HIPAA & HITECH Made Easy for Behavioral Health Professionals -- Marlene Maheu


HIPAA & HITECH Made Easy for Behavioral Health Professionals

HIPAA & HITECH Made Easy for Behavioral Health Professionals
  HIPAA & HITECH Made Easy for Behavioral Health Professionals Marlene M. Maheu, Ph. D. Executive Director TeleMental Health Institute
  Disclaimer: I am an MFT and clinical psychologist, not an attorney, physician or Information technology specialist. My goal is educational only. The information I present is my best attempt to bring you timely and relevant information in a rapidly evolving area. I therefore make no warranty, guarantee, or representation as to the accuracy or sufficiency of the information contained in my training. My goal is to outline the issues and alert you to what's happening, including legal, ethical and other risk management issues. You are encouraged to seek specific advice related to your circumstance from your qualified authorities.
  Health Insurance Portability and Accountability Act (HIPAA) Three HIPAA Rules: Transmission * Privacy * Security
  HIPAA Privacy Rule: Data are ''individually identifiable'' if they include any of the 18 types of identifiers if the provider or researcher if the information could be used, either alone or in combination with other information, to identify an individual:
  HIPAA Privacy Rule (cont.): 2. Address (all geographic subdivisions smaller than state, including street address, city, county, zip code) 3. All elements (except years) of dates related to an individual (including birth date, admission date, discharge date, date of death and exact age if over 89) 4. Telephone numbers 5. Fax number 6. Email address 7. Social Security number 8. Medical record number 9. Health plan beneficiary number 10. Account number 11. Certificate/license number 12. Any vehicle or other device serial number 13. Device identifiers or serial numbers 14. Web URL 15. Internet Protocol (IP) address numbers 16. Finger or voice prints 17. Photographic images 18. Any other characteristic that could uniquely identify the individual
  HIPAA ''Final Rule": When HIPAA was first passed in 1996, most health care practitioners, hospitals and insurance companies scurried to bring themselves into compliance with the new standards. In the face of these final rules, business associates will have to engage in the same process. HHS is stepping up enforcement efforts. See Federal Register available online at http://federalregister.gov/a/2013-01073, and on FDsys.gov
  Intelligently discuss how HITECH relates to HIPAA
  HIPAA vs. HITECH: Health Information Technology for Economic and Clinical Health (HITECH Act) of 2009: * Applied privacy and security provisions and penalties to business associates * Imposed new breach notification requirements * Created stricter disclosure requirements, such as: * Limiting the disclosure of PHI the minimum necessary * Requiring health care providers to make available an accounting of certain disclosures when made at client/patient's request * Strengthening enforcement procedures and penalties
  Breach Reporting Requirements: If aware of a potential breach of protected health information: — Conduct risk assessment — Mitigate breaches * Purchase 1 year account to Equifax, Transunion or Experian — Report breach to affected clients, the federal government, and in some cases, the media
  Insurance Company Disclosures: Do not disclose treatment information to your client's health insurance carrier if they are paying you out-of-pocket, unless the disclosure is required by law
  Client/Patient Request for Records: Clients/patients may ask for copies of their electronic health records in electronic form and you must comply
  What makes you a "covered entity"?
  Covered Entity: The term "covered entity" under the HIPAA Privacy Rule refers to three specific groups, including health plans, health care clearinghouses, and health care providers that transmit health information electronically. Providers subject to the Privacy rule include: Doctors, Clinics, Psychologists, Dentists, Chiropractors, Nursing Homes, and Pharmacies. http://www.hrsa.gov/healthit/toolbox/HealthITAdoptiontoolbox/Privacyandsecurity/entityhipaa.html
  Explain why encryption is not adequate for HIPAA compliance
  HIPAA and Encryption: HIPAA sets many different types of standards * Technology does not need to be in compliance with those standards * Professionals have to be in compliance with the standards
  Name 5 little known, yet essential changes to HIPAA and HITECH as of January 2013
  HIPAA ''Final Rule": Infrastructure, documentation, and procedures for information privacy and security, and data encryption and disposal will have to be evaluated and brought into compliance. Companies need to provide formal security training to all employees, designate a security official and implement appropriate business associate contracts with their own subcontractors.
  HIPAA, Business Associates & HITECH: - All Business Associates in health care must sign an agreement stating their adherence to HIPAA standards - Transactions - Security - Privacy - True for any service you hire - This requirement is now enforced by the HITECH ACT
  HIPAA "Final Rule" January 17, 2013: Business associates of covered entities are directly liable for compliance with HIPAA Privacy and Security Rules' requirements. Includes contractors, subcontractors and business service companies working for health care providers, (e.g., companies providing electronic health records software, teleconferencing, data back-up and storage, billing, transcription and other IT services). Raises the maximum penalty for data breaches from a previous cap of $250,000 to a maximum penalty is $1.5 million per violation.
