HIPAA Basic Training for Privacy & Information Security



Similar documents
HIPAA Privacy & Security Training for Clinicians

HIPAA Privacy and Security. Rochelle Steimel, HIPAA Privacy Official Judy Smith, Staff Development January 2012

HIPAA Training for Hospice Staff and Volunteers

2014 Core Training 1

Annual Compliance Training. HITECH/HIPAA Refresher

HIPAA PRIVACY POLICIES & PROCEDURES. Department of Behavioral Health and Developmental Services DBHHDS GENERAL AWARENESS TRAINING

Page 1. NAOP HIPAA and Privacy Risks 3/11/2014. Privacy means being able to have control over how your information is collected, used, or shared;

Health Insurance Portability and Accountability Act (HIPAA)

HFS DATA SECURITY TRAINING WITH TECHNOLOGY COMES RESPONSIBILITY

Information Security. Annual Education Information Security Mission Health System, Inc.

Department of Health and Human Services Policy ADMN 004, Attachment A

A Privacy and Information Security Guide for UCLA Workforce. HIPAA and California Privacy Laws

SELF-LEARNING MODULE (SLM) 2012 HIPAA Education Privacy Basics and Intermediate Modules

HIPAA Training for the MDAA Preceptorship Program. Health Insurance Portability and Accountability Act

8.03 Health Insurance Portability and Accountability Act (HIPAA)

Grand Rapids Medical Education Partners Mercy Health Saint Mary s Spectrum Health. Pam Jager, GRMEP Director of Education & Development

HIPAA Employee Compliance Program TRAINING MANUAL

HIPAA and Health Information Privacy and Security

HIPAA Auditing Tool. Department: Site Location: Visit Date:

Health Insurance Portability and Accountability Act of 1996 (HIPAA) Contents

HIPAA. New Breach Notification Risk Assessment and Sanctions Policy. Incident Management Policy. Focus on: For breaches affecting 1 3 individuals

How To Protect Your Health Information At Uni Of California

Clinician s Guide to HIPAA Privacy. I. Introduction What is HIPAA? Health Information Privacy Protected Health Information

HIPAA (Health Insurance Portability and Accountability Act) Awareness Training for Volunteers and Interns

Topics. What are privacy and security all about? How can I protect confidential information? What should I do if I see a problem?

Patient Privacy and HIPAA/HITECH

HIPAA Privacy and Security

HIPAA Happenings in Hospital Systems. Donna J Brock, RHIT System HIM Audit & Privacy Coordinator

HIPAA Training for Staff and Volunteers

HIPAA Privacy and Security

Instructions for Completing Required Documentation for Clinical Rotations

HIPAA Policy, Protection, and Pitfalls ARTHUR J. GALLAGHER & CO. BUSINESS WITHOUT BARRIERS

HIPAA and Privacy Policy Training

HIPAA Education Level One For Volunteers & Observers

PRIVACY AND SECURITY SURVIVAL TRAINING

Department of Alcohol & Drug Programs. Information Management Services Division (IMSD) ENCRYPTION INSTRUCTIONS

HIPAA RULES AND REGULATIONS

HIPAA Privacy & Security Rules

HIPAA and You The Basics

Awareness Training for VIM Volunteers and Staff

HIPAA TRAINING. A training course for Shiawassee County Community Mental Health Authority Employees

Health Information Privacy Refresher Training. March 2013

BSHSI Security Awareness Training

HIPAA Compliance Annual Mandatory Education

HIPAA And Public Health. March 2006 Delaware s Division of Public Health 1

How To Write A Health Care Security Rule For A University

Target Audience: All Non-Management CHS Employees, Students, Volunteers, and Physicians

HIPAA 101: Privacy and Security Basics

MCCP Online Orientation

Section 5 Identify Theft Red Flags and Address Discrepancy Procedures Index

HIPAA Compliance for Students

HIPAA Privacy for Caregivers

HFS DATA SECURITY TRAINING

HEALTH INSURANCE PORTABILITY & ACCOUNTABILITY ACT OF 1996 HIPAA

Annual HIPAA Security & Information Security Competency

Are you in the correct place?

HIPAA Self-Study Module Patient Privacy at Unity Health Care, Inc HIPAA Hotline

PHI- Protected Health Information

HIPAA PRIVACY AND SECURITY TRAINING P I E D M O N T COMMUNITY H EA LT H P L A N

Guide to INFORMATION SECURITY FOR THE HEALTH CARE SECTOR

HIPAA Security Training Manual

Welcome to the University of Utah Health Sciences HIPAA Privacy and Security Training Program

Louisiana Department of Health and Hospitals Basic HIPAA Privacy Training: Policies and Procedures

Privacy Compliance Health Occupations Students

HIPAA PRIVACY OVERVIEW

LEARNING MODULE: HIPAA AND COMPLIANCE. For Clinical Students and Instructors Greater Green Bay Healthcare Alliance Updated June 27, 2014

