Introducing the NASW Updated Sample HIPAA Privacy Forms and Policies

Size: px
Start display at page:

Download "Introducing the NASW Updated Sample HIPAA Privacy Forms and Policies"

Transcription

1 Introducing the NASW Updated Sample HIPAA Privacy Forms and Policies Presenter: Sherri Morgan, JD, MSW Associate Counsel, NASW Legal Defense Fund and Office of Ethics & Professional Review 2013 National Association of Social Workers. All Rights Reserved. 1

2 Permissions for Use of Forms NASW s sample privacy forms and policies are for use by individual NASW members free of charge. For use by members only Sample forms need to be customized and modified for the specific social work practice setting and according to state law Use does not constitute legal advice Legal consultation or other advice in your state may be needed for full compliance. Each entity subject to HIPAA is responsible for compliance with the regulations National Association of Social Workers. All Rights Reserved. 2

3 Topics Covered Four types of sample NASW HIPAA privacy documents Who must comply with HIPAA Notice of Privacy Practices and modifications The interaction of HIPAA and state privacy laws Written HIPAA office policies and procedures Authorization forms and policies to release health information, drug & alcohol abuse treatment records and psychotherapy notes Sample breach notification documents and office policies Business associates defined; sample policy and contract Client access to electronic health records under HIPAA Key Recommendations Overview of federal and NASW online resources 2013 National Association of Social Workers. All Rights Reserved. 3

4 Sample HIPAA Privacy Documents Four categories of documents: Privacy, Authorizations, Breach Notification, Business Associates Types of documents: Forms, Office Policies, Instructions HIPAA requires written office policies HIPAA requires the Notice of Privacy Practices, compliant authorization forms, documentation of breaches, notification of breaches, business associate agreements, risk assessment, acknowledgement of the NPP, accounting of disclosures and more National Association of Social Workers. All Rights Reserved. 4

5 2013 National Association of Social Workers. All Rights Reserved. 5

6 HIPAA Regulations Security Standards Breach Notification Privacy Standards HIPAA Administrative Simplification National Provider Identifier Electronic Transactions Standards 2013 National Association of Social Workers. All Rights Reserved. 6

7 Who Must Comply with HIPAA? Covered Entities Defined: Health care providers and their business associates (and their sub-contractors) who transmit health information in certain electronic transactions Health plans Health care clearinghouses 2013 National Association of Social Workers. All Rights Reserved. 7

8 Applicability of HIPAA Generally HIPAA applies to a social work practice if that practice submits insurance claims electronically, either directly or through a billing service or clearinghouse. HIPAA does not apply to a health care practice that does not file any insurance claims electronically (i.e. via a computer) National Association of Social Workers. All Rights Reserved. 8

9 Notice of Privacy Practices (NPP) Four related NASW sample documents: 1. Notice of Privacy Practices 2. Instructions for Use of the NPP 2013 National Association of Social Workers. All Rights Reserved. 9

10 Notice of Privacy Practices (NPP) 3. Notice of Privacy Practices Policy 4. Acknowledgement of the NPP 2013National Association of Social Workers. All Rights Reserved. 10

11 Modifying the Sample NPP Delete the underlined heading Sample Notice of Privacy Practices 2013 National Association of Social Workers. All Rights Reserved. 11

12 Modifying the Sample NPP Fill in the contact information (address, , telephone, etc.) for your Privacy Officer in the blank lines on pp. 3 & National Association of Social Workers. All Rights Reserved. 12

13 Modifying the Sample NPP Read the NPP in its entirety and consider whether it accurately reflects your office privacy policies & procedures, as consistent with HIPAA, state law and professional ethics. Modify the effective date of the policy as of the date you implement it (not earlier). Retain copies of the NPP for six years National Association of Social Workers. All Rights Reserved. 13

14 HIPAA and State Law HIPAA is a set of federal minimum health privacy standards HIPAA pre-empts state law, unless State law is more protective of client privacy, or State law provides clients with a greater right of access to their protected health information. Practitioners needs to review their state confidentiality rules according to the social worker licensing board and compare to HIPAA s listed disclosures National Association of Social Workers. All Rights Reserved. 14

15 State Law Resources Look at state laws on access to health records and what deadlines apply and specific authorization requirements: See Access to Records by Social Workers Clients (Oct. 2012, LDF Legal Issue of the Month) 12.asp Look at licensing board confidentiality rules and when client consent is required or any limits on information disclosure: Visit the state social work licensing board website for your state. Links available at Some areas of possible conflict between HIPAA and state law: Amount of information disclosed to health plans (e.g. NJ) Timeframe for providing records to clients Consent required for disclosures for treatment, payment and healthcare business operations National Association of Social Workers. All Rights Reserved. 15

16 Use of the Finalized NPP Post your finalized NPP on your website Post the NPP in a common area of the office (i.e. waiting room) Provide individual copies of the NPP to all new clients/patients Attempt to gain client s written acknowledgement of receipt of the NPP or social worker must independently document the good faith attempt to provide the NPP (individual acknowledgement forms to be kept with client chart for six years) National Association of Social Workers. All Rights Reserved. 16

17 NPP Office Policy This is a HIPAA internal office policy document, required regardless of the size of the social work practice. It should be tailored to the actual privacy practices and procedures adopted by your office, as consistent with state law, social work ethics and HIPAA requirements. The day-to-day office privacy practices should be consistent with your written Notice of Privacy Practices Policy. Violations of your privacy policies are considered HIPAA violations National Association of Social Workers. All Rights Reserved. 17

