SlideShare a Scribd company logo
1 of 66
Welco
ESSENTIAL STRATEGIES
HIPAA 2.0
Allan Ridings Jeff Mongelli
CEO, Acentec, Inc.
•15 years of health care IT
experience
•Nationally published on health
care IT security
Senior Risk Management& Patient
Safety Specialist – Cooperative of
American Physicians, Inc.
• 30 years of practice management
experience
• Nationally published on HIPAA and
eHealth
ESSENTIAL STRATEGIES
OBJECTIVES:
• Identify components of HIPAA
compliancy
• Describe recent changes in HIPAA
• Sharing protected health information
• Restricting protected health information
ESSENTIAL STRATEGIES
HEALTH INFORMATION PRIVACY
Overview:
Health Insurance Portability &
Accountability Act of 1996 (HIPAA)
What is HIPAA?
HIPAA regulations require all health care providers,
organizations, and business associates to develop / follow
procedures that ensure the security and confidentiality of
protected health information (PHI, ePHI) when being handled,
received, transferred, or shared (oral, paper, or electronic).
HIPAA is enforced by the Office of Civil Rights
(OCR).
HIPAA Benefits
• Supporting obligations
• Supporting compliance
• Secured records
• Knowledgeable staff
• Reduced risk
HIPAA Compliancy
• Notice of Privacy Practices (NPP)
• Patient Acknowledgements
• Protected Health Information (PHI, ePHI)
• Office Risk Assessment (RA)
• Business Associate Agreements (BAA)
HIPAA Compliancy
• E-mailing of ePHI
• Copying / Releasing PHI
• Childhood / Student Immunizations
HIPAA Compliancy
• Disclosure Duties
• Unapproved Access to PHI, ePHI (breach)
• Sale of PHI
ESSENTIAL STRATEGIES:
HIPAA COMPLIANCY
Notice of Privacy Practices
(NPP)
Requires that all covered health care providers
develop and distribute a notice.
The notice must provide a clear, user-friendly
explanation of individuals’ [patients’] rights
regarding PHI, ePHI, and the privacy practices of
the entity, health provider, or health plan.
Notice of Privacy
Practices
NPP - Patient
Acknowledgements
Notice of Privacy Practices (HIPAA, PHI, ePHI, BAA):
• Accessible via poster or binder for patient and
others
• Provide a fact sheet
• Signed receipt / acknowledgment form
(physically or electronically)
Notice of Privacy
Practices
Must be posted or available.
NPP - Patient
Acknowledgements
Patient acknowledgement!
ESSENTIAL STRATEGIES:
HIPAA COMPLIANCY
Releasing Protected Health
Information (PHI, ePHI)
COOPERATIVE OF
AMERICAN PHYSICIANS
Affected individuals must be notified:
• When types of uses and disclosures require authorization
• That disclosures will be made only with authorization
• If any information is used for marketing or sold
An individual may revoke authorization.
PHI - Release
Authorization
Why this matters:
• The Office for Civil Rights has stated the next big HIPAA
update will be regarding ACCOUNTING FOR DISCLOSURES
(it’s past due).
PHI - Release
Authorization
PHI - Release
Authorization
Written authorizations:
• Are required for inspection and/or release
of billing notes or any part of a medical record.
• A separate authorization is required for each
release.
(with exceptions)
PHI - Release
Authorization
Time:
• Inspection of records honored within 5 working
days
• Copies must be released within 15 calendar days
• Have uniformed policy, educated staff
PHI - Release
Authorization
Applicable Charges:
• Reasonable clerical fees, plus 25¢ per page
• $15 maximum clerical fee for subpoena copy
services
• Records to support an appeal for a public benefit
program provided at no charge and within 30 days
• When released on CD or USB thumb-drive, you
may charge for the labor and media
PHI - Release
Authorization
Applicable Exceptions:
Health care providers and other entities that
participate in an Organized Health Care
Arrangement (OHCA)
All entities, sites, and locations may share medical
information with each other for treatment,
payment, and health care operations purposes. [45
CFR 164.520(d)]
PHI - Release
Authorization
HIPAA Privacy during emergencies (11/2014):
• Treatment during emergencies
[45 CFR 164.502(a)(1)(ii), 164.506(c), 164.510(b)]
• Public Health Activities - CDC & Public Heath
Authorities
• Imminent threat to public health
[45 CFR 164.512(b)(1)(i)]
PHI - Release
Authorization
Physician Notification & Review:
• Review all requests that arrive to your
offices
Documentation:
• Who, Where, When (disclosure log)
PHI - Personal Request
Authorization
Future Date
Personal
PHI - Release To / From
Authorization
Specific Date
Continuity
Childhood Immunization
Records
A Covered Entity may release student or childhood
immunization records to a school/college without
authorization:
• If state law requires a school to have an
immunization record on file
• Written or oral agreement (must be documented)
PHI - Disclosure Log
DISCLOSURE
LOG
ESSENTIAL STRATEGIES:
HIPAA COMPLIANCY
E-mailing & Texting Patients
E-mail & Texting ePHI
What is needed…
when we e-mail
or text patients?
Code of
Federal Regulations
Code of
Federal Regulations
CFR requires encryption
when e-mailing or texting
electronic protected health
information (ePHI).
ENCRYPTION
Code of
Federal Regulations
A covered entity must:
• Implement a mechanism to encrypt and decrypt
electronically protected health information
(45 CFR § 164.312)
• Be in accordance with privacy rule
(45 CFR§164.306)
Code of
Federal Regulations
Access rights require a covered entity to:
• Use Advanced Encryption Standard (AES)
encryption, either 128-bit or 256-bit
• Implement technical policies and procedures for
systems that maintain electronic protected health
information 164.308(a)(4) [Information Access
Management]
ESSENTIAL STRATEGIES:
HIPAA COMPLIANCY
Treatment, Payment
& Operations
(TPO)
Treatment, Payment,
Operations
Treatment:
• Medical care, all in-office, e-health, m-health, t-
health
Payment:
• Referrals
• Medical billing office, claims, internal /external
services
Operations:
• Medical office policies /procedures
• Office rules and regulations /business policies
ESSENTIAL STRATEGIES:
HIPAA COMPLIANCY
Business Associate
Agreement
(BAA)
COOPERATIVE OF
AMERICAN PHYSICIANS
Business Associate
Agreements
Required with entities that:
• Create
• Receive e-health / diagnostic services
• Store / maintain any type of PHI, ePHI
• Transmit ePHI on behalf of a covered entity
Subcontractor:
• Subcontractor = person to whom a business
associate delegates a function, activity, or service
• Subcontractor + PHI = Business Associate
Agency vs. Independent Contractor
Business Associate
Agreements
Business Associate
Agreements
Is this person a Business Associate?
Business Associate
Agreements
ESSENTIAL STRATEGIES:
HIPAA COMPLIANCY
Breach Notifications
Breach Disclosure Duties
Breach (45 C.F.R. § 164.406 - 164.410) :
Unauthorized acquisition, access, use, disclosure
