HIPAA. For General Workforce. What you need to know. HIPAA Training Presentation for Management Workforce
|
|
|
- Rosanna Chapman
- 10 years ago
- Views:
Transcription
1 HIPAA For General Workforce What you need to know HIPAA Training Presentation for Management Workforce 1
2 The Catholic Health Initiatives Mission Catholic Health Initiatives continues the journey begun by our foundresses. Like these women religious, we continue the healing ministry of Jesus Christ through the provision of health care in our many communities. Our core values of reverence, integrity, compassion and excellence guide us on this journey. We build relationships based upon these core values. These relationships enable us to assume the challenging role of caring for those most in need, those least able to care for themselves. Our core values and standards of conduct are the principles that guide us in navigating the complexity of providing health care. At a minimum, we are expected to follow all laws related to our responsibilities. However, following the law is not enough. Our values call us to live by an ethical standard that is greater than the law. We are responsible for ensuring the privacy of an individual s health information and are entrusted with that information in order to provide the necessary care and services. We have a duty to prevent the inappropriate use or disclosure of an individual s health information.
3 Course Objectives/Navigation The objectives of this course are: To foster and maintain a culture of integrity. To develop individual and team character and virtue in the workplace. To foster compliance with applicable federal and state laws and regulations. To understand the policies and procedures in order to protect health information. Navigating this course: Each course contains Cases to Consider, which are designed to help improve your understanding of the course material. At the end of each course you will take a Section Test. The Section Test is designed to measure your understanding of the course material and is scored. You will be required to successfully pass the Section Test. You can use the arrows at the top and bottom of your screen to move forward and backward through the course. For most people, this course should take approximately 1 hour.
4 Education Objectives Understand the Health Insurance Portability and Accountability Act (HIPAA) rules and regulations Understand the penalties for not complying Understand patients rights and health care workers role in protecting them Understand your responsibilities under HIPAA-related policies and procedures
5 The Health Insurance Portability and Accountability Act of 1996 (HIPAA) HIPAA is a federal law imposed on all health care organizations, including: Hospitals, physician offices, home health agencies, nursing homes, and other health care providers Clearinghouses HMOs, private health plans, and public payers such as Medicare and Medicaid The above organizations are considered Covered Entities under HIPAA.
6 HIPAA HIPAA consists of five main sections, or titles. The most important title for health providers is Title II, Administrative Simplification. The three main components of Title II include the following standards: Privacy Security Electronic Data Interchange The Privacy and Security standards will be reviewed in this module.
7 HIPAA Privacy Rule HIPAA Training Presentation for Management Workforce 7
8 HIPAA Privacy Rule Compliance date of April 14, 2003 Gives patients federal rights to gain access to their medical records and restrict who sees their health information Requires organizations to take measures to safeguard patient health information Requires organizations to train members of the workforce on patients rights to privacy and control over their health information Punishes individuals and organizations that fail to keep patient health information confidential
9 The Privacy Official A Privacy Official has been appointed by each covered entity to: Manage the development of the organization s privacy standards, policies, and procedures Oversee training and education of workforce Enforce the rules and investigate violations
10 Myths about HIPAA Patients cannot be paged Organizations must get rid of all their semi-private rooms and put up sound barriers Organizations cannot put patient names outside their doors or use white boards HIPAA does not require the above measures and these myths are not true.
11 Quiz Question What type of rule is HIPAA? a. a state law imposed only on hospitals b. a federal law imposed on all health care organizations c. a guideline set forth by the American Medical Association d. an accreditation requirement b. HIPAA is the first federal regulation that gives patients rights to gain access to their medical records and restrict who sees their health information.
12 Safeguarding Health Information
13 What is Confidential? Any information about a patient written on paper, saved on a computer, or spoken, is protected health information (PHI), including: Name Address Age Social Security number Phone number address Diagnosis Medical history Medications Observations of health Medical record number And more...
14 Protect Patient Privacy Do s Log off the computer when you re finished Dispose of health information only by shredding or storing in locked containers for destruction Notify Security if you see an unescorted visitor in a private area
15 Protect Patient Privacy Don ts Don t leave patient records lying around Don t discuss a patient in public areas such as elevators, hallways, and cafeterias Don t look at information about a patient unless you need it to do your job
16 Rules for Computers Do s Keep your password a secret Turn computer screens away from public view Change your password every 180 days or as required by internal policy Do not log into the system using someone else s password Do not remove equipment, disks, or software without permission
17 Quiz Question When are you free to repeat a patient s private health information that you hear on the job? a. after you no longer work at the organization b. after a patient dies c. if you know the patient would not mind d. when your job requires it
18 Quiz Question Which of the following is protected health information under HIPAA? a. the patient s address b. the patient s allergies c. the patient s medical record number d. all of the above
19 Quiz Question Which of the following types of information does HIPAA s privacy rule protect? a. patient information in electronic form b. patient information communicated orally c. patient information in paper form d. all of the above
20 Do You Need to Know? The Minimum Necessary Standard
21 Do You Need To Know? HIPAA requires health care workers to use the minimum amount of health information they need to do their jobs efficiently and effectively. Ask yourself: Do I need this information to do my job and provide good service? What is the least amount of information I need to do my job?