  Business Association Agreements: Remember to update Business Association Agreements (BAAs) — Contractors & subcontractors — Billing — Data storage — Office admins — Whomever has access
  HIPAA Policies: Use HIPAA compliant technologies and develop written processes — Document policies * Security & privacy policies — Repairs — Staff training — Breach notification, etc.
  Email: Send PHI in unencrypted e-mail only if the client/patient is advised of the risk and still requests use of email as a means of transmission
  Unencrypted Email: The new ethical standards released by the American Counseling Association (March, 2014) now state that counselors cannot have an initial contact with a potential client in email.
  Policies & Procedures: Implement or update privacy and security policies and procedures: * Need policies to be written (a paragraph is ok) * Staff education * Breach procedures — Consult your attorney — 500 or more records notify media
  Explain at least 2 warning against Skype by leading mental health professional associations
  Skype and Health Privacy: * Free * AES 265-bit encryption * Access to patient's environment BUT * Skype makes no claim that its services can be used in a HIPAA-compliant manner * Skype does not offer a BA Agreement * Cannot verify transmission security * Does not provide breach notification * Does not provide technical support * Frequently dropped calls — Emergencies? * No audit trails
  • 27. APA 2014 Skype Statement Li EMAIL 6 l"KlN I Home 1 Pracboeupdate » Practicaupdale — Apni 24. 2014 » Practitioner Folnler Does Ihe use of Practice Updlh I April 24, 2014 " l’-5‘ ‘r ‘L 1' 'APAteamawIInMlcmeofI to create mental health Thle new lawn mm on APA Practice omnluclon provides answers Irovn APA ‘mm ""009" ‘SW99 '" Practice atafl to common Inquirtee from members. ‘"9 °"“’°°"“ collaborative education By Legal and Regulatory Aliens stall pmgmm Given the growing use of tedlnology for communication. many practitioners are ' APAISI(ypa In the interested in knowing whether popular options are compatible with Health insurance daaaroom pmyet: ‘Let's Portability and Accountability Not (HIPAA) requirements. Skype. Msoee oeeic leatures Talk Aooul Mental Health‘ are free and easy to use, in one such option of interest to practidng psychologists. . Dwmon ‘B U“. HIPAA does not epeolly the itlnde at leamologlee that covered entities should use for lnleoonflmnclng for board creating. receiving, atotlng or transmitting electrorllc patient health information (ePl-ll). meetlng Under the HIPAA Security Rule. covered entities must conduct lndlvlduel risk assessment: about the technologies (hardware, software, etc. ) they use that store or tlanamlt QPHI. Skype does use enayption. a factor related to HIPAA Secunty Rule compinnce. Even ' “"3 °“°' " M” (279) so. that factor alone does not accommodate HIPAA requirements. ' web Page (201) The use at Skype raises several ooncems related to HIPAA ' Megaznne Article (147) First. liability for failure to comply with HIPAA is now shared equally by covered entities ' Journal (82) and business associates — third parties that provide aervicea to covered entities and . web M, ” (.5) mey have access to PHI. so It is critical tor practitioners to have business associate agreements In place. Yet Skype does not offer oualneee eaeoclate agreements for health we professionals who want to use It for teiehealth purposes. In fact, Mlcroeolt, whim owns Skwfi. did not mention Skype In Ila April 2013 press release announang its updated business 09‘ "'9 3m'u3"° http: //www. apapracticecentra| .or / update/2014/04-24/skype—hipaa. aspx
  American Psychological Association: 1. Practitioners need to have Business Associate's Agreements, but Skype doesn't offer BAAs 2. Lack of audit controls to monitor who is accessing ePHI 3. Lack of breach notification tools to alert users of unauthorized disclosures or access to ePHI
  HIPAA requires an "audit trail": Skype doesn't provide audit trails — and isn't obligated to
  HIPAA & Private Practices: From the compliance date to the present, the compliance issues investigated most are, compiled cumulatively, in order of frequency: Impermissible uses and disclosures of protected health information; Lack of safeguards of protected health information; Lack of patient access to their protected health information; Uses or disclosures of more than the minimum necessary protected health information; and Lack of administrative safeguards of electronic protected health information. The most common types of covered entities that have been required to take corrective action to achieve voluntary compliance are, in order of frequency: Private Practices; General Hospitals; Outpatient Facilities; Health Plans (group health plans and health insurance issuers); and, Pharmacies. http://www.hhs.gov/ocr/privacy/hipaa/enforcement/highlights/index.html
  Read Skype's Privacy Policy: Skype may gather and use info about you... — Identification data (e.g. name, username, address, telephone number, mobile number, email address) — Electronic identification data (e.g. IP addresses, cookies) — List of your contacts and related data — Content of instant messaging communications, VMs, video messages Skype uses its own cookies for a variety of purposes, including to — Provide internal and customer analytics and gain statistics and metrics about our websites Skype's analytics, ad-serving and affiliate partners may also set and access cookies on your computer Skype will take appropriate organizational and technical measures to protect the personal data and traffic data provided to it or collected by it with due observance of the applicable obligations and exceptions under the relevant legislation
