SlideShare a Scribd company logo
1 of 21
© 2017 American Health Information Management Association© 2017 American Health Information Management Association
Chapter 11: HIPAA Privacy Rule,
Part II
Fundamentals of Law for Health
Informatics and Information
Management, Third Edition
© 2017 American Health Information Management Association
HIPAA: Individual Rights
• HIPAA privacy rule provides individuals with
rights to provide some control over their
health information
– Access
– Request amendment
– Accounting of disclosures
– Request confidential communications
– Request restrictions
– Complain of privacy rule violations
© 2017 American Health Information Management Association
HIPAA: Individual Right of
Access
• Can access one’s own PHI contained in a
designated record set
• There are exceptions to access
– Examples: Psychotherapy notes; information
compiled for civil or criminal actions
• Denial of access
– May be subject to review (appeal)
– May not be subject to review (appeal)
© 2017 American Health Information Management Association
HIPAA: Individual Right of
Access (continued)
• May require that request in writing
• Covered entity must respond within 30 days after
request received
– 30 days from receipt of request
• Permitted 30-day extension if written statement includes
reason for delay and date covered entity will complete its
action.
• Extended time permitted for records not maintained on site
– Per HITECH, covered entities with EHRs must make
PHI available electronically, or must send it to
designated person or entity electronically if individual
requests
© 2017 American Health Information Management Association
HIPAA: Individual Right of
Access (continued)
• Reasonable fee may be imposed on
individual’s request
– Labor and supplies
• Search and retrieval fees may not be charged to
individuals for their own records
– Postage, when individual has requested
information to be mailed
– Preparation of an explanation summary, if agreed
to by the individual in advance
• Stricter state laws may apply to fees
© 2017 American Health Information Management Association
HIPAA: Individual Right to
Request Amendment
• Individual has the right to request an
amendment to his or her health information
• May require the amendment request to be in
writing
• HIPAA provides reasons that an amendment
request may be denied
• Timely response to the request is required
• HIPAA provides process for denial of
amendment requests
© 2017 American Health Information Management Association
HIPAA: Individual Right of
Accounting of Disclosures
• Individuals have the right to know about instances
where his or her PHI has been disclosed
• Accounting includes:
– Date of disclosure
– Name and address of entity or person who received
the information
– Brief statement of the purpose of the disclosure
• Timely response to request for accounting
• First accounting within a 12-month period is free
• Must account for disclosures in past 3 years
© 2017 American Health Information Management Association
HIPAA: Individual Right of
Accounting of Disclosures
• Exceptions (disclosures not required to be
accounted for)
– For TPO purposes (unless disclosed from an EHR)
– Individual was given his/her own PHI
– Incident to an otherwise permitted or required use or disclosure
– Pursuant to an authorization
– Use in a facility directory, to persons involved in the individual’s
care, or for other notification purposes
– To meet national security or intelligence requirements
– To correctional institutions or law enforcement officials
– Limited data set
– That occurred before the HIPAA privacy compliance date
© 2017 American Health Information Management Association
HIPAA: Individual Right of
Accounting of Disclosures
• Per HITECH, pending “access report”
would require CEs to account for everyone
who used or disclosed electronic health
information in a DRS
© 2017 American Health Information Management Association
HIPAA: Individual Right of
Confidential Communications
• Individuals have the right to request
alternative routing/destination of PHI
• Requests may be refused if information is
not provided as to how payment will be
handled
© 2017 American Health Information Management Association
HIPAA: Individual Right to
Request Restrictions
• Individuals may request restrictions on uses and
disclosures of PHI to carry out TPO
– Covered entity does not have to agree to the
requested restriction
– Exception: Per HITECH, covered entity must agree if
disclosure would be made to health plan for payment
or operations, and PHI pertains solely to an item or
service that has been paid for in full by other than the
health plan
• Must document and abide by request if covered
entity agrees to it, unless and until terminated with
notice to the other party
© 2017 American Health Information Management Association
HIPAA: Individual Right to
Complain of Violations
• Notice of Privacy Practices must inform
individuals of right to complain at CE level
and to the US Department of Health and
Human Services, along with contact
information
© 2017 American Health Information Management Association
HIPAA: Breach
• Breach is an “unauthorized acquisition, access,
use or disclosure of PHI which compromises the
security or privacy of such information”
– Several exceptions
– Requirements apply only to unsecured PHI: that
which technology has not made unusable,
unreadable, or indecipherable to unauthorized
persons
– An impermissible use or disclosure of PHI is
presumed to be a breach unless the CE or BA
demonstrates a low probability the PHI has been
compromised
© 2017 American Health Information Management Association
HIPAA: Breach Notification
• HITECH requires breach notification
as mitigation
– Notification to individuals affected
– Notification to HHS via online portal
• HIPAA-covered entities and BAs
subject to HHS regulations
• Non HIPAA-covered entities and non-
BAs subject to FTC regulations
– Includes PHR vendors, third-party
service providers of PHR vendors
© 2017 American Health Information Management Association
HIPAA: Breach Notification
(continued)
• Must inform affected individuals of
– Description of what occurred (including date of
breach and date of discovery)
– Types of unsecured PHI involved
– Steps individual may take to protect him/herself
– Entity’s steps to investigate, mitigate, prevent in
the future
– Contact information for individuals to ask
questions and receive updates
© 2017 American Health Information Management Association
HIPAA: Breach Notification
(continued)
• If a breach affects 500+ individuals,
immediate notification is required to:
– Local media outlets
– Secretary of HHS for posting on breach portal
© 2017 American Health Information Management Association
HIPAA: Research
• HIPAA affects research in the following
ways:
– When authorization is required
• Research is a public interest and benefit
authorization exception, but IRB or privacy board
must approve variations to authorization
requirement
– In what form authorization may occur:
• Standalone
• Compound (informed consent + authorization)
• Conditioned + unconditioned
• Altered
• Waived
© 2017 American Health Information Management Association
HIPAA: Preemption
• HIPAA is a federal floor, or minimum, on
patient privacy requirements.
• State laws contrary to HIPAA apply if they
are “more stringent”
– Provide greater privacy protections
– Provide greater patient rights regarding their
PHI
or
– Fulfill specific purposes enumerated in the law
(i.e., are less stringent but serve purposes such
as controlling regulated substances or
preventing healthcare fraud and abuse)
© 2017 American Health Information Management Association
HIPAA: Administrative
Requirements
• Policies and procedures
• Designation of privacy officer
• Workforce training
– Non-disclosure agreements
• Mitigation
– Include process for handling privacy complaints
• Data safeguards
• Retaliation and waiver
• Document and record retention (HIPAA standard
is 6 years)
© 2017 American Health Information Management Association
HIPAA: Penalties and
Enforcement
• HIPAA Enforcement Rule (2006)
• Penalties for non-compliance apply to both CEs
and BAs
– Civil
– Criminal
• Penalty categories
– Unknowing
– Due to reasonable cause and not willful neglect
– Due to willful neglect/corrected within 30 days of discovery
– Due to willful neglect and not corrected as required
© 2017 American Health Information Management Association
HIPAA: Penalties and
Enforcement Per HITECH
• HHS contracts with a private entity to conduct
random audits (no longer complaint-driven
only)
• State attorneys general may bring civil
actions in federal court representing citizens
affected by HIPAA violations
• Individuals can now be individually
prosecuted
• Recommendations for compensating
individuals harmed by violations

