HIPAA Basics: IMPORTANT HIPAA CONCEPTS. What We re going to Cover. Training for Employee Benefits Staff

Similar documents
HIPAA Basic Training for Health & Welfare Plan Administrators

2016 Business Associate Workforce Member HIPAA Training Handbook

HIPAA PRIVACY REQUIREMENTS. Dana L. Thrasher Robert S. Ellerbrock, III Constangy, Brooks & Smith, LLP

HIPAA PRIVACY REQUIREMENTS. Dana L. Thrasher Constangy, Brooks & Smith, LLP (205)

HIPAA PRIVACY AND SECURITY AWARENESS

HIPAA Privacy Compliance Checklist

HIPAA The Health Insurance Portability and Accountability Act of 1996

ARE YOU HIP WITH HIPAA?

Texas Health and Safety Code, Chapter 181 Medical Records Privacy Law, HB 300

Breach Policy. Applicable Standards from the HITRUST Common Security Framework. Applicable Standards from the HIPAA Security Rule

Non-Union. Health Plan Notices IMPORTANT NOTICE

The Impact of Final Omnibus HIPAA/HITECH Rules. Presented by Eileen Coyne Clark Niki McCoy September 19, 2013

NOTIFICATION OF PRIVACY AND SECURITY BREACHES

"HIPAA RULES AND COMPLIANCE"

HIPAA Privacy Overview

Effective Date: 4/3/17

March 1. HIPAA Privacy Policy

University of California Group Health and Welfare Benefit Plans HIPAA Privacy Rule Policies and Procedures (Interim)

HIPAA Privacy & Security. Transportation Providers 2017

HIPAA / HITECH. Ed Massey Affiliated Marketing Group

Determining Whether You Are a Business Associate

EXCERPT. Do the Right Thing R1112 P1112

HIPAA FUNDAMENTALS For Substance abuse Treatment Industry

NATIONAL RECOVERY AGENCY COMPLIANCE INFORMATION GRAMM-LEACH-BLILEY SAFEGUARD RULE

JEFFERSON HEALTH CARE LINK ACCESS AGREEMENT

HIPAA: Impact on Corporate Compliance

HIPAA Compliance Under the Magnifying Glass

AMA Practice Management Center, What you need to know about the new health privacy and security requirements

CHAPTER 33 HIPAA PRIVACY REGULATIONS

AGREEMENT FOR ACCESS TO PROTECTED HEALTH INFORMATION

What Brown County employees need to know about the Federal legislation entitled the Health Insurance Portability and Accountability Act of 1996.

8/14/2013. HIPAA Privacy & Security 2013 Omnibus Final Rule update. Highlights from Final Rules January 25, 2013

HIPAA Privacy, Breach, & Security Rules

HIPAA Business Associate Agreement

1641 Tamiami Trail Port Charlotte, Fl Phone: Fax: Health Insurance Portability and Accountability Act of 1996

COMPLIANCE DEPARTMENT. LSUHSC-S Louisiana State University Health Sciences Center Shreveport ACKNOWLEDGEMENT RECEIPT

HIPAA PRIVACY RULE POLICIES AND PROCEDURES

Georgia Health Information Network, Inc. Georgia ConnectedCare Policies

ARTICLE 1. Terms { ;1}

OMNIBUS COMPLIANT BUSINESS ASSOCIATE AGREEMENT RECITALS

HIPAA Training. HOPE Health Facility Administrators June 2013 Isaac Willett and Jason Schnabel

SDM Health Insurance Portability and Accountability Act (HIPAA) Terms and Conditions For Business Associates

UCLA Policy 420: Breaches of Computerized Personal Information

Emma Eccles Jones College of Education & Human Services. Title: Business Associate Agreements

Regenstrief Center for Healthcare Engineering HIPAA Compliance Policy

HIPAA Privacy & Security Plan October 2016

MEMORANDUM. Health Care Information Privacy The HIPAA Regulations What Has Changed and What You Need to Know

DELHAIZE AMERICA PHARMACIES AND WELFARE BENEFIT PLAN HIPAA SECURITY POLICY (9/1/2016 VERSION)

Business Associate Agreement Health Insurance Portability and Accountability Act (HIPAA)

Do You Want To Know A Secret? HIPAA s Medical Privacy Regulations

Health Insurance Portability and Accountability Act - HIPAA

HIPAA Background and History

HIPAA Privacy and Security for Employers in the Age of Common Data Breaches. April 30, 2015

March 1. HIPAA Privacy Policy. This document includes: HIPAA Privacy Policy Statement, HIPAA Manual and HIPAA Forms

OLD DOMINION UNIVERSITY PCI SECURITY AWARENESS TRAINING OFFICE OF FINANCE

Safeguarding Your HIPAA and Personal Health Information Data. Robert Hess, Office of General Counsel Steve Cosentino, Stinson Morrison Hecker

UNDERSTANDING HIPAA & THE HITECH ACT. Heather Deixler, Esq. Associate, Morgan, Lewis & Bockius LLP

HIPAA Privacy Policy and Procedures Supplement for KP-IT

HIPAA and Lawyers: Your stakes have just been raised

HIPAA Compliance Guide

It s as AWESOME as You Think It Is!