18 HIPAA Office Policy Documents Must be maintained for six years (including prior versions of the policies) This time period may be longer or shorter than the required time for maintaining client records under state law and is independent of that requirement. Effective date cannot be earlier than the date on the written document. Need to insert the name of the actual social work practice to replace the bracketed title on the NASW sample documents National Association of Social Workers. All Rights Reserved. 18

19 Authorization to Release PHI Three related sample HIPAA documents: Authorization Policy 2013 National Association of Social Workers. All Rights Reserved. 19

20 Authorization to Release PHI Authorization to Release Substance Abuse Treatment Information 2013 National Association of Social Workers. All Rights Reserved. 20

21 Authorization to Release PHI Authorization to Release Mental Health Treatment Information 2013 National Association of Social Workers. All Rights Reserved. 21

22 Use of Authorization Forms Drug & Alcohol Treatment vs. Mental Health: Drug & alcohol abuse treatment records cannot be rereleased by the individual who receives them; however, health and mental health information may be re-released by the receiving party and the authorization must state that, depending on the type of records being released. Psychotherapy Notes vs. Patient Chart: Authorizations to release HIPAA-compliant psychotherapy notes (e.g. clinician s separate, private notes) cannot be combined with an authorization of any other type of information. Use the check-off on the Mental Health Authorization or write in psychotherapy notes in Other on the Drug & Alcohol Abuse Authorization) National Association of Social Workers. All Rights Reserved. 22

23 Resources for Authorizations LDF Legal Issue of the Month articles ( Confidentiality of Drug & Alcohol Abuse Treatment Information in an Electronic Age (February 2011) Social Workers and Psychotherapy Notes (June 2006) Health Insurance, HIPAA and Client Privacy (July 2011) 2013National Association of Social Workers. All Rights Reserved. 23

24 Authorization to Notify Patient of Breach via /Phone In the event of a privacy breach, HIPAA permits notification to clients by or telephone, if the client has given prior agreement. This should be to enable faster notification to clients, not for the convenience of the social worker. A sample form to document this agreement is provided and may be best to discuss with clients at the initiation of treatment when other consent forms are signed National Association of Social Workers. All Rights Reserved. 24

25 Breach Notification Policy Replace the header [INSERT NAME OF SOCIAL WORK ORGANIZATION] with the name of your social work practice/organization. Write in the effective date of the policy. Keep this with other HIPAA office policy documents. Most breach notifications to HHS are conducted online, rather than by mail: breachnotificationrule/brinstruction.html 2013National Association of Social Workers. All Rights Reserved. 25

26 Breach Notification Pointers Less than 500 affected clients (small breaches): Notify clients quickly (within 60 days) Notify HHS within 60 days after the end of the calendar year in a combined report with all breaches. 500 or more affected clients (large breaches): Notify clients quickly (within 60 days) Notify HHS when you notify clients Notify the media (within 60 days) 2013 National Association of Social Workers. All Rights Reserved. 26

27 Breach Notification to Clients Conduct investigation, assess risk of harm to clients, write breach incident report, document in breach incident log, contact authorities as appropriate. Send client s notification by U.S. mail unless you document an agreement to notify by or telephone National Association of Social Workers. All Rights Reserved. 27

28 Breach Notification to Clients Sample notification letter The text in brackets needs to be revised specifically for the social work organization, affected client, and specific breach incident National Association of Social Workers. All Rights Reserved. 28

29 HIPAA Business Associates HIPAA business associates = contracting entities that assist in operating a social work practice + have access to PHI (attorneys, accountants, billing services, information technology contractors, cloud computing vendors, etc.). Business associates (and subcontractors) are directly responsible for HIPAA compliance. Clinical social workers should require all business associates, including health information data vendors to sign a business associate contract. Sample forms from NASW LDF and HHS: entities/contractprov.html 2013 National Association of Social Workers. All Rights Reserved. 29

30 Business Associate (BA) Agreement Policy Review relationships with outside entities and put BA agreements in place. Review timing of existing agreements for compliance deadlines. Timeline for updated agreements under the Omnibus HIPAA Rule: For agreements in place prior to 1/25/13 and not renewed between 3/26/13 and 9/23/13: September 22, 2014 Compliance Deadline For new agreements or those modified/renewed between 3/26/13 and 9/23/13: September 23, 2013 Compliance Deadline 2013 National Association of Social Workers. All Rights Reserved. 30

31 Sample BA Agreement Delete the word Sample in the document title. Enter the effective date of the agreement. Enter the business name of the social work practice in the spaces designated for the covered entity. Enter the name of the business associate in the spaces designated. Delete or cross out inapplicable provisions relating to: drug and alcohol abuse treatment programs and/or Qualified Service Organizations National Association of Social Workers. All Rights Reserved. 31

32 Sample BA Agreement, cont. Section 2.1 Check the first box to specify the purpose for the business associate s access to clients protected health information and enter the specific purpose in the blank space OR check the second box if a separate services agreement is attached which details the purpose of the business associates use of protected health information and enter the name of that document in the blank space. Section 2.2 Check all options that apply. Section 2.6 Review with the business associate how state social worker confidentiality laws are also applicable and may restrict disclosure of PHI more than HIPAA. Have each party sign and date the agreement. Make a copy and store the agreement with HIPAA compliance documents. Provide a copy of your Notice of Privacy Practices Policy to the business associate. Review with business associates their use of subcontractors to perform functions under the BA agreement National Association of Social Workers. All Rights Reserved. 32

