COMPLIANCE DEPARTMENT. LSUHSC-S Louisiana State University Health Sciences Center Shreveport ACKNOWLEDGEMENT RECEIPT

Size: px
Start display at page:

Download "COMPLIANCE DEPARTMENT. LSUHSC-S Louisiana State University Health Sciences Center Shreveport ACKNOWLEDGEMENT RECEIPT"

Transcription

1 COMPLIANCE DEPARTMENT LSUHSC-S Louisiana State University Health Sciences Center Shreveport ACKNOWLEDGEMENT RECEIPT for COMPLIANCE, HIPAA PRIVACY, AND INFORMATION SECURITY SELF-STUDY GUIDE I hereby certify that I have received the LSUHSC-S Compliance, HIPAA Privacy, and Security Self-Study Basic Training Guide. I understand that I will be accountable for the information contained therein. I also understand that this acknowledgement will be maintained as a record of my participation in the Compliance and HIPAA training program and may be reviewed by the Federal Government. PRINT NAME: DEPARTMENT: EMPLOYEE ID #: DATE: SIGNATURE: FOR OFFICE USE ONLY Original 4/1/03 Revision 1/22/07, 1/08/09, 1/21/16

2 COMPLIANCE, HIPAA PRIVACY, AND INFORMATION SECURITY SELF-STUDY GUIDE Education about HIPAA and LSUHSC-S s policies and procedures related to complying with HIPAA is required by law. All facility employees of LSUHSC clinics and LSUHSC School of Medicine, who are under the direction of the North Louisiana Chancellor, are required to complete this module and be familiar with related policies. All campuses and facilities will be designated as LSUHSC-S for purposes of HIPAA. 1

3 What is HIPAA? In 1996, the Health Insurance Portability and Accountability Act (HIPAA) was endorsed by the U.S. Congress. The HIPAA Privacy Rule, also called the Standards for Privacy of Individually Identifiable Health Information, provided the first nationally-recognizable regulations for the use/disclosure of an individual's health information. Essentially, the Privacy Rule defines how covered entities use individually-identifiable health information or Personal Health Information (PHI). Why is HIPAA necessary? HIPAA was passed by Congress in response to growing concerns that technological advances and the increasingly complex manner in which health care services were delivered and coordinated were resulting in, or could result in, risks to the privacy of an individual s health information maintained by health care providers, health plans, and their various business associates. State statutes existed; however, few provided comprehensive, reliable standards and even fewer made it clear as to what patients rights were to access information in their own medical records. Objective of HIPAA Gives patients control over the use of their health information Defines boundaries for the use/disclosure of health records by covered entities Establishes national-level standards that healthcare providers must comply with Helps to limit the use of PHI and minimizes chances of its inappropriate disclosure Strictly investigates compliance-related issues and holds violators accountable with civil or criminal penalties for violating the privacy of an individual's PHI Supports the cause of disclosing PHI without individual consent for individual healthcare needs, public benefit, and national interests What is a Covered Entity? A Covered Entity is a health care provider, health care clearinghouse, or health plan, which transmits PHI electronically in connection with a transaction. All of LSUHSC-Shreveport facilities are part of the LSUHSC-S covered entity and for purposes of HIPAA are designated as LSUHSC-S. 2

4 What is a Business Associate? A Business Associate is a person or entity that performs certain functions or activities on behalf of an entity or provides certain services to an entity that involves the use or disclosure of PHI. Examples are document shredding services and physician billing companies. What does disclosure mean? Disclosure means the release, transfer, provision of, access to, or the divulgence of patient information in any manner outside of the covered facility. What is a Notice of Privacy Practices? The HIPAA Privacy Rule gives individuals a fundamental new right to be informed of the privacy practices of their health plans and most of their health care providers, as well as to be informed of their privacy rights with respect to their personal health information. Health plans and covered health care providers are required to develop and distribute a notice that provides a clear explanation of these rights and practices. The notice is intended to focus individuals on privacy issues and concerns, to prompt them to have discussions with their health plans and health care providers, and exercise their rights. Covered entities are required to provide a notice in plain language that describes: How the covered entity may use and disclose protected health information about an individual. The individual s rights with respect to the information and how the individual may exercise these rights, including how the individual may complain to the covered entity. The covered entity s legal duties with respect to the information, including a statement that the covered entity is required by law to maintain the privacy of protected health information. Whom individuals can contact for further information about the covered entity s privacy policies. The Notice of Privacy Practices must be given to each patient and must be posted at each provider site. Except in an emergency treatment situation, LSUHSC-S employees must make a good faith effort to obtain the individual s written acknowledgment of receipt of the privacy notice. If an acknowledgment cannot be obtained, the representative must document his or her efforts to obtain the acknowledgment and the reason why it was not obtained. 3

5 What is Protected Health Information? Any individually identifiable health information transmitted or maintained by a covered entity used or disclosed for treatment, payment, or operations. It also includes all electronic, written, and verbal patient information. There are 18 identifying date elements listed in HIPAA regulations. PHI Data Elements Names All geographic subdivisions smaller than a state, except for the initial three digits of the zip code if the geographic unit formed by combining all zip codes with the same three initial digits contains more than 20,000 people All elements of dates, except year, and all ages over 89 or elements indicative of such age Telephone numbers Fax numbers addresses Social security numbers Medical record numbers Health plan beneficiary numbers Account numbers Certificate or license numbers Vehicle identifiers and serial numbers, including license plate numbers Device identifiers and serial numbers Web Universal Resource Locators (URLs) Internet Protocol (IP) addresses Biometric identifiers, including finger and voice prints Full face photographs and any comparable images Any other unique, identifying number, characteristic, or code, except as permitted for reidentification in the Privacy Rule What is not considered PHI? Health information is not protected health information if it is de-identified. Deidentified information may be used without restriction and without patient authorization. If the resulting information cannot be used to identify the individual, then it is no longer PHI. 4

6 What patient information must we protect? We must protect all PHI including, but not limited to, medical records, diagnoses, x-rays, photos and images, recordings, prescriptions, specimens, lab work and other test results, billing records, claim data, referral authorizations, and explanation of benefits. Clinical research records of patient care must also be protected. Who is authorized to access confidential PHI? PHI may be accessed without patient consent under certain circumstances and for certain purposes. Three of these purposes Treatment, Payment and health care Operations (TPO) are the most common: T Treatment (A physician can call his or her colleague in another specialty to get the colleague s input on the care being provided). P Payment (A physician s staff can submit a bill to the individual s insurance company to obtain payment for the services provided). O Operations (A physician s compliance staff can access the individual s PHI to conduct an assessment of the physician s coding and documentation practices). What is the minimum necessary standard? HIPAA covered entities must make reasonable efforts to limit their use or disclosure of PHI to the minimum necessary to accomplish the intended purpose. It is up to the covered entity rather than patient to determine what minimum necessary means. Also, there are some situations to which the minimum necessary standard does not apply. For example, it doesn t apply to information disclosed in connection with treatment or when a patient authorizes a use or disclosure of information. For more information on the minimum necessary standard, see 45 CFR (b) and 45 CFR (d). When are written patient authorizations required? To use or disclose PHI for almost any reason other than T-P-O, including research and fundraising, you will need to obtain a written authorization from the patient prior to access, use, or disclosure. For releases from the medical record, the signed authorization must be placed in the patient s medical record. 5

