to other benefit laws and regulations (e.g. COBRA, IRS tax code, etc.). 14. Are there other city functions that might make us a covered entity? There are a variety of ways in which a city may be considered a covered entity under HIPAA. Cities self-insuring employee benefits, including group health plans and health flexible spending accounts, city-owned medical clinics, hospitals and/or nursing homes, and cities with public health departments are likely considered a covered entity that must comply with the HIPAA administrative simplification standards (including the privacy and security standards). Since the HIPAA privacy and security standards may impact various departments within the city, such as human resources, the technology department, fire departments with ambulance

11 services or the police and corrections department (relating primarily to health information on inmates), cities are encouraged to conduct a department-by-department assessment to determine which areas may be subject to HIPAA including evaluating which departments may have access to and use individually identifiable health information, as well as how access to this information can be limited (i.e. what fire walls or protections can be put in place to limit access to this information). HIPAA potentially impacts several departments if the city does any of the following: Receives, uses, discloses or maintains private health information Administers a public health program. Contracts with or is considered a business associate of a covered entity, such as a third party administrator for its self-insured health plan or is a plan sponsor under a fully insured health plan. Owns medical clinics, hospitals, ambulance services, home health care agencies and/or nursing homes. Performs certain health plan functions on behalf of the insurance carrier. Has a Health Flexible Spending Account Transmits individual health information electronically In addition, cities that charge a fee (or are thinking of charging a fee) to citizens for first responders (ambulance, firefighters, police officers) should be aware that by doing so, the city may end up falling under the HIPAA requirements if they provide medical care to those citizens. In this case, the city would fall under HIPAA as a health care provider. 15. What do the security standards require? At a minimum, the security standards require that a covered entity conduct a risk assessment and document their determinations regarding whether the security measures apply to them. Even if a city thinks that it is not subject to the security standards, it should go through this assessment and document the reasons why it is not covered under the security standards (e.g. the city does not conduct billing or enrollment online, the city only communicates with vendors/insurance carriers and employees by telephone regarding employee claim questions and issues, and none of the information containing PHI is stored on the computer it is only kept in file cabinets under lock and key). If a city is subject to the security standards, there are five sets of safeguards and requirements that must be met (more information about each can be found by going to the HIPAA Security Overview Information Sheet): Administrative safeguards Physical safeguards Technical safeguards Organizational requirements Policies and procedures and documentation requirements The good news is that the security standards allow covered entities some flexibility to determine which of the security measures are appropriate for their circumstances. The security standards are designed to be general and flexible enough to be used in varying degrees according to the size of the covered entity, sophistication and financial capability.

12 Covered entities must address the security measures under each safeguard and determine whether the measure is reasonable and appropriate to implement for that organization. If it is appropriate, then the measure must be implemented. If not, then it must be documented why it is unreasonable and implement an equivalent, alternative measure if reasonable to do so. 16. What are the deadlines for complying with HIPAA? All cities should now be incompliance with HIPAA s privacy standards. The deadline for complying with the privacy standards for most covered entities was April 13, However, there was a one-year extension for small health plans (those plans with less than $5 million in premiums for fully-insured plans or $5 million in claims for self-insured plans). Most cities will have fallen under the extension and will need to have complied with HIPAA by April 14, The deadline for complying with the security standards for most covered entities and large health plans was April 20, As with the privacy standards, small health plans (and therefore many cities) received a one-year extension and will need to comply with the security standards by April 21, 2006, which means covered entities must conduct their risk assessment, implement the appropriate safeguards (or alternative safeguard measures, if appropriate), and have implemented policies and procedures by these dates. 17. What additional resources are available on HIPAA compliance? The League has worked with a benefits attorney to develop templates of policies and procedures for both the privacy and security standards. Member cities may contact Erin Rian, LMC Benefits Manager, at or by at erian@lmnc.org for these additional tools or if you have questions about HIPAA compliance for your city. In addition, the following resources may be of some assistance to cities as they evaluate how these regulations apply to the city or its departments: HIPAA Compliance Guide Employee Benefits Institute of America (EBIA) or A subscription fee applies Quick Reference to HIPAA Compliance International Foundation of Employee Benefit Plans, A subscription fee applies. Employers Guide to HIPAA Privacy Requirements Thompson Publishing, A subscription fee applies. Link to the U.S. Department of Health and Human Services for information on the privacy and security standards MN Department of Human Services (DHS) website

January 2003. Employers must be prepared for their obligations under the HIPAA Privacy Rules

January 2003. Employers must be prepared for their obligations under the HIPAA Privacy Rules Employer Sponsored Group Health Plans and the HIPAA Privacy Rules Employers must be prepared for their obligations under the HIPAA Privacy Rules January 2003 Bob Radecki KnowHIPAA.com HIPAA-COBRA-FMLA

More information

The HIPAA Privacy Rule: Overview and Impact

The HIPAA Privacy Rule: Overview and Impact The HIPAA Privacy Rule: Overview and Impact DISCLAIMER: This information is provided as is without any express or implied warranty. It is provided for educational purposes only and does not constitute

More information

HIPAA. Privacy and Security Frequently Asked Questions for Employers. Gallagher Benefit Services, Inc.

