Texas Medical Records Privacy Act (a.k.a. Texas House Bill 300)
|
|
|
- Tyler Simmons
- 10 years ago
- Views:
Transcription
1 Texas Medical Records Privacy Act (a.k.a. Texas House Bill 300) Ricky Link, Coalfire ISACA North Texas and IIA Fort Worth Chapters The Petroleum Club of Fort Worth March 4,
2 About Coalfire Coalfire offers demonstrated leadership in all key areas in information security, compliance and risk management services for all industries and verticals. 2
3 Agenda What IS the Texas House Bill 300? What are the differences between the Texas Medical Records Privacy Act and HIPAA? What are the new compliance requirements? What's the current enforcement environment that might affect my organization? What are the fines and the penalties for noncompliance? How can I defend or avoid a data breach and protect PHI? Q&A Disclaimer Presentation Not intended To Be An Exhaustive Explanation of HB
4 Key Learning Objectives How to know if their organization is required to comply with the new law? What are the requirements for compliance and what do to do in case of a data breach? What are the fines and the penalties for noncompliance? What's the current enforcement environment that might affect their organization? How to defend or avoid a data breach and protect PHI? 4
5 Background of Texas Medical Records Privacy Act House Bill 300 5
6 Where to Find the Texas Statute 6
7 Healthcare Regulation Evolution HIPAA Act 1996 Signed by Bill Clinton; i.e., Kennedy-Kassbaum Act HIPAA Privacy Rule 2003 Privacy protections for health information HIPAA Security Rule 2005 Safeguards for electronic health information HITECH Act 2010 Security breach notification Enhanced enforcement New requirements for business associates Texas House Bill New and additional mandates New fines and penalties HIPAA Omnibus Rule Released Jan 2013 (Effective Sept 23 ) HIPAA Privacy, Security & Enforcement rules 7
8 What IS Texas House Bill 300? Objective: Enhance protections for protected health information (PHI) Expands training requirements Imposes new restrictions on electronic disclosures of PHI Enhances access rights Expands security breach notification requirements Increases penalties and enforcement 8
9 Additional Changes Under Texas House Bill 300 The Act broadens the scope of Covered Entities (i.e., called Texas CEs) (Section (2)): It applies not only to health care providers, health plans and other entities that process health insurance claims. Also applies to any individual, business, or organization that obtains, assembles, collects, analyzes, evaluates, stores, or transmits PHI as well as their agents, employees and contractors. 9
10 Additional Changes Under Texas House Bill 300 Grants enforcement authority to relevant state agencies Texas Attorney General Office Texas Health and Human Services Commission Creates a consumer website to communicate patient s privacy rights regarding PHI under federal and state (Section ) A list of state agencies that regulate covered entities and the agency s complaint enforcement process (Section ) Patient requests for Electronic Health Records must fulfill in 15 days (Section ) 10
11 Compliance Challenges of Texas House Bill 300 Poorly drafted Substantial ambiguity surrounding scope of coverage Substantial ambiguity surrounding certain requirements Texas Office of Attorney General has been inundated with calls Informal guidance or regulations might provide additional clarity; however, none provided to date 11
12 Discussion Points What emphasis or differences between HB 300 compared to HIPAA? 12
13 Which Providers are covered by HIPAA? Healthcare providers that: Provide care for an individual in the normal course of business; and Engage in standard electronic transactions Excludes: Providers who do not bill electronically using HIPAA transaction codes In-house providers i.e., medical professional on-site 13
14 What Health Plans are covered by HIPAA? Health Insurers and Health Maintenance Organizations (HMOs) Employer-sponsored health plans Group health, vision and dental plans Pharmacy benefit plans Healthcare reimbursement flexible spending accounts Employee assistance programs Long-term care plans 14
15 Who is a Business Associate under HIPAA? Business Associates Those who use PHI to perform, or assist in performing, covered functions for a covered entity. Or who are engaged with processing, storing, or transmission of ephi The HITECH Act 2010 extended to business associates HIPAA Security Rule requirements and many HIPAA Privacy Rule requirements. 15
16 Who is Covered Under the HB 300? Definition #1 Any for-profit or non-profit entity that collects, uses, stores, or transmits protected health information, including: 1. Healthcare facility, clinic, healthcare provider HIPAA-covered and non-covered providers 2. Healthcare Payer But only some HIPAA-covered health plans 3. Business Associates 4. Information or computer management entity 5. Person who maintains an Internet site 6. Schools 16