7 Psychotherapy notes require special handling and authorizations. All requests for psychotherapy notes must be routed to the appropriate medical records department. PHI may be used for research, fundraising, public information, or health care communications, but special rules apply. Why do I need to know this information? All reasonable efforts must be made to disclose no more than the minimum necessary information about a patient than is needed to accomplish the intended purpose. Staff access to PHI is based on specific job duties and roles. What are some things I can do to protect our patients privacy? Access only information you need to do your job Treat all information as if it were about you or your family Limit discussions at bedside (use good judgment) Do not discuss confidential patient information in elevators, hallways, the cafeteria, restrooms, etc. Do not discuss patients with your family, friends, or other employees in the hospital that are not directly involved in the patient s treatment, payment, and operations Do not access or share patient information about your family members, your friends, or any other person unless it is needed to do your job Access only those computer systems you are officially authorized to access Do not leave charts, schedules, or computer screens containing patient information in plain view Do not share passwords Do not allow others to read over your shoulders Do not allow visitors or patients in staff areas, dictating rooms, chart storage areas, etc. Do not hold telephone conversations or conduct dictation in areas where confidential patient information can be overheard Shred PHI before discarding Call out only the patient s name in a waiting room 6

8 What rights do patients have under the HIPAA Privacy Regulations? Patients rights under HIPAA are described in the Notice of Privacy Practices. The notice is made available to patients in many settings. These rights include: Right to Receive the Notice of Privacy Practices Right of Access to Paper or Electronic Copies Right to Request an Amendment or Addendum Right to an Accounting of Disclosures Right to Request Restrictions Right to Request Confidential Communications Right to Complain What are the penalties under HIPAA? Civil Penalties: HIPAA Violation Minimum Penalty Maximum Penalty Individual did not know (and by exercising reasonable diligence would not have known) that he/she violated HIPAA HIPAA violation due to reasonable cause and not due to willful neglect HIPAA violation due to willful neglect but violation is corrected within the required time period $100 per violation, with an annual maximum of $25,000 for repeat violations $1,000 per violation, with an annual maximum of $100,000 for repeat violations $10,000 per violation, with an annual maximum of $250,000 for repeat violations $50,000 per violation, with an annual maximum of $1.5 million $50,000 per violation, with an annual maximum of $1.5 million $50,000 per violation, with an annual maximum of $1.5 million HIPAA violation is due to willful neglect and is not corrected $50,000 per violation, with an annual maximum of $1.5 million $50,000 per violation, with an annual maximum of $1.5 million ***The Secretary of the Department of Health and Human Services is still prohibited from imposing civil penalties (except in cases of willful neglect) if the violation is corrected within 30 days (this time period may be extended). 7

9 Criminal Penalties: Simple Disclosure: fines up to $50,000 and/or up to 1 year in prison Disclosure under False Pretenses: fines up to $100,000 and/or up to 5 years in prison Disclosure with intent to sell or use: fines up to $250,000 and/or up to 10 years in prison HIPAA Information Security If your job duties require that you access the LSUHSC-S network or any hospital computer system, you will also be required to complete online HIPAA training. Even though you may not need access to the computer network to do your job, you still play an important role in the security of LSUHSC-S. Things you should not do: Look over the shoulders of people working at computers. Hold open the door to a secure area (like computer services) for someone you don t know. Try to hack or otherwise gain access to the network. Assist anyone who is trying to hack the network. Help anyone who asks you to find their password. Surf the internet with an unused computer. Some websites carry viruses that can disable the network. It also ties up network resources others need to do their jobs. Bring a computer from home and plug it into the network. 8

10 Things you should do: Always keep keys, access cards, and other security items in your possession. Never loan them out to anyone. If you wish to be helpful to someone who does not have access to a secure area, escort him or her to someone within the secure area who can assist him or her in his or her needs. If you see an unattended computer with data displayed, bring it to the attention of the supervisor of that area. If a printout is left unattended on a printer or copier, bring it to the attention of the supervisor of that area. If you see someone you do not recognize using a computer or loitering around a computer, ask them politely if you can help them and escort them to someone who can make sure they get what they need. If they do not cooperate, notify campus police and your help desk. By following these simple rules, you are helping to ensure that the data of our faculty, staff, patients, and students is kept secure and confidential. Where can I find LSUHSC-S s HIPAA Policies? Compliance The False Claims Act: 31 U.S.C. Sections 3729 through 3730 The statute begins, in 3729(a), by explaining the conduct that creates False Claims Act (FCA) liability. The FCA imposes liability on any person who submits a claim to the federal government that he or she knows (or should know) is false. An example may be a physician who submits a bill to Medicare for medical services she knows she has not provided. The FCA also imposes liability on an individual who may knowingly submit a false record in order to obtain payment from the government. An example of this may include a government contractor who submits records that he knows (or should know) are false and that indicates compliance with certain contractual or regulatory requirements. 9

11 The third area of liability includes those instances in which someone may obtain money from the federal government to which he may not be entitled and then uses false statements or records in order to retain the money. An example of this so-called reverse false claim may include a hospital that obtains interim payments from Medicare throughout the year, and then knowingly files a false cost report at the end of the year in order to avoid making a refund to the Medicare program. The terms "know(s)" and "knowingly" mean that a person, with respect to information (1) has actual knowledge of the information; (2) acts in deliberate ignorance of the truth or falsity of the information; or (3) acts in reckless disregard of the truth or falsity of the information, and no proof of specific intent to defraud is required. Civil Penalties under the False Claims Act Violators of the FCA is liable to the United States Government for a civil penalty of not less than $5,000 and not more than $10,000, (those amounts are adjusted from time to time; the current amounts are $5,500 to $11,000) plus 3 times the amount of damages which the Government sustains because of the act of that person. Federal Whistleblower The FCA provides that private parties may bring an action on behalf of the United States, 31 U.S.C (b). These private parties, known as qui tam relators, may share in a percentage of the proceeds from an FCA action or settlement. Section 3730(d)(1) of the FCA provides, with some exceptions, that a qui tam relator, when the Government has intervened in the lawsuit, shall receive at least 15 percent but not more than 25 percent of the proceeds of the FCA action depending upon the extent to which the relator substantially contributed to the prosecution of the action. When the Government does not intervene, section 3730(d)(2) provides that the relator shall receive an amount that the court decides is reasonable and shall be not less than 25 percent and not more than 30 percent. Federal Whistleblower Protection Under Section 3730(h) of the FCA, any employee who is discharged, demoted, harassed, or otherwise discriminated against because of lawful acts by the employee in furtherance of an action under the Act is entitled to all relief necessary to make the employee whole. Such relief may include: Reinstatement Double back pay Compensation for any special damages including litigation costs and reasonable attorneys' fees 10

