HIPAA & TRAINING. Web-Based Strategies for Compliance



Similar documents
REQUEST FOR BOARD ACTION

HIPAA FOR HUMAN RESOURCE EXECUTIVES. Stuart Miller, Esq. Gerry Hinkley, Esq. Davis Wright Tremaine LLP

Welcome to part 2 of the HIPAA Security Administrative Safeguards presentation. This presentation covers information access management, security

HIPAA Information Security Overview

HIPAA Security Training Manual

Huseman Health Law Group 3733 University Blvd. West, Suite 305-A Jacksonville, Florida Telephone (904) Facsimile (904)

Policy Title: HIPAA Security Awareness and Training

DEPARTMENT OF MENTAL HEALTH AND DEVELOPMENTAL DISABILITIES

HIPAA Security. 2 Security Standards: Administrative Safeguards. Security Topics

It is anticipated that the following individuals may become an Authorized User:

HIPAA Privacy & Security Rules

HIPAA BUSINESS ASSOCIATE AGREEMENT

Health Insurance Portability and Accountability Act (HIPAA) and Health Information Technology for Economic and Clinical Health Act (HITECH)

HIPAA Security Alert

How To Protect Your Health Care From Being Hacked

Guide: Meeting HIPAA Security Rules

Unified Security Anywhere HIPAA COMPLIANCE ACHIEVING HIPAA COMPLIANCE WITH MASERGY PROFESSIONAL SERVICES

HIPAA Security. 1 Security 101 for Covered Entities. Security Topics

Seven Requirements for Successfully Implementing Information Security Policies and Standards

ensure prompt restart of critical applications and business activities in a timely manner following an emergency or disaster

VMware vcloud Air HIPAA Matrix

STATE OF NEVADA DEPARTMENT OF HEALTH AND HUMAN SERVICES BUSINESS ASSOCIATE ADDENDUM

CMA BUSINESS ASSOCIATE AGREEMENT WITH CMA MEMBERS

HIPAA and Mental Health Privacy:

SUBJECT: SECURITY OF ELECTRONIC MEDICAL RECORDS COMPLIANCE WITH THE HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996 (HIPAA)

Privacy Officer Job Description 4/28/2014. HIPAA Privacy Officer Orientation. Cathy Montgomery, RN. Presented by:

Donna S. Sheperis, PhD, LPC, NCC, CCMHC, ACS Sue Sadik, PhD, LPC, NCC, BC-HSP Carl Sheperis, PhD, LPC, NCC, MAC, ACS

Protection of Clients' Personal Health Information G & G LIVING CENTERS, INC.'s Privacy Practices

Policies and Procedures Audit Checklist for HIPAA Privacy, Security, and Breach Notification

IBM Internet Security Systems. The IBM Internet Security Systems approach for Health Insurance Portability and Accountability Act compliance overview

Information Security Plan May 24, 2011

HIPAA Security. 4 Security Standards: Technical Safeguards. Security Topics

HIPAA Audit Processes HIPAA Audit Processes. Erik Hafkey Rainer Waedlich

Securing the FOSS VistA Stack HIPAA Baseline Discussion. Jack L. Shaffer, Jr. Chief Operations Officer

An Oracle White Paper December Leveraging Oracle Enterprise Single Sign-On Suite Plus to Achieve HIPAA Compliance

CHIS, Inc. Privacy General Guidelines

BEFORE THE BOARD OF COUNTY COMMISSIONERS FOR MULTNOMAH COUNTY, OREGON RESOLUTION NO

HIPAA 100 Training Manual Table of Contents. V. A Word About Business Associate Agreements 10

HIPAA Security. 2 Security Standards: Administrative Safeguards. Security. Topics

Montclair State University. HIPAA Security Policy

The HIPAA Security Rule Primer Compliance Date: April 20, 2005

Solution Brief for HIPAA HIPAA. Publication Date: Jan 27, EventTracker 8815 Centre Park Drive, Columbia MD 21045

ELKIN & ASSOCIATES, LLC. HIPAA Privacy Policy and Procedures INTRODUCTION

BUSINESS ASSOCIATE AGREEMENT ( BAA )

BUSINESS ASSOCIATE AGREEMENT

SARASOTA COUNTY GOVERNMENT EMPLOYEE MEDICAL BENEFIT PLAN HIPAA PRIVACY POLICY

HIPAA Compliance: Are you prepared for the new regulatory changes?

