SlideShare a Scribd company logo
1 of 13
Privacy and Security Awareness
Training
Jessica Quesada
Health Care Capstone , MHA 690
Doctor David Cole
July 24, 2014
Privacy and Security Awareness
Training
Contents
 Employees Roles of Keeping Patients’ PHI
Secured
 HIPAA Privacy Rule
 PHI Violations and Breach
 Recommendations if PHI is Suspected
 Conclusions
Privacy and Security Awareness
Training
Awareness and training are important keys to
educate UCLA Hospital employees on how to
safeguard patients’ Protected Health Information
(PHI) and reduce the incidence of security breaches
in their healthcare organization. It is vital to describe
that PHI is information associated to the patient’s
health care such as patient’s name, address, date of
birth, phone number, social security number and
medical health records.
Privacy and Security Awareness
Training
Therefore, all employees
that handle sensitive and
confidential information
should be trained on the
policies and procedures
with respect to the
protection of this
information and they
should learn their
responsibilities to protect
the privacy of patients
annually.
Privacy and Security Awareness
Training
Employees’ roles of keeping Patients’ PHI
secured
Employees need to understand the importance of the
use and disclose of PHI as it is related to their job
because patient information is confidential.
Employees are not allowed to share this information
with others on duty or off duty. In fact, employees
are responsible of safeguarding and protecting
sensitive and confidential information by
unauthorized personnel.
Privacy and Security Awareness
Training
HIPAA Privacy Rule
Health Insurance
Portability and
Accountability (HIPAA)
Privacy Rule ensures
federal protection for the
privacy of patients’ records
and health information
from covered entities such
as health plans, health care
providers, health care and
clearinghouses.
Privacy and Security Awareness
Training
HIPAA Privacy Rule
The Privacy Rule standards address the use and
disclosure of patients’ PHI by these covered entities
and provide strong legal protection to ensure
confidentiality and privacy of electronic protected
health records. HIPAA Privacy Rule ensures that
patients’ health information is protected by users
while health care services are provided (New York
State, 2012).
Privacy and Security Awareness
Training
PHI violations and Breach Examples
Sometimes, PHI violations might not be identified as
incidents that cause significant harm to patients;
hence employees need to recognize potential violation
of the Privacy Rule and report them immediately.
For instance, PHI is sent to wrong recipient via
email, PHI is in lost laptops or flash drives,
unauthorized personnel access patient’s information
using other coworker’s passwords, a physician is
discussing about patient’s medical records to others
on a public area.
Privacy and Security Awareness
Training
PHI violations and Breach Examples
Another example is when an outreach letter with
sensitive information is sent to the wrong patient or
patient’s medical records are found in public areas
such as cafeteria or bathroom. If employees violate
the privacy and security policies that support the
HIPAA regulations, they might face disciplinary
action or employment termination (UPMC Horizon,
2012).
Privacy and Security Awareness
Training
Recommendations
if PHI is suspected
Employees need to access
PHI only if their job
requires, therefore
employees must report to
their supervisors or
compliance officer if they
observe any potential
threats that might
compromise PHI.
Privacy and Security Awareness
Training
Recommendations if PHI is suspected
Employees should never discuss patients’
information to those who have no right to know
about them. Another important recommendation is
to avoid discussing about PHI in public areas and
never repeat what is heard. Please keep drawers,
desks and doors locked in station where PHI is
found. It is highly recommended that employees
protect their passwords and log off if computers will
be unattended because it represents a significant
threat to the hospital and patients.
Privacy and Security Awareness
Training
Conclusion
Privacy and security awareness training can answer
many questions and concerns that employees might
experience in daily basis. It is vital to keep employees
informed and educated of their legal and ethical
obligations and security restriction in the event of a
PHI breach; thus they need to keep aware of any
changes that can help them comply with regulations
and policies that safeguard PHI. Indeed, different
examples were shared to visualize different situations
that might prevent employees from violating privacy
policies and receive sanctions that might lead to
employment termination.
References
Health Insurance Portability and Accountability Act
(HIPAA). (2012). New York State. Retrieved from
https://www.omh.ny.gov/omhweb/hipaa/
HIPAA Privacy & Security Awareness Training for
Students. (2010). UPMC Horizon. Retrieved from
http://www.upmc.com/locations/hospitals/horizon/career
s/documents/hippa-training.pdf

