Heather L. Hughes, J.D. HIPAA Privacy Officer U.S. Legal Support, Inc. hhughes@uslegalsupport.com www.uslegalsupport.com



Similar documents
HIPAA Compliance: Are you prepared for the new regulatory changes?

Healthcare Compliance Solutions

Health Insurance Portability and Accountability Act (HIPAA) and Health Information Technology for Economic and Clinical Health Act (HITECH)

HIPAA and Mental Health Privacy:

HIPAA Security Rule Compliance

HIPAA PRIVACY AND SECURITY FOR EMPLOYERS

New HIPAA Breach Notification Rule: Know Your Responsibilities. Loudoun Medical Group Spring 2010

M E M O R A N D U M. Definitions

Health Care Information Privacy The HIPAA Regulations What Has Changed and What You Need to Know

Healthcare Compliance Solutions

HIPAA Compliance Guide

HIPAA PRIVACY AND SECURITY AWARENESS

HIPAA & HITECH AND THE DISCOVERY PROCESS

HIPAA Information Security Overview

White Paper THE HIPAA FINAL OMNIBUS RULE: NEW CHANGES IMPACTING BUSINESS ASSOCIATES

PRIVACY POLICIES AND FORMS FOR BUSINESS ASSOCIATES

VMware vcloud Air HIPAA Matrix

COMPLIANCE ALERT 10-12

This presentation focuses on the Healthcare Breach Notification Rule. First published in 2009, the final breach notification rule was finalized in

HIPAA/HITECH PRIVACY & SECURITY CHECKLIST SELF ASSESSMENT INSTRUCTIONS

HIPAA Security. Jeanne Smythe, UNC-CH Jack McCoy, ECU Chad Bebout, UNC-CH Doug Brown, UNC-CH

HHS Finalizes HIPAA Privacy and Data Security Rules, Including Stricter Rules for Breaches of Unsecured PHI

HIPAA and the HITECH Act Privacy and Security of Health Information in 2009

Policies and Procedures Audit Checklist for HIPAA Privacy, Security, and Breach Notification

BREVIUM HIPAA BUSINESS ASSOCIATE TERMS AND CONDITIONS

HIPAA/HITECH: A Guide for IT Service Providers

HIPAA Compliance and the Protection of Patient Health Information

Privacy Officer Job Description 4/28/2014. HIPAA Privacy Officer Orientation. Cathy Montgomery, RN. Presented by:

INFORMATION SECURITY & HIPAA COMPLIANCE MPCA

HIPAA Compliance The Time is Now Changes on the Horizon: The Final Regulations on Privacy and Security. May 7, 2013

HIPAA BUSINESS ASSOCIATE AGREEMENT

HIPAA Security. 5 Security Standards: Organizational, Policies. Security Topics. and Procedures and Documentation Requirements

HIPAA: In Plain English

3/13/2015 HIPAA/HITECH WHAT S YOUR COMPLIANCE STATUS? Daniel B. Mills Pretzel & Stouffer, Chartered WHAT IS HIPAA?

OCRA Spring Convention ~ 2014 Phyllis Craver Lykken, RPR, CLR, CCR Court Reporters and HIPAA

Use & Disclosure of Protected Health Information by Business Associates

Health Partners HIPAA Business Associate Agreement

Securing the FOSS VistA Stack HIPAA Baseline Discussion. Jack L. Shaffer, Jr. Chief Operations Officer

BUSINESS ASSOCIATE AGREEMENT. Business Associate. Business Associate shall mean.

HIPAA Security. 2 Security Standards: Administrative Safeguards. Security Topics

HIPAA Security Alert

What is HIPAA? The Health Insurance Portability and Accountability Act of 1996

HIPAA Security. 4 Security Standards: Technical Safeguards. Security Topics

SECURITY RISK ASSESSMENT SUMMARY

HIPAA Omnibus Rule Overview. Presented by: Crystal Stanton MicroMD Marketing Communication Specialist

NCHICA HITECH Act Breach Notification Risk Assessment Tool. Prepared by the NCHICA Privacy, Security & Legal Officials Workgroup

Appendix 4-2: Sample HIPAA Security Risk Assessment For a Small Physician Practice

Security Is Everyone s Concern:

SCHOOL DISTRICT OF BLACK RIVER FALLS HIPAA PRIVACY AND SECURITY POLICY

Datto Compliance 101 1

Overview of the HIPAA Security Rule

Data Security and Integrity of e-phi. MLCHC Annual Clinical Conference Worcester, MA Wednesday, November 12, :15pm 3:30pm

HIPAA COMPLIANCE AND DATA PROTECTION Page 1

Community First Health Plans Breach Notification for Unsecured PHI

University Healthcare Physicians Compliance and Privacy Policy

Understanding HIPAA Privacy and Security Helping Your Practice Select a HIPAA- Compliant IT Provider A White Paper by CMIT Solutions

HIPAA: Protecting Your. Ericka L. Adler. Practice and Your Patients

C.T. Hellmuth & Associates, Inc.

HIPAA Compliance Guide

Why Lawyers? Why Now?