State HIPAA Security Policy State of Connecticut

An Introduction to HIPAA and how it relates to docstar

HomeCare Rehab and Nursing, LLC (HCRN) (DBA - Baker Rehab Group) Notice of Privacy Practice

Our Commitment to Information Security

HIPAA Security Rule Compliance

Information Security Policy and Handbook Overview. ITSS Information Security June 2015

The George Washington University Hospital

Guidelines Relating to Implementation of the Privacy Regulations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA)

White Paper THE HIPAA FINAL OMNIBUS RULE: NEW CHANGES IMPACTING BUSINESS ASSOCIATES

HIPAA Security COMPLIANCE Checklist For Employers

Joseph Suchocki HIPAA Compliance 2015

PRIVACY AND INFORMATION SECURITY WORKFORCE TRAINING

HIPAA: Understanding The Omnibus Rule and Keeping Your Business Compliant

The HIPAA Security Rule Primer A Guide For Mental Health Practitioners

HIPAA 203: Security. An Introduction to the Draft HIPAA Security Regulations

Document Title: System Administrator Policy

BUSINESS ASSOCIATE AGREEMENT

SCDA and SCDA Member Benefits Group

HIPAA Security Checklist

IDAHO STATE UNIVERSITY POLICIES AND PROCEDURES (ISUPP) HIPAA Privacy & Security - Sanctions 10210

Procedure Title: TennDent HIPAA Security Awareness and Training

ITS HIPAA Security Compliance Recommendations

FirstCarolinaCare Insurance Company Business Associate Agreement

BUSINESS ASSOCIATE AGREEMENT

HIPAA Security. 5 Security Standards: Organizational, Policies. Security Topics. and Procedures and Documentation Requirements

Authorized. User Agreement

HEALTH CARE ADVISORY

University of Wisconsin-Madison Policy and Procedure

HIPAA Security. assistance with implementation of the. security standards. This series aims to

OFFICE OF CONTRACT ADMINISTRATION PURCHASING DIVISION. Appendix A HEALTHCARE INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPPA)

HIPAA/HITECH PRIVACY & SECURITY CHECKLIST SELF ASSESSMENT INSTRUCTIONS

Privacy and Security Awareness, Education and Training Policy

This form may not be modified without prior approval from the Department of Justice.

Health Insurance Portability and Accountability Act Enterprise Compliance Auditing & Reporting ECAR for HIPAA Technical Product Overview Whitepaper

COMPLIANCE ALERT 10-12

HIPAA: In Plain English

HIPAA: Privacy/Info Security

HIPAA Security Rule Compliance and Health Care Information Protection

ADDENDUM TO ADMINISTRATIVE SERVICES AGREEMENT FOR HIPAA PRIVACY/SECURITY RULES

SAMPLE BUSINESS ASSOCIATE AGREEMENT

HIPAA HANDBOOK. Keeping your backup HIPAA-compliant

HIPAA Compliance Guide

Compliance and Industry Regulations

Security Awareness Training Policy

MMA SAMPLE FORM *REVIEW CAREFULLY & ADAPT TO YOUR PRACTICE*

Iowa Health Information Network BUSINESS ASSOCIATE AGREEMENT

HIPAA BUSINESS ASSOCIATE SUBCONTRACTOR AGREEMENT

HIPAA SECURITY RULES FOR IT: WHAT ARE THEY?

