Entities Covered by the HIPAA Privacy Rule
|
|
|
- Edmund Hancock
- 10 years ago
- Views:
Transcription
1 Entities Covered by the HIPAA Privacy Rule
2 Who Is A Covered Entity? HIPAA standards apply only to: Health care providers who transmit any health information electronically in connection with certain transactions Health plans Health care clearinghouses 45 CFR , HHS/OCR
3 What is a Health Care Provider? A health care provider is Any person or organization who furnishes, bills, or is paid for health care in the normal course of business 45 CFR HHS/OCR
4 Are All Health Care Providers Covered? Health care providers are covered only if they transmit health information electronically in connection with a transaction covered by the HIPAA Transaction Rule * Directly or through a business associate 45 CFR HHS/OCR
5 HIPAA Transactions Rule Standards 1. Health care claims or equivalent encounter information 2. Health care payment and remittance advice 3. Coordination of benefits 4. Health care claim status 5. Enrollment or disenrollment in a health plan 6. Eligibility for a health plan 7. Health plan premium payments 8. Referral certification and authorization 45 CFR HHS/OCR
6 What Is A Health Plan? Any individual or group plan (or combination) that provides, or pays for the cost, of medical care. Examples include: Health insurance issuers HMOs Group Health Plans Medicare, Parts A and B Medicare + Choice Medicaid 45 CFR HHS/OCR
7 What Health Plans Are Covered? All health plans are covered Entities that are not considered health plans include: Employer plans with fewer than 50 participants and which are selfadministered Excepted Benefit Plans Certain government funded programs 45 CFR HHS/OCR
8 Group Health Plans as Covered Entities Under ERISA, a group health plan is a separate legal entity from the employer/plan sponsor The Privacy Rule does not cover employers or plan sponsors 45 CFR HHS/OCR
9 What Is A Health Care Clearinghouse? How does Rule Apply? Translates data content or format for another entity from non-standard to standard or vice versa Limitation on Applicability of Privacy Rule 45 CFR , (b) HHS/OCR
10 Business Associates
11 Who Is A Business Associate? A person who performs a function or activity on behalf of, or provides services to, a Covered Entity that involves Individually Identifiable Health Information Is not a workforce member Covered Entity can be a Business Associate 45 CFR HHS/OCR
12 Examples Outside BA Definition Two Covered Entities each performing functions on its own behalf Provider gives PHI to payer for payment Hospital and physician treating patients at hospital Persons or organizations where access to protected health information is not necessary to do their job Janitors, electricians, copy machine repair persons 45 CFR HHS/OCR
13 Requirements on Covered Entity Obtain satisfactory assurance that Business Associate will appropriately safeguard Protected Health Information Written contract or other written arrangement or agreement No monitoring Cure or terminate contract if known violation 45 CFR (e), (e) HHS/OCR
14 Contracts Must Include: Permitted uses and disclosures Requirement to use appropriate safeguards Requirement to report of nonpermitted uses and disclosures to Covered Entity Requirement to extend same terms to subcontractors/agents 45 CFR (e) HHS/OCR
15 Business Associate Exceptions Disclosures to a provider for treatment to an individual Disclosures by a group health plan to plan sponsor if for plan administration Uses or disclosures by a government health plan (e.g., Medicare) to another agency (e.g., SSA) for eligibility or enrollment determinations if authorized by law 45 CFR (e) HHS/OCR
16 Transition Provisions For a written contract existing as of 10/15/02 and not renewed or modified by 4/14/03: Covered Entities are allowed until 4/14/04 to have contract comply with Privacy Rule requirements 45 CFR (d) HHS/OCR
17 Group Health Plan Disclosures to Plan Sponsors
18 Types of Disclosures to Plan Sponsors Summary health information; Enrollment and disenrollment information Amend plan documents With individual authorization 45 CFR (f), (a), HHS/OCR
19 Summary Health Information, Enrollment & Disenrollment May disclose summary health information for: Obtaining premium bids from health plans Modifying, amending or terminating health plans Enrollment or disenrollment in a health plan 45 CFR (f) HHS/OCR