HIPAA. Privacy and Security Frequently Asked Questions for Employers. Gallagher Benefit Services, Inc. 2013 HIPAA Privacy and Security Frequently Asked Questions for Employers Gallagher Benefit Services, Inc. Disclaimer We share this information with our clients and friends for general informational purposes

More information

NLRG HIPAA PRIVACY SHORTCUT ROUTE: AN EMPLOYER GUIDE PARTNERING WITH YOU ON TRENDS AND BEST PRACTICES TO SUPPORT YOUR HUMAN RESOURCES INITIATIVES

NLRG HIPAA PRIVACY SHORTCUT ROUTE: AN EMPLOYER GUIDE PARTNERING WITH YOU ON TRENDS AND BEST PRACTICES TO SUPPORT YOUR HUMAN RESOURCES INITIATIVES NLRG PARTNERING WITH YOU ON TRENDS AND BEST PRACTICES TO SUPPORT YOUR HUMAN RESOURCES INITIATIVES HIPAA PRIVACY SHORTCUT ROUTE: AN EMPLOYER GUIDE PERFORMANCE MANAGEMENT EMPLOYER GUIDE PAGE 1 HIPAA PRIVACY

More information

HIPAA COMPLIANCE. What is HIPAA?

HIPAA COMPLIANCE. What is HIPAA? HIPAA COMPLIANCE What is HIPAA? The Health Insurance Portability and Accountability Act (HIPAA) also known as the Privacy Rule specifies the conditions under which protected health information may be used

More information

HIPAA. HIPAA and Group Health Plans

HIPAA. HIPAA and Group Health Plans HIPAA HIPAA and Group Health Plans CareFirst BlueCross BlueShield is the business name of CareFirst of Maryland, Inc. and is an independent licensee of the Blue Cross and Blue Shield Association. Registered

More information

An Employer s Introduction to HIPAA Prepared by Ballard, Rosenberg Golper & Savitt, LLP

An Employer s Introduction to HIPAA Prepared by Ballard, Rosenberg Golper & Savitt, LLP An Employer s Introduction to HIPAA Prepared by Ballard, Rosenberg Golper & Savitt, LLP Important Disclaimer: Practice limited to labor and employment law on behalf of management and related litigation.

More information

BROWN RUDNICK BERLACK ISRAELS LLP. Group Health Plan Compliance with HIPAA and ERISA: NAVIGATING THE LEGAL AND

BROWN RUDNICK BERLACK ISRAELS LLP. Group Health Plan Compliance with HIPAA and ERISA: NAVIGATING THE LEGAL AND B R B I BROWN RUDNICK BERLACK ISRAELS LLP Group Health Plan Compliance with HIPAA and ERISA: NAVIGATING THE LEGAL AND ADMINISTRATIVE MAZE Q&A 2003 QUESTION AND ANSWER RESOURCE GUIDE Group Health Plan Compliance

More information

RONALD V. MCGUCKIN AND ASSOCIATES Post Office Box 2126 Bristol, Pennsylvania 19007 (215) 785-3400 (215) 785-3401 (Fax) childproviderlaw.

RONALD V. MCGUCKIN AND ASSOCIATES Post Office Box 2126 Bristol, Pennsylvania 19007 (215) 785-3400 (215) 785-3401 (Fax) childproviderlaw. RONALD V. MCGUCKIN AND ASSOCIATES Post Office Box 2126 Bristol, Pennsylvania 19007 (215) 785-3400 (215) 785-3401 (Fax) childproviderlaw.com HIPAA The Health Insurance Portability and Accountability Act

More information

State of Nevada Public Employees Benefits Program. Master Plan Document for the HIPAA Privacy and Security Requirements for PEBP Health Benefits

State of Nevada Public Employees Benefits Program. Master Plan Document for the HIPAA Privacy and Security Requirements for PEBP Health Benefits State of Nevada for the Requirements for PEBP Health Benefits Plan Year 2016 July 1, 2015 June 30, 2016 www.pebp.state.nv.us (775) 684-7000 Or (800) 326-5496 Amendments Amendment Log Any amendments, changes

More information

HIPAA Policy, Protection, and Pitfalls ARTHUR J. GALLAGHER & CO. BUSINESS WITHOUT BARRIERS

HIPAA Policy, Protection, and Pitfalls ARTHUR J. GALLAGHER & CO. BUSINESS WITHOUT BARRIERS HIPAA Policy, Protection, and Pitfalls Overview HIPAA Privacy Basics What s covered by HIPAA privacy rules, and what isn t? Interlude on the Hands-Off Group Health Plan When does this exception apply,

More information

Guidelines Relating to Implementation of the Privacy Regulations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA)

Guidelines Relating to Implementation of the Privacy Regulations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) HUMAN RESOURCES Index No. VI-35 PROCEDURES MEMORANDUMS TO: FROM: SUBJECT: MCC Personnel Office of the President Guidelines Relating to Implementation of the Privacy Regulations of the Health Insurance

More information

Plan Sponsor Guide HIPAA Privacy Rule

Plan Sponsor Guide HIPAA Privacy Rule Plan Sponsor Guide HIPAA Privacy Rule Plan Sponsor s Guide to the HIPAA Privacy Rule Compliments of Aetna 00.02.108.1A (5/05) Compliments of Aetna You have likely heard a great deal about the HIPAA Privacy

