What Every Healthcare
Worker Needs to Know
About HIPAA and Privacy
What is HIPAA?
โ€ข Health Insurance Portability and Accountability
Act (HIPAA) is broad federal legislation that
includes rules to protect the privacy and confidentiality
of patient information.
โ€ข Does not replace existing confidentiality laws
โ€ข Establishes a minimum requirement
Protected Health
Information
โ€ข HIPAA regulates the use and disclosure of what is
known as protected health information or โ€œPHI.โ€
โ€ข PHI is any information that can be used to identify
the past, present, or future healthcare of an individual
or the payment for that care.
Protected Health
Information
This is virtually all information about a patient,
whether written on paper, saved on a computer, or
spoken aloud. This includes their:
โ€ข Name
โ€ข Address
โ€ข Age
โ€ข Social Security number
โ€ข Other personal information
โ€ข License plate numbers
โ€ข Fax machine numbers
HIPAA Confidentiality
HIPAA privacy also protects the following:
โ€ข The reason the patient is sick or in the hospital
โ€ข The treatments and medication he or she receives
โ€ข Caregiversโ€™notes
โ€ข Information about past health conditions
Use of Protected Health
Information
โ€ข In general, a healthcare provider can access and use
PHI without specific patient authorization, if it is to
be used for treatment, payment, or healthcare
operations (TPO).
โ€ข Before looking at a patientโ€™s health information,
ask yourself, โ€œDo I need to know this to do my
job?โ€
Use of Protected Health
Information
A healthcare provider can also disclose PHI without
patient authorization as follows:
โ€ข As required by law
โ€ข Public Health Activities
โ€ข Law Enforcement
โ€ข Other national priorities - funeral directors, organ
donation, research, prevent a disaster, special
government functions, workers compensation
Use of Protected Health
Information
โ€ข Minimum Necessary Standard โ€“ Always use or
disclose only the Minimum amount of information
necessary to honor the request
โ€ข If you are not sure whether you should disclose any
form of PHI, ASK your supervisor, department
compliance representative or the compliance officer
โ€ข Once the disclosure is made itโ€™s too late to get it
back.
What Every
Healthcare Worker
Needs to Know About
HIPAA Security
Use of Electronic Protected Health
Information(ePHI)
49
โ€ข HIPAA security rules apply only to ePHI stored,
maintained or transmitted in an electronic format
โ€ข ePHI is the same information as PHI; it is anything
that could identify the patient, their medical
condition or method of payment
โ€ข Security rules require additional compliance
50
โ€ข Workforce members cannot use their computers or
access to review personal or family PHI.
โ€ข If you use a laptop, flash drive, PDA or other
storage media, it is your responsibility to:
โ€“ Obtain approval before transferring ePHI to a portable
device
โ€“ It is your responsibility to protect ALL ePHI from theft
both electronic and physical
Use of Electronic Protected
Health Information (ePHI)
Use of Electronic Protected
Health Information (ePHI)
51
โ€ข Monitor the use of cellular phones
โ€“ information and images (ePHI) can be sent over Internet.
This ePHI is not encrypted
โ€ข It is not allowed to send ePHI over the text message
โ€ข Use E-mail and Internet access appropriately
โ€“ workforce members should remember that e-mails sent to or
from work computers are not considered private. Your
employer may audit e-mail and Internet usage
Use of Electronic Protected
Health Information (ePHI)
โ€ข HIPAA and PHI says that you should not disclose anything
more specific than the State in which they live
โ€ข You may send PHI, ePHI in emails if you are using your
work assigned email, but DO NOT place sensitive
information such as patient name in the Subject field
because the subject field is not encrypted when it
travels over the internet.
52
What Does HIPAA
Mean To Me?
53
โ€ข Our patients have a right to expect we will keep their information
confidential. This information includes anything that could identify
Or be used to find out the identity of the patient or their medical
condition.
โ€ข As employees, volunteers, and physicians, we come in contact
with many forms of patient information. We need to understand
what are acceptable uses of this information.