HIPAA Security Checklist

Business Associates and Breach Reporting Under HITECH and the Omnibus Final HIPAA Rule

HIPAA 101. March 18, 2015 Webinar

Joseph Suchocki HIPAA Compliance 2015

Health Information Privacy Refresher Training. March 2013

The ReHabilitation Center Buffalo Street. Olean. NY

Huseman Health Law Group 3733 University Blvd. West, Suite 305-A Jacksonville, Florida Telephone (904) Facsimile (904)

CMA BUSINESS ASSOCIATE AGREEMENT WITH CMA MEMBERS

OCTOBER 2013 PART 1. Keeping Data in Motion: How HIPAA affects electronic transfer of protected health information

Am I a Business Associate?

Protecting Patient Information in an Electronic Environment- New HIPAA Requirements

Page 1. NAOP HIPAA and Privacy Risks 3/11/2014. Privacy means being able to have control over how your information is collected, used, or shared;

Are You Still HIPAA Compliant? Staying Protected in the Wake of the Omnibus Final Rule Click to edit Master title style.

SCHOOL DISTRICT OF BLACK RIVER FALLS HIPAA PRIVACY AND SECURITY POLICY

HIPAA Security. 1 Security 101 for Covered Entities. Security Topics

FIVE EASY STEPS FOR HANDLING NEW HIPAA REQUIREMENTS & MANAGING YOUR ELECTRONIC COMMUNICATIONS

HIPAA BUSINESS ASSOCIATE AGREEMENT

Neither You Nor Your Business Associates Can Afford to be Lax About Complying with HIPAA Requirements

12/19/2014. HIPAA More Important Than You Realize. Administrative Simplification Privacy Rule Security Rule

HIPAA Omnibus Rule Practice Impact. Kristen Heffernan MicroMD Director of Prod Mgt and Marketing

HIPAA Update Focus on Breach Prevention

CREATIVE SOLUTIONS IN HEALTHCARE, INC. Privacy Policy

Privacy and Security Meaningful Use Requirement HIPAA Readiness Review

Legislative & Regulatory Information

what your business needs to do about the new HIPAA rules

New HIPAA regulations require action. Are you in compliance?

HIPAA Audit Processes HIPAA Audit Processes. Erik Hafkey Rainer Waedlich

Regulatory Update with a Touch of HIPAA

How To Understand And Understand The Benefits Of A Health Insurance Risk Assessment

When HHS Calls, Will Your Plan Be HIPAA Compliant?

HIPAA Happenings in Hospital Systems. Donna J Brock, RHIT System HIM Audit & Privacy Coordinator

SAMPLE HIPAA/HITECH POLICIES AND PROCEDURES MANUAL FOR THE SECURITY OF ELECTRONIC PROTECTED HEALTH INFORMATION

BUSINESS ASSOCIATE AGREEMENT

The HIPAA Security Rule Primer A Guide For Mental Health Practitioners

Sample Business Associate Agreement Provisions

UNDERSTANDING THE HIPAA/HITECH BREACH NOTIFICATION RULE 2/25/14

2/9/ HIPAA Privacy and Security Audit Readiness. Table of contents

SUBJECT: SECURITY OF ELECTRONIC MEDICAL RECORDS COMPLIANCE WITH THE HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996 (HIPAA)

Business Associates, HITECH & the Omnibus HIPAA Final Rule

The Basics of HIPAA Privacy and Security and HITECH

Transcription:

Heather L. Hughes, J.D. HIPAA Privacy Officer U.S. Legal Support, Inc. hhughes@uslegalsupport.com www.uslegalsupport.com

HIPAA Privacy Rule Sets standards for confidentiality and privacy of individually identifiable health information April 14, 2003 compliance date Applies to Covered Entities Health plans Health care clearinghouses Health care providers that transmit health information electronically

Privacy Rule vs. Security Rule The Security rule applies only to PHI that is transmitted or maintained electronically. The Privacy Rule applies to PHI that is transmitted electronically, verbally, or in written form. The deadline for compliance: Privacy Rule: April 14, 2003 Security Rule: April 21, 2005

Allowed Disclosures Covered entities are permitted to disclose PHI without Authorizations for the purposes of: Treatment: management of healthcare Payment: reimbursement and benefits Healthcare Operations: medical reviews, contracts, compliance, business planning, financial, and legal activities (45 CFR 164.501)

States and HIPAA HIPAA is a federal floor for patient protections and industry standards, the states maintain the ability to enforce laws which exceed those federal boundaries. HIPAA requires the states to self-determine: Which agencies meet the federal definition of a covered entity Whether those entities are governed by state law, HIPAA, or other federal privacy laws.

Business Associates Covered Entities (health care providers, health insurance companies, etc.) hire law firms, accounting firms, shred companies, litigation support companies, and many other types of businesses whose job involves accessing PHI. Those businesses are then called Business Associates. In 2009, those Business Associates were required to adhere to stricter regulations and law firms became the Covered Entities when they represented health care entities.