More Related Content

What's hot

Privacy & security training.pptx
Privacy & security training.pptxPrivacy & security training.pptx
Privacy & security training.pptxQmcleod
 
HIPAA - Understanding the Basics of Compliance
HIPAA - Understanding the Basics of ComplianceHIPAA - Understanding the Basics of Compliance
HIPAA - Understanding the Basics of ComplianceJay Hodes
 
Health Insurance Portability and Accountability Act (HIPPA) - Kloudlearn
Health Insurance Portability and Accountability Act (HIPPA) - KloudlearnHealth Insurance Portability and Accountability Act (HIPPA) - Kloudlearn
Health Insurance Portability and Accountability Act (HIPPA) - KloudlearnKloudLearn
 
HIPAA Compliance for Developers
HIPAA Compliance for DevelopersHIPAA Compliance for Developers
HIPAA Compliance for DevelopersTrueVault
 
HIPAA Summary for Training
HIPAA Summary for Training HIPAA Summary for Training
HIPAA Summary for Training MDManagement
 
Health insurance portability and act(hipaa)2
Health insurance portability and act(hipaa)2Health insurance portability and act(hipaa)2
Health insurance portability and act(hipaa)29535814851
 
Health Insurance Portability and Accountability Act (HIPAA) Compliance
Health Insurance Portability and Accountability Act (HIPAA) ComplianceHealth Insurance Portability and Accountability Act (HIPAA) Compliance
Health Insurance Portability and Accountability Act (HIPAA) ComplianceControlCase
 
HIPPA Compliance
HIPPA ComplianceHIPPA Compliance
HIPPA Compliancedixibee
 
The Startup Path to HIPAA Compliance
The Startup Path to HIPAA ComplianceThe Startup Path to HIPAA Compliance
The Startup Path to HIPAA ComplianceJim Anfield
 
MEDICAL ANSWERING SERVICE
MEDICAL ANSWERING SERVICE MEDICAL ANSWERING SERVICE
MEDICAL ANSWERING SERVICE Milk663
 

What's hot (16)

Privacy & security training.pptx
Privacy & security training.pptxPrivacy & security training.pptx
Privacy & security training.pptx
 
HIPAA - Understanding the Basics of Compliance
HIPAA - Understanding the Basics of ComplianceHIPAA - Understanding the Basics of Compliance
HIPAA - Understanding the Basics of Compliance
 
HIPAA and How it Applies to You
HIPAA and How it Applies to YouHIPAA and How it Applies to You
HIPAA and How it Applies to You
 
HIPAA Complaince
HIPAA ComplainceHIPAA Complaince
HIPAA Complaince
 
Health Insurance Portability and Accountability Act (HIPPA) - Kloudlearn
Health Insurance Portability and Accountability Act (HIPPA) - KloudlearnHealth Insurance Portability and Accountability Act (HIPPA) - Kloudlearn
Health Insurance Portability and Accountability Act (HIPPA) - Kloudlearn
 
Hm300 week 5 part 1 of 2
Hm300 week 5 part 1 of 2Hm300 week 5 part 1 of 2
Hm300 week 5 part 1 of 2
 
Hi103 week 4 chpt 9
Hi103 week 4 chpt 9Hi103 week 4 chpt 9
Hi103 week 4 chpt 9
 
HIPAA Compliance for Developers
HIPAA Compliance for DevelopersHIPAA Compliance for Developers
HIPAA Compliance for Developers
 
Hippa training 2017
Hippa training 2017Hippa training 2017
Hippa training 2017
 
HIPAA Summary for Training
HIPAA Summary for Training HIPAA Summary for Training
HIPAA Summary for Training
 
Hippa laws
Hippa lawsHippa laws
Hippa laws
 
Health insurance portability and act(hipaa)2
Health insurance portability and act(hipaa)2Health insurance portability and act(hipaa)2
Health insurance portability and act(hipaa)2
 
Health Insurance Portability and Accountability Act (HIPAA) Compliance
Health Insurance Portability and Accountability Act (HIPAA) ComplianceHealth Insurance Portability and Accountability Act (HIPAA) Compliance
Health Insurance Portability and Accountability Act (HIPAA) Compliance
 
HIPPA Compliance
HIPPA ComplianceHIPPA Compliance
HIPPA Compliance
 
The Startup Path to HIPAA Compliance
The Startup Path to HIPAA ComplianceThe Startup Path to HIPAA Compliance
The Startup Path to HIPAA Compliance
 
MEDICAL ANSWERING SERVICE
MEDICAL ANSWERING SERVICE MEDICAL ANSWERING SERVICE
MEDICAL ANSWERING SERVICE
 

Similar to Hm300 week 7 part 1 of 2

HIPAA Lockdown: One-Hour Guide to PHI Best Practice
HIPAA Lockdown: One-Hour Guide to PHI Best PracticeHIPAA Lockdown: One-Hour Guide to PHI Best Practice
HIPAA Lockdown: One-Hour Guide to PHI Best Practicebenefitexpress
 
Privacy & security training.pptx
Privacy & security training.pptxPrivacy & security training.pptx
Privacy & security training.pptxQmcleod
 
Hitech changes-to-hipaa
Hitech changes-to-hipaaHitech changes-to-hipaa
Hitech changes-to-hipaageeksikh
 
Staff_confidentiality_training_TeresaStewart
Staff_confidentiality_training_TeresaStewartStaff_confidentiality_training_TeresaStewart
Staff_confidentiality_training_TeresaStewartteresastewart99
 
HIPAA Rights Privacy and Enforcements RD.pptx
HIPAA Rights  Privacy and Enforcements RD.pptxHIPAA Rights  Privacy and Enforcements RD.pptx
HIPAA Rights Privacy and Enforcements RD.pptxRAJIV RANJAN DAS
 
Patient Privacy Provisions of the HITECH Act Implications for Patients and Sm...
Patient Privacy Provisions of the HITECH Act Implications for Patients and Sm...Patient Privacy Provisions of the HITECH Act Implications for Patients and Sm...
Patient Privacy Provisions of the HITECH Act Implications for Patients and Sm...Xiaoming Zeng
 
Understanding HIPAA
Understanding HIPAAUnderstanding HIPAA
Understanding HIPAAManas Deep
 
MHA690 confidentiality training
MHA690 confidentiality trainingMHA690 confidentiality training
MHA690 confidentiality trainingsdavis49
 
health insurance portability and accountability act.pptx
health insurance portability and accountability act.pptxhealth insurance portability and accountability act.pptx
health insurance portability and accountability act.pptxamartya2087
 

Similar to Hm300 week 7 part 1 of 2 (20)

Hm300 week 6
Hm300 week 6 Hm300 week 6
Hm300 week 6
 
Hm300 week 5 part 2 of 2
Hm300 week 5 part 2 of 2Hm300 week 5 part 2 of 2
Hm300 week 5 part 2 of 2
 
Hm300 week 5 part 2 of 2
Hm300 week 5 part 2 of 2Hm300 week 5 part 2 of 2
Hm300 week 5 part 2 of 2
 
Hi103 week 6 chpt 15
Hi103 week 6 chpt 15Hi103 week 6 chpt 15
Hi103 week 6 chpt 15
 
HIPAA Lockdown: One-Hour Guide to PHI Best Practice
HIPAA Lockdown: One-Hour Guide to PHI Best PracticeHIPAA Lockdown: One-Hour Guide to PHI Best Practice
HIPAA Lockdown: One-Hour Guide to PHI Best Practice
 
Medical Records Seminar
Medical Records SeminarMedical Records Seminar
Medical Records Seminar
 
Hi103 week 5 chpt 13
Hi103 week 5 chpt 13Hi103 week 5 chpt 13
Hi103 week 5 chpt 13
 
Hm300 week 8 part 2 of 2
Hm300 week 8 part 2 of 2Hm300 week 8 part 2 of 2
Hm300 week 8 part 2 of 2
 
Hi103 week 7 chpt 18
Hi103 week 7 chpt 18Hi103 week 7 chpt 18
Hi103 week 7 chpt 18
 
Hm300 week 8 part 2 of 2
Hm300 week 8 part 2 of 2Hm300 week 8 part 2 of 2
Hm300 week 8 part 2 of 2
 
Privacy & security training.pptx
Privacy & security training.pptxPrivacy & security training.pptx
Privacy & security training.pptx
 
Hm300 week 5 part 1 of 2
Hm300 week 5 part 1 of 2Hm300 week 5 part 1 of 2
Hm300 week 5 part 1 of 2
 
Hitech changes-to-hipaa
Hitech changes-to-hipaaHitech changes-to-hipaa
Hitech changes-to-hipaa
 
Staff_confidentiality_training_TeresaStewart
Staff_confidentiality_training_TeresaStewartStaff_confidentiality_training_TeresaStewart
Staff_confidentiality_training_TeresaStewart
 
Annual HIPAA Training
Annual HIPAA TrainingAnnual HIPAA Training
Annual HIPAA Training
 
HIPAA Rights Privacy and Enforcements RD.pptx
HIPAA Rights  Privacy and Enforcements RD.pptxHIPAA Rights  Privacy and Enforcements RD.pptx
HIPAA Rights Privacy and Enforcements RD.pptx
 
Patient Privacy Provisions of the HITECH Act Implications for Patients and Sm...
Patient Privacy Provisions of the HITECH Act Implications for Patients and Sm...Patient Privacy Provisions of the HITECH Act Implications for Patients and Sm...
Patient Privacy Provisions of the HITECH Act Implications for Patients and Sm...
 
Understanding HIPAA
Understanding HIPAAUnderstanding HIPAA
Understanding HIPAA
 
MHA690 confidentiality training
MHA690 confidentiality trainingMHA690 confidentiality training
MHA690 confidentiality training
 
health insurance portability and accountability act.pptx
health insurance portability and accountability act.pptxhealth insurance portability and accountability act.pptx
health insurance portability and accountability act.pptx
 

More from BHUOnlineDepartment

Bi 117 week 1 ppt the bible as literature
Bi 117 week 1 ppt the bible as literatureBi 117 week 1 ppt the bible as literature
Bi 117 week 1 ppt the bible as literatureBHUOnlineDepartment
 
ESL 0845L-OL Week 9 a usa government branches
ESL 0845L-OL Week 9 a   usa government branchesESL 0845L-OL Week 9 a   usa government branches
ESL 0845L-OL Week 9 a usa government branchesBHUOnlineDepartment
 
ESL 0845L-OL Week 8 b the coca cola case
ESL 0845L-OL Week 8 b   the coca cola caseESL 0845L-OL Week 8 b   the coca cola case
ESL 0845L-OL Week 8 b the coca cola caseBHUOnlineDepartment
 
ESL 0845L-OL Week 8 a organizational communication
ESL 0845L-OL Week 8 a   organizational communicationESL 0845L-OL Week 8 a   organizational communication
ESL 0845L-OL Week 8 a organizational communicationBHUOnlineDepartment
 
ESL 0845L-OL Week 5 b modern manners
ESL 0845L-OL Week 5 b   modern mannersESL 0845L-OL Week 5 b   modern manners
ESL 0845L-OL Week 5 b modern mannersBHUOnlineDepartment
 
ESL 0845L-OL Week 4 a products - sales presentation
ESL 0845L-OL Week 4 a   products - sales presentationESL 0845L-OL Week 4 a   products - sales presentation
ESL 0845L-OL Week 4 a products - sales presentationBHUOnlineDepartment
 
ESL 0845L-OL Week 3 a consumption
ESL 0845L-OL Week 3 a   consumptionESL 0845L-OL Week 3 a   consumption
ESL 0845L-OL Week 3 a consumptionBHUOnlineDepartment
 
ESL 0845L-OL Week 2 b generally speaking
ESL 0845L-OL Week 2 b   generally speakingESL 0845L-OL Week 2 b   generally speaking
ESL 0845L-OL Week 2 b generally speakingBHUOnlineDepartment
 
ESL 0845L-OL Week 1 b relationships
ESL 0845L-OL Week 1 b   relationshipsESL 0845L-OL Week 1 b   relationships
ESL 0845L-OL Week 1 b relationshipsBHUOnlineDepartment
 
ESL 0845L-OL Week 1 a introductions
ESL 0845L-OL Week 1 a   introductionsESL 0845L-OL Week 1 a   introductions
ESL 0845L-OL Week 1 a introductionsBHUOnlineDepartment
 
ESL 0845L-OL Week 1 a family life
ESL 0845L-OL Week 1 a   family lifeESL 0845L-OL Week 1 a   family life
ESL 0845L-OL Week 1 a family lifeBHUOnlineDepartment
 
ESL 0823L week 8 general interest in products
ESL 0823L week 8 general interest in productsESL 0823L week 8 general interest in products
ESL 0823L week 8 general interest in productsBHUOnlineDepartment
 
ESL 0823L week 7 a job-interview-oneonone-activities-pronunciation-exercises-...
ESL 0823L week 7 a job-interview-oneonone-activities-pronunciation-exercises-...ESL 0823L week 7 a job-interview-oneonone-activities-pronunciation-exercises-...
ESL 0823L week 7 a job-interview-oneonone-activities-pronunciation-exercises-...BHUOnlineDepartment
 
ESL 0823L week 6 parts of-the-body-matter-7160
ESL 0823L week 6 parts of-the-body-matter-7160ESL 0823L week 6 parts of-the-body-matter-7160
ESL 0823L week 6 parts of-the-body-matter-7160BHUOnlineDepartment
 

More from BHUOnlineDepartment (20)

Bi 117 week 1 ppt the bible as literature
Bi 117 week 1 ppt the bible as literatureBi 117 week 1 ppt the bible as literature
Bi 117 week 1 ppt the bible as literature
 
ESL 0845L-OL Week 9 a usa government branches
ESL 0845L-OL Week 9 a   usa government branchesESL 0845L-OL Week 9 a   usa government branches
ESL 0845L-OL Week 9 a usa government branches
 
ESL 0845L-OL Week 8 b the coca cola case
ESL 0845L-OL Week 8 b   the coca cola caseESL 0845L-OL Week 8 b   the coca cola case
ESL 0845L-OL Week 8 b the coca cola case
 
ESL 0845L-OL Week 8 a organizational communication
ESL 0845L-OL Week 8 a   organizational communicationESL 0845L-OL Week 8 a   organizational communication
ESL 0845L-OL Week 8 a organizational communication
 
ESL 0845L-OL Week 7 a jobs
ESL 0845L-OL Week 7 a   jobsESL 0845L-OL Week 7 a   jobs
ESL 0845L-OL Week 7 a jobs
 
ESL 0845L-OL Week 6 a health
ESL 0845L-OL Week 6 a   healthESL 0845L-OL Week 6 a   health
ESL 0845L-OL Week 6 a health
 
ESL 0845L-OL Week 5 b modern manners
ESL 0845L-OL Week 5 b   modern mannersESL 0845L-OL Week 5 b   modern manners
ESL 0845L-OL Week 5 b modern manners
 
ESL 0845L-OL Week 5 a community
ESL 0845L-OL Week 5 a   communityESL 0845L-OL Week 5 a   community
ESL 0845L-OL Week 5 a community
 
ESL 0845L-OL Week 4 a products - sales presentation
ESL 0845L-OL Week 4 a   products - sales presentationESL 0845L-OL Week 4 a   products - sales presentation
ESL 0845L-OL Week 4 a products - sales presentation
 
ESL 0845L-OL Week 3 b symbols
ESL 0845L-OL Week 3 b   symbolsESL 0845L-OL Week 3 b   symbols
ESL 0845L-OL Week 3 b symbols
 
ESL 0845L-OL Week 3 a consumption
ESL 0845L-OL Week 3 a   consumptionESL 0845L-OL Week 3 a   consumption
ESL 0845L-OL Week 3 a consumption
 
ESL 0845L-OL Week 2 b generally speaking
ESL 0845L-OL Week 2 b   generally speakingESL 0845L-OL Week 2 b   generally speaking
ESL 0845L-OL Week 2 b generally speaking
 
ESL 0845L-OL Week 2 a money
ESL 0845L-OL Week 2 a   moneyESL 0845L-OL Week 2 a   money
ESL 0845L-OL Week 2 a money
 
ESL 0845L-OL Week 1 b success
ESL 0845L-OL Week 1 b   successESL 0845L-OL Week 1 b   success
ESL 0845L-OL Week 1 b success
 
ESL 0845L-OL Week 1 b relationships
ESL 0845L-OL Week 1 b   relationshipsESL 0845L-OL Week 1 b   relationships
ESL 0845L-OL Week 1 b relationships
 
ESL 0845L-OL Week 1 a introductions
ESL 0845L-OL Week 1 a   introductionsESL 0845L-OL Week 1 a   introductions
ESL 0845L-OL Week 1 a introductions
 
ESL 0845L-OL Week 1 a family life
ESL 0845L-OL Week 1 a   family lifeESL 0845L-OL Week 1 a   family life
ESL 0845L-OL Week 1 a family life
 
ESL 0823L week 8 general interest in products
ESL 0823L week 8 general interest in productsESL 0823L week 8 general interest in products
ESL 0823L week 8 general interest in products
 
ESL 0823L week 7 a job-interview-oneonone-activities-pronunciation-exercises-...
ESL 0823L week 7 a job-interview-oneonone-activities-pronunciation-exercises-...ESL 0823L week 7 a job-interview-oneonone-activities-pronunciation-exercises-...
ESL 0823L week 7 a job-interview-oneonone-activities-pronunciation-exercises-...
 
ESL 0823L week 6 parts of-the-body-matter-7160
ESL 0823L week 6 parts of-the-body-matter-7160ESL 0823L week 6 parts of-the-body-matter-7160
ESL 0823L week 6 parts of-the-body-matter-7160
 

Recently uploaded

Employee wellbeing at the workplace.pptx
Employee wellbeing at the workplace.pptxEmployee wellbeing at the workplace.pptx
Employee wellbeing at the workplace.pptxNirmalaLoungPoorunde1
 
Enzyme, Pharmaceutical Aids, Miscellaneous Last Part of Chapter no 5th.pdf
Enzyme, Pharmaceutical Aids, Miscellaneous Last Part of Chapter no 5th.pdfEnzyme, Pharmaceutical Aids, Miscellaneous Last Part of Chapter no 5th.pdf
Enzyme, Pharmaceutical Aids, Miscellaneous Last Part of Chapter no 5th.pdfSumit Tiwari
 
ECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptx
ECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptxECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptx
ECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptxiammrhaywood
 
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...Marc Dusseiller Dusjagr
 
Proudly South Africa powerpoint Thorisha.pptx
Proudly South Africa powerpoint Thorisha.pptxProudly South Africa powerpoint Thorisha.pptx
Proudly South Africa powerpoint Thorisha.pptxthorishapillay1
 
Roles & Responsibilities in Pharmacovigilance
Roles & Responsibilities in PharmacovigilanceRoles & Responsibilities in Pharmacovigilance
Roles & Responsibilities in PharmacovigilanceSamikshaHamane
 
Biting mechanism of poisonous snakes.pdf
Biting mechanism of poisonous snakes.pdfBiting mechanism of poisonous snakes.pdf
Biting mechanism of poisonous snakes.pdfadityarao40181
 
Capitol Tech U Doctoral Presentation - April 2024.pptx
Capitol Tech U Doctoral Presentation - April 2024.pptxCapitol Tech U Doctoral Presentation - April 2024.pptx
Capitol Tech U Doctoral Presentation - April 2024.pptxCapitolTechU
 
Presiding Officer Training module 2024 lok sabha elections
Presiding Officer Training module 2024 lok sabha electionsPresiding Officer Training module 2024 lok sabha elections
Presiding Officer Training module 2024 lok sabha electionsanshu789521
 
CARE OF CHILD IN INCUBATOR..........pptx
CARE OF CHILD IN INCUBATOR..........pptxCARE OF CHILD IN INCUBATOR..........pptx
CARE OF CHILD IN INCUBATOR..........pptxGaneshChakor2
 
call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️9953056974 Low Rate Call Girls In Saket, Delhi NCR
 
Introduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher EducationIntroduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher Educationpboyjonauth
 
Meghan Sutherland In Media Res Media Component
Meghan Sutherland In Media Res Media ComponentMeghan Sutherland In Media Res Media Component
Meghan Sutherland In Media Res Media ComponentInMediaRes1
 
How to Make a Pirate ship Primary Education.pptx
How to Make a Pirate ship Primary Education.pptxHow to Make a Pirate ship Primary Education.pptx
How to Make a Pirate ship Primary Education.pptxmanuelaromero2013
 
Hierarchy of management that covers different levels of management
Hierarchy of management that covers different levels of managementHierarchy of management that covers different levels of management
Hierarchy of management that covers different levels of managementmkooblal
 
भारत-रोम व्यापार.pptx, Indo-Roman Trade,
भारत-रोम व्यापार.pptx, Indo-Roman Trade,भारत-रोम व्यापार.pptx, Indo-Roman Trade,
भारत-रोम व्यापार.pptx, Indo-Roman Trade,Virag Sontakke
 
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdfssuser54595a
 
Earth Day Presentation wow hello nice great
Earth Day Presentation wow hello nice greatEarth Day Presentation wow hello nice great
Earth Day Presentation wow hello nice greatYousafMalik24
 

Recently uploaded (20)

TataKelola dan KamSiber Kecerdasan Buatan v022.pdf
TataKelola dan KamSiber Kecerdasan Buatan v022.pdfTataKelola dan KamSiber Kecerdasan Buatan v022.pdf
TataKelola dan KamSiber Kecerdasan Buatan v022.pdf
 
Employee wellbeing at the workplace.pptx
Employee wellbeing at the workplace.pptxEmployee wellbeing at the workplace.pptx
Employee wellbeing at the workplace.pptx
 
9953330565 Low Rate Call Girls In Rohini Delhi NCR
9953330565 Low Rate Call Girls In Rohini  Delhi NCR9953330565 Low Rate Call Girls In Rohini  Delhi NCR
9953330565 Low Rate Call Girls In Rohini Delhi NCR
 