22 Do You Need to Know? Coders and billers need to look at certain portions of records to code and bill correctly Professional health care workforce members such as doctors, nurses, and therapists need to look at their patients records to care for them Housekeeping staff do not need to look at patient records to perform their job
23 Quiz Question What question should you ask yourself before looking at health information? a. Would the patient mind if I looked at this? b. Do I need to know this to do my job? c. Can anyone see what I m doing? d. Am I curious?
24 Quiz Question Your sister s friend just had triple bypass surgery at your organization. She asks you to find out his prognosis. What should you do? a. ask a nurse on the floor how the patient is doing and pass the information along to your sister b. log in to the computerized record system and read the patient s record to find information for your sister c. explain that it is a violation of the patient s privacy for you to ask around or look at his record, and suggest that she call one of her friend s family members d. none of the above
25 Authorization
26 Authorization Organizations must obtain authorization from a patient before using or sharing protected health information (PHI) for reasons other than treatment, payment, or health care operations. Reasons other than treatment, payment or health care operations include: Marketing Fundraising Research Employment determinations A patient may revoke an authorization at any time by making a written request.
27 Examples of Treatment, Payment and Health Care Operations Treatment: doctors and nurses caring for patients; technicians performing tests Payment: billers sending out claims; coders applying codes to procedures Health care operations: quality assurance staff performing reviews; transcriptionists typing reports
28 Authorization Exceptions An authorization is not necessary for uses or disclosures mandated by law such as: Reporting births, deaths, and communicable diseases to state agencies Giving certain information to the police for investigations, searches for missing people Responding to a court order, subpoena, or other lawful process Workers compensation Specialized government functions External health oversight agencies Public health activities
29 Quiz Question When is the patient s authorization to release information required? a. in most cases in which information is going to be shared with anyone for reasons other than treatment, payment, or health care operations b. upon admission c. when information is to be shared among two or more clinicians d. when information is used for billing a private insurer
30 Marketing and Fundraising
31 Marketing In most cases, we may not use or disclose protected health information (PHI) to market a product or service without obtaining a valid authorization.
32 Defining Marketing The following are not considered marketing under HIPAA and do not require an authorization: Descriptions of the organization and whether products or services are provided or covered Explanations of treatment alternatives Case management or care coordination Recommendations of alternative treatments, therapies, providers, or settings Reminders and disease management and wellness programs
33 Fundraising We can use only the following information for fundraising purposes without patient authorization: Demographic information Dates of service
34 Opting Out A patient has the right to revoke his/her authorization and opt out of receiving future fundraising or marketing communications
35 The Facility Directory
36 The Facility Directory Unless a patient has asked not to be included in the directory, you may disclose the following information to visitors and callers who ask for a patient listed in the directory by name: Location (room number) General condition (e.g. stable, critical)
37 Directory Disclosures to Clergy Clergy who have signed the Clergy Confidentiality Agreement do not have to ask for a patient by name and may receive: Names of patients listed in the directory with the same religious affiliation of the clergy making the request Locations General conditions
38 Quiz Question What information about a patient who is listed in the directory can be disclosed to someone who asks for the patient by name? A. room number and name of doctor B. room number and general condition C. general condition and prognosis C. D. nothing
39 Individual Rights
40 Individual Rights Patients have the following rights under HIPAA: To know who has access to their health information and how it is used (Notice of Privacy of Practices) To access and request an amendment to their health records in the designated record set (Access and Amendment) To request a list of people and organizations who have received his/her health information (Accounting of Disclosures) To request that we communicate with them by alternative means (Confidential Communications) To request restrictions for the use and disclosure of their health information (Request Restrictions) To complain to a covered entity, to the Secretary of HHS, or to the Office for Civil Rights (OCR)
41 Notice of Privacy Practices Provides individual notice of the ways the organization uses and shares an individual s health information Explains an individual s rights to confidentiality and access to his/her health information Is posted prominently in the organization
42 Right to Access A patient has the right to inspect and obtain a copy of his/her designated record set, which includes protected health information (PHI) used in whole or in part to make decisions about the patient.
43 Designated Record Set A designated record set is a group of records that may include: Health care provider medical and billing records Health plan enrollment, payment, claims adjudication and case or medical management records
44 Right to Request Amendments A patient has the right to request amendments to his/her designated record set. However, organizations are not required to automatically make whatever changes the patient requests.
45 Personal Representatives Persons who have the authority (under federal and state laws) to act on behalf of a patient in making health care decisions may have access to the patient s health information as his/her personal representative.