17 Who is Covered Under the HB 300? Definition #2 Any person who comes into possession of PHI 1. Sub-contractors to Business Associates 2. Lawyers not acting as business associates 3. Employers as they may come into possession of PHI (?) 4. Conduits of PHI ISPs and other telecom providers (?) 5. Someone who finds a CD with PHI on the street (?) Texas OAG has informally stated that the Texas House Bill 300 does not apply to individuals 17
18 Entities Excluded from the HB 300 Partial Exemption NOTE: Not exempted from electronic disclosure, marketing, or sale of PHI rules (Section (4)) Employers Insurance companies, insurance agents and HMOs 18
19 Entities Excluded from the HB 300 Employee benefit plans and any person... acting in connection with an employee benefit plan, i.e., business associates to a plan Workers compensation Educational records covered by FERPA The American Red Cross Non-profits that pay for healthcare for the indigent and are exempted by regulation by the AG 19
20 Summary: Who Is Covered? Fully Covered 1. All health care providers 2. Business associates to providers and their subcontractors 3. Lawyers and other service providers who are not business associates but do come into possession of PHI 4. Schools with respect to treatment records Partially Covered 1. Employers 2. Insurance companies, insurance agents and HMOs 20
21 Interplay of Texas HB 300 and HIPAA HIPAA-covered entities must comply with both HIPAA and Texas House Bill 300. If there is a conflict between HIPAA and Texas House Bill 300, a HIPAA-covered entity must comply with the more stringent standard. Texas House Bill 300 likely will be more stringent than HIPAA 21
22 Texas House Bill 300 s New Compliance Requirements 22
23 New Training Requirements 1. Section Training must be tailored to (a) the covered entity s particular business, and (b) each employee s business activities 2. Training must be completed within days of hire date (Changed on 6/14/13) 3. Training must be repeated at least bi-annually 4. Employer must obtain and retain a signed statement by each employee verifying attendance No retention period established in Texas House Bill
24 New Training Requirements Comparison to HIPAA: HIPAA (a) does not mandate tailored training, (b) requires training only within a reasonable time, (c) does not require retraining unless there is material change, and (d) does not require a signed verification Implications: 1. Existing training policies must be updated 2. Existing training materials must be updated 24
25 Electronic Disclosures of PHI 2 New Requirements 1. If a covered entity engages in electronic disclosures of PHI for any reason, it must post a written notice at its place of business or on its website (Section ). However, there are challenges with these new requirements 25
26 Electronic Disclosures of PHI 2 New Requirements 2. Before each individual electronic disclosure, covered entities must obtain the individual s authorization on a form created by the Texas AG (Section ) Authorization is not required for disclosures (i) to another covered entity for treatment, (ii) for payment or health care operations, or (ii) when required by law However, there are challenges with these new requirements 26
27 Electronic Disclosures of PHI Implications (Section ) 1. Review your organization s disclosures of PHI by electronic means, e.g., , using a CD or flash drive, through a portal 2. Determine which disclosures are not for Treatment, Payment and Healthcare Operations (TPO) or required by law 3. Identify one or more point persons to control the flow of non-exempt electronic disclosures 4. Train designated point persons on Texas House Bill 300 s electronic disclosure requirements 27
28 Expanded Access Rights Healthcare providers that maintain electronic health records must respond to a request for access within 15 business days of receipt of a written request unless HIPAA does not require access HIPAA standard is 30 calendar days HIPAA permits extensions, but no extensions under Texas H.B. 300 Implications: Ensure that employees and business associates are aware of the shorter response period 28
29 Sales And Marketing Rules (Section ) 1. Sales: No disclosures of PHI for direct or indirect remuneration except as necessary for treatment, payment or healthcare operations 2. Marketing: Covered entity can use PHI for marketing only with individual s prior written authorization 3. Marketing Mailings: If PHI is contained in a marketing mailing, the envelope must show only the individual s contact information, and the mailing must (a) state the name and toll-free number of the entity sending the marketing communication; and (b) explain the recipient's right to have the recipient's name removed from the sender's mailing list. Recipient must be removed from mailing list within 45 days of a request 29
30 Enhanced Enforcement 30
31 Increased Civil Penalties Under Texas House Bill 300 Potential maximum civil penalties for breach > 500 patients (Section ): Negligent violations: $5K/violation/calendar year Intentional violations: $25K/violation/calendar year Intentional for financial gain: $250K/violation Pattern or practice: (a) capped at $1.5M (previously was $250K), (b) revocation of license, and (c) compliance audit Electronic disclosure violations: Capped at $250K in limited circumstances Texas AG may keep a reasonable portion of the penalty 31