More Related Content

What's hot

Confidentiality in Healthcare
Confidentiality in HealthcareConfidentiality in Healthcare
Confidentiality in Healthcarekmasterson
 
Patients’ privacy and confidentiality
Patients’ privacy and confidentialityPatients’ privacy and confidentiality
Patients’ privacy and confidentialitybernardsanch
 
Healthcare Confidentiality
Healthcare ConfidentialityHealthcare Confidentiality
Healthcare Confidentialityljbroshious
 
Privacy and confidentiality
Privacy and confidentialityPrivacy and confidentiality
Privacy and confidentialityjohnzinn
 
Patient Confidentiality
Patient ConfidentialityPatient Confidentiality
Patient Confidentialitymarosemond
 
Leading your HIPAA Compliance Culture in 2016
Leading your HIPAA Compliance Culture in 2016Leading your HIPAA Compliance Culture in 2016
Leading your HIPAA Compliance Culture in 2016Lance King
 
Patient confidentiality
Patient confidentialityPatient confidentiality
Patient confidentialityptamayo1958
 
Health care confidentiality and privacy
Health care confidentiality and privacyHealth care confidentiality and privacy
Health care confidentiality and privacysawanda
 
Patient privacy and confidentiality training
Patient privacy and confidentiality trainingPatient privacy and confidentiality training
Patient privacy and confidentiality trainingmandymandy3536
 
Confidentiality in the Workplace
Confidentiality in the WorkplaceConfidentiality in the Workplace
Confidentiality in the Workplacesalvarez63
 
Privacy and confidentiality
Privacy and confidentialityPrivacy and confidentiality
Privacy and confidentialityjaredbrady
 
Protecting patients confidentiality slide presentation
Protecting patients confidentiality slide presentationProtecting patients confidentiality slide presentation
Protecting patients confidentiality slide presentationplunkk
 
susanfullerMha690 week1discussion2pp
susanfullerMha690 week1discussion2ppsusanfullerMha690 week1discussion2pp
susanfullerMha690 week1discussion2ppPrayerful
 
MHA690 Patient Confidentiality Training
MHA690 Patient Confidentiality TrainingMHA690 Patient Confidentiality Training
MHA690 Patient Confidentiality Trainingrgasaway
 
Craig Hudson's HIPAA Training Outline
Craig Hudson's HIPAA Training OutlineCraig Hudson's HIPAA Training Outline
Craig Hudson's HIPAA Training OutlineCraig Hudson
 
Patient confidentiality training
Patient confidentiality trainingPatient confidentiality training
Patient confidentiality trainingSheena705
 

What's hot (20)

Confidentiality in Healthcare
Confidentiality in HealthcareConfidentiality in Healthcare
Confidentiality in Healthcare
 
Patients’ privacy and confidentiality
Patients’ privacy and confidentialityPatients’ privacy and confidentiality
Patients’ privacy and confidentiality
 
Healthcare Confidentiality
Healthcare ConfidentialityHealthcare Confidentiality
Healthcare Confidentiality
 
Privacy and confidentiality
Privacy and confidentialityPrivacy and confidentiality
Privacy and confidentiality
 
Confidentiality
ConfidentialityConfidentiality
Confidentiality
 
Patient Confidentiality
Patient ConfidentialityPatient Confidentiality
Patient Confidentiality
 
Leading your HIPAA Compliance Culture in 2016
Leading your HIPAA Compliance Culture in 2016Leading your HIPAA Compliance Culture in 2016
Leading your HIPAA Compliance Culture in 2016
 
Patient confidentiality
Patient confidentialityPatient confidentiality
Patient confidentiality
 
Health care confidentiality and privacy
Health care confidentiality and privacyHealth care confidentiality and privacy
Health care confidentiality and privacy
 
Patient privacy and confidentiality training
Patient privacy and confidentiality trainingPatient privacy and confidentiality training
Patient privacy and confidentiality training
 
