SlideShare a Scribd company logo
1 of 13
Philadelphia Center 
N.W. Louisiana AIDS Resource Center 
http://www.hhs.gov/ocr/privacy/
Electronic Health Information Exchange in 
a Networked Environment 
Introduction to HIPAA 
Health Information Portability and Accountability Act of (1996)
HIPAA Basics 
 HIPAA compliance and 
confidentiality must be 
maintained for the sake of 
the client, the employee, 
and the organization. 
 Compliance is mandatory 
for any organization dealing 
with medical records. 
 HIPAA stands for Health 
Insurance Portability & 
Accountability Act of 1996. 
 PHI stands for Protected 
Health Information. 
 TPO stands for Treatment , 
Payment, and Operations. 
 OCR stands for Office of Civil 
Rights—Hotline #: (1- 
800-537-7697) 
 HIO stands for Health 
Information Organization. 
 PRP stands for Privacy Rule 
Policies
HIPAA Basics 
 All client information and 
money spent at the 
Philadelphia Center needs to 
be protected and HIPAA has 
guidelines to help us do this. 
 HIPAA also has audits that 
makes sure the Philadelphia 
Center is within guideline 
limits and the Audit is tough. 
 We, the IT’s, are aware of 
HIPAA and the necessary 
things needed to make sure 
the Philadelphia Center is in 
compliance. 
There should be openness and 
transparency about policies, 
procedures, and technologies that 
directly affect individuals and/or 
their individually identifiable health 
information (PHI).
HIPAA 
Philadelphia Center 
Accountability 
 A HIPAA audit will look something like this: 
 We need to make sure that we have all bases covered in 
case they decide to make us their next audit.
The Privacy Rule 
 The Standards for Privacy of Individually Identifiable Health 
Information (“Privacy Rule”) establishes, for the first time, a set of 
national standards for the protection of certain health information. 
 The U.S. Department of Health and Human Services (“HHS”) issued 
the Privacy Rule to implement the requirement of the Health 
Insurance Portability and Accountability Act of 1996 (“HIPAA”).
The Privacy Rule 
 The Privacy Rule standards address the use and disclosure of 
individuals’ health information—called “Protected Health 
Information” by organizations subject to the Privacy Rule — called 
“covered entities,” as well as standards for individuals' privacy rights 
to understand and control how their health information is used. 
 Within HHS, the Office for Civil Rights (“OCR”) has responsibility 
for implementing and enforcing the Privacy Rule with respect to 
voluntary compliance activities and civil money penalties.
Electronic Health Information Exchange in 
a Networked Environment 
Accountability 
Health Insurance Portability and Accountability Act of 1996 (“HIPAA”)
ACCOUNTABILITY 
 The Privacy Rule provides the foundation for accountability 
within an electronic health information exchange 
environment 
 Requires covered entities (Philadelphia Center) that 
exchange Protected Health Information (PHI) to comply with 
its administrative requirements 
 Requires Philadelphia Center employees to adhere to the 
HIPAA privacy rules
ACCOUNTABILITY 
Administrative 
Requirements 
 The Philadelphia Center must have 
written policies and procedures in place 
to implement privacy standards See 45 
C.F.R. § 164.530(b) 
 Employees should be trained on those 
policies and procedures 
 The Philadelphia Center director must 
reprimand employees who violate 
established Privacy Rule Policies [See 45 
C.F.R. § 164.530(e)] 
Privacy Rule Requirements 
 A Philadelphia Center, Client complaint 
form has to be created See 45 C.F.R. § 
164.530(d) 
 A Notice of Privacy Practices has to be 
sent to every Philadelphia Center 
client 
 Contact information and instructions 
on how to file complaints should be 
included with the Notice of Privacy See 
45 C.F.R. § 164.530(b)(1)(vi)-(vii)
Electronic Health Information Exchange in 
a Networked Environment 
Collection, Use, and 
Disclosure Limitation 
Health Insurance Portability and Accountability Act of 1996 (“HIPAA”)
Permitted Uses 
& Disclosures 
 To the Individual 
 Used for Philadelphia’s 
Treatment, Payments, 
Health Care Operations 
 Uses and Disclosures with 
Opportunity to Agree or 
Object 
 Incidental Use and 
Disclosure 
 Public Interest and Benefit 
Activities 
 Limited Data Set 
 Basic Principle 
 Required Disclosures
Philadelphia Center 
N.W. Louisiana AIDS Resource Center 
http://www.hhs.gov/ocr/privacy/

