SlideShare a Scribd company logo
1 of 1
Download to read offline
“ T h e e a s i e s t w a y t o L e a r n ! ” Drag & Drop Seminars 
Training Day “HIPAA Privacy Rules - Pt. 1” 
June 26, 2013_Wednesday 
A. HIPAA Client Complaint Form 
C. Confidentiality Statement / Training 
B. Notice of Privacy Practices for (PHI) 
Areas to Address 
Total Hrs.: 1 
Presenter: Kevin W. Jenkins 
Location: The Philadelphia Center 
I looked at a copy of the current form used by 
clients who disagree with actions or decisions 
made by the Philadelphia Center, its employees, 
or volunteers. It is called “Client Grievance 
Procedure for Philadelphia Center” and details the 
procedure for filing a grievance. 
However, it fails to meet HIPAA standards. All 
it needs is a little rewording and the addition of 
an actual complaint form, instead of requiring 
clients to create one. 
Every client that the Philadelphia Center serves 
has to be given (either by mail or when they 
visit their Case Manager) a copy of a Notice 
of Privacy Practices for Protected Health 
Information. 
Content of the Notice 
Covered entities (Philadelphia Center) are 
required to provide a notice in plain language 
that describes: 
• How the covered entity may use and disclose 
protected health information about an 
individual. 
• The individual’s rights with respect to the 
information and how the individual may 
exercise these rights, including how the 
individual may complain to the covered 
entity. 
• The covered entity’s legal duties with respect 
to the information, including a statement 
that the covered entity is required by law 
to maintain the privacy of protected health 
information. 
• Whom individuals can contact for further 
information about the covered entity’s 
privacy policies. 
The notice must include an effective date. See 45 
CFR 164.520(b) for the specific requirements 
for developing the content of the notice. A 
covered entity is required to promptly revise and 
distribute its notice whenever it makes material 
changes to any of its privacy practices. See 45 
CFR 164.520(b)(3), 164.520(c)(1)(i)(C) for 
health plans, and 164.520(c)(2)(iv) for covered 
health care providers with direct treatment 
relationships with individuals. 
Providing the Notice 
• A covered entity (Philadelphia Center) must 
make its notice available to any person who 
asks for it. 
• A covered entity must prominently post and 
make available its notice on any web site it 
maintains that provides information about its 
customer services or benefits. 
• The Employee Handbook does not contain 
contract language that makes references to 
HIPAA rules and regulations nor breach 
notification procedures. 
• Furthermore, if employees are not trained in 
Breach Notification Procedures, HIPAA Laws 
and Safeguard Practices, then they can not 
be held responsible or liable for any HIPAA 
privacy violations that may occur.

More Related Content

Viewers also liked (9)

Herramientas tic
Herramientas ticHerramientas tic
Herramientas tic
 
Especialmente para ti
Especialmente para tiEspecialmente para ti
Especialmente para ti
 
Towel options
Towel optionsTowel options
Towel options
 
Medios de comunicacion
Medios de comunicacionMedios de comunicacion
Medios de comunicacion
 
Giza gorputza
Giza gorputzaGiza gorputza
Giza gorputza
 
Qué entendemos por convivencia escolar
Qué entendemos por convivencia escolarQué entendemos por convivencia escolar
Qué entendemos por convivencia escolar
 
Inkapower präsentation
Inkapower präsentationInkapower präsentation
Inkapower präsentation
 
Top 8 staffing supervisor resume samples
Top 8 staffing supervisor resume samplesTop 8 staffing supervisor resume samples
Top 8 staffing supervisor resume samples
 
Redes sociales en los jovenes
Redes sociales en los jovenesRedes sociales en los jovenes
Redes sociales en los jovenes
 

Similar to Minutes_HIPAApt1-Training

Perception of CBAHI accreditation among health workers case study.docx
Perception of CBAHI accreditation among health workers case study.docxPerception of CBAHI accreditation among health workers case study.docx
Perception of CBAHI accreditation among health workers case study.docx
ssuser562afc1
 
Patient Privacy Provisions of the HITECH Act Implications for Patients and Sm...
Patient Privacy Provisions of the HITECH Act Implications for Patients and Sm...Patient Privacy Provisions of the HITECH Act Implications for Patients and Sm...
Patient Privacy Provisions of the HITECH Act Implications for Patients and Sm...
Xiaoming Zeng
 
