SlideShare a Scribd company logo
1 of 14
Download to read offline
HIPAA and De-Identification of PHI
Sometimes Required, Never Easy
Jim Sheldon-Dean
Director of Compliance Services
Lewis Creek Systems, LLC
www.lewiscreeksystems.com
1
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
Agenda
• The HIPAA Requirements for De-identification
• De-identification and its Rationale
• The De-identification Standard
• Preparation for De-identification
• Guidance on Satisfying the Expert Determination Method
• Who is an expert, and how do experts assess and mitigate the
risk of identification of an individual in health information
• Guidance on Satisfying the Safe Harbor Method
• What are examples of dates that are not permitted
• What constitutes "any other unique identifying number,
characteristic, or code”
• What is "actual knowledge that the remaining information could
be used either alone or in combination with other information to
identify an individual who is a subject of the information.”
• Q&A
2
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
HIPAA Privacy, Security, & Breach Rules
• Privacy Rule
– 45 CFR §164.5xx; Enforceable since 2003
– Establishes Rights of Individuals
– Controls on Uses and Disclosures
– Access of PHI is a hot button issue for HHS – FORTY-THREE settlements so far
recently in HHS OCR Right of Access initiative
• Security Rule
– 45 CFR §164.3xx; Enforceable since 2005
– Applies to all electronic PHI
– Flexible, customizable approach to health information security
– Uses Risk Analysis to identify and plan the mitigation of security risks
• Breach Notification Rule
– 45 CFR §164.4xx; Enforceable since February 2010
– Requires reporting of all PHI breaches to HHS and individuals
– Extensive/expensive obligations
– Provides examples of what not to do on the HHS “Wall of Shame”:
https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
3
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
PHI, Uses, and Disclosures
➢ Protected Health Information (PHI): Individually identifiable
information about health, health care or payment for
healthcare services; past, present, future; in any form or
format
➢ If PHI is truly de-identified it is no longer considered PHI but
that’s not easy to do properly
➢ Disclosure: the release, transfer, provision of, access to, or
divulging in any other manner of information outside the
entity holding the information
➢ Use: the sharing, employment, application, utilization,
examination, or analysis of individually identifiable health
information within an entity that maintains such information
4
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
Required & Permitted Uses & Disclosures
• MUST disclose:
– To HHS for compliance purposes
– To the individual (with limited exceptions)
• MAY use or disclose for:
– Treatment, Payment, and Healthcare Operations, with notice or in
emergencies
– Any purpose with an Authorization
– Directories, with opt-out
– For public good
– Subject to court orders
• Consider Minimum Necessary, except when requested by a
provider, the individual, or according to an Authorization
5
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
Allowable Disclosures, no permission needed
• Required by Law
• Public Health Activities
• Victims of Abuse, Neglect, or Domestic Violence
• Health Oversight
• Judicial and Administrative Proceedings
• Law Enforcement Activities
• Decedent Information, Organ Donation
• Research
• Serious Threat to Health or Safety
• Specialized Government Functions
• Worker’s Compensation
6
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
De-Identified Data:
The HIPAA Personal Identifiers
• Name
• Address including city and
zip code
• Telephone number
• Fax number
• E-mail address
• Social security number
• Date of birth
• Medical record number
• Health plan ID number
• Dates of treatment
• Account number
• Certificate/license number
• Device identifiers and serial number
• Vehicle identifiers and serial number
• URL
• IP address
• Biometric identifiers including finger
prints
• Full face photo and other
comparable image
• Or anything else that might be used
to identify the individual
7
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
Guidance on De-identification
• HHS’s guidance from 2012 on De-identification of PHI
http://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/un
derstanding/coveredentities/De-
identification/hhs_deid_guidance.pdf
• NIST IR 8053, released December 17, 2015, a report on De-
Identification of Personal Information
http://nvlpubs.nist.gov/nistpubs/ir/2015/NIST.IR.8053.pdf
– Summarizes de-identification research
– Discusses current practices, including discussion of HIPAA
methods for de-identification, and the effectiveness of the HIPAA
Safe Harbor method
8
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
Two Methods of De-Identification
1. Remove all eighteen personal identifiers of subject,
relatives, employer, or household members; or
2. Biostatistician confirms that individual cannot be
identified.
• Verify data cannot be identified
• Small sample sets, unique data hard to de-identify
• De-Identified PHI is no longer PHI and need not be
protected or accounted for
9
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
De-identifying Photographs and Video
• Identifying data that was generated by the camera when a photo or
video was taken may be in embedded metadata in the image file
• Even if not in metadata, the circumstances and timing of the
appearance of photos and video, and the uniqueness of images can
identify the individuals
• When de-identifying, consider:
– The precision and accuracy of identifying objects requiring de-
identification
– The reversibility of the transformation – is it really, actually de-
identified? Or is the data still there?
– The visual quality of the resulting imagery
– The effectiveness of the chosen identity obscuring techniques in
actually obscuring identity
10
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
De-identification and Breaches
• Following HIPAA requirements for de-identified
data and Limited Data Sets limits breach exposure
• Securing the data limits breach exposure
• Require Protection and Prohibit re-identification of
data in data use agreements, for both:
– De-identified PHI
– Limited Data Sets
11
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
HIPAA Tiered Penalty Structure
12
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
• Tier 1: Did not know and, with reasonable diligence, would not have known
– $114 - $57,051 per violation, $28,525 annual max (may use an Affirmative
Defense)
• Tier 2: Violation due to reasonable cause and not willful neglect
– $1,141 - $57,051 per violation, $114,102 annual maximum (may get a Waiver)
• Willful Neglect: Conscious, intentional failure or reckless indifference to the
obligation to comply with the administrative simplification provision violated
• Tier 3: Violation due to willful neglect and corrected within 30 days of when
known or should have been known with reasonable diligence
– $11,182 - $57,051 per violation, $285,255 annual maximum
• Tier 4: Violation due to willful neglect and NOT corrected within 30 days of
when known or should have been known with reasonable diligence
– $57,051 per violation, $1,711, 533 annual maximum
• See the HHS OCR enforcement pages: http://www.hhs.gov/hipaa/for-
professionals/compliance-enforcement
13
Your to-do list…
✓ Review how you use and share PHI
✓ Look for invalid pseudonymization, such as using
patient initials as a name substitute
✓ For insecure communications, use a private code
✓ Call on a professional if you are not sure!
✓ Think through the context of information – where
did it come from and when?
✓ Verify that your procedures and processes are being
followed and actually work
✓ Be prepared for breaches, just in case
✓ Keep improving your processes and verification
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
Thank you!
Any Questions?
For additional information, please contact:
Jim Sheldon-Dean
Lewis Creek Systems, LLC
5675 Spear Street, Charlotte, VT 05445
jim@lewiscreeksystems.com
www.lewiscreeksystems.com
14
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
Register Now!!!