33 Clients Requests for Restrictions Clients are permitted to ask for restrictions to disclosures of their information that are usually permitted by HIPAA without consent (e.g. for purposes of treatment, payment and healthcare business operations). If clients ask that their health plan not be notified, the provider is required to comply if the client has self-paid for services National Association of Social Workers. All Rights Reserved. 33

34 Clients Requests for Restrictions Sample form is limited to client-initiated requests for restrictions National Association of Social Workers. All Rights Reserved. 34

35 Clients Access to ephi HIPAA does not require health care providers to maintain an electronic health record for clients; however, Providers who maintain an electronic client record are now obligated to provide access to this information in electronic format, upon request of the client. Access to the PHI is a mandatory client right, regardless of whether it is maintained electronically or in paper form. Social workers should review all client-related electronic data, files and communications in response to a client s request for access National Association of Social Workers. All Rights Reserved. 35

36 Key Recommendations Install encryption, firewalls and virus protection for all electronic media, software and communications Read your current state social work laws Get training/consultation for new technologies and practice modalities Become fully HIPAA compliant: written policies, privacy notices, authorization forms, training, business associate contracts Become proficient in the use of technology Use NASW and HHS resources National Association of Social Workers. All Rights Reserved. 36

37 Federal Health IT Privacy and Security Resources Cybersecure: security training module Security risk assessment tool Guide for physicians on evaluating security practices Cyber-security checklist HIPAA summary and guide Available at: National Association of Social Workers. All Rights Reserved. 37

38 NASW Legal Defense Fund Resources NASW HIPAA Information, Articles and Links: NASW Online HIPAA training courses: Sample HIPAA privacy forms and policies: Legal Defense Fund Legal Issue of the Month Articles: Law Note Series: National Association of Social Workers. All Rights Reserved. 38

39 Like us on Facebook National Association of Social Workers. All Rights Reserved. 39

40 Celebrate LDF s 40 th Anniversary Give $40 for the 40 th! LDF depends on member contributions: Call Visit National Association of Social Workers. All Rights Reserved. 40

HIPAA and Mental Health Privacy:

HIPAA and Mental Health Privacy: HIPAA and Mental Health Privacy: What Social Workers Need to Know Presenter: Sherri Morgan, JD, MSW Associate Counsel, NASW Legal Defense Fund and Office of Ethics & Professional Review 2010 National Association

More information

How To Write A Community Based Care Coordination Program Agreement

How To Write A Community Based Care Coordination Program Agreement Section 4.3 Implement Business Associate and Other Agreements This tool identifies the types of agreements that may be necessary for a community-based care coordination (CCC) program to have in place in

More information

Understanding HIPAA Privacy and Security Helping Your Practice Select a HIPAA- Compliant IT Provider A White Paper by CMIT Solutions

Understanding HIPAA Privacy and Security Helping Your Practice Select a HIPAA- Compliant IT Provider A White Paper by CMIT Solutions Understanding HIPAA Privacy and Security Helping Your Practice Select a HIPAA- Compliant IT Provider A White Paper by CMIT Solutions Table of Contents Understanding HIPAA Privacy and Security... 1 What

More information

New HIPAA regulations require action. Are you in compliance?

New HIPAA regulations require action. Are you in compliance? New HIPAA regulations require action. Are you in compliance? Mary Harrison, JD Tami Simon, JD May 22, 2013 Discussion topics Introduction Remembering the HIPAA Basics HIPAA Privacy Rules HIPAA Security

More information

Heather L. Hughes, J.D. HIPAA Privacy Officer U.S. Legal Support, Inc. [email protected] www.uslegalsupport.com

Heather L. Hughes, J.D. HIPAA Privacy Officer U.S. Legal Support, Inc. hhughes@uslegalsupport.com www.uslegalsupport.com Heather L. Hughes, J.D. HIPAA Privacy Officer U.S. Legal Support, Inc. [email protected] www.uslegalsupport.com HIPAA Privacy Rule Sets standards for confidentiality and privacy of individually

More information

HIPAA Omnibus & HITECH Rules: Key Provisions and a Simple Checklist. www.riskwatch.com

HIPAA Omnibus & HITECH Rules: Key Provisions and a Simple Checklist. www.riskwatch.com HIPAA Omnibus & HITECH Rules: Key Provisions and a Simple Checklist www.riskwatch.com Introduction Last year, the federal government published its long awaited final regulations implementing the Health

More information

12/19/2014. HIPAA More Important Than You Realize. Administrative Simplification Privacy Rule Security Rule

12/19/2014. HIPAA More Important Than You Realize. Administrative Simplification Privacy Rule Security Rule HIPAA More Important Than You Realize J. Ira Bedenbaugh Consulting Shareholder February 20, 2015 This material was used by Elliott Davis Decosimo during an oral presentation; it is not a complete record

More information

Texas House Bill 300 & HIPAA. A MainNerve Whitepaper

Texas House Bill 300 & HIPAA. A MainNerve Whitepaper A MainNerve Whitepaper Overview If you do business in Texas and your organization handles, creates, stores, transmits or has access to electronic patient healthcare information, you need to be mindful

More information

HIPAA Help for Social Workers

HIPAA Help for Social Workers HIPAA Help for Social Workers Introduction Social workers are increasingly entering the world of electronic claims transactions as these processes become more prevalent across the health care payment system.