More information

HIPAA Compliance Manual

HIPAA Compliance Manual HIPAA Compliance Manual HIPAA Compliance Manual 1 This Manual is provided to assist your efforts to comply with the federal privacy and security rules mandated under HIPAA and HITECH, specifically as said

More information

Alert. Client PROSKAUER ROSE LLP. HIPAA Compliance Update: Employers, As Group Health Plan Sponsors, Will Be Affected By HIPAA Privacy Requirements

Alert. Client PROSKAUER ROSE LLP. HIPAA Compliance Update: Employers, As Group Health Plan Sponsors, Will Be Affected By HIPAA Privacy Requirements PROSKAUER ROSE LLP Client Alert HIPAA Compliance Update: Employers, As Group Health Plan Sponsors, Will Be Affected By HIPAA Privacy Requirements The U.S. Department of Health and Human Services published

More information

HIPAA Privacy Manual

HIPAA Privacy Manual California State University HIPAA Privacy Manual Revised February 17, 2010 As prepared by Mercer Human Resource Consulting 2010 California State University The HIPAA Privacy Manual was drafted for the

More information

HIPAA COMPLIANCE INFORMATION. HIPAA Policy

HIPAA COMPLIANCE INFORMATION. HIPAA Policy HIPAA COMPLIANCE INFORMATION HIPAA Policy Use of Protected Health Information for Research Policy University of North Texas Health Science Center at Fort Worth Applicability: All University of North Texas

More information

HIPAA Privacy Rule Primer for the College or University Administrator

HIPAA Privacy Rule Primer for the College or University Administrator HIPAA Privacy Rule Primer for the College or University Administrator On August 14, 2002, the Department of Health and Human Services ( HHS ) issued final medical privacy regulations (the Privacy Rule

More information

HIPAA PRIVACY AND EDI RULES

HIPAA PRIVACY AND EDI RULES The Health and Human Services (HHS) issued final HIPAA privacy regulations on August 14, 2002. These rules govern how individually identifiable medical information must be protected. HIIPAA also requires

More information

Covered Entity Charts

Covered Entity Charts Covered Entity Charts Guidance on how to determine whether an organization or individual is a covered entity under the Administrative Simplification provisions of HIPAA 2 Background: The Administrative

More information

THE HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) EMPLOYEE TRAINING MANUAL

THE HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) EMPLOYEE TRAINING MANUAL THE HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) EMPLOYEE TRAINING MANUAL What is HIPAA? Comprehensive federal legislation regarding health insurance which is comprised of four key areas:

More information

HIPAA-Compliant Research Access to PHI

HIPAA-Compliant Research Access to PHI HIPAA-Compliant Research Access to PHI HIPAA permits the access, disclosure and use of PHI from a HIPAA Covered Entity s or HIPAA Covered Unit s treatment, payment or health care operations records for

More information

Affordable Care Act (ACA) Frequently Asked Questions

Affordable Care Act (ACA) Frequently Asked Questions Grandfathered policies Q1: What is grandfathered health plan coverage? A: The interim final rule on grandfathering under ACA generally defines grandfathered health plan coverage as coverage provided by

More information

HIPAA 100 Training Manual Table of Contents. V. A Word About Business Associate Agreements 10

HIPAA 100 Training Manual Table of Contents. V. A Word About Business Associate Agreements 10 HIPAA 100 Training Manual Table of Contents I. Introduction 1 II. Definitions 2 III. Privacy Rule 5 IV. Security Rule 8 V. A Word About Business Associate Agreements 10 CHICAGO DEPARTMENT OF PUBIC HEALTH

More information

Health Reimbursement Arrangement Frequently Asked Questions

Health Reimbursement Arrangement Frequently Asked Questions Health Reimbursement Arrangement Frequently Asked Questions What is a Health Reimbursement Arrangement (HRA)? The HRA is an employer-funded health care reimbursement account. The employee incurs eligible

More information

Health Insurance Portability & Accountability Act (HIPAA) Compliance Application

Health Insurance Portability & Accountability Act (HIPAA) Compliance Application Health Insurance Portability & Accountability Act (HIPAA) Compliance Application IRB Office 101 - Altru Psychiatry Center 860 S. Columbia Rd, Grand Forks, North Dakota 58201 Phone: (701) 780-6161 PROJECT

More information

HIPAA Privacy Overview

HIPAA Privacy Overview May 21, 2003 HIPAA Privacy Overview Presented to the California State University Agenda Introduction HIPAA privacy regulations HIPAA privacy impact on CSU Next steps/action items Mercer Human Resource

More information

What is Covered by HIPAA at VCU?