12 Louisiana State Law RS 46:437.3 through RS 46:440.3 Under Louisiana state law, the definition of a false or fraudulent claim is slightly broader, LSA R.S , 8 False or fraudulent claim" means a claim which the health care provider or his billing agent submits knowing the claim to be false, fictitious, untrue, or misleading in regard to any material information. The terms know(s) and knowingly mean that the person has actual knowledge of the information or acts in deliberate ignorance or reckless disregard of the truth or falsity of the information. State Whistleblower Just as with the federal whistleblower statute, under Louisiana state law, A private person may institute a civil action in the courts of this state on behalf of the medical assistance programs and himself to seek recovery for the violation. The institutor shall be known as a "qui tam plaintiff" and the civil action shall be known as a "qui tam action". Generally, if the secretary or the attorney general intervenes in the action brought by a qui tam plaintiff, the qui tam plaintiff shall receive at least ten percent, but not more than twenty percent, of recovery, exclusive of the civil monetary penalty provided in R.S. 46:439.6(C). In making a determination of award to the qui tam plaintiff, the court shall consider the extent to which the qui tam plaintiff substantially contributed to investigations and proceedings related to the qui tam action. A person who is or was a public employee or public official or a person who is or was acting on behalf of the state shall not bring a qui tam action if one of the following: The person has or had a duty or obligation to report, investigate, or pursue allegations of wrongdoing or misconduct by healthcare providers. The person had access to the records of the state through the normal course and scope of his employment relative to activities of healthcare providers. State Whistleblower Protection No employee shall be discharged, demoted, suspended, threatened, harassed, or discriminated against in any manner in the terms and conditions of his employment because of any lawful act engaged in by the employee or on behalf of the employee in furtherance of any action taken pursuant to this Part in regard to a health care provider or other person from whom recovery is or could be sought. Such an employee may seek any and all relief for his injury to which he is entitled under state or federal law. No individual shall be threatened, harassed, or discriminated against in any manner by a health care provider or other person because of any lawful act engaged in by the individual or on behalf of the individual in furtherance of any action taken pursuant to this Part in regard to a health care provider or 11

13 other person from whom recovery is or could be sought except that a health care provider may arrange for a recipient to receive goods, services, or supplies from another health care provider if the recipient agrees and the arrangement is approved by the secretary. Such an individual may seek any and all relief for his injury to which he is entitled under state or federal law. An employee of a private entity may bring his action for relief against his employer or the health care provider in the same court as the action or actions were brought pursuant to this Part or as part of an action brought pursuant to this Part. A qui tam plaintiff shall not be entitled to recovery pursuant to this Section if the court finds that the qui tam plaintiff instituted or proceeded with an action that was frivolous, vexatious, or harassing part of an action brought pursuant to this Part. Rewards for Fraud and Abuse Information State law provides that there may be a reward of up to two thousand dollars to an individual who submits information to the secretary which results in recovery pursuant to the provisions of this Part, provided such individual is not himself subject to recovery under this Part. It is every employee s responsibility to report suspected violations of the laws, regulations and policies, or other questionable conduct. Fraud Hurts Everyone! 12

NewYork-Presbyterian Hospital Sites: All Centers Hospital Policy and Procedure Manual Number: D160 Page 1 of 8

NewYork-Presbyterian Hospital Sites: All Centers Hospital Policy and Procedure Manual Number: D160 Page 1 of 8 Page 1 of 8 TITLE: FEDERAL DEFICIT REDUCTION ACT OF 2005 FRAUD AND ABUSE PROVISIONS POLICY: NewYork- Presbyterian Hospital (NYP or the Hospital) is committed to preventing and detecting any fraud, waste,

More information

Cardinal McCloskey Community Services. Corporate Compliance. False Claims Act and Whistleblower Provisions

Cardinal McCloskey Community Services. Corporate Compliance. False Claims Act and Whistleblower Provisions Cardinal McCloskey Community Services Corporate Compliance False Claims Act and Whistleblower Provisions Purpose: Cardinal McCloskey Community Services is committed to prompt, complete and accurate billing

More information

Effective Date: 1/01/07 N/A

Effective Date: 1/01/07 N/A North Shore-LIJ Health System is now Northwell Health POLICY TITLE: Detecting and Preventing Fraud, Waste, Abuse and Misconduct POLICY #: 800.09 System Approval Date: 03/30/2017 Site Implementation Date:

More information

Corporate Compliance Topic: False Claims Act and Whistleblower Provisions

Corporate Compliance Topic: False Claims Act and Whistleblower Provisions Purpose: INDEPENDENT LIVING, Inc. (also referred to as ILI, ) is committed to prompt, complete and accurate billing of all services provided to individuals. ILI and its employees, contractors and agents

More information

SOUTH NASSAU COMMUNITIES HOSPITAL One Healthy Way, Oceanside, NY 11572

SOUTH NASSAU COMMUNITIES HOSPITAL One Healthy Way, Oceanside, NY 11572 SOUTH NASSAU COMMUNITIES HOSPITAL One Healthy Way, Oceanside, NY 11572 POLICY TITLE: Compliance with Applicable Federal and State False Claims Acts POLICY NUMBER: OF-ADM-232 DEPARTMENT: Hospital-wide BACKGROUND/PURPOSE

More information

This policy applies to all employees, including management, contractors, and agents. For purpose of this policy, a contractor or agent is defined as:

This policy applies to all employees, including management, contractors, and agents. For purpose of this policy, a contractor or agent is defined as: Policy and Procedure: Corporate Compliance Topic: Purpose: Choice of NY is committed to prompt, complete, and accurate billing of all services provided to individuals. Choice of NY and its employees, contractors,

More information

SUNY DOWNSTATE MEDICAL CENTER POLICY AND PROCEDURE. No:

SUNY DOWNSTATE MEDICAL CENTER POLICY AND PROCEDURE. No: SUNY DOWNSTATE MEDICAL CENTER POLICY AND PROCEDURE Subject: Complying with the Deficit Reduction Act of 2005: Detection & Prevention of Fraud, Waste & Abuse Page 1 of 4 Prepared by: Shoshana Milstein Original

More information

AGENCY POLICY. IDENTIFICATION NUMBER: CCD001 DATE APPROVED: Nov 1, 2017 POLICY NAME: False Claims & Whistleblower SUPERSEDES: May 18, 2009

AGENCY POLICY. IDENTIFICATION NUMBER: CCD001 DATE APPROVED: Nov 1, 2017 POLICY NAME: False Claims & Whistleblower SUPERSEDES: May 18, 2009 IDENTIFICATION NUMBER: CCD001 DATE APPROVED: Nov 1, 2017 POLICY NAME: False Claims & Whistleblower SUPERSEDES: May 18, 2009 Provisions OWNER S DEPARTMENT: Compliance APPLICABILITY: All Agency Programs

More information

DEFICIT REDUCTION ACT AND FALSE CLAIMS POLICY INFORMATION FOR All NEW YORK WORKFORCE MEMBERS

DEFICIT REDUCTION ACT AND FALSE CLAIMS POLICY INFORMATION FOR All NEW YORK WORKFORCE MEMBERS DEFICIT REDUCTION ACT AND FALSE CLAIMS POLICY INFORMATION FOR All NEW YORK WORKFORCE MEMBERS The Company is committed to preventing health care fraud, waste and abuse and complying with applicable state

More information

Clinical and Administrative Policies and Procedures

Clinical and Administrative Policies and Procedures Clinical and Administrative Policies and Procedures Purpose: Centerstone is committed to its role in preventing health care fraud and abuse and complying with applicable state and federal law related to