Phi training
Phi trainingPhi training
Phi training
 
Phi training
Phi trainingPhi training
Phi training
 
Confidentiality in the Workplace
Confidentiality in the WorkplaceConfidentiality in the Workplace
Confidentiality in the Workplace
 
Privacy and confidentiality
Privacy and confidentialityPrivacy and confidentiality
Privacy and confidentiality
 
Protecting patients confidentiality slide presentation
Protecting patients confidentiality slide presentationProtecting patients confidentiality slide presentation
Protecting patients confidentiality slide presentation
 
susanfullerMha690 week1discussion2pp
susanfullerMha690 week1discussion2ppsusanfullerMha690 week1discussion2pp
susanfullerMha690 week1discussion2pp
 
MHA690 Patient Confidentiality Training
MHA690 Patient Confidentiality TrainingMHA690 Patient Confidentiality Training
MHA690 Patient Confidentiality Training
 
Phitrain
PhitrainPhitrain
Phitrain
 
Craig Hudson's HIPAA Training Outline
Craig Hudson's HIPAA Training OutlineCraig Hudson's HIPAA Training Outline
Craig Hudson's HIPAA Training Outline
 
Patient confidentiality training
Patient confidentiality trainingPatient confidentiality training
Patient confidentiality training
 

Viewers also liked

3 of 3 - 2015 Information Security & Privacy Awareness Training
3 of 3 - 2015 Information Security & Privacy Awareness Training3 of 3 - 2015 Information Security & Privacy Awareness Training
3 of 3 - 2015 Information Security & Privacy Awareness TrainingHaytham EL-Mahlawy
 
Webinar privacyawarenesswestviewpcn preview
Webinar privacyawarenesswestviewpcn previewWebinar privacyawarenesswestviewpcn preview
Webinar privacyawarenesswestviewpcn preview4WEB
 
The Perils of Policy: Potential OER Pitfalls of Copyright Policies and OA Leg...
The Perils of Policy: Potential OER Pitfalls of Copyright Policies and OA Leg...The Perils of Policy: Potential OER Pitfalls of Copyright Policies and OA Leg...
The Perils of Policy: Potential OER Pitfalls of Copyright Policies and OA Leg...BCcampus
 
Protection of Privacy in Internet-based Teaching & Learning Activities
Protection of Privacy in Internet-based Teaching & Learning ActivitiesProtection of Privacy in Internet-based Teaching & Learning Activities
Protection of Privacy in Internet-based Teaching & Learning ActivitiesBCcampus
 
Annual HIPAA Education
Annual HIPAA EducationAnnual HIPAA Education
Annual HIPAA EducationDirkRhodes
 
2015 azgfd heritage grants for education info session
2015 azgfd heritage grants for education info session2015 azgfd heritage grants for education info session
2015 azgfd heritage grants for education info sessioneproctor
 
Compliance2015
Compliance2015Compliance2015
Compliance2015pssurgery
 
Security awareness training ip5
Security awareness training ip5Security awareness training ip5
Security awareness training ip5Josh Chandler
 
Security Awareness Training
Security Awareness TrainingSecurity Awareness Training
Security Awareness TrainingDaniel P Wallace
 

Viewers also liked (11)

3 of 3 - 2015 Information Security & Privacy Awareness Training
3 of 3 - 2015 Information Security & Privacy Awareness Training3 of 3 - 2015 Information Security & Privacy Awareness Training
3 of 3 - 2015 Information Security & Privacy Awareness Training
 
Webinar privacyawarenesswestviewpcn preview
Webinar privacyawarenesswestviewpcn previewWebinar privacyawarenesswestviewpcn preview
Webinar privacyawarenesswestviewpcn preview
 
The Perils of Policy: Potential OER Pitfalls of Copyright Policies and OA Leg...
The Perils of Policy: Potential OER Pitfalls of Copyright Policies and OA Leg...The Perils of Policy: Potential OER Pitfalls of Copyright Policies and OA Leg...
The Perils of Policy: Potential OER Pitfalls of Copyright Policies and OA Leg...
 