  Skype's Hackings: By Leonas Sendrauskas on November 14, 2012, [UPDATE:14/11/2012@15:28GMT] Early this morning we were notified of user concerns surrounding the security of the password reset feature on our website. This issue affected some users where multiple Skype accounts were registered to the same email address. We suspended the password reset feature temporarily this morning as a precaution and have made updates to the password reset process today so that it is now working properly. We are reaching out to a small number of users who may have been impacted to assist as necessary. Skype is committed to providing a safe and secure communications experience to our users and we apologize for the inconvenience.
  Is Skype Reliable? Skype tiles & pixelates, the audio gets tinny, echoes develop, and often calls drop entirely. Sometimes consumers can see you and hear you, without your awareness.
  Telepsychiatry: The Perils of Using Skype: First released in 2003, Skype offers free, worldwide video access to any patient with an Internet connection, either by mobile device or desktop computer. What it does not offer, however, is a means of communication clearly suitable for clinical services—especially in mental health. According to estimates reported by groups such as the Institute for Healthcare Consumerism, telehealth is poised to grow by 55% in 2013 alone, and 6-fold by 2017. Wisely or otherwise, some of this growth will likely occur via Skype. Thus, it is prudent to consider the issues. The Health Insurance Portability and Accountability Act: Ordinarily, neither federal nor state law is designed to regulate specific proprietary entities such as Skype and its competitors. Video-chat platforms were developed for marketing to the general consumer, and not for health care. The Health Insurance Portability and Accountability Act (HIPAA) holds professionals responsible for conducting their own internal risk assessments regarding their chosen technologies. Before using any equipment the professional should require documentation that explicitly promises 'HIPAA compliance' or 'HIPAA compatibility' One could take further comfort in a designation of Federal Information Processing Standard (FIPS) certification, a standard that may meet and exceed HIPAA standards. HIPAA requires the use of equipment that allows for audit trails. According to the American Health Information Management Association, audit trails allow breaches to be traced. Like other proprietary platforms, Skype makes it impossible to conduct approved security audits via audit trails. Skype itself is not
  Name the top US government website to reference when needing HIPAA/HITECH information.
  • 36. Ur-‘L ! l’-lfr-. l-uil'—lil- -ll : i—l*-llli 33 : l', llIl'-Jl ~‘1—lr~'1l-‘. —k'~ . |~: ¢. . éifll JF‘fi, )_, ,i-, K~, j‘; ,'_i_i , ';-_, ~._i[; ,', .—}. _i. *_i. ’,'i, -. ,i, i._ V I 3 Search , '.'i'+lIL: ,-‘: ~—I/ u; -7’ : lul'—i'-’f-. *-, -‘T‘-i= ,li-lI- 9 ‘I‘2:- All = |=l: HHS Home| HHS News| About HHS Font Size - + Print Download Reader "~_ Health Information Privacy Office for Civil Rights Civfl Rights Health Information Privacy OCR Home > Health Information Privacy > HIPAA Administrative Simplification Statute and Rules HIPAA Administrative Simplification Statute and Rules “"Jl, lIll| :'l', L“ : Ll}l, ;!; ‘ HIPAA §, ('_ll‘-ill? -,lt§lIL'l _ To improve the efficiency and effectiveness of the health “ U"d°"5ta'_‘d'"9 care system, the Health Insurance Portability and l’ HHS a””°“”°e5 3 “WM """a¢Y Accountability Act of 1995 (HIPAA), Public Law 104-191, jfinal rule that i-i1pA_A included Administrative Simplification provisions that 'mP': me“§-5 3 Administrative required HHS to adopt national standards for electronic "”m_ ? ' ° f h . Sin-1p| ifi¢afion health care transactions and code sets, unique health at ‘3 statute and identifiers, and security. At the same time, Congress C ° Rules recognized that advances in electronic technology could 5tfe”9the" the , erode the privacy of health information. Consequently, P"'Va‘_5V and ggmus Congress incorporated into HIPAA provisions that mandated Sec‘-"“7Y . the adoption of Federal privacy protections for individually F"'°'5e°t'°"‘5 7°’ R I k ' ' " ema "19 identifiable health information. hea“5h_ '”f°"""at'°” statute established under _ HHS published a final Privacy Rule in December 2000, which , HIPAA- P""’a°V R“'e was later modified in August 2002. This Rule set national security Ruie standards for the protection of individually identifiable health information by three types of covered entities: health : ":rf'_: h t, plans, health care clearinghouses, and health care providers R3“: "3 '°" who conduct the standard health care transactions electronically. Compliance with the Privacy Rule was other required as of April 14, 2003 (April 14, 2004, for small Administrative health plans). ¢". '.u~. .I5f1—~l: .. .
