SlideShare a Scribd company logo
1 of 35
SECTION 1
THE BASICS OF HIPAA
COMPLIANCE
A B E G I N N E R ' S G U I D E
COURSE OUTLINE
W H A T W E ' R E C O V E R I N G
We will cover the progression of HIPAA from origin
until the present. This presentation will include
COVID19 updates. Next, we will focus on The HIPAA
Privacy and Security Rules.
DISCLAIMER
This Guide is not intended to serve as legal advice or as recommendations based on a provider or
professional’s specific circumstances. We encourage providers and professionals to seek expert
advice when evaluating the use of this Guide.
D A M I A N K N O W L E S
A B R I E F H I S T O R Y
WHAT IS HIPAA?
HIPAA is an acronym for “The Health Insurance
Portability and Accountability Act.” This Act covers
Privacy, Security, and Breach Notification Rules which
protect a patient’s health information. It protects the civil
rights of their health information.
D A M I A N K N O W L E S
A B R I E F H I S T O R Y
WHEN WAS HIPAA
STARTED?
HIPAA came into existence on August 21st,
1996 and it was signed into law by President
Bill Clinton.
D A M I A N K N O W L E S
A B R I E F H I S T O R Y
WHAT IS THE INTENT
OF HIPAA?
HIPAA is meant to improve the level of responsibility
and portability of the health insurance for employees
between their jobs. Another objective was to curb
corruption by health insurance and the health care
industry as a whole. HIPAA administered guidelines for
the healthcare industry to protect the patient’s medical
health records.
As technology advanced, the Act by means of the Health
Information Technology for Economic and Clinical
Health Act (HITECH) in 2009, provided a financial
incentive for healthcare providers to migrate to
electronic health record maintenance.
Meanwhile, Congress recognized that advances in
electronic technology could negatively impact the
privacy of health information. Consequently, Congress
incorporated provisions that required the adoption of
Federal privacy protections for individually identifiable
health information.
D A M I A N K N O W L E S
A B R I E F H I S T O R Y
WHO MUST COMPLY
WITH HIPAA?
Covered entities and business associates, as
applicable, must follow HIPAA rules. If an
entity does not meet the definition of a covered
entity or business associate, it does not have
to comply with the HIPAA rules
D A M I A N K N O W L E S
COMMONLY USED
TERMS
Implementation Specification
An implementation specification is a more detailed
description of the method or approach primary care
organizations can use to meet a particular requirement
Addressable
Addressable means that there is flexibility in how the
implementation is made not if it is made. It means you
must address the specification in some way or address
the standard itself in some way by at least assessing
the risk.
Required
“Required” rules simply mean that you implement
them, or you automatically fail to comply with the
Security Rule.
BUSINESS ASSOCIATES
A business associate is a person or organization,
other than a workforce member of a covered entity,
that performs certain functions on behalf of or
provides certain services to, a covered entity that
involves access to PHI.
WHAT IS A COVERED ENTITY?
Presentations are communication tools
that can be used as demonstrations,
lectures, speeches, reports, and more.
• H E A L T H C A R E P R O V I D E R S ,
• H O S P I T A L S ,
• N U R S I N G H O M E S , A N D
• P H A R M A C I E S .
• H E A L T H P L A N S
• H E A L T H C A R E
C L E A R I N G H O U S E S
Examples of
Covered Entities
A N Y S U B C O N T R A C T O R O F A C O V E R E D
E N T I T Y W I T H A C C E S S T O P R O T E C T E D
H E A L T H I N F O R M A T I O N :
• E - P R E S C R I B E R G A T E W A Y S ,
• T R A N S C R I P T I O N I S T S
• L A W Y E R S
Examples of Business
Associates
3 MUST KNOW HIPAA RULES
The Breach Notification Rule, requires
covered entities to notify affected individuals;
U.S. Department of Health & Human Services
(HHS); and, in some cases, the media of a
breach of unsecured PHI.
The Breach Notification Rule
The Security Rule specifies safeguards that covered entities
and their business associates must implement to protect the
confidentiality, integrity, and availability of electronically
protected health information (ePHI)
The Security Rule
The Privacy Rule, sets national
standards for when protected
health information (PHI) may be
used and disclosed
The Privacy Rule
H I P A A B A S I C S
WHAT TYPES OF
INFORMATION
DOES HIPAA
PROTECT?
The Privacy Rule protects most individually
identifiable health information held or transmitted by a
CE or its BA, in any form or media, whether electronic,
paper or oral. The Privacy Rule calls this information
“protected health information” or “PHI.”
C O M M O N L Y U S E D T E R M S
WHAT IS
PROTECTED
HEALTH
INFORMATION?
Protected Health Information (PHI) is defined as any
individually identifiable health information collected
or created as a consequence of the provision of
health care by a covered entity, in any form,
including verbal communications.PHI is information
that can be linked to a particular person and that is
created, used, or disclosed while providing a health
care service (i.e., diagnosis or treatment)
H I P A A B A S I C S
WHO IS
RESPONSIBLE
FOR
ENFORCEMENT?
The HHS Office for Civil Rights Health and Human
Services, Office for Civil Rights, handles the
enforcement of the HIPAA Privacy and Security
Rules.
A laptop with 1,391 individuals’ ePHI was
stolen.
$2.5M
The investigation revealed insufficient risk analysis
and risk management processes in place at the time
of the theft.
F I N E S A R E B A S E D O N I N T E N T
PENALTIES FOR
VIOLATIONS
• Did Not Know or Could Not Have Known
• Reasonable Cause and Not Willful Neglect
• Willful Neglect, but Corrected Within 30 Days
• Willful Neglect and Not Corrected Within 30
Days
0
K
25,000
K
50,000
K
75,000
K
100,000