32 Enhanced Enforcement Mechanisms Texas Attorney General must maintain a website which, among other things, contains contact information for each government agency that regulates covered entities and a description of the agency s complaint enforcement process Texas agencies can ask HHS to audit a covered entity s compliance (Section ) 32
33 HHS Enforcement HHS has moved from a philosophy that emphasized voluntary compliance to audits and muscular enforcement OCR Pilot audits of 150 covered entities in 2012 (KPMG) Audit program becomes permanent in 2013 $1.5M settlement with Mass Eye & Ear after theft of laptop containing unencrypted PHI of 3,621 patients $1.5M settlement with BCBS of TN over the loss of 57 hard drives containing 1M patient records $1M settlement with Mass General after employee left 192 patients records on subway 33
34 Civil Penalty Enhancement Under HIPAA Minimum penalties if violation is not corrected within 30 days of notice of the violation Unknowing Violations: $100 per violation and $25,000 annually Negligent Violations: $1,000 per violation and $100,000 annually Willful Neglect: Conscious intentional failure or reckless indifference to the obligation to comply $10,000 per violation and $250,000 annually (if corrected within 30 days) $50,000 per violation and $1.5M (if not corrected) 34
35 Expect More Civil Enforcement State attorneys general can sue in federal district court to recover damages to state residents caused by a HIPAA violation TX AG has obtained settlements from numerous entities for alleged improper destruction of PHI and other sensitive personal information. 07/11/12: Indiana AG announces that WellPoint agreed to pay $100k to settle charges that the company had unreasonably delayed security breach notification. 07/10/12: CT AG announces settlement with HealthNet over its loss of a computer disk drive containing the PHI of 1.5M individuals nationwide. HealthNet to (a) implement Corrective Action Plan, (b) pay $250K fine, and (c) make additional $500K payment if it is determined that PHI on lost disk was misused. 35
36 How can I defend or avoid a data breach and protect PHI? 36
37 Audits and Risk Assessments The state will direct federal audits to be conducted by the Department of Health and Human Services. If the state identifies evidence of violation, the covered entity may be required to submit a written risk analysis to determine if the violation qualifies for enforcement action. As with any compliance requirement, covered entities should maintain a current risk assessment that demonstrates the level of protection provided to patient data. This may prove that any failure to protect patient data would have been an exception to policy and not a pattern of neglect. Evidence of Good Faith efforts to comply with HB 300 is recommended 37
38 Data Breach Notification Data breach notification is already a part of Texas code. Texas House Bill 300 specifically requires covered entities to provide notice of breach that meets specific unauthorized disclosure thresholds. An entity must disclose any breach of system security, after discovering or receiving notification of the breach, to any individual whose sensitive personal information was, or is reasonably believed to have been, acquired by an unauthorized individual. The disclosure must be made as quickly as possible or as necessary to determine the scope of the breach and restore the reasonable integrity of the system. Penalty: $100/individual/day that notice is not sent, capped at $250K 38
39 Five Simple Steps to Compliance 1. Establish a risk management program to support protection of sensitive patient data. 2. Document policies and controls regarding patient access to their EHRs to mitigate risks. 3. Train users to implement the controls and privacy program. 4. Deploy a breach notification and incident response plan. 5. Conduct a periodic assessment of the controls and risk management program to demonstrate effective oversight (i.e. avoid claims of a pattern of neglect). 39
40 Tools and Resources 1. Health IT Resources Consolidated from Best Practices; downloadable tools: 2. Regional Extension Centers: 3. Texas HIT Connection: 40
41 Questions Ricky Link, Coalfire Systems Managing Director, Southwest Region ext Visit the Coalfire blog: 41
Texas House Bill 300 & HIPAA. A MainNerve Whitepaper
A MainNerve Whitepaper Overview If you do business in Texas and your organization handles, creates, stores, transmits or has access to electronic patient healthcare information, you need to be mindful
Trust 9/10/2015. Why Does Privacy and Security Matter? Who Must Comply with HIPAA Rules? HIPAA Breaches, Security Risk Analysis, and Audits
HIPAA Breaches, Security Risk Analysis, and Audits Derrick Hill Senior Health IT Advisor Kentucky REC Why Does Privacy and Security Matter? Trust Who Must Comply with HIPAA Rules? Covered Entities (CE)
Philip L. Gordon, Esq. Littler Mendelson, P.C.