What Does The New Omnibus HIPAA/HITECH Final Rule Really Mean For Employers And Their Service Providers?

Preparing for a HIPAA Audit & Hot Topics in Health Care Reform

Business Associate Agreement For Protected Healthcare Information

Privacy Rule - Complaint Investigations

HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT BUSINESS ASSOCIATE TERMS AND CONDITIONS

OCR Phase II Audit Protocol Breach Notification. HIPAA COW Spring Conference 2017 Page 1 Boerner Consulting, LLC

Health Insurance Portability and Accountability Act (HIPAA) Terms and Conditions For Business Associates

HITECH and HIPAA: Highlights for Health Departments. Aimee Wall UNC School of Government

To: Our Clients and Friends January 25, 2013

HIPAA COMPLIANCE ROADMAP AND CHECKLIST FOR BUSINESS ASSOCIATES

The wait is over HHS releases final omnibus HIPAA privacy and security regulations

NOTICE OF PRIVACY PRACTICES

HEALTH INFORMATION PRIVACY POLICIES & PROCEDURES

ACCESS TO ELECTRONIC HEALTH RECORDS AGREEMENT WITH THE DOCTORS CLINIC, PART OF FRANCISCAN MEDICAL GROUP

Privacy Sleuths: Solving the Mystery of Wellness Program Privacy Compliance. Agenda. Health Data Exposure National Wellness Conference

Central Florida Regional Transportation Authority Table of Contents A. Introduction...1 B. Plan s General Policies...4

2. HIPAA was introduced in There are many facets to the law. Which includes the facets of HIPAA that have been implemented?

New. To comply with HIPAA notice requirements, all Providence covered entities shall follow, at a minimum, the specifications described below.

Interim Date: July 21, 2015 Revised: July 1, 2015

HIPAA. Privacy Compliance Manual

SUBCONTRACTOR BUSINESS ASSOCIATE AGREEMENT

Healthcare Data Breaches: Handle with Care.

IACT Medical Trust. June 28, Jim Hamilton (317) HIPAA Privacy Training Bose McKinney & Evans LLP

HIPAA & HITECH Privacy & Security. Volunteer Annual Review 2017

Notice of Privacy Practices

Uses and Disclosures of Medical Information

HIPAA HEALTH INSURANCE PORTABILITY & ACCOUNTABILITY ACT

COMPLIANCE TRAINING 2015 C O M P L I A N C E P R O G R A M - F W A - H I P A A - C O D E O F C O N D U C T

HIPAA. What s New & What Do I Have To Do? Presented by Leslie Canham, CDA, RDA, CSP (Certified Speaking Professional)

Ottawa Children s Dentistry

The Privacy Rule. Health insurance Portability & Accountability Act

~Cityof. ~~Corpu~ ~.--=.;: ChnstI City Policies HR29.0 NO.

HIPAA Information. Who does HIPAA apply to? What are Sync.com s responsibilities? What is a Business Associate?

Credit Card Handling Security Standards

HIPAA Redux 2013 Kim Cavitt, AuD Audiology Resources, Inc. Expert e-seminar 4/29/2013. HIPAA Redux Presented by: Kim Cavitt, AuD

LIMITED DATA SET REQUEST AND DATA USE AGREEMENT

ARRA s Amendments to HIPAA Privacy & Security Rules

HIPAA AND ONLINE BACKUP WHAT YOU NEED TO KNOW ABOUT

SCHOOLS SELF-INSURANCE OF CONTRA COSTA COUNTY NOTICE OF PRIVACY PRACTICES

Transcription:

HIPAA Basics: Training for Employee Benefits Staff March 25, 2015 Norbert F. Kugele nkugele@wnj.com 616.752.2186 April A. Goff agoff@wnj.com 616.752.2154 What We re going to Cover Important HIPAA concepts HIPAA Privacy Rule requirements Safeguarding HIPAA Common HIPAA problems HIPAA penalties IMPORTANT HIPAA CONCEPTS 1

What Is HIPAA? Health Insurance Portability and Accountability Act of 1996. Limits who may use or disclose PHI. Limits the purposes for which PHI may be used or disclosed Limits the amount of information that may be used or disclosed (Minimum Necessary rule) Requires use of safeguards over how PHI is used, stored and disclosed Protected Health Information Individually identifiable health information used by a health plan or health care provider Any form: written, electronic or oral Includes information relating to: Physical health Mental health Payment for health care Protected Health Information Examples of PHI: Health plan claims records Health insurance policy numbers Claims appeal information Questions if procedures are covered by the plan Always assume that information you are handling is PHI! 2

HIPAA Regulations HIPAA Privacy Rules HIPAA Security Rules HIPAA Transaction Rules HIPAA Breach Notification Rules WHAT PLANS ARE SUBJECT TO HIPAA? Health Plans Subject to HIPAA Medical plans Dental plans Vision plans Health flexible spending accounts Employee assistance programs Wellness programs 3