K
125,000
K
Wilful 30+
Wilful 30
Reasonable
Didn't Know
HIPAA BASICS
THE HIPAA PRIVACY RULE
H I P A A P R I V A C Y R U L E L I M I T S U S E S A N D D I S C L O S U R E S O F P A T I E N T
I N F O R M A T I O N
Yes, a CE must prominently post and distribute an NPP. The notice
must describe the ways in which the CE may use and disclose PHI.
The notice must state the CE’s duties to protect privacy, provide an
NPP, and abide by the terms of the current notice.
DO I NEED TO INFORM MY PATIENTS
ABOUT HOW I USE OR DISCLOSE THEIR
HEALTH INFORMATION?
NPPs must include the following information:
• How the CE may use and disclose an individual’s PHI
• The individual’s rights with respect to the information
• A statement that the CE is required by law to display the privacy policies
and how the individual may exercise these rights,
• How the individual may complain to the CE
• The CE’s legal duties with respect to the information, maintain the
privacy of PHI
• Whom individuals can contact for further information
NOTICE OF PRIVACY PRACTICES
• A CE may disclose PHI when:
• Treating a Patient,
• Managing Payment Activities,
• Both CE's have a relationship with the patient,
• Quality assessments Assessment Reviews, or
• Fraud and abuse detection or compliance.
DO I HAVE TO GET MY PATIENTS’
PERMISSION TO DISCLOSE THEIR PHI WITH
ANOTHER CE?
You may disclose, without a patient’s authorization, PHI about the patient as
necessary for treatment, payment, and health care operations purposes.
WHEN ARE PATIENT AUTHORIZATIONS NOT
REQUIRED FOR DISCLOSURE?
Yes. To make disclosures to family and friends involved in the
individual’s care or for notification purposes, or to other persons whom
the individual identifies, you must obtain informal permission by asking
the individual outright, or by determining that the individual did not
object in circumstances that clearly gave the individual the opportunity
to agree, acquiesce, or object.
DO I NEED PERMISSION FOR DISCLOSURES TO
FAMILY, FRIENDS, AND OTHERS INVOLVED IN
THE CARE OF THE INDIVIDUAL AS WELL AS FOR
NOTIFICATION PURPOSES?
You may disclose PHI without individual authorization in the following
situations:
• To send immunization records to schools,
• To a public health authority that is authorized by law
• To a foreign government agency
• To persons at risk of contracting or spreading a disease
DO I NEED PERMISSION FOR DISCLOSURES
INFORMATION IF NEEDED TO ENSURE PUBLIC
HEALTH AND SAFETY ?
WHEN ARE PATIENT AUTHORIZATIONS
REQUIRED FOR DISCLOSURE?
Psychotherapy
Notes
Marketing
Activities
PHI Sales
and Licensing
Research
WHAT IS DE-IDENTIFIED PHI?
D E - I D E N T I F I E D H E A L T H I N F O R M A T I O N
N E I T H E R I D E N T I F I E S N O R P R O V I D E S A
R E A S O N A B L E B A S I S T O I D E N T I F Y A N
I N D I V I D U A L .
WHAT ABOUT PATIENT
INFORMATION PERTAINING TO
BEHAVIORAL HEALTH OR
SUBSTANCE ABUSE?
T H E H I P A A R U L E S A P P L Y E Q U A L L Y T O
A L L P H I , I N C L U D I N G I N D I V I D U A L L Y
I D E N T I F I A B L E B E H A V I O R A L H E A L T H O R
S U B S T A N C E A B U S E I N F O R M A T I O N T H A T
Y O U R P R A C T I C E C O L L E C T S O R
M A I N T A I N S I N A P A T I E N T S ’ R E C O R D .
FEDERAL AND STATE PRIVACY
LAWS — WHICH PREVAIL?
T H E H I P A A R U L E S D O N O T O V E R R I D E
S U C H S T A T E L A W S T H A T D O N O T
C O N F L I C T W I T H T H E R U L E S A N D O F F E R
G R E A T E R P R I V A C Y P R O T E C T I O N S
The HIPAA Security Rule
These Security Rule safeguards can help health care providers
avoid some of the common security gaps that could lead to
cyber-attack intrusions and data loss.
Administrative
safeguards are
administrative actions,
policies, and procedures
to prevent, detect,
contain, and correct
security violations.
Administrative
SECURITY RULE SAFEGUARDS
These safeguards are
physical measures,
policies, and
procedures to protect
electronic information
systems and
equipment from
natural and
environmental
hazards and
unauthorized
intrusion.
Physical
These standards require
a CE to have contracts
or other arrangements
with BAs that will have
access to the CE’s
ePHI.
Organizational
These standards
require a CE to adopt
reasonable and
appropriate policies
and procedures to
comply with the
provisions of the
Security Rule
Policies
The HIPAA Breach Notification Rule
A breach is, generally, an impermissible use or disclosure
under the Privacy Rule that compromises the security or
privacy of PHI.
RISK ASSESSMENT
PROCESS FOR
BREACHES
When you suspect a breach of unsecured PHI has
occurred, first conduct a risk assessment in order to
examine the likelihood that the PHI has been
compromised.
REPORTING BREACHES
If after performing the risk assessment, you determine that
breach notification is required, there are three types of
notification to be made. To individuals, to the Secretary of
HHS, and, in some cases, to the media.
OTHER LAWS
AND
REQUIREMENTS
Sensitive Health Information
Some laws recognize that particular health conditions may put
individuals at a higher risk for discrimination or harm based on that
condition. Some state laws require special treatment and handling of
information relating to alcohol and drug abuse, genetics, domestic
violence, mental health, and HIV/AIDS
Adolescent/Minors’ Information
State and federal laws generally authorize a parent or guardian
access. Depending on age and health condition (e.g., reproductive
health, child abuse, mental health minors also have privacy
protections related to their ability to consent for certain services
under federal or state law.
Private Sector
A contracting health plan or payer may require additional
confidentiality or safeguards
HealthIT.Gov
Guide to Privacy and Security
The HIPAA Security Rule
Summary of the Security Rule
The HIPAA Privacy Rule
Summary of the Privacy Rule
REFERENCES
wwww.damianknowles.com