46 Personal Representatives for Minors Parents, guardians, and others who have authority (under federal and state laws) to act on behalf of a minor in making health care decisions may have access to the minor s health information as his/her personal representative
47 Accounting of Disclosures A patient has the right to request a list of people and organizations who have received his/her health information. The list does not have to include disclosures: For treatment, payment, and health care operations Authorized by the patient To the facility directory For national security Of limited data set information
48 Confidential Communications A patient may ask to receive correspondence at an alternate location or by an alternate means. Organizations must honor all reasonable requests such as: Sending mail to a P.O. Box or alternative location Calling the patient at work instead of home Using sealed envelopes instead of postcards
49 Complaints and Grievances The Notice of Privacy Practices includes information on filing complaints: The name of the designated representative or department for handling grievances The representative s phone number The steps for filing a formal complaint
50 The Formal Grievance Process If a patient or personal representative complains about a breach of confidentiality or a violation of a HIPAA rule, notify your supervisor and contact the representative listed on the Notice of Privacy Practices.
51 Quiz Question What should members of the workforce do if a patient complains that her privacy was violated during her stay? a. Notify their supervisor and the person or department responsible for handling complaints listed on the Notice of Privacy Practices b. Ask the patient to provide proof c. Nothing it s not their job to handle complaints d. None of the above
52 Quiz Question Which of the following does the complaints section of the Notice of Privacy Practices include? a. the name of the designated representative or department for handling grievances b. the representative s phone number c. the steps for filing a formal complaint d. all of the above
53 Confidentiality Agreement and Penalties
54 Confidentiality Agreement By signing you agree to: Dispose of health information properly Follow the organization s policies and procedures Use computers and information systems only for performing job duties Use confidential information only in performing job duties Share confidential information only with those who need the information to do their jobs Handle health records carefully to preserve individual privacy
55 Penalties for Breaking the Privacy Rules Criminal penalties under HIPAA: Maximum of 10 years in jail and a $250,000 fine for serious offenses Civil penalties under HIPAA: Maximum fine of $25,000 per violation Organization actions: Employee disciplinary actions including suspension and/or termination for serious violations of the organization s policies and procedures
56 HIPAA Security Rule
57 HIPAA Security Rule Compliance date of April 20, 2005 Applies to the same covered entities described in the Privacy Rule section. Applies to protected health information (PHI) that is electronically sent from one location to another or stored by the facility. Identifies steps to take to secure electronic PHI.
58 Information Security A Security Official has been appointed with responsibility to: Make sure the covered entity complies with the security standards, and Provide training to all system users at the facility.
59 Information Security The Security Rule has three key areas that work together to protect PHI. These include: Physical safeguards Technical safeguards Administrative safeguards
60 Physical Safeguards The purpose of physical safeguards is to help protect the physical computer systems and related buildings and equipment from unauthorized access, fire, and other natural and environmental hazards. Some physical safeguards were discussed in the privacy section of this course. These included access to computer systems, workstations, and the use of passwords.
61 Technical Safeguards Technical safeguards focus on the steps and procedures that must be in place to: Protect the integrity of electronic PHI Control access Record and examine system activity Validate the identity and authorization of users Protect electronic PHI transmitted over a communications network
62 Technical Safeguard Examples Unique user IDs Reliable user authentication typically passwords Authorization to access information Automatic computer logoff (inactivity timeout) Firewalls Log capture and monitoring
63 Passwords, the First Layer of Protection Password usage: Generic User IDs are not permitted except in special circumstances. User ID access must be changed immediately upon a User s transfer to a different role in the organization. All User ID passwords must change at least once every 180 days or as required by policy. Systems should be set to automatically force password changes. When changing passwords, a User must not create passwords that are identical to his or her previous eight passwords.
64 Passwords, the first layer of protection Password Syntax Rules Passwords must be at least six characters in length and have a minimum of four alphabetic characters. have a minimum of two numeric characters (0 through 9). Passwords may include no more than two consecutively repeated characters. NOTE: The use of control characters and other non-printing characters is not permitted because they may cause network or system problems.
65 Passwords, the First Layer of Protection Examples of passwords: Good / strong passwords: 15djOth (15 dogs jumped over the house) Cft6vgy& (keyboard pattern) Poor / weak passwords: Orange Skipper BobH
66 Passwords, the First Layer of Protection Password Selection Rules Choose passwords that are difficult to guess. Passwords must not be related to the user s job or personal life. For example, do not use names of family members or pets as a password. Personal information that is easily obtainable, including date of birth, license plate number, telephone number, Social Security number, make of automobile or home address must not be used as a password. The first, middle or last name of the user should not be used to construct a password. User IDs must not be used as a password in any form.