More information

Effective Date: 5/31/2007 Reissue Date: 10/08/2018. I. Summary of Policy

Effective Date: 5/31/2007 Reissue Date: 10/08/2018. I. Summary of Policy Issuing Department: Internal Audit, Compliance, and Enterprise Risk Management Preventing Fraud, Waste, and Abuse: Federal and State False Claims and False Statements Effective Date: 5/31/2007 Reissue

More information

DEFICIT REDUCTION ACT AND FALSE CLAIMS POLICY INFORMATION FOR All MASSACHUSETTS WORKFORCE MEMBERS

DEFICIT REDUCTION ACT AND FALSE CLAIMS POLICY INFORMATION FOR All MASSACHUSETTS WORKFORCE MEMBERS DEFICIT REDUCTION ACT AND FALSE CLAIMS POLICY INFORMATION FOR All MASSACHUSETTS WORKFORCE MEMBERS The Company is committed to preventing health care fraud, waste and abuse and complying with applicable

More information

UAMS ADMINISTRATIVE GUIDE NUMBER: 2.1

UAMS ADMINISTRATIVE GUIDE NUMBER: 2.1 UAMS ADMINISTRATIVE GUIDE NUMBER: 2.1.12 DATE: 04/01/2003 REVISION: 3/1/2004; 12/28/2010; 01/02/2013 PAGE: 1 of 18 SECTION: HIPAA AREA: HIPAA PRIVACY/SECURITY POLICIES SUBJECT: HIPAA RESEARCH POLICY PURPOSE

More information

False Claims Liability, Anti-Retaliation Protections, and Detecting and Responding to Fraud, Waste, and Abuse

False Claims Liability, Anti-Retaliation Protections, and Detecting and Responding to Fraud, Waste, and Abuse False Claims Liability, Anti-Retaliation Protections, and Detecting and Responding to Fraud, Waste, and 1. SCOPE 1.1 System-wide, including Marshfield Clinic Health System (MCHS), Inc. and its affiliated

More information

Federal and State False Claims Act Education Policy

Federal and State False Claims Act Education Policy *TEAMHealth Policies and Procedures Policy Name: Federal and State False Claims Act Education Policy Effective Date: January 1, 2017 Approved By: Executive Compliance Committee Replaces Policy Dated: January

More information

HILLSBOROUGH COUNTY HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) PROCEDURES

HILLSBOROUGH COUNTY HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) PROCEDURES HILLSBOROUGH COUNTY HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) PROCEDURES July 1, 2017 Table of Contents Section 1 - Statement of Commitment to Compliance... 3 Section 2 General Guidelines

More information

Corporate Compliance Program. Intended Audience: All SEH Associates 2016 Content Expert: Lisa Frey -

Corporate Compliance Program. Intended Audience: All SEH Associates 2016 Content Expert: Lisa Frey - Corporate Compliance Program Intended Audience: All SEH Associates 2016 Content Expert: Lisa Frey - lisa.frey@stelizabeth.com Developed 2012, reviewed Dec 2015 What is Corporate Compliance? Hospitals,

More information

University of California Group Health and Welfare Benefit Plans HIPAA Privacy Rule Policies and Procedures (Interim)

University of California Group Health and Welfare Benefit Plans HIPAA Privacy Rule Policies and Procedures (Interim) Group Insurance Regulations Administrative Supplement No. 19 April 2003 University of California Group Health and Welfare Benefit Plans HIPAA Privacy Rule Policies and Procedures (Interim) The University

More information

Limited Data Set Data Use Agreement For Research

Limited Data Set Data Use Agreement For Research Limited Data Set Data Use Agreement For Research This Data Use Agreement is dated,, and is between the ( Recipient ) and University of Miami, ( Covered Entity ). This Data Use Agreement is made in accordance

More information

THE NEW YORK FOUNDLING

THE NEW YORK FOUNDLING THE NEW YORK FOUNDLING COMMITMENT TO COMPLIANCE HANDBOOK CODE OF CONDUCT AND COMPLIANCE STANDARDS COMPLIANCE PROGRAM STRUCTURE AND GUIDELINES POLICIES AND PROCEDURES December 2012 COMMITMENT TO COMPLIANCE

More information

Texas Tech University Health Sciences Center HIPAA Privacy Policies

Texas Tech University Health Sciences Center HIPAA Privacy Policies Administration Policy 1.1 Glossary of Terms - HIPAA Effective Date: January 15, 2015 Reviewed Date: August 7, 2017 References: http://www.hhs.gov/ocr/hippa HSC HIPAA website http://www.ttuhsc.edu/hipaa/policies_procedures.aspx

More information

Charging, Coding and Billing Compliance

Charging, Coding and Billing Compliance GWINNETT HEALTH SYSTEM CORPORATE COMPLIANCE Charging, Coding and Billing Compliance 9510-04-10 Original Date Review Dates Revision Dates 01/2007 05/2009, 09/2012 POLICY Gwinnett Health System, Inc. (GHS),

More information

FEDERAL DEFICIT REDUCTION ACT POLICY

FEDERAL DEFICIT REDUCTION ACT POLICY A. Introduction. FEDERAL DEFICIT REDUCTION ACT POLICY Partnership for Children of Essex, Inc. (referred to herein as the Organization ) has instituted this Federal Deficit Reduction Act Policy as part

More information

Texas Tech University Health Sciences Center El Paso HIPAA Privacy Policies

Texas Tech University Health Sciences Center El Paso HIPAA Privacy Policies Administration Policy 1.1 Glossary of Terms - HIPAA Effective Date: January 15, 2015 References: http://www.hhs.gov/ocr/hipaa TTUHSC El Paso HIPAA website: http://elpaso.ttuhsc.edu/hipaa/ Policy Statement

More information

Policy to Provide Information for Combating Fraud, Waste and Abuse and the Ability of Employees to Report Wrongdoing

Policy to Provide Information for Combating Fraud, Waste and Abuse and the Ability of Employees to Report Wrongdoing 1 of 8 and Abuse and the Ability of Employees to Report Wrongdoing 1. Purpose The purpose of this policy is to provide information for combating fraud, waste and abuse and the ability of employees to report

More information

JAMAICA HOSPITAL MEDICAL CENTER

JAMAICA HOSPITAL MEDICAL CENTER JAMAICA HOSPITAL MEDICAL CENTER COMMITMENT TO COMPLIANCE CODE OF CONDUCT AND COMPLIANCE PROGRAM SUMMARY SEPTEMBER 2009 REVIEWED: 3/12, 9/13, 5/14, 6/15 REVISED: 8/12, 8/16, 7/17, 2/18 COMMITMENT TO COMPLIANCE

More information

ChoiceNet/InterCare Health Plans Getting Your Arms Around HIPAA Compliance

ChoiceNet/InterCare Health Plans Getting Your Arms Around HIPAA Compliance ChoiceNet/InterCare Health Plans Getting Your Arms Around HIPAA Compliance The enclosed packet includes basic HIPAA Privacy Rule information, Amendments for your health care plan, identified action items