of unsecured PHI, ePHI in a manner not permitted
by the HIPAA Privacy Rule that compromises the
security or privacy of PHI, ePHI.
Covered entities and business associates are
required to report any breach of unsecured PHI,
ePHI.
Do we HAVE to notify patients?:
“… breach notification is necessary in all situations
except those in which the CE demonstrates that
there is a low probability that the protected health
information has been compromised based on a risk
assessment ...”
Section 160.402
Breach Disclosure Duties
Less than 500 patients:
Covered entities and business associates are
required to notify OCR of breach no later than 60
days of calendar year end.
• Notify your Medical Professional Liability Carrier.
• Follow breach instructions:
www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/brinstru
ction.html
Breach Disclosure Duties
Greater than 500 patients:
Required to notify OCR within 60 days of breach.
• Must notify the media
• Offer affected patients 1 year credit monitoring
service
• Notify your Medical Professional Liability Carrier
• Follow breach instructions:
www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/brinstru
ction.html
Breach Disclosure Duties
Incident Risk Assessment (IRA):
An Incident Risk Assessment should include:
• the nature and extent of the PHI involved;
• the unauthorized person who used the PHI or to
whom the PHI was disclosed;
• whether the PHI was actually acquired or viewed;
and
• the extent to which the risk to the PHI has been
mitigated.
The IRA is only required if the CE, based on the facts, wants to demonstrate
that no notification is required.
Breach Disclosure Duties
ESSENTIAL STRATEGIES:
HIPAA COMPLIANCY
Office Risk Assessment
(RA)
COOPERATIVE OF
AMERICAN PHYSICIANS
Office Risk Assessment
• A risk assessment helps
your organization ensure it
is compliant with HIPAA’s
administrative, physical,
and technical safeguards.
• Risk assessments may
reveal areas where your
organization’s protected
health information (PHI, ePHI)
may be at risk.
Risk Assessment
Risk Assessment
ESSENTIAL STRATEGIES:
HIPAA COMPLIANCY
Let’s review what’s required of
you…
Medical Office
Requirements #1
Secure registration process:
• Face-to-face
• Patient portal (EHR)
Notice of Privacy Practices - HIPAA / PHI, ePHI:
• Poster, notice, or binder
• Signature acceptance
Business Associate Agreements (BAA)
• Transmit ePHI on behalf of a covered entity
Medical Office
Requirements #2
HIPAA education training for all staff:
• Sign-in sheet
• Signature understanding / acceptance
Risk Assessment:
• Regularly scheduled assessments
8 Most Common Causes
of Violations
• Users that have legitimate access to sensitive
information are the weakest link in information
security
• Sharing passwords
• Exposing passwords (taped to monitor)
• Giving out passwords
• Sending PHI to incorrect destinations
• Sharing PHI on social media
• Discussing PHI with others or in front of others
#1 Authorized Users
8 Most Common Causes
of Violations
• BCBS Tennessee ($1.5 M)
• Failure to re-evaluate threats/vulnerabilities to ePHI caused
by changing operational environment and manage risk
• Alaska DHSS ($1.7M)
• Failure to conduct a risk analysis to identify location and
safeguards for PHI, training, and controls for portal devices
• Mass. St. Elizabeth’s Medical Center (SEMC) ($218,000 )
• Has agreed to settle potential violations of HIPAA … for
use of an Internet-based document sharing product and
failure to timely notify OCR
#2 Failure to Conduct or Update Risk Assessment
8 Most Common Causes
of Violations
• E-mail encryption
• Backup encryption
• Massachusetts Eye and Ear Institute ($1.5M)
• Stolen personal laptop of physician using device as desktop
substitute
• Covered entity had not implemented a program to mitigate
identified risks to ePHI
• Encrypt data stored on end-user devices
#3 Failure to Consider or Properly Implement New
Technology
8 Most Common Causes
of Violations
• Phoenix Cardiac Surgery ($100K)
• Backup encryption
• ePHI disclosed through Internet when provider used third
party application hosted in the cloud
Business associate agreements are required when sharing data
with cloud computing service providers!
#4 Failure to Identify Business Associates
8 Most Common Causes
of Violations
• Culture of Convenience remains the prevailing
practice in medicine
• CSMC – settled violations related to disclosure of PHI
of celebrity patients for $865,500
• Sharing of passwords, etc.
• No enforcement of policies, i.e., “everyone is doing it”
#5 Failure to Create Culture of Compliance Among
Workforce
8 Most Common Causes
of Violations
• Cignet Health fined $4.3 million for refusing to
provide access to medical records upon patient’s
request. ($3 million attributed to “willful neglect” for
refusing to comply with investigative requests.)
• Right to amend information.
• OCR examples
• Failure to allow access to whole record (because
part of it was created by another provider).
#6 Failure to Remember Patient Rights
8 Most Common Causes
of Violations
• Attempt to condition privacy rule compliance on
patient’s agreement to not disclose information about
physician (we won’t tell if you don’t tell) (Yelp)
• Failure to accommodate a reasonable request for
confidential communications (patient requested to be
contacted only on mobile phone, not at home – but
the treatment reminder was left on home voicemail)
#6 Failure to Remember Patient Rights (cont.)
8 Most Common Causes
of Violations
• Discussion of PHI in front of other patients, in waiting
rooms
• Paper PHI not safeguarded from theft
• Information faxed to patient’s employer did not
include confidentiality statement on cover sheet
• Massachusetts General Hospital – Paid
$1,000,000 to settle violations related to loss
of PHI of 192 patients on subway train from
infectious disease outpatient practice (including
HIV/AIDS patients)
#7 Forgetting About “Reasonable Safeguards”
8 Most Common Causes
of Violations
• Failure to distribute information on a “need to know”
basis
• Example: OR schedule sent to people who had no
need for the information – complainant was an
employee/patient
• Computer access and paper access
#8 Forgetting the Minimum Necessary Rule
ESSENTIAL STRATEGIES:
HIPAA COMPLIANCY
Questions…
ESSENTIAL STRATEGIES:
HIPAA COMPLIANCY
The information in this
presentation should not be considered
legal advice applicable to a specific
situation.
Legal guidance for individual matters
should be obtained from a retained
attorney.
ESSENTIAL STRATEGIES:
HIPAA COMPLIANCY
Allan Ridings
Cooperative of American Physicians, Inc.
Phone: 800-252-7706
Email: riskmanagement@CAPphysicians.com
Web: www.CAPphysicians.com
Jeff Mongelli, CEO
Acentec, Inc.
Phone: 949-474-7774
Email: jeffm@acentec.com
Web: www.acentec.com
Thank You!