MONTSERRAT COLLEGE OF ART WRITTEN INFORMATION SECURITY POLICY (WISP)

ENISA s ten security awareness good practices July 09

For All HIPAA Workforce Members Revised April 2013

Transcription:

HIPAA Basic Training for Privacy & Information Security Vanderbilt University Medical Center VUMC HIPAA Website: www.mc.vanderbilt.edu/hipaa

Vanderbilt Credo We treat others as we wish to be treated Vanderbilt Credo Behavior I respect privacy and confidentiality

What is HIPAA? Health Insurance Portability and Accountability Act of 1996 Limits how we use and share patient information Gives patients more control over their information Protects the integrity, availability and confidentiality of patient information Defines violation penalties

What is Protected under HIPAA? Individually identifiable health information collected from an individual that is created or received by a health care provider, employer, or plan. In any form: written, verbal, electronic Information pertaining to HIV, alcohol and drug treatment, psychotherapy notes, etc. have even more stringent protections.

Patient Rights HIPAA regulations provide individuals with certain rights that are reflected in VUMC policy. Patients have the right to: Receive a Notice of Privacy Practices that describes how we use and share their information Review and obtain copies of their medical and financial records Request corrections if they believe information is incorrect

Sharing Patient Information You must obtain patient authorization except for in these circumstances: Treatment (referring physicians, family members involved in patient s care, etc.) Whenever possible, the patient should be given the opportunity to control which family members receive information. Payment (insurance companies, other third parties) Administrative functions (QI, financial analysis, educational or training activities) Other specific exceptions (required by law, Department of Public Health)

Giving Patients Control Over their Information Only share patient information with other faculty and staff who need the information to do their job. Avoid accessing a patient s record unless you need to do so for your job or you have written permission from the patient. You are not allowed to access the record of your co-worker, spouse, or family member unless there is a signed authorization form in the patient s record.

Key Information Security Practices Passwords & Electronic Signatures Logging Off Email

Passwords and Electronic Signatures Some Do s and Don ts related to passwords and electronic signatures. Note: Electronic signatures should be protected in the same manner as passwords. DO choose ones that you can remember DO remember that the longer they are, the better DO use numbers, uppercase and lowercase letters, and special symbols to create them, where allowed DO NOT share them with anyone DO NOT write them down where others can see or store them where others can access them (unless encrypted) DO NOT use words, names, or personal data (e.g., SSN)

Logging Off When using a computer if you need to walk away you should always: Log Off OR Lock the computer screen This is important so that others do not document in the electronic medical record under your user-id or gain access to information they may not be authorized to view.

Email Email sent over the Internet is unencrypted and not secure. Find alternative ways to communicate confidential information (e.g., encryption, MyHealthAtVanderbilt, password protected files, VPN) Limit the amount of patient information. Beware of Email Attachments!

Helpful Reminders Privacy Risks 1. Conversations at nurses stations, front desks, semiprivate rooms, hallways, etc. 2. Documents or computer monitors in view. Printers accessible by public. 3. Whiteboards with patient info. 4. Faxing clinical information Approaches to Reduce the Risk 1. Lower voice, ask visitors to leave the room 2. Turn monitors away or use filter screens, log off or lock systems, keep documents in folders. Keep printers in secure areas. 3. Use initials, abbreviations, codes, etc. 4. Make sure you enter the correct fax number. Always use a cover sheet.

Helpful Reminders Privacy Risks 5. Emailing patients, or patient information 6. Leaving messages for patients 7. Disposal of document or electronic media containing patient information in regular trash. Approaches to Reduce the Risk 5. Use an alternative method for communicating patient information whenever possible. Avoid emailing patient information outside of VUMC. 6. Limit the information on the message 7. Shred documents and dispose of electronic media appropriately

Sanctions for Privacy and Information Security Violations VUMC considers it a serious incident anytime that a privacy or security violation occurs. HIPAA requires that we monitor information system activity which assists in identifying violations and that we document all incidents. Disciplinary/corrective action ranges from training/counseling to termination. Unfortunately every year someone at VUMC is terminated due to committing this type of violation.

What should be reported? Examples: Looking at someone else s confidential data. Leaving paperwork with patient information lying around unattended. Sharing your password or electronic signature with someone else or using someone else s password or electronic signature.

Contact one of the following to Report Privacy & Information Security Incidents Privacy Office (936-3594) or email Privacy.Office@vanderbilt.edu Help Desk (343-4357) Compliance Reporting Line (343-0135) Your manager Always forward Patient privacy complaints to Patient Affairs (322-6154) or the Privacy Office.

The Bottom Line Consider the patient s perspective and give them control over how their information is used. Avoid situations in which the patient would object to how their information was used or shared Implement appropriate security measures to maintain the integrity of patient data, ensure its availability, and keep it confidential. Be familiar with Vanderbilt s privacy & information security policies

Next Steps You must complete the TEST associated with this lesson in order to be marked complete for the HIPAA training. Close this window and then select the link to TEST beside the name of the Lesson (HIPAA Basic Training).