More information

Federal Deficit Reduction Act of 2005, Section 6032 on Fraud, Waste, and Abuse

Federal Deficit Reduction Act of 2005, Section 6032 on Fraud, Waste, and Abuse Policy Number: 4003 Page: 1 of 8 POLICY: It is the policy of Bridgeway Rehabilitation Services, Inc. to obey all federal and state laws and to implement and enforce procedures to detect and prevent fraudulent

More information

THE CITY AND COUNTY OF SAN FRANCISCO SECTION 125 CAFETERIA PLAN HIPAA PRIVACY POLICIES & PROCEDURES

THE CITY AND COUNTY OF SAN FRANCISCO SECTION 125 CAFETERIA PLAN HIPAA PRIVACY POLICIES & PROCEDURES THE CITY AND COUNTY OF SAN FRANCISCO SECTION 125 CAFETERIA PLAN HIPAA PRIVACY POLICIES & PROCEDURES Effective: November 8, 2012 Terms used, but not otherwise defined, in this Policy and Procedure have

More information

False Claims Act and Whistleblower Protections

False Claims Act and Whistleblower Protections False Claims Act and Protections Date Implemented: 1/28/2009 Date Reviewed/ Revised: 9/5/2017 Reviewed/ Revised By: SR/KBJ Purpose: To satisfy requirements to provide information and education about False

More information

EVMS Medical Group A. RESEARCH USE AND OR DISCLOSURE WITHOUT AUTHORIZATION:

EVMS Medical Group A. RESEARCH USE AND OR DISCLOSURE WITHOUT AUTHORIZATION: Page 1 of 8 Definitions: Research Research is defined as systematic investigation, including the research development, testing, and evaluation, designed to develop or contribute to generalizable knowledge

More information

C. Enrollees: A Medicaid beneficiary who is currently enrolled in the MCCMH PIHP.

C. Enrollees: A Medicaid beneficiary who is currently enrolled in the MCCMH PIHP. professionally recognized standards for health care. It also includes beneficiary practices that result in unnecessary cost to the Medicaid program. 42 CFR 455.2 B. CMS: Centers for Medicare & Medicaid

More information

Certifying Employee Training Navicent Health s Corporate Integrity Agreement Year Two

Certifying Employee Training Navicent Health s Corporate Integrity Agreement Year Two Certifying Employee Training Navicent Health s Corporate Integrity Agreement Year Two Corporate Integrity Agreement Effective 4/23/2015 Term of five years Basic Requirement: Maintain a Compliance Program

More information

UBMD Policy for HIPAA Compliant Subject Recruitment

UBMD Policy for HIPAA Compliant Subject Recruitment UBMD Policy for HIPAA Compliant Subject Recruitment Approved by Executive Committee on December 5, 2016 I. Statement of Purpose This policy is applicable in the situation where the Principle Researcher

More information

Anti-Fraud Policy. The following non-exhaustive list provides a few examples of fraud that this Policy is designed to prevent and detect:

Anti-Fraud Policy. The following non-exhaustive list provides a few examples of fraud that this Policy is designed to prevent and detect: Introduction Anti-Fraud Policy In some instances, Medicaid pays for some or all of the services provided. It is the policy of Helper s Inc. to comply with all applicable federal, state and local laws and

More information

COMPLIANCE TRAINING 2015 C O M P L I A N C E P R O G R A M - F W A - H I P A A - C O D E O F C O N D U C T

COMPLIANCE TRAINING 2015 C O M P L I A N C E P R O G R A M - F W A - H I P A A - C O D E O F C O N D U C T COMPLIANCE TRAINING 2015 QUALITY MANAGEMENT COMPLIANCE DEPARTMENT 2015 C O M P L I A N C E P R O G R A M - F W A - H I P A A - C O D E O F C O N D U C T Compliance Program why? Ensure ongoing education

More information

Current Status: Active PolicyStat ID: Fraud, Waste and Abuse

Current Status: Active PolicyStat ID: Fraud, Waste and Abuse Current Status: Active PolicyStat ID: 2397820 Policy Scope: Date Of Origin: 06/2015 Last Approved: 07/2016 Last Revised: 07/2016 Next Review: 07/2018 Sponsor: Policy Area: Regulatory Tags: Applicability:

More information

HIPAA FUNDAMENTALS For Substance abuse Treatment Industry

HIPAA FUNDAMENTALS For Substance abuse Treatment Industry HIPAA FUNDAMENTALS For Substance abuse Treatment Industry (c)firststepcounselingonline2014 1 At the conclusion of the course/unit/study the student will... ANALYZE THE EFFECTS OF TRANSFERING INFORMATION

More information

Vendor Information On Our Compliance Program

Vendor Information On Our Compliance Program Vendor Information On Our Compliance Program Version 1 April 13, 2009 Compliance Program Information for Vendors Table of Contents Page I. PURPOSE AND INTRODUCION 1 II. CODE OF CONDUCT: ETHICAL BEHAVIOR

More information

MEDISYS AMBULANCE SERVICES, INC.

MEDISYS AMBULANCE SERVICES, INC. MEDISYS AMBULANCE SERVICES, INC. COMMITMENT TO COMPLIANCE CODE OF CONDUCT AND COMPLIANCE PROGRAM SUMMARY OCTOBER 2009 REVIEWED: 4/12, 10/13, 5/14, 6/15 REVISED: 8/12, 8/16, 7/17, 2/18 COMMITMENT TO COMPLIANCE

More information

Effective Date: 4/3/17

Effective Date: 4/3/17 HIPAA AND HITECH ADM 067.4 Attachment D Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule and Security Rule Health Information Technology for Economic and Clinical Health (HITECH)

More information

HIPAA Insurance Portability Act HIPAA. HIPAA Privacy Rule - Education Module for Institutional Review Boards

HIPAA Insurance Portability Act HIPAA. HIPAA Privacy Rule - Education Module for Institutional Review Boards HIPAA Insurance Portability Act HIPAA HIPAA Privacy Rule - Education Module for Institutional Review Boards The HIPAA Privacy Rule protects the privacy and security of an individual s health information

More information

Section (Primary Department) Medicaid Special Investigations Unit. Effective Date Date of Last Review 01/30/2015 Department Approval/Signature :

Section (Primary Department) Medicaid Special Investigations Unit. Effective Date Date of Last Review 01/30/2015 Department Approval/Signature : Medicaid Special Investigations Unit Medicaid Business Unit Date of Last Revision Dept. Approval Date Policy applies to Medicaid products offered by health plans operating in the following State(s) California

More information

SUNY DOWNSTATE MEDICAL CENTER UNIVERSITY HOSPITAL OF BROOKLYN POLICY AND PROCEDURE

SUNY DOWNSTATE MEDICAL CENTER UNIVERSITY HOSPITAL OF BROOKLYN POLICY AND PROCEDURE SUNY DOWNSTATE MEDICAL CENTER UNIVERSITY HOSPITAL OF BROOKLYN POLICY AND PROCEDURE Subject: USE OF LIMITED DATA SETS Page 1 of 3 No. HIPAA-27 Original Issue Date: 12/2003 Prepared by: Shoshana Milstein

More information

What is a Compliance Program?