Third Party Risk Management 12 April 2012

A Technical Template for HIPAA Security Compliance

BUSINESS ASSOCIATE AGREEMENT HIPAA Omnibus Rule (Final Rule)

Transcription:

HIPAA & TRAINING Web-Based Strategies for Compliance Dion P. Sheidy, CPA PricewaterhouseCoopers LLP Partner National Leader Compliance and Operational Control (412) 355-7575 M. Kevin McMahon Complient Vice President, Education (440) 519-2662

HIPAA Training Requirements Two Of The Proposed Regulations Specifically Require Training: - Privacy (section 164.518) - Security and Electronic Signatures (section 142.308)

HIPAA Training Requirements Privacy Who Must Be Trained: - All members of an entity s workforce who, by virtue of their position, are likely to obtain access to protected health information -Employees - Volunteers - Trainees - Others under direct control of persons working on behalf of covered entity, but not a business partner

HIPAA Training Requirements Privacy Who Must Be Trained: (continued) - While training of Business Partner workforces is not specifically mandated, covered entities are required to ensure that Business Partners have appropriate safeguards in place for protected health information.

HIPAA Training Requirements Privacy What Must The Training Include? - The workforce must receive training on an entity s policies and procedures relating to protected health information.

HIPAA Training Requirements Privacy When Is The Training To Be Completed? - The entire affected workforce must have received training by the date on which the regulations become effective. - New members of the workforce must be trained within a reasonable period.

HIPAA Training Requirements Privacy When Is The Training To Be Completed? (continued) - Members of the workforce who are affected by any material changes in the privacy policies and procedures must be retrained in those changes. The proposed regulation is silent as to how promptly this retraining must be accomplished.

HIPAA Training Requirements Privacy When Are Certifications Required? - Each trained member of the workforce must sign a statement certifying: - Date of training; and - Willingness to honor the privacy policies and procedures - Every three years each member of the workforce must re-certify.

HIPPA Training Requirements Security The proposed Security and Electronic Signature rule under section 142.308(12) requires security training regarding the vulnerabilities of the health information in an entity s possession and procedures, which must be followed to ensure the protection of that information.

HIPAA Training Requirements Security The Implementation Features Required Are As Follows: - Awareness training for all personnel, including management, agents and contractors - Based on job responsibilities, customized education programs that focus on issues regarding use of health information and responsibilities regarding confidentiality and security

HIPAA Training Requirements Security The Implementation Features Required Are As Follows: (continued) - Periodic security reminders - User education concerning virus protection - User education in importance of monitoring login success/failure, and how to report discrepancies - User education in password management

HIPAA Training Requirements Security Awareness Training: - Required for all personnel, including management personnel, agents and contractors - Security awareness is defined as -- but not limited to -- password maintenance, incident reporting and viruses and other forms of malicious software

HIPAA Training Requirements Security Customized Training: - Based on job responsibility, customized education that focuses on the use of health information and responsibilities regarding confidentiality. - This area also includes education on physical safeguards (i.e. verifying access authorizations to health information, maintenance of records, need-to-know procedures, secure workstation areas)

HIPAA Training Requirements Security Periodic Security Reminders: - Employees, agents and contractors are made aware of security concerns on an ongoing basis.

HIPAA Training Requirements Security Virus Protection: - Training relative to user awareness of the potential harm that can be caused by a virus, how to prevent the introduction of a virus to a computer system and what to do if a virus is detected.

HIPAA Training Requirements Security Login Success/Failure - User education in the importance of monitoring log-in success or failure and how to report discrepancies - Training in the user s responsibility to ensure the security of health care information

HIPAA Training Requirements Security Password Management: - User education in password management. - Rules to be followed in creating and changing passwords and the need to keep them confidential.