More Related Content

What's hot

Keys To HIPAA Compliance
Keys To HIPAA ComplianceKeys To HIPAA Compliance
Keys To HIPAA ComplianceCBIZ, Inc.
 
HIPAA 101- What all Doctors NEED to know
HIPAA 101- What all Doctors NEED to knowHIPAA 101- What all Doctors NEED to know
HIPAA 101- What all Doctors NEED to knowCompliancy Group
 
Health Insurance Portability and Accountability Act (HIPAA) Compliance
Health Insurance Portability and Accountability Act (HIPAA) ComplianceHealth Insurance Portability and Accountability Act (HIPAA) Compliance
Health Insurance Portability and Accountability Act (HIPAA) ComplianceControlCase
 
Hipaa journal com - HIPAA compliance guide
Hipaa journal com - HIPAA compliance guideHipaa journal com - HIPAA compliance guide
Hipaa journal com - HIPAA compliance guideFelipe Prado
 
Welcome to HIPAA Training
Welcome to HIPAA TrainingWelcome to HIPAA Training
Welcome to HIPAA TrainingJonathan Montes
 
Hipaa101 updated
Hipaa101 updatedHipaa101 updated
Hipaa101 updatedkkurapat
 
HIPPA-Health Insurance Portability and Accountability Act
HIPPA-Health Insurance Portability and Accountability ActHIPPA-Health Insurance Portability and Accountability Act
HIPPA-Health Insurance Portability and Accountability ActHarshit Trivedi
 
2017 HIPAA Clinical Research Training
2017 HIPAA Clinical Research Training2017 HIPAA Clinical Research Training
2017 HIPAA Clinical Research TrainingCynthia Holland
 
The Health Insurance Portability and Accountability Act 
The Health Insurance Portability and Accountability Act The Health Insurance Portability and Accountability Act 
The Health Insurance Portability and Accountability Act Kartheek Kein
 
HIPAA - Understanding the Basics of Compliance
HIPAA - Understanding the Basics of ComplianceHIPAA - Understanding the Basics of Compliance
HIPAA - Understanding the Basics of ComplianceJay Hodes
 
The Startup Path to HIPAA Compliance
The Startup Path to HIPAA ComplianceThe Startup Path to HIPAA Compliance
The Startup Path to HIPAA ComplianceJim Anfield
 
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)Sanjeev Bharwan
 
HIPAA Compliance For Small Practices
HIPAA Compliance For Small PracticesHIPAA Compliance For Small Practices
HIPAA Compliance For Small PracticesNisos Health
 
HIPAA Summary for Training
HIPAA Summary for Training HIPAA Summary for Training
HIPAA Summary for Training MDManagement
 

What's hot (20)

Hipaa
HipaaHipaa
Hipaa
 
HIPAA Audio Presentation
HIPAA  Audio PresentationHIPAA  Audio Presentation
HIPAA Audio Presentation
 
Keys To HIPAA Compliance
Keys To HIPAA ComplianceKeys To HIPAA Compliance
Keys To HIPAA Compliance
 
HIPAA 101- What all Doctors NEED to know
HIPAA 101- What all Doctors NEED to knowHIPAA 101- What all Doctors NEED to know
HIPAA 101- What all Doctors NEED to know
 
Health Insurance Portability and Accountability Act (HIPAA) Compliance
Health Insurance Portability and Accountability Act (HIPAA) ComplianceHealth Insurance Portability and Accountability Act (HIPAA) Compliance
Health Insurance Portability and Accountability Act (HIPAA) Compliance
 
HIPAA Basics by Brian Fleetham
HIPAA Basics by Brian FleethamHIPAA Basics by Brian Fleetham
HIPAA Basics by Brian Fleetham
 
Hipaa journal com - HIPAA compliance guide
Hipaa journal com - HIPAA compliance guideHipaa journal com - HIPAA compliance guide
Hipaa journal com - HIPAA compliance guide
 
Welcome to HIPAA Training
Welcome to HIPAA TrainingWelcome to HIPAA Training
Welcome to HIPAA Training
 
HIPAA Complaince
HIPAA ComplainceHIPAA Complaince
HIPAA Complaince
 
Hipaa101 updated
Hipaa101 updatedHipaa101 updated
Hipaa101 updated
 
HIPPA-Health Insurance Portability and Accountability Act
HIPPA-Health Insurance Portability and Accountability ActHIPPA-Health Insurance Portability and Accountability Act
HIPPA-Health Insurance Portability and Accountability Act
 
2017 HIPAA Clinical Research Training
2017 HIPAA Clinical Research Training2017 HIPAA Clinical Research Training
2017 HIPAA Clinical Research Training
 
The Health Insurance Portability and Accountability Act 
The Health Insurance Portability and Accountability Act The Health Insurance Portability and Accountability Act 
The Health Insurance Portability and Accountability Act 
 
HIPAA - Understanding the Basics of Compliance
HIPAA - Understanding the Basics of ComplianceHIPAA - Understanding the Basics of Compliance
HIPAA - Understanding the Basics of Compliance
 
The Startup Path to HIPAA Compliance
The Startup Path to HIPAA ComplianceThe Startup Path to HIPAA Compliance
The Startup Path to HIPAA Compliance
 
UNA HIPAA Training 8-13
UNA HIPAA Training   8-13UNA HIPAA Training   8-13
UNA HIPAA Training 8-13
 
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)
 
HIPAA Compliance For Small Practices
HIPAA Compliance For Small PracticesHIPAA Compliance For Small Practices
HIPAA Compliance For Small Practices
 
HIPAA Summary for Training
HIPAA Summary for Training HIPAA Summary for Training
HIPAA Summary for Training
 
HIPAA HITECH training 7-9-12
HIPAA HITECH training 7-9-12HIPAA HITECH training 7-9-12
HIPAA HITECH training 7-9-12
 

Similar to What You Don’t Know About the HIPAA Security Rule

Patient confidentiality power point
Patient confidentiality power pointPatient confidentiality power point
Patient confidentiality power pointchwiso8418
 
Patient confidentiality
Patient confidentialityPatient confidentiality
Patient confidentialitychwiso8418
 
Patient confidentiality power point
Patient confidentiality power pointPatient confidentiality power point
Patient confidentiality power pointchwiso8418
 
MHA690 confidentiality training
MHA690 confidentiality trainingMHA690 confidentiality training
MHA690 confidentiality trainingsdavis49
 
2018-HIPAA-Renewal-Training.pptx
2018-HIPAA-Renewal-Training.pptx2018-HIPAA-Renewal-Training.pptx
2018-HIPAA-Renewal-Training.pptxFariida Osman
 
Patient confidentiality.ppt
Patient confidentiality.pptPatient confidentiality.ppt
Patient confidentiality.pptchwiso8418
 