67 Administrative Safeguards Under the Security Rule, policies and procedures must be in place that define the steps to address: Adding, changing or deleting user access based on job responsibilities or if user terminates employment Use and assignment of individual user IDs and passwords How to access the computer system and/or electronic PHI in the event of an emergency
68 Quiz Question Which of the following is NOT a key area of the HIPAA Security Rule? a. Physical safeguards b. Technical safeguards c. Documentation safeguards d. Administrative safeguards
69 Quiz Question When is it acceptable to share your password? a. when your co-worker forgets his password b. when it saves time c. when you know you can trust the person to use it appropriately d. never
70 Quiz Question Which of the following choice of passwords is best to use? a. AlSm!th b. 15djOth c. Terry d
71 What Should You Do?
72 Case #1 You are called to work in a patient s room to perform a routine job. You knock on the door and are invited in. You see that a nurse is in the room discussing the patient s condition or medication. What should you do?
73 Case #1 Answer If you must do the job immediately ask whether you can interrupt. If the job can wait, explain that you are there to perform a routine job and will return in 15 or 20 minutes. This protects the patient s privacy by allowing him/her to openly discuss his/her condition without being overheard. Some patients may say that it is acceptable for you to stay in the room during the conversation. But remember that patients may not feel comfortable sharing everything about their symptoms or medical history while you are in the room. They also might not feel comfortable asking you to leave.
74 Case #2 A visitor tells you she is at the organization to work on the computers and wants you to point the way to the system. How do you respond?
75 Case #2 Answer The best response is to ask the repairwoman who at the organization contacted her. Find that person. He or she can take the repairwoman to the appropriate work area.
76 Case #3 You are walking by a trash can and notice a pile of photocopied health records has been laid on top of the trash can. How should you handle this?
77 Case #3 Answer Gather the records and take them to your supervisor. He or she will report it to the organization s Privacy Official to determine why the records were not destroyed.
78 Case #4 You are working on a nursing unit and see the name of a friend on a white board. Should you stop by her room?
79 Case #4 Answer If you learned of your friend s stay only by looking at the white board, you should not go to her room unless your job responsibilities take you there. If you find out from the patient or her family member that she is a patient at the facility, feel free to visit her. Be sure to follow the visitor policies.
80 Case #5 A co-worker is having trouble logging in to the organization s system. She asks for your login name and password so she can use them. Should you share them with her?
81 Case #5 Answer No. The HIPAA security standards require the use of individual passwords for each workforce member with access to health information stored in the computer system. The organization keeps track of the records you gain access to based on the login name and password you use to enter the system. If you let others use your name and password, you are breaking HIPAA s rules and the organization s policy, and you may be held responsible if the co-worker gains access to patient information inappropriately.
82 Case #6 You have a hard time remembering your password for the computerized record system. Should you jot it down on a piece of paper and stick it in your desk drawer?
83 Case #6 Answer No. Even if your desk drawer remains locked, it is not appropriate to keep it in your desk. If you have a hard time remembering your password, select a password that meets your organization s criteria, but is easy for you to remember.
84 Test Your Understanding
85 Question #1 A man comes into the organization and tells you he is supposed to work on the computers and wants you to open a door for him or point the way to a workstation. How should you respond to this request? a. provide him with the information or access he needs b. ask him who at the organization hired him and find that person for assistance c. call the police d. none of the above
86 Question #2 Your sister s friend just had triple bypass surgery at your organization. She asks you to find out his prognosis. What should you do? a. ask a nurse on the floor how the patient is doing and pass the information along to your sister b. log in to the computerized record system and read the patient s record to find information for your sister c. explain that it is a violation of the patient s privacy for you to ask around or look at his record, and suggest that she call one of her friend s family members d. none of the above
87 Question #3 When are you free to repeat a patient s private health information that you hear on the job? a. after you no longer work at the organization b. after a patient dies c. if you know the patient would not mind d. when your job requires it
88 Question #4 You see an open recycling bin full of paper. You can see names, addresses, and diagnoses on the paper. What should you do? a. nothing b. bring it to your supervisor or the Privacy Official so he or she can dispose of it properly and determine why it was put there c. read the report and try to figure out what workforce member disposed of it improperly d. none of the above
89 Question #5 What question should you ask yourself before looking at patient information? a. Would the patient mind if I looked at this? b. Do I need to know this to do my job? c. Can anyone see what I m doing? d. Am I curious?