20 Adequate Assurances from Plan Sponsor Group health plan may disclose PHI to plan sponsor for plan administrative functions if: plan documents are amended to provide permitted and required uses/disclosures by plan sponsor Certification by plan sponsor Adequate separation ( erect firewalls ) 45 CFR (f) HHS/OCR
21 ORGANIZATIONAL ISSUES Hybrid Entities Affiliated Covered Entities Organized Health Care Arrangements
22 Choosing Hybrid Entity Status Covered Entity that does both covered and non-covered functions Option to restrict the application of the Privacy Rule to certain parts of its organization By designating health care components (HCC) This designation will make the Covered Entity a Hybrid Entity under the Rule 45 CFR , 105 HHS/OCR
23 Effects of Hybrid Status Covered Entity retains administrative and legal responsibilities Must ensure that The Health Care Component complies with Privacy Rule ( erect firewalls ) Workforce members who perform tasks for both the HCC and non-hcc do not inappropriately use or disclose PHI Has legal responsibility for complying with Privacy Rule 45 CFR (a) HHS/OCR
24 Affiliated Covered Entity Legally separate Covered Entities Under common ownership or control Option to be treated as a single legal entity By choosing to designate This designation will make the Covered Entity an Affiliated Covered Entity under the Rule 45 CFR , (b) HHS/OCR
25 Effects of Affiliated Covered Entity Status May be able to share information in a way that would otherwise be impermissible (sharing becomes a use not a disclosure ). May minimize administrative burdens BUT, each is separately subject to liability for enforcement actions, and could be cumbersome to devise and comply with uniform set of policies, and/or one notice 45 CFR (b) HHS/OCR
26 Organized Health Care Arrangement (OHCA) Several defined arrangements are OHCAs: Clinically integrated care settings (e.g., hospital and doctors on medical staff) Covered entities that hold themselves out to the public as participating in joint arrangements and engage in certain joint activities (e.g., IPA) Certain group health plan arrangements 45 CFR HHS/OCR
27 OHCA: Application of the Rule OHCA or its members can choose whether or not: To contract as one entity with a business associate To disclose PHI to another covered entity that participates in the OHCA for joint health care activities of the OHCA To have joint notices only need be provided once BUT, each is separately subject to liability for enforcement actions 45 CFR , (d) HHS/OCR
28 Summary Rule applies to: Providers that conduct certain transactions electronically Health plans Clearinghouses 45 CFR , HHS/OCR
BUSINESS ASSOCIATES [45 CFR 164.502(e), 164.504(e), 164.532(d) and (e)]
OR HIPAA Privacy BUSINESS ASSOIATES [45 FR 164.502(e), 164.504(e), 164.532(d) and (e)] Background By law, the HIPAA Privacy Rule applies only to covered entities health plans, health care clearinghouses,
BUSINESS ASSOCIATES [45 CFR 164.502(e), 164.504(e), 164.532(d) and (e)]
BUSINESS ASSOCIATES [45 CFR 164.502(e), 164.504(e), 164.532(d) and (e)] Background By law, the HIPAA Privacy Rule applies only to covered entities health plans, health care clearinghouses, and certain
HIPAA Enforcement Training for State Attorneys General
: State Attorneys General Enforcement of Federal Health Privacy Law HIPAA Enforcement Training for State Attorneys General Module Introduction : Introduction This module of the HIPAA Enforcement Training
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) TERMS AND CONDITIONS FOR BUSINESS ASSOCIATES
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) TERMS AND CONDITIONS FOR BUSINESS ASSOCIATES I. Overview / Definitions The Health Insurance Portability and Accountability Act is a federal law
Hybrid Entities Health Insurance Portability and Accountability Act of 1996 (HIPAA)
Hybrid Entities Health Insurance Portability and Accountability Act of 1996 (HIPAA) 160.102 APPLICABILITY U.S. Department of Health and Human Services Office of the Secretary THE PRIVACY RULE Related Excerpts
HIPAA Privacy Summary for Fully-insured Employer Groups
HIPAA Privacy Summary for Fully-insured Employer Groups I. Overview The Privacy Regulations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) regulate the uses and disclosures
RONALD V. MCGUCKIN AND ASSOCIATES Post Office Box 2126 Bristol, Pennsylvania 19007 (215) 785-3400 (215) 785-3401 (Fax) childproviderlaw.