HIPAA Part I the Law Test
HIPAA Part I  the Law TestHIPAA Part I  the Law Test
HIPAA Part I the Law TestSachiko Hurst
 
Data Security and Privacy Practices
Data Security and Privacy PracticesData Security and Privacy Practices
Data Security and Privacy PracticesSpringfield Clinic
 
HIPAA and Privacy Training
HIPAA and Privacy TrainingHIPAA and Privacy Training
HIPAA and Privacy TrainingJasAmataga
 
Hipaa basics.pp2
Hipaa basics.pp2Hipaa basics.pp2
Hipaa basics.pp2martykoepke
 
Understanding HIPAA
Understanding HIPAAUnderstanding HIPAA
Understanding HIPAAManas Deep
 
HIPAA Compliance: What Medical Practices and Their Business Associates Need t...
HIPAA Compliance: What Medical Practices and Their Business Associates Need t...HIPAA Compliance: What Medical Practices and Their Business Associates Need t...
HIPAA Compliance: What Medical Practices and Their Business Associates Need t...Skoda Minotti
 
health insurance portability and accountability act.pptx
health insurance portability and accountability act.pptxhealth insurance portability and accountability act.pptx
health insurance portability and accountability act.pptxamartya2087
 
Rems hipaa
Rems hipaaRems hipaa
Rems hipaadhexel
 
Are You HIPAA Safe?
Are You HIPAA Safe?Are You HIPAA Safe?
Are You HIPAA Safe?TriageLogic
 
A brief introduction to hipaa compliance
A brief introduction to hipaa complianceA brief introduction to hipaa compliance
A brief introduction to hipaa compliancePrince George
 

Similar to What You Don’t Know About the HIPAA Security Rule (20)

Patient confidentiality power point
Patient confidentiality power pointPatient confidentiality power point
Patient confidentiality power point
 
Patient confidentiality
Patient confidentialityPatient confidentiality
Patient confidentiality
 
Patient confidentiality power point
Patient confidentiality power pointPatient confidentiality power point
Patient confidentiality power point
 
MHA690 confidentiality training
MHA690 confidentiality trainingMHA690 confidentiality training
MHA690 confidentiality training
 
2018-HIPAA-Renewal-Training.pptx
2018-HIPAA-Renewal-Training.pptx2018-HIPAA-Renewal-Training.pptx
2018-HIPAA-Renewal-Training.pptx
 
Patient confidentiality.ppt
Patient confidentiality.pptPatient confidentiality.ppt
Patient confidentiality.ppt
 
HIPAA Part I the Law Test
HIPAA Part I  the Law TestHIPAA Part I  the Law Test
HIPAA Part I the Law Test
 
Data Security and Privacy Practices
Data Security and Privacy PracticesData Security and Privacy Practices
Data Security and Privacy Practices
 
HIPAA and Privacy Training
HIPAA and Privacy TrainingHIPAA and Privacy Training
HIPAA and Privacy Training
 
Hipaa basics.pp2
Hipaa basics.pp2Hipaa basics.pp2
Hipaa basics.pp2
 
Understanding HIPAA
Understanding HIPAAUnderstanding HIPAA
Understanding HIPAA
 
Hipaa
HipaaHipaa
Hipaa
 
HIPAA Compliance: What Medical Practices and Their Business Associates Need t...
HIPAA Compliance: What Medical Practices and Their Business Associates Need t...HIPAA Compliance: What Medical Practices and Their Business Associates Need t...
HIPAA Compliance: What Medical Practices and Their Business Associates Need t...
 
health insurance portability and accountability act.pptx
health insurance portability and accountability act.pptxhealth insurance portability and accountability act.pptx
health insurance portability and accountability act.pptx
 
Rems hipaa
Rems hipaaRems hipaa
Rems hipaa
 
Hipaa for business associates simple
Hipaa for business associates   simpleHipaa for business associates   simple
Hipaa for business associates simple
 
HNI U: HIPAA Essentials
HNI U: HIPAA EssentialsHNI U: HIPAA Essentials
HNI U: HIPAA Essentials
 
Are You HIPAA Safe?
Are You HIPAA Safe?Are You HIPAA Safe?
Are You HIPAA Safe?
 
Dustin HIPAA
Dustin HIPAADustin HIPAA
Dustin HIPAA
 
A brief introduction to hipaa compliance
A brief introduction to hipaa complianceA brief introduction to hipaa compliance
A brief introduction to hipaa compliance
 

Recently uploaded

Call Now ☎ 9999965857 !! Call Girls in Hauz Khas Escort Service Delhi N.C.R.
Call Now ☎ 9999965857 !! Call Girls in Hauz Khas Escort Service Delhi N.C.R.Call Now ☎ 9999965857 !! Call Girls in Hauz Khas Escort Service Delhi N.C.R.
Call Now ☎ 9999965857 !! Call Girls in Hauz Khas Escort Service Delhi N.C.R.ktanvi103
 
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Call Girls Service Faridabad 📲 9999965857 ヅ10k NiGhT Call Girls In Faridabad
Call Girls Service Faridabad 📲 9999965857 ヅ10k NiGhT Call Girls In FaridabadCall Girls Service Faridabad 📲 9999965857 ヅ10k NiGhT Call Girls In Faridabad
Call Girls Service Faridabad 📲 9999965857 ヅ10k NiGhT Call Girls In Faridabadgragmanisha42
 
❤️♀️@ Jaipur Call Girl Agency ❤️♀️@ Manjeet Russian Call Girls Service in Jai...
❤️♀️@ Jaipur Call Girl Agency ❤️♀️@ Manjeet Russian Call Girls Service in Jai...❤️♀️@ Jaipur Call Girl Agency ❤️♀️@ Manjeet Russian Call Girls Service in Jai...
❤️♀️@ Jaipur Call Girl Agency ❤️♀️@ Manjeet Russian Call Girls Service in Jai...Gfnyt.com
 
Call Girl Raipur 📲 9999965857 ヅ10k NiGhT Call Girls In Raipur
Call Girl Raipur 📲 9999965857 ヅ10k NiGhT Call Girls In RaipurCall Girl Raipur 📲 9999965857 ヅ10k NiGhT Call Girls In Raipur
Call Girl Raipur 📲 9999965857 ヅ10k NiGhT Call Girls In Raipurgragmanisha42
 
VIP Call Girl Sector 25 Gurgaon Just Call Me 9899900591
VIP Call Girl Sector 25 Gurgaon Just Call Me 9899900591VIP Call Girl Sector 25 Gurgaon Just Call Me 9899900591
VIP Call Girl Sector 25 Gurgaon Just Call Me 9899900591adityaroy0215
 
Nanded Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Nanded Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetNanded Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Nanded Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetCall Girls Service
 