More Related Content

What's hot

Hipaa overview 073118
Hipaa overview 073118Hipaa overview 073118
Hipaa overview 073118robint2125
 
HIPAA 101- What all Doctors NEED to know
HIPAA 101- What all Doctors NEED to knowHIPAA 101- What all Doctors NEED to know
HIPAA 101- What all Doctors NEED to knowCompliancy Group
 
Welcome to HIPAA Training
Welcome to HIPAA TrainingWelcome to HIPAA Training
Welcome to HIPAA TrainingJonathan Montes
 
Presentation hippa
Presentation hippaPresentation hippa
Presentation hippamaggie_Platt
 
HIPPA Compliance
HIPPA ComplianceHIPPA Compliance
HIPPA Compliancedixibee
 
2017 HIPAA Clinical Research Training
2017 HIPAA Clinical Research Training2017 HIPAA Clinical Research Training
2017 HIPAA Clinical Research TrainingCynthia Holland
 
Data protection in_india
Data protection in_indiaData protection in_india
Data protection in_indiaAltacit Global
 
Privacy and social media in the workplace
Privacy and social media in the workplacePrivacy and social media in the workplace
Privacy and social media in the workplaceBailey and Wyant PLLC
 
WB-2022-01-25-India Data Protection Bill
WB-2022-01-25-India Data Protection BillWB-2022-01-25-India Data Protection Bill
WB-2022-01-25-India Data Protection BillTrustArc
 
Confidentiality New Employee Training (First-Week)
Confidentiality New Employee Training (First-Week)Confidentiality New Employee Training (First-Week)
Confidentiality New Employee Training (First-Week)ChildrensHomeIllinois
 
Personal Data Protection in Malaysia
Personal Data Protection in MalaysiaPersonal Data Protection in Malaysia
Personal Data Protection in Malaysiakhenghoe
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...Cvent
 
Personal Data Protection Act - Employee Data Privacy
Personal Data Protection Act - Employee Data PrivacyPersonal Data Protection Act - Employee Data Privacy
Personal Data Protection Act - Employee Data PrivacylegalPadmin
 

What's hot (20)

Hipaa overview 073118
Hipaa overview 073118Hipaa overview 073118
Hipaa overview 073118
 
HIPAA 101- What all Doctors NEED to know
HIPAA 101- What all Doctors NEED to knowHIPAA 101- What all Doctors NEED to know
HIPAA 101- What all Doctors NEED to know
 
Welcome to HIPAA Training
Welcome to HIPAA TrainingWelcome to HIPAA Training
Welcome to HIPAA Training
 
HIPAA Privacy & Security
HIPAA Privacy & SecurityHIPAA Privacy & Security
HIPAA Privacy & Security
 
Hipaa for business associates simple
Hipaa for business associates   simpleHipaa for business associates   simple
Hipaa for business associates simple
 
Presentation hippa
Presentation hippaPresentation hippa
Presentation hippa
 
HIPPA Compliance
HIPPA ComplianceHIPPA Compliance
HIPPA Compliance
 
2017 HIPAA Clinical Research Training
2017 HIPAA Clinical Research Training2017 HIPAA Clinical Research Training
2017 HIPAA Clinical Research Training
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
Overview on data privacy
Overview on data privacy Overview on data privacy
Overview on data privacy
 
HIPAA
HIPAAHIPAA
HIPAA
 
Data protection in_india
Data protection in_indiaData protection in_india
Data protection in_india
 
HIPAA and How it Applies to You
HIPAA and How it Applies to YouHIPAA and How it Applies to You
HIPAA and How it Applies to You
 
Privacy and social media in the workplace
Privacy and social media in the workplacePrivacy and social media in the workplace
Privacy and social media in the workplace
 
WB-2022-01-25-India Data Protection Bill
WB-2022-01-25-India Data Protection BillWB-2022-01-25-India Data Protection Bill
WB-2022-01-25-India Data Protection Bill
 
Confidentiality New Employee Training (First-Week)
Confidentiality New Employee Training (First-Week)Confidentiality New Employee Training (First-Week)
Confidentiality New Employee Training (First-Week)
 
Personal Data Protection in Malaysia
Personal Data Protection in MalaysiaPersonal Data Protection in Malaysia
Personal Data Protection in Malaysia
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...
 
HIPAA for Dummies
HIPAA for DummiesHIPAA for Dummies
HIPAA for Dummies
 
Personal Data Protection Act - Employee Data Privacy
Personal Data Protection Act - Employee Data PrivacyPersonal Data Protection Act - Employee Data Privacy
Personal Data Protection Act - Employee Data Privacy
 

Similar to The Basics of HIPAA

Hipaa and patient medical record confidentiality
Hipaa and patient medical record confidentialityHipaa and patient medical record confidentiality
Hipaa and patient medical record confidentialityvflores007
 
HIPAA Workforce Training by Wayne-Holmes Mental Health Recovery Board
HIPAA Workforce Training by Wayne-Holmes Mental Health Recovery BoardHIPAA Workforce Training by Wayne-Holmes Mental Health Recovery Board
HIPAA Workforce Training by Wayne-Holmes Mental Health Recovery BoardAtlantic Training, LLC.
 
Week 1 discussion 2 hipaa and privacy training
Week 1 discussion 2 hipaa and privacy trainingWeek 1 discussion 2 hipaa and privacy training
Week 1 discussion 2 hipaa and privacy trainingvrgill22
 
Sylvia hipaa powerpoint presentation 2010(1)
Sylvia hipaa powerpoint presentation 2010(1)Sylvia hipaa powerpoint presentation 2010(1)
Sylvia hipaa powerpoint presentation 2010(1)bholmes
 
Sylvia hipaa powerpoint presentation 2010(2)
Sylvia hipaa powerpoint presentation 2010(2)Sylvia hipaa powerpoint presentation 2010(2)
Sylvia hipaa powerpoint presentation 2010(2)bholmes
 
Hipaa presentation
Hipaa presentationHipaa presentation
Hipaa presentationcjkonsella
 
Knowing confidentiality
Knowing confidentialityKnowing confidentiality
Knowing confidentialityjessie66
 
