SlideShare a Scribd company logo
1 of 16
HIPAA and
42CFR Part 2
HIPAA
 Health Insurance Portability and
Accountability Act
•
• Federal Law, enacted 1996
• National standards for security of health data
• Administrative Guidelines Privacy, Security &
Standard Transactions
 Health Information Technology for Economic
and Clinical Health Act (HITECH)
 Included in the American Recovery and
Reinvestment Act (ARRA) of 2009
 Omnibus Rule (2013)
Important Definitions
Covered Entity
A Covered Entity is a
healthcare delivery
option that includes
doctors, clinics,
hospitals, dentists,
nursing homes and
pharmacies that
transmit data, health
plan and healthcare
clearinghouses
Business Associate
A Business Associate is
any person or
organization that
functions on behalf of a
covered entity that
involves use or
disclosure of
identifiable health
information. Examples
include billing and
coding vendors
What is Protected Health
Information (PHI)?
 Name
 Address
 Dates directly related to
patient
 Telephone number
 Fax Number
 Email addresses
 Social Security Number
 Medical Record Number
 Health Plan Beneficiary
Number
 Account Number
 Certification/License
Number
 Any vehicle license
number
 Any device serial number
 Web URL, IP address
 Finger or voice prints
 Photographic images
 Any other unique number,
characteristic or code
 Age greater than 89
PHI Details
What information is
Protected?
All Medical Records and
Other Individually
Identifiable Health
Information (PHI) Used
or Disclosed by a
Covered Entity in any
Form; Electronic, on
Paper or Orally
What is Included?
Individually Identifiable
Information that was
provided by the client,
created by you, created
by another and
forwarded to you and
forwarded to you for
payment, treatment or
healthcare operations.
Covered Entities Permitted Uses
and Disclosures
 A CE is permitted, but not required, to use and
disclose PHI without an authorization, for the
following purposes:
◦ To the individual
◦ Treatment, Payment and Health Care
Operations (TPO)
◦ Opportunity to Agree (having someone in the
room during the session)
◦ Incident to an otherwise permitted use
◦ Limited Data Set for purposes of research,
public health or health care operations
Privacy Rules
 The goal of the HIPAA Privacy Rule is to
properly protect individual’s health
information and to use PHI appropriately
while protecting the privacy of people who
seek care and healing
42 CFR Part 2
42 CFR Part 2
 42 CFR Part 2 (commonly referred to as "Part 2")
are the federal regulations governing the
confidentiality of drug and alcohol abuse
treatment and prevention records.
 Privacy protections afforded to alcohol and drug
abuse patient records
 Motivated by the understanding that stigma and
fear of prosecution might dissuade persons from
seeking treatment
Who is Covered?
 42 CFR Part 2 applies to any individual or
entity that is federally assisted and
provides alcohol or drug abuse treatment
or referral for treatment (42 CFR § 2.11)
 Includes funding, treatment provided and
clinical licenses that are at the federal
level (DEA license)
Regulations
 Restrict the disclosure and use of alcohol
and drug client records
 Any information disclosed by a covered
program that “would identify a patient as
an alcohol or drug abuser” (42 CFR
§2.12(a) (1)
 With limited exceptions, 42 CFR Part 2
requires client consent for disclosures of
PHI even for the purposes of TPO.
Consent must be in writing
US Government Publishing Office
 Includes the electronic codes of federal
regulations
 Introduction, General Provisions, Disclosures
with Patient Consent, Disclosures without
Patient Consent, Court Orders Authorizing
Disclosure and Use
 http://www.ecfr.gov/cgi-bin/text-
idx?rgn=div5;node=42%3A1.0.1.1.2
 42 CFR Changes coming
 https://www.federalregister.gov/articles/2016
/02/09/2016-01841/confidentiality-of-
substance-use-disorder-patient-records
Written Consent
 The primary way in which patient substance
abuse information may be disclosed is with a
patient’s written consent. Substance abuse
programs and providers must give patients a
written summary of the federal laws and
regulations that protect the confidentiality of
patient substance abuse records and a
description of the circumstances when the
patient’s information may be disclosed without
his/her consent.
Consent Forms
 For all other disclosures,
consent must be obtained
using a written consent
form. A single consent form
may authorize disclosure to
multiple parties or for
multiple purposes.
 Consent forms must contain
specific elements (see right
column)
 Patient Name
 Agency making disclosure
 agency name of the person or
agency to which disclosure is
made
 nature and amount of
information to be disclosed
(minimum necessary),
 purpose of the disclosure (as
specific as possible),
 effective and expiration dates
and event or condition upon
which the consent expires
 language explaining the consent
process and may include a
statement about possible denial
of services if not signed for
purposes of treatment, payment
or healthcare operations
 and signatures of client,
authorized representative and
description of authority to sign
on the client’s behalf
Exceptions-Always work with
Privacy Officers
 Program
Communications
 To communicate with
Qualified Service
Organizations (QSO)
◦ Similar to other covered
entities or business
associates
 Medical Emergencies
 Response to a crime
against program
personnel or on
program premises
 Research activities
(approved by IRB)
 Audit and Evaluation
 Report suspected
child abuse or neglect
 Circumstances
involving certain
minors or
incompetent patients
 Response to a valid
court order
 Cause of death
HIPAA and 42 CFR Part 2
 Substance use programs must comply
with both HIPAA 45 CFR and 42 CFR Part
2
 If there is a conflict, the more stringent
rule applies
 HIPAA/42CFR comparison