Processing HIPAA Privacy Forms 2014-Sample
Processing HIPAA Privacy Forms 2014-SampleProcessing HIPAA Privacy Forms 2014-Sample
Processing HIPAA Privacy Forms 2014-Sample
Katrina Wiley Belton
 
MHA690 confidentiality training
MHA690 confidentiality trainingMHA690 confidentiality training
MHA690 confidentiality training
sdavis49
 
Introduction to HIPAA for Healthcare Professionals by OUP
Introduction to HIPAA for Healthcare Professionals by OUPIntroduction to HIPAA for Healthcare Professionals by OUP
Introduction to HIPAA for Healthcare Professionals by OUP
Atlantic Training, LLC.
 

Similar to Minutes_HIPAApt1-Training (20)

Contracts and Memorandums of Understanding - Requirements and Responsibilities
Contracts and Memorandums of Understanding - Requirements and ResponsibilitiesContracts and Memorandums of Understanding - Requirements and Responsibilities
Contracts and Memorandums of Understanding - Requirements and Responsibilities
 
2023 Compliatric Webinar Series - Contracts and Memorandums of Understanding ...
2023 Compliatric Webinar Series - Contracts and Memorandums of Understanding ...2023 Compliatric Webinar Series - Contracts and Memorandums of Understanding ...
2023 Compliatric Webinar Series - Contracts and Memorandums of Understanding ...
 
Hipaa Goes Hitech
Hipaa Goes HitechHipaa Goes Hitech
Hipaa Goes Hitech
 
Perception of CBAHI accreditation among health workers case study.docx
Perception of CBAHI accreditation among health workers case study.docxPerception of CBAHI accreditation among health workers case study.docx
Perception of CBAHI accreditation among health workers case study.docx
 
Translating compliance requirements into action items 340B
Translating compliance requirements into action items 340BTranslating compliance requirements into action items 340B
Translating compliance requirements into action items 340B
 
Patient Privacy Provisions of the HITECH Act Implications for Patients and Sm...
Patient Privacy Provisions of the HITECH Act Implications for Patients and Sm...Patient Privacy Provisions of the HITECH Act Implications for Patients and Sm...
Patient Privacy Provisions of the HITECH Act Implications for Patients and Sm...
 
The Startup Path to HIPAA Compliance
The Startup Path to HIPAA ComplianceThe Startup Path to HIPAA Compliance
The Startup Path to HIPAA Compliance
 
HIPAA Panel Discussion
HIPAA Panel Discussion HIPAA Panel Discussion
HIPAA Panel Discussion
 
Confidentiality powerpoint
Confidentiality powerpointConfidentiality powerpoint
Confidentiality powerpoint
 
Data Security and Privacy Practices
Data Security and Privacy PracticesData Security and Privacy Practices
Data Security and Privacy Practices
 
Processing HIPAA Privacy Forms 2014-Sample
Processing HIPAA Privacy Forms 2014-SampleProcessing HIPAA Privacy Forms 2014-Sample
Processing HIPAA Privacy Forms 2014-Sample
 
Hipaa for business associates simple
Hipaa for business associates   simpleHipaa for business associates   simple
Hipaa for business associates simple
 
What You Don’t Know About the HIPAA Security Rule
What You Don’t Know About the HIPAA Security RuleWhat You Don’t Know About the HIPAA Security Rule
What You Don’t Know About the HIPAA Security Rule
 
Hipaa
HipaaHipaa
Hipaa
 
HIPAA Part I the Law Test
HIPAA Part I  the Law TestHIPAA Part I  the Law Test
HIPAA Part I the Law Test
 
MHA690 confidentiality training
MHA690 confidentiality trainingMHA690 confidentiality training
MHA690 confidentiality training
 
UNA HIPAA Training 8-13
UNA HIPAA Training   8-13UNA HIPAA Training   8-13
UNA HIPAA Training 8-13
 
Compliatric Required and Additional Health Services
Compliatric Required and Additional Health ServicesCompliatric Required and Additional Health Services
Compliatric Required and Additional Health Services
 
