SlideShare a Scribd company logo
1 of 13
HIPAA
Privacy And Security
Presented by:
Michele Madison
Partner, Healthcare &
Healthcare IT Practices
Morris, Manning & Martin, LLP
mmadison@mmmlaw.com
Direct: 404-504-7621
Privacy and Security
2
HIPAA Omnibus Rule Purpose
3
Final Rule Addresses 4 Proposed Rules
Published in 2009 and 2010
1. Strengthen the HIPAA Privacy and Security Requirements
Mandated by HITECH (Proposed Rule July 2010)
• Strengthen Restrictions on Marketing and Fundraising Activities
• Enhanced Patient Rights on Access and Restricting Disclosures to
Health Plans
• Modify the Notice of Privacy Practices
• Modify the Authorization process
• Expands Direct Enforcement of HIPAA Requirements and Penalties
to Business Associates
HIPAA Omnibus Rule Purposes
4
2. Adopt changes to the Enforcement Rule (Proposed
October 2009)
• New Tiered Civil Monetary Penalties Standards
• Increased Monetary Penalties
3. Modifies the Breach Notification for Unsecured Protected
Health Information by replacing the breach notification
rule‘s ‗‗harm‘‘ threshold with a more objective standard.
(Proposed Rule August 2009 –supplanted)
4. Modifies HIPAA to conform with Genetic Information
Nondiscrimination Act
Important Dates and Laws
5
1. HIPAA – Privacy Rule Effective on April 14, 2003
Security Rule Effective on April 20, 2005
2. HITECH signed February 17, 2009
• Interim Final Rule on Breach of Unsecured PHI– August 24, 2009
and effective on September 23, 2009
• Interim Final Rule on Civil Monetary Penalty—October 30, 2009
and effective on November 30, 2009
• Proposed Rule on July 14, 2010
3. GINA 2008 – Proposed Rule to address HIPAA on
October 7, 2009
Effective Dates
6
Final Rule Provisions:
 Final Rule Effective on March 26, 2013
 Compliance Deadline September 23, 2013 (for
Privacy and Security)
 Business Associates flexible compliance date
standards
 Transition provisions permit time to address
documents and practices to establish compliance
Security Risk Assessment
7
 Ensure the full Risk Assessment has been completed
- Administrative
- Physical
- Technical Safeguards
 This is part of the Meaningful Use Requirements
Security Breach Notification
8
• Old standard: Notification required where ―significant risk of financial,
reputational, or other harm to individual‖. Burden was on CE or BA
to show there was no significant risk.
• New standard: Subject to certain existing exceptions, any access,
use or disclosure of unsecured PHI in violation of Privacy Rule is
presumed a breach unless demonstrate low probability that PHI has
been compromised based on risk assessment involving at least the
following factors:
– Nature and extent of PHI involved, including types of identifiers and likelihood of
re-identification
– Unauthorized person who used the PHI or to whom disclosure was made
– Whether PHI was actually acquired or viewed
– Extent to which risk to PHI has been mitigated
• Rule also eliminates exception for limited data sets that do not
contain dates of birth or zip codes.
Common Violations
9
 Of the 90,000 complaints investigated most are, compiled
cumulatively, in order of frequency:
 Impermissible uses and disclosures of protected health
information;
 Lack of safeguards of protected health information;
 Lack of patient access to their protected health information;
 Uses or disclosures of more than the minimum necessary
protected health information; and
 Lack of administrative safeguards of electronic protected
health information.
Most Common Violators
10
The most common types of covered entities that have been
required to take corrective action to achieve voluntary
compliance are, in order of frequency:
 PRIVATE PRACTICES;
 General Hospitals;
 Outpatient Facilities;
 Health Plans (group health plans and health insurance
issuers); and,
 Pharmacies.
Enforcement Activities
11
Adult & Pediatric Dermatology, P.C., of Concord,
Massachusetts (APDerm) -$150,000.00
Affinity Health Plan, Inc. will settle potential violations of the
Health Insurance Portability and Accountability Act of 1996
(HIPAA) Privacy and Security Rules for $1,215,780.
WellPoint Inc. has agreed to pay the U.S. Department of
Health and Human Services $1.7 million to settle potential
violations of the Health Insurance Portability and Accountability
Act of 1996 (HIPAA) Privacy and Security Rules
Major Steps to Take Now
12
• Evaluate BA and subcontractor status
• Evaluate BA and subcontractor agreements for compliance and
amend as appropriate
• Evaluate whether BAs and subcontractors are federal common law
agents
• Review Security Rule compliance
• Implement BA policies and procedures as appropriate—for example,
minimum necessary
• Amend security breach policies and procedures appropriately
• Ensure the Security Risk Assessment and policies are completed
and in effect
Questions
13
Michele Madison, Partner, Morris, Manning & Martin, LLP
Healthcare & Healthcare IT Practices
mmadison@mmmlaw.com
Direct: 404-504-7621