What is Covered by HIPAA at VCU? What is Covered by HIPAA at VCU? The Privacy Rule was designed to protect private health information from incidental disclosures. The regulations specifically apply to health care providers, health plans,

More information

CROSS, GUNTER, WITHERSPOON & GALCHUS, P.C. ATTORNEYS AT LAW LITTLE ROCK/FORT SMITH/FAYETTEVILLE

CROSS, GUNTER, WITHERSPOON & GALCHUS, P.C. ATTORNEYS AT LAW LITTLE ROCK/FORT SMITH/FAYETTEVILLE CROSS, GUNTER, WITHERSPOON & GALCHUS, P.C. ATTORNEYS AT LAW LITTLE ROCK/FORT SMITH/FAYETTEVILLE Scotty Shively sshively@cgwg.com www.cgwg.com 500 President Clinton Avenue, Suite 200 Little Rock, AR 72201

More information

Donna S. Sheperis, PhD, LPC, NCC, CCMHC, ACS Sue Sadik, PhD, LPC, NCC, BC-HSP Carl Sheperis, PhD, LPC, NCC, MAC, ACS

Donna S. Sheperis, PhD, LPC, NCC, CCMHC, ACS Sue Sadik, PhD, LPC, NCC, BC-HSP Carl Sheperis, PhD, LPC, NCC, MAC, ACS Donna S. Sheperis, PhD, LPC, NCC, CCMHC, ACS Sue Sadik, PhD, LPC, NCC, BC-HSP Carl Sheperis, PhD, LPC, NCC, MAC, ACS 1 DISCLAIMER Please review your own documentation with your attorney. This information

More information

List of Insurance Terms and Definitions for Uniform Translation

List of Insurance Terms and Definitions for Uniform Translation Term actuarial value Affordable Care Act allowed charge Definition The percentage of total average costs for covered benefits that a plan will cover. For example, if a plan has an actuarial value of 70%,

More information

Statement of Policy. Reason for Policy

Statement of Policy. Reason for Policy Table of Contents Statement of Policy 2 Reason for Policy 2 HIPAA Liaison 2 Individuals and Entities Affected by Policy 2 Who Should Know Policy 3 Exclusions 3 Website Address for Policy 3 Definitions

More information

Entities Covered by the HIPAA Privacy Rule

Entities Covered by the HIPAA Privacy Rule Entities Covered by the HIPAA Privacy Rule Who Is A Covered Entity? HIPAA standards apply only to: Health care providers who transmit any health information electronically in connection with certain transactions

More information

Healthcare Reform Provisions Unique to Small Employers/Financial and Other Benefits Concerns for All Employers (updated May 2, 2014)

Healthcare Reform Provisions Unique to Small Employers/Financial and Other Benefits Concerns for All Employers (updated May 2, 2014) /Financial and Other Benefits Concerns for All Employers (updated May 2, 2014) Lisa L. Carlson, J.D., Area Senior Vice President, Compliance Counsel Gallagher Benefit Services, Inc. While most healthcare

More information

VALPARAISO UNIVERSITY NOTICE OF PRIVACY PRACTICES. Health, Dental and Vision Benefits Health Care Reimbursement Account

VALPARAISO UNIVERSITY NOTICE OF PRIVACY PRACTICES. Health, Dental and Vision Benefits Health Care Reimbursement Account VALPARAISO UNIVERSITY NOTICE OF PRIVACY PRACTICES THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

More information

Professional Employer Organizations Obligations Under HIPAA A Summary

Professional Employer Organizations Obligations Under HIPAA A Summary NAPEO Legal InsightsTM Volume 2, Number 6 November 2009 Professional Employer Organizations Obligations Under HIPAA A Summary Dale R. Vlasek, Esq. Attorney McDonald Hopkins LLC Cleveland, Ohio A PEO is

More information

HIPAA Compliance Review

HIPAA Compliance Review HIPAA Compliance Review For HR and IT Presented by: Linda Railton, PHR HR Consultant Leavitt Group linda.railton@leavitt.com Discussion Points HIPAA Final Rule (effective March 26, 2013) Overview of HIPAA

More information

BUSINESS ASSOCIATE AGREEMENT HIPAA Protected Health Information

BUSINESS ASSOCIATE AGREEMENT HIPAA Protected Health Information BUSINESS ASSOCIATE AGREEMENT HIPAA Protected Health Information I. PREAMBLE ( Covered Entity ) and ( Business Associate ) (jointly the Parties ) wish to enter into an Agreement to comply with the requirements

More information

HIPAA Privacy For our Group Customers and Business Partners

HIPAA Privacy For our Group Customers and Business Partners HIPAA Privacy For our Group Customers and Business Partners AmeriHealth HMO, Inc. AmeriHealth Insurance Company of New Jersey QCC Insurance Company, d/b/a AmeriHealth Insurance Company HIPAA, The Health

More information

HIPAA PLAN & PROCEDURES

HIPAA PLAN & PROCEDURES HIPAA PLAN & PROCEDURES TOWN OF STONINGTON/ STONINGTON BOARD OF EDUCATION HEALTH PLAN Definitions. Whenever used the following terms shall have the respective meanings set forth below. 1. Health Plan means

More information

What is Covered under the Privacy Rule? Protected Health Information (PHI)

What is Covered under the Privacy Rule? Protected Health Information (PHI) HIPAA & RESEARCH What is Covered under the Privacy Rule? Protected Health Information (PHI) Health information + Identifier = PHI Transmitted or maintained in any form (paper, electronic, forms, web-based,

More information

Compliance Program and HIPAA Training For First Tier, Downstream and Related Entities

Compliance Program and HIPAA Training For First Tier, Downstream and Related Entities Compliance Program and HIPAA Training For First Tier, Downstream and Related Entities 09/2011 Training Goals In this training you will gain an understanding of: Our Compliance Program elements Pertinent