More information

HHS Issues New HITECH/HIPAA Rule: Implications for Hospice Providers

HHS Issues New HITECH/HIPAA Rule: Implications for Hospice Providers Compliance Tip Sheet National Hospice and Palliative Care Organization www.nhpco.org/regulatory HHS Issues New HITECH/HIPAA Rule: Implications for Hospice Providers Hospice Provider Compliance To Do List

More information

University Healthcare Physicians Compliance and Privacy Policy

University Healthcare Physicians Compliance and Privacy Policy Page 1 of 11 POLICY University Healthcare Physicians (UHP) will enter into business associate agreements in compliance with the provisions of the Health Insurance Portability and Accountability Act of

More information

COMPLIANCE ALERT 10-12

COMPLIANCE ALERT 10-12 HAWAII HEALTH SYSTEMS C O R P O R A T I O N "Touching Lives Every Day COMPLIANCE ALERT 10-12 HIPAA Expansion under the American Recovery and Reinvestment Act of 2009 The American Recovery and Reinvestment

More information

BUSINESS ASSOCIATE AGREEMENT HIPAA Protected Health Information

BUSINESS ASSOCIATE AGREEMENT HIPAA Protected Health Information BUSINESS ASSOCIATE AGREEMENT HIPAA Protected Health Information I. PREAMBLE ( Covered Entity ) and ( Business Associate ) (jointly the Parties ) wish to enter into an Agreement to comply with the requirements

More information

HIPAA Omnibus Rule Overview. Presented by: Crystal Stanton MicroMD Marketing Communication Specialist

HIPAA Omnibus Rule Overview. Presented by: Crystal Stanton MicroMD Marketing Communication Specialist HIPAA Omnibus Rule Overview Presented by: Crystal Stanton MicroMD Marketing Communication Specialist 1 HIPAA Omnibus Rule - Agenda History of the Omnibus Rule What is the HIPAA Omnibus Rule and its various

More information

BUSINESS ASSOCIATE AGREEMENT. Recitals

BUSINESS ASSOCIATE AGREEMENT. Recitals BUSINESS ASSOCIATE AGREEMENT This Agreement is executed this 8 th day of February, 2013, by BETA Healthcare Group. Recitals BETA Healthcare Group consists of BETA Risk Management Authority (BETARMA) and

More information

The Basics of HIPAA Privacy and Security and HITECH

The Basics of HIPAA Privacy and Security and HITECH The Basics of HIPAA Privacy and Security and HITECH Protecting Patient Privacy Disclaimer The content of this webinar is to introduce the principles associated with HIPAA and HITECH regulations and is

More information

Ethics, Privilege, and Practical Issues in Cloud Computing, Privacy, and Data Protection: HIPAA February 13, 2015

Ethics, Privilege, and Practical Issues in Cloud Computing, Privacy, and Data Protection: HIPAA February 13, 2015 Ethics, Privilege, and Practical Issues in Cloud Computing, Privacy, and Data Protection: HIPAA February 13, 2015 Katherine M. Layman Cozen O Connor 1900 Market Street Philadelphia, PA 19103 (215) 665-2746

More information

HIPAA Security Rule Compliance

HIPAA Security Rule Compliance HIPAA Security Rule Compliance Caryn Reiker MAXIS360 HIPAA Security Rule Compliance what is it and why you should be concerned about it Table of Contents About HIPAA... 2 Who Must Comply... 2 The HIPAA

More information

Dissecting New HIPAA Rules and What Compliance Means For You

Dissecting New HIPAA Rules and What Compliance Means For You Dissecting New HIPAA Rules and What Compliance Means For You A White Paper by Cindy Phillips of CMIT Solutions and Kelly McClendon of CompliancePro Solutions TABLE OF CONTENTS Introduction 3 What Are the

More information

Updated HIPAA Regulations What Optometrists Need to Know Now. HIPAA Overview

Updated HIPAA Regulations What Optometrists Need to Know Now. HIPAA Overview Updated HIPAA Regulations What Optometrists Need to Know Now The U.S. Department of Health & Human Services Office for Civil Rights recently released updated regulations regarding the Health Insurance

More information

Sample Business Associate Agreement Provisions

Sample Business Associate Agreement Provisions Sample Business Associate Agreement Provisions Words or phrases contained in brackets are intended as either optional language or as instructions to the users of these sample provisions. Definitions Catch-all

More information

OCR UPDATE Breach Notification Rule & Business Associates (BA)

OCR UPDATE Breach Notification Rule & Business Associates (BA) OCR UPDATE Breach Notification Rule & Business Associates (BA) Alicia Galan Supervisory Equal Opportunity Specialist March 7, 2014 HITECH OMNIBUS A Reminder of What s Included: Final Modifications of the

More information

Health Care Information Privacy The HIPAA Regulations What Has Changed and What You Need to Know

Health Care Information Privacy The HIPAA Regulations What Has Changed and What You Need to Know Health Care Information Privacy The HIPAA Regulations What Has Changed and What You Need to Know Note: Information provided to NCRA by Melodi Gates, Associate with Patton Boggs, LLC Privacy and data protection

More information

HIPAA Compliance Calendar

HIPAA Compliance Calendar TITLE DESCRIPTION National Provider Identifier National Provider Identifier This final rule establishes the standard for a unique health identifier for health care providers for use in the health care

More information

My Docs Online HIPAA Compliance

My Docs Online HIPAA Compliance My Docs Online HIPAA Compliance Updated 10/02/2013 Using My Docs Online in a HIPAA compliant fashion depends on following proper usage guidelines, which can vary based on a particular use, but have several

More information

BUSINESS ASSOCIATE ADDENDUM

BUSINESS ASSOCIATE ADDENDUM BUSINESS ASSOCIATE ADDENDUM This BA Agreement, effective as of the effective date of the Terms of Use, adds to and is made part of the Terms of Use by and between Business Associate and Covered Entity.