Hot Call Girl In Chandigarh 👅🥵 9053'900678 Call Girls Service In Chandigarh
Hot  Call Girl In Chandigarh 👅🥵 9053'900678 Call Girls Service In ChandigarhHot  Call Girl In Chandigarh 👅🥵 9053'900678 Call Girls Service In Chandigarh
Hot Call Girl In Chandigarh 👅🥵 9053'900678 Call Girls Service In ChandigarhVip call girls In Chandigarh
 
Krishnagiri call girls Tamil aunty 7877702510
Krishnagiri call girls Tamil aunty 7877702510Krishnagiri call girls Tamil aunty 7877702510
Krishnagiri call girls Tamil aunty 7877702510Vipesco
 
VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591
VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591
VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591adityaroy0215
 
Dehradun Call Girls Service 08854095900 Real Russian Girls Looking Models
Dehradun Call Girls Service 08854095900 Real Russian Girls Looking ModelsDehradun Call Girls Service 08854095900 Real Russian Girls Looking Models
Dehradun Call Girls Service 08854095900 Real Russian Girls Looking Modelsindiancallgirl4rent
 
❤️Call girls in Jalandhar ☎️9876848877☎️ Call Girl service in Jalandhar☎️ Jal...
❤️Call girls in Jalandhar ☎️9876848877☎️ Call Girl service in Jalandhar☎️ Jal...❤️Call girls in Jalandhar ☎️9876848877☎️ Call Girl service in Jalandhar☎️ Jal...
❤️Call girls in Jalandhar ☎️9876848877☎️ Call Girl service in Jalandhar☎️ Jal...chandigarhentertainm
 
Call Girls Service Chandigarh Gori WhatsApp ❤7710465962 VIP Call Girls Chandi...
Call Girls Service Chandigarh Gori WhatsApp ❤7710465962 VIP Call Girls Chandi...Call Girls Service Chandigarh Gori WhatsApp ❤7710465962 VIP Call Girls Chandi...
Call Girls Service Chandigarh Gori WhatsApp ❤7710465962 VIP Call Girls Chandi...Niamh verma
 
Local Housewife and effective ☎️ 8250192130 🍉🍓 Sexy Girls VIP Call Girls Chan...
Local Housewife and effective ☎️ 8250192130 🍉🍓 Sexy Girls VIP Call Girls Chan...Local Housewife and effective ☎️ 8250192130 🍉🍓 Sexy Girls VIP Call Girls Chan...
Local Housewife and effective ☎️ 8250192130 🍉🍓 Sexy Girls VIP Call Girls Chan...Russian Call Girls Amritsar
 
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Me
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near MeVIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Me
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Memriyagarg453
 
Jalandhar Female Call Girls Contact Number 9053900678 💚Jalandhar Female Call...
Jalandhar  Female Call Girls Contact Number 9053900678 💚Jalandhar Female Call...Jalandhar  Female Call Girls Contact Number 9053900678 💚Jalandhar Female Call...
Jalandhar Female Call Girls Contact Number 9053900678 💚Jalandhar Female Call...Call Girls Service Chandigarh Ayushi
 
💚😋Mumbai Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Mumbai Escort Service Call Girls, ₹5000 To 25K With AC💚😋💚😋Mumbai Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Mumbai Escort Service Call Girls, ₹5000 To 25K With AC💚😋Sheetaleventcompany
 
Call Girls In ludhiana For Fun 9053900678 By ludhiana Call Girls For Pick...
Call Girls In  ludhiana  For Fun 9053900678 By  ludhiana  Call Girls For Pick...Call Girls In  ludhiana  For Fun 9053900678 By  ludhiana  Call Girls For Pick...
Call Girls In ludhiana For Fun 9053900678 By ludhiana Call Girls For Pick...Russian Call Girls in Ludhiana
 
Enjoyment ★ 8854095900 Indian Call Girls In Dehradun 🍆🍌 By Dehradun Call Girl ★
Enjoyment ★ 8854095900 Indian Call Girls In Dehradun 🍆🍌 By Dehradun Call Girl ★Enjoyment ★ 8854095900 Indian Call Girls In Dehradun 🍆🍌 By Dehradun Call Girl ★
Enjoyment ★ 8854095900 Indian Call Girls In Dehradun 🍆🍌 By Dehradun Call Girl ★indiancallgirl4rent
 
Dehradun Call Girls Service ❤️🍑 8854095900 👄🫦Independent Escort Service Dehradun
Dehradun Call Girls Service ❤️🍑 8854095900 👄🫦Independent Escort Service DehradunDehradun Call Girls Service ❤️🍑 8854095900 👄🫦Independent Escort Service Dehradun
Dehradun Call Girls Service ❤️🍑 8854095900 👄🫦Independent Escort Service DehradunNiamh verma
 

Recently uploaded (20)

Call Now ☎ 9999965857 !! Call Girls in Hauz Khas Escort Service Delhi N.C.R.
Call Now ☎ 9999965857 !! Call Girls in Hauz Khas Escort Service Delhi N.C.R.Call Now ☎ 9999965857 !! Call Girls in Hauz Khas Escort Service Delhi N.C.R.
Call Now ☎ 9999965857 !! Call Girls in Hauz Khas Escort Service Delhi N.C.R.
 
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service Available
 
Call Girls Service Faridabad 📲 9999965857 ヅ10k NiGhT Call Girls In Faridabad
Call Girls Service Faridabad 📲 9999965857 ヅ10k NiGhT Call Girls In FaridabadCall Girls Service Faridabad 📲 9999965857 ヅ10k NiGhT Call Girls In Faridabad
Call Girls Service Faridabad 📲 9999965857 ヅ10k NiGhT Call Girls In Faridabad
 
❤️♀️@ Jaipur Call Girl Agency ❤️♀️@ Manjeet Russian Call Girls Service in Jai...
❤️♀️@ Jaipur Call Girl Agency ❤️♀️@ Manjeet Russian Call Girls Service in Jai...❤️♀️@ Jaipur Call Girl Agency ❤️♀️@ Manjeet Russian Call Girls Service in Jai...
❤️♀️@ Jaipur Call Girl Agency ❤️♀️@ Manjeet Russian Call Girls Service in Jai...
 