More Related Content

What's hot

National Patient Safety Goals by UMass Memorial Health Care
National Patient Safety Goals by UMass Memorial Health CareNational Patient Safety Goals by UMass Memorial Health Care
National Patient Safety Goals by UMass Memorial Health CareAtlantic Training, LLC.
 
Advance directive01
Advance directive01Advance directive01
Advance directive01Kelly Snyder
 
Lecture 17 ethical issues in medical reports, sick-leaves & medical rec...
Lecture 17   ethical issues in medical reports, sick-leaves & medical rec...Lecture 17   ethical issues in medical reports, sick-leaves & medical rec...
Lecture 17 ethical issues in medical reports, sick-leaves & medical rec...Dr Ghaiath Hussein
 
legal issue in nursing.
legal issue in nursing.legal issue in nursing.
legal issue in nursing.Ujjwal Sharma
 
L20 Financial issues in healthcare: Ethical and Legal Issues
L20 Financial issues in healthcare: Ethical and Legal IssuesL20 Financial issues in healthcare: Ethical and Legal Issues
L20 Financial issues in healthcare: Ethical and Legal IssuesDr Ghaiath Hussein
 
Records Management Principles for Community Health
Records Management Principles for Community HealthRecords Management Principles for Community Health
Records Management Principles for Community Healthnstanzer
 
3.principles of ethics in medical practice in ethiopia
3.principles of ethics in medical practice in ethiopia3.principles of ethics in medical practice in ethiopia
3.principles of ethics in medical practice in ethiopiaMesfin Tafa
 
Rights of the rights of psychiatric patients
Rights of the rights of psychiatric patientsRights of the rights of psychiatric patients
Rights of the rights of psychiatric patientsPooja Dhimaan
 
Medical Negligence (ভুল চিকিৎসায় রোগীর মৃত্যু)
Medical Negligence (ভুল চিকিৎসায় রোগীর মৃত্যু)Medical Negligence (ভুল চিকিৎসায় রোগীর মৃত্যু)
Medical Negligence (ভুল চিকিৎসায় রোগীর মৃত্যু)drmainuddin
 
Leave against medical advice
Leave against medical adviceLeave against medical advice
Leave against medical adviceAhmad Thanin
 
Consent & confidentiality
Consent & confidentialityConsent & confidentiality
Consent & confidentialityAhmed Elaghoury
 
h_Plain-English-Version-Code-of-Conduct
h_Plain-English-Version-Code-of-Conducth_Plain-English-Version-Code-of-Conduct
h_Plain-English-Version-Code-of-ConductJenny Hall
 
Acc chapter presentation for JCI awarness week
Acc chapter presentation for JCI awarness weekAcc chapter presentation for JCI awarness week
Acc chapter presentation for JCI awarness weekDralaa Holiel , Ph.D
 
LITIGATION RISKS ASSOCIATED WITH HOSPITALIZATION
LITIGATION RISKS ASSOCIATED WITH HOSPITALIZATIONLITIGATION RISKS ASSOCIATED WITH HOSPITALIZATION
LITIGATION RISKS ASSOCIATED WITH HOSPITALIZATIONAnnette Kasera
 