What is a Compliance Program? Course Objectives Learn about the most important elements of the compliance program; Increase awareness and effectiveness of our compliance program; Learn about the important laws and what the government

More information

HIPAA Training. HOPE Health Facility Administrators June 2013 Isaac Willett and Jason Schnabel

HIPAA Training. HOPE Health Facility Administrators June 2013 Isaac Willett and Jason Schnabel HIPAA Training HOPE Health Facility Administrators June 2013 Isaac Willett and Jason Schnabel Agenda HIPAA basics HITECH highlights Questions and discussion HIPAA Basics Legal Basics Health Insurance Portability

More information

UNDERSTANDING HIPAA & THE HITECH ACT. Heather Deixler, Esq. Associate, Morgan, Lewis & Bockius LLP

UNDERSTANDING HIPAA & THE HITECH ACT. Heather Deixler, Esq. Associate, Morgan, Lewis & Bockius LLP UNDERSTANDING HIPAA & THE HITECH ACT Heather Deixler, Esq. Associate, Morgan, Lewis & Bockius LLP 1 Objectives of Presentation Learn what HIPAA is Learn the purpose of HIPAA Understand who HIPAA regulates

More information

CORPORATE COMPLIANCE POLICY AND PROCEDURE

CORPORATE COMPLIANCE POLICY AND PROCEDURE Title: Fraud Waste and Abuse Laws in Health Care Policy # 1011 Sponsor: Corporate Compliance Approved by: Russell J. Matuszak, Interim Director, Corporate Compliance and Chief Privacy Officer Issued: Page:

More information

North Shore LIJ Health System, Inc. Facility Name. CATEGORY: Effective Date: 8/15/13

North Shore LIJ Health System, Inc. Facility Name. CATEGORY: Effective Date: 8/15/13 North Shore LIJ Health System, Inc. Facility Name POLICY TITLE: HIPAA Marketing and Sale of Protected Health Information Policy ADMINISTRATIVE POLICY AND PROCEDURE MANUAL POLICY #: 800.43 System Approval

More information

Health Insurance Portability and Accountability Act - HIPAA

Health Insurance Portability and Accountability Act - HIPAA What is HIPAA and what does it govern? Health Insurance Portability and Accountability Act of 1996 (HIPAA) Summary of Administrative Simplification Provisions In 1996, the Health Insurance Portability

More information

UNIVERSITY OF TENNESSEE HEALTH SCIENCE CENTER INSTITUTIONAL REVIEW BOARD USE OF PROTECTED HEALTH INFORMATION WITHOUT SUBJECT AUTHORIZATION

UNIVERSITY OF TENNESSEE HEALTH SCIENCE CENTER INSTITUTIONAL REVIEW BOARD USE OF PROTECTED HEALTH INFORMATION WITHOUT SUBJECT AUTHORIZATION UNIVERSITY OF TENNESSEE HEALTH SCIENCE CENTER INSTITUTIONAL REVIEW BOARD USE OF PROTECTED HEALTH INFORMATION WITHOUT SUBJECT AUTHORIZATION I. PURPOSE To provide guidance to investigators regarding the

More information

HIPAA s Medical Privacy Standards:

HIPAA s Medical Privacy Standards: HIPAA s Medical Privacy Standards: The Long and Really Winding Road Michael D. Bell, Esq. Mintz, Levin, Cohn, Ferris, Glovsky and Popeo, P.C. Washington, D.C. (202) 434-7481 mbell@mintz.com The Health

More information

Title: HP-53 Use and Disclosure of Protected Health Information for Purposes of Research. Department: Research

Title: HP-53 Use and Disclosure of Protected Health Information for Purposes of Research. Department: Research Title: HP-53 Use and Disclosure of Protected Health Information for Purposes of Research Department: Research I. STATEMENT OF POLICY In order for an investigator to use or disclose protected health information

More information

These restrictions apply to:

These restrictions apply to: These restrictions apply to: - LSUHSC-NO Institutionally-related foundations that are being used to raise funds on behalf of the LSU ( e.g. The LSUHSC-NO Foundation, alumni associations) - Any third-party

More information

FRAUD, WASTE, & ABUSE (FWA) for Brokers. revised 10/17

FRAUD, WASTE, & ABUSE (FWA) for Brokers. revised 10/17 FRAUD, WASTE, & ABUSE (FWA) for Brokers revised 10/17 OBJECTIVES After reviewing this information, you will be able to: Understand Fraud, Waste, and Abuse (FWA) training requirements; Be familiar with

More information

False Claims Prevention

False Claims Prevention False Claims Prevention POLICY STATEMENT It is the policy of Atrium Health & Senior Living ( Atrium ) to put into practice procedures designed to detect and prevent fraud, waste and abuse, and to maintain

More information

HIPAA Privacy Procedure #13

HIPAA Privacy Procedure #13 HIPAA Privacy Procedure #13 Uses or Disclosures of Protected Health Insurance Without a Verbal or Written Authorization Effective Date: April 14, 2003 Reviewed Date: February, 2011 Revised Date: Scope:

More information

HIPAA Privacy & Security. Transportation Providers 2017

HIPAA Privacy & Security. Transportation Providers 2017 HIPAA Privacy & Security Transportation Providers 2017 HIPAA Privacy & Security As a non emergency medical transportation provider, you deal directly with Medicare and Medicaid Members healthcare information

More information

This form cannot act as an authorization to assign commissions. Appointment Form Only. Steps to obtain an Appointment:

This form cannot act as an authorization to assign commissions. Appointment Form Only. Steps to obtain an Appointment: Appointment Form Only Steps to obtain an Appointment: Complete the Personal Information Sheet Entirely The Personal Information Sheet is used to obtain information necessary to establish an appointment

More information

Effective Date: 08/2013

Effective Date: 08/2013 POLICY/GUIDELINE TITLE: HIPAA Marketing and Sale of Protected Health Information Policy POLICY #: 800.43 System Approval Date: 5/18/18 Site Implementation Date: 6/17/18 Prepared by: ADMINISTRATIVE POLICY

More information

It s as AWESOME as You Think It Is!

It s as AWESOME as You Think It Is! It s as AWESOME as You Think It Is! Fine Print This presentation and any materials and/or comments are training and educational in nature only. They do not establish an attorney-client relationship, are

More information

NMH HIPAA Privacy Training Version

NMH HIPAA Privacy Training Version NMH HIPAA Privacy Training 2017 Version Training Objectives To gain a better understanding of: The Notice of Privacy Practices Access Monitoring Keeping Customer Information Private Minimum Necessary Requirements

More information

Regenstrief Center for Healthcare Engineering HIPAA Compliance Policy

Regenstrief Center for Healthcare Engineering HIPAA Compliance Policy Regenstrief Center for Healthcare Engineering HIPAA Compliance Policy Revised December 6, 2017 Table of Contents Statement of Policy 3 Reason for Policy 3 HIPAA Liaison 3 Individuals and Entities Affected

More information

Amy Bingham, Compliance Director Reviewed Only Date: 6/05,1/31/2011, 1/24/2012 Supersedes and replaces: "CC-02 - Anti-

Amy Bingham, Compliance Director Reviewed Only Date: 6/05,1/31/2011, 1/24/2012 Supersedes and replaces: CC-02 - Anti- MOLINA HEALTHCARE Polic:y and Procedure No. C 08 of Utah Effective Date: November 2003 Reviewed and Revised Ollie: 2/6/08; 2/25/0S; 11 /5/0S; II/ IS/OS, 3/4/09, 6/9/09, S/31 / 1O Amy Bingham, Compliance