Call Girl Raipur 📲 9999965857 ヅ10k NiGhT Call Girls In Raipur
Call Girl Raipur 📲 9999965857 ヅ10k NiGhT Call Girls In RaipurCall Girl Raipur 📲 9999965857 ヅ10k NiGhT Call Girls In Raipur
Call Girl Raipur 📲 9999965857 ヅ10k NiGhT Call Girls In Raipur
 
VIP Call Girl Sector 25 Gurgaon Just Call Me 9899900591
VIP Call Girl Sector 25 Gurgaon Just Call Me 9899900591VIP Call Girl Sector 25 Gurgaon Just Call Me 9899900591
VIP Call Girl Sector 25 Gurgaon Just Call Me 9899900591
 
Nanded Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Nanded Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetNanded Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Nanded Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
Hot Call Girl In Chandigarh 👅🥵 9053'900678 Call Girls Service In Chandigarh
Hot  Call Girl In Chandigarh 👅🥵 9053'900678 Call Girls Service In ChandigarhHot  Call Girl In Chandigarh 👅🥵 9053'900678 Call Girls Service In Chandigarh
Hot Call Girl In Chandigarh 👅🥵 9053'900678 Call Girls Service In Chandigarh
 
Krishnagiri call girls Tamil aunty 7877702510
Krishnagiri call girls Tamil aunty 7877702510Krishnagiri call girls Tamil aunty 7877702510
Krishnagiri call girls Tamil aunty 7877702510
 
VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591
VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591
VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591
 
Dehradun Call Girls Service 08854095900 Real Russian Girls Looking Models
Dehradun Call Girls Service 08854095900 Real Russian Girls Looking ModelsDehradun Call Girls Service 08854095900 Real Russian Girls Looking Models
Dehradun Call Girls Service 08854095900 Real Russian Girls Looking Models
 
❤️Call girls in Jalandhar ☎️9876848877☎️ Call Girl service in Jalandhar☎️ Jal...
❤️Call girls in Jalandhar ☎️9876848877☎️ Call Girl service in Jalandhar☎️ Jal...❤️Call girls in Jalandhar ☎️9876848877☎️ Call Girl service in Jalandhar☎️ Jal...
❤️Call girls in Jalandhar ☎️9876848877☎️ Call Girl service in Jalandhar☎️ Jal...
 
Call Girls Service Chandigarh Gori WhatsApp ❤7710465962 VIP Call Girls Chandi...
Call Girls Service Chandigarh Gori WhatsApp ❤7710465962 VIP Call Girls Chandi...Call Girls Service Chandigarh Gori WhatsApp ❤7710465962 VIP Call Girls Chandi...
Call Girls Service Chandigarh Gori WhatsApp ❤7710465962 VIP Call Girls Chandi...
 
Local Housewife and effective ☎️ 8250192130 🍉🍓 Sexy Girls VIP Call Girls Chan...
Local Housewife and effective ☎️ 8250192130 🍉🍓 Sexy Girls VIP Call Girls Chan...Local Housewife and effective ☎️ 8250192130 🍉🍓 Sexy Girls VIP Call Girls Chan...
Local Housewife and effective ☎️ 8250192130 🍉🍓 Sexy Girls VIP Call Girls Chan...
 
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Me
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near MeVIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Me
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Me
 
Jalandhar Female Call Girls Contact Number 9053900678 💚Jalandhar Female Call...
Jalandhar  Female Call Girls Contact Number 9053900678 💚Jalandhar Female Call...Jalandhar  Female Call Girls Contact Number 9053900678 💚Jalandhar Female Call...
Jalandhar Female Call Girls Contact Number 9053900678 💚Jalandhar Female Call...
 
💚😋Mumbai Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Mumbai Escort Service Call Girls, ₹5000 To 25K With AC💚😋💚😋Mumbai Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Mumbai Escort Service Call Girls, ₹5000 To 25K With AC💚😋
 
Call Girls In ludhiana For Fun 9053900678 By ludhiana Call Girls For Pick...
Call Girls In  ludhiana  For Fun 9053900678 By  ludhiana  Call Girls For Pick...Call Girls In  ludhiana  For Fun 9053900678 By  ludhiana  Call Girls For Pick...
Call Girls In ludhiana For Fun 9053900678 By ludhiana Call Girls For Pick...
 
Enjoyment ★ 8854095900 Indian Call Girls In Dehradun 🍆🍌 By Dehradun Call Girl ★
Enjoyment ★ 8854095900 Indian Call Girls In Dehradun 🍆🍌 By Dehradun Call Girl ★Enjoyment ★ 8854095900 Indian Call Girls In Dehradun 🍆🍌 By Dehradun Call Girl ★
Enjoyment ★ 8854095900 Indian Call Girls In Dehradun 🍆🍌 By Dehradun Call Girl ★
 
Dehradun Call Girls Service ❤️🍑 8854095900 👄🫦Independent Escort Service Dehradun
Dehradun Call Girls Service ❤️🍑 8854095900 👄🫦Independent Escort Service DehradunDehradun Call Girls Service ❤️🍑 8854095900 👄🫦Independent Escort Service Dehradun
Dehradun Call Girls Service ❤️🍑 8854095900 👄🫦Independent Escort Service Dehradun
 