RONALD V. MCGUCKIN AND ASSOCIATES Post Office Box 2126 Bristol, Pennsylvania 19007 (215) 785-3400 (215) 785-3401 (Fax) childproviderlaw.com HIPAA The Health Insurance Portability and Accountability Act
HIPAA. HIPAA and Group Health Plans
HIPAA HIPAA and Group Health Plans CareFirst BlueCross BlueShield is the business name of CareFirst of Maryland, Inc. and is an independent licensee of the Blue Cross and Blue Shield Association. Registered
HIPAA Privacy Rule Primer for the College or University Administrator
HIPAA Privacy Rule Primer for the College or University Administrator On August 14, 2002, the Department of Health and Human Services ( HHS ) issued final medical privacy regulations (the Privacy Rule
Covered Entity Charts
Covered Entity Charts Guidance on how to determine whether an organization or individual is a covered entity under the Administrative Simplification provisions of HIPAA 2 Background: The Administrative
HIPAA PRIVACY AND EDI RULES
The Health and Human Services (HHS) issued final HIPAA privacy regulations on August 14, 2002. These rules govern how individually identifiable medical information must be protected. HIIPAA also requires
Alert. Client PROSKAUER ROSE LLP. HIPAA Compliance Update: Employers, As Group Health Plan Sponsors, Will Be Affected By HIPAA Privacy Requirements
PROSKAUER ROSE LLP Client Alert HIPAA Compliance Update: Employers, As Group Health Plan Sponsors, Will Be Affected By HIPAA Privacy Requirements The U.S. Department of Health and Human Services published
HIPAA. Privacy and Security Frequently Asked Questions for Employers. Gallagher Benefit Services, Inc.
2013 HIPAA Privacy and Security Frequently Asked Questions for Employers Gallagher Benefit Services, Inc. Disclaimer We share this information with our clients and friends for general informational purposes
State of Nevada Public Employees Benefits Program. Master Plan Document for the HIPAA Privacy and Security Requirements for PEBP Health Benefits
State of Nevada for the Requirements for PEBP Health Benefits Plan Year 2016 July 1, 2015 June 30, 2016 www.pebp.state.nv.us (775) 684-7000 Or (800) 326-5496 Amendments Amendment Log Any amendments, changes
HIPAA Compliance and PrintFleet Software Applications
HIPAA Compliance and PrintFleet Software Applications PrintFleet Software Applications Do Not Impact HIPAA Compliance The use of PrintFleet software applications will not have an impact on compliance with
SUMMARY OF THE HIPAA PRIVACY RULE
OCR PRIVACY BRIEF SUMMARY OF THE HIPAA PRIVACY RULE HIPAA Compliance Assistance SUMMARY OF THE HIPAA PRIVACY RULE Contents Introduction... 1 Statutory & Regulatory Background... 1 Who is Covered by the
HIPAA Privacy Summary for Self-insured Employer Groups
I. Overview HIPAA Privacy Summary for Self-insured Employer Groups The Privacy Regulations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) regulate the uses and disclosures of
Business Associates and Breach Reporting Under HITECH and the Omnibus Final HIPAA Rule
Business Associates and Breach Reporting Under HITECH and the Omnibus Final HIPAA Rule Patricia D. King, Esq. Associate General Counsel Swedish Covenant Hospital Chicago, IL I. Business Associates under
HIPAA. Health Insurance Portability & Accountability Act Administrative Simplification FIVE THINGS YOU SHOULD KNOW ABOUT PAYMENTS AND HIPAA