More Related Content

What's hot

Mha 690 presentation hippa
Mha 690 presentation hippaMha 690 presentation hippa
Mha 690 presentation hippabelle0508
 
Application Developers Guide to HIPAA Compliance
Application Developers Guide to HIPAA ComplianceApplication Developers Guide to HIPAA Compliance
Application Developers Guide to HIPAA ComplianceTrueVault
 
HIPAA Compliance Checklist
HIPAA Compliance ChecklistHIPAA Compliance Checklist
HIPAA Compliance ChecklistLeigh-Ann Renz
 
HIPAA Privacy Filter - PrivacyDevil is the only HIPAA Compliant Privacy Filter
HIPAA Privacy Filter - PrivacyDevil is the only HIPAA Compliant Privacy FilterHIPAA Privacy Filter - PrivacyDevil is the only HIPAA Compliant Privacy Filter
HIPAA Privacy Filter - PrivacyDevil is the only HIPAA Compliant Privacy FilterJessica Arevalo
 
Confidentiality Rules
Confidentiality RulesConfidentiality Rules
Confidentiality Ruleskholman1
 
Is your billing partner hipaa compliant
Is your billing partner hipaa compliantIs your billing partner hipaa compliant
Is your billing partner hipaa compliantjennyvergeese
 
Importance of Following HITECH Compliance Guidelines
Importance of Following HITECH Compliance Guidelines Importance of Following HITECH Compliance Guidelines
Importance of Following HITECH Compliance Guidelines Aegify Inc.
 
HIPAA 101 for Startups
HIPAA 101 for StartupsHIPAA 101 for Startups
HIPAA 101 for StartupsObaa, Inc.
 
Week 1 privacy and security training
Week 1 privacy and security trainingWeek 1 privacy and security training
Week 1 privacy and security trainingSonja Davis
 
HIPAA Compliance For Small Practices
HIPAA Compliance For Small PracticesHIPAA Compliance For Small Practices
HIPAA Compliance For Small PracticesNisos Health
 
HIPAA Access Medical Records by Sainsbury-Wong
HIPAA Access Medical Records by Sainsbury-WongHIPAA Access Medical Records by Sainsbury-Wong
HIPAA Access Medical Records by Sainsbury-WongLorianne Sainsbury-Wong
 
HIPAA Training Basics
HIPAA Training BasicsHIPAA Training Basics
HIPAA Training Basicssecky65
 
Assessing Your Hosting Environment for HIPAA Compliance
Assessing Your Hosting Environment for HIPAA ComplianceAssessing Your Hosting Environment for HIPAA Compliance
Assessing Your Hosting Environment for HIPAA ComplianceHostway|HOSTING
 
HIPAA | HIPAA Training
HIPAA | HIPAA TrainingHIPAA | HIPAA Training
HIPAA | HIPAA Traininghimalya sharma
 
HIPAA | HIPAA Training
HIPAA | HIPAA TrainingHIPAA | HIPAA Training
HIPAA | HIPAA Traininghimalya sharma
 
Mha690 hipaa minimum necessary week 1
Mha690 hipaa minimum necessary week 1Mha690 hipaa minimum necessary week 1
Mha690 hipaa minimum necessary week 1CynthiaRaccio
 

What's hot (20)

Hipaa
HipaaHipaa
Hipaa
 
Mha 690 presentation hippa
Mha 690 presentation hippaMha 690 presentation hippa
Mha 690 presentation hippa
 
Hippa presentation
Hippa presentationHippa presentation
Hippa presentation
 
Application Developers Guide to HIPAA Compliance
Application Developers Guide to HIPAA ComplianceApplication Developers Guide to HIPAA Compliance
Application Developers Guide to HIPAA Compliance
 
HIPAA Compliance Checklist
HIPAA Compliance ChecklistHIPAA Compliance Checklist
HIPAA Compliance Checklist
 
HIPAA Privacy Filter - PrivacyDevil is the only HIPAA Compliant Privacy Filter
HIPAA Privacy Filter - PrivacyDevil is the only HIPAA Compliant Privacy FilterHIPAA Privacy Filter - PrivacyDevil is the only HIPAA Compliant Privacy Filter
HIPAA Privacy Filter - PrivacyDevil is the only HIPAA Compliant Privacy Filter
 
Confidentiality Rules
Confidentiality RulesConfidentiality Rules
Confidentiality Rules
 