What You Don’t Know About the HIPAA Security Rule

  • 2. ESSENTIAL STRATEGIES HIPAA 2.0 Allan Ridings Jeff Mongelli CEO, Acentec, Inc. •15 years of health care IT experience •Nationally published on health care IT security Senior Risk Management& Patient Safety Specialist – Cooperative of American Physicians, Inc. • 30 years of practice management experience • Nationally published on HIPAA and eHealth
  • 3. ESSENTIAL STRATEGIES OBJECTIVES: • Identify components of HIPAA compliancy • Describe recent changes in HIPAA • Sharing protected health information • Restricting protected health information
  • 4. ESSENTIAL STRATEGIES HEALTH INFORMATION PRIVACY Overview: Health Insurance Portability & Accountability Act of 1996 (HIPAA)
  • 5. What is HIPAA? HIPAA regulations require all health care providers, organizations, and business associates to develop / follow procedures that ensure the security and confidentiality of protected health information (PHI, ePHI) when being handled, received, transferred, or shared (oral, paper, or electronic). HIPAA is enforced by the Office of Civil Rights (OCR).
  • 6. HIPAA Benefits • Supporting obligations • Supporting compliance • Secured records • Knowledgeable staff • Reduced risk
  • 7. HIPAA Compliancy • Notice of Privacy Practices (NPP) • Patient Acknowledgements • Protected Health Information (PHI, ePHI) • Office Risk Assessment (RA) • Business Associate Agreements (BAA)
  • 8. HIPAA Compliancy • E-mailing of ePHI • Copying / Releasing PHI • Childhood / Student Immunizations
  • 9. HIPAA Compliancy • Disclosure Duties • Unapproved Access to PHI, ePHI (breach) • Sale of PHI
  • 10. ESSENTIAL STRATEGIES: HIPAA COMPLIANCY Notice of Privacy Practices (NPP)
  • 11. Requires that all covered health care providers develop and distribute a notice. The notice must provide a clear, user-friendly explanation of individuals’ [patients’] rights regarding PHI, ePHI, and the privacy practices of the entity, health provider, or health plan. Notice of Privacy Practices
  • 12. NPP - Patient Acknowledgements Notice of Privacy Practices (HIPAA, PHI, ePHI, BAA): • Accessible via poster or binder for patient and others • Provide a fact sheet • Signed receipt / acknowledgment form (physically or electronically)
  • 13. Notice of Privacy Practices Must be posted or available.
  • 15. ESSENTIAL STRATEGIES: HIPAA COMPLIANCY Releasing Protected Health Information (PHI, ePHI) COOPERATIVE OF AMERICAN PHYSICIANS
  • 16. Affected individuals must be notified: • When types of uses and disclosures require authorization • That disclosures will be made only with authorization • If any information is used for marketing or sold An individual may revoke authorization. PHI - Release Authorization
  • 17. Why this matters: • The Office for Civil Rights has stated the next big HIPAA update will be regarding ACCOUNTING FOR DISCLOSURES (it’s past due). PHI - Release Authorization
  • 18. PHI - Release Authorization Written authorizations: • Are required for inspection and/or release of billing notes or any part of a medical record. • A separate authorization is required for each release. (with exceptions)
  • 19. PHI - Release Authorization Time: • Inspection of records honored within 5 working days • Copies must be released within 15 calendar days • Have uniformed policy, educated staff
  • 20. PHI - Release Authorization Applicable Charges: • Reasonable clerical fees, plus 25¢ per page • $15 maximum clerical fee for subpoena copy services • Records to support an appeal for a public benefit program provided at no charge and within 30 days • When released on CD or USB thumb-drive, you may charge for the labor and media
  • 21. PHI - Release Authorization Applicable Exceptions: Health care providers and other entities that participate in an Organized Health Care Arrangement (OHCA) All entities, sites, and locations may share medical information with each other for treatment, payment, and health care operations purposes. [45 CFR 164.520(d)]
  • 22. PHI - Release Authorization HIPAA Privacy during emergencies (11/2014): • Treatment during emergencies [45 CFR 164.502(a)(1)(ii), 164.506(c), 164.510(b)] • Public Health Activities - CDC & Public Heath Authorities • Imminent threat to public health [45 CFR 164.512(b)(1)(i)]
  • 23. PHI - Release Authorization Physician Notification & Review: • Review all requests that arrive to your offices Documentation: • Who, Where, When (disclosure log)
  • 24. PHI - Personal Request Authorization Future Date Personal
  • 25. PHI - Release To / From Authorization Specific Date Continuity
  • 26. Childhood Immunization Records A Covered Entity may release student or childhood immunization records to a school/college without authorization: • If state law requires a school to have an immunization record on file • Written or oral agreement (must be documented)
  • 27. PHI - Disclosure Log DISCLOSURE LOG
  • 30. What is needed… when we e-mail or text patients? Code of Federal Regulations
  • 31. Code of Federal Regulations CFR requires encryption when e-mailing or texting electronic protected health information (ePHI). ENCRYPTION
  • 32. Code of Federal Regulations A covered entity must: • Implement a mechanism to encrypt and decrypt electronically protected health information (45 CFR § 164.312) • Be in accordance with privacy rule (45 CFR§164.306)
  • 33. Code of Federal Regulations Access rights require a covered entity to: • Use Advanced Encryption Standard (AES) encryption, either 128-bit or 256-bit • Implement technical policies and procedures for systems that maintain electronic protected health information 164.308(a)(4) [Information Access Management]
  • 35. Treatment, Payment, Operations Treatment: • Medical care, all in-office, e-health, m-health, t- health Payment: • Referrals • Medical billing office, claims, internal /external services Operations: • Medical office policies /procedures • Office rules and regulations /business policies
  • 36. ESSENTIAL STRATEGIES: HIPAA COMPLIANCY Business Associate Agreement (BAA) COOPERATIVE OF AMERICAN PHYSICIANS
  • 37. Business Associate Agreements Required with entities that: • Create • Receive e-health / diagnostic services • Store / maintain any type of PHI, ePHI • Transmit ePHI on behalf of a covered entity Subcontractor: • Subcontractor = person to whom a business associate delegates a function, activity, or service • Subcontractor + PHI = Business Associate
  • 38. Agency vs. Independent Contractor Business Associate Agreements
  • 40. Is this person a Business Associate? Business Associate Agreements
  • 42. Breach Disclosure Duties Breach (45 C.F.R. § 164.406 - 164.410) : Unauthorized acquisition, access, use, disclosure of unsecured PHI, ePHI in a manner not permitted by the HIPAA Privacy Rule that compromises the security or privacy of PHI, ePHI. Covered entities and business associates are required to report any breach of unsecured PHI, ePHI.
  • 43. Do we HAVE to notify patients?: “… breach notification is necessary in all situations except those in which the CE demonstrates that there is a low probability that the protected health information has been compromised based on a risk assessment ...” Section 160.402 Breach Disclosure Duties
  • 44. Less than 500 patients: Covered entities and business associates are required to notify OCR of breach no later than 60 days of calendar year end. • Notify your Medical Professional Liability Carrier. • Follow breach instructions: www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/brinstru ction.html Breach Disclosure Duties
  • 45. Greater than 500 patients: Required to notify OCR within 60 days of breach. • Must notify the media • Offer affected patients 1 year credit monitoring service • Notify your Medical Professional Liability Carrier • Follow breach instructions: www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/brinstru ction.html Breach Disclosure Duties
  • 46. Incident Risk Assessment (IRA): An Incident Risk Assessment should include: • the nature and extent of the PHI involved; • the unauthorized person who used the PHI or to whom the PHI was disclosed; • whether the PHI was actually acquired or viewed; and • the extent to which the risk to the PHI has been mitigated. The IRA is only required if the CE, based on the facts, wants to demonstrate that no notification is required. Breach Disclosure Duties
  • 47. ESSENTIAL STRATEGIES: HIPAA COMPLIANCY Office Risk Assessment (RA) COOPERATIVE OF AMERICAN PHYSICIANS
  • 48. Office Risk Assessment • A risk assessment helps your organization ensure it is compliant with HIPAA’s administrative, physical, and technical safeguards. • Risk assessments may reveal areas where your organization’s protected health information (PHI, ePHI) may be at risk.
  • 51. ESSENTIAL STRATEGIES: HIPAA COMPLIANCY Let’s review what’s required of you…
  • 52. Medical Office Requirements #1 Secure registration process: • Face-to-face • Patient portal (EHR) Notice of Privacy Practices - HIPAA / PHI, ePHI: • Poster, notice, or binder • Signature acceptance Business Associate Agreements (BAA) • Transmit ePHI on behalf of a covered entity
  • 53. Medical Office Requirements #2 HIPAA education training for all staff: • Sign-in sheet • Signature understanding / acceptance Risk Assessment: • Regularly scheduled assessments
  • 54. 8 Most Common Causes of Violations • Users that have legitimate access to sensitive information are the weakest link in information security • Sharing passwords • Exposing passwords (taped to monitor) • Giving out passwords • Sending PHI to incorrect destinations • Sharing PHI on social media • Discussing PHI with others or in front of others #1 Authorized Users
  • 55. 8 Most Common Causes of Violations • BCBS Tennessee ($1.5 M) • Failure to re-evaluate threats/vulnerabilities to ePHI caused by changing operational environment and manage risk • Alaska DHSS ($1.7M) • Failure to conduct a risk analysis to identify location and safeguards for PHI, training, and controls for portal devices • Mass. St. Elizabeth’s Medical Center (SEMC) ($218,000 ) • Has agreed to settle potential violations of HIPAA … for use of an Internet-based document sharing product and failure to timely notify OCR #2 Failure to Conduct or Update Risk Assessment
  • 56. 8 Most Common Causes of Violations • E-mail encryption • Backup encryption • Massachusetts Eye and Ear Institute ($1.5M) • Stolen personal laptop of physician using device as desktop substitute • Covered entity had not implemented a program to mitigate identified risks to ePHI • Encrypt data stored on end-user devices #3 Failure to Consider or Properly Implement New Technology
  • 57. 8 Most Common Causes of Violations • Phoenix Cardiac Surgery ($100K) • Backup encryption • ePHI disclosed through Internet when provider used third party application hosted in the cloud Business associate agreements are required when sharing data with cloud computing service providers! #4 Failure to Identify Business Associates
  • 58. 8 Most Common Causes of Violations • Culture of Convenience remains the prevailing practice in medicine • CSMC – settled violations related to disclosure of PHI of celebrity patients for $865,500 • Sharing of passwords, etc. • No enforcement of policies, i.e., “everyone is doing it” #5 Failure to Create Culture of Compliance Among Workforce
  • 59. 8 Most Common Causes of Violations • Cignet Health fined $4.3 million for refusing to provide access to medical records upon patient’s request. ($3 million attributed to “willful neglect” for refusing to comply with investigative requests.) • Right to amend information. • OCR examples • Failure to allow access to whole record (because part of it was created by another provider). #6 Failure to Remember Patient Rights
  • 60. 8 Most Common Causes of Violations • Attempt to condition privacy rule compliance on patient’s agreement to not disclose information about physician (we won’t tell if you don’t tell) (Yelp) • Failure to accommodate a reasonable request for confidential communications (patient requested to be contacted only on mobile phone, not at home – but the treatment reminder was left on home voicemail) #6 Failure to Remember Patient Rights (cont.)
  • 61. 8 Most Common Causes of Violations • Discussion of PHI in front of other patients, in waiting rooms • Paper PHI not safeguarded from theft • Information faxed to patient’s employer did not include confidentiality statement on cover sheet • Massachusetts General Hospital – Paid $1,000,000 to settle violations related to loss of PHI of 192 patients on subway train from infectious disease outpatient practice (including HIV/AIDS patients) #7 Forgetting About “Reasonable Safeguards”
  • 62. 8 Most Common Causes of Violations • Failure to distribute information on a “need to know” basis • Example: OR schedule sent to people who had no need for the information – complainant was an employee/patient • Computer access and paper access #8 Forgetting the Minimum Necessary Rule
  • 64. ESSENTIAL STRATEGIES: HIPAA COMPLIANCY The information in this presentation should not be considered legal advice applicable to a specific situation. Legal guidance for individual matters should be obtained from a retained attorney.
  • 65. ESSENTIAL STRATEGIES: HIPAA COMPLIANCY Allan Ridings Cooperative of American Physicians, Inc. Phone: 800-252-7706 Email: riskmanagement@CAPphysicians.com Web: www.CAPphysicians.com Jeff Mongelli, CEO Acentec, Inc. Phone: 949-474-7774 Email: jeffm@acentec.com Web: www.acentec.com