HIPAA Health Insurance Portability & Accountability Act Administrative Simplification FIVE THINGS YOU SHOULD KNOW ABOUT PAYMENTS AND HIPAA Steve Stone PNC Bank, N.A. October 14, 2009 Five Things You Should
Business Associate Agreement
Business Associate Agreement This Business Associate Agreement (the Agreement ) is made by and between Business Associate, [Name of Business Associate], and Covered Entity, The Connecticut Center for Health,
BUSINESS ASSOCIATE AGREEMENT HIPAA Protected Health Information
BUSINESS ASSOCIATE AGREEMENT HIPAA Protected Health Information I. PREAMBLE ( Covered Entity ) and ( Business Associate ) (jointly the Parties ) wish to enter into an Agreement to comply with the requirements
HIPAA Agreements Overview, Guidelines, Samples
HIPAA Agreements Overview, Guidelines, Samples I. Purpose The purpose of this document is to provide an overview of the regulatory requirements related to HIPAA trading partner agreements, business associate
The privacy rules under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) have been
As Appeared in Benefits Law Journal Vol. 17, No. 1, Spring 2004 HIPAA Privacy Compliance: It s Time to Take It Seriously By Russell E. Greenblatt and Jeffrey J. Bakker, Katten Muchin Zavis Rosenman 2004
The HIPAA Security Rule Primer A Guide For Mental Health Practitioners
The HIPAA Security Rule Primer A Guide For Mental Health Practitioners Distributed by NASW Printer-friendly PDF 2006 APAPO 1 Contents Click on any title below to jump to that page. 1 What is HIPAA? 3 2
General HIPAA Implementation FAQ
General HIPAA Implementation FAQ What is HIPAA? Signed into law in August 1996, the Health Insurance Portability and Accountability Act ( HIPAA ) was created to provide better access to health insurance,
HIPAA Compliance Calendar
TITLE DESCRIPTION National Provider Identifier National Provider Identifier This final rule establishes the standard for a unique health identifier for health care providers for use in the health care
Health Insurance Portability and Accountability Act HIPAA. Glossary of Common Terms
Health Insurance Portability and Accountability Act HIPAA Glossary of Common Terms Terms: HIPAA Definition*: PHCS Definition/Interpretation: Administrative Simplification HIPAA Subtitle F It is the purpose
Am I a Business Associate? Do I want to be a Business Associate? What are my obligations?
Am I a Business Associate? Do I want to be a Business Associate? What are my obligations? Brought to you by Winston & Strawn s Health Care Practice Group 2013 Winston & Strawn LLP Today s elunch Presenters
Neither You Nor Your Business Associates Can Afford to be Lax About Complying with HIPAA Requirements
Neither You Nor Your Business Associates Can Afford to be Lax About Complying with HIPAA Requirements Sara Kashing, JD, Staff Attorney July/August 2012 The Therapist If you are considered a Covered Entity
CROSS, GUNTER, WITHERSPOON & GALCHUS, P.C. ATTORNEYS AT LAW LITTLE ROCK/FORT SMITH/FAYETTEVILLE
CROSS, GUNTER, WITHERSPOON & GALCHUS, P.C. ATTORNEYS AT LAW LITTLE ROCK/FORT SMITH/FAYETTEVILLE Scotty Shively [email protected] www.cgwg.com 500 President Clinton Avenue, Suite 200 Little Rock, AR 72201
HIPAA POLICIES & PROCEDURES AND ADMINISTRATIVE FORMS TABLE OF CONTENTS
HIPAA POLICIES & PROCEDURES AND ADMINISTRATIVE FORMS TABLE OF CONTENTS 1. HIPAA Privacy Policies & Procedures Overview (Policy & Procedure) 2. HIPAA Privacy Officer (Policy & Procedure) 3. Notice of Privacy
HIPAA Security Rule Compliance