New 2009 Regulations Health Information Technology for Economic and Clinical Health (HITECH) Act was passed in 2009 and affects Privacy: Covered entities and their business associates will have to notify individuals and HHS of any security breach sometimes the media will need to be notified as well.» Vendors of personal health records and other non-hipaa covered entities will have to report security breaches (Sec. 13407 of HITECH)» Determination of unsecured will be made by HHS and Federal Trade Commission for notification purposes» Encryption of electronic information and destruction of PHI will render it unusable, unreadable, or indecipherable to unauthorized individuals and will relieve the covered entity of the need to notify individuals in case of a breach

Attorneys Representing Covered Entities Attorneys are responsible for ensuring that others hired to assist in providing legal services to the covered entity will also safeguard the privacy of the PHI. Includes joint counsel, jury experts, investigators, litigation support, etc. ** not responsible for opposing counsel even if PHI was disclosed to them because they are not assisting in representing the covered entity. (45 CFR 164.504(e))

Attorneys Representing Covered Entities, cont. Business Associate Agreements are signed to provide that the attorney will ensure that the minimum necessary standard of disclosures of PHI are consistent with those of the covered entity s. Law Firms must now have all subcontractors sign Business Associate Agreements when representing Covered Entities. The law firm becomes the covered entity when drafting business associate agreements with subcontractors

HIPAA & HITECH Requirements Law Firms as well as their Subcontractors and Business Associates (when representing Covered Entities) must now comply with the Administrative, Technical and Physical Safeguards required by the Security Rule.

Administrative Safeguards Risk Analysis and Risk Management: assess potential risks to the confidentiality, integrity and availability of electronic PHI. Sanction Policy: against workforce members who fail to comply with security procedures. Security Awareness Training, Incident Response & Reporting, Workforce Clearance, Termination Procedures and Access Authorization must all be addressed. Contingency Plans, Data Backup Plan, Disaster Recovery Plans and Emergency Mode Operation Plans are required to protect electronic PHI from vandalism, natural disasters and other security incidents. (45 CFR 164.308(a))

Technical Safeguards Security standards to protect electronic PHI Electronic Access Integrity and Control: Unique user I.D. with time-outs and automatic log-off Person or entity authentication Emergency access procedures Audit controls to monitor activity on I.T. systems containing PHI Transmission security must include encryption and decryption

Physical Safeguards Facility Access Controls: Safeguard the facility and any equipment or I.T. systems with electronic PHI. Includes validation of people s access and visitor control. Workstation Use and Security: Physical safeguards for all workstations that access electronic PHI and restrict unauthorized users. Device and Media Controls: Safeguarding the receipt and removal of hardware and electronic media in and out of the facility Disposal of electronic PHI and hardware containing PHI ( cleaning ) Removal of PHI before electronic media is available for re-use (copiers, facsimile machines, etc.) Retrievable data backup and storage BEFORE movement of equipment (45 CFR 164.310)

2013 Omnibus Rule Expanded responsibilities of Business Associates Further. Business associates are required to develop comprehensive written HIPAA policies, procedures and agreements with covered entities and subcontractors specifying the provisions required by the HIPAA Privacy and Security Rules. New business associate agreements must comply with the Omnibus Rule by September 23, 2013. If a business associate agreement complied with the pre-omnibus rule, parties have 1 additional year, or until September 22, 2014, to bring their agreements into compliance.

Omnibus Rule Cont. The Omnibus Rule changed the breach standard from a "significant risk of harm" to a "probability that data was compromised" standard The criteria to assess whether a breach occurred is as follows: a) The nature and extent of PHI (including identifiers and the likelihood of re-identification of the individual) b) The identity of the unauthorized person who used the PHI or to whom disclosure was made; c) Whether PHI was actually acquired or viewed (can be determined through a forensic analysis); and d) The extent to which the risk to PHI has been mitigated.

Enforcement The Department of Health and Human Services (HHS) established rules for investigating, prosecuting, and imposing penalties for HIPAA Privacy Rule violations. NEW RULE: (as of December 29, 2009) Tiered ranges of increasing minimum penalty amounts, with a maximum penalty of $1.5 million for all violations of an identical provision Criminal violations fined up to $250,000 and up to ten years in prison (enforced by the Department of Justice) HHS hired auditing firms to randomly audit covered entities and business associates for compliance and will be conducting more audits in 2013 and 2014 with the new Omnibus Rule

Important HITECH Information State attorneys general now can bring civil actions and recover attorneys fees from covered entities. Business associates now can be fined by the government the same way covered entities can. Physical, Technical and Administrative Safeguards are now required and involve all aspects of law practices including: law firms software systems (data backup, encryption, firewalls, passwords, etc.), PDAs, office access and security, employee training, storage and destruction of PHI, etc..

Additional HIPAA and HITECH Information Office of Civil Rights HIPAA website: http://www.hhs.gov/ocr/privacy/ Health and Human Services HITECH website: http://healthit.hhs.gov/portal/server.pt U.S. Legal Support HIPAA page: http://www.uslegalsupport.com/recordretrieval/hipaa/