More information

FAQs RELEASED ON APPLICATION OF HIPAA TO WELLNESS PROGRAMS

FAQs RELEASED ON APPLICATION OF HIPAA TO WELLNESS PROGRAMS Employee Benefits Legislative Compliance Wellness programs are HIP-AA! Find out how the HIPAA rules apply to your wellness program It pays to be sick in Massachusetts! Proposed regulations released for

More information

HIPAA PRIVACY FOR EMPLOYERS A Comprehensive Introduction. HIPAA Privacy Regulations-General

HIPAA PRIVACY FOR EMPLOYERS A Comprehensive Introduction. HIPAA Privacy Regulations-General HIPAA PRIVACY FOR EMPLOYERS A Comprehensive Introduction HIPAA Privacy Regulations-General The final HIPAA Privacy regulation was released on December 20, 2000 and was effective for compliance on April

More information

SCHOOL DISTRICT OF BLACK RIVER FALLS HIPAA PRIVACY AND SECURITY POLICY

SCHOOL DISTRICT OF BLACK RIVER FALLS HIPAA PRIVACY AND SECURITY POLICY SCHOOL DISTRICT OF BLACK RIVER FALLS HIPAA PRIVACY AND SECURITY POLICY School Board Policy 523.5 The School District of Black River Falls ( District ) is committed to compliance with the health information

More information

HIPAA Privacy Summary for Fully-insured Employer Groups

HIPAA Privacy Summary for Fully-insured Employer Groups HIPAA Privacy Summary for Fully-insured Employer Groups I. Overview The Privacy Regulations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) regulate the uses and disclosures

More information

TriageLogic Information Security Policy

TriageLogic Information Security Policy TriageLogic Information Security Policy What is HIPAA, and what information is protected by it? HIPAA, short for the United States Health Insurance Portability and Accountability Act, is a set of standards

More information

HIPAA Compliance for Students

HIPAA Compliance for Students HIPAA Compliance for Students The Health Insurance Portability and Accountability Act (HIPAA) was passed in 1996 by the United States Congress. It s intent was to help people obtain health insurance benefits

More information

California State University. HIPAA Privacy Summary Manual

California State University. HIPAA Privacy Summary Manual California State University HIPAA Privacy Summary Manual As prepared by Mercer Human Resource Consulting 2003 California State University The HIPAA Privacy Summary Manual was drafted for the exclusive

More information

The privacy rules under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) have been

The privacy rules under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) have been As Appeared in Benefits Law Journal Vol. 17, No. 1, Spring 2004 HIPAA Privacy Compliance: It s Time to Take It Seriously By Russell E. Greenblatt and Jeffrey J. Bakker, Katten Muchin Zavis Rosenman 2004

More information

HIPAA OVERVIEW ETSU 1

HIPAA OVERVIEW ETSU 1 HIPAA OVERVIEW ETSU 1 What is HIPAA? Health Insurance Portability and Accountability Act. 2 PURPOSE - TITLE II ADMINISTRATIVE SIMPLIFICATION To increase the efficiency and effectiveness of the entire health

More information

HIPAA and You The Basics

HIPAA and You The Basics HIPAA and You The Basics The Purpose of HIPAA Privacy Rules 1. Provide strong federal protections for privacy rights Ensure individual trust in the privacy and security of his or her health information

More information

Frequently Asked Questions About the Privacy Rule Under HIPAA

Frequently Asked Questions About the Privacy Rule Under HIPAA Q-1: What is HIPAA? Frequently Asked Questions About the Privacy Rule Under HIPAA A: HIPAA is the Health Insurance Portability and Accountability Act (passed by Congress in 1996). The Privacy Rule was

More information

Health Care Reform How it Will Affect Employers and their Group Health Plans. Benecon Comments and Observations

Health Care Reform How it Will Affect Employers and their Group Health Plans. Benecon Comments and Observations Health Care Reform How it Will Affect Employers and their Group Health Plans This Health Care Reform Summary applies to all employers (including government and church plans) that provide health coverage

More information

The Health and Benefit Trust Fund of the International Union of Operating Engineers Local Union No. 94-94A-94B, AFL-CIO. Notice of Privacy Practices

The Health and Benefit Trust Fund of the International Union of Operating Engineers Local Union No. 94-94A-94B, AFL-CIO. Notice of Privacy Practices The Health and Benefit Trust Fund of the International Union of Operating Section 1: Purpose of This Notice Notice of Privacy Practices Effective as of September 23, 2013 THIS NOTICE DESCRIBES HOW MEDICAL

More information

Graphic Communications National Health and Welfare Fund. Notice of Privacy Practices

Graphic Communications National Health and Welfare Fund. Notice of Privacy Practices Notice of Privacy Practices Section 1: Purpose of This Notice and Effective Date THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION.