Indian medical council (professional conduct, etiquette and ethics) regulatio...
Indian medical council (professional conduct, etiquette and ethics) regulatio...Indian medical council (professional conduct, etiquette and ethics) regulatio...
Indian medical council (professional conduct, etiquette and ethics) regulatio...sebis1
 
Lecture 18 Medical Errors: Ethical, professional and Legal Aspects
Lecture 18 Medical Errors: Ethical, professional and Legal AspectsLecture 18 Medical Errors: Ethical, professional and Legal Aspects
Lecture 18 Medical Errors: Ethical, professional and Legal AspectsDr Ghaiath Hussein
 
Legal ethical issues & MLC
Legal ethical issues & MLCLegal ethical issues & MLC
Legal ethical issues & MLCHarpreet Kaur
 

What's hot (20)

National Patient Safety Goals by UMass Memorial Health Care
National Patient Safety Goals by UMass Memorial Health CareNational Patient Safety Goals by UMass Memorial Health Care
National Patient Safety Goals by UMass Memorial Health Care
 
Hand off communication
Hand off communicationHand off communication
Hand off communication
 
Advance directive01
Advance directive01Advance directive01
Advance directive01
 
Lecture 17 ethical issues in medical reports, sick-leaves & medical rec...
Lecture 17   ethical issues in medical reports, sick-leaves & medical rec...Lecture 17   ethical issues in medical reports, sick-leaves & medical rec...
Lecture 17 ethical issues in medical reports, sick-leaves & medical rec...
 
legal issue in nursing.
legal issue in nursing.legal issue in nursing.
legal issue in nursing.
 
L20 Financial issues in healthcare: Ethical and Legal Issues
L20 Financial issues in healthcare: Ethical and Legal IssuesL20 Financial issues in healthcare: Ethical and Legal Issues
L20 Financial issues in healthcare: Ethical and Legal Issues
 
Records Management Principles for Community Health
Records Management Principles for Community HealthRecords Management Principles for Community Health
Records Management Principles for Community Health
 
3.principles of ethics in medical practice in ethiopia
3.principles of ethics in medical practice in ethiopia3.principles of ethics in medical practice in ethiopia
3.principles of ethics in medical practice in ethiopia
 
Rights of the rights of psychiatric patients
Rights of the rights of psychiatric patientsRights of the rights of psychiatric patients
Rights of the rights of psychiatric patients
 
Medical Negligence (ভুল চিকিৎসায় রোগীর মৃত্যু)
Medical Negligence (ভুল চিকিৎসায় রোগীর মৃত্যু)Medical Negligence (ভুল চিকিৎসায় রোগীর মৃত্যু)
Medical Negligence (ভুল চিকিৎসায় রোগীর মৃত্যু)
 
Confidentiality
ConfidentialityConfidentiality
Confidentiality
 
Leave against medical advice
Leave against medical adviceLeave against medical advice
Leave against medical advice
 
Consent & confidentiality
Consent & confidentialityConsent & confidentiality
Consent & confidentiality
 
Medical records ppt
Medical records pptMedical records ppt
Medical records ppt
 
h_Plain-English-Version-Code-of-Conduct
h_Plain-English-Version-Code-of-Conducth_Plain-English-Version-Code-of-Conduct
h_Plain-English-Version-Code-of-Conduct
 
Acc chapter presentation for JCI awarness week
Acc chapter presentation for JCI awarness weekAcc chapter presentation for JCI awarness week
Acc chapter presentation for JCI awarness week
 
LITIGATION RISKS ASSOCIATED WITH HOSPITALIZATION
LITIGATION RISKS ASSOCIATED WITH HOSPITALIZATIONLITIGATION RISKS ASSOCIATED WITH HOSPITALIZATION
LITIGATION RISKS ASSOCIATED WITH HOSPITALIZATION
 
Indian medical council (professional conduct, etiquette and ethics) regulatio...
Indian medical council (professional conduct, etiquette and ethics) regulatio...Indian medical council (professional conduct, etiquette and ethics) regulatio...
Indian medical council (professional conduct, etiquette and ethics) regulatio...
 
Lecture 18 Medical Errors: Ethical, professional and Legal Aspects
Lecture 18 Medical Errors: Ethical, professional and Legal AspectsLecture 18 Medical Errors: Ethical, professional and Legal Aspects
Lecture 18 Medical Errors: Ethical, professional and Legal Aspects
 
Legal ethical issues & MLC
Legal ethical issues & MLCLegal ethical issues & MLC
Legal ethical issues & MLC
 

Similar to Hipaa 42 cfr review

HIPAA Privacy Training by University of Hawaii
HIPAA Privacy Training by University of HawaiiHIPAA Privacy Training by University of Hawaii
HIPAA Privacy Training by University of HawaiiAtlantic Training, LLC.
 