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)Sanjeev Bharwan
 
HIPAA INSERVICE 2017
HIPAA INSERVICE 2017 HIPAA INSERVICE 2017
HIPAA INSERVICE 2017 Meg Oser
 
Mha690 wk 1 fletcher
Mha690 wk 1   fletcherMha690 wk 1   fletcher
Mha690 wk 1 fletcherEmed32
 
Hipaa and patient medical record confidentiality
Hipaa and patient medical record confidentialityHipaa and patient medical record confidentiality
Hipaa and patient medical record confidentialityvflores007
 
Hipaa.ppt3
Hipaa.ppt3Hipaa.ppt3
Hipaa.ppt3akwei2
 
Hipaa.ppt5
Hipaa.ppt5Hipaa.ppt5
Hipaa.ppt5akwei2
 
Hipaa.ppt4
Hipaa.ppt4Hipaa.ppt4
Hipaa.ppt4akwei2
 
Hipaa.ppt6
Hipaa.ppt6Hipaa.ppt6
Hipaa.ppt6akwei2
 
Hipaa.ppt1
Hipaa.ppt1Hipaa.ppt1
Hipaa.ppt1akwei2
 

Similar to The Basics of HIPAA (20)

Hipaa and patient medical record confidentiality
Hipaa and patient medical record confidentialityHipaa and patient medical record confidentiality
Hipaa and patient medical record confidentiality
 
HIPAA Workforce Training by Wayne-Holmes Mental Health Recovery Board
HIPAA Workforce Training by Wayne-Holmes Mental Health Recovery BoardHIPAA Workforce Training by Wayne-Holmes Mental Health Recovery Board
HIPAA Workforce Training by Wayne-Holmes Mental Health Recovery Board
 
Week 1 discussion 2 hipaa and privacy training
Week 1 discussion 2 hipaa and privacy trainingWeek 1 discussion 2 hipaa and privacy training
Week 1 discussion 2 hipaa and privacy training
 
Sylvia hipaa powerpoint presentation 2010(1)
Sylvia hipaa powerpoint presentation 2010(1)Sylvia hipaa powerpoint presentation 2010(1)
Sylvia hipaa powerpoint presentation 2010(1)
 
Sylvia hipaa powerpoint presentation 2010(2)
Sylvia hipaa powerpoint presentation 2010(2)Sylvia hipaa powerpoint presentation 2010(2)
Sylvia hipaa powerpoint presentation 2010(2)
 
Hipaa presentation
Hipaa presentationHipaa presentation
Hipaa presentation
 
HIPAA Audio Presentation
HIPAA  Audio PresentationHIPAA  Audio Presentation
HIPAA Audio Presentation
 
Knowing confidentiality
Knowing confidentialityKnowing confidentiality
Knowing confidentiality
 
Hipaa inservice
Hipaa inserviceHipaa inservice
Hipaa inservice
 
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)
 
HIPAA INSERVICE 2017
HIPAA INSERVICE 2017 HIPAA INSERVICE 2017
HIPAA INSERVICE 2017
 
Mha 690 w1 d2
Mha 690 w1 d2Mha 690 w1 d2
Mha 690 w1 d2
 
Hipaa training
Hipaa trainingHipaa training
Hipaa training
 
Mha690 wk 1 fletcher
Mha690 wk 1   fletcherMha690 wk 1   fletcher
Mha690 wk 1 fletcher
 
Hipaa and patient medical record confidentiality
Hipaa and patient medical record confidentialityHipaa and patient medical record confidentiality
Hipaa and patient medical record confidentiality
 
Hipaa.ppt3
Hipaa.ppt3Hipaa.ppt3
Hipaa.ppt3
 
Hipaa.ppt5
Hipaa.ppt5Hipaa.ppt5
Hipaa.ppt5
 
Hipaa.ppt4
Hipaa.ppt4Hipaa.ppt4
Hipaa.ppt4
 
Hipaa.ppt6
Hipaa.ppt6Hipaa.ppt6
Hipaa.ppt6
 
Hipaa.ppt1
Hipaa.ppt1Hipaa.ppt1
Hipaa.ppt1
 

Recently uploaded

MAGNESIUM - ELECTROLYTE IMBALANCE (HYPERMAGNESEMIA & HYPOMAGNESEMIA).pdf
MAGNESIUM - ELECTROLYTE IMBALANCE (HYPERMAGNESEMIA & HYPOMAGNESEMIA).pdfMAGNESIUM - ELECTROLYTE IMBALANCE (HYPERMAGNESEMIA & HYPOMAGNESEMIA).pdf
MAGNESIUM - ELECTROLYTE IMBALANCE (HYPERMAGNESEMIA & HYPOMAGNESEMIA).pdfDolisha Warbi
 
Spauldings classification ppt by Dr C P PRINCE
Spauldings classification ppt by Dr C P PRINCESpauldings classification ppt by Dr C P PRINCE
Spauldings classification ppt by Dr C P PRINCEDR.PRINCE C P
 
Test bank for community public health nursing evidence for practice 4TH editi...
Test bank for community public health nursing evidence for practice 4TH editi...Test bank for community public health nursing evidence for practice 4TH editi...
Test bank for community public health nursing evidence for practice 4TH editi...robinsonayot
 
❤️ Chandigarh Call Girls ☎️99158-51334☎️ Escort service in Chandigarh ☎️ Chan...
❤️ Chandigarh Call Girls ☎️99158-51334☎️ Escort service in Chandigarh ☎️ Chan...❤️ Chandigarh Call Girls ☎️99158-51334☎️ Escort service in Chandigarh ☎️ Chan...
❤️ Chandigarh Call Girls ☎️99158-51334☎️ Escort service in Chandigarh ☎️ Chan...rajveerescorts2022
 
Cash Payment 😋 +9316020077 Goa Call Girl No Advance *Full Service
Cash Payment 😋  +9316020077 Goa Call Girl No Advance *Full ServiceCash Payment 😋  +9316020077 Goa Call Girl No Advance *Full Service
Cash Payment 😋 +9316020077 Goa Call Girl No Advance *Full ServiceReal Sex Provide In Goa
 