HIPAA Compliance
HIPAA Compliance HIPAA Compliance
HIPAA Compliance
 
Is your billing partner hipaa compliant
Is your billing partner hipaa compliantIs your billing partner hipaa compliant
Is your billing partner hipaa compliant
 
2010 New Guidelines Hipaa Checklist V1
2010 New Guidelines Hipaa Checklist V12010 New Guidelines Hipaa Checklist V1
2010 New Guidelines Hipaa Checklist V1
 
Importance of Following HITECH Compliance Guidelines
Importance of Following HITECH Compliance Guidelines Importance of Following HITECH Compliance Guidelines
Importance of Following HITECH Compliance Guidelines
 
HIPAA 101 for Startups
HIPAA 101 for StartupsHIPAA 101 for Startups
HIPAA 101 for Startups
 
Week 1 privacy and security training
Week 1 privacy and security trainingWeek 1 privacy and security training
Week 1 privacy and security training
 
HIPAA Compliance For Small Practices
HIPAA Compliance For Small PracticesHIPAA Compliance For Small Practices
HIPAA Compliance For Small Practices
 
HIPAA Access Medical Records by Sainsbury-Wong
HIPAA Access Medical Records by Sainsbury-WongHIPAA Access Medical Records by Sainsbury-Wong
HIPAA Access Medical Records by Sainsbury-Wong
 
HIPAA Training Basics
HIPAA Training BasicsHIPAA Training Basics
HIPAA Training Basics
 
Assessing Your Hosting Environment for HIPAA Compliance
Assessing Your Hosting Environment for HIPAA ComplianceAssessing Your Hosting Environment for HIPAA Compliance
Assessing Your Hosting Environment for HIPAA Compliance
 
HIPAA | HIPAA Training
HIPAA | HIPAA TrainingHIPAA | HIPAA Training
HIPAA | HIPAA Training
 
HIPAA | HIPAA Training
HIPAA | HIPAA TrainingHIPAA | HIPAA Training
HIPAA | HIPAA Training
 
Mha690 hipaa minimum necessary week 1
Mha690 hipaa minimum necessary week 1Mha690 hipaa minimum necessary week 1
Mha690 hipaa minimum necessary week 1
 

Viewers also liked

Viewers also liked (8)

2012SVR Win_7 NETWORK
2012SVR Win_7 NETWORK2012SVR Win_7 NETWORK
2012SVR Win_7 NETWORK
 
kjGOOGLE_CLOUD_PT2
kjGOOGLE_CLOUD_PT2kjGOOGLE_CLOUD_PT2
kjGOOGLE_CLOUD_PT2
 
HIPAA-2-_FINAL
HIPAA-2-_FINALHIPAA-2-_FINAL
HIPAA-2-_FINAL
 
HIPAApt2-PGM
HIPAApt2-PGMHIPAApt2-PGM
HIPAApt2-PGM
 
GOOGLE_CLOUD_PT3
GOOGLE_CLOUD_PT3GOOGLE_CLOUD_PT3
GOOGLE_CLOUD_PT3
 
kjGOOGLE_CLOUD_pt1
kjGOOGLE_CLOUD_pt1kjGOOGLE_CLOUD_pt1
kjGOOGLE_CLOUD_pt1
 
DV Brochure
DV BrochureDV Brochure
DV Brochure
 
Win_8_Final Version
Win_8_Final VersionWin_8_Final Version
Win_8_Final Version
 

Similar to HIPAA Compliance Guide for Philadelphia Center

Explaining the HIPAA Privacy[.docx
Explaining the HIPAA Privacy[.docxExplaining the HIPAA Privacy[.docx
Explaining the HIPAA Privacy[.docxVistaInfosec
 
A brief introduction to hipaa compliance
A brief introduction to hipaa complianceA brief introduction to hipaa compliance
A brief introduction to hipaa compliancePrince George
 
Describe one safeguard that should be in place to protect the confid.pdf
Describe one safeguard that should be in place to protect the confid.pdfDescribe one safeguard that should be in place to protect the confid.pdf
Describe one safeguard that should be in place to protect the confid.pdfmohammedfootwear
 
HIPAA Panel Discussion
HIPAA Panel Discussion HIPAA Panel Discussion
HIPAA Panel Discussion Dan Wellisch
 
The Startup Path to HIPAA Compliance
The Startup Path to HIPAA ComplianceThe Startup Path to HIPAA Compliance
The Startup Path to HIPAA ComplianceJim Anfield
 