HIPAA and RHIOs
HIPAA and RHIOsHIPAA and RHIOs
HIPAA and RHIOsnobumoto
 
Week 1 discussion 2 hipaa and privacy training
Week 1 discussion 2 hipaa and privacy trainingWeek 1 discussion 2 hipaa and privacy training
Week 1 discussion 2 hipaa and privacy trainingvrgill22
 
Knowing confidentiality
Knowing confidentialityKnowing confidentiality
Knowing confidentialityjessie66
 
Confidentiality & privacy
Confidentiality & privacyConfidentiality & privacy
Confidentiality & privacykendale
 
Confidentiality & privacy
Confidentiality & privacyConfidentiality & privacy
Confidentiality & privacykendale
 
Introduction to HIPAA for Healthcare Professionals by OUP
Introduction to HIPAA for Healthcare Professionals by OUPIntroduction to HIPAA for Healthcare Professionals by OUP
Introduction to HIPAA for Healthcare Professionals by OUPAtlantic Training, LLC.
 
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)Sanjeev Bharwan
 
Patient confidentiality
Patient confidentialityPatient confidentiality
Patient confidentialitypraisehim1
 
Patient confidentiality
Patient confidentialityPatient confidentiality
Patient confidentialitypraisehim1
 
Patient confidentiality
Patient confidentialityPatient confidentiality
Patient confidentialitypraisehim1
 
Patient confidentiality
Patient confidentialityPatient confidentiality
Patient confidentialitypraisehim1
 
Hippa and Confidentiality
Hippa and ConfidentialityHippa and Confidentiality
Hippa and Confidentialityramonapage
 

Similar to Hipaa 42 cfr review (20)

HIPAA Privacy Training by University of Hawaii
HIPAA Privacy Training by University of HawaiiHIPAA Privacy Training by University of Hawaii
HIPAA Privacy Training by University of Hawaii
 
HIPAA and RHIOs
HIPAA and RHIOsHIPAA and RHIOs
HIPAA and RHIOs
 
HIPAA Privacy & Security
HIPAA Privacy & SecurityHIPAA Privacy & Security
HIPAA Privacy & Security
 
Week 1 discussion 2 hipaa and privacy training
Week 1 discussion 2 hipaa and privacy trainingWeek 1 discussion 2 hipaa and privacy training
Week 1 discussion 2 hipaa and privacy training
 
Knowing confidentiality
Knowing confidentialityKnowing confidentiality
Knowing confidentiality
 
Chapter 3: Ethics
Chapter 3: EthicsChapter 3: Ethics
Chapter 3: Ethics
 
HIPAA Complaince
HIPAA ComplainceHIPAA Complaince
HIPAA Complaince
 
Hippa training v2
Hippa training v2Hippa training v2
Hippa training v2
 
Confidentiality & privacy
Confidentiality & privacyConfidentiality & privacy
Confidentiality & privacy
 
Confidentiality & privacy
Confidentiality & privacyConfidentiality & privacy
Confidentiality & privacy
 
Introduction to HIPAA for Healthcare Professionals by OUP
Introduction to HIPAA for Healthcare Professionals by OUPIntroduction to HIPAA for Healthcare Professionals by OUP
Introduction to HIPAA for Healthcare Professionals by OUP
 
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)
 
HIPAA
HIPAAHIPAA
HIPAA
 
Patient confidentiality
Patient confidentialityPatient confidentiality
Patient confidentiality
 
Patient confidentiality
Patient confidentialityPatient confidentiality
Patient confidentiality
 
Patient confidentiality
Patient confidentialityPatient confidentiality
Patient confidentiality
 
Patient confidentiality
Patient confidentialityPatient confidentiality
Patient confidentiality
 
HIPAA Glossary
HIPAA GlossaryHIPAA Glossary
HIPAA Glossary
 
Hippa and Confidentiality
Hippa and ConfidentialityHippa and Confidentiality
Hippa and Confidentiality
 
Hippa
HippaHippa
Hippa
 

Recently uploaded

Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Sheetaleventcompany
 
Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024Marel
 
Famous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st CenturyFamous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st Centuryrwgiffor
 