More Related Content

Similar to Safeguarding Personal Health Information: HIPAA Rules on De-Identification

Privacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffinPrivacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffinWhitmeyerTuffin
 
Closing the Governance Gap - Enabling Governed Self-Service Analytics
Closing the Governance Gap  - Enabling Governed Self-Service AnalyticsClosing the Governance Gap  - Enabling Governed Self-Service Analytics
Closing the Governance Gap - Enabling Governed Self-Service AnalyticsPrivacera
 
HIPAA in the Public Cloud: The Rules Have Been Set - RightScale Compute 2013
HIPAA in the Public Cloud: The Rules Have Been Set - RightScale Compute 2013HIPAA in the Public Cloud: The Rules Have Been Set - RightScale Compute 2013
HIPAA in the Public Cloud: The Rules Have Been Set - RightScale Compute 2013RightScale
 
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...Diana Maier
 
Technology, policy, privacy and freedom
Technology, policy, privacy and freedomTechnology, policy, privacy and freedom
Technology, policy, privacy and freedomG Prachi
 
Privacy and Data Security: Risk Management and Avoidance
Privacy and Data Security: Risk Management and AvoidancePrivacy and Data Security: Risk Management and Avoidance
Privacy and Data Security: Risk Management and AvoidanceAmy Purcell
 
HIPAA Compliant Cloud Computing, An Overview
HIPAA Compliant Cloud Computing, An OverviewHIPAA Compliant Cloud Computing, An Overview
HIPAA Compliant Cloud Computing, An OverviewClearDATACloud
 
Texting and e mail with patients 2020
Texting and e mail with patients 2020Texting and e mail with patients 2020
Texting and e mail with patients 2020RobertAByrdr
 
HIPAA and HITECH : What you need to know
HIPAA and HITECH : What you need to knowHIPAA and HITECH : What you need to know
HIPAA and HITECH : What you need to knowShred-it
 
Hcc_hipaa hitech training_Basic www.hcctecnologies.com
Hcc_hipaa hitech training_Basic www.hcctecnologies.comHcc_hipaa hitech training_Basic www.hcctecnologies.com
Hcc_hipaa hitech training_Basic www.hcctecnologies.comejazmazhar
 
Hitech changes-to-hipaa
Hitech changes-to-hipaaHitech changes-to-hipaa
Hitech changes-to-hipaageeksikh
 
health insurance portability and accountability act.pptx
health insurance portability and accountability act.pptxhealth insurance portability and accountability act.pptx
health insurance portability and accountability act.pptxamartya2087
 
When Past Performance May Be Indicative of Future Results - The Legal Implica...
When Past Performance May Be Indicative of Future Results - The Legal Implica...When Past Performance May Be Indicative of Future Results - The Legal Implica...
When Past Performance May Be Indicative of Future Results - The Legal Implica...Jason Haislmaier
 
Patient confidentiality awareness training
Patient confidentiality awareness trainingPatient confidentiality awareness training
Patient confidentiality awareness trainingRichard Chaney
 
IT6701 Information Management Unit - V
IT6701 Information Management Unit - VIT6701 Information Management Unit - V
IT6701 Information Management Unit - Vpkaviya
 
CAHU EXPO Grove City, OH 2014
CAHU EXPO Grove City, OH 2014 CAHU EXPO Grove City, OH 2014
CAHU EXPO Grove City, OH 2014 Jason Karn
 
Patient confidentiality awareness training
Patient confidentiality awareness trainingPatient confidentiality awareness training
Patient confidentiality awareness trainingRichard Chaney
 
Marlene brooks week 1 discussion 2 - confidentiality
Marlene brooks   week 1 discussion 2 - confidentialityMarlene brooks   week 1 discussion 2 - confidentiality
Marlene brooks week 1 discussion 2 - confidentialitybablot33
 

Similar to Safeguarding Personal Health Information: HIPAA Rules on De-Identification (20)

Privacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffinPrivacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffin
 
Closing the Governance Gap - Enabling Governed Self-Service Analytics
Closing the Governance Gap  - Enabling Governed Self-Service AnalyticsClosing the Governance Gap  - Enabling Governed Self-Service Analytics
Closing the Governance Gap - Enabling Governed Self-Service Analytics
 
HIPAA in the Public Cloud: The Rules Have Been Set - RightScale Compute 2013
HIPAA in the Public Cloud: The Rules Have Been Set - RightScale Compute 2013HIPAA in the Public Cloud: The Rules Have Been Set - RightScale Compute 2013
HIPAA in the Public Cloud: The Rules Have Been Set - RightScale Compute 2013
 