Protection of Privacy in Internet-based Teaching & Learning Activities
Protection of Privacy in Internet-based Teaching & Learning ActivitiesProtection of Privacy in Internet-based Teaching & Learning Activities
Protection of Privacy in Internet-based Teaching & Learning Activities
 
Annual HIPAA Education
Annual HIPAA EducationAnnual HIPAA Education
Annual HIPAA Education
 
2015 azgfd heritage grants for education info session
2015 azgfd heritage grants for education info session2015 azgfd heritage grants for education info session
2015 azgfd heritage grants for education info session
 
Hipaa-2015
Hipaa-2015Hipaa-2015
Hipaa-2015
 
Compliance2015
Compliance2015Compliance2015
Compliance2015
 
Security awareness training ip5
Security awareness training ip5Security awareness training ip5
Security awareness training ip5
 
Corporate Company Training Guide 2015
Corporate Company Training Guide 2015Corporate Company Training Guide 2015
Corporate Company Training Guide 2015
 
Security Awareness Training
Security Awareness TrainingSecurity Awareness Training
Security Awareness Training
 

Similar to Week 1 discussion 2

Week 1 dq 2 - confidentiality1
Week 1   dq 2 - confidentiality1Week 1   dq 2 - confidentiality1
Week 1 dq 2 - confidentiality1mesaunders
 
Week 1 dq 2 - confidentiality1
Week 1   dq 2 - confidentiality1Week 1   dq 2 - confidentiality1
Week 1 dq 2 - confidentiality1mesaunders
 
Week 1 dq 2 - confidentiality1
Week 1   dq 2 - confidentiality1Week 1   dq 2 - confidentiality1
Week 1 dq 2 - confidentiality1mesaunders
 
Week 1 dq 2 - confidentiality1
Week 1   dq 2 - confidentiality1Week 1   dq 2 - confidentiality1
Week 1 dq 2 - confidentiality1mesaunders
 
HIPAA Basics
HIPAA BasicsHIPAA Basics
HIPAA BasicsKarna *
 
Marc etienne week1 discussion2 presentation
Marc etienne week1 discussion2 presentationMarc etienne week1 discussion2 presentation
Marc etienne week1 discussion2 presentationMarcEtienne6
 
Week 1 dq 2 - confidentiality1
Week 1   dq 2 - confidentiality1Week 1   dq 2 - confidentiality1
Week 1 dq 2 - confidentiality1mesaunders
 
Week 1 dq 2 - confidentiality1
Week 1   dq 2 - confidentiality1Week 1   dq 2 - confidentiality1
Week 1 dq 2 - confidentiality1mesaunders
 
Mha690 health care capstone - confidentiality 9-26-2013
Mha690   health care capstone - confidentiality 9-26-2013Mha690   health care capstone - confidentiality 9-26-2013
Mha690 health care capstone - confidentiality 9-26-2013LeRoy Ulibarri
 
Mha690 health care capstone - confidentiality 9-26-2013
Mha690   health care capstone - confidentiality 9-26-2013Mha690   health care capstone - confidentiality 9-26-2013
Mha690 health care capstone - confidentiality 9-26-2013LeRoy Ulibarri
 
Mha690 health care capstone - confidentiality 9-26-2013
Mha690   health care capstone - confidentiality 9-26-2013Mha690   health care capstone - confidentiality 9-26-2013
Mha690 health care capstone - confidentiality 9-26-2013LeRoy Ulibarri
 
Confidentiality
ConfidentialityConfidentiality
ConfidentialityTravisDC4
 
Sylvia hipaa powerpoint presentation 2010(2)
Sylvia hipaa powerpoint presentation 2010(2)Sylvia hipaa powerpoint presentation 2010(2)
Sylvia hipaa powerpoint presentation 2010(2)bholmes
 
Hipaa overview2011 student orientation
Hipaa overview2011 student orientationHipaa overview2011 student orientation
Hipaa overview2011 student orientationUniversity of Miami
 
