HIPAA Happenings in Hospital Systems. Donna J Brock, RHIT System HIM Audit & Privacy Coordinator



Similar documents
Patient Privacy and HIPAA/HITECH

HIPAA Privacy Keys to Success Updated January 2010

HIPAA The Law Explained. Click here to view the HIPAA information.

HIPAA Security Rule Compliance

Health Insurance Portability and Accountability Act of 1996 (HIPAA) Contents

Understanding HIPAA Privacy and Security Helping Your Practice Select a HIPAA- Compliant IT Provider A White Paper by CMIT Solutions

Health Information Privacy Refresher Training. March 2013

Heather L. Hughes, J.D. HIPAA Privacy Officer U.S. Legal Support, Inc.

The Basics of HIPAA Privacy and Security and HITECH

HIPAA and Privacy Policy Training

HIPAA PRIVACY AND SECURITY FOR EMPLOYERS

Privacy and Information Security Awareness Training. Health Insurance Portability & Accountability Act of HIPAA

HIPAA Education Level One For Volunteers & Observers

ACCOUNTABLE HEALTHCARE IPA HIPAA PRIVACY AND SECURITY TRAINING. By: Jerry Jackson Compliance and Privacy Officer

HIPAA PRIVACY AND SECURITY AWARENESS

PHI- Protected Health Information

HIPAA and Mental Health Privacy:

HIPAA PRIVACY POLICIES & PROCEDURES. Department of Behavioral Health and Developmental Services DBHHDS GENERAL AWARENESS TRAINING

HIPAA Compliance: Are you prepared for the new regulatory changes?

HIPAA Privacy & Security Training for Clinicians

12/19/2014. HIPAA More Important Than You Realize. Administrative Simplification Privacy Rule Security Rule

HIPAA Compliance for Students

Health Insurance Portability and Accountability Act (HIPAA) Compliance Training

HIPAA, HIPAA Hi-TECH and HIPAA Omnibus Rule

HIPAA 101. March 18, 2015 Webinar

HIPAA OVERVIEW ETSU 1

Why Lawyers? Why Now?

Huseman Health Law Group 3733 University Blvd. West, Suite 305-A Jacksonville, Florida Telephone (904) Facsimile (904)

PROTECTING PATIENT PRIVACY and INFORMATION SECURITY

3/13/2015 HIPAA/HITECH WHAT S YOUR COMPLIANCE STATUS? Daniel B. Mills Pretzel & Stouffer, Chartered WHAT IS HIPAA?

HIPAA PRIVACY OVERVIEW

Welcome to ChiroCare s Fourth Annual Fall Business Summit. October 3, 2013

Somansa Data Security and Regulatory Compliance for Healthcare

HIPAA Audits: How to Be Prepared. Lindsey Wiley, MHA, CHTS-IM, CHTS-TS HIT Manager Oklahoma Foundation for Medical Quality

My Docs Online HIPAA Compliance

Introduction to HIPAA Privacy

HIPAA Privacy and Security

HEALTH INSURANCE PORTABILITY & ACCOUNTABILITY ACT OF 1996 HIPAA

Dissecting New HIPAA Rules and What Compliance Means For You

HIPAA Overview. Darren Skyles, Partner McGinnis Lochridge. Darren S. Skyles

Privacy Officer Job Description 4/28/2014. HIPAA Privacy Officer Orientation. Cathy Montgomery, RN. Presented by:

MCCP Online Orientation

HIPAA Enforcement Training for State Attorneys General

HIPAA. New Breach Notification Risk Assessment and Sanctions Policy. Incident Management Policy. Focus on: For breaches affecting 1 3 individuals

HIPAA Orientation. Health Insurance Portability and Accountability Act

How To Understand And Understand The Benefits Of A Health Insurance Risk Assessment

Understanding Health Insurance Portability Accountability Act AND HITECH. HIPAA s Privacy Rule

HIPAA Violations Incur Multi-Million Dollar Penalties

HIPAA PRIVACY AND SECURITY AWARENESS. Covering Kids and Families of Indiana April 10, 2014

2014 Core Training 1

Data Security and Integrity of e-phi. MLCHC Annual Clinical Conference Worcester, MA Wednesday, November 12, :15pm 3:30pm

HIPAA Policy, Protection, and Pitfalls ARTHUR J. GALLAGHER & CO. BUSINESS WITHOUT BARRIERS

Policies and Procedures Audit Checklist for HIPAA Privacy, Security, and Breach Notification

White Paper #6. Privacy and Security

HIPAA Refresher. HIPAA Health Insurance Portability & Accountability Act

Compliance HIPAA Training. Steve M. McCarty, Esq. General Counsel Sound Physicians

HIPAA Violations Incur Multi-Million Dollar Penalties

Guadalupe Regional Medical Center

What Health Care Entities Need to Know about HIPAA and the American Recovery and Reinvestment Act

Health Insurance Portability and Accountability Act HIPAA Privacy Standards

M E M O R A N D U M. Definitions

ELECTRONIC HEALTH RECORDS

HIPAA COMPLIANCE AND DATA PROTECTION Page 1

HIPAA Privacy and Security

HIPAA/ HITECH HEALTH INSURANCE PORTABILITY ACCOUNTABILITY ACT. and. Health Information Technology for Economic and Clinical Health Act.