More information

Reporting and Plan Documents under ERISA and Cafeteria Plan Rules

Reporting and Plan Documents under ERISA and Cafeteria Plan Rules Reporting and Plan Documents under ERISA and Cafeteria Plan Rules The Employee Retirement Income Security Act (ERISA) was signed in 1974. The U.S. Department of Labor (DOL) is the agency responsible for

More information

IDAHO STATE UNIVERSITY POLICIES AND PROCEDURES (ISUPP) HIPAA Privacy - De-identification of PHI 10030

IDAHO STATE UNIVERSITY POLICIES AND PROCEDURES (ISUPP) HIPAA Privacy - De-identification of PHI 10030 IDAHO STATE UNIVERSITY POLICIES AND PROCEDURES (ISUPP) HIPAA Privacy - De-identification of PHI 10030 POLICY INFORMATION Major Functional Area (MFA): MFA X - Office of General Counsel & Compliance Policy

More information

Winthrop-University Hospital

Winthrop-University Hospital Winthrop-University Hospital Use of Patient Information in the Conduct of Research Activities In accordance with 45 CFR 164.512(i), 164.512(a-c) and in connection with the implementation of the HIPAA Compliance

More information

The MC Academy The Employee Benefits and Executive Compensation Series. HIPAA PRIVACY AND SECURITY The New Final Regulations

The MC Academy The Employee Benefits and Executive Compensation Series. HIPAA PRIVACY AND SECURITY The New Final Regulations The MC Academy The Employee Benefits and Executive Compensation Series HIPAA PRIVACY AND SECURITY The New Final Regulations June 18, 2013 Overview Background Recent Changes to HIPAA Identifying Business

More information

Employment & Employee Benefits Developments

Employment & Employee Benefits Developments Employment & Employee Benefits Developments January 2015 New Health Care Compliance Considerations for Employers in 2015 Over the past year, the U.S. Departments of Labor (the DOL ), Treasury and Health

More information

HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA): FACT SHEET FOR NEUROPSYCHOLOGISTS Division 40, American Psychological Association

HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA): FACT SHEET FOR NEUROPSYCHOLOGISTS Division 40, American Psychological Association HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA): FACT SHEET FOR NEUROPSYCHOLOGISTS Division 40, American Psychological Association DISCLAIMER This general information fact sheet is made available

More information

SUMMARY OF GUIDE CONTENTS... 1 HIGHLIGHTS OF TAX-ADVANTAGED PLANS... 2 EMPLOYEE SALARY REDUCTION PLANS... 5

SUMMARY OF GUIDE CONTENTS... 1 HIGHLIGHTS OF TAX-ADVANTAGED PLANS... 2 EMPLOYEE SALARY REDUCTION PLANS... 5 This Guide is for informational and educational purposes only. It does not constitute legal advice or a comprehensive guide to issues to be considered by employers in establishing tax-advantaged benefits

More information

University of Cincinnati Limited HIPAA Glossary

University of Cincinnati Limited HIPAA Glossary University of Cincinnati Limited HIPAA Glossary ephi System A system that creates accesses, transmits or receives: 1) primary source ephi, 2) ephi critical for treatment, payment or health care operations

More information

Agent Instruction Sheet for PriorityHRA Plan Document

Agent Instruction Sheet for PriorityHRA Plan Document Agent Instruction Sheet for PriorityHRA Plan Document Thank you for choosing PriorityHRA! Here are some instructions as to what to do with each PriorityHRA document. Required Documents: HRA Application

More information

INDIANA UNIVERSITY SCHOOL OF OPTOMETRY HIPAA COMPLIANCE PLAN TABLE OF CONTENTS. I. Introduction 2. II. Definitions 3

INDIANA UNIVERSITY SCHOOL OF OPTOMETRY HIPAA COMPLIANCE PLAN TABLE OF CONTENTS. I. Introduction 2. II. Definitions 3 INDIANA UNIVERSITY SCHOOL OF OPTOMETRY HIPAA COMPLIANCE PLAN TABLE OF CONTENTS I. Introduction 2 II. Definitions 3 III. Program Oversight and Responsibilities 4 A. Structure B. Compliance Committee C.

More information

Self-insured Plans under Health Care Reform

Self-insured Plans under Health Care Reform Brought to you by Good Neighbor Insurance Self-insured Plans under Health Care Reform The Affordable Care Act (ACA) includes numerous reforms affecting the health coverage that employers provide to their

More information

HIPAA POLICIES & PROCEDURES AND ADMINISTRATIVE FORMS TABLE OF CONTENTS

HIPAA POLICIES & PROCEDURES AND ADMINISTRATIVE FORMS TABLE OF CONTENTS HIPAA POLICIES & PROCEDURES AND ADMINISTRATIVE FORMS TABLE OF CONTENTS 1. HIPAA Privacy Policies & Procedures Overview (Policy & Procedure) 2. HIPAA Privacy Officer (Policy & Procedure) 3. Notice of Privacy

More information

National Health Insurance Reform

National Health Insurance Reform JANUARY2011 National Health Insurance Reform Impact Year by Year With the passage of National Health Insurance Reform it is crucial that employers and plan sponsors have clear information about the impact

More information

CREATIVE SOLUTIONS IN HEALTHCARE, INC. Privacy Policy

CREATIVE SOLUTIONS IN HEALTHCARE, INC. Privacy Policy CREATIVE SOLUTIONS IN HEALTHCARE, INC. Privacy Policy Amended as of February 12, 2010 on the authority of the HIPAA Privacy Officer for Creative Solutions in Healthcare, Inc. TABLE OF CONTENTS ARTICLE