90 Question #6 When is the patient s authorization to release information required? a. in most cases in which information is going to be shared with anyone for reasons other than treatment, payment, or health care operations b. upon admission c. when information is to be shared among two or more clinicians d. when information is used for billing a private insurer
91 Question #7 When is it acceptable to share your password? a. when your co-worker forgets his password b. when it saves time c. when you know you can trust the person to use it appropriately d. never
92 Question #8 Which of the following is protected health information under HIPAA? a. the patient s address b. the patient s allergies c. the patient s medical record number d. all of the above
93 Question #9 Which of the following types of information does HIPAA s privacy rule protect? a. patient information in electronic form b. patient information communicated orally c. patient information in paper form d. all of the above
94 Question #10 What should members of the workforce do if a patient complains that her privacy was violated during her stay? a. Notify their supervisor and the person or department responsible for handling complaints listed on the Notice of Privacy Practices b. Ask the patient to provide proof c. Nothing it s not their job to handle complaints d. None of the above
95 Question 11 Which of the following does the complaints section of the Notice of Privacy Practices include? a. the name of the designated representative or department for handling grievances b. the representative s phone number c. the steps for filing a formal complaint d. all of the above
96 Question #12 Which of the following choice of passwords is best to use? a. AlSm!th b. 15djOth c. Terry d
97 Course Summary This course linked your everyday job functions with their effect on the organization s privacy and security practices and compliance with the Health Insurance Portability and Accountability Act (HIPAA). The HIPAA requirements discussed throughout this course included: Understanding the purpose of HIPAA regulations. Safeguarding written, oral and electronic information. Knowing the steps to protect privacy. Understanding the role of the Privacy and Security Officials in your organization. The intent of this course was to educate staff members and make them more aware of how their everyday activities affect their organization s HIPAA compliance. Through this course, you were empowered to protect the privacy of those we serve and prevent violations of confidentiality. Our purpose for asking you to take this course was not only to help you become familiar with some of the current laws and regulations associated with HIPAA, but also to reinforce the mission of Catholic Health Initiatives (CHI). CHI is built upon a foundation of integrity. All of the women and men who have gone before us tried to ensure that, regardless of the challenges they faced, CHI would truly minister to and be worthy of trust by their communities. It is our ethical duty to continue this mission at CHI. Knowledge from this course is one tool that assists us in fulfilling that mission. Thank you for taking this course. Please click here to take the Final Test.
Health Insurance Portability and Accountability Act (HIPAA)
Health Insurance Portability and Accountability Act (HIPAA) General Education Presented by: Bureau of Personnel Department of Health Department of Human Services Department of Social Services Bureau of
HIPAA Privacy & Security Training for Clinicians
HIPAA Privacy & Security Training for Clinicians Agenda This training will cover the following information: Overview of Privacy Rule and Security Rules Using and disclosing Protected Health Information
Department of Health and Human Services Policy ADMN 004, Attachment A
WASHINGTON COUNTY Department of Health and Human Services Policy ADMN 004, Attachment A HHS Confidentiality Agreement Including HIPAA (Health Information Portability and Accessibility Act of 1996) OREGON
HIPAA PRIVACY POLICIES & PROCEDURES. Department of Behavioral Health and Developmental Services DBHHDS GENERAL AWARENESS TRAINING
HIPAA PRIVACY POLICIES & PROCEDURES Department of Behavioral Health and Developmental Services DBHHDS GENERAL AWARENESS TRAINING March 2012 HIPAA Humor (North Dakota Dept of Health) 2 HIPAA-Ectomy - the
The Basics of HIPAA Privacy and Security and HITECH
The Basics of HIPAA Privacy and Security and HITECH Protecting Patient Privacy Disclaimer The content of this webinar is to introduce the principles associated with HIPAA and HITECH regulations and is
HIPAA Privacy and Security. Rochelle Steimel, HIPAA Privacy Official Judy Smith, Staff Development January 2012
HIPAA Privacy and Security Rochelle Steimel, HIPAA Privacy Official Judy Smith, Staff Development January 2012 Goals and Objectives Course Goal: To introduce the staff of Munson Healthcare to the concepts
HIPAA Education Level One For Volunteers & Observers
UK HealthCare HIPAA Education Page 1 September 1, 2009 HIPAA Education Level One For Volunteers & Observers ~ What does HIPAA stand for? H Health I Insurance P Portability A And Accountability A - Act
HIPAA and Privacy Policy Training
HIPAA and Privacy Policy Training July 2015 1 This training addresses the requirements for maintaining the privacy of confidential information received from HFS and DHS (the Agencies). During this training
Annual Compliance Training. HITECH/HIPAA Refresher
Annual Compliance Training HITECH/HIPAA Refresher January 2015 Sisters of Charity of Leavenworth Health System, Inc. All rights reserved. 1 Annual Refresher Training Welcome to the SCL Health System Compliance
HIPAA PRIVACY SELF-STUDY MATERIALS
HIPAA PRIVACY SELF-STUDY MATERIALS This self-study packet serves as a review of important Health Insurance Portability and Accountability Act (HIPAA) requirements. Many of these requirements are included
HIPAA 101: Privacy and Security Basics
HIPAA 101: Privacy and Security Basics Purpose This document provides important information about Kaiser Permanente policies and state and federal laws for protecting the privacy and security of individually
Protecting Patient Privacy It s Everyone s Responsibility
Protecting Patient Privacy It s Everyone s Responsibility Observation & Student Learning Packet 1. Read packet Instructions for Self-Study Module 2. Complete post-test. A score of 80% must be achieved.