HIPAA Training for Hospice Staff and Volunteers

Reporting of HIPAA Privacy/Security Breaches. The Breach Notification Rule

HIPAA Privacy and Security. Rochelle Steimel, HIPAA Privacy Official Judy Smith, Staff Development January 2012

HIPAA Training for the MDAA Preceptorship Program. Health Insurance Portability and Accountability Act

HIPAA Privacy & Security Rules

HIPAA: Bigger and More Annoying

COMPLIANCE ALERT 10-12

Privacy for Beginners: What Every Healthcare Worker Needs to Know About HIPAA and Privacy

HIPAA Privacy. September 21, 2013

Neither You Nor Your Business Associates Can Afford to be Lax About Complying with HIPAA Requirements

HIPAA Compliance and the Protection of Patient Health Information

Catholic Health HIPAA/ HITECH

Health Insurance Portability and Accountability Act (HIPAA) and Health Information Technology for Economic and Clinical Health Act (HITECH)

HIPAA Update Focus on Breach Prevention

HIPPA Goes HITECH. Data Protection for Agents

SECURITY RISK ASSESSMENT SUMMARY

Lessons Learned from HIPAA Audits

HIPAA TRAINING. A training course for Shiawassee County Community Mental Health Authority Employees

Privacy Compliance Health Occupations Students

Louisiana Department of Health and Hospitals Basic HIPAA Privacy Training: Policies and Procedures

The benefits you need... from the name you know and trust

Department of Health and Human Services Policy ADMN 004, Attachment A

Ethics, Privilege, and Practical Issues in Cloud Computing, Privacy, and Data Protection: HIPAA February 13, 2015

HIPAA Hot Topics. Audits, the Latest on Enforcement and the Impact of Breaches. September Nashville Knoxville Memphis Washington, D.C.

HIPAA Privacy Overview

University Healthcare Physicians Compliance and Privacy Policy

Tools to Prepare and Protect Your Practice for HIPAA and Meaningful Use Audits

HIPAA Privacy, Security, Breach, and Meaningful Use. CHUG October 2012

Grand Rapids Medical Education Partners Mercy Health Saint Mary s Spectrum Health. Pam Jager, GRMEP Director of Education & Development

HIPAA In The Workplace. What Every Employee Should Know and Remember

Joe Dylewski President, ATMP Solutions

HIPAA Training: Ensuring Privacy for our Patients

Information Security and Privacy. WHAT is to be done? HOW is it to be done? WHY is it done?

Business Associates, HITECH & the Omnibus HIPAA Final Rule

HIPAA and the HITECH Act Privacy and Security of Health Information in 2009

Transcription:

HIPAA Happenings in Hospital Systems Donna J Brock, RHIT System HIM Audit & Privacy Coordinator

HIPAA

Health Insurance Portability and Accountability Act of 1996 Title 1 Title II Title III Title IV Title V Insurance Portability Fraud and Abuse Medical Liability Reform Administrative Simplification Tax Related Health Provision Group Health Plan Requirements Revenue Off-sets Privacy Transactions Security Code Sets Electronic Data Identifiers

HIPAA Privacy Rule Our focus today! HIPAA PRIVACY RULE Title 45, CFR Parts 164 & 160 Protect individuals rights to privacy and confidentiality

Who Does HIPAA Apply To? The law applies directly to 4 groups referred to as Covered Entities. Health Care Providers Health Plans Health Care Clearinghouses Business Associates

HIPAA What Should You Know Why privacy is important Provide awareness in protecting patient s health information Potential consequences and penalties for violation of HIPAA laws

Privacy Rule Set of national standards for protection of certain health information was established by the Standards for Privacy of Individually Identifiable Health Information Privacy Rule standards address the use and disclosure of individuals health information Protected Health Information (PHI) Name and birth date Picture ID drivers license # and email Developing and establishing Privacy Rule Standards is responsibility of Department of Health and Human Services (DHHS) Implemented and enforced by the Office of Civil Rights (OCR)

HITECH Act Overview American Recovery and Reinvestment Act of 2009 (ARRA) became federal law in February, 2009. The HITECH Act, a subset of the ARRA, expands and enhances the HIPAA Privacy and Security Rules giving more pressure to federal and state authorities to enforce privacy and security protections for patient data.