Sylvia hipaa powerpoint presentation 2010(1)
Sylvia hipaa powerpoint presentation 2010(1)Sylvia hipaa powerpoint presentation 2010(1)
Sylvia hipaa powerpoint presentation 2010(1)bholmes
 
Mha690 wk 1 fletcher
Mha690 wk 1   fletcherMha690 wk 1   fletcher
Mha690 wk 1 fletcherEmed32
 
Discussion2
Discussion2 Discussion2
Discussion2 amberlinn
 
Week 1 discussion patient confidentiality
Week 1 discussion  patient confidentialityWeek 1 discussion  patient confidentiality
Week 1 discussion patient confidentialityapalaciosy
 

Similar to Week 1 discussion 2 (20)

Week 1 dq 2 - confidentiality1
Week 1   dq 2 - confidentiality1Week 1   dq 2 - confidentiality1
Week 1 dq 2 - confidentiality1
 
Week 1 dq 2 - confidentiality1
Week 1   dq 2 - confidentiality1Week 1   dq 2 - confidentiality1
Week 1 dq 2 - confidentiality1
 
Week 1 dq 2 - confidentiality1
Week 1   dq 2 - confidentiality1Week 1   dq 2 - confidentiality1
Week 1 dq 2 - confidentiality1
 
Week 1 dq 2 - confidentiality1
Week 1   dq 2 - confidentiality1Week 1   dq 2 - confidentiality1
Week 1 dq 2 - confidentiality1
 
HIPAA Basics
HIPAA BasicsHIPAA Basics
HIPAA Basics
 
Marc etienne week1 discussion2 presentation
Marc etienne week1 discussion2 presentationMarc etienne week1 discussion2 presentation
Marc etienne week1 discussion2 presentation
 
Week 1 dq 2 - confidentiality1
Week 1   dq 2 - confidentiality1Week 1   dq 2 - confidentiality1
Week 1 dq 2 - confidentiality1
 
Week 1 dq 2 - confidentiality1
Week 1   dq 2 - confidentiality1Week 1   dq 2 - confidentiality1
Week 1 dq 2 - confidentiality1
 
Mha690 health care capstone - confidentiality 9-26-2013
Mha690   health care capstone - confidentiality 9-26-2013Mha690   health care capstone - confidentiality 9-26-2013
Mha690 health care capstone - confidentiality 9-26-2013
 
Mha690 health care capstone - confidentiality 9-26-2013
Mha690   health care capstone - confidentiality 9-26-2013Mha690   health care capstone - confidentiality 9-26-2013
Mha690 health care capstone - confidentiality 9-26-2013
 
Mha690 health care capstone - confidentiality 9-26-2013
Mha690   health care capstone - confidentiality 9-26-2013Mha690   health care capstone - confidentiality 9-26-2013
Mha690 health care capstone - confidentiality 9-26-2013
 
Confidentiality
ConfidentialityConfidentiality
Confidentiality
 
Sylvia hipaa powerpoint presentation 2010(2)
Sylvia hipaa powerpoint presentation 2010(2)Sylvia hipaa powerpoint presentation 2010(2)
Sylvia hipaa powerpoint presentation 2010(2)
 
Hipaa overview2011 student orientation
Hipaa overview2011 student orientationHipaa overview2011 student orientation
Hipaa overview2011 student orientation
 
Sylvia hipaa powerpoint presentation 2010(1)
Sylvia hipaa powerpoint presentation 2010(1)Sylvia hipaa powerpoint presentation 2010(1)
Sylvia hipaa powerpoint presentation 2010(1)
 
Mha690 wk 1 fletcher
Mha690 wk 1   fletcherMha690 wk 1   fletcher
Mha690 wk 1 fletcher
 
Discussion2
Discussion2 Discussion2
Discussion2
 
Confidentiality
ConfidentialityConfidentiality
Confidentiality
 
Dustin HIPAA
Dustin HIPAADustin HIPAA
Dustin HIPAA
 
Week 1 discussion patient confidentiality
Week 1 discussion  patient confidentialityWeek 1 discussion  patient confidentiality
Week 1 discussion patient confidentiality
 