HIPAA Self-Study Module Patient Privacy at Unity Health Care, Inc [email protected] 202-667-0016 - HIPAA Hotline
HIPAA Self-Study Module Patient Privacy at Unity Health Care, Inc [email protected] 202-667-0016 - HIPAA Hotline Self-Study Module Requirements Read all program slides and complete test. Complete
HIPAA Orientation. Health Insurance Portability and Accountability Act
HIPAA Orientation Health Insurance Portability and Accountability Act HIPAA Federal legislation enacted in 1996 to improve the efficiency and effectiveness of electronic information transfers used in the
HIPAA Compliance. 2013 Annual Mandatory Education
HIPAA Compliance 2013 Annual Mandatory Education What is HIPAA? Health Insurance Portability and Accountability Act Federal Law enacted in 1996 that mandates adoption of Privacy protections for health
HIPAA (Health Insurance Portability and Accountability Act) Awareness Training for Volunteers and Interns
HIPAA (Health Insurance Portability and Accountability Act) Awareness Training for Volunteers and Interns Boulder County Public Health Volunteer/Intern Services 3450 Broadway Boulder, CO 80304 1 Boulder
Patient Privacy and HIPAA/HITECH
Patient Privacy and HIPAA/HITECH What is HIPAA? Health Insurance Portability and Accountability Act of 1996 Implemented in 2003 Title II Administrative Simplification It s a federal law HIPAA is mandatory,
HIPAA Compliance for Students
HIPAA Compliance for Students The Health Insurance Portability and Accountability Act (HIPAA) was passed in 1996 by the United States Congress. It s intent was to help people obtain health insurance benefits
HIPAA Privacy Policies
HIPAA Privacy Policies Healthcare Insurance Portability and Accountability Act of 1996 (HIPAA) The HIPAA Privacy Rule created a national standard to protect patient s medical records and other personal
SELF-LEARNING MODULE (SLM) 2012 HIPAA Education Privacy Basics and Intermediate Modules
SELF-LEARNING MODULE (SLM) 2012 HIPAA Education Privacy Basics and Intermediate Modules Page 2 Index Privacy 101 and Intermediate Privacy Self-Learning Module 2012 HIPAA Education 3 Instructions Index
SDC-League Health Fund
SDC-League Health Fund 1501 Broadway, 17 th Floor New York, NY 10036 Tel: 212-869-8129 Fax: 212-302-6195 E-mail: [email protected] NOTICE OF PRIVACY PRACTICES THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION
The Health and Benefit Trust Fund of the International Union of Operating Engineers Local Union No. 94-94A-94B, AFL-CIO. Notice of Privacy Practices
The Health and Benefit Trust Fund of the International Union of Operating Section 1: Purpose of This Notice Notice of Privacy Practices Effective as of September 23, 2013 THIS NOTICE DESCRIBES HOW MEDICAL
HIPAA Training for Hospice Staff and Volunteers
HIPAA Training for Hospice Staff and Volunteers Hospice Education Network Objectives Explain the purpose of the HIPAA privacy and security regulations Name three patient privacy rights Discuss what you
HIPAA Privacy and Security
HIPAA Privacy and Security Cindy Cummings, RHIT February, 2015 1 HIPAA Privacy and Security The regulation is designed to safeguard Protected Health Information referred to PHI AND electronic Protected
HIPAA Privacy & Security Rules
HIPAA Privacy & Security Rules HITECH Act Applicability If you are part of any of the HIPAA Affected Areas, this training is required under the IU HIPAA Privacy and Security Compliance Plan pursuant to
Patients First: How We Protect Your Privacy
Patients First: How We Protect Your Privacy To Our Patients: At Northwestern Memorial Hospital, we are committed to providing you with the highest quality of care in an environment that protects your privacy
Page 1. NAOP HIPAA and Privacy Risks 3/11/2014. Privacy means being able to have control over how your information is collected, used, or shared;
Page 1 National Organization of Alternative Programs 2014 NOAP Educational Conference HIPAA and Privacy Risks Ira J Rothman, CPHIMS, CIPP/US/IT/E/G Senior Vice President - Privacy Official March 26, 2014
A A E S C. Albuquerque Ambulatory Eye Surgery Center NOTICE OF PRIVACY PRACTICES
A A E S C Albuquerque Ambulatory Eye Surgery Center NOTICE OF PRIVACY PRACTICES THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION.
Clinician s Guide to HIPAA Privacy. I. Introduction What is HIPAA? Health Information Privacy Protected Health Information
Clinician s Guide to HIPAA Privacy I. Introduction What is HIPAA? Health Information Privacy Protected Health Information II. HIPAA s Impact On Clinical Practice, Treatment, Referrals And Payment How is
HEALTH INSURANCE PORTABILITY & ACCOUNTABILITY ACT OF 1996 HIPAA
TRAINING MANUAL HEALTH INSURANCE PORTABILITY & ACCOUNTABILITY ACT OF 1996 HIPAA Table of Contents INTRODUCTION 3 What is HIPAA? Privacy Security Transactions and Code Sets What is covered ADMINISTRATIVE
Notice of Health Information Privacy Practices Radiology Associates of Norwood, Inc.