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...rajveerescorts2022
 
Falcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon investment
 
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai KuwaitThe Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwaitdaisycvs
 
Malegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Malegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort ServiceMalegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Malegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort ServiceDamini Dixit
 
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...amitlee9823
 
Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876
Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876
Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876dlhescort
 
Phases of Negotiation .pptx
 Phases of Negotiation .pptx Phases of Negotiation .pptx
Phases of Negotiation .pptxnandhinijagan9867
 
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...Anamikakaur10
 
How to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityHow to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityEric T. Tung
 
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...lizamodels9
 
Value Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsValue Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsP&CO
 
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service NoidaCall Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service Noidadlhescort
 
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756dollysharma2066
 
Eluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort Service
Eluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort ServiceEluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort Service
Eluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort ServiceDamini Dixit
 
Business Model Canvas (BMC)- A new venture concept
Business Model Canvas (BMC)-  A new venture conceptBusiness Model Canvas (BMC)-  A new venture concept
Business Model Canvas (BMC)- A new venture conceptP&CO
 
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfDr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfAdmir Softic
 

Recently uploaded (20)

Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
 
Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024
 
Famous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st CenturyFamous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st Century
 
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
 
Falcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business Growth
 
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai KuwaitThe Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
 
Malegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Malegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort ServiceMalegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Malegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
 
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
 
Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876
Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876
Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876
 
Phases of Negotiation .pptx
 Phases of Negotiation .pptx Phases of Negotiation .pptx
Phases of Negotiation .pptx
 
(Anamika) VIP Call Girls Napur Call Now 8617697112 Napur Escorts 24x7
(Anamika) VIP Call Girls Napur Call Now 8617697112 Napur Escorts 24x7(Anamika) VIP Call Girls Napur Call Now 8617697112 Napur Escorts 24x7
(Anamika) VIP Call Girls Napur Call Now 8617697112 Napur Escorts 24x7
 
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
 
How to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityHow to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League City
 
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
 
Value Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsValue Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and pains
 
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service NoidaCall Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
 
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
 
Eluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort Service
Eluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort ServiceEluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort Service
Eluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort Service
 
Business Model Canvas (BMC)- A new venture concept
Business Model Canvas (BMC)-  A new venture conceptBusiness Model Canvas (BMC)-  A new venture concept
Business Model Canvas (BMC)- A new venture concept
 
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfDr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
 