More Related Content

What's hot

Protecting patient privacy
Protecting patient privacyProtecting patient privacy
Protecting patient privacy
dlemin919
 
Hipaa and him security brunelle
Hipaa and him security brunelleHipaa and him security brunelle
Hipaa and him security brunelle
sjbusnpa
 
Complying with HIPAA Security Rule
Complying with HIPAA Security RuleComplying with HIPAA Security Rule
Complying with HIPAA Security Rule
complianceonline123
 
HIPAA Omnibus Presentation
HIPAA Omnibus PresentationHIPAA Omnibus Presentation
HIPAA Omnibus Presentation
Compliancy Group
 
Hi paa and eh rs
Hi paa and eh rsHi paa and eh rs
Hi paa and eh rs
supportc2go
 
HIPAA Compliance: Simple Steps to the Healthcare Cloud
HIPAA Compliance: Simple Steps to the Healthcare CloudHIPAA Compliance: Simple Steps to the Healthcare Cloud
HIPAA Compliance: Simple Steps to the Healthcare Cloud
Hostway|HOSTING
 

What's hot (20)

Compliance planning for hipaa 2
Compliance planning for hipaa 2Compliance planning for hipaa 2
Compliance planning for hipaa 2
 
Business Associates: How to become HIPAA compliant, increase revenue, and gai...
Business Associates: How to become HIPAA compliant, increase revenue, and gai...Business Associates: How to become HIPAA compliant, increase revenue, and gai...
Business Associates: How to become HIPAA compliant, increase revenue, and gai...
 
HIPAA Access Medical Records by Sainsbury-Wong
HIPAA Access Medical Records by Sainsbury-WongHIPAA Access Medical Records by Sainsbury-Wong
HIPAA Access Medical Records by Sainsbury-Wong
 
Protecting patient privacy
Protecting patient privacyProtecting patient privacy
Protecting patient privacy
 
Québec's Privacy Modernization: Bill 64
Québec's Privacy Modernization: Bill 64Québec's Privacy Modernization: Bill 64
Québec's Privacy Modernization: Bill 64
 
Hipaa and him security brunelle
Hipaa and him security brunelleHipaa and him security brunelle
Hipaa and him security brunelle
 
Firehost Webinar: Hipaa Compliance 101 Part 1
Firehost Webinar: Hipaa Compliance 101 Part 1Firehost Webinar: Hipaa Compliance 101 Part 1
Firehost Webinar: Hipaa Compliance 101 Part 1
 
Complying with HIPAA Security Rule
Complying with HIPAA Security RuleComplying with HIPAA Security Rule
Complying with HIPAA Security Rule
 
How to Ensure HIPPA Compliance
How to Ensure HIPPA ComplianceHow to Ensure HIPPA Compliance
How to Ensure HIPPA Compliance
 
HIPAA Omnibus Presentation
HIPAA Omnibus PresentationHIPAA Omnibus Presentation
HIPAA Omnibus Presentation
 
The Startup Path to HIPAA Compliance
The Startup Path to HIPAA ComplianceThe Startup Path to HIPAA Compliance
The Startup Path to HIPAA Compliance
 