Notice of Health Information Privacy Practices THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW THIS NOTICE
HFS DATA SECURITY TRAINING WITH TECHNOLOGY COMES RESPONSIBILITY
HFS DATA SECURITY TRAINING WITH TECHNOLOGY COMES RESPONSIBILITY Illinois Department of Healthcare and Family Services Training Outline: Training Goals What is the HIPAA Security Rule? What is the HFS Identity
Reproductive Medicine Associates of New Jersey, LLC
NOTICE OF PRIVACY PRACTICES Effective Date: September 20, 2013 Last Modified: May 12, 2013 THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO
MCCP Online Orientation
Objectives At the conclusion of this presentation, students will be able to: Describe the federal requirements of the HIPAA/HITECH regulations that protect the privacy and security of confidential data.
HIPAA Omnibus Notice of Privacy Practices Effective Date: March 03, 2012 Revised on: July 1, 2015
HIPAA Omnibus Notice of Privacy Practices Effective Date: March 03, 2012 Revised on: July 1, 2015 Mobile Physician Group PC 231 High Street Suite 1, Mount Holly, NJ 08060 1-855-MPG-DOCS THIS NOTICE DESCRIBES
HIPAA Policy, Protection, and Pitfalls ARTHUR J. GALLAGHER & CO. BUSINESS WITHOUT BARRIERS
HIPAA Policy, Protection, and Pitfalls Overview HIPAA Privacy Basics What s covered by HIPAA privacy rules, and what isn t? Interlude on the Hands-Off Group Health Plan When does this exception apply,
OUR LADY OF THE LAKE, HOSPITAL INC. AND OUR LADY OF THE LAKE PHYSICIAN GROUP, LLC NOTICE OF PRIVACY PRACTICES
OUR LADY OF THE LAKE, HOSPITAL INC. AND OUR LADY OF THE LAKE PHYSICIAN GROUP, LLC NOTICE OF PRIVACY PRACTICES THIS NOTICE DESCRIBES HOW HEALTH INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU
The HIPAA Security Rule Primer A Guide For Mental Health Practitioners
The HIPAA Security Rule Primer A Guide For Mental Health Practitioners Distributed by NASW Printer-friendly PDF 2006 APAPO 1 Contents Click on any title below to jump to that page. 1 What is HIPAA? 3 2
Birkam Health Center Ferris State University NOTICE OF PRIVACY PRACTICES
Birkam Health Center Ferris State University NOTICE OF PRIVACY PRACTICES Effective Date of Notice: October 1, 2013 THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND
Health Insurance Portability and Accountability Act of 1996 (HIPAA) Contents
Health Insurance Portability and Accountability Act of 1996 (HIPAA) Contents Health Insurance Portability and Accountability Act of 1996 (HIPAA)... 1 Welcome to HIPAA Awareness Training Content... 3 HIPAA
Notice of Privacy Practices
SHANNON LERACH, Ph.D. Licensed Clinical Psychologist PSY23705 243 N. Highway 101, Suite 16, Solana Beach, CA 92075 Telephone: (619) 817.5320 Fax: (858) 481.1674 Notice of Privacy Practices This Notice
PRIVACY PRACTICES OUR PRIVACY OBLIGATIONS
PRIVACY PRACTICES THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY. General Information To comply
HIPAA PRIVACY AND SECURITY TRAINING P I E D M O N T COMMUNITY H EA LT H P L A N
HIPAA PRIVACY AND SECURITY TRAINING P I E D M O N T COMMUNITY H EA LT H P L A N 1 COURSE OVERVIEW This course is broken down into 4 modules: Module 1: HIPAA Omnibus Rule - What you need to know to remain
PROTECTING PATIENT PRIVACY and INFORMATION SECURITY
PROTECTING PATIENT PRIVACY and INFORMATION SECURITY 2 PROTECTING PATIENT PRIVACY AND INFORMATION SECURITY PROTECTING PATIENT PRIVACY AND INFORMATION SECURITY 3 INTRODUCTION As an agency employee, student,
BERKELEY COLLEGE DATA SECURITY POLICY
BERKELEY COLLEGE DATA SECURITY POLICY BERKELEY COLLEGE DATA SECURITY POLICY TABLE OF CONTENTS Chapter Title Page 1 Introduction 1 2 Definitions 2 3 General Roles and Responsibilities 4 4 Sensitive Data
HIPAA: Privacy/Info Security
HIPAA: Privacy/Info Security Jeff Jones HIPAA Privacy Officer HIPAA Information Security Officer KY Region What you should know Discussion Topics Protected Health Security Awareness Information(PHI) Disclosure
HIPAA Notice of Privacy Practices HAND & MICROSURGERY ASSOCIATES, INC.