Top 10 Famous Indian Pornstar - Top 10 Female Porn Star Name List 2024
Top 10 Famous Indian Pornstar - Top 10 Female Porn Star Name List 2024Top 10 Famous Indian Pornstar - Top 10 Female Porn Star Name List 2024
Top 10 Famous Indian Pornstar - Top 10 Female Porn Star Name List 2024Inaayaeventcompany
 
Test Bank -Medical-Surgical Nursing Concepts for Interprofessional Collaborat...
Test Bank -Medical-Surgical Nursing Concepts for Interprofessional Collaborat...Test Bank -Medical-Surgical Nursing Concepts for Interprofessional Collaborat...
Test Bank -Medical-Surgical Nursing Concepts for Interprofessional Collaborat...rightmanforbloodline
 
Call Girls Service In Jalandhar💯Call Us 🔝 8146719683🔝 💃 Top Class ☎️ Call Gir...
Call Girls Service In Jalandhar💯Call Us 🔝 8146719683🔝 💃 Top Class ☎️ Call Gir...Call Girls Service In Jalandhar💯Call Us 🔝 8146719683🔝 💃 Top Class ☎️ Call Gir...
Call Girls Service In Jalandhar💯Call Us 🔝 8146719683🔝 💃 Top Class ☎️ Call Gir...daljeetkaur2026
 
Agra Call Girl 📲 ( 9084454195 ) ⏎ Independent Call Girls In Agra By Meera
Agra Call Girl 📲 ( 9084454195 ) ⏎ Independent Call Girls In Agra By MeeraAgra Call Girl 📲 ( 9084454195 ) ⏎ Independent Call Girls In Agra By Meera
Agra Call Girl 📲 ( 9084454195 ) ⏎ Independent Call Girls In Agra By MeeraInaayaeventcompany
 
RESPIRATORY ALKALOSIS & RESPIRATORY ACIDOSIS.pdf
RESPIRATORY ALKALOSIS & RESPIRATORY ACIDOSIS.pdfRESPIRATORY ALKALOSIS & RESPIRATORY ACIDOSIS.pdf
RESPIRATORY ALKALOSIS & RESPIRATORY ACIDOSIS.pdfDolisha Warbi
 
Real Sex Provide In Goa ✂️ Call Girl (9316020077) Call Girl In Goa
Real Sex Provide In Goa ✂️ Call Girl   (9316020077) Call Girl In GoaReal Sex Provide In Goa ✂️ Call Girl   (9316020077) Call Girl In Goa
Real Sex Provide In Goa ✂️ Call Girl (9316020077) Call Girl In GoaReal Sex Provide In Goa
 
Independent Call Girl in 😋 Goa +9316020077 Goa Call Girl
Independent Call Girl in 😋 Goa  +9316020077 Goa Call GirlIndependent Call Girl in 😋 Goa  +9316020077 Goa Call Girl
Independent Call Girl in 😋 Goa +9316020077 Goa Call GirlReal Sex Provide In Goa
 
Call Girls In Kharar 💯Call Us 🔝 9915851334🔝 💃 Top Class ☎️ Call Girl Service ...
Call Girls In Kharar 💯Call Us 🔝 9915851334🔝 💃 Top Class ☎️ Call Girl Service ...Call Girls In Kharar 💯Call Us 🔝 9915851334🔝 💃 Top Class ☎️ Call Girl Service ...
Call Girls In Kharar 💯Call Us 🔝 9915851334🔝 💃 Top Class ☎️ Call Girl Service ...daljeetkaur2026
 
TIME FOR ACTION: MAY 2024 Securing A Strong Nursing Workforce for North Carolina
TIME FOR ACTION: MAY 2024 Securing A Strong Nursing Workforce for North CarolinaTIME FOR ACTION: MAY 2024 Securing A Strong Nursing Workforce for North Carolina
TIME FOR ACTION: MAY 2024 Securing A Strong Nursing Workforce for North CarolinaMebane Rash
 
ISO 15189 2022 standards for laboratory quality and competence
ISO 15189 2022 standards for laboratory quality and competenceISO 15189 2022 standards for laboratory quality and competence
ISO 15189 2022 standards for laboratory quality and competencePathKind Labs
 
TEST BANK For Little and Falace's Dental Management of the Medically Compromi...
TEST BANK For Little and Falace's Dental Management of the Medically Compromi...TEST BANK For Little and Falace's Dental Management of the Medically Compromi...
TEST BANK For Little and Falace's Dental Management of the Medically Compromi...rightmanforbloodline
 
Bobath Technique (Samrth Pareta) .ppt.pptx
Bobath Technique (Samrth Pareta) .ppt.pptxBobath Technique (Samrth Pareta) .ppt.pptx
Bobath Technique (Samrth Pareta) .ppt.pptxSamrth Pareta
 
Making change happen: learning from "positive deviancts"
Making change happen: learning from "positive deviancts"Making change happen: learning from "positive deviancts"
Making change happen: learning from "positive deviancts"HelenBevan4
 

Recently uploaded (20)

MAGNESIUM - ELECTROLYTE IMBALANCE (HYPERMAGNESEMIA & HYPOMAGNESEMIA).pdf
MAGNESIUM - ELECTROLYTE IMBALANCE (HYPERMAGNESEMIA & HYPOMAGNESEMIA).pdfMAGNESIUM - ELECTROLYTE IMBALANCE (HYPERMAGNESEMIA & HYPOMAGNESEMIA).pdf
MAGNESIUM - ELECTROLYTE IMBALANCE (HYPERMAGNESEMIA & HYPOMAGNESEMIA).pdf
 
Spauldings classification ppt by Dr C P PRINCE
Spauldings classification ppt by Dr C P PRINCESpauldings classification ppt by Dr C P PRINCE
Spauldings classification ppt by Dr C P PRINCE
 
Abortion pills Buy Farwaniya (+918133066128) Cytotec 200mg tablets Al AHMEDI
Abortion pills Buy Farwaniya (+918133066128) Cytotec 200mg tablets Al AHMEDIAbortion pills Buy Farwaniya (+918133066128) Cytotec 200mg tablets Al AHMEDI
Abortion pills Buy Farwaniya (+918133066128) Cytotec 200mg tablets Al AHMEDI
 
Test bank for community public health nursing evidence for practice 4TH editi...
Test bank for community public health nursing evidence for practice 4TH editi...Test bank for community public health nursing evidence for practice 4TH editi...
Test bank for community public health nursing evidence for practice 4TH editi...
 