HIPAA Compliant Cloud Computing, An Overview
HIPAA Compliant Cloud Computing, An OverviewHIPAA Compliant Cloud Computing, An Overview
HIPAA Compliant Cloud Computing, An Overview
 
Understanding HIPAA
Understanding HIPAAUnderstanding HIPAA
Understanding HIPAA
 
Hi paa and eh rs
Hi paa and eh rsHi paa and eh rs
Hi paa and eh rs
 
HIPAA Compliance: Simple Steps to the Healthcare Cloud
HIPAA Compliance: Simple Steps to the Healthcare CloudHIPAA Compliance: Simple Steps to the Healthcare Cloud
HIPAA Compliance: Simple Steps to the Healthcare Cloud
 
Dental Compliance for Dentists and Business Associates
Dental Compliance for Dentists and Business AssociatesDental Compliance for Dentists and Business Associates
Dental Compliance for Dentists and Business Associates
 
The importance of hipaa compliance and training
The importance of hipaa compliance and trainingThe importance of hipaa compliance and training
The importance of hipaa compliance and training
 
Hipaa omnibus presentation webinar
Hipaa omnibus presentation webinarHipaa omnibus presentation webinar
Hipaa omnibus presentation webinar
 
HealthCare Compliance - HIPAA and HITRUST
HealthCare Compliance - HIPAA and HITRUSTHealthCare Compliance - HIPAA and HITRUST
HealthCare Compliance - HIPAA and HITRUST
 
The Summary Guide to Compliance with the Kenya Data Protection Law
The Summary Guide to Compliance with the Kenya Data Protection Law The Summary Guide to Compliance with the Kenya Data Protection Law
The Summary Guide to Compliance with the Kenya Data Protection Law
 

Similar to Hipaa privacy and security 03192014

HIPAA Violations and Penalties power point
HIPAA Violations and Penalties power pointHIPAA Violations and Penalties power point
HIPAA Violations and Penalties power point
Deena Fetrow
 
The New HIPAA: Rules and Responsibilitues
The New HIPAA: Rules and ResponsibilituesThe New HIPAA: Rules and Responsibilitues
The New HIPAA: Rules and Responsibilitues
complianceexpert
 
Describe one safeguard that should be in place to protect the confid.pdf
Describe one safeguard that should be in place to protect the confid.pdfDescribe one safeguard that should be in place to protect the confid.pdf
Describe one safeguard that should be in place to protect the confid.pdf
mohammedfootwear
 

Similar to Hipaa privacy and security 03192014 (20)

Health Insurance Portability & Accountability Act (HIPAA)
Health Insurance Portability & Accountability Act (HIPAA)Health Insurance Portability & Accountability Act (HIPAA)
Health Insurance Portability & Accountability Act (HIPAA)
 
Hipaa omnibus
Hipaa omnibusHipaa omnibus
Hipaa omnibus
 
Executive Presentation on adhering to Healthcare Industry compliance
Executive Presentation on adhering to Healthcare Industry complianceExecutive Presentation on adhering to Healthcare Industry compliance
Executive Presentation on adhering to Healthcare Industry compliance
 
PanoMed HIPAA Omnibus Compendium
PanoMed HIPAA Omnibus CompendiumPanoMed HIPAA Omnibus Compendium
PanoMed HIPAA Omnibus Compendium
 
HIPAA Violations and Penalties power point
HIPAA Violations and Penalties power pointHIPAA Violations and Penalties power point
HIPAA Violations and Penalties power point
 
HIPAA Privacy & Security
HIPAA Privacy & SecurityHIPAA Privacy & Security
HIPAA Privacy & Security
 
HiPAA info
HiPAA infoHiPAA info
HiPAA info
 
Hipaa for business associates simple
Hipaa for business associates   simpleHipaa for business associates   simple
Hipaa for business associates simple
 
HIPAA Final Omnibus Rule Playbook
HIPAA Final Omnibus Rule PlaybookHIPAA Final Omnibus Rule Playbook
HIPAA Final Omnibus Rule Playbook
 
HIPAA/HITECH Requirements for FQHCs and the New Omnibus Rule
HIPAA/HITECH Requirements for FQHCs and the New Omnibus RuleHIPAA/HITECH Requirements for FQHCs and the New Omnibus Rule
HIPAA/HITECH Requirements for FQHCs and the New Omnibus Rule
 
PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...
PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...
PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...
 
Updated Healthcare Industry Compliance Presentation
Updated Healthcare Industry Compliance PresentationUpdated Healthcare Industry Compliance Presentation
Updated Healthcare Industry Compliance Presentation
 
The New HIPAA: Rules and Responsibilitues
The New HIPAA: Rules and ResponsibilituesThe New HIPAA: Rules and Responsibilitues
The New HIPAA: Rules and Responsibilitues
 
Hipaa in clinical trails
Hipaa in clinical trailsHipaa in clinical trails
Hipaa in clinical trails
 
Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017
 
Describe one safeguard that should be in place to protect the confid.pdf
Describe one safeguard that should be in place to protect the confid.pdfDescribe one safeguard that should be in place to protect the confid.pdf
Describe one safeguard that should be in place to protect the confid.pdf
 
HIPAA for Dummies
HIPAA for DummiesHIPAA for Dummies
HIPAA for Dummies
 
Healthcare and Cyber security
Healthcare and Cyber securityHealthcare and Cyber security
Healthcare and Cyber security
 
HIPAA and FDCPA Compliance for Process Servers
HIPAA and FDCPA Compliance for Process ServersHIPAA and FDCPA Compliance for Process Servers
HIPAA and FDCPA Compliance for Process Servers
 
Hipaa journal com - HIPAA compliance guide
Hipaa journal com - HIPAA compliance guideHipaa journal com - HIPAA compliance guide
Hipaa journal com - HIPAA compliance guide
 

More from Samantha Haas

Suleima salgado dph telehealth telemedicine presentation gpt conference_s_sal...
Suleima salgado dph telehealth telemedicine presentation gpt conference_s_sal...Suleima salgado dph telehealth telemedicine presentation gpt conference_s_sal...
Suleima salgado dph telehealth telemedicine presentation gpt conference_s_sal...
Samantha Haas
 

More from Samantha Haas (20)

Tammy carter troy spicer pp
Tammy carter troy spicer ppTammy carter troy spicer pp
Tammy carter troy spicer pp
 
Suleima salgado dph telehealth telemedicine presentation gpt conference_s_sal...
Suleima salgado dph telehealth telemedicine presentation gpt conference_s_sal...Suleima salgado dph telehealth telemedicine presentation gpt conference_s_sal...
Suleima salgado dph telehealth telemedicine presentation gpt conference_s_sal...
 
Savannah innovations
Savannah innovationsSavannah innovations
Savannah innovations
 
Savannah gpt
Savannah gptSavannah gpt
Savannah gpt
 
Paula guy gpt 3-27-2015
Paula guy   gpt 3-27-2015Paula guy   gpt 3-27-2015
Paula guy gpt 3-27-2015
 
Nsat mar2015
Nsat mar2015Nsat mar2015
Nsat mar2015
 
Michael osborne
Michael osborneMichael osborne
Michael osborne
 
Mario gutierrez georgia trc 2015 mario final
Mario gutierrez   georgia trc 2015 mario finalMario gutierrez   georgia trc 2015 mario final
Mario gutierrez georgia trc 2015 mario final
 
Kelly kesler gpt savannah aiha
Kelly kesler gpt savannah aihaKelly kesler gpt savannah aiha
Kelly kesler gpt savannah aiha
 
Kayla money's pp
Kayla money's ppKayla money's pp
Kayla money's pp
 
Joseph ebberwein 2015 gpt conference
Joseph ebberwein 2015 gpt conferenceJoseph ebberwein 2015 gpt conference
Joseph ebberwein 2015 gpt conference
 
Jonathan neufeld nuts and bolts
Jonathan neufeld   nuts and boltsJonathan neufeld   nuts and bolts
Jonathan neufeld nuts and bolts
 
Jessica aspinwall mumc telemedicine presentation
Jessica aspinwall mumc telemedicine presentationJessica aspinwall mumc telemedicine presentation
Jessica aspinwall mumc telemedicine presentation
 
Jerry kolosky gpt 032615 v2.0
Jerry kolosky   gpt 032615 v2.0Jerry kolosky   gpt 032615 v2.0
Jerry kolosky gpt 032615 v2.0
 
Jeff robbins tift regional-power point
Jeff robbins tift regional-power pointJeff robbins tift regional-power point
Jeff robbins tift regional-power point
 
Gpt logo slide
Gpt logo slideGpt logo slide
Gpt logo slide
 
Gpt 2015 conference exhibitor slide show
Gpt 2015 conference exhibitor slide showGpt 2015 conference exhibitor slide show
Gpt 2015 conference exhibitor slide show
 
Ellen bolch & max stachura advanced telehomecare
Ellen bolch & max stachura advanced telehomecareEllen bolch & max stachura advanced telehomecare
Ellen bolch & max stachura advanced telehomecare
 
Dr. zanga power point
Dr. zanga power pointDr. zanga power point
Dr. zanga power point
 
Dr. winston price decatur co telehealth march 26
Dr. winston price decatur co telehealth march 26Dr. winston price decatur co telehealth march 26
Dr. winston price decatur co telehealth march 26
 

Recently uploaded

College Call Girls in Haridwar 9667172968 Short 4000 Night 10000 Best call gi...
College Call Girls in Haridwar 9667172968 Short 4000 Night 10000 Best call gi...College Call Girls in Haridwar 9667172968 Short 4000 Night 10000 Best call gi...
College Call Girls in Haridwar 9667172968 Short 4000 Night 10000 Best call gi...
perfect solution
 
Russian Escorts Girls Nehru Place ZINATHI 🔝9711199012 ☪ 24/7 Call Girls Delhi
Russian Escorts Girls  Nehru Place ZINATHI 🔝9711199012 ☪ 24/7 Call Girls DelhiRussian Escorts Girls  Nehru Place ZINATHI 🔝9711199012 ☪ 24/7 Call Girls Delhi
Russian Escorts Girls Nehru Place ZINATHI 🔝9711199012 ☪ 24/7 Call Girls Delhi
AlinaDevecerski
 
Call Girls Aurangabad Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Aurangabad Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Aurangabad Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Aurangabad Just Call 8250077686 Top Class Call Girl Service Available
Dipal Arora
 

Recently uploaded (20)

College Call Girls in Haridwar 9667172968 Short 4000 Night 10000 Best call gi...
College Call Girls in Haridwar 9667172968 Short 4000 Night 10000 Best call gi...College Call Girls in Haridwar 9667172968 Short 4000 Night 10000 Best call gi...
College Call Girls in Haridwar 9667172968 Short 4000 Night 10000 Best call gi...
 
Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...
Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...
Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...
 
(👑VVIP ISHAAN ) Russian Call Girls Service Navi Mumbai🖕9920874524🖕Independent...
(👑VVIP ISHAAN ) Russian Call Girls Service Navi Mumbai🖕9920874524🖕Independent...(👑VVIP ISHAAN ) Russian Call Girls Service Navi Mumbai🖕9920874524🖕Independent...
(👑VVIP ISHAAN ) Russian Call Girls Service Navi Mumbai🖕9920874524🖕Independent...
 
Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...
Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...
Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...
 
All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...
All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...
All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...
 
Night 7k to 12k Navi Mumbai Call Girl Photo 👉 BOOK NOW 9833363713 👈 ♀️ night ...
Night 7k to 12k Navi Mumbai Call Girl Photo 👉 BOOK NOW 9833363713 👈 ♀️ night ...Night 7k to 12k Navi Mumbai Call Girl Photo 👉 BOOK NOW 9833363713 👈 ♀️ night ...
Night 7k to 12k Navi Mumbai Call Girl Photo 👉 BOOK NOW 9833363713 👈 ♀️ night ...
 
Top Rated Bangalore Call Girls Ramamurthy Nagar ⟟ 9332606886 ⟟ Call Me For G...
Top Rated Bangalore Call Girls Ramamurthy Nagar ⟟  9332606886 ⟟ Call Me For G...Top Rated Bangalore Call Girls Ramamurthy Nagar ⟟  9332606886 ⟟ Call Me For G...
Top Rated Bangalore Call Girls Ramamurthy Nagar ⟟ 9332606886 ⟟ Call Me For G...
 
Call Girls Kochi Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Kochi Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Kochi Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Kochi Just Call 8250077686 Top Class Call Girl Service Available
 
♛VVIP Hyderabad Call Girls Chintalkunta🖕7001035870🖕Riya Kappor Top Call Girl ...
♛VVIP Hyderabad Call Girls Chintalkunta🖕7001035870🖕Riya Kappor Top Call Girl ...♛VVIP Hyderabad Call Girls Chintalkunta🖕7001035870🖕Riya Kappor Top Call Girl ...
♛VVIP Hyderabad Call Girls Chintalkunta🖕7001035870🖕Riya Kappor Top Call Girl ...
 
Call Girls Cuttack Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Cuttack Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Cuttack Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Cuttack Just Call 9907093804 Top Class Call Girl Service Available
 
Pondicherry Call Girls Book Now 9630942363 Top Class Pondicherry Escort Servi...
Pondicherry Call Girls Book Now 9630942363 Top Class Pondicherry Escort Servi...Pondicherry Call Girls Book Now 9630942363 Top Class Pondicherry Escort Servi...
Pondicherry Call Girls Book Now 9630942363 Top Class Pondicherry Escort Servi...
 
Call Girls Coimbatore Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Coimbatore Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Coimbatore Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Coimbatore Just Call 9907093804 Top Class Call Girl Service Available
 
Russian Escorts Girls Nehru Place ZINATHI 🔝9711199012 ☪ 24/7 Call Girls Delhi
Russian Escorts Girls  Nehru Place ZINATHI 🔝9711199012 ☪ 24/7 Call Girls DelhiRussian Escorts Girls  Nehru Place ZINATHI 🔝9711199012 ☪ 24/7 Call Girls Delhi
Russian Escorts Girls Nehru Place ZINATHI 🔝9711199012 ☪ 24/7 Call Girls Delhi
 
Call Girls Ooty Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Ooty Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Ooty Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Ooty Just Call 8250077686 Top Class Call Girl Service Available
 
Call Girls Dehradun Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Dehradun Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Dehradun Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Dehradun Just Call 9907093804 Top Class Call Girl Service Available
 
Premium Bangalore Call Girls Jigani Dail 6378878445 Escort Service For Hot Ma...
Premium Bangalore Call Girls Jigani Dail 6378878445 Escort Service For Hot Ma...Premium Bangalore Call Girls Jigani Dail 6378878445 Escort Service For Hot Ma...
Premium Bangalore Call Girls Jigani Dail 6378878445 Escort Service For Hot Ma...
 
Call Girls Visakhapatnam Just Call 9907093804 Top Class Call Girl Service Ava...
Call Girls Visakhapatnam Just Call 9907093804 Top Class Call Girl Service Ava...Call Girls Visakhapatnam Just Call 9907093804 Top Class Call Girl Service Ava...
Call Girls Visakhapatnam Just Call 9907093804 Top Class Call Girl Service Ava...
 
Call Girls Aurangabad Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Aurangabad Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Aurangabad Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Aurangabad Just Call 8250077686 Top Class Call Girl Service Available
 
VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋
VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋
VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋
 
Call Girls Bareilly Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Bareilly Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Bareilly Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Bareilly Just Call 8250077686 Top Class Call Girl Service Available
 

Hipaa privacy and security 03192014

  • 1. HIPAA Privacy And Security Presented by: Michele Madison Partner, Healthcare & Healthcare IT Practices Morris, Manning & Martin, LLP mmadison@mmmlaw.com Direct: 404-504-7621
  • 3. HIPAA Omnibus Rule Purpose 3 Final Rule Addresses 4 Proposed Rules Published in 2009 and 2010 1. Strengthen the HIPAA Privacy and Security Requirements Mandated by HITECH (Proposed Rule July 2010) • Strengthen Restrictions on Marketing and Fundraising Activities • Enhanced Patient Rights on Access and Restricting Disclosures to Health Plans • Modify the Notice of Privacy Practices • Modify the Authorization process • Expands Direct Enforcement of HIPAA Requirements and Penalties to Business Associates
  • 4. HIPAA Omnibus Rule Purposes 4 2. Adopt changes to the Enforcement Rule (Proposed October 2009) • New Tiered Civil Monetary Penalties Standards • Increased Monetary Penalties 3. Modifies the Breach Notification for Unsecured Protected Health Information by replacing the breach notification rule‘s ‗‗harm‘‘ threshold with a more objective standard. (Proposed Rule August 2009 –supplanted) 4. Modifies HIPAA to conform with Genetic Information Nondiscrimination Act
  • 5. Important Dates and Laws 5 1. HIPAA – Privacy Rule Effective on April 14, 2003 Security Rule Effective on April 20, 2005 2. HITECH signed February 17, 2009 • Interim Final Rule on Breach of Unsecured PHI– August 24, 2009 and effective on September 23, 2009 • Interim Final Rule on Civil Monetary Penalty—October 30, 2009 and effective on November 30, 2009 • Proposed Rule on July 14, 2010 3. GINA 2008 – Proposed Rule to address HIPAA on October 7, 2009
  • 6. Effective Dates 6 Final Rule Provisions:  Final Rule Effective on March 26, 2013  Compliance Deadline September 23, 2013 (for Privacy and Security)  Business Associates flexible compliance date standards  Transition provisions permit time to address documents and practices to establish compliance
  • 7. Security Risk Assessment 7  Ensure the full Risk Assessment has been completed - Administrative - Physical - Technical Safeguards  This is part of the Meaningful Use Requirements
  • 8. Security Breach Notification 8 • Old standard: Notification required where ―significant risk of financial, reputational, or other harm to individual‖. Burden was on CE or BA to show there was no significant risk. • New standard: Subject to certain existing exceptions, any access, use or disclosure of unsecured PHI in violation of Privacy Rule is presumed a breach unless demonstrate low probability that PHI has been compromised based on risk assessment involving at least the following factors: – Nature and extent of PHI involved, including types of identifiers and likelihood of re-identification – Unauthorized person who used the PHI or to whom disclosure was made – Whether PHI was actually acquired or viewed – Extent to which risk to PHI has been mitigated • Rule also eliminates exception for limited data sets that do not contain dates of birth or zip codes.
  • 9. Common Violations 9  Of the 90,000 complaints investigated most are, compiled cumulatively, in order of frequency:  Impermissible uses and disclosures of protected health information;  Lack of safeguards of protected health information;  Lack of patient access to their protected health information;  Uses or disclosures of more than the minimum necessary protected health information; and  Lack of administrative safeguards of electronic protected health information.
  • 10. Most Common Violators 10 The most common types of covered entities that have been required to take corrective action to achieve voluntary compliance are, in order of frequency:  PRIVATE PRACTICES;  General Hospitals;  Outpatient Facilities;  Health Plans (group health plans and health insurance issuers); and,  Pharmacies.
  • 11. Enforcement Activities 11 Adult & Pediatric Dermatology, P.C., of Concord, Massachusetts (APDerm) -$150,000.00 Affinity Health Plan, Inc. will settle potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules for $1,215,780. WellPoint Inc. has agreed to pay the U.S. Department of Health and Human Services $1.7 million to settle potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules
  • 12. Major Steps to Take Now 12 • Evaluate BA and subcontractor status • Evaluate BA and subcontractor agreements for compliance and amend as appropriate • Evaluate whether BAs and subcontractors are federal common law agents • Review Security Rule compliance • Implement BA policies and procedures as appropriate—for example, minimum necessary • Amend security breach policies and procedures appropriately • Ensure the Security Risk Assessment and policies are completed and in effect
  • 13. Questions 13 Michele Madison, Partner, Morris, Manning & Martin, LLP Healthcare & Healthcare IT Practices mmadison@mmmlaw.com Direct: 404-504-7621