HIPAA Notice of Privacy Practices HAND & MICROSURGERY ASSOCIATES, INC. THIS NOTICE OF PRIVACY PRACTICES (THE NOTICE ) DESCRIBES HOW HEALTH INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN
A Privacy and Information Security Guide for UCLA Workforce. HIPAA and California Privacy Laws
A Privacy and Information Security Guide for UCLA Workforce HIPAA and California Privacy Laws A Privacy and Information Security Guide for UCLA Workforce HIPAA and California Privacy Laws Table of Contents
CREATIVE SOLUTIONS IN HEALTHCARE, INC. Privacy Policy
CREATIVE SOLUTIONS IN HEALTHCARE, INC. Privacy Policy Amended as of February 12, 2010 on the authority of the HIPAA Privacy Officer for Creative Solutions in Healthcare, Inc. TABLE OF CONTENTS ARTICLE
NOTICE OF PRIVACY PRACTICES
Effective Date: September 23, 2013 THIS NOTICE DESCRIBES HOW HEALTH INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY. OUR PLEDGE
Floyd Healthcare Management, Inc. Notice of Privacy Practices
Floyd Healthcare Management, Inc. Notice of Privacy Practices THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW
C.T. Hellmuth & Associates, Inc.
Technical Monograph C.T. Hellmuth & Associates, Inc. Technical Monographs usually are limited to only one subject which is treated in considerably more depth than is possible in our Executive Newsletter.
Privacy Compliance Health Occupations Students
Privacy Compliance Health Occupations Students Health Occupations Students The information in this power point is the same information provided to new SCHS caregivers at their orientation. We cannot stress
SCHOOL DISTRICT OF BLACK RIVER FALLS HIPAA PRIVACY AND SECURITY POLICY
SCHOOL DISTRICT OF BLACK RIVER FALLS HIPAA PRIVACY AND SECURITY POLICY School Board Policy 523.5 The School District of Black River Falls ( District ) is committed to compliance with the health information
The HIPAA Security Rule Primer Compliance Date: April 20, 2005
AMERICAN PSYCHOLOGICAL ASSOCIATION PRACTICE ORGANIZATION Practice Working for You The HIPAA Security Rule Primer Compliance Date: April 20, 2005 Printer-friendly PDF 1 Contents Click on any title below
Pulmonary Associates of Richmond, Inc. Notice of Privacy Practices Page 1 of 6
Page 1 of 6 THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY. If you have any questions about
NOTICE OF THE NATHAN ADELSON HOSPICE PRIVACY PRACTICES
THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION PLEASE REVIEW IT CAREFULLY. DEFINITIONS PROTECTED HEALTH INFORMATION (PHI):
HIPAA TRAINING. A training course for Shiawassee County Community Mental Health Authority Employees
HIPAA TRAINING A training course for Shiawassee County Community Mental Health Authority Employees WHAT IS HIPAA? HIPAA is an acronym that stands for Health Insurance Portability and Accountability Act.
MEDICAL OFFICE COMPLIANCE TOOLKIT. The Complete Medical Practice Compliance Resource HIPAA HITECH OSHA CLIA
MEDICAL OFFICE COMPLIANCE TOOLKIT The Complete Medical Practice Compliance Resource HIPAA HITECH OSHA CLIA MEDICAL OFFICE COMPLIANCE TOOLKIT The Complete Medical Practice Compliance Resource HIPAA HITECH
8.03 Health Insurance Portability and Accountability Act (HIPAA)
Human Resource/Miscellaneous Page 1 of 5 8.03 Health Insurance Portability and Accountability Act (HIPAA) Policy: It is the policy of Licking/Knox Goodwill Industries, Inc., to maintain the privacy of
AVE MARIA UNIVERSITY HIPAA PRIVACY NOTICE
AVE MARIA UNIVERSITY HIPAA PRIVACY NOTICE This Notice of Privacy Practices describes the legal obligations of Ave Maria University, Inc. (the plan ) and your legal rights regarding your protected health
ADVOCATE HEALTH CARE NOTICE OF PRIVACY PRACTICES
THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY. I have received the attached Advocate Health
HIPAA AND COMPLIANCE
HIPAA AND COMPLIANCE LEARNING MODULE #2 For Clinical Students and Instructors HWCA- South Central- Southwest Member Clinical Sites HEALTH CARE WORKFORCE ALLIANCE Revised August 2011 Objectives 2 At the
HIPAA Training for Staff and Volunteers
HIPAA Training for Staff and Volunteers Objectives Explain the purpose of the HIPAA privacy, security and breach notification regulations Name three patient privacy rights Discuss what you can do to help
Notice of Privacy Practices for Protected Health Information (PHI)
Notice of Privacy Practices for Protected Health Information (PHI) Arapahoe Sports Medicine and Rehabilitation THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW
NOTICE OF PRIVACY PRACTICES
NOTICE OF PRIVACY PRACTICES Effective Date: September, 2013 THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW