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
 
Technology, policy, privacy and freedom
Technology, policy, privacy and freedomTechnology, policy, privacy and freedom
Technology, policy, privacy and freedom
 
Privacy and Data Security: Risk Management and Avoidance
Privacy and Data Security: Risk Management and AvoidancePrivacy and Data Security: Risk Management and Avoidance
Privacy and Data Security: Risk Management and Avoidance
 
HIPAA Compliant Cloud Computing, An Overview
HIPAA Compliant Cloud Computing, An OverviewHIPAA Compliant Cloud Computing, An Overview
HIPAA Compliant Cloud Computing, An Overview
 
Data Management Protection Acts
Data Management Protection ActsData Management Protection Acts
Data Management Protection Acts
 
Texting and e mail with patients 2020
Texting and e mail with patients 2020Texting and e mail with patients 2020
Texting and e mail with patients 2020
 
HIPAA
HIPAAHIPAA
HIPAA
 
HIPAA and HITECH : What you need to know
HIPAA and HITECH : What you need to knowHIPAA and HITECH : What you need to know
HIPAA and HITECH : What you need to know
 
Hcc_hipaa hitech training_Basic www.hcctecnologies.com
Hcc_hipaa hitech training_Basic www.hcctecnologies.comHcc_hipaa hitech training_Basic www.hcctecnologies.com
Hcc_hipaa hitech training_Basic www.hcctecnologies.com
 
Hitech changes-to-hipaa
Hitech changes-to-hipaaHitech changes-to-hipaa
Hitech changes-to-hipaa
 
health insurance portability and accountability act.pptx
health insurance portability and accountability act.pptxhealth insurance portability and accountability act.pptx
health insurance portability and accountability act.pptx
 
When Past Performance May Be Indicative of Future Results - The Legal Implica...
When Past Performance May Be Indicative of Future Results - The Legal Implica...When Past Performance May Be Indicative of Future Results - The Legal Implica...
When Past Performance May Be Indicative of Future Results - The Legal Implica...
 
Patient confidentiality awareness training
Patient confidentiality awareness trainingPatient confidentiality awareness training
Patient confidentiality awareness training
 
IT6701 Information Management Unit - V
IT6701 Information Management Unit - VIT6701 Information Management Unit - V
IT6701 Information Management Unit - V
 
CAHU EXPO Grove City, OH 2014
CAHU EXPO Grove City, OH 2014 CAHU EXPO Grove City, OH 2014
CAHU EXPO Grove City, OH 2014
 
Patient confidentiality awareness training
Patient confidentiality awareness trainingPatient confidentiality awareness training
Patient confidentiality awareness training
 
Marlene brooks week 1 discussion 2 - confidentiality
Marlene brooks   week 1 discussion 2 - confidentialityMarlene brooks   week 1 discussion 2 - confidentiality
Marlene brooks week 1 discussion 2 - confidentiality
 

More from Conference Panel

Grievances and Complaints 2024 Compliance with the CMS CoPs, Joint Commission...
Grievances and Complaints 2024 Compliance with the CMS CoPs, Joint Commission...Grievances and Complaints 2024 Compliance with the CMS CoPs, Joint Commission...
Grievances and Complaints 2024 Compliance with the CMS CoPs, Joint Commission...Conference Panel
 
The 2024 Prior Authorization Process For Medical Providers
The 2024 Prior Authorization Process For Medical ProvidersThe 2024 Prior Authorization Process For Medical Providers
The 2024 Prior Authorization Process For Medical ProvidersConference Panel
 
Protecting Patient Privacy: Navigating HIPAA in Digital Landscapes
Protecting Patient Privacy: Navigating HIPAA in Digital LandscapesProtecting Patient Privacy: Navigating HIPAA in Digital Landscapes
Protecting Patient Privacy: Navigating HIPAA in Digital LandscapesConference Panel
 
HIPAA Guidelines and Electronic Communication: What Healthcare Professionals ...
HIPAA Guidelines and Electronic Communication: What Healthcare Professionals ...HIPAA Guidelines and Electronic Communication: What Healthcare Professionals ...
HIPAA Guidelines and Electronic Communication: What Healthcare Professionals ...Conference Panel
 
Nursing Standards in Hospital Accreditation: CMS Guidelines 2024
Nursing Standards in Hospital Accreditation: CMS Guidelines 2024Nursing Standards in Hospital Accreditation: CMS Guidelines 2024
Nursing Standards in Hospital Accreditation: CMS Guidelines 2024Conference Panel
 
Implementing CMS Hospital QAPI Guidelines for 2024
Implementing CMS Hospital QAPI Guidelines for 2024Implementing CMS Hospital QAPI Guidelines for 2024
Implementing CMS Hospital QAPI Guidelines for 2024Conference Panel
 
Exploring the Revised Medicare 855 Enrollment Form for 2024
Exploring the Revised Medicare 855 Enrollment Form for 2024Exploring the Revised Medicare 855 Enrollment Form for 2024
Exploring the Revised Medicare 855 Enrollment Form for 2024Conference Panel
 
Demystifying Shared Care and "Incident To" Billing: 2024 Updates
Demystifying Shared Care and "Incident To" Billing: 2024 UpdatesDemystifying Shared Care and "Incident To" Billing: 2024 Updates
Demystifying Shared Care and "Incident To" Billing: 2024 UpdatesConference Panel
 
Understanding CPT Code Revisions in 2024
Understanding CPT Code Revisions in 2024Understanding CPT Code Revisions in 2024
Understanding CPT Code Revisions in 2024Conference Panel
 