Knowing confidentiality
Knowing confidentialityKnowing confidentiality
Knowing confidentialityjessie66
 
health insurance portability and accountability act.pptx
health insurance portability and accountability act.pptxhealth insurance portability and accountability act.pptx
health insurance portability and accountability act.pptxamartya2087
 
HIPPA Security Presentation
HIPPA Security PresentationHIPPA Security Presentation
HIPPA Security PresentationRebecca Norman
 
MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...
MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...
MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...Michigan Primary Care Association
 
Marc etienne week1 discussion2 presentation
Marc etienne week1 discussion2 presentationMarc etienne week1 discussion2 presentation
Marc etienne week1 discussion2 presentationMarcEtienne6
 
Week 1 discussion 2 hipaa and privacy training
Week 1 discussion 2 hipaa and privacy trainingWeek 1 discussion 2 hipaa and privacy training
Week 1 discussion 2 hipaa and privacy trainingvrgill22
 
Privacy-Security-Training-Session-Template-4.6.21.pptx
Privacy-Security-Training-Session-Template-4.6.21.pptxPrivacy-Security-Training-Session-Template-4.6.21.pptx
Privacy-Security-Training-Session-Template-4.6.21.pptxMohammadBashir26
 
Does your Mobile App require HIPAA Compliance.pdf
Does your Mobile App require HIPAA Compliance.pdfDoes your Mobile App require HIPAA Compliance.pdf
Does your Mobile App require HIPAA Compliance.pdfShelly Megan
 
Introduction hippaa
Introduction hippaaIntroduction hippaa
Introduction hippaaTina Peña
 
Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017Kimberly Simon MBA
 
Hi paa and eh rs
Hi paa and eh rsHi paa and eh rs
Hi paa and eh rssupportc2go
 

Similar to HIPAA Compliance Guide for Philadelphia Center (20)

Explaining the HIPAA Privacy[.docx
Explaining the HIPAA Privacy[.docxExplaining the HIPAA Privacy[.docx
Explaining the HIPAA Privacy[.docx
 
Hipaa for business associates simple
Hipaa for business associates   simpleHipaa for business associates   simple
Hipaa for business associates simple
 
A brief introduction to hipaa compliance
A brief introduction to hipaa complianceA brief introduction to hipaa compliance
A brief introduction to hipaa compliance
 
Describe one safeguard that should be in place to protect the confid.pdf
Describe one safeguard that should be in place to protect the confid.pdfDescribe one safeguard that should be in place to protect the confid.pdf
Describe one safeguard that should be in place to protect the confid.pdf
 
HIPAA and How it Applies to You
HIPAA and How it Applies to YouHIPAA and How it Applies to You
HIPAA and How it Applies to You
 
HIPAA Panel Discussion
HIPAA Panel Discussion HIPAA Panel Discussion
HIPAA Panel Discussion
 
The Startup Path to HIPAA Compliance
The Startup Path to HIPAA ComplianceThe Startup Path to HIPAA Compliance
The Startup Path to HIPAA Compliance
 
Knowing confidentiality
Knowing confidentialityKnowing confidentiality
Knowing confidentiality
 
health insurance portability and accountability act.pptx
health insurance portability and accountability act.pptxhealth insurance portability and accountability act.pptx
health insurance portability and accountability act.pptx
 
HIPPA Security Presentation
HIPPA Security PresentationHIPPA Security Presentation
HIPPA Security Presentation
 
MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...
MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...
MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...
 
Marc etienne week1 discussion2 presentation
Marc etienne week1 discussion2 presentationMarc etienne week1 discussion2 presentation
Marc etienne week1 discussion2 presentation
 
Week 1 discussion 2 hipaa and privacy training
Week 1 discussion 2 hipaa and privacy trainingWeek 1 discussion 2 hipaa and privacy training
Week 1 discussion 2 hipaa and privacy training
 
Privacy-Security-Training-Session-Template-4.6.21.pptx
Privacy-Security-Training-Session-Template-4.6.21.pptxPrivacy-Security-Training-Session-Template-4.6.21.pptx
Privacy-Security-Training-Session-Template-4.6.21.pptx
 
Does your Mobile App require HIPAA Compliance.pdf
Does your Mobile App require HIPAA Compliance.pdfDoes your Mobile App require HIPAA Compliance.pdf
Does your Mobile App require HIPAA Compliance.pdf
 