ROLLING HIPAA OUT Maintenance & Refinement Implementation Assessment Awareness 01/2001 12/2002

01/2001 12/2002 EDUCATION IN A HIPAA ROLLOUT Maintenance Refinement Implementation Assessment

HIPAA EDUCATION CHALLENGES Content Volume Audience Size Awareness Implementation Planning Implementation Maintenance

ISSUES/CHALLENGES/REQUIREMENTS Issue Challenge Requirement Content Volume Central Management Content Detail Customized Consistency Logistics Large Audiences Local Management Delivery Dispersed Audiences Diverse Audiences Limited Availability Costs Direct Costs including Content Development Delivery Scalable, Flexible Infrastructure Indirect including time lost from work travel and lost productivity Management Process Definition evolving content and audience turnover Flexible Content & Repository Tracking Reporting To Senior Management status/effectiveness/cost Robust Reporting Functionality To Regulatory Agency status/compliance/incidents From Partners and Suppliers status/compliance/incidents Measurable Effects Reduced costs percentage compliance Enterprise Systems Orientation Reduced incidents Business Planning Greater operating efficiency Robust Reporting Tools

TYPICAL e-learning e CAPABILITIES Requirement Management Education Limited Reporting

ISSUES/CHALLENGES/REQUIREMENTS Issue Challenge Requirement Content Volume Central Management Content Detail Customized Consistency Logistics Large Audiences Local Management Delivery Dispersed Audiences Diverse Audiences Limited Availability Costs Direct Costs including Content Development Delivery Scalable, Flexible Infrastructure Indirect including time lost from work travel and lost productivity Management Process Definition evolving content and audience turnover Flexible Content & Repository Tracking Reporting To Senior Management status/effectiveness/cost Robust Reporting Functionality To Regulatory Agency status/compliance/incidents From Partners and Suppliers status/compliance/incidents Measurable Effects Reduced costs percentage compliance Enterprise Systems Orientation Reduced incidents Business Planning Greater operating efficiency Robust Reporting Tools

e-learning CAPABILITIES IN A COMPLIANCE MANAGEMENT ENVIRONMENT INCIDENT MANAGEMENT Organization Modeling Audience Definition Requirement Managemen t Expert Systems Policies Plans Procedures Knowledge Managemen t Education Record Keeping & Follow-up INCIDENT MANAGEMENT

MODELING YOUR ORGANIZATION CORPORATE DIVISION 1 DIVISION 2 DIVISION 3 DIVISION 4 SITE SITE SITE SITE FUNCTION 1 FUNCTION 2 FUNCTION 3

MODELING YOUR ORGANIZATION CORPORATE DIVISION 1 DIVISION 2 DIVISION 3 DIVISION 4 SITE SITE SITE SITE FUNCTION 1 FUNCTION 2 FUNCTION 3

MODELING YOUR ORGANIZATION CORPORATE DIVISION 1 DIVISION 2 DIVISION 3 DIVISION 4 SITE SITE SITE SITE FUNCTION 1 FUNCTION 2 FUNCTION 3 REQUIREMENT 1 REQUIREMENT 2 REQUIREMENT 3

MANAGING CONTENT Overview Concept Detailed concept Reference Application F1 F2 F3 F4 Information

ASSEMBLING CONTENT Function Level Function Function Function Level Task Resp #1 Level Level Task Resp #2

TARGET CONTENT Employee Senior Manager Functional Manager Employee

TRACKING & REQUIREMENTS Administration Requirements Assembly Audience Track, Automated, Follow-up & Report

MAINTENANCE Ongoing Knowledge Management Tracking Reporting Incident Management

ISSUES/CHALLENGES/REQUIREMENTS Issue Challenge Requirement Content Volume Central Management Content Detail Customized Consistency Logistics Large Audiences Local Management Delivery Dispersed Audiences Diverse Audiences Limited Availability Costs Direct Costs including Content Development Delivery Scalable, Flexible Infrastructure Indirect including time lost from work travel and lost productivity Management Process Definition evolving content and audience turnover Flexible Content & Repository Tracking Reporting To Senior Management status/effectiveness/cost Robust Reporting Functionality To Regulatory Agency status/compliance/incidents From Partners and Suppliers status/compliance/incidents Measurable Effects Reduced costs percentage compliance Enterprise Systems Orientation Reduced incidents Business Planning Greater operating efficiency Robust Reporting Tools

EDUCATION IN A HIPAA ROLLOUT Maintenance Refinement Implementation Assessment 01/2001 12/2002