More information

HIPAA and HITECH Compliance for Cloud Applications

HIPAA and HITECH Compliance for Cloud Applications What Is HIPAA? The healthcare industry is rapidly moving towards increasing use of electronic information systems - including public and private cloud services - to provide electronic protected health

More information

HIPAA BUSINESS ASSOCIATE AGREEMENT

HIPAA BUSINESS ASSOCIATE AGREEMENT HIPAA BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement ( BA Agreement ) is entered into by Medtep Inc., a Delaware corporation ( Business Associate ) and the covered entity ( Covered Entity

More information

INTRODUCTION. The HIPAA Privacy Rule and Electronic Health Information Exchange in a Networked Environment

INTRODUCTION. The HIPAA Privacy Rule and Electronic Health Information Exchange in a Networked Environment INTRODUCTION This guidance is composed of a series of fact sheets that clarify how the HIPAA Privacy Rule applies to, and can be used to help structure the privacy policies behind, electronic health information

More information

HIPAA/HITECH and Texas Privacy Laws Comparison Tool Updated 2013

HIPAA/HITECH and Texas Privacy Laws Comparison Tool Updated 2013 HIPAA/HITECH and Texas Privacy Laws Comparison Tool Updated 2013 Federal and Texas Privacy & Security Requirements Minimizing Your Risk of Violations DISCLAIMER The information contained in this document

More information

SAMPLE BUSINESS ASSOCIATE AGREEMENT

SAMPLE BUSINESS ASSOCIATE AGREEMENT SAMPLE BUSINESS ASSOCIATE AGREEMENT This is a draft business associate agreement based on the template provided by HHS. It is not intended to be used as is and you should only use the agreement after you

More information

BUSINESS ASSOCIATE PRIVACY AND SECURITY ADDENDUM RECITALS

BUSINESS ASSOCIATE PRIVACY AND SECURITY ADDENDUM RECITALS BUSINESS ASSOCIATE PRIVACY AND SECURITY ADDENDUM This Business Associate Addendum ( Addendum ), effective, 20 ( Effective Date ), is entered into by and between University of Southern California, ( University

More information

OCR s Anatomy: HIPAA Breaches, Investigations, and Enforcement

OCR s Anatomy: HIPAA Breaches, Investigations, and Enforcement OCR s Anatomy: HIPAA Breaches, Investigations, and Enforcement Clinton Mikel The Health Law Partners, P.C. Alessandra Swanson U.S. Department of Health and Human Services - Office for Civil Rights Disclosure

More information

AVE MARIA UNIVERSITY HIPAA PRIVACY NOTICE

AVE MARIA UNIVERSITY HIPAA PRIVACY NOTICE AVE MARIA UNIVERSITY HIPAA PRIVACY NOTICE This Notice of Privacy Practices describes the legal obligations of Ave Maria University, Inc. (the plan ) and your legal rights regarding your protected health

More information

Business Associate Agreement

Business Associate Agreement Business Associate Agreement This BUSINESS ASSOCIATE AGREEMENT (the "Agreement") is entered into by and between the Board of Regents of the University of Wisconsin System on behalf of the [insert name

More information

HIPAA Update. Presented by: Melissa M. Zambri. June 25, 2014

HIPAA Update. Presented by: Melissa M. Zambri. June 25, 2014 HIPAA Update Presented by: Melissa M. Zambri June 25, 2014 Timeline of New Rules 2/17/09 - Stimulus Package Enacted 8/24/09 - Interim Final Rule on Breach Notification 10/7/09 - Proposed Rule Regarding

More information

Donna S. Sheperis, PhD, LPC, NCC, CCMHC, ACS Sue Sadik, PhD, LPC, NCC, BC-HSP Carl Sheperis, PhD, LPC, NCC, MAC, ACS

Donna S. Sheperis, PhD, LPC, NCC, CCMHC, ACS Sue Sadik, PhD, LPC, NCC, BC-HSP Carl Sheperis, PhD, LPC, NCC, MAC, ACS Donna S. Sheperis, PhD, LPC, NCC, CCMHC, ACS Sue Sadik, PhD, LPC, NCC, BC-HSP Carl Sheperis, PhD, LPC, NCC, MAC, ACS 1 DISCLAIMER Please review your own documentation with your attorney. This information

More information

HIPAA and the HITECH Act Privacy and Security of Health Information in 2009

HIPAA and the HITECH Act Privacy and Security of Health Information in 2009 HIPAA and the HITECH Act Privacy and Security of Health Information in 2009 What is HIPAA? Health Insurance Portability & Accountability Act of 1996 Effective April 13, 2003 Federal Law HIPAA Purpose:

More information

Business Associate Agreement (BAA) Guidance

Business Associate Agreement (BAA) Guidance Business Associate Agreement (BAA) Guidance Introduction The purpose of this document is to provide guidance for creating or updating business associate agreements between your Practice ( Covered Entity