โ€ข Follow the โ€œneed to knowโ€ rule. Ask yourself โ€œdo I need to see
patient information to perform my jobโ€. If the answer is โ€œYesโ€, you
have nothing to worry about. If the answer is โ€œnoโ€, STOP.
What Does This All Mean
To Me?
โ€ข The cafeteria, the elevator or any of the social media sites are notthe
place to discuss the medical condition or other aspects of a patientโ€™s
care.
โ€ข Information you have access to must not be the subject of
conversation with family, friends or neighbors.
โ€ข The minimum necessary standard needs to be applied to all
disclosures except for treatment purposes, disclosures to the
patient or as required by law.
What Does This All Mean
To Me?
โ€ข Never send ePHI to anyone unless you have verified who will
receive the information and how the information will be used.
If it doesnโ€™t seem right to you, it probably isnโ€™t.
โ€ข Remember follow the โ€œneed to knowโ€ rule. Ask yourself โ€œdo I
need to see patient information to perform my jobโ€.
If the answer is โ€œYesโ€, you have nothing to worry about.
If the answer is โ€œnoโ€, STOP.
โ€ข Use e-mail and Internet services in the proper manner.
What Does This All Mean
To Me?
โ€ข Always protect your password. NEVER give your password or
sign-on to anyone.If you think your password or sign-on has
been compromised, notify the Administrator immediately.
โ€ข Violations can also result in personal civil penalties of up to
$25,000 per person and criminal penalties of up to $250,000
and/or 10 years in prison.
โ€ข Violations of confidentiality and privacy policies can result in
disciplinary action up to and including discharge.
What Does This All Mean
To Me?
โ€ข If you know of any violation of our existing
confidentiality policies or the Privacy Policy, it is your
obligation to bring the violation to the attention of your
supervisor, Administrator, or Compliance Officer.
Compliance is the responsibility
of every employee!

5 hipaa training

  • 1.
    What Every Healthcare WorkerNeeds to Know About HIPAA and Privacy
  • 2.
    What is HIPAA? โ€ขHealth Insurance Portability and Accountability Act (HIPAA) is broad federal legislation that includes rules to protect the privacy and confidentiality of patient information. โ€ข Does not replace existing confidentiality laws โ€ข Establishes a minimum requirement
  • 3.
    Protected Health Information โ€ข HIPAAregulates the use and disclosure of what is known as protected health information or โ€œPHI.โ€ โ€ข PHI is any information that can be used to identify the past, present, or future healthcare of an individual or the payment for that care.
  • 4.
    Protected Health Information This isvirtually all information about a patient, whether written on paper, saved on a computer, or spoken aloud. This includes their: โ€ข Name โ€ข Address โ€ข Age โ€ข Social Security number โ€ข Other personal information โ€ข License plate numbers โ€ข Fax machine numbers
  • 5.
    HIPAA Confidentiality HIPAA privacyalso protects the following: โ€ข The reason the patient is sick or in the hospital โ€ข The treatments and medication he or she receives โ€ข Caregiversโ€™notes โ€ข Information about past health conditions
  • 6.
    Use of ProtectedHealth Information โ€ข In general, a healthcare provider can access and use PHI without specific patient authorization, if it is to be used for treatment, payment, or healthcare operations (TPO). โ€ข Before looking at a patientโ€™s health information, ask yourself, โ€œDo I need to know this to do my job?โ€
  • 7.
    Use of ProtectedHealth Information A healthcare provider can also disclose PHI without patient authorization as follows: โ€ข As required by law โ€ข Public Health Activities โ€ข Law Enforcement โ€ข Other national priorities - funeral directors, organ donation, research, prevent a disaster, special government functions, workers compensation
  • 8.
    Use of ProtectedHealth Information โ€ข Minimum Necessary Standard โ€“ Always use or disclose only the Minimum amount of information necessary to honor the request โ€ข If you are not sure whether you should disclose any form of PHI, ASK your supervisor, department compliance representative or the compliance officer โ€ข Once the disclosure is made itโ€™s too late to get it back.