Hipaa Compliance
Hipaa Compliance Hipaa Compliance
Hipaa Compliance
 
HIPAA for Dummies
HIPAA for DummiesHIPAA for Dummies
HIPAA for Dummies
 
Introduction hippaa
Introduction hippaaIntroduction hippaa
Introduction hippaa
 
Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017
 
Hi paa and eh rs
Hi paa and eh rsHi paa and eh rs
Hi paa and eh rs
 

HIPAA Compliance Guide for Philadelphia Center

  • 1. Philadelphia Center N.W. Louisiana AIDS Resource Center http://www.hhs.gov/ocr/privacy/
  • 2. Electronic Health Information Exchange in a Networked Environment Introduction to HIPAA Health Information Portability and Accountability Act of (1996)
  • 3. HIPAA Basics  HIPAA compliance and confidentiality must be maintained for the sake of the client, the employee, and the organization.  Compliance is mandatory for any organization dealing with medical records.  HIPAA stands for Health Insurance Portability & Accountability Act of 1996.  PHI stands for Protected Health Information.  TPO stands for Treatment , Payment, and Operations.  OCR stands for Office of Civil Rights—Hotline #: (1- 800-537-7697)  HIO stands for Health Information Organization.  PRP stands for Privacy Rule Policies
  • 4. HIPAA Basics  All client information and money spent at the Philadelphia Center needs to be protected and HIPAA has guidelines to help us do this.  HIPAA also has audits that makes sure the Philadelphia Center is within guideline limits and the Audit is tough.  We, the IT’s, are aware of HIPAA and the necessary things needed to make sure the Philadelphia Center is in compliance. There should be openness and transparency about policies, procedures, and technologies that directly affect individuals and/or their individually identifiable health information (PHI).
  • 5. HIPAA Philadelphia Center Accountability  A HIPAA audit will look something like this:  We need to make sure that we have all bases covered in case they decide to make us their next audit.
  • 6. The Privacy Rule  The Standards for Privacy of Individually Identifiable Health Information (“Privacy Rule”) establishes, for the first time, a set of national standards for the protection of certain health information.  The U.S. Department of Health and Human Services (“HHS”) issued the Privacy Rule to implement the requirement of the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”).
  • 7. The Privacy Rule  The Privacy Rule standards address the use and disclosure of individuals’ health information—called “Protected Health Information” by organizations subject to the Privacy Rule — called “covered entities,” as well as standards for individuals' privacy rights to understand and control how their health information is used.  Within HHS, the Office for Civil Rights (“OCR”) has responsibility for implementing and enforcing the Privacy Rule with respect to voluntary compliance activities and civil money penalties.
  • 8. Electronic Health Information Exchange in a Networked Environment Accountability Health Insurance Portability and Accountability Act of 1996 (“HIPAA”)
  • 9. ACCOUNTABILITY  The Privacy Rule provides the foundation for accountability within an electronic health information exchange environment  Requires covered entities (Philadelphia Center) that exchange Protected Health Information (PHI) to comply with its administrative requirements  Requires Philadelphia Center employees to adhere to the HIPAA privacy rules
  • 10. ACCOUNTABILITY Administrative Requirements  The Philadelphia Center must have written policies and procedures in place to implement privacy standards See 45 C.F.R. § 164.530(b)  Employees should be trained on those policies and procedures  The Philadelphia Center director must reprimand employees who violate established Privacy Rule Policies [See 45 C.F.R. § 164.530(e)] Privacy Rule Requirements  A Philadelphia Center, Client complaint form has to be created See 45 C.F.R. § 164.530(d)  A Notice of Privacy Practices has to be sent to every Philadelphia Center client  Contact information and instructions on how to file complaints should be included with the Notice of Privacy See 45 C.F.R. § 164.530(b)(1)(vi)-(vii)
  • 11. Electronic Health Information Exchange in a Networked Environment Collection, Use, and Disclosure Limitation Health Insurance Portability and Accountability Act of 1996 (“HIPAA”)
  • 12. Permitted Uses & Disclosures  To the Individual  Used for Philadelphia’s Treatment, Payments, Health Care Operations  Uses and Disclosures with Opportunity to Agree or Object  Incidental Use and Disclosure  Public Interest and Benefit Activities  Limited Data Set  Basic Principle  Required Disclosures
  • 13. Philadelphia Center N.W. Louisiana AIDS Resource Center http://www.hhs.gov/ocr/privacy/