Introduction to HIPAA for Healthcare Professionals by OUP
Introduction to HIPAA for Healthcare Professionals by OUPIntroduction to HIPAA for Healthcare Professionals by OUP
Introduction to HIPAA for Healthcare Professionals by OUP
 
Top form 5 a gotchas and how to avoid them
Top form 5 a gotchas and how to avoid themTop form 5 a gotchas and how to avoid them
Top form 5 a gotchas and how to avoid them
 

More from Kevin Jenkins

More from Kevin Jenkins (11)

Win_8_Final Version
Win_8_Final VersionWin_8_Final Version
Win_8_Final Version
 
HIPAA-2-_FINAL
HIPAA-2-_FINALHIPAA-2-_FINAL
HIPAA-2-_FINAL
 
HIPAA-1-_FINAL_Draft
HIPAA-1-_FINAL_DraftHIPAA-1-_FINAL_Draft
HIPAA-1-_FINAL_Draft
 
HIPAApt2-PGM
HIPAApt2-PGMHIPAApt2-PGM
HIPAApt2-PGM
 
GOOGLE_CLOUD_PT3
GOOGLE_CLOUD_PT3GOOGLE_CLOUD_PT3
GOOGLE_CLOUD_PT3
 
kjGOOGLE_CLOUD_PT2
kjGOOGLE_CLOUD_PT2kjGOOGLE_CLOUD_PT2
kjGOOGLE_CLOUD_PT2
 
kjGOOGLE_CLOUD_pt1
kjGOOGLE_CLOUD_pt1kjGOOGLE_CLOUD_pt1
kjGOOGLE_CLOUD_pt1
 
COMODO UNITE
COMODO UNITECOMODO UNITE
COMODO UNITE
 
2012SVR Win_7 NETWORK
2012SVR Win_7 NETWORK2012SVR Win_7 NETWORK
2012SVR Win_7 NETWORK
 
March 2008 Newsletter-web
March 2008 Newsletter-webMarch 2008 Newsletter-web
March 2008 Newsletter-web
 
DV Brochure
DV BrochureDV Brochure
DV Brochure
 

Minutes_HIPAApt1-Training

  • 1. “ T h e e a s i e s t w a y t o L e a r n ! ” Drag & Drop Seminars Training Day “HIPAA Privacy Rules - Pt. 1” June 26, 2013_Wednesday A. HIPAA Client Complaint Form C. Confidentiality Statement / Training B. Notice of Privacy Practices for (PHI) Areas to Address Total Hrs.: 1 Presenter: Kevin W. Jenkins Location: The Philadelphia Center I looked at a copy of the current form used by clients who disagree with actions or decisions made by the Philadelphia Center, its employees, or volunteers. It is called “Client Grievance Procedure for Philadelphia Center” and details the procedure for filing a grievance. However, it fails to meet HIPAA standards. All it needs is a little rewording and the addition of an actual complaint form, instead of requiring clients to create one. Every client that the Philadelphia Center serves has to be given (either by mail or when they visit their Case Manager) a copy of a Notice of Privacy Practices for Protected Health Information. Content of the Notice Covered entities (Philadelphia Center) are required to provide a notice in plain language that describes: • How the covered entity may use and disclose protected health information about an individual. • The individual’s rights with respect to the information and how the individual may exercise these rights, including how the individual may complain to the covered entity. • The covered entity’s legal duties with respect to the information, including a statement that the covered entity is required by law to maintain the privacy of protected health information. • Whom individuals can contact for further information about the covered entity’s privacy policies. The notice must include an effective date. See 45 CFR 164.520(b) for the specific requirements for developing the content of the notice. A covered entity is required to promptly revise and distribute its notice whenever it makes material changes to any of its privacy practices. See 45 CFR 164.520(b)(3), 164.520(c)(1)(i)(C) for health plans, and 164.520(c)(2)(iv) for covered health care providers with direct treatment relationships with individuals. Providing the Notice • A covered entity (Philadelphia Center) must make its notice available to any person who asks for it. • A covered entity must prominently post and make available its notice on any web site it maintains that provides information about its customer services or benefits. • The Employee Handbook does not contain contract language that makes references to HIPAA rules and regulations nor breach notification procedures. • Furthermore, if employees are not trained in Breach Notification Procedures, HIPAA Laws and Safeguard Practices, then they can not be held responsible or liable for any HIPAA privacy violations that may occur.