Beyond The Legal Requirements: Key Practical Issues in Negotiating Business Associate Agreements, Responding to a Breach of Unsecured PHI, and Understanding HHS Enforcement Philip L. Gordon, Esq. Littler
Are You Still HIPAA Compliant? Staying Protected in the Wake of the Omnibus Final Rule Click to edit Master title style.
Are You Still HIPAA Compliant? Staying Protected in the Wake of the Omnibus Final Rule Click to edit Master title style March 27, 2013 www.mcguirewoods.com Introductions Holly Carnell McGuireWoods LLP
University Healthcare Physicians Compliance and Privacy Policy
Page 1 of 11 POLICY University Healthcare Physicians (UHP) will enter into business associate agreements in compliance with the provisions of the Health Insurance Portability and Accountability Act of
Updated HIPAA Regulations What Optometrists Need to Know Now. HIPAA Overview
Updated HIPAA Regulations What Optometrists Need to Know Now The U.S. Department of Health & Human Services Office for Civil Rights recently released updated regulations regarding the Health Insurance
REGULATORY CHANGES DEMAND AN ENTERPRISE-WIDE APPROACH TO DISCLOSURE MANAGEMENT OF PHI
REGULATORY CHANGES DEMAND AN ENTERPRISE-WIDE APPROACH TO DISCLOSURE MANAGEMENT OF PHI Healthcare Organizations Can Adopt Enterprise-Wide Disclosure Management Systems To Standardize Disclosure Processes,
HIPAA, HIPAA Hi-TECH and HIPAA Omnibus Rule
HIPAA, HIPAA Hi-TECH and HIPAA Omnibus Rule NYCR-245157 HIPPA, HIPAA HiTECH& the Omnibus Rule A. HIPAA IIHI and PHI Privacy & Security Rule Covered Entities and Business Associates B. HIPAA Hi-TECH Why
The HITECH Act: Implications to HIPAA Covered Entities and Business Associates. Linn F. Freedman, Esq.
The HITECH Act: Implications to HIPAA Covered Entities and Business Associates Linn F. Freedman, Esq. Introduction and Overview On February 17, 2009, President Obama signed P.L. 111-05, the American Recovery
BUSINESS ASSOCIATE AGREEMENT
BUSINESS ASSOCIATE AGREEMENT The parties to this ( Agreement ) are, a _New York_ corporation ( Business Associate ) and ( Client ) you, as a user of our on-line health record system (the "System"). BY
Health Information Privacy Refresher Training. March 2013
Health Information Privacy Refresher Training March 2013 1 Disclosure There are no significant or relevant financial relationships to disclose. 2 Topics for Today State health information privacy law Federal
HIPAA and the HITECH Act Privacy and Security of Health Information in 2009
HIPAA and the HITECH Act Privacy and Security of Health Information in 2009 What is HIPAA? Health Insurance Portability & Accountability Act of 1996 Effective April 13, 2003 Federal Law HIPAA Purpose:
BUSINESS ASSOCIATE AGREEMENT
BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement ( the Agreement ) is entered into this day of, 20 by and between the Tennessee Chapter of the American Academy of Pediatrics ( Business Associate
HHS Issues New HITECH/HIPAA Rule: Implications for Hospice Providers
Compliance Tip Sheet National Hospice and Palliative Care Organization www.nhpco.org/regulatory HHS Issues New HITECH/HIPAA Rule: Implications for Hospice Providers Hospice Provider Compliance To Do List
OCR Reports on the Enforcement. Learning Objectives 4/1/2013. HIPAA Compliance/Enforcement (As of December 31, 2012) HCCA Compliance Institute
OCR Reports on the Enforcement of the HIPAA Rules HCCA Compliance Institute April 22, 2013 David Holtzman Sr. Health IT & Privacy Specialist U.S. Department of Health and Human Services Office for Civil
OCR Reports on the Enforcement. Learning Objectives
OCR Reports on the Enforcement of the HIPAA Rules HCCA Compliance Institute April 22, 2013 David Holtzman Sr. Health IT & Privacy Specialist U.S. Department of Health and Human Services Office for Civil
HIPAA/HITECH and Texas Privacy Laws Comparison Tool Updated 2013
HIPAA/HITECH and Texas Privacy Laws Comparison Tool Updated 2013 Federal and Texas Privacy & Security Requirements Minimizing Your Risk of Violations DISCLAIMER The information contained in this document
By Ross C. D Emanuele, John T. Soshnik, and Kari Bomash, Dorsey & Whitney LLP Minneapolis, MN
Major Changes to HIPAA Security and Privacy Rules Enacted in Economic Stimulus Package By Ross C. D Emanuele, John T. Soshnik, and Kari Bomash, Dorsey & Whitney LLP Minneapolis, MN The HITECH Act is the
New HIPAA regulations require action. Are you in compliance?