More information

HHS Finalizes HIPAA Privacy and Data Security Rules, Including Stricter Rules for Breaches of Unsecured PHI

HHS Finalizes HIPAA Privacy and Data Security Rules, Including Stricter Rules for Breaches of Unsecured PHI January 23, 2013 HHS Finalizes HIPAA Privacy and Data Security Rules, Including Stricter Rules for Breaches of Unsecured PHI Executive Summary HHS has issued final regulations that address recent legislative

More information

HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT BUSINESS ASSOCIATE TERMS AND CONDITIONS

HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT BUSINESS ASSOCIATE TERMS AND CONDITIONS COVERYS RRG, INC. HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT BUSINESS ASSOCIATE TERMS AND CONDITIONS WHEREAS, the Administrative Simplification section of the Health Insurance Portability and

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement (the "Agreement") is made and entered into this day of,, by and between Quicktate and idictate ("Business Associate") and ("Covered Entity").

More information

How To Notify Of A Security Breach In Health Care Records

How To Notify Of A Security Breach In Health Care Records CHART YOUR HIPAA COURSE... HHS ISSUES SECURITY BREACH NOTIFICATION RULES PUBLISHED IN FEDERAL REGISTER 8/24/09 EFFECTIVE 9/23/09 The Department of Health and Human Services ( HHS ) has issued interim final

More information

ACKNOWLEDGMENT OF RECEIPT OF NOTICE OF PRIVACY PRACTICES

ACKNOWLEDGMENT OF RECEIPT OF NOTICE OF PRIVACY PRACTICES ACKNOWLEDGMENT OF RECEIPT OF NOTICE OF PRIVACY PRACTICES I acknowledge that I have been provided a copy of Fiorillo Cosmetic and General Dentistry s Notice of Privacy Practices, which has an effective

More information

Disclaimer: Template Business Associate Agreement (45 C.F.R. 164.308)

Disclaimer: Template Business Associate Agreement (45 C.F.R. 164.308) HIPAA Business Associate Agreement Sample Notice Disclaimer: Template Business Associate Agreement (45 C.F.R. 164.308) The information provided in this document does not constitute, and is no substitute

More information

Tulane University. Tulane University Business Associates Agreement SCOPE OF POLICY STATEMENT OF POLICY IMPLEMENTATION OF POLICY

Tulane University. Tulane University Business Associates Agreement SCOPE OF POLICY STATEMENT OF POLICY IMPLEMENTATION OF POLICY Tulane University DEPARTMENT: General Counsel s POLICY DESCRIPTION: Business Associates Office -- HIPAA Agreement PAGE: 1 of 1 APPROVED: April 1, 2003 REVISED: November 29, 2004, December 1, 2008, October

More information

HIPAA Omnibus Rule Practice Impact. Kristen Heffernan MicroMD Director of Prod Mgt and Marketing

HIPAA Omnibus Rule Practice Impact. Kristen Heffernan MicroMD Director of Prod Mgt and Marketing HIPAA Omnibus Rule Practice Impact Kristen Heffernan MicroMD Director of Prod Mgt and Marketing 1 HIPAA Omnibus Rule Agenda History of the Rule HIPAA Stats Rule Overview Use of Personal Health Information

More information

Please Read. Apgar & Associates, LLC apgarandassoc.com P. O. Box 80278 Portland, OR 97280 503-384-2538 877-376-1981 503-384-2539 Fax

Please Read. Apgar & Associates, LLC apgarandassoc.com P. O. Box 80278 Portland, OR 97280 503-384-2538 877-376-1981 503-384-2539 Fax Please Read This business associate audit questionnaire is part of Apgar & Associates, LLC s healthcare compliance resources, Copyright 2014. This questionnaire should be viewed as a tool to aid in evaluating

More information

HIPAA Audit Risk Assessment - Risk Factors

HIPAA Audit Risk Assessment - Risk Factors I II Compliance Compliance I Compliance II SECTION ONE COVERED ENTITY RESPONSIBILITIES AREA ONE Notice of Privacy Practices 1 Is your full notice of privacy practices given to every new patient in your

More information

6/17/2013 PRESENTED BY: Updates on HIPAA, Data, IT and Security Technology. June 25, 2013

6/17/2013 PRESENTED BY: Updates on HIPAA, Data, IT and Security Technology. June 25, 2013 Updates on HIPAA, Data, IT and Security Technology June 25, 2013 1 The material appearing in this presentation is for informational purposes only and should not be construed as advice of any kind, including,

More information

Business Associate Management Methodology

Business Associate Management Methodology Methodology auxilioinc.com 844.874.0684 Table of Contents Methodology Overview 3 Use Case 1: Upstream of s I manage business associates 4 System 5 Use Case 2: Eco System of s I manage business associates

More information

Overview of the HIPAA Security Rule

Overview of the HIPAA Security Rule Office of the Secretary Office for Civil Rights () Overview of the HIPAA Security Rule Office for Civil Rights Region IX Alicia Cornish, EOS Sheila Fischer, Supervisory EOS Topics Upon completion of this

More information

What do you need to know?