Enzyme, Pharmaceutical Aids, Miscellaneous Last Part of Chapter no 5th.pdf
Enzyme, Pharmaceutical Aids, Miscellaneous Last Part of Chapter no 5th.pdfEnzyme, Pharmaceutical Aids, Miscellaneous Last Part of Chapter no 5th.pdf
Enzyme, Pharmaceutical Aids, Miscellaneous Last Part of Chapter no 5th.pdf
 
ECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptx
ECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptxECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptx
ECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptx
 
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
 
Proudly South Africa powerpoint Thorisha.pptx
Proudly South Africa powerpoint Thorisha.pptxProudly South Africa powerpoint Thorisha.pptx
Proudly South Africa powerpoint Thorisha.pptx
 
Roles & Responsibilities in Pharmacovigilance
Roles & Responsibilities in PharmacovigilanceRoles & Responsibilities in Pharmacovigilance
Roles & Responsibilities in Pharmacovigilance
 
Biting mechanism of poisonous snakes.pdf
Biting mechanism of poisonous snakes.pdfBiting mechanism of poisonous snakes.pdf
Biting mechanism of poisonous snakes.pdf
 
Capitol Tech U Doctoral Presentation - April 2024.pptx
Capitol Tech U Doctoral Presentation - April 2024.pptxCapitol Tech U Doctoral Presentation - April 2024.pptx
Capitol Tech U Doctoral Presentation - April 2024.pptx
 
Presiding Officer Training module 2024 lok sabha elections
Presiding Officer Training module 2024 lok sabha electionsPresiding Officer Training module 2024 lok sabha elections
Presiding Officer Training module 2024 lok sabha elections
 
CARE OF CHILD IN INCUBATOR..........pptx
CARE OF CHILD IN INCUBATOR..........pptxCARE OF CHILD IN INCUBATOR..........pptx
CARE OF CHILD IN INCUBATOR..........pptx
 
call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
 
Introduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher EducationIntroduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher Education
 
Meghan Sutherland In Media Res Media Component
Meghan Sutherland In Media Res Media ComponentMeghan Sutherland In Media Res Media Component
Meghan Sutherland In Media Res Media Component
 
How to Make a Pirate ship Primary Education.pptx
How to Make a Pirate ship Primary Education.pptxHow to Make a Pirate ship Primary Education.pptx
How to Make a Pirate ship Primary Education.pptx
 
Hierarchy of management that covers different levels of management
Hierarchy of management that covers different levels of managementHierarchy of management that covers different levels of management
Hierarchy of management that covers different levels of management
 
भारत-रोम व्यापार.pptx, Indo-Roman Trade,
भारत-रोम व्यापार.pptx, Indo-Roman Trade,भारत-रोम व्यापार.pptx, Indo-Roman Trade,
भारत-रोम व्यापार.pptx, Indo-Roman Trade,
 
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
 
Earth Day Presentation wow hello nice great
Earth Day Presentation wow hello nice greatEarth Day Presentation wow hello nice great
Earth Day Presentation wow hello nice great
 