New HIPAA regulations require action. Are you in compliance? Mary Harrison, JD Tami Simon, JD May 22, 2013 Discussion topics Introduction Remembering the HIPAA Basics HIPAA Privacy Rules HIPAA Security
COMPLIANCE ALERT 10-12
HAWAII HEALTH SYSTEMS C O R P O R A T I O N "Touching Lives Every Day COMPLIANCE ALERT 10-12 HIPAA Expansion under the American Recovery and Reinvestment Act of 2009 The American Recovery and Reinvestment
HIPAA Omnibus Compliance How A Data Loss Prevention Solution Can Help
HIPAA Omnibus Compliance How A Data Loss Prevention Solution Can Help The Health Information Portability and Accountability Act (HIPAA) Omnibus Rule which will begin to be enforced September 23, 2013,
HIPAA: Breach Notification By: Office of University Counsel For: Jefferson IRB Continuing Education. September 2014
HIPAA: Breach Notification By: Office of University Counsel For: Jefferson IRB Continuing Education September 2014 Introduction The HIPAA Privacy Rule establishes the conditions under which Covered Entities
HIPAA Hot Topics. Audits, the Latest on Enforcement and the Impact of Breaches. September 2012. Nashville Knoxville Memphis Washington, D.C.
HIPAA Hot Topics Audits, the Latest on Enforcement and the Impact of Breaches September 2012 Nashville Knoxville Memphis Washington, D.C. Overview HITECH Act HIPAA Audit Program: update and initial results
HIPAA Compliance and the Protection of Patient Health Information
HIPAA Compliance and the Protection of Patient Health Information WHITE PAPER By Swift Systems Inc. April 2015 Swift Systems Inc. 7340 Executive Way, Ste M Frederick MD 21704 1 Contents HIPAA Compliance
Heather L. Hughes, J.D. HIPAA Privacy Officer U.S. Legal Support, Inc. [email protected] www.uslegalsupport.com
Heather L. Hughes, J.D. HIPAA Privacy Officer U.S. Legal Support, Inc. [email protected] www.uslegalsupport.com HIPAA Privacy Rule Sets standards for confidentiality and privacy of individually
Health Care Information Privacy The HIPAA Regulations What Has Changed and What You Need to Know
Health Care Information Privacy The HIPAA Regulations What Has Changed and What You Need to Know Note: Information provided to NCRA by Melodi Gates, Associate with Patton Boggs, LLC Privacy and data protection
HIPAA BUSINESS ASSOCIATE AGREEMENT
HIPAA BUSINESS ASSOCIATE AGREEMENT THIS HIPAA BUSINESS ASSOCIATE AGREEMENT ( BAA ) is entered into effective the day of, 20 ( Effective Date ), by and between the Regents of the University of Michigan,
HIPAA WEBINAR HANDOUT
HIPAA WEBINAR HANDOUT OCR Enforcement Tools Voluntary corrective action Resolution Agreement and Payment CMPs Referral to DOJ for criminal investigation Resolution Agreements Contract signed by HHS and
The Institute of Professional Practice, Inc. Business Associate Agreement
The Institute of Professional Practice, Inc. Business Associate Agreement This Business Associate Agreement ( Agreement ) effective on (the Effective Date ) is entered into by and between The Institute
BUSINESS ASSOCIATE AGREEMENT
BUSINESS ASSOCIATE AGREEMENT THIS BUSINESS ASSOCIATE AGREEMENT is made and entered into as of the day of, 2013 ( Effective Date ), by and between [Physician Practice] on behalf of itself and each of its
What do you need to know?