  • 9.
    What Every Healthcare Worker Needsto Know About HIPAA Security
  • 10.
    Use of ElectronicProtected Health Information(ePHI) 49 โ€ข HIPAA security rules apply only to ePHI stored, maintained or transmitted in an electronic format โ€ข ePHI is the same information as PHI; it is anything that could identify the patient, their medical condition or method of payment โ€ข Security rules require additional compliance
  • 11.
    50 โ€ข Workforce memberscannot use their computers or access to review personal or family PHI. โ€ข If you use a laptop, flash drive, PDA or other storage media, it is your responsibility to: โ€“ Obtain approval before transferring ePHI to a portable device โ€“ It is your responsibility to protect ALL ePHI from theft both electronic and physical Use of Electronic Protected Health Information (ePHI)
  • 12.
    Use of ElectronicProtected Health Information (ePHI) 51 โ€ข Monitor the use of cellular phones โ€“ information and images (ePHI) can be sent over Internet. This ePHI is not encrypted โ€ข It is not allowed to send ePHI over the text message โ€ข Use E-mail and Internet access appropriately โ€“ workforce members should remember that e-mails sent to or from work computers are not considered private. Your employer may audit e-mail and Internet usage
  • 13.
    Use of ElectronicProtected Health Information (ePHI) โ€ข HIPAA and PHI says that you should not disclose anything more specific than the State in which they live โ€ข You may send PHI, ePHI in emails if you are using your work assigned email, but DO NOT place sensitive information such as patient name in the Subject field because the subject field is not encrypted when it travels over the internet. 52
  • 14.
    What Does HIPAA MeanTo Me? 53 โ€ข Our patients have a right to expect we will keep their information confidential. This information includes anything that could identify Or be used to find out the identity of the patient or their medical condition. โ€ข As employees, volunteers, and physicians, we come in contact with many forms of patient information. We need to understand what are acceptable uses of this information. โ€ข Follow the โ€œneed to knowโ€ rule. Ask yourself โ€œdo I need to see patient information to perform my jobโ€. If the answer is โ€œYesโ€, you have nothing to worry about. If the answer is โ€œnoโ€, STOP.
  • 15.
    What Does ThisAll Mean To Me? โ€ข The cafeteria, the elevator or any of the social media sites are notthe place to discuss the medical condition or other aspects of a patientโ€™s care. โ€ข Information you have access to must not be the subject of conversation with family, friends or neighbors. โ€ข The minimum necessary standard needs to be applied to all disclosures except for treatment purposes, disclosures to the patient or as required by law.
  • 16.
    What Does ThisAll Mean To Me? โ€ข Never send ePHI to anyone unless you have verified who will receive the information and how the information will be used. If it doesnโ€™t seem right to you, it probably isnโ€™t. โ€ข Remember follow the โ€œneed to knowโ€ rule. Ask yourself โ€œdo I need to see patient information to perform my jobโ€. If the answer is โ€œYesโ€, you have nothing to worry about. If the answer is โ€œnoโ€, STOP. โ€ข Use e-mail and Internet services in the proper manner.
  • 17.
    What Does ThisAll Mean To Me? โ€ข Always protect your password. NEVER give your password or sign-on to anyone.If you think your password or sign-on has been compromised, notify the Administrator immediately. โ€ข Violations can also result in personal civil penalties of up to $25,000 per person and criminal penalties of up to $250,000 and/or 10 years in prison. โ€ข Violations of confidentiality and privacy policies can result in disciplinary action up to and including discharge.
  • 18.
    What Does ThisAll Mean To Me? โ€ข If you know of any violation of our existing confidentiality policies or the Privacy Policy, it is your obligation to bring the violation to the attention of your supervisor, Administrator, or Compliance Officer. Compliance is the responsibility of every employee!