Hipaa 42 cfr review

  • 2. HIPAA  Health Insurance Portability and Accountability Act • • Federal Law, enacted 1996 • National standards for security of health data • Administrative Guidelines Privacy, Security & Standard Transactions  Health Information Technology for Economic and Clinical Health Act (HITECH)  Included in the American Recovery and Reinvestment Act (ARRA) of 2009  Omnibus Rule (2013)
  • 3. Important Definitions Covered Entity A Covered Entity is a healthcare delivery option that includes doctors, clinics, hospitals, dentists, nursing homes and pharmacies that transmit data, health plan and healthcare clearinghouses Business Associate A Business Associate is any person or organization that functions on behalf of a covered entity that involves use or disclosure of identifiable health information. Examples include billing and coding vendors
  • 4. What is Protected Health Information (PHI)?  Name  Address  Dates directly related to patient  Telephone number  Fax Number  Email addresses  Social Security Number  Medical Record Number  Health Plan Beneficiary Number  Account Number  Certification/License Number  Any vehicle license number  Any device serial number  Web URL, IP address  Finger or voice prints  Photographic images  Any other unique number, characteristic or code  Age greater than 89
  • 5. PHI Details What information is Protected? All Medical Records and Other Individually Identifiable Health Information (PHI) Used or Disclosed by a Covered Entity in any Form; Electronic, on Paper or Orally What is Included? Individually Identifiable Information that was provided by the client, created by you, created by another and forwarded to you and forwarded to you for payment, treatment or healthcare operations.
  • 6. Covered Entities Permitted Uses and Disclosures  A CE is permitted, but not required, to use and disclose PHI without an authorization, for the following purposes: ◦ To the individual ◦ Treatment, Payment and Health Care Operations (TPO) ◦ Opportunity to Agree (having someone in the room during the session) ◦ Incident to an otherwise permitted use ◦ Limited Data Set for purposes of research, public health or health care operations
  • 7. Privacy Rules  The goal of the HIPAA Privacy Rule is to properly protect individual’s health information and to use PHI appropriately while protecting the privacy of people who seek care and healing
  • 9. 42 CFR Part 2  42 CFR Part 2 (commonly referred to as "Part 2") are the federal regulations governing the confidentiality of drug and alcohol abuse treatment and prevention records.  Privacy protections afforded to alcohol and drug abuse patient records  Motivated by the understanding that stigma and fear of prosecution might dissuade persons from seeking treatment
  • 10. Who is Covered?  42 CFR Part 2 applies to any individual or entity that is federally assisted and provides alcohol or drug abuse treatment or referral for treatment (42 CFR § 2.11)  Includes funding, treatment provided and clinical licenses that are at the federal level (DEA license)
  • 11. Regulations  Restrict the disclosure and use of alcohol and drug client records  Any information disclosed by a covered program that “would identify a patient as an alcohol or drug abuser” (42 CFR §2.12(a) (1)  With limited exceptions, 42 CFR Part 2 requires client consent for disclosures of PHI even for the purposes of TPO. Consent must be in writing
  • 12. US Government Publishing Office  Includes the electronic codes of federal regulations  Introduction, General Provisions, Disclosures with Patient Consent, Disclosures without Patient Consent, Court Orders Authorizing Disclosure and Use  http://www.ecfr.gov/cgi-bin/text- idx?rgn=div5;node=42%3A1.0.1.1.2  42 CFR Changes coming  https://www.federalregister.gov/articles/2016 /02/09/2016-01841/confidentiality-of- substance-use-disorder-patient-records
  • 13. Written Consent  The primary way in which patient substance abuse information may be disclosed is with a patient’s written consent. Substance abuse programs and providers must give patients a written summary of the federal laws and regulations that protect the confidentiality of patient substance abuse records and a description of the circumstances when the patient’s information may be disclosed without his/her consent.
  • 14. Consent Forms  For all other disclosures, consent must be obtained using a written consent form. A single consent form may authorize disclosure to multiple parties or for multiple purposes.  Consent forms must contain specific elements (see right column)  Patient Name  Agency making disclosure  agency name of the person or agency to which disclosure is made  nature and amount of information to be disclosed (minimum necessary),  purpose of the disclosure (as specific as possible),  effective and expiration dates and event or condition upon which the consent expires  language explaining the consent process and may include a statement about possible denial of services if not signed for purposes of treatment, payment or healthcare operations  and signatures of client, authorized representative and description of authority to sign on the client’s behalf
  • 15. Exceptions-Always work with Privacy Officers  Program Communications  To communicate with Qualified Service Organizations (QSO) ◦ Similar to other covered entities or business associates  Medical Emergencies  Response to a crime against program personnel or on program premises  Research activities (approved by IRB)  Audit and Evaluation  Report suspected child abuse or neglect  Circumstances involving certain minors or incompetent patients  Response to a valid court order  Cause of death
  • 16. HIPAA and 42 CFR Part 2  Substance use programs must comply with both HIPAA 45 CFR and 42 CFR Part 2  If there is a conflict, the more stringent rule applies  HIPAA/42CFR comparison