Week 1 discussion 2

  • 1. Privacy and Security Awareness Training Jessica Quesada Health Care Capstone , MHA 690 Doctor David Cole July 24, 2014
  • 2. Privacy and Security Awareness Training Contents  Employees Roles of Keeping Patients’ PHI Secured  HIPAA Privacy Rule  PHI Violations and Breach  Recommendations if PHI is Suspected  Conclusions
  • 3. Privacy and Security Awareness Training Awareness and training are important keys to educate UCLA Hospital employees on how to safeguard patients’ Protected Health Information (PHI) and reduce the incidence of security breaches in their healthcare organization. It is vital to describe that PHI is information associated to the patient’s health care such as patient’s name, address, date of birth, phone number, social security number and medical health records.
  • 4. Privacy and Security Awareness Training Therefore, all employees that handle sensitive and confidential information should be trained on the policies and procedures with respect to the protection of this information and they should learn their responsibilities to protect the privacy of patients annually.
  • 5. Privacy and Security Awareness Training Employees’ roles of keeping Patients’ PHI secured Employees need to understand the importance of the use and disclose of PHI as it is related to their job because patient information is confidential. Employees are not allowed to share this information with others on duty or off duty. In fact, employees are responsible of safeguarding and protecting sensitive and confidential information by unauthorized personnel.
  • 6. Privacy and Security Awareness Training HIPAA Privacy Rule Health Insurance Portability and Accountability (HIPAA) Privacy Rule ensures federal protection for the privacy of patients’ records and health information from covered entities such as health plans, health care providers, health care and clearinghouses.
  • 7. Privacy and Security Awareness Training HIPAA Privacy Rule The Privacy Rule standards address the use and disclosure of patients’ PHI by these covered entities and provide strong legal protection to ensure confidentiality and privacy of electronic protected health records. HIPAA Privacy Rule ensures that patients’ health information is protected by users while health care services are provided (New York State, 2012).
  • 8. Privacy and Security Awareness Training PHI violations and Breach Examples Sometimes, PHI violations might not be identified as incidents that cause significant harm to patients; hence employees need to recognize potential violation of the Privacy Rule and report them immediately. For instance, PHI is sent to wrong recipient via email, PHI is in lost laptops or flash drives, unauthorized personnel access patient’s information using other coworker’s passwords, a physician is discussing about patient’s medical records to others on a public area.
  • 9. Privacy and Security Awareness Training PHI violations and Breach Examples Another example is when an outreach letter with sensitive information is sent to the wrong patient or patient’s medical records are found in public areas such as cafeteria or bathroom. If employees violate the privacy and security policies that support the HIPAA regulations, they might face disciplinary action or employment termination (UPMC Horizon, 2012).
  • 10. Privacy and Security Awareness Training Recommendations if PHI is suspected Employees need to access PHI only if their job requires, therefore employees must report to their supervisors or compliance officer if they observe any potential threats that might compromise PHI.
  • 11. Privacy and Security Awareness Training Recommendations if PHI is suspected Employees should never discuss patients’ information to those who have no right to know about them. Another important recommendation is to avoid discussing about PHI in public areas and never repeat what is heard. Please keep drawers, desks and doors locked in station where PHI is found. It is highly recommended that employees protect their passwords and log off if computers will be unattended because it represents a significant threat to the hospital and patients.
  • 12. Privacy and Security Awareness Training Conclusion Privacy and security awareness training can answer many questions and concerns that employees might experience in daily basis. It is vital to keep employees informed and educated of their legal and ethical obligations and security restriction in the event of a PHI breach; thus they need to keep aware of any changes that can help them comply with regulations and policies that safeguard PHI. Indeed, different examples were shared to visualize different situations that might prevent employees from violating privacy policies and receive sanctions that might lead to employment termination.
  • 13. References Health Insurance Portability and Accountability Act (HIPAA). (2012). New York State. Retrieved from https://www.omh.ny.gov/omhweb/hipaa/ HIPAA Privacy & Security Awareness Training for Students. (2010). UPMC Horizon. Retrieved from http://www.upmc.com/locations/hospitals/horizon/career s/documents/hippa-training.pdf