Breaking Down the Latest HIPAA Modifications: What's New in 2024 and Beyond
Breaking Down the Latest HIPAA Modifications: What's New in 2024 and BeyondBreaking Down the Latest HIPAA Modifications: What's New in 2024 and Beyond
Breaking Down the Latest HIPAA Modifications: What's New in 2024 and BeyondConference Panel
 
Decoding the Latest Changes in the 2024 Medicare Physician Fee Schedule (MPFS...
Decoding the Latest Changes in the 2024 Medicare Physician Fee Schedule (MPFS...Decoding the Latest Changes in the 2024 Medicare Physician Fee Schedule (MPFS...
Decoding the Latest Changes in the 2024 Medicare Physician Fee Schedule (MPFS...Conference Panel
 
Provider Enrollment Excellence: A Strategic Program Guide
Provider Enrollment Excellence: A Strategic Program GuideProvider Enrollment Excellence: A Strategic Program Guide
Provider Enrollment Excellence: A Strategic Program GuideConference Panel
 
What Physicians Need to Know: CMS Final Rules 2024
What Physicians Need to Know: CMS Final Rules 2024What Physicians Need to Know: CMS Final Rules 2024
What Physicians Need to Know: CMS Final Rules 2024Conference Panel
 
A Deep Dive into 2023: Hospital CoPs and Best Practices for History and Physi...
A Deep Dive into 2023: Hospital CoPs and Best Practices for History and Physi...A Deep Dive into 2023: Hospital CoPs and Best Practices for History and Physi...
A Deep Dive into 2023: Hospital CoPs and Best Practices for History and Physi...Conference Panel
 
Demystifying the 2024 OIG Audit Selection Criteria
Demystifying the 2024 OIG Audit Selection CriteriaDemystifying the 2024 OIG Audit Selection Criteria
Demystifying the 2024 OIG Audit Selection CriteriaConference Panel
 
Medicare Preventive Care: A CMS Perspective
Medicare Preventive Care: A CMS PerspectiveMedicare Preventive Care: A CMS Perspective
Medicare Preventive Care: A CMS PerspectiveConference Panel
 
Part B Unpacking the 2023 CMS Hospital Infection Prevention Mandates
Part B Unpacking the 2023 CMS Hospital Infection Prevention MandatesPart B Unpacking the 2023 CMS Hospital Infection Prevention Mandates
Part B Unpacking the 2023 CMS Hospital Infection Prevention MandatesConference Panel
 
Part A Unpacking the 2023 CMS Hospital Infection Prevention Mandates
Part A Unpacking the 2023 CMS Hospital Infection Prevention MandatesPart A Unpacking the 2023 CMS Hospital Infection Prevention Mandates
Part A Unpacking the 2023 CMS Hospital Infection Prevention MandatesConference Panel
 
Key Elements of CMS Emergency Preparedness Regulations
Key Elements of CMS Emergency Preparedness RegulationsKey Elements of CMS Emergency Preparedness Regulations
Key Elements of CMS Emergency Preparedness RegulationsConference Panel
 
2023 Proposed HIPAA Amendments: What You Need to Know
2023 Proposed HIPAA Amendments: What You Need to Know2023 Proposed HIPAA Amendments: What You Need to Know
2023 Proposed HIPAA Amendments: What You Need to KnowConference Panel
 

More from Conference Panel (20)

Grievances and Complaints 2024 Compliance with the CMS CoPs, Joint Commission...
Grievances and Complaints 2024 Compliance with the CMS CoPs, Joint Commission...Grievances and Complaints 2024 Compliance with the CMS CoPs, Joint Commission...
Grievances and Complaints 2024 Compliance with the CMS CoPs, Joint Commission...
 
The 2024 Prior Authorization Process For Medical Providers
The 2024 Prior Authorization Process For Medical ProvidersThe 2024 Prior Authorization Process For Medical Providers
The 2024 Prior Authorization Process For Medical Providers
 
Protecting Patient Privacy: Navigating HIPAA in Digital Landscapes
Protecting Patient Privacy: Navigating HIPAA in Digital LandscapesProtecting Patient Privacy: Navigating HIPAA in Digital Landscapes
Protecting Patient Privacy: Navigating HIPAA in Digital Landscapes
 
HIPAA Guidelines and Electronic Communication: What Healthcare Professionals ...
HIPAA Guidelines and Electronic Communication: What Healthcare Professionals ...HIPAA Guidelines and Electronic Communication: What Healthcare Professionals ...
HIPAA Guidelines and Electronic Communication: What Healthcare Professionals ...
 
Nursing Standards in Hospital Accreditation: CMS Guidelines 2024
Nursing Standards in Hospital Accreditation: CMS Guidelines 2024Nursing Standards in Hospital Accreditation: CMS Guidelines 2024
Nursing Standards in Hospital Accreditation: CMS Guidelines 2024
 
Implementing CMS Hospital QAPI Guidelines for 2024
Implementing CMS Hospital QAPI Guidelines for 2024Implementing CMS Hospital QAPI Guidelines for 2024
Implementing CMS Hospital QAPI Guidelines for 2024
 
Exploring the Revised Medicare 855 Enrollment Form for 2024
Exploring the Revised Medicare 855 Enrollment Form for 2024Exploring the Revised Medicare 855 Enrollment Form for 2024
Exploring the Revised Medicare 855 Enrollment Form for 2024
 
Demystifying Shared Care and "Incident To" Billing: 2024 Updates
Demystifying Shared Care and "Incident To" Billing: 2024 UpdatesDemystifying Shared Care and "Incident To" Billing: 2024 Updates
Demystifying Shared Care and "Incident To" Billing: 2024 Updates
 