What do you need to know? DISCLAIMER Please note that the information provided is to inform our clients and friends of recent HIPAA and HITECH act developments. It is not intended, nor should it be used,
SECURETexas Health Information Privacy & Security Certification Program FAQs
What is the relationship between the Texas Health Services Authority (THSA) and the Health Information Trust Alliance (HITRUST)? The THSA and HITRUST have partnered to help improve the protection of healthcare
Overview of the HIPAA Security Rule
Office of the Secretary Office for Civil Rights () Overview of the HIPAA Security Rule Office for Civil Rights Region IX Alicia Cornish, EOS Sheila Fischer, Supervisory EOS Topics Upon completion of this
12/19/2014. HIPAA More Important Than You Realize. Administrative Simplification Privacy Rule Security Rule
HIPAA More Important Than You Realize J. Ira Bedenbaugh Consulting Shareholder February 20, 2015 This material was used by Elliott Davis Decosimo during an oral presentation; it is not a complete record
Data Breach, Electronic Health Records and Healthcare Reform
Data Breach, Electronic Health Records and Healthcare Reform (This presentation is for informational purposes only and it is not intended, and should not be relied upon, as legal advice.) Overview of HIPAA
HIPAA Security Rule Compliance
HIPAA Security Rule Compliance Caryn Reiker MAXIS360 HIPAA Security Rule Compliance what is it and why you should be concerned about it Table of Contents About HIPAA... 2 Who Must Comply... 2 The HIPAA
HIPAA Omnibus & HITECH Rules: Key Provisions and a Simple Checklist. www.riskwatch.com
HIPAA Omnibus & HITECH Rules: Key Provisions and a Simple Checklist www.riskwatch.com Introduction Last year, the federal government published its long awaited final regulations implementing the Health
BUSINESS ASSOCIATE PRIVACY AND SECURITY ADDENDUM RECITALS
BUSINESS ASSOCIATE PRIVACY AND SECURITY ADDENDUM This Business Associate Addendum ( Addendum ), effective, 20 ( Effective Date ), is entered into by and between University of Southern California, ( University
HIPAA and HITECH Compliance for Cloud Applications
What Is HIPAA? The healthcare industry is rapidly moving towards increasing use of electronic information systems - including public and private cloud services - to provide electronic protected health
Understanding HIPAA Privacy and Security Helping Your Practice Select a HIPAA- Compliant IT Provider A White Paper by CMIT Solutions
Understanding HIPAA Privacy and Security Helping Your Practice Select a HIPAA- Compliant IT Provider A White Paper by CMIT Solutions Table of Contents Understanding HIPAA Privacy and Security... 1 What
HIPAA Compliance, Notification & Enforcement After The HITECH Act. Presenter: Radha Chanderraj, Esq.
HIPAA Compliance, Notification & Enforcement After The HITECH Act Presenter: Radha Chanderraj, Esq. Key Dates Publication date January 25, 2013 Effective date - March 26, 2013 Compliance date - September
HIPAA Omnibus Rule Practice Impact. Kristen Heffernan MicroMD Director of Prod Mgt and Marketing
HIPAA Omnibus Rule Practice Impact Kristen Heffernan MicroMD Director of Prod Mgt and Marketing 1 HIPAA Omnibus Rule Agenda History of the Rule HIPAA Stats Rule Overview Use of Personal Health Information
Disclaimer: Template Business Associate Agreement (45 C.F.R. 164.308)
HIPAA Business Associate Agreement Sample Notice Disclaimer: Template Business Associate Agreement (45 C.F.R. 164.308) The information provided in this document does not constitute, and is no substitute
HIPAA Audits: How to Be Prepared. Lindsey Wiley, MHA, CHTS-IM, CHTS-TS HIT Manager Oklahoma Foundation for Medical Quality
HIPAA Audits: How to Be Prepared Lindsey Wiley, MHA, CHTS-IM, CHTS-TS HIT Manager Oklahoma Foundation for Medical Quality An Important Reminder For audio, you must use your phone: Step 1: Call (866) 906-0123.