More information

Reporting Requirements for Employers and Health Plans

Reporting Requirements for Employers and Health Plans Brought to you by Cross Employee Benefits Reporting Requirements for Employers and Health Plans The Affordable Care Act (ACA) created a number of federal reporting requirements for employers and health

More information

HIPAA Privacy Compliance Manual

HIPAA Privacy Compliance Manual HIPAA Privacy Compliance Manual AgriPlan BizPlan COBRAToday DirectPay FlexSystem MAPP PHiEd 1 Purpose of this Manual This publication provides authoritative and accurate information regarding requirements

More information

Member s Name First M.I. Last Dependent s Name (if enrolling in Medicare) First M.I. Last

Member s Name First M.I. Last Dependent s Name (if enrolling in Medicare) First M.I. Last Oklahoma State and Education Employees Group Insurance Board A Division of the Office of State Finance APPLICATION FOR MEDICARE SUPPLEMENT WITH PART D Member ID # *MCENRL* Phone ( ) Member s Name First

More information

Self-insured Plans under Health Care Reform

Self-insured Plans under Health Care Reform Brought to you by Cottingham & Butler Self-insured Plans under Health Care Reform The Affordable Care Act (ACA) includes numerous reforms affecting the health coverage that employers provide to their employees.

More information

University of California Policy

University of California Policy University of California Policy HIPAA Uses and Disclosures for UC Group Health Plans Responsible Officer: Senior Vice President/Chief Compliance and Audit Officer Responsible Office: Ethics, Compliance

More information

Everett School Employee Benefit Trust. Reportable Breach Notification Policy HIPAA HITECH Rules and Washington State Law

Everett School Employee Benefit Trust. Reportable Breach Notification Policy HIPAA HITECH Rules and Washington State Law Everett School Employee Benefit Trust Reportable Breach Notification Policy HIPAA HITECH Rules and Washington State Law Introduction The Everett School Employee Benefit Trust ( Trust ) adopts this policy

More information

PEPPERDINE UNIVERSITY HIPAA Policies Procedures and Forms Manual

PEPPERDINE UNIVERSITY HIPAA Policies Procedures and Forms Manual PEPPERDINE UNIVERSITY HIPAA Policies Procedures and Forms Manual 1 Table of Contents I. INTRODUCTION... 4 A. GENERAL POLICY... 4 B. SCOPE... 4 II. DEFINITIONS... 5 III. GENERAL POLICIES AND PROCEDURES...

More information

NOTICE OF PRIVACY PRACTICES for the HARVARD UNIVERSITY MEDICAL, DENTAL, VISION AND MEDICAL REIMBURSEMENT PLANS

NOTICE OF PRIVACY PRACTICES for the HARVARD UNIVERSITY MEDICAL, DENTAL, VISION AND MEDICAL REIMBURSEMENT PLANS NOTICE OF PRIVACY PRACTICES for the HARVARD UNIVERSITY MEDICAL, DENTAL, VISION AND MEDICAL REIMBURSEMENT PLANS THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW

More information

HIPAA (Health Insurance Portability and Accountability Act of 1996) Stetson University HIPAA Training

HIPAA (Health Insurance Portability and Accountability Act of 1996) Stetson University HIPAA Training HIPAA (Health Insurance Portability and Accountability Act of 1996) Stetson University HIPAA Training Objectives of this Training l To help you understand: l What HIPAA privacy rule is l Why it is important

More information

American Bar Association. Technical Session Between the Department of Health and Human Services and the Joint Committee on Employee Benefits

American Bar Association. Technical Session Between the Department of Health and Human Services and the Joint Committee on Employee Benefits American Bar Association Technical Session Between the Department of Health and Human Services and the Joint Committee on Employee Benefits May 6, 2008 The following notes are based upon the personal comments

More information

HIPAA Privacy & Breach Notification Training for System Administration Business Associates

HIPAA Privacy & Breach Notification Training for System Administration Business Associates HIPAA Privacy & Breach Notification Training for System Administration Business Associates Barbara M. Holthaus privacyofficer@utsystem.edu Office of General Counsel University of Texas System April 10,

More information

How To Get A Health Care License

How To Get A Health Care License HIPAA Privacy Compliance Manual 10/21/09 HOW TO USE THIS MANUAL This HIPAA Compliance Manual is an interactive workbook to help you comply with the HIPAA Privacy Rule. (45 CFR 164.500 et. seq.) We intend

More information

PROTECTED HEALTH INFORMATION AND THE JHSPH

PROTECTED HEALTH INFORMATION AND THE JHSPH PROTECTED HEALTH INFORMATION AND THE JHSPH The Health Insurance Portability and Accountability Act (HIPAA) protects individually identifiable health information, or Protected Health Information ( PHI ),

More information

How to De-identify Data. Xulei Shirley Liu Department of Biostatistics Vanderbilt University 03/07/2008

How to De-identify Data. Xulei Shirley Liu Department of Biostatistics Vanderbilt University 03/07/2008 How to De-identify Data Xulei Shirley Liu Department of Biostatistics Vanderbilt University 03/07/2008 1 Outline The problem Brief history The solutions Examples with SAS and R code 2 Background The adoption