HIPAA Security Rule Compliance Caryn Reiker MAXIS360 HIPAA Security Rule Compliance what is it and why you should be concerned about it Table of Contents About HIPAA... 2 Who Must Comply... 2 The HIPAA
American Bar Association. Technical Session Between the Department of Health and Human Services and the Joint Committee on Employee Benefits
American Bar Association Technical Session Between the Department of Health and Human Services and the Joint Committee on Employee Benefits May 6, 2008 The following notes are based upon the personal comments
HIPAA PRIVACY AND SECURITY AWARENESS
HIPAA PRIVACY AND SECURITY AWARENESS Introduction The Health Insurance Portability and Accountability Act (known as HIPAA) was enacted by Congress in 1996. HIPAA serves three main purposes: To protect
Business Associate Agreement (BAA) Guidance
Business Associate Agreement (BAA) Guidance Introduction The purpose of this document is to provide guidance for creating or updating business associate agreements between your Practice ( Covered Entity
The Basics of HIPAA Privacy and Security and HITECH
The Basics of HIPAA Privacy and Security and HITECH Protecting Patient Privacy Disclaimer The content of this webinar is to introduce the principles associated with HIPAA and HITECH regulations and is
SAMPLE BUSINESS ASSOCIATE AGREEMENT
SAMPLE BUSINESS ASSOCIATE AGREEMENT THIS AGREEMENT IS TO BE USED ONLY AS A SAMPLE IN DEVELOPING YOUR OWN BUSINESS ASSOCIATE AGREEMENT. ANYONE USING THIS DOCUMENT AS GUIDANCE SHOULD DO SO ONLY IN CONSULT
HIPAA Business Associate Contract. Definitions
HIPAA Business Associate Contract Definitions Terms used, but not otherwise defined, in this Agreement shall have the same meaning as those terms in the Privacy Rule. Examples of specific definitions:
HIPAA: AN OVERVIEW September 2013
HIPAA: AN OVERVIEW September 2013 Introduction The Health Insurance Portability and Accountability Act of 1996, known as HIPAA, was enacted on August 21, 1996. The overall goal was to simplify and streamline
ELECTRONIC HEALTH RECORDS
ELECTRONIC HEALTH RECORDS Understanding and Using Computerized Medical Records CHAPTER TEN LESSON ONE Privacy and Security of Health Records Understanding HIPAA HIPAA: acronym for Health Insurance Portability
APPENDIX 1: Frequently Asked Questions
APPENDIX 1: Frequently Asked Questions Practice Name Q: What is the HIPAA Privacy Rule? A: The HIPAA Privacy Rule controls the use and disclosure of what is known as Protected Health Information (PHI).
Schindler Elevator Corporation
-4539 Telephone: (973) 397-6500 Mail Address: P.O. Box 1935 Morristown, NJ 07962-1935 NOTICE OF PRIVACY PRACTICES FOR PROTECTED HEALTH INFORMATION THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU
How To Get A Health Care License
HIPAA Privacy Compliance Manual 10/21/09 HOW TO USE THIS MANUAL This HIPAA Compliance Manual is an interactive workbook to help you comply with the HIPAA Privacy Rule. (45 CFR 164.500 et. seq.) We intend
The HIPAA Security Rule Primer Compliance Date: April 20, 2005
AMERICAN PSYCHOLOGICAL ASSOCIATION PRACTICE ORGANIZATION Practice Working for You The HIPAA Security Rule Primer Compliance Date: April 20, 2005 Printer-friendly PDF 1 Contents Click on any title below
Graphic Communications National Health and Welfare Fund. Notice of Privacy Practices
Notice of Privacy Practices Section 1: Purpose of This Notice and Effective Date THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION.