Understanding CPT Code Revisions in 2024
Understanding CPT Code Revisions in 2024Understanding CPT Code Revisions in 2024
Understanding CPT Code Revisions in 2024
 
Breaking Down the Latest HIPAA Modifications: What's New in 2024 and Beyond
Breaking Down the Latest HIPAA Modifications: What's New in 2024 and BeyondBreaking Down the Latest HIPAA Modifications: What's New in 2024 and Beyond
Breaking Down the Latest HIPAA Modifications: What's New in 2024 and Beyond
 
Decoding the Latest Changes in the 2024 Medicare Physician Fee Schedule (MPFS...
Decoding the Latest Changes in the 2024 Medicare Physician Fee Schedule (MPFS...Decoding the Latest Changes in the 2024 Medicare Physician Fee Schedule (MPFS...
Decoding the Latest Changes in the 2024 Medicare Physician Fee Schedule (MPFS...
 
Provider Enrollment Excellence: A Strategic Program Guide
Provider Enrollment Excellence: A Strategic Program GuideProvider Enrollment Excellence: A Strategic Program Guide
Provider Enrollment Excellence: A Strategic Program Guide
 
What Physicians Need to Know: CMS Final Rules 2024
What Physicians Need to Know: CMS Final Rules 2024What Physicians Need to Know: CMS Final Rules 2024
What Physicians Need to Know: CMS Final Rules 2024
 
A Deep Dive into 2023: Hospital CoPs and Best Practices for History and Physi...
A Deep Dive into 2023: Hospital CoPs and Best Practices for History and Physi...A Deep Dive into 2023: Hospital CoPs and Best Practices for History and Physi...
A Deep Dive into 2023: Hospital CoPs and Best Practices for History and Physi...
 
Demystifying the 2024 OIG Audit Selection Criteria
Demystifying the 2024 OIG Audit Selection CriteriaDemystifying the 2024 OIG Audit Selection Criteria
Demystifying the 2024 OIG Audit Selection Criteria
 
Medicare Preventive Care: A CMS Perspective
Medicare Preventive Care: A CMS PerspectiveMedicare Preventive Care: A CMS Perspective
Medicare Preventive Care: A CMS Perspective
 
Part B Unpacking the 2023 CMS Hospital Infection Prevention Mandates
Part B Unpacking the 2023 CMS Hospital Infection Prevention MandatesPart B Unpacking the 2023 CMS Hospital Infection Prevention Mandates
Part B Unpacking the 2023 CMS Hospital Infection Prevention Mandates
 
Part A Unpacking the 2023 CMS Hospital Infection Prevention Mandates
Part A Unpacking the 2023 CMS Hospital Infection Prevention MandatesPart A Unpacking the 2023 CMS Hospital Infection Prevention Mandates
Part A Unpacking the 2023 CMS Hospital Infection Prevention Mandates
 
Key Elements of CMS Emergency Preparedness Regulations
Key Elements of CMS Emergency Preparedness RegulationsKey Elements of CMS Emergency Preparedness Regulations
Key Elements of CMS Emergency Preparedness Regulations
 
2023 Proposed HIPAA Amendments: What You Need to Know
2023 Proposed HIPAA Amendments: What You Need to Know2023 Proposed HIPAA Amendments: What You Need to Know
2023 Proposed HIPAA Amendments: What You Need to Know
 

Recently uploaded

College Call Girls Hyderabad Sakshi 9907093804 Independent Escort Service Hyd...
College Call Girls Hyderabad Sakshi 9907093804 Independent Escort Service Hyd...College Call Girls Hyderabad Sakshi 9907093804 Independent Escort Service Hyd...
College Call Girls Hyderabad Sakshi 9907093804 Independent Escort Service Hyd...delhimodelshub1
 
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Me
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near MeVIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Me
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Memriyagarg453
 
Call Girls in Mohali Surbhi ❤️🍑 9907093804 👄🫦 Independent Escort Service Mohali
Call Girls in Mohali Surbhi ❤️🍑 9907093804 👄🫦 Independent Escort Service MohaliCall Girls in Mohali Surbhi ❤️🍑 9907093804 👄🫦 Independent Escort Service Mohali
Call Girls in Mohali Surbhi ❤️🍑 9907093804 👄🫦 Independent Escort Service MohaliHigh Profile Call Girls Chandigarh Aarushi
 
💚😋Chandigarh Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Chandigarh Escort Service Call Girls, ₹5000 To 25K With AC💚😋💚😋Chandigarh Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Chandigarh Escort Service Call Girls, ₹5000 To 25K With AC💚😋Sheetaleventcompany
 
Udaipur Call Girls 📲 9999965857 Call Girl in Udaipur
Udaipur Call Girls 📲 9999965857 Call Girl in UdaipurUdaipur Call Girls 📲 9999965857 Call Girl in Udaipur
Udaipur Call Girls 📲 9999965857 Call Girl in Udaipurseemahedar019
 
Call Girls Chandigarh 👙 7001035870 👙 Genuine WhatsApp Number for Real Meet
Call Girls Chandigarh 👙 7001035870 👙 Genuine WhatsApp Number for Real MeetCall Girls Chandigarh 👙 7001035870 👙 Genuine WhatsApp Number for Real Meet
Call Girls Chandigarh 👙 7001035870 👙 Genuine WhatsApp Number for Real Meetpriyashah722354
 
Chandigarh Call Girls 👙 7001035870 👙 Genuine WhatsApp Number for Real Meet
Chandigarh Call Girls 👙 7001035870 👙 Genuine WhatsApp Number for Real MeetChandigarh Call Girls 👙 7001035870 👙 Genuine WhatsApp Number for Real Meet
Chandigarh Call Girls 👙 7001035870 👙 Genuine WhatsApp Number for Real Meetpriyashah722354
 
VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591
VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591
VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591adityaroy0215
 
Call Girl Price Amritsar ❤️🍑 9053900678 Call Girls in Amritsar Suman
Call Girl Price Amritsar ❤️🍑 9053900678 Call Girls in Amritsar SumanCall Girl Price Amritsar ❤️🍑 9053900678 Call Girls in Amritsar Suman
Call Girl Price Amritsar ❤️🍑 9053900678 Call Girls in Amritsar SumanCall Girls Service Chandigarh Ayushi
 
Call Girl Gurgaon Saloni 9711199012 Independent Escort Service Gurgaon
Call Girl Gurgaon Saloni 9711199012 Independent Escort Service GurgaonCall Girl Gurgaon Saloni 9711199012 Independent Escort Service Gurgaon
Call Girl Gurgaon Saloni 9711199012 Independent Escort Service GurgaonCall Girls Service Gurgaon
 
Russian Call Girls Hyderabad Indira 9907093804 Independent Escort Service Hyd...
Russian Call Girls Hyderabad Indira 9907093804 Independent Escort Service Hyd...Russian Call Girls Hyderabad Indira 9907093804 Independent Escort Service Hyd...
Russian Call Girls Hyderabad Indira 9907093804 Independent Escort Service Hyd...delhimodelshub1
 
VIP Call Girl Sector 25 Gurgaon Just Call Me 9899900591
VIP Call Girl Sector 25 Gurgaon Just Call Me 9899900591VIP Call Girl Sector 25 Gurgaon Just Call Me 9899900591
VIP Call Girl Sector 25 Gurgaon Just Call Me 9899900591adityaroy0215
 
💚😋Mumbai Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Mumbai Escort Service Call Girls, ₹5000 To 25K With AC💚😋💚😋Mumbai Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Mumbai Escort Service Call Girls, ₹5000 To 25K With AC💚😋Sheetaleventcompany
 
Call Girl Hyderabad Madhuri 9907093804 Independent Escort Service Hyderabad
Call Girl Hyderabad Madhuri 9907093804 Independent Escort Service HyderabadCall Girl Hyderabad Madhuri 9907093804 Independent Escort Service Hyderabad
Call Girl Hyderabad Madhuri 9907093804 Independent Escort Service Hyderabaddelhimodelshub1
 
Leading transformational change: inner and outer skills
Leading transformational change: inner and outer skillsLeading transformational change: inner and outer skills
Leading transformational change: inner and outer skillsHelenBevan4
 
indian Call Girl Panchkula ❤️🍑 9907093804 Low Rate Call Girls Ludhiana Tulsi
indian Call Girl Panchkula ❤️🍑 9907093804 Low Rate Call Girls Ludhiana Tulsiindian Call Girl Panchkula ❤️🍑 9907093804 Low Rate Call Girls Ludhiana Tulsi
indian Call Girl Panchkula ❤️🍑 9907093804 Low Rate Call Girls Ludhiana TulsiHigh Profile Call Girls Chandigarh Aarushi
 
Russian Escorts Aishbagh Road * 9548273370 Naughty Call Girls Service in Lucknow
Russian Escorts Aishbagh Road * 9548273370 Naughty Call Girls Service in LucknowRussian Escorts Aishbagh Road * 9548273370 Naughty Call Girls Service in Lucknow
Russian Escorts Aishbagh Road * 9548273370 Naughty Call Girls Service in Lucknowgragteena
 

Recently uploaded (20)

College Call Girls Hyderabad Sakshi 9907093804 Independent Escort Service Hyd...
College Call Girls Hyderabad Sakshi 9907093804 Independent Escort Service Hyd...College Call Girls Hyderabad Sakshi 9907093804 Independent Escort Service Hyd...
College Call Girls Hyderabad Sakshi 9907093804 Independent Escort Service Hyd...
 
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Me
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near MeVIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Me
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Me
 
Call Girls in Mohali Surbhi ❤️🍑 9907093804 👄🫦 Independent Escort Service Mohali
Call Girls in Mohali Surbhi ❤️🍑 9907093804 👄🫦 Independent Escort Service MohaliCall Girls in Mohali Surbhi ❤️🍑 9907093804 👄🫦 Independent Escort Service Mohali
Call Girls in Mohali Surbhi ❤️🍑 9907093804 👄🫦 Independent Escort Service Mohali
 
💚😋Chandigarh Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Chandigarh Escort Service Call Girls, ₹5000 To 25K With AC💚😋💚😋Chandigarh Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Chandigarh Escort Service Call Girls, ₹5000 To 25K With AC💚😋
 
Udaipur Call Girls 📲 9999965857 Call Girl in Udaipur
Udaipur Call Girls 📲 9999965857 Call Girl in UdaipurUdaipur Call Girls 📲 9999965857 Call Girl in Udaipur
Udaipur Call Girls 📲 9999965857 Call Girl in Udaipur
 
Call Girls Chandigarh 👙 7001035870 👙 Genuine WhatsApp Number for Real Meet
Call Girls Chandigarh 👙 7001035870 👙 Genuine WhatsApp Number for Real MeetCall Girls Chandigarh 👙 7001035870 👙 Genuine WhatsApp Number for Real Meet
Call Girls Chandigarh 👙 7001035870 👙 Genuine WhatsApp Number for Real Meet
 
Chandigarh Call Girls 👙 7001035870 👙 Genuine WhatsApp Number for Real Meet
Chandigarh Call Girls 👙 7001035870 👙 Genuine WhatsApp Number for Real MeetChandigarh Call Girls 👙 7001035870 👙 Genuine WhatsApp Number for Real Meet
Chandigarh Call Girls 👙 7001035870 👙 Genuine WhatsApp Number for Real Meet
 
VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591
VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591
VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591
 
Call Girl Price Amritsar ❤️🍑 9053900678 Call Girls in Amritsar Suman
Call Girl Price Amritsar ❤️🍑 9053900678 Call Girls in Amritsar SumanCall Girl Price Amritsar ❤️🍑 9053900678 Call Girls in Amritsar Suman
Call Girl Price Amritsar ❤️🍑 9053900678 Call Girls in Amritsar Suman
 
Call Girl Gurgaon Saloni 9711199012 Independent Escort Service Gurgaon
Call Girl Gurgaon Saloni 9711199012 Independent Escort Service GurgaonCall Girl Gurgaon Saloni 9711199012 Independent Escort Service Gurgaon
Call Girl Gurgaon Saloni 9711199012 Independent Escort Service Gurgaon
 
Russian Call Girls Hyderabad Indira 9907093804 Independent Escort Service Hyd...
Russian Call Girls Hyderabad Indira 9907093804 Independent Escort Service Hyd...Russian Call Girls Hyderabad Indira 9907093804 Independent Escort Service Hyd...
Russian Call Girls Hyderabad Indira 9907093804 Independent Escort Service Hyd...
 
VIP Call Girl Sector 25 Gurgaon Just Call Me 9899900591
VIP Call Girl Sector 25 Gurgaon Just Call Me 9899900591VIP Call Girl Sector 25 Gurgaon Just Call Me 9899900591
VIP Call Girl Sector 25 Gurgaon Just Call Me 9899900591
 
Call Girls in Lucknow Esha 🔝 8923113531 🔝 🎶 Independent Escort Service Lucknow
Call Girls in Lucknow Esha 🔝 8923113531  🔝 🎶 Independent Escort Service LucknowCall Girls in Lucknow Esha 🔝 8923113531  🔝 🎶 Independent Escort Service Lucknow
Call Girls in Lucknow Esha 🔝 8923113531 🔝 🎶 Independent Escort Service Lucknow
 
Call Girl Lucknow Gauri 🔝 8923113531 🔝 🎶 Independent Escort Service Lucknow
Call Girl Lucknow Gauri 🔝 8923113531  🔝 🎶 Independent Escort Service LucknowCall Girl Lucknow Gauri 🔝 8923113531  🔝 🎶 Independent Escort Service Lucknow
Call Girl Lucknow Gauri 🔝 8923113531 🔝 🎶 Independent Escort Service Lucknow
 
VIP Call Girls Lucknow Isha 🔝 9719455033 🔝 🎶 Independent Escort Service Lucknow
VIP Call Girls Lucknow Isha 🔝 9719455033 🔝 🎶 Independent Escort Service LucknowVIP Call Girls Lucknow Isha 🔝 9719455033 🔝 🎶 Independent Escort Service Lucknow
VIP Call Girls Lucknow Isha 🔝 9719455033 🔝 🎶 Independent Escort Service Lucknow
 
💚😋Mumbai Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Mumbai Escort Service Call Girls, ₹5000 To 25K With AC💚😋💚😋Mumbai Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Mumbai Escort Service Call Girls, ₹5000 To 25K With AC💚😋
 
Call Girl Hyderabad Madhuri 9907093804 Independent Escort Service Hyderabad
Call Girl Hyderabad Madhuri 9907093804 Independent Escort Service HyderabadCall Girl Hyderabad Madhuri 9907093804 Independent Escort Service Hyderabad
Call Girl Hyderabad Madhuri 9907093804 Independent Escort Service Hyderabad
 
Leading transformational change: inner and outer skills
Leading transformational change: inner and outer skillsLeading transformational change: inner and outer skills
Leading transformational change: inner and outer skills
 
indian Call Girl Panchkula ❤️🍑 9907093804 Low Rate Call Girls Ludhiana Tulsi
indian Call Girl Panchkula ❤️🍑 9907093804 Low Rate Call Girls Ludhiana Tulsiindian Call Girl Panchkula ❤️🍑 9907093804 Low Rate Call Girls Ludhiana Tulsi
indian Call Girl Panchkula ❤️🍑 9907093804 Low Rate Call Girls Ludhiana Tulsi
 
Russian Escorts Aishbagh Road * 9548273370 Naughty Call Girls Service in Lucknow
Russian Escorts Aishbagh Road * 9548273370 Naughty Call Girls Service in LucknowRussian Escorts Aishbagh Road * 9548273370 Naughty Call Girls Service in Lucknow
Russian Escorts Aishbagh Road * 9548273370 Naughty Call Girls Service in Lucknow
 