More information

A. HIPAA Privacy Authorizations and Exceptions for Use of Identifiable Protected Health Information

A. HIPAA Privacy Authorizations and Exceptions for Use of Identifiable Protected Health Information Protected Health Information and the JHSPH The Health Insurance Portability and Accountability Act (HIPAA) protects individually identifiable health information, or Protected Health Information ( PHI ),

More information

HIPAA PRIVACY AND SECURITY FOR EMPLOYERS

HIPAA PRIVACY AND SECURITY FOR EMPLOYERS HIPAA PRIVACY AND SECURITY FOR EMPLOYERS Agenda Background and Enforcement HIPAA Privacy and Security Rules Breach Notification Rules HPID Number Why Does it Matter HIPAA History HIPAA Title II Administrative

More information

HIPAA. HIPAA s provisions affect group health plan coverage in the following ways:

HIPAA. HIPAA s provisions affect group health plan coverage in the following ways: HIPAA The Health Insurance Portability and Accountability Act of 1996 (HIPAA) includes provisions of Federal law governing health coverage portability, health information privacy, administrative simplification,

More information

NOTICE OF HIPAA PRIVACY AND SECURITY PRACTICES

NOTICE OF HIPAA PRIVACY AND SECURITY PRACTICES SCHOOL DISTRICT OF BLACK RIVER FALLS 523.5 Exhibit NOTICE OF HIPAA PRIVACY AND SECURITY PRACTICES PRIVACY NOTICE This notice describes how medical information about you may be used and disclosed and how

More information

HEALTH CARE REFORM: Grandfathered Health Plans

HEALTH CARE REFORM: Grandfathered Health Plans HEALTH CARE REFORM: Grandfathered Health Plans Guidance concerning grandfathered health plan status was issued on June 17, 2010, by the Departments of Labor, Treasury and Health and Human Services with

More information

Protecting Personal Health Information in Research: Understanding the HIPAA Privacy Rule

Protecting Personal Health Information in Research: Understanding the HIPAA Privacy Rule AA Privacy RuleP DEPARTMENT OF HE ALTH & HUMAN SERVICES USA Protecting Personal Health Information in Research: Understanding the HIPAA Privacy Rule NIH Publication Number 03-5388 The HI Protecting Personal

More information

Employer Reporting of Health Coverage Code Sections 6055 & 6056

Employer Reporting of Health Coverage Code Sections 6055 & 6056 Brought to you by Hickok & Boardman HR Intelligence Employer Reporting of Health Coverage Code Sections 6055 & 6056 The Affordable Care Act (ACA) created new reporting requirements under Internal Revenue

More information

Plan Sponsor s Guide to the HIPAA Security Rule

Plan Sponsor s Guide to the HIPAA Security Rule Plan Sponsor s Guide to the HIPAA Security Rule Compliments of Aetna 00.02.117.1 (8/04) The HIPAA Security Rule We live in a world with ever increasing Internet and e-mail access, networking capabilities,

More information

HIPAA Medical Billing Requirements For Research

HIPAA Medical Billing Requirements For Research The Health Insurance Portability and Accountability Act (HIPAA) Excerpted from the UTC IRB Policy June 2008 Table of Contents PART V: The Health Insurance Portability and Accountability Act (HIPAA)...

More information

Specifically, section 6035 of the DRA amended section 1902(a) (25) of the Act:

Specifically, section 6035 of the DRA amended section 1902(a) (25) of the Act: DEPARTMENT OF HEALTH & HUMAN SERVICES Centers for Medicare & Medicaid Services 7500 Security Boulevard, Mail Stop S2-26-12 Baltimore, Maryland 21244-1850 Medicaid and CHIP FAQs: Identification of Medicaid

More information

HIPAA - - Basic Concepts and Implementation Roadmap

HIPAA - - Basic Concepts and Implementation Roadmap HIPAA - - Basic Concepts and Implementation Roadmap Prepared by: David Weiner dweiner@seyfarth.com Fredric Singerman fsingerman@dc.seyfarth.com Today s Agenda n Introduction of HIPAA Privacy and Electronic

More information

HIPAA Privacy Summary for Self-insured Employer Groups

HIPAA Privacy Summary for Self-insured Employer Groups I. Overview HIPAA Privacy Summary for Self-insured Employer Groups The Privacy Regulations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) regulate the uses and disclosures of

More information

Compliance Alert. New requirement for health plans: HIPAA Health Plan Identifier (HPID) August 29, 2014

Compliance Alert. New requirement for health plans: HIPAA Health Plan Identifier (HPID) August 29, 2014 Compliance Alert New requirement for health plans: HIPAA Health Plan Identifier (HPID) August 29, 2014 Quick Facts: Health plans need to obtain a unique health plan identifier number (HPID). For insured

More information

Gaston County HIPAA Manual

Gaston County HIPAA Manual Gaston County HIPAA Manual Includes Gaston County IT Manual Action Date Reviewed and Revised December 2012 Gaston County HIPAA Policy Manual has be updated and combined with the Gaston County IT Manual.

More information

Chapter 91. Regulation 68 Patient Rights under Health Insurance Coverage in Louisiana

Chapter 91. Regulation 68 Patient Rights under Health Insurance Coverage in Louisiana D. A copy of the certification form shall be maintained by the insurer and by the producing agent or broker in the policyholder's record for a period of five years from the date of issuance of the insurance

More information