Hm300 week 7 part 1 of 2

  • 1. © 2017 American Health Information Management Association© 2017 American Health Information Management Association Chapter 11: HIPAA Privacy Rule, Part II Fundamentals of Law for Health Informatics and Information Management, Third Edition
  • 2. © 2017 American Health Information Management Association HIPAA: Individual Rights • HIPAA privacy rule provides individuals with rights to provide some control over their health information – Access – Request amendment – Accounting of disclosures – Request confidential communications – Request restrictions – Complain of privacy rule violations
  • 3. © 2017 American Health Information Management Association HIPAA: Individual Right of Access • Can access one’s own PHI contained in a designated record set • There are exceptions to access – Examples: Psychotherapy notes; information compiled for civil or criminal actions • Denial of access – May be subject to review (appeal) – May not be subject to review (appeal)
  • 4. © 2017 American Health Information Management Association HIPAA: Individual Right of Access (continued) • May require that request in writing • Covered entity must respond within 30 days after request received – 30 days from receipt of request • Permitted 30-day extension if written statement includes reason for delay and date covered entity will complete its action. • Extended time permitted for records not maintained on site – Per HITECH, covered entities with EHRs must make PHI available electronically, or must send it to designated person or entity electronically if individual requests
  • 5. © 2017 American Health Information Management Association HIPAA: Individual Right of Access (continued) • Reasonable fee may be imposed on individual’s request – Labor and supplies • Search and retrieval fees may not be charged to individuals for their own records – Postage, when individual has requested information to be mailed – Preparation of an explanation summary, if agreed to by the individual in advance • Stricter state laws may apply to fees
  • 6. © 2017 American Health Information Management Association HIPAA: Individual Right to Request Amendment • Individual has the right to request an amendment to his or her health information • May require the amendment request to be in writing • HIPAA provides reasons that an amendment request may be denied • Timely response to the request is required • HIPAA provides process for denial of amendment requests
  • 7. © 2017 American Health Information Management Association HIPAA: Individual Right of Accounting of Disclosures • Individuals have the right to know about instances where his or her PHI has been disclosed • Accounting includes: – Date of disclosure – Name and address of entity or person who received the information – Brief statement of the purpose of the disclosure • Timely response to request for accounting • First accounting within a 12-month period is free • Must account for disclosures in past 3 years
  • 8. © 2017 American Health Information Management Association HIPAA: Individual Right of Accounting of Disclosures • Exceptions (disclosures not required to be accounted for) – For TPO purposes (unless disclosed from an EHR) – Individual was given his/her own PHI – Incident to an otherwise permitted or required use or disclosure – Pursuant to an authorization – Use in a facility directory, to persons involved in the individual’s care, or for other notification purposes – To meet national security or intelligence requirements – To correctional institutions or law enforcement officials – Limited data set – That occurred before the HIPAA privacy compliance date
  • 9. © 2017 American Health Information Management Association HIPAA: Individual Right of Accounting of Disclosures • Per HITECH, pending “access report” would require CEs to account for everyone who used or disclosed electronic health information in a DRS
  • 10. © 2017 American Health Information Management Association HIPAA: Individual Right of Confidential Communications • Individuals have the right to request alternative routing/destination of PHI • Requests may be refused if information is not provided as to how payment will be handled
  • 11. © 2017 American Health Information Management Association HIPAA: Individual Right to Request Restrictions • Individuals may request restrictions on uses and disclosures of PHI to carry out TPO – Covered entity does not have to agree to the requested restriction – Exception: Per HITECH, covered entity must agree if disclosure would be made to health plan for payment or operations, and PHI pertains solely to an item or service that has been paid for in full by other than the health plan • Must document and abide by request if covered entity agrees to it, unless and until terminated with notice to the other party
  • 12. © 2017 American Health Information Management Association HIPAA: Individual Right to Complain of Violations • Notice of Privacy Practices must inform individuals of right to complain at CE level and to the US Department of Health and Human Services, along with contact information
  • 13. © 2017 American Health Information Management Association HIPAA: Breach • Breach is an “unauthorized acquisition, access, use or disclosure of PHI which compromises the security or privacy of such information” – Several exceptions – Requirements apply only to unsecured PHI: that which technology has not made unusable, unreadable, or indecipherable to unauthorized persons – An impermissible use or disclosure of PHI is presumed to be a breach unless the CE or BA demonstrates a low probability the PHI has been compromised
  • 14. © 2017 American Health Information Management Association HIPAA: Breach Notification • HITECH requires breach notification as mitigation – Notification to individuals affected – Notification to HHS via online portal • HIPAA-covered entities and BAs subject to HHS regulations • Non HIPAA-covered entities and non- BAs subject to FTC regulations – Includes PHR vendors, third-party service providers of PHR vendors
  • 15. © 2017 American Health Information Management Association HIPAA: Breach Notification (continued) • Must inform affected individuals of – Description of what occurred (including date of breach and date of discovery) – Types of unsecured PHI involved – Steps individual may take to protect him/herself – Entity’s steps to investigate, mitigate, prevent in the future – Contact information for individuals to ask questions and receive updates
  • 16. © 2017 American Health Information Management Association HIPAA: Breach Notification (continued) • If a breach affects 500+ individuals, immediate notification is required to: – Local media outlets – Secretary of HHS for posting on breach portal
  • 17. © 2017 American Health Information Management Association HIPAA: Research • HIPAA affects research in the following ways: – When authorization is required • Research is a public interest and benefit authorization exception, but IRB or privacy board must approve variations to authorization requirement – In what form authorization may occur: • Standalone • Compound (informed consent + authorization) • Conditioned + unconditioned • Altered • Waived
  • 18. © 2017 American Health Information Management Association HIPAA: Preemption • HIPAA is a federal floor, or minimum, on patient privacy requirements. • State laws contrary to HIPAA apply if they are “more stringent” – Provide greater privacy protections – Provide greater patient rights regarding their PHI or – Fulfill specific purposes enumerated in the law (i.e., are less stringent but serve purposes such as controlling regulated substances or preventing healthcare fraud and abuse)
  • 19. © 2017 American Health Information Management Association HIPAA: Administrative Requirements • Policies and procedures • Designation of privacy officer • Workforce training – Non-disclosure agreements • Mitigation – Include process for handling privacy complaints • Data safeguards • Retaliation and waiver • Document and record retention (HIPAA standard is 6 years)
  • 20. © 2017 American Health Information Management Association HIPAA: Penalties and Enforcement • HIPAA Enforcement Rule (2006) • Penalties for non-compliance apply to both CEs and BAs – Civil – Criminal • Penalty categories – Unknowing – Due to reasonable cause and not willful neglect – Due to willful neglect/corrected within 30 days of discovery – Due to willful neglect and not corrected as required
  • 21. © 2017 American Health Information Management Association HIPAA: Penalties and Enforcement Per HITECH • HHS contracts with a private entity to conduct random audits (no longer complaint-driven only) • State attorneys general may bring civil actions in federal court representing citizens affected by HIPAA violations • Individuals can now be individually prosecuted • Recommendations for compensating individuals harmed by violations