What do you need to know? What do you need to know? DISCLAIMER Please note that the information provided is to inform our clients and friends of recent HIPAA and HITECH act developments. It is not intended, nor should it be used,

More information

Welcome to the Privacy and Security PowerPoint presentation in the Data Analytics Toolkit. This presentation will provide introductory information

Welcome to the Privacy and Security PowerPoint presentation in the Data Analytics Toolkit. This presentation will provide introductory information Welcome to the Privacy and Security PowerPoint presentation in the Data Analytics Toolkit. This presentation will provide introductory information about HIPAA, the HITECH-HIPAA Omnibus Privacy Act, how

More information

Health Information Privacy Refresher Training. March 2013

Health Information Privacy Refresher Training. March 2013 Health Information Privacy Refresher Training March 2013 1 Disclosure There are no significant or relevant financial relationships to disclose. 2 Topics for Today State health information privacy law Federal

More information

Health Plan Select, Inc. Business Associate Privacy Addendum To The Service Agreement

Health Plan Select, Inc. Business Associate Privacy Addendum To The Service Agreement This (hereinafter referred to as Addendum ) by and between Athens Area Health Plan Select, Inc. (hereinafter referred to as HPS ) a Covered Entity under HIPAA, and INSERT ORG NAME (hereinafter referred

More information

The Practical Guide to HIPAA Privacy and Security Compliance

The Practical Guide to HIPAA Privacy and Security Compliance The Practical Guide to HIPAA Privacy and Security Compliance By Kevin Beaver and Rebecca Herold Published by Auerbach Publications in December 2003 TABLE OF CONTENTS SECTION 1 HIPAA ESSENTIALS 1 Introduction

More information

When HHS Calls, Will Your Plan Be HIPAA Compliant?

When HHS Calls, Will Your Plan Be HIPAA Compliant? When HHS Calls, Will Your Plan Be HIPAA Compliant? Petula Workman, J.D., CEBS Division Vice President Compliance Counsel Gallagher Benefit Services, Inc., Sugar Land, Texas The opinions expressed in this

More information

Page 1. NAOP HIPAA and Privacy Risks 3/11/2014. Privacy means being able to have control over how your information is collected, used, or shared;

Page 1. NAOP HIPAA and Privacy Risks 3/11/2014. Privacy means being able to have control over how your information is collected, used, or shared; Page 1 National Organization of Alternative Programs 2014 NOAP Educational Conference HIPAA and Privacy Risks Ira J Rothman, CPHIMS, CIPP/US/IT/E/G Senior Vice President - Privacy Official March 26, 2014

More information

The Health and Benefit Trust Fund of the International Union of Operating Engineers Local Union No. 94-94A-94B, AFL-CIO. Notice of Privacy Practices

The Health and Benefit Trust Fund of the International Union of Operating Engineers Local Union No. 94-94A-94B, AFL-CIO. Notice of Privacy Practices The Health and Benefit Trust Fund of the International Union of Operating Section 1: Purpose of This Notice Notice of Privacy Practices Effective as of September 23, 2013 THIS NOTICE DESCRIBES HOW MEDICAL

More information

HIPAA in an Omnibus World. Presented by

HIPAA in an Omnibus World. Presented by HIPAA in an Omnibus World Presented by HITECH COMPLIANCE ASSOCIATES IS NOT A LAW FIRM The information given is not intended to be a substitute for legal advice or consultation. As always in legal matters

More information

Terms and Conditions Relating to Protected Health Information ( City PHI Terms ) Revised and Effective as of September 23, 2013

Terms and Conditions Relating to Protected Health Information ( City PHI Terms ) Revised and Effective as of September 23, 2013 Terms and Conditions Relating to Protected Health Information ( City PHI Terms ) Revised and Effective as of September 23, 2013 The City of Philadelphia is a Covered Entity as defined in the regulations

More information

Surviving a HIPAA violation One Agency s Experience Presented by: Roger Shindell. Topics Covered Part One. Topics Covered Part Two.

Surviving a HIPAA violation One Agency s Experience Presented by: Roger Shindell. Topics Covered Part One. Topics Covered Part Two. Surviving a HIPAA violation One Agency s Experience Presented by: Roger Shindell President & CEO Carosh Compliance Solutions & Liz Mayer, RHIA Director, Organizational Integrity HCI Care Services and VNS

More information

This form may not be modified without prior approval from the Department of Justice.

This form may not be modified without prior approval from the Department of Justice. This form may not be modified without prior approval from the Department of Justice. Delete this header in execution (signature) version of agreement. HIPAA BUSINESS ASSOCIATE AGREEMENT This Business Associate

More information

BENCHMARK MEDICAL LLC, BUSINESS ASSOCIATE AGREEMENT

BENCHMARK MEDICAL LLC, BUSINESS ASSOCIATE AGREEMENT BENCHMARK MEDICAL LLC, BUSINESS ASSOCIATE AGREEMENT This BUSINESS ASSOCIATE AGREEMENT ( Agreement ) dated as of the signature below, (the Effective Date ), is entered into by and between the signing organization

More information

The Challenges of Applying HIPAA to the Cloud. Adam Greene, Partner Davis Wright Tremaine LLP

The Challenges of Applying HIPAA to the Cloud. Adam Greene, Partner Davis Wright Tremaine LLP The Challenges of Applying HIPAA to the Cloud Adam Greene, Partner Davis Wright Tremaine LLP AGENDA Key Concepts Under HIPAA HIPAA Obligations for a BA Questions Remain Reaching Answers Resources KEY CONCEPTS