❤️ Chandigarh Call Girls ☎️99158-51334☎️ Escort service in Chandigarh ☎️ Chan...
❤️ Chandigarh Call Girls ☎️99158-51334☎️ Escort service in Chandigarh ☎️ Chan...❤️ Chandigarh Call Girls ☎️99158-51334☎️ Escort service in Chandigarh ☎️ Chan...
❤️ Chandigarh Call Girls ☎️99158-51334☎️ Escort service in Chandigarh ☎️ Chan...
 
Cash Payment 😋 +9316020077 Goa Call Girl No Advance *Full Service
Cash Payment 😋  +9316020077 Goa Call Girl No Advance *Full ServiceCash Payment 😋  +9316020077 Goa Call Girl No Advance *Full Service
Cash Payment 😋 +9316020077 Goa Call Girl No Advance *Full Service
 
Top 10 Famous Indian Pornstar - Top 10 Female Porn Star Name List 2024
Top 10 Famous Indian Pornstar - Top 10 Female Porn Star Name List 2024Top 10 Famous Indian Pornstar - Top 10 Female Porn Star Name List 2024
Top 10 Famous Indian Pornstar - Top 10 Female Porn Star Name List 2024
 
Test Bank -Medical-Surgical Nursing Concepts for Interprofessional Collaborat...
Test Bank -Medical-Surgical Nursing Concepts for Interprofessional Collaborat...Test Bank -Medical-Surgical Nursing Concepts for Interprofessional Collaborat...
Test Bank -Medical-Surgical Nursing Concepts for Interprofessional Collaborat...
 
Call Girls Service In Jalandhar💯Call Us 🔝 8146719683🔝 💃 Top Class ☎️ Call Gir...
Call Girls Service In Jalandhar💯Call Us 🔝 8146719683🔝 💃 Top Class ☎️ Call Gir...Call Girls Service In Jalandhar💯Call Us 🔝 8146719683🔝 💃 Top Class ☎️ Call Gir...
Call Girls Service In Jalandhar💯Call Us 🔝 8146719683🔝 💃 Top Class ☎️ Call Gir...
 
Agra Call Girl 📲 ( 9084454195 ) ⏎ Independent Call Girls In Agra By Meera
Agra Call Girl 📲 ( 9084454195 ) ⏎ Independent Call Girls In Agra By MeeraAgra Call Girl 📲 ( 9084454195 ) ⏎ Independent Call Girls In Agra By Meera
Agra Call Girl 📲 ( 9084454195 ) ⏎ Independent Call Girls In Agra By Meera
 
RESPIRATORY ALKALOSIS & RESPIRATORY ACIDOSIS.pdf
RESPIRATORY ALKALOSIS & RESPIRATORY ACIDOSIS.pdfRESPIRATORY ALKALOSIS & RESPIRATORY ACIDOSIS.pdf
RESPIRATORY ALKALOSIS & RESPIRATORY ACIDOSIS.pdf
 
Real Sex Provide In Goa ✂️ Call Girl (9316020077) Call Girl In Goa
Real Sex Provide In Goa ✂️ Call Girl   (9316020077) Call Girl In GoaReal Sex Provide In Goa ✂️ Call Girl   (9316020077) Call Girl In Goa
Real Sex Provide In Goa ✂️ Call Girl (9316020077) Call Girl In Goa
 
Independent Call Girl in 😋 Goa +9316020077 Goa Call Girl
Independent Call Girl in 😋 Goa  +9316020077 Goa Call GirlIndependent Call Girl in 😋 Goa  +9316020077 Goa Call Girl
Independent Call Girl in 😋 Goa +9316020077 Goa Call Girl
 
Call Girls In Kharar 💯Call Us 🔝 9915851334🔝 💃 Top Class ☎️ Call Girl Service ...
Call Girls In Kharar 💯Call Us 🔝 9915851334🔝 💃 Top Class ☎️ Call Girl Service ...Call Girls In Kharar 💯Call Us 🔝 9915851334🔝 💃 Top Class ☎️ Call Girl Service ...
Call Girls In Kharar 💯Call Us 🔝 9915851334🔝 💃 Top Class ☎️ Call Girl Service ...
 
@Safe Abortion pills IN Jeddah(+918133066128) Un_wanted kit Buy Jeddah
@Safe Abortion pills IN Jeddah(+918133066128) Un_wanted kit Buy Jeddah@Safe Abortion pills IN Jeddah(+918133066128) Un_wanted kit Buy Jeddah
@Safe Abortion pills IN Jeddah(+918133066128) Un_wanted kit Buy Jeddah
 
TIME FOR ACTION: MAY 2024 Securing A Strong Nursing Workforce for North Carolina
TIME FOR ACTION: MAY 2024 Securing A Strong Nursing Workforce for North CarolinaTIME FOR ACTION: MAY 2024 Securing A Strong Nursing Workforce for North Carolina
TIME FOR ACTION: MAY 2024 Securing A Strong Nursing Workforce for North Carolina
 
ISO 15189 2022 standards for laboratory quality and competence
ISO 15189 2022 standards for laboratory quality and competenceISO 15189 2022 standards for laboratory quality and competence
ISO 15189 2022 standards for laboratory quality and competence
 
TEST BANK For Little and Falace's Dental Management of the Medically Compromi...
TEST BANK For Little and Falace's Dental Management of the Medically Compromi...TEST BANK For Little and Falace's Dental Management of the Medically Compromi...
TEST BANK For Little and Falace's Dental Management of the Medically Compromi...
 