  Identify more than 60 HIPAA Compliant alternatives to Skype
  OCPM Step 3 Legal Issues: Which Technologies to Use? No Guesswork Needed HIPAA Compliant Handoff - any Device
  HIPAA-Compliant Video Alternatives: www.telehealth.org/video
  Identify at least 3 HIPAA requirements for risk assessment
  Risk Assessment & HIPAA: * Conduct regular assessments — Identify all devices used with PHI — Identify potential weakness in security policies, processes and systems — Set & document goals for remediation * HHS's Office for Civil Rights and the Office of the National Coordinator for Health IT have released a security risk assessment tool: http://www.healthit.gov/providers-professionals/security-risk-assessment
  Identify at least one reason that HIPAA evokes concern among clinicians with regard to duty to warn
  Confidentiality Risk & HIPAA?: * HIPAA is not a risk to privacy or confidentiality standards for mandated reporting. — Privacy is the client/patient's right to keep their information from being disseminated. — Confidentiality is our legal duty to protect the client's patient's privacy. * HIPAA has set a standard for privacy and confidentiality.
  OCPM: Online Clinical Practice Management: Identify 3 states that have laws that are even more stringent than HIPAA for privacy or security
  State vs. Federal Law: * Many states have their own privacy laws, which can be more stringent than federal law HIPAA & HITECH. * Examples are California, Illinois, New York & Texas.
  • 46. HIPAA U. S. Department of Health & Human Services HHS. gov Improving the health, safety, and well-being of America HHS Home| HHS News| About HHS Search 5.‘ OCR 0 All HHS Font Size - + Print Download Reader 1 Health Information Privacy Understanding HIPAA Privacy HIPAA Administrative Simplification Statute and Rules Enforcement Activities R Results How to File a Complaint News Archive Frequently Asked Questions PSQIA xR Home > He_a_| th Informati_on Privacy > Fre_qi. i_ent| _y AsLed Qi. ig_st_ions 11 '37:. :v How do I know if a State law is "more stringent" than the HIPAA Privacy Rule? Answer: In general, a State law is "more stringent" than the HIPAA Privacy Rule if it relates to the privacy of individually identifiable health information and provides greater privacy protections for individuals‘ identifiable health information, or greater rights to individuals with respect to that information, than the Privacy Rule does. See the definition of "more stringent" at 45 C. F.R. 1§Q.2Q2 for the specific criteria. For example, a State law that provides individuals with a right to inspect and obtain a copy of their medical records in a more timely manner than the Privacy Rule is "more stringent" than the Privacy Rule. In the unusual case where a more stringent provision of State law is contrary to a provision of the Privacy Rule, the Privacy Rule provides an exception to preemption for the more stringent provision of State law, and the State law prevails. Where the more stringent State law and Privacy Rule are not contrary, covered entities must comply with both laws. See 45 C. F.R. Part 160, Subpart B, for specific requirements related to preemption of State law. View an unofficial version of the Privacy Rule and the preemption requirements.
  State vs. Federal Law: * Consider obtaining a legal review of your HIPAA policies, procedures and other documents by your local, informed attorney. * Speak with your professional association's ethics or legal office.
  Notice of Privacy Practices: Update your Notice of Privacy Practices: * OCR and the Office of the National Coordinator for Health Information Technology released a Model Notice of Privacy Practices, get it here: http://www.hhs.gov/ocr/privacy/hipaa/modelnotices.html
  Notice of Privacy Practices (cont.): Notice of Privacy Practices * Make available to existing clients on request * Post on your website * Display in a prominent location in your professional premises * Provide copy to all new clients
  Sale of Protected Health information (PHI): There are additional new restrictions on marketing and sale of PHI, which should be included in practitioners' HIPAA policies and procedures and Notice of Privacy Practices, if relevant.