Editor's Notes

  1. Welcome to the HIPAA Compliance Overview for CIBHS class. This class will cover, at a high level, the basics of the HIPAA 45 CFR regulations as of January 2016, what you will need to do to meet compliance and future planning needs.
  2. HIPAA was enacted in 1996 to address the different standards noted in the slide. This class will cover the security and privacy sections of the law. HIPAA set a national standard for accessing and handling medical information. It was started by President Clinton, AKA the Kennedy Kassenbaum Act. Click on the orange bubble for more info on HITECH. 8/21/96 Included a number of titles but we are concerned with Title II, Administrative Simplification.
  3. We mentioned a Business Associate earlier in the class. That is one of the important definitions you will need to remember as you work on your compliance efforts. A Business Associate is a person or organization that functions on behalf of the covered entity. CIBHS is considered a Business Associate to our customers who are covered entities. A covered entity is a healthcare delivery option that includes doctors, clinics, hospitals, nursing homes and pharmacies that transmit data. Also includes health plans and healthcare clearinghouses (billing services, medical reviewers). Show BAA example.
  4. There are 18 types of identifiers that if used alone or in combination are considered PHI. Review the list and see if you are surprised by any item. The last item, Age greater than 89, relates to a possible identification of someone just based on their age. For example, Mr. Jones is 99 and receiving services at the local MH agency. The agency has an article in the local paper talking about their services and mentions their 99 y/o client who loves coming in for services. Mr. Jones is the only 99 y/o in the town. He could be identified and his privacy breached by that remark. Mr. Jones should have signed a release of information to allow his information to be used.
  5. All medical records and other individually identifiable health information used or disclosed by a CE in any form (electronic, paper and oral) is protected. You have to consider all of the information you have on the client; information that was provided by the client, created by you, created by another, forwarded to you for any reason including TPO.
  6. There are some instances where a covered entity is permitted to disclose PHI without an authorization. You can use and disclose PHI to the individual, for Treatment, Payment and Healthcare Operations (TPO), and other areas noted here that may or may not come up at your agency. The government understands you have to treat your client, work together with others at your agency and receive payment for services delivered without undue hardship. Remember that any other use or disclosure falls under privacy rules. Code of Federal Regulations. The Privacy Rule is located at 45 CFR Part 160 and Subparts A and E of Part 164.  Patients rights under HIPAA: To see their medical record Obtain a copy of their medical record Request amendments to their medical record Request disclosure restrictions Private Pay Certain other disclosures, including research and marketing To authorize disclosures To receive a Notice of Privacy Practices To have an accounting of disclosures (not TPO) Timely notification of any breaches Secure Communications Confidential communications when requested
  7. Privacy rules are more focused on the individual’s health information and how we protect it. The goal of the privacy rule is to properly protect the client’s health information and use PHI appropriately while protecting the privacy of people who seek care and healing. June 13, 2016 Obama Administration Temporarily Waives HIPAA:  But Did It Have To Be? In the aftermath of the shootings in Orlando late Saturday night, President Obama applied a unique waiver to HIPAA -- allowing family and friends of the victims to gain quicker access to information about their loved ones.  In most situations, information about an individual's condition would not be released to anyone but a spouse or next of kin absent a consent from the patient  In normal circumstances this is a valuable protection on an individual's privacy.  However, the situation this weekend was anything but normal. Family and friends were unable to obtain any information on the condition of their loved ones, and a consent was simply not possible in many circumstances. Section 1135 of the Social Security Act which was invoked allows healthcare providers flexibility in sharing protected health information ("PHI") with loved ones in emergency situations. The only other time this provision had been enacted was in the aftermath of Hurricane Katrina.  For this waiver to be applied the president must declare a national emergency and the secretary of the Department of Health and Human Services must declare a public health emergency.  Both of which were declared for Orlando on Sunday.  The waiver applying during an "emergency period" may be no more than 72 hours, which is how long this waiver is in effect.  This is also not a complete waiver of HIPAA, but only a temporary suspension on requiring patient consent before releasing PHI to loved ones who are not a spouse or next of kin.   There is a question whether Section 1135 had to be invoked.  The Office of Civil Rights has published opinions stating that health care providers can release PHI to loved ones if a person is incapacitated "if, in their professional judgment, doing so is in the patient's best interest."  Arguably that would be the end of the discussion.  However, invoking Section 1135 unequivocally insulated health care providers from even the potential of fines or sanctions for non-compliance.  Absolutely necessary or not, temporarily waiving limited portions of HIPAA  allowed providers to focus on the important tasks at hand rather than worrying about potential HIPAA violations.  
  8. Now we’ll discuss 42 CFR. You are aware of these regulations if you work in a substance abuse program. These regulations were developed to reduce stigma while receiving substance abuse treatment and to help address the privacy concerns client’s may have.
  9. Read slide
  10. Rules first enacted between 1972-75. There have been a lot of changes since then. 42CFR includes some of the same rules as HIPAA but it is a separate federal law that is often more stringent than HIPAA.
  11. Read slide. Ask if they remember what TPO is.
  12. For your information, here is the link to the 42 CFR regulation.
  13. Must get a written consent-read slide
  14. Lots of content on this slide, but the consent form is very prescribed and MUST include these data elements.
  15. Read slide
  16. Both HIPAA (45 CFR) and 42 CFR Part 2 are about client privacy. The most stringent rule will apply. Here is a reference to a comparison between HIPAA and 42 CFR. In most cases, 42 CFR will be followed. There are some HIPAA requirements for form language that also must be met. Click link to show comparison chart.