More information

BUSINESS ASSOCIATE AGREEMENT BETWEEN LEWIS & CLARK COLLEGE AND ALLEGIANCE BENEFIT PLAN MANAGEMENT, INC. I. PREAMBLE

BUSINESS ASSOCIATE AGREEMENT BETWEEN LEWIS & CLARK COLLEGE AND ALLEGIANCE BENEFIT PLAN MANAGEMENT, INC. I. PREAMBLE BUSINESS ASSOCIATE AGREEMENT BETWEEN LEWIS & CLARK COLLEGE AND ALLEGIANCE BENEFIT PLAN MANAGEMENT, INC. I. PREAMBLE Lewis & Clark College and Allegiance Benefit Plan Management, Inc., (jointly the Parties

More information

HIPAA Compliance Guide

HIPAA Compliance Guide HIPAA Compliance Guide Important Terms Covered Entities (CAs) The HIPAA Privacy Rule refers to three specific groups as covered entities, including health plans, healthcare clearinghouses, and health care

More information

HIPAA BUSINESS ASSOCIATE AGREEMENT

HIPAA BUSINESS ASSOCIATE AGREEMENT HIPAA BUSINESS ASSOCIATE AGREEMENT THIS HIPAA BUSINESS ASSOCIATE AGREEMENT ( BAA ) is entered into effective the day of, 20 ( Effective Date ), by and between the Regents of the University of Michigan,

More information

HIPAA Notice of Privacy Practices

HIPAA Notice of Privacy Practices This notice describes how medical information about you may be used and disclosed and how you can get access to this information. Please review this notice carefully. This practice is required by law to

More information

HIPAA Data Breaches: Managing Them Internally and in Response to Civil/Criminal Investigations

HIPAA Data Breaches: Managing Them Internally and in Response to Civil/Criminal Investigations HIPAA Data Breaches: Managing Them Internally and in Response to Civil/Criminal Investigations Health Care Litigation Webinar Series March 22, 2012 Spence Pryor Paula Stannard Jason Popp 1 HIPAA/HITECH

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT THIS BUSINESS ASSOCIATE AGREEMENT is made and entered into as of the day of, 2013 ( Effective Date ), by and between [Physician Practice] on behalf of itself and each of its

More information

HIPAA Compliance Guide

HIPAA Compliance Guide HIPAA Compliance Guide Important Terms Covered Entities (CAs) The HIPAA Privacy Rule refers to three specific groups as covered entities, including health plans, healthcare clearinghouses, and health care

More information

HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) TERMS AND CONDITIONS FOR BUSINESS ASSOCIATES

HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) TERMS AND CONDITIONS FOR BUSINESS ASSOCIATES HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) TERMS AND CONDITIONS FOR BUSINESS ASSOCIATES I. Overview / Definitions The Health Insurance Portability and Accountability Act is a federal law

More information

Protecting Patient Information in an Electronic Environment- New HIPAA Requirements

Protecting Patient Information in an Electronic Environment- New HIPAA Requirements Protecting Patient Information in an Electronic Environment- New HIPAA Requirements SD Dental Association Holly Arends, RHIT Clinical Program Manager Meet the Speaker TRUST OBJECTIVES Overview of HIPAA

More information

HIPAA Privacy and Security. Rochelle Steimel, HIPAA Privacy Official Judy Smith, Staff Development January 2012

HIPAA Privacy and Security. Rochelle Steimel, HIPAA Privacy Official Judy Smith, Staff Development January 2012 HIPAA Privacy and Security Rochelle Steimel, HIPAA Privacy Official Judy Smith, Staff Development January 2012 Goals and Objectives Course Goal: To introduce the staff of Munson Healthcare to the concepts

More information

HIPAA Awareness Training

HIPAA Awareness Training New York State Office of Mental Health Bureau of Education and Workforce Development HIPAA Awareness Training This training material was prepared for internal use by the New York State Office of Mental

More information

The ReHabilitation Center. 1439 Buffalo Street. Olean. NY. 14760

The ReHabilitation Center. 1439 Buffalo Street. Olean. NY. 14760 Procedure Name: HITECH Breach Notification The ReHabilitation Center 1439 Buffalo Street. Olean. NY. 14760 Purpose To amend The ReHabilitation Center s HIPAA Policy and Procedure to include mandatory breach

More information

New HIPAA Breach Notification Rule: Know Your Responsibilities. Loudoun Medical Group Spring 2010

New HIPAA Breach Notification Rule: Know Your Responsibilities. Loudoun Medical Group Spring 2010 New HIPAA Breach Notification Rule: Know Your Responsibilities Loudoun Medical Group Spring 2010 Health Information Technology for Economic and Clinical Health Act (HITECH) As part of the Recovery Act,

More information

HIPAA: Understanding The Omnibus Rule and Keeping Your Business Compliant

HIPAA: Understanding The Omnibus Rule and Keeping Your Business Compliant 1 HIPAA: Understanding The Omnibus Rule and Keeping Your Business Compliant Introduction U.S. healthcare laws intended to protect patient information (Protected Health Information or PHI) and the myriad

More information

Breach Notification Policy

Breach Notification Policy 1. Breach Notification Team. Breach Notification Policy Ferris State University ( Ferris State ), a hybrid entity with health care components, has established a Breach Notification Team, which consists

More information

HIPAA BUSINESS ASSOCIATE SUBCONTRACTOR AGREEMENT

HIPAA BUSINESS ASSOCIATE SUBCONTRACTOR AGREEMENT This HIPAA Sub Business Associate Agreement ("Sub Agreement") is entered into by and between HR Simplified, Inc. ( Business Associate ) and [Vendor Name] on behalf of itself and its Affiliates ( Subcontractor

More information