  Where can you get all the other needed HIPAA forms? (Your professional association)
  Enforcement: The most common types of covered entities required to take corrective action: * Private Practices * General Hospitals * Outpatient Facilities * Health Plans (group health plans and health insurance issuers) and * Pharmacies http://www.hhs.gov/ocr/privacy/hipaa/enforcement/highlights/index.html
  • 53. |l. B.Dopartm-Itolflmlthlflumlnlarvlcao . g0V nIIIpmoIgo-nuanuuaunnnano-0-uuunonu Health Information Privacy . . V ) Office for Clvl nights I (‘NI mg In Mei: Inlovmofina Fnvacy , I . I . A , . . I ‘ , I _ Cue Examples and Resolution Agreements an tuvnplu mun . Vina an-noun new new covnson ormuai ta-I -tr-uiww cnmpvy I. IIIvI ma mq. ..»nnm~a. s at on I-many ’ ' ‘ > I l, *'~¢-r‘'-*H "5 WV” and $I(uvIly Inlet >uIIoaII. .uy, an «pun um ooun mm taco cumulus of ma mu-I. iIn auimu uval ’ ' ‘ ' ' "”" out uuI. I.I. [urn can -u ammo: uIIu. .qn our uI«aI¢. IvIII~II grim. ’ ' " I ‘ I I I I I I I FAA ; .sIII. rI MrI"I: a1|I'l sI. I I. .. I.4 n. .I. . can Example: 2 iuFtK‘VIlr'( ; I.; I.III. . n I4.. . n. n. . n. -I. II. .III - E. . . I :4.. . 41». .. : L‘ , ‘ ~‘ ' ' I . II. ... . . g I ( -4 7 Resolution Agreements unauu. -In II. nun [CIVrIdliV">V nonunion Agnomonn um clul honey Donovan -A rgguuxxon aqreemarit I9 - com-u alpaca Dr Hus um I: «Iv-Ims entity -1| I. >IIcrI the cauereu anuw arees to neflb-'75 Ct"VJI-'| ooligniom (e g . sun tmmmg) can make reports lo mas, uervamiy For a nation at me: was own: the neuoa, >045 mowers we uwuaa ematvs uynpunce aim at: oixlgazlons A vcsoiwon JQVEQMEVIK mvrw Iwoum Incmde mu oovmeru or a reso-uuon -n-ounz men anvcemenu are «curved to “we Imnuqnouns wan mom inflow! wiznmeo. V00:-V was run not neon able In Iucn ll nwdacmry ltlfliullnfi through In Lovlvnd an. In's a«nooInInuu cIzvI-Iumm or coil! -LLIVI (non Inruugn Iurm IIWDINIII mum, cwll menu or-Iums (cum) --y no Immna Var rIon¢IwpII. nm Against - my-Ian mmy. To nu. ms: nu cm. -ion mm 21 Itsoluhon aomcmenu Mo msuod cram m on: (ovnvcd uvury Maul 5:-mu g -a. .I. LI. ..“-. ... -I IIIIIM. .. I n. ... II. Now II. - I. . cu»-I. .I. II«I Ag‘-~»; ~:_-ouvvnlu I~Ag-an, ago "LA. L;: v; 'r_-152.2-"J -Au-1In, 'auu r«~. .«-, r'l. P‘lVI": III I. I- up: -: .;I ‘i‘Ifi: I"VJ I; amalgam CL‘U‘i1I: "'. "i . »I: LcI u. .v. .-‘ax’. .-5.. ': '«LI~m_~r. II. ~. z-(rev I , «’~vII>II. IIIII»-nu‘ I~. >'r~III -~"~III1jMI- I. _:_, .fi. 'uigg; ;, - _. '::1:. ~_uE‘_I_-. £I~: J. u;: L._'- “JLJQ -Inn: -our 1'7. In: t . I . . rNu—rI. :<Iy_c. :1-v. ) Lzr. 3.; -32 - was at. we . . . ~ 1 . . . 2.63: I, VD ». I I_, I Q) : ..'. ;;. uuI. »t_(n. _'. :' ' ' *<" *4 *. .:: I:s -lpl t_: .I_nxl«
  • 54. Discussion? Tele/ Mental Health Institute, Inc. contact@te| ehea| th. org www. te| ehea| th. org