Joe Dylewski President, ATMP Solutions
Joe Dylewski President, ATMP Solutions Joe Dylewski President, ATMP Solutions Assistant Professor, Madonna University 20 Years, Technology and Application Implementation Experience Served as Michigan Healthcare
Health Care Information Privacy The HIPAA Regulations What Has Changed and What You Need to Know
Health Care Information Privacy The HIPAA Regulations What Has Changed and What You Need to Know Note: Information provided to NCRA by Melodi Gates, Associate with Patton Boggs, LLC Privacy and data protection
BUSINESS ASSOCIATE AGREEMENT
THIS IS A TEMPLATE ONLY. CERTAIN STATES MAY NOT PERMIT THE TYPES OF ACTIVITIES ALLOWED HEREUNDER RELATING TO PROTECTED HEALTH INFORMATION. THUS THIS AGREEMENT MAY NEED TO BE MODIFIED IN ORDER TO COMPLY
HIPAA Security. 5 Security Standards: Organizational, Policies. Security Topics. and Procedures and Documentation Requirements
HIPAA Security S E R I E S Security Topics 1. Security 101 for Covered Entities 2. Security Standards - Administrative Safeguards 3. Security Standards - Physical Safeguards 4. Security Standards - Technical
U.S. Department of Health and Human Services. U.S. Department of Education
U.S. Department of Health and Human Services U.S. Department of Education Joint Guidance on the Application of the Family Educational Rights and Privacy Act (FERPA) And the Health Insurance Portability
HIPAA NOTICE OF PRIVACY PRACTICES
HIPAA NOTICE OF PRIVACY PRACTICES Human Resources Department 16000 N. Civic Center Plaza Surprise, AZ 85374 Ph: 623-222-3532 // Fax: 623-222-3501 TTY: 623-222-1002 Purpose of This Notice This Notice describes
SCHOOL DISTRICT OF BLACK RIVER FALLS HIPAA PRIVACY AND SECURITY POLICY
SCHOOL DISTRICT OF BLACK RIVER FALLS HIPAA PRIVACY AND SECURITY POLICY School Board Policy 523.5 The School District of Black River Falls ( District ) is committed to compliance with the health information
Name of Other Party: Address of Other Party: Effective Date: Reference Number as applicable:
PLEASE NOTE: THIS DOCUMENT IS SUBMITTED AS A SAMPLE, FOR INFORMATIONAL PURPOSES ONLY TO ABC ORGANIZATION. HIPAA SOLUTIONS LC IS NOT ENGAGED IN THE PRACTICE OF LAW IN ANY STATE, JURISDICTION, OR VENUE OF
The Health and Benefit Trust Fund of the International Union of Operating Engineers Local Union No. 94-94A-94B, AFL-CIO. Notice of Privacy Practices
The Health and Benefit Trust Fund of the International Union of Operating Section 1: Purpose of This Notice Notice of Privacy Practices Effective as of September 23, 2013 THIS NOTICE DESCRIBES HOW MEDICAL
Sample Business Associate Agreement Provisions
Sample Business Associate Agreement Provisions Words or phrases contained in brackets are intended as either optional language or as instructions to the users of these sample provisions. Definitions Catch-all
Legislative & Regulatory Information
Americas - U.S. Legislative, Privacy & Projects Jurisdiction Effective Date Author Release Date File No. UFS Topic Citation: Reference: Federal 3/26/13 Michael F. Tietz Louis Enahoro HIPAA, Privacy, Privacy
BUSINESS ASSOCIATE AGREEMENT
BUSINESS ASSOCIATE AGREEMENT This Agreement ( Agreement ) is made and entered into this day of [Month], [Year] by and between [Business Name] ( Covered Entity ), [Type of Entity], whose business address
BUSINESS ASSOCIATE AGREEMENT. Recitals
BUSINESS ASSOCIATE AGREEMENT This Agreement is executed this 8 th day of February, 2013, by BETA Healthcare Group. Recitals BETA Healthcare Group consists of BETA Risk Management Authority (BETARMA) and
BUSINESS ASSOCIATES AND BUSINESS ASSOCIATE AGREEMENTS
PRIVACY 27.0 BUSINESS ASSOCIATES AND BUSINESS ASSOCIATE AGREEMENTS Scope: Purpose: All subsidiaries of Universal Health Services, Inc., including facilities and UHS of Delaware Inc. (collectively, UHS