Safeguarding Personal Health Information: HIPAA Rules on De-Identification

  • 1. HIPAA and De-Identification of PHI Sometimes Required, Never Easy Jim Sheldon-Dean Director of Compliance Services Lewis Creek Systems, LLC www.lewiscreeksystems.com 1 © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 2. Agenda • The HIPAA Requirements for De-identification • De-identification and its Rationale • The De-identification Standard • Preparation for De-identification • Guidance on Satisfying the Expert Determination Method • Who is an expert, and how do experts assess and mitigate the risk of identification of an individual in health information • Guidance on Satisfying the Safe Harbor Method • What are examples of dates that are not permitted • What constitutes "any other unique identifying number, characteristic, or code” • What is "actual knowledge that the remaining information could be used either alone or in combination with other information to identify an individual who is a subject of the information.” • Q&A 2 © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 3. HIPAA Privacy, Security, & Breach Rules • Privacy Rule – 45 CFR §164.5xx; Enforceable since 2003 – Establishes Rights of Individuals – Controls on Uses and Disclosures – Access of PHI is a hot button issue for HHS – FORTY-THREE settlements so far recently in HHS OCR Right of Access initiative • Security Rule – 45 CFR §164.3xx; Enforceable since 2005 – Applies to all electronic PHI – Flexible, customizable approach to health information security – Uses Risk Analysis to identify and plan the mitigation of security risks • Breach Notification Rule – 45 CFR §164.4xx; Enforceable since February 2010 – Requires reporting of all PHI breaches to HHS and individuals – Extensive/expensive obligations – Provides examples of what not to do on the HHS “Wall of Shame”: https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf 3 © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 4. PHI, Uses, and Disclosures ➢ Protected Health Information (PHI): Individually identifiable information about health, health care or payment for healthcare services; past, present, future; in any form or format ➢ If PHI is truly de-identified it is no longer considered PHI but that’s not easy to do properly ➢ Disclosure: the release, transfer, provision of, access to, or divulging in any other manner of information outside the entity holding the information ➢ Use: the sharing, employment, application, utilization, examination, or analysis of individually identifiable health information within an entity that maintains such information 4 © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 5. Required & Permitted Uses & Disclosures • MUST disclose: – To HHS for compliance purposes – To the individual (with limited exceptions) • MAY use or disclose for: – Treatment, Payment, and Healthcare Operations, with notice or in emergencies – Any purpose with an Authorization – Directories, with opt-out – For public good – Subject to court orders • Consider Minimum Necessary, except when requested by a provider, the individual, or according to an Authorization 5 © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 6. Allowable Disclosures, no permission needed • Required by Law • Public Health Activities • Victims of Abuse, Neglect, or Domestic Violence • Health Oversight • Judicial and Administrative Proceedings • Law Enforcement Activities • Decedent Information, Organ Donation • Research • Serious Threat to Health or Safety • Specialized Government Functions • Worker’s Compensation 6 © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 7. De-Identified Data: The HIPAA Personal Identifiers • Name • Address including city and zip code • Telephone number • Fax number • E-mail address • Social security number • Date of birth • Medical record number • Health plan ID number • Dates of treatment • Account number • Certificate/license number • Device identifiers and serial number • Vehicle identifiers and serial number • URL • IP address • Biometric identifiers including finger prints • Full face photo and other comparable image • Or anything else that might be used to identify the individual 7 © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 8. Guidance on De-identification • HHS’s guidance from 2012 on De-identification of PHI http://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/un derstanding/coveredentities/De- identification/hhs_deid_guidance.pdf • NIST IR 8053, released December 17, 2015, a report on De- Identification of Personal Information http://nvlpubs.nist.gov/nistpubs/ir/2015/NIST.IR.8053.pdf – Summarizes de-identification research – Discusses current practices, including discussion of HIPAA methods for de-identification, and the effectiveness of the HIPAA Safe Harbor method 8 © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 9. Two Methods of De-Identification 1. Remove all eighteen personal identifiers of subject, relatives, employer, or household members; or 2. Biostatistician confirms that individual cannot be identified. • Verify data cannot be identified • Small sample sets, unique data hard to de-identify • De-Identified PHI is no longer PHI and need not be protected or accounted for 9 © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 10. De-identifying Photographs and Video • Identifying data that was generated by the camera when a photo or video was taken may be in embedded metadata in the image file • Even if not in metadata, the circumstances and timing of the appearance of photos and video, and the uniqueness of images can identify the individuals • When de-identifying, consider: – The precision and accuracy of identifying objects requiring de- identification – The reversibility of the transformation – is it really, actually de- identified? Or is the data still there? – The visual quality of the resulting imagery – The effectiveness of the chosen identity obscuring techniques in actually obscuring identity 10 © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 11. De-identification and Breaches • Following HIPAA requirements for de-identified data and Limited Data Sets limits breach exposure • Securing the data limits breach exposure • Require Protection and Prohibit re-identification of data in data use agreements, for both: – De-identified PHI – Limited Data Sets 11 © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 12. HIPAA Tiered Penalty Structure 12 © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com • Tier 1: Did not know and, with reasonable diligence, would not have known – $114 - $57,051 per violation, $28,525 annual max (may use an Affirmative Defense) • Tier 2: Violation due to reasonable cause and not willful neglect – $1,141 - $57,051 per violation, $114,102 annual maximum (may get a Waiver) • Willful Neglect: Conscious, intentional failure or reckless indifference to the obligation to comply with the administrative simplification provision violated • Tier 3: Violation due to willful neglect and corrected within 30 days of when known or should have been known with reasonable diligence – $11,182 - $57,051 per violation, $285,255 annual maximum • Tier 4: Violation due to willful neglect and NOT corrected within 30 days of when known or should have been known with reasonable diligence – $57,051 per violation, $1,711, 533 annual maximum • See the HHS OCR enforcement pages: http://www.hhs.gov/hipaa/for- professionals/compliance-enforcement
  • 13. 13 Your to-do list… ✓ Review how you use and share PHI ✓ Look for invalid pseudonymization, such as using patient initials as a name substitute ✓ For insecure communications, use a private code ✓ Call on a professional if you are not sure! ✓ Think through the context of information – where did it come from and when? ✓ Verify that your procedures and processes are being followed and actually work ✓ Be prepared for breaches, just in case ✓ Keep improving your processes and verification © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 14. Thank you! Any Questions? For additional information, please contact: Jim Sheldon-Dean Lewis Creek Systems, LLC 5675 Spear Street, Charlotte, VT 05445 jim@lewiscreeksystems.com www.lewiscreeksystems.com 14 © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com Register Now!!!