What Is Not A Health Plan? Employment records Leaves of absence, FMLA records ADA claims On the job injuries Workers compensation Fitness for duty exams Drug screening What Is Not A Health Plan? Life insurance Disability (STD & LTD) Some wellness programs COMPLYING WITH HIPAA 4

Restrictions on PHI May not use or disclose PHI unless: The Privacy Rule specifically allows the use/disclosure; or The individual who is the subject of the PHI specifically allows it. Who May Use PHI? Workforce members trained on HIPAA privacy. You are only given access to PHI if you need it in order to perform your job You must agree to protect the confidentiality of the information You are subject to discipline if you violate your employer s privacy policies and procedures. Permitted Uses of PHI TPO Treatment Payment Health care operations Complying with law (but privacy officer must first approve) Any other use or disclosure generally requires authorization 5

Treatment Providing, coordinating & managing health care Includes: Direct treatment of patient Consultation among health care providers Indirect treatment (for example, laboratory testing) Patient referral from one provider to another Payment Activities by health plan to determine premiums and to pay claims Pre-certification Claims determination (including medical necessity determinations) Resolving claims appeals Coordination of benefits Determining COBRA rates Health Care Operations Activities directly related to payment and treatment: Case management, auditing, quality assessment, training programs Supporting activities such as computer systems support Administrative and managerial activities such as business planning, resolving complaints, and complying with HIPAA. 6

Minimum Necessary Rule Except for treatment purposes, must limit uses and disclosures of PHI to the minimum amount necessary to accomplish the intended purpose. Do not disclose more information than required Do not access information you don t need Business Associates Person or organization who: Performs a function or activity for the health plan; or Assists employer (or its business associate) in performing a health plan function or activity; and the Function or activity involves use, access, creation or disclosure of PHI. Employees are not business associates HMOs/insurers are not business associates Examples of Business Associates Third-party administrators (TPAs) Outside attorneys and accountants Computer service technicians Software vendors Cloud computing vendors Subcontractors of business associates 7

Individual Rights Access to PHI Request amendments of PHI Accounting of disclosures Request additional restrictions Request confidential communications Right to notification in the event of a breach SAFEGUARDING PROTECTED HEALTH INFORMATION Safeguarding PHI People consider health information their most confidential information, and we must protect it accordingly Do not access PHI that you do not need Do not discuss PHI with individuals who do not need to know it. Do not provide PHI to anyone not authorized to receive it Misusing PHI can result in discipline, legal penalties and loss of trust 8

Safeguarding PHI When using PHI, think about: Where you are Who might overhear Who might see Safeguarding PHI Avoid: Discussing PHI in front of others who do not need to know. Leaving records accessible to others who do not need to see them Positioning monitors/mobile devices where others can view them Using printers located in public or unsecured areas Safeguarding PHI Only share what needs to be shared (minimum necessary rule) What is the intended purpose for sharing the information? What is the least amount of information necessary to achieve the intended purpose? 9

Safeguarding PHI Communicating with health plan participants Do not leave detailed voicemail messages Avoid putting PHI in unencrypted email Use cover sheet when faxing PHI Safeguarding PHI Follow safe practices for your computer system ID and password Use strong passwords see your area administrator for guidelines Keep your user ID and password confidential and secure if you need to write it down, keep it in your wallet Do not allow anyone else to access the computer system under your ID Safeguarding PHI Handle health plan participant records with care: Secure storage Store paper records in rooms, cabinets, drawers that are locked when unattended. Keep devices that access electronic records secured/password protected Follow check-out/check-in requirements Do not leave records (or devices that can access records) lying around unattended Handle records to avoid disclosing information to others. 10

Safeguarding PHI Do not engage in risky practices with computers/devices used to access PHI Do not surf the internet Do not open attachments to or links in e- mail unless from a trusted source Do not install applications unless approved by the IT Department Do not save PHI to portable media that can be easily lost Safeguarding PHI Report unusual activity to your supervisor promptly You observe questionable practices You find PHI in inappropriate areas You suspect unauthorized use of your user ID/password A health plan participant complains to you about a privacy issue COMMON HIPAA PROBLEMS TO AVOID 11

Common HIPAA Problems Lost/stolen portable devices Paper documents that are lost or stolen Snooping into other people s records Discussing PHI in public areas Disclosing more PHI than necessary Ignoring individual requests to access records Common HIPAA Problems Failing to safeguard user IDs/passwords Placement of computer monitors. Opening e-mail attachments containing viruses/malware Missing security updates CONSEQUENCES OF VIOLATING HIPAA POLICIES AND PROCEDURES 12

Health Plan Liability HIPAA penalties: up to $1.5 million per year per violation State Attorneys General and FTC given enforcement authority HHS authorized to conduct audits Automatic audits in response to breaches involving at least 500 individuals Lawsuits for negligence or invasion of privacy Individual Consequences Subject to discipline up to and including termination. Criminal liability Up to 10 years in jail Up to $250,000 in criminal penalties Lawsuits by individuals who are harmed. QUESTIONS? Norbert F. Kugele nkugele@wnj.com 616.752.2186 April A. Goff agoff@wnj.com 616.752.2154 125263501-1 13