More information

University of Mississippi Medical Center Data Use Agreement Protected Health Information

University of Mississippi Medical Center Data Use Agreement Protected Health Information Data Use Agreement Protected Health Information This Data Use Agreement ( DUA ) is effective on the day of, 20, ( Effective Date ) by and between University of Mississippi Medical Center (UMMC) ( Data

More information

UCLA Health System Data Use Agreement

UCLA Health System Data Use Agreement UCLA Health System Data Use Agreement The federal Health Insurance Portability and Accountability Act and the regulations promulgated thereunder (collectively referred to as the Privacy Rule ) permit the

More information

Montefiore Medical Center Compliance Program. Welcome House Staff Orientation

Montefiore Medical Center Compliance Program. Welcome House Staff Orientation Montefiore Medical Center Compliance Program Welcome House Staff Orientation The Healthcare Industry Government is largest payor. Perception that $100 Billion Dollars per year lost because of on healthcare

More information

Cedargate Health Care COMPLIANCE PROGRAM MANUAL CODE OF CONDUCT AND COMPLIANCE GUIDELINES

Cedargate Health Care COMPLIANCE PROGRAM MANUAL CODE OF CONDUCT AND COMPLIANCE GUIDELINES Cedargate Health Care COMPLIANCE PROGRAM MANUAL CODE OF CONDUCT AND COMPLIANCE GUIDELINES Page 1 of 18 OUR MISSION AND VALUES Cedargate Health Care is committed not only to providing residents with high

More information

"HIPAA RULES AND COMPLIANCE"

HIPAA RULES AND COMPLIANCE PRESENTER'S GUIDE "HIPAA RULES AND COMPLIANCE" Training for HIPAA REGULATIONS Quality Safety and Health Products, for Today...and Tomorrow OUTLINE OF MAJOR PROGRAM POINTS OUTLINE OF MAJOR PROGRAM POINTS

More information

Approval Signatures: *This policy is based on VO legacy policy LC310 issued 12/4/06 and last approved 3/14/14

Approval Signatures: *This policy is based on VO legacy policy LC310 issued 12/4/06 and last approved 3/14/14 Category: A Page 1 of 5 Beacon Health Options Policies and Procedure cover the operations of all entities within the BVO Holdings, LLC corporate structure, including but not limited to Beacon Health Strategies

More information

HIPAA HEALTH INSURANCE PORTABILITY & ACCOUNTABILITY ACT

HIPAA HEALTH INSURANCE PORTABILITY & ACCOUNTABILITY ACT HIPAA HEALTH INSURANCE PORTABILITY & ACCOUNTABILITY ACT HIPAA OMNIBUS FINAL RULE HITECH GINA TERMINOLOGY OMNIBUS FINAL RULE Issued January 23, 2013 Effective March 26, 2013 Modified HIPAA privacy and security

More information

HIPAA Policy 5032 Statement of Policy on Use and Disclosure of Protected Health Information for Research Purposes

HIPAA Policy 5032 Statement of Policy on Use and Disclosure of Protected Health Information for Research Purposes HIPAA Policy 5032 Statement of Policy on Use and Disclosure of Protected Health Information for Research Purposes Responsible Office Provost Effective Date 04/14/03 Responsible Official Privacy Officer

More information

Compliance Fraud, Waste and Abuse HIPAA Privacy and Security

Compliance Fraud, Waste and Abuse HIPAA Privacy and Security 2017 Compliance Fraud, Waste and Abuse HIPAA Privacy and Security Table of Contents/Agenda Welcome to General Compliance Training for Providers! Training Objectives: Understand why you need Compliance

More information

HIPAA PRIVACY AND SECURITY AWARENESS

HIPAA PRIVACY AND SECURITY AWARENESS HIPAA PRIVACY AND SECURITY AWARENESS Introduction The Health Insurance Portability and Accountability Act (known as HIPAA) was enacted by Congress in 1996. HIPAA serves three main purposes: To protect

More information

Saint Louis University Notice of Privacy Practices Effective Date: April 14, 2003 Amended: September 22, 2013

Saint Louis University Notice of Privacy Practices Effective Date: April 14, 2003 Amended: September 22, 2013 Saint Louis University Notice of Privacy Practices Effective Date: April 14, 2003 Amended: September 22, 2013 This notice describes how medical information about you may be used and disclosed and how you

More information

POLICY & PROCEDURE. Policy Title: False Claims Prevention Effective Date: 3/20/2013. Department: Compliance Policy Number: N/A

POLICY & PROCEDURE. Policy Title: False Claims Prevention Effective Date: 3/20/2013. Department: Compliance Policy Number: N/A PURPOSE The purpose of this policy is to comply with certain requirements set for in the Deficit Reduction Act of 2005 with regard to federal and state false claims laws. SCOPE This policy applies to all

More information

7 ATLzr UNIVERSITY OF CALIFORNIA. January 30, 2014

7 ATLzr UNIVERSITY OF CALIFORNIA. January 30, 2014 UNIVERSITY OF CALIFORNIA BEPKELEY DAVIS IRVINE LOS ANGELES MERCED RIVERSIDE SAN DIEGO SAN FRANCISCO 4 SANTA BAREARA SANTA CRUZ CHANCELLORS MEDICAL CENTER CHIEF EXECUTIVE OFFICERS LAWRENCE BERKELEY NATIONAL

More information

HIPAA Basics: IMPORTANT HIPAA CONCEPTS. What We re going to Cover. Training for Employee Benefits Staff

HIPAA Basics: IMPORTANT HIPAA CONCEPTS. What We re going to Cover. Training for Employee Benefits Staff HIPAA Basics: Training for Employee Benefits Staff March 25, 2015 Norbert F. Kugele nkugele@wnj.com 616.752.2186 April A. Goff agoff@wnj.com 616.752.2154 What We re going to Cover Important HIPAA concepts

More information

Hayden W. Shurgar HIPAA: Privacy, Security, Enforcement, HITECH, and HIPAA Omnibus Final Rule

Hayden W. Shurgar HIPAA: Privacy, Security, Enforcement, HITECH, and HIPAA Omnibus Final Rule Hayden W. Shurgar HIPAA: Privacy, Security, Enforcement, HITECH, and HIPAA Omnibus Final Rule 1 IMPORTANCE OF STAFF TRAINING HIPAA staff training is a key, required element in a covered entity's HIPAA

More information

In this course, we will cover the following topics: The structure and purpose of Navicent Health s Compliance Program The requirements of the

In this course, we will cover the following topics: The structure and purpose of Navicent Health s Compliance Program The requirements of the In this course, we will cover the following topics: The structure and purpose of Navicent Health s Compliance Program The requirements of the Navicent Health s Corporate Integrity Agreement (CIA) Your

More information

HIPAA and Research at UB

HIPAA and Research at UB HIPAA and Research at UB Brian Murphy, MS Director, University at Buffalo HIPAA Compliance Office of the President Director, Health Professions IT Partnership Office of the VP for Health Affairs bwmurphy@buffalo.edu