HIPAA Patient Rights Right to request restrictions on release of PHI Right to confidential communications Right to access and amend on request Right to provide specific authorization of their PHI other than TPO Right to opt out of patient directory Right to make a complaint Right to a copy of Notice of Privacy Practices on request

What Role Do You Play? Protect PHI at all times Written Electronic Spoken

True or False? HIPAA s goal is to catch staff sharing patients health information with those who do not need the information.

False Goal of HIPAA is to protect confidential patient information from improper use or disclosure. If you see an apparent violation, you should report it immediately to your Privacy Officer.

Beware of Discussing PHI Some of the most common threats to patient privacy is unintentional disclosure of PHI: Discussing where other patients or visitors may overhear

Unintentional Disclosure Leaving sensitive information out where others can see

Unauthorized Disclosures Another threat is when workforce members intentionally use or disclose information: Copying information and taking it home Removing PHI from facility and giving to others who don t have legal right Deliberately sharing with family, friends, coworkers

Unauthorized Disclosures Leaving a computer unattended after logging in Sharing passwords with others or leaving around computers Providing status of patient condition

Ways You Can Protect PHI Shred or properly dispose of all PHI Protect portable or mobile devices Faxing PHI Leaving messages Beware of taking PHI home

Do You Have the Right Patient? Two Identifiers Registering a patient Treating a patient Discharging a patient

Okay to Use and Disclose PHI Without patient s authorization Treatment, Payment, and Health Care Operations Facility Directory Agree or Object Incidental Disclosures Public Interest

True or False? One of the privileges of working in health care is that we have access to family and friends PHI so we can see how they are doing.

False We do not have the right to access anyone s health information unless it is directly needed for the completion of our job. If you accidently see patient information, you cannot share that information with anyone else.

What Role Do You Play? No access if it is NOT part of your job duty. Do I need to know this to do my job?

NOT Okay to Disclose Must have patient authorization for: Disclosure to patient s attorney for malpractice lawsuit Disclosure to life insurance company Person is seeking to obtain coverage

PHI is Protected Against Not involved in the care of the patient Insurance companies using PHI to deny life or disability insurance Employers using PHI in hiring/firing decisions News media Nosey family members, neighbors, coworkers

Is This a Violation? If an ambulance that is not affiliated with our organization transports a patient to our facility, can we give them PHI to use for their billing? Do we need the patient s written authorization?

Answer One covered entity (CE), such as the hospital, is permitted to share PHI with another CE, the ambulance service without authorization from the patient. TPO

What are the High Risks? Confidentiality Integrity Availability of ephi

Office of Civil Rights (OCR) OCR Phase 2 Focus Privacy Rule - Patient notice and access Breach Notification Rule - Content and timeliness of notifications Security Rule - Risk analysis and risk management BAs - Risk analysis and risk management; breach reporting to CE practices

Office of Civil Rights (OCR) Projected 2015 Focus ephi transmission security Device/media controls Privacy safeguards and training efforts Projected 2016 Focus Higher risk topics: Encryption and decryption Facility physical access controls Breach reports and complaints

Fines HIPAA Omnibus Rule Covered entities and business associates failing to safeguard PHI Up to $1.5M in annual fines

What Can Be Done to Minimize Violations? Regular risk analysis Updating policies regularly Combine device scanning with understanding of workflow, policies, procedures Implement a remediation plan

Use My Mobile Device Right?! Using cell phones at work

Social Media Is this acceptable practice?

Is this a HIPAA Violation/Breach? Credentialed physicians and allied health professionals have a right to access the records of their adult child or spouse to follow up on results while not treating provider?

Answer Yes, a breach may also be a federal crime Intentional or not? Accidental access? When would it be appropriate to access the medical record? From HCPro

Civil and Criminal Penalties Not only levied against the facility Employee can be fined and/or imprisoned $100/person/violation-up to $25,000/year Ignorance is not a defense U.S. Dept. of Health and Human Service for Civil Rights enforces civil penalties

Civil and Criminal Penalties Criminal penalties Up to $50,000 and 1 year prison; knowingly releasing patient information Up to $100,000 and 5 years prison; gaining access to health information under false pretenses Up to $250,000 and 10 years prison; releasing patient information with harmful intent or selling patient information U.S. Dept. of Justice enforces criminal penalties

Reporting Violations/Breaches

Is this a Violation? If you are presenting or demonstrating a workflow or application, is it okay to bring it up showing a real patient to all in the room?

Answer No, the people in the meeting do not have a business need to view that particular patient s chart.

Consider this What if it was about my medical or personal information? What can I do to protect someone else s privacy? If I violate HIPAA, would I: Lose my job and license? Be fined or imprisoned?

Protecting Privacy is EVERYONE S JOB! Donna J Brock, RHIT Donna.Brock@leememorial.org Lee Memorial Health System, Florida 239-343-8141