Bobath Technique (Samrth Pareta) .ppt.pptx
Bobath Technique (Samrth Pareta) .ppt.pptxBobath Technique (Samrth Pareta) .ppt.pptx
Bobath Technique (Samrth Pareta) .ppt.pptx
 
Making change happen: learning from "positive deviancts"
Making change happen: learning from "positive deviancts"Making change happen: learning from "positive deviancts"
Making change happen: learning from "positive deviancts"
 

The Basics of HIPAA

  • 1. SECTION 1 THE BASICS OF HIPAA COMPLIANCE A B E G I N N E R ' S G U I D E
  • 2. COURSE OUTLINE W H A T W E ' R E C O V E R I N G We will cover the progression of HIPAA from origin until the present. This presentation will include COVID19 updates. Next, we will focus on The HIPAA Privacy and Security Rules.
  • 3. DISCLAIMER This Guide is not intended to serve as legal advice or as recommendations based on a provider or professional’s specific circumstances. We encourage providers and professionals to seek expert advice when evaluating the use of this Guide. D A M I A N K N O W L E S
  • 4. A B R I E F H I S T O R Y WHAT IS HIPAA? HIPAA is an acronym for “The Health Insurance Portability and Accountability Act.” This Act covers Privacy, Security, and Breach Notification Rules which protect a patient’s health information. It protects the civil rights of their health information. D A M I A N K N O W L E S
  • 5. A B R I E F H I S T O R Y WHEN WAS HIPAA STARTED? HIPAA came into existence on August 21st, 1996 and it was signed into law by President Bill Clinton. D A M I A N K N O W L E S
  • 6. A B R I E F H I S T O R Y WHAT IS THE INTENT OF HIPAA? HIPAA is meant to improve the level of responsibility and portability of the health insurance for employees between their jobs. Another objective was to curb corruption by health insurance and the health care industry as a whole. HIPAA administered guidelines for the healthcare industry to protect the patient’s medical health records. As technology advanced, the Act by means of the Health Information Technology for Economic and Clinical Health Act (HITECH) in 2009, provided a financial incentive for healthcare providers to migrate to electronic health record maintenance. Meanwhile, Congress recognized that advances in electronic technology could negatively impact the privacy of health information. Consequently, Congress incorporated provisions that required the adoption of Federal privacy protections for individually identifiable health information. D A M I A N K N O W L E S
  • 7. A B R I E F H I S T O R Y WHO MUST COMPLY WITH HIPAA? Covered entities and business associates, as applicable, must follow HIPAA rules. If an entity does not meet the definition of a covered entity or business associate, it does not have to comply with the HIPAA rules D A M I A N K N O W L E S
  • 8. COMMONLY USED TERMS Implementation Specification An implementation specification is a more detailed description of the method or approach primary care organizations can use to meet a particular requirement Addressable Addressable means that there is flexibility in how the implementation is made not if it is made. It means you must address the specification in some way or address the standard itself in some way by at least assessing the risk. Required “Required” rules simply mean that you implement them, or you automatically fail to comply with the Security Rule.
  • 9. BUSINESS ASSOCIATES A business associate is a person or organization, other than a workforce member of a covered entity, that performs certain functions on behalf of or provides certain services to, a covered entity that involves access to PHI. WHAT IS A COVERED ENTITY? Presentations are communication tools that can be used as demonstrations, lectures, speeches, reports, and more.
  • 10. • H E A L T H C A R E P R O V I D E R S , • H O S P I T A L S , • N U R S I N G H O M E S , A N D • P H A R M A C I E S . • H E A L T H P L A N S • H E A L T H C A R E C L E A R I N G H O U S E S Examples of Covered Entities A N Y S U B C O N T R A C T O R O F A C O V E R E D E N T I T Y W I T H A C C E S S T O P R O T E C T E D H E A L T H I N F O R M A T I O N : • E - P R E S C R I B E R G A T E W A Y S , • T R A N S C R I P T I O N I S T S • L A W Y E R S Examples of Business Associates
  • 11. 3 MUST KNOW HIPAA RULES The Breach Notification Rule, requires covered entities to notify affected individuals; U.S. Department of Health & Human Services (HHS); and, in some cases, the media of a breach of unsecured PHI. The Breach Notification Rule The Security Rule specifies safeguards that covered entities and their business associates must implement to protect the confidentiality, integrity, and availability of electronically protected health information (ePHI) The Security Rule The Privacy Rule, sets national standards for when protected health information (PHI) may be used and disclosed The Privacy Rule
  • 12. H I P A A B A S I C S WHAT TYPES OF INFORMATION DOES HIPAA PROTECT? The Privacy Rule protects most individually identifiable health information held or transmitted by a CE or its BA, in any form or media, whether electronic, paper or oral. The Privacy Rule calls this information “protected health information” or “PHI.”
  • 13. C O M M O N L Y U S E D T E R M S WHAT IS PROTECTED HEALTH INFORMATION? Protected Health Information (PHI) is defined as any individually identifiable health information collected or created as a consequence of the provision of health care by a covered entity, in any form, including verbal communications.PHI is information that can be linked to a particular person and that is created, used, or disclosed while providing a health care service (i.e., diagnosis or treatment)
  • 14. H I P A A B A S I C S WHO IS RESPONSIBLE FOR ENFORCEMENT? The HHS Office for Civil Rights Health and Human Services, Office for Civil Rights, handles the enforcement of the HIPAA Privacy and Security Rules.
  • 15. A laptop with 1,391 individuals’ ePHI was stolen. $2.5M The investigation revealed insufficient risk analysis and risk management processes in place at the time of the theft.