More information

COLUMBIA UNIVERSITY INSTITUTIONAL REVIEW BOARD POLICY ON THE PRIVACY RULE AND THE USE OF HEALTH INFORMATION IN RESEARCH

COLUMBIA UNIVERSITY INSTITUTIONAL REVIEW BOARD POLICY ON THE PRIVACY RULE AND THE USE OF HEALTH INFORMATION IN RESEARCH COLUMBIA UNIVERSITY INSTITUTIONAL REVIEW BOARD POLICY ON THE PRIVACY RULE AND THE USE OF HEALTH INFORMATION IN RESEARCH I. Background The Health Insurance Portability and Accountability Act of 1996 (as

More information

D E B R A S C H U C H E R T, C O M P L I A N C E O F F I C E R

D E B R A S C H U C H E R T, C O M P L I A N C E O F F I C E R D E B R A S C H U C H E R T, C O M P L I A N C E O F F I C E R INTEGRATED CARE ALLIANCE, LLC CORPORATE COMPLIANCE PROGRAM It is the policy of Integrated Care Alliance to comply with all laws governing

More information

Region 10 PIHP FY Corporate Compliance Program Plan

Region 10 PIHP FY Corporate Compliance Program Plan Region 10 PIHP FY 2018 Corporate Compliance Program Plan 1 Mission The purpose of the Region 10 Corporate Compliance Program Plan is to provide quality care for all the individuals it serves by acting

More information

Long Island Neurology Consultants NOTICE OF PRIVACY PRACTICES

Long Island Neurology Consultants NOTICE OF PRIVACY PRACTICES Long Island Neurology Consultants NOTICE OF PRIVACY PRACTICES EFFECTIVE DATE: THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION.

More information

~Cityof. ~~Corpu~ ~.--=.;: ChnstI City Policies HR29.0 NO.

~Cityof. ~~Corpu~ ~.--=.;: ChnstI City Policies HR29.0 NO. ~Cityof ~~Corpu~ ~.--=.;: ChnstI City Policies SUBJECT: Health Insurance Portability & Accountability Act (HIPPA) Privacy Policies & Procedures NO. HR29.0 Effective: 04/14/2003 Revised: 01117/2005 APPROVED:

More information

STANDARDS OF CONDUCT

STANDARDS OF CONDUCT STANDARDS OF CONDUCT OVERVIEW At PacificSource Community Health Plans, Inc. and PacificSource Community Solutions, Inc. (collectively, PacificSource), our mission is to fully comply with all applicable

More information

The False Claims Act and Off-Label Promotion: Understanding and Minimizing the Risks for Pharmaceutical Manufacturers

The False Claims Act and Off-Label Promotion: Understanding and Minimizing the Risks for Pharmaceutical Manufacturers 4th Annual Pharmaceutical Regulatory Congress November 12, 2003 The False Claims Act and Off-Label Promotion: Understanding and Minimizing the Risks for Pharmaceutical Manufacturers John T. Bentivoglio

More information

Another covered entity can be a business associate.

Another covered entity can be a business associate. HIPAA Cite Topic HIPAA Privacy Rule CFR 42 Cite 164.501 Definitions Business associate Designated record set for providers Disclosure Health oversight agency Individually identifiable health information

More information

VNSNY Compliance Orientation

VNSNY Compliance Orientation VNSNY Compliance Orientation 2016-2017 VNSNY COMPLIANCE ORIENTATION CONTENT 1. General Compliance Orientation Training a. Code of Conduct b. HIPAA c. HIV Confidentiality 2. Corporate Policies and Procedures

More information

Health Insurance Portability and Accountability Act Category: Administration 04/30/2015 Vice President for Legal Prior Effective Date:

Health Insurance Portability and Accountability Act Category: Administration 04/30/2015 Vice President for Legal Prior Effective Date: Policy Title: Policy Number: Health Insurance 1.8.4 Portability and Accountability Act Category: Effective Date: Policy Owner: Administration 04/30/2015 Vice President for Legal Prior Effective Date: Affairs

More information

HIPAA COMPLIANCE. for Small & Mid-Size Practices

HIPAA COMPLIANCE. for Small & Mid-Size Practices HIPAA COMPLIANCE for Small & Mid-Size Practices Golden State Web Solutions 619.825.GSWS (4797) INTRODUCTION Most individuals reading this are interested in HIPAA, GSWS, or some combination of the two;

More information

Presented by Marti Arvin Chief Compliance Officer UCLA Health Sciences

Presented by Marti Arvin Chief Compliance Officer UCLA Health Sciences Presented by Marti Arvin Chief Compliance Officer UCLA Health Sciences 1 Brief discussion of where we have been and where we are going Discussion of Federal Enforcement Actions Privacy and Security issue

More information

1. Does the plan exist for purposes of providing or paying for the cost of medical care?

1. Does the plan exist for purposes of providing or paying for the cost of medical care? HUMAN RESOURCES & BENEFITS INFORMATION HIPPA FLOW CHART Questions and Answers 1. Does the plan exist for purposes of providing or paying for the cost of medical care? A health plan could be an individual

More information

HIPAA: What Researchers Need to Know

HIPAA: What Researchers Need to Know HIPAA: What Researchers Need to Know The Health Insurance Portability and Accountability Act (HIPAA) protects individuals medical records from unauthorized use. Medical records, however, are often integral

More information

Executive Policy, EP HIPAA. Page 1 of 25

Executive Policy, EP HIPAA. Page 1 of 25 Executive Policy, EP 2.217 HIPAA Page 1 of 25 Executive Policy Chapter 2, Administration Executive Policy EP 2.217, HIPAA Policy Effective Date: June 2017 Prior Dates Amended: None Responsible Office:

More information

This course is designed to provide Part B providers with an overview of the Medicare Fraud and Abuse program including:

This course is designed to provide Part B providers with an overview of the Medicare Fraud and Abuse program including: This course is designed to provide Part B providers with an overview of the Medicare Fraud and Abuse program including: Medicare Trust Fund Defining Fraud & Abuse Examples of Fraud & Abuse Fraud & Abuse

More information

HIPAA Privacy Compliance Plan for Research. University of South Alabama IRB Guidance and Procedures

HIPAA Privacy Compliance Plan for Research. University of South Alabama IRB Guidance and Procedures HIPAA Privacy Compliance Plan for Research University of South Alabama IRB Guidance and Procedures Office of Research Compliance and Assurance CSAB 140 460-6625 Adopted: 4/2/2003 2 HIPAA PRIVACY COMPLIANCE

More information

Vendor Code of Business Conduct & Ethics

Vendor Code of Business Conduct & Ethics Dear Valued Vendor, Horizon Blue Cross Blue Shield of New Jersey, including its subsidiaries and affiliates (collectively, Horizon BCBSNJ ), operates under high standards of conduct and we comply with

More information

Self Funded Provider Manual. Self Funded Provider Manual 1. Section 8: Compliance

Self Funded Provider Manual. Self Funded Provider Manual 1. Section 8: Compliance Self Funded Provider Manual Section 8 Compliance Self Funded Provider Manual 1 Table of Contents 8 SECTION 8: COMPLIANCE... 3 8.1 COMPLIANCE WITH LAW... 3 8.2 KAISER PERMANENTE PRINCIPLES OF RESPONSIBILITY

More information