BUSINESS ASSOCIATE AGREEMENT
BUSINESS ASSOCIATE AGREEMENT THIS BUSINESS ASSOCIATE AGREEMENT (the AGREEMENT ) is entered into this (the "Effective Date"), between Delta Dental of Tennessee ( Covered Entity ) and ( Business Associate
FirstCarolinaCare Insurance Company Business Associate Agreement
FirstCarolinaCare Insurance Company Business Associate Agreement THIS BUSINESS ASSOCIATE AGREEMENT ("Agreement"), is made and entered into as of, 20 (the "Effective Date") between FirstCarolinaCare Insurance
How To Understand And Understand The Benefits Of A Health Insurance Risk Assessment
4547 The Case For HIPAA Risk Assessment Leader s Guide IMPORTANT INFORMATION FOR EDUCATION COORDINATORS & PROGRAM FACILITATORS PLEASE NOTE: In order for this program to meet Florida course requirements,
Lessons Learned from HIPAA Audits
Lessons Learned from HIPAA Audits October 29, 2012 Tony Brooks, CISA, CRISC Partner - IT Assurance and Risk Services HORNE LLP AGENDA HIPAA/HITECH Regulations Breaches and Fines OCR HIPAA/HITECH Compliance
HIPAA Enforcement. Emily Prehm, J.D. Office for Civil Rights U.S. Department of Health and Human Services. December 18, 2013
Office of the Secretary Office for Civil Rights () HIPAA Enforcement Emily Prehm, J.D. Office for Civil Rights U.S. Department of Health and Human Services December 18, 2013 Presentation Overview s investigative
BUSINESS ASSOCIATE AGREEMENT ( BAA )
BUSINESS ASSOCIATE AGREEMENT ( BAA ) Pursuant to the terms and conditions specified in Exhibit B of the Agreement (as defined in Section 1.1 below) between EMC (as defined in the Agreement) and Subcontractor
HIPAA. New Breach Notification Risk Assessment and Sanctions Policy. Incident Management Policy. Focus on: For breaches affecting 1 3 individuals
HIPAA New Breach Notification Risk Assessment and Sanctions Policy Incident Management Policy For breaches affecting 1 3 individuals +25 individuals + 500 individuals Focus on: analysis documentation PHI
BUSINESS ASSOCIATE AGREEMENT
BUSINESS ASSOCIATE AGREEMENT Please complete the following and return signed via Fax: 919-785-1205 via Mail: Aesthetic & Reconstructive Plastic Surgery, PLLC 2304 Wesvill Court Suite 360 Raleigh, NC 27607
Business Associate Agreement
This Business Associate Agreement Is Related To and a Part of the Following Underlying Agreement: Effective Date of Underlying Agreement: Vendor: Business Associate Agreement This Business Associate Agreement
Welcome to the Privacy and Security PowerPoint presentation in the Data Analytics Toolkit. This presentation will provide introductory information
Welcome to the Privacy and Security PowerPoint presentation in the Data Analytics Toolkit. This presentation will provide introductory information about HIPAA, the HITECH-HIPAA Omnibus Privacy Act, how
Terms and Conditions Relating to Protected Health Information ( City PHI Terms ) Revised and Effective as of September 23, 2013
Terms and Conditions Relating to Protected Health Information ( City PHI Terms ) Revised and Effective as of September 23, 2013 The City of Philadelphia is a Covered Entity as defined in the regulations
Arizona Physicians Group To Pay $100,000 To Settle HIPAA Charges
Cynthia Marcotte Stamer Board Certified Labor and Employment Law Texas Board of Legal Specialization Primary Telephone: (214) 452-8297 24-Hour Telephone (469) 767.8872 Addison Telephone (972) 588.1860
The HIPAA Audit Program
The HIPAA Audit Program Anna C. Watterson Davis Wright Tremaine LLP The U.S. Department of Health and Human Services (HHS) was given authority, and a mandate, to conduct periodic audits of HIPAA 1 compliance
FORM OF HIPAA BUSINESS ASSOCIATE AGREEMENT
FORM OF HIPAA BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement ( Agreement ) is made and entered into to be effective as of, 20 (the Effective Date ), by and between ( Covered Entity ) and
New Privacy Laws Impacting the Health Care Work Place
New Privacy Laws Impacting the Health Care Work Place Presented by Thomas E. Jeffry, Jr., Esq. Arent Fox LLP Washington, DC New York, NY Los Angeles, CA November 12 & 19, 2009 Overview 1. Overview of California
HIPAA and HITECH Compliance Under the New HIPAA Final Rule. HIPAA Final Omnibus Rule ( Final Rule )
HIPAA and HITECH Compliance Under the New HIPAA Final Rule Presented Presented by: by: Barry S. Herrin, Attorney CHPS, Name FACHE Smith Smith Moore Moore Leatherwood Leatherwood LLP LLP Atlanta Address
Business Associate Agreement
Business Associate Agreement This Business Associate Agreement (this Agreement ) is entered into as of _September 23_, 2013, (the Effective Date ) by and between Denise T. Nguyen, DDS, PC ( Dental Practice
what your business needs to do about the new HIPAA rules
what your business needs to do about the new HIPAA rules Whether you are an employer that provides health insurance for your employees, a business in the growing health care industry, or a hospital or
HIPAA Omnibus Rule Overview. Presented by: Crystal Stanton MicroMD Marketing Communication Specialist
HIPAA Omnibus Rule Overview Presented by: Crystal Stanton MicroMD Marketing Communication Specialist 1 HIPAA Omnibus Rule - Agenda History of the Omnibus Rule What is the HIPAA Omnibus Rule and its various
BUSINESS ASSOCIATE AGREEMENT
Note: This form is not meant to encompass all the various ways in which any particular facility may use health information and should be specifically tailored to your organization. In addition, as with
SAMPLE BUSINESS ASSOCIATE AGREEMENT
SAMPLE BUSINESS ASSOCIATE AGREEMENT This is a draft business associate agreement based on the template provided by HHS. It is not intended to be used as is and you should only use the agreement after you
Presented by Jack Kolk President ACR 2 Solutions, Inc.