Editor's Notes

  1. This is the personal request for records, talk of the yellow highlighted (CONTINUITY OF CARE) and (SPECIFIC DATE) and a little of the yellow highlighted CMIA Protected information. THIS doesn't override CMIA or HIPAA – however if the patient wishes their records to go to any caregiver / medical care provider that is NOT within a network / OHCA, then an authorization is optimal to show that you have complied with the 15 / 30 day record release rules of CMIA / HIPAA
  2. CA has a requirement that all students must have immunizations to attend public schools or colleges. Do not talk regarding current legislation on the requirements.
  3. How to use the disclosure log for anything being released except for TPO – if its personal, or going anywhere not involved in any TPO –, log it.
  4. Explain the CFR encryption rules – see next slide
  5. Explain what the reason, talk a little of all the breaches that are happening, name some of the big box retailers, the insurance industry, and the government hacking issues. The standard you’ll be held to is based upon financial and technical feasibility. If you could have implemented a technology for a reasonable cost and you didn’t, you’ll be facing greater scrutiny (that’s code for penalties).
  6. Give some details these items do not need to be logged on the disclosure log, however, there is nothing stopping your office from doing so, if you do so, have a standard policy for all staff members to follow. “Treatment” generally means the provision, coordination, or management of health care and related services among health care providers or by a health care provider with a third party, consultation between health care providers regarding a patient, or the referral of a patient from one health care provider to another. “Payment” encompasses the various activities of health care providers to obtain payment or be reimbursed for their services and of a health plan to obtain premiums, to fulfill their coverage responsibilities and provide benefits under the plan, and to obtain or provide reimbursement for the provision of health care. “Health care operations” are certain administrative, financial, legal, and quality improvement activities of a covered entity that are necessary to run its business and to support the core functions of treatment and payment.
  7. Explain the sharing of data – e-health e-PHI, PHI etc.. And give an example of a billing service, and if you change your contracts, what needs to happen with a BAA
  8. Talk of what a breach is, how it happens, why the importance is there!
  9. What the importance of the Greater than 500 patients – talk a little of the breach that happened at the BLUE’s / TARGET / HOME DEPOT etc.
  10. This is NOT the Risk Assessment you are required to conduct (and document) annually. This is the process you should use when you suspect you’ve experienced a breach.
  11. Talk of this example and what it means to the office, and to EHR incentive plans or, Meaningful Use (MU)
  12. This is a closer look at passwords on the Risk Assessment, explain other ideas of a potential risk – servers in open areas, possible theft, USB flash drives. Etc.
  13. Most common passwords in 2014: 1. 123456 (Unchanged) – 1 and 2 have flipped back and forth for years. 2. password (Unchanged) 3. 12345 (Up 17) 4. 12345678 (Down 1) 5. qwerty (Down 1) 6. 123456789 (Unchanged) 7. 1234 (Up 9)
  14. Massachusetts General Hospital fine was announced July 2015. Also included was a breach of an employee storing ePHI on an unencrypted personal laptop and thumb drive. Difference between potential vs. actual exposure.