  • 16. F I N E S A R E B A S E D O N I N T E N T PENALTIES FOR VIOLATIONS • Did Not Know or Could Not Have Known • Reasonable Cause and Not Willful Neglect • Willful Neglect, but Corrected Within 30 Days • Willful Neglect and Not Corrected Within 30 Days 0 K 25,000 K 50,000 K 75,000 K 100,000 K 125,000 K Wilful 30+ Wilful 30 Reasonable Didn't Know
  • 17. HIPAA BASICS THE HIPAA PRIVACY RULE H I P A A P R I V A C Y R U L E L I M I T S U S E S A N D D I S C L O S U R E S O F P A T I E N T I N F O R M A T I O N
  • 18. Yes, a CE must prominently post and distribute an NPP. The notice must describe the ways in which the CE may use and disclose PHI. The notice must state the CE’s duties to protect privacy, provide an NPP, and abide by the terms of the current notice. DO I NEED TO INFORM MY PATIENTS ABOUT HOW I USE OR DISCLOSE THEIR HEALTH INFORMATION?
  • 19. NPPs must include the following information: • How the CE may use and disclose an individual’s PHI • The individual’s rights with respect to the information • A statement that the CE is required by law to display the privacy policies and how the individual may exercise these rights, • How the individual may complain to the CE • The CE’s legal duties with respect to the information, maintain the privacy of PHI • Whom individuals can contact for further information NOTICE OF PRIVACY PRACTICES
  • 20. • A CE may disclose PHI when: • Treating a Patient, • Managing Payment Activities, • Both CE's have a relationship with the patient, • Quality assessments Assessment Reviews, or • Fraud and abuse detection or compliance. DO I HAVE TO GET MY PATIENTS’ PERMISSION TO DISCLOSE THEIR PHI WITH ANOTHER CE?
  • 21. You may disclose, without a patient’s authorization, PHI about the patient as necessary for treatment, payment, and health care operations purposes. WHEN ARE PATIENT AUTHORIZATIONS NOT REQUIRED FOR DISCLOSURE?
  • 22. Yes. To make disclosures to family and friends involved in the individual’s care or for notification purposes, or to other persons whom the individual identifies, you must obtain informal permission by asking the individual outright, or by determining that the individual did not object in circumstances that clearly gave the individual the opportunity to agree, acquiesce, or object. DO I NEED PERMISSION FOR DISCLOSURES TO FAMILY, FRIENDS, AND OTHERS INVOLVED IN THE CARE OF THE INDIVIDUAL AS WELL AS FOR NOTIFICATION PURPOSES?
  • 23. You may disclose PHI without individual authorization in the following situations: • To send immunization records to schools, • To a public health authority that is authorized by law • To a foreign government agency • To persons at risk of contracting or spreading a disease DO I NEED PERMISSION FOR DISCLOSURES INFORMATION IF NEEDED TO ENSURE PUBLIC HEALTH AND SAFETY ?
  • 24. WHEN ARE PATIENT AUTHORIZATIONS REQUIRED FOR DISCLOSURE? Psychotherapy Notes Marketing Activities PHI Sales and Licensing Research
  • 25. WHAT IS DE-IDENTIFIED PHI? D E - I D E N T I F I E D H E A L T H I N F O R M A T I O N N E I T H E R I D E N T I F I E S N O R P R O V I D E S A R E A S O N A B L E B A S I S T O I D E N T I F Y A N I N D I V I D U A L .
  • 26. WHAT ABOUT PATIENT INFORMATION PERTAINING TO BEHAVIORAL HEALTH OR SUBSTANCE ABUSE? T H E H I P A A R U L E S A P P L Y E Q U A L L Y T O A L L P H I , I N C L U D I N G I N D I V I D U A L L Y I D E N T I F I A B L E B E H A V I O R A L H E A L T H O R S U B S T A N C E A B U S E I N F O R M A T I O N T H A T Y O U R P R A C T I C E C O L L E C T S O R M A I N T A I N S I N A P A T I E N T S ’ R E C O R D .
  • 27. FEDERAL AND STATE PRIVACY LAWS — WHICH PREVAIL? T H E H I P A A R U L E S D O N O T O V E R R I D E S U C H S T A T E L A W S T H A T D O N O T C O N F L I C T W I T H T H E R U L E S A N D O F F E R G R E A T E R P R I V A C Y P R O T E C T I O N S
  • 28. The HIPAA Security Rule These Security Rule safeguards can help health care providers avoid some of the common security gaps that could lead to cyber-attack intrusions and data loss.
  • 29. Administrative safeguards are administrative actions, policies, and procedures to prevent, detect, contain, and correct security violations. Administrative SECURITY RULE SAFEGUARDS These safeguards are physical measures, policies, and procedures to protect electronic information systems and equipment from natural and environmental hazards and unauthorized intrusion. Physical These standards require a CE to have contracts or other arrangements with BAs that will have access to the CE’s ePHI. Organizational These standards require a CE to adopt reasonable and appropriate policies and procedures to comply with the provisions of the Security Rule Policies
  • 30. The HIPAA Breach Notification Rule A breach is, generally, an impermissible use or disclosure under the Privacy Rule that compromises the security or privacy of PHI.
  • 31. RISK ASSESSMENT PROCESS FOR BREACHES When you suspect a breach of unsecured PHI has occurred, first conduct a risk assessment in order to examine the likelihood that the PHI has been compromised.
  • 32. REPORTING BREACHES If after performing the risk assessment, you determine that breach notification is required, there are three types of notification to be made. To individuals, to the Secretary of HHS, and, in some cases, to the media.
  • 33. OTHER LAWS AND REQUIREMENTS Sensitive Health Information Some laws recognize that particular health conditions may put individuals at a higher risk for discrimination or harm based on that condition. Some state laws require special treatment and handling of information relating to alcohol and drug abuse, genetics, domestic violence, mental health, and HIV/AIDS Adolescent/Minors’ Information State and federal laws generally authorize a parent or guardian access. Depending on age and health condition (e.g., reproductive health, child abuse, mental health minors also have privacy protections related to their ability to consent for certain services under federal or state law. Private Sector A contracting health plan or payer may require additional confidentiality or safeguards
  • 34. HealthIT.Gov Guide to Privacy and Security The HIPAA Security Rule Summary of the Security Rule The HIPAA Privacy Rule Summary of the Privacy Rule REFERENCES