HIPAA 102 : What you don t know about the new changes in the law can hurt you! Presented by Jack Kolk President ACR 2 Solutions, Inc. Todays Agenda: 1) Jack Kolk, CEO of ACR 2 Solutions a information security
Vendor Management Challenges and Solutions for HIPAA Compliance. Jim Sandford Vice President, Coalfire
Vendor Management Challenges and Solutions for HIPAA Compliance Jim Sandford Vice President, Coalfire Housekeeping You may submit questions throughout the webinar using the question area in the control
Long-Expected Omnibus HIPAA Rule Implements Significant Privacy and Security Regulations for Entities and Business Associates
Legal Update February 11, 2013 Long-Expected Omnibus HIPAA Rule Implements Significant Privacy and Security Regulations for Entities and Business Associates On January 17, 2013, the Department of Health
BUSINESS ASSOCIATE CONTRACTUAL ADDENDUM
BUSINESS ASSOCIATE CONTRACTUAL ADDENDUM This HIPAA Addendum ("Addendum") is entered into effective this first day of November 1, 2015, by and between "Business Associate" AND COUNTY OF OTTAWA Ottawa County
STATE OF NEVADA DEPARTMENT OF HEALTH AND HUMAN SERVICES BUSINESS ASSOCIATE ADDENDUM
STATE OF NEVADA DEPARTMENT OF HEALTH AND HUMAN SERVICES BUSINESS ASSOCIATE ADDENDUM BETWEEN The Division of Health Care Financing and Policy Herein after referred to as the Covered Entity and (Enter Business
Disclaimer 8/8/2014. Current Developments in Privacy and Security Rule Enforcement
Office of the Secretary Office for Civil Rights () Current Developments in Privacy and Security Rule Enforcement Michigan Medical Billers Association Andrew C. Kruley, J.D. Equal Opportunity Specialist
ACCOUNTABLE HEALTHCARE IPA HIPAA PRIVACY AND SECURITY TRAINING. By: Jerry Jackson Compliance and Privacy Officer
ACCOUNTABLE HEALTHCARE IPA HIPAA PRIVACY AND SECURITY TRAINING By: Jerry Jackson Compliance and Privacy Officer 1 1 Introduction Welcome to Privacy and Security Training course. This course will help you
REPRODUCTIVE ASSOCIATES OF DELAWARE (RAD) NOTICE OF PRIVACY PRACTICES PLEASE REVIEW IT CAREFULLY.
REPRODUCTIVE ASSOCIATES OF DELAWARE (RAD) NOTICE OF PRIVACY PRACTICES THIS NOTICE DESCRIBES HOW PROTECTED HEALTH INFORMATION (PHI) ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS
Am I a Business Associate? Do I want to be a Business Associate? What are my obligations?
Am I a Business Associate? Do I want to be a Business Associate? What are my obligations? Brought to you by Winston & Strawn s Health Care Practice Group 2013 Winston & Strawn LLP Today s elunch Presenters
The Basics of HIPAA Privacy and Security and HITECH
The Basics of HIPAA Privacy and Security and HITECH Protecting Patient Privacy Disclaimer The content of this webinar is to introduce the principles associated with HIPAA and HITECH regulations and is
