SlideShare a Scribd company logo
1 of 15
HIPAA & HITECH
HIPAA
• Has been a federal privacy regulation since 2003.
Covers privacy and security of health information.
• Reviewed in annual education
• Taught in new employee orientation
• The facility Security Officer is Michael Boudreaux
• The facility Privacy Officer is Alane Bryan
HITECH
• Does not replace HIPAA—it gives it TEETH!
• Requires a breach notification policy
• Encourages EHR adoption
• Provides strict data protection regulations for
more secure patient privacy
New Fines as of March 26, 2013
Violation Type Each Violation Repeat Violations/Yr.
Did not know $100 - $50,000 $1.5 million
Reasonable Cause $1,000 - $50,000 $1.5 million
Willful Neglect – Corrected $10,000 - $50,000 $1.5 million
Willful Neglect – Not Corrected $50,000 $1.5 million
•Healthcare organizations or providers may be held liable for
violations.
•Individual employees may be prosecuted or may be sued for
civil penalties.
Breach Notifications
 Must notify individuals and HHS and, in some cases the media, of any
substantiated breaches within 60 days.
 Breaches affecting 500 or more patients will be posted to the
HHS.gov website.
 Four factors are used to determine if there is low to high probability of
PHI compromise:
1. The nature and extent of the PHI involved in the incident
• Is the PHI sensitive information i.e. Security numbers, or infectious disease test
results
1. The unauthorized recipient of the PHI
• Is another physician receiving the PHI?
1. Whether the PHI was actually acquired or viewed
2. The extent to which the risk to the PHI has been mitigated
• Was it immediately destroyed?
Documented Breaches
• Mass General
• California Breaches
• BCBS of TN Breach
• Individual Prosecution
• Personal Gain
Top Privacy Violations
• Stolen laptops/computers
• Lost CDs
• ID theft/Social Security Numbers
• Medicare Fraud
• Access to EMR with no job-related need
Privacy Breach Examples
• Using Social Networking to talk about patients
• Discussing PHI with employees or family who
do not have a job-related need
• Looking at EMR out of concern or curiosity
• Telling others that a patient was “in” for
treatment
• Discussing progress or prognosis in front of
family without permission
More Privacy Breach Examples
• Using chart to get information to use against
patient in lawsuit or divorce
• Looking in minor child’s EMR
• Taking a peek for “educational purposes”
• Starting conversations with “Don’t tell anyone
I told you this, but…”
• Sharing computer access/passwords
Permitted HIPAA Exceptions
• Treatment, Payment, Operations
• Some law enforcement exceptions
• Public health reporting
• When in doubt, get a Signed Release
• Disclose “minimal necessary” amount of PHI
HIPAA, HITECH, & YOU
• Patients/family members requesting patient
information AFTER DISCHARGE should be
referred to the HIM Department
• If a patient requests information during an
admission, make sure the report is FINAL before
giving the information to the patient or to their
designee (document the designee). We do not
release information unless it is in a FINAL status.
• Discuss patient information as quietly as possible
HIPAA, HITECH, & YOU
• Try not to say the patient’s name repeatedly
• Make sure paper containing PHI makes it to a shred bin
• Shred bins should be dumped in large bins each day
• Use fax cover sheets with the confidentiality clause
• Do not leave messages with too much information
• Wear your employee ID badge at all times
• Do not take pictures in patient care areas. Patients , their
names, or their family members may be visible without
you realizing it. It is not worth the risk!!
HIPAA, HITECH, & YOU
• Use workstations for intended purposes
– No gaming, no unauthorized downloading of files,
personal emails are subject to access by P&S
Surgical Hospital
• Log-off or lock your computer when you are
not using it
• Make sure others cannot view your computer
screen
HIPAA, HITECH, & YOU
• Keep passwords secure
• Use your own individual password
• Avoid sharing passwords
• Trigger encryption for emails containing PHI
being sent outside the organization
• If photos must be taken of a patient, use a
P&S camera or device; NEVER use your
personal camera or smart phone
HIPAA, HITECH, & YOU
• Never share proprietary or confidential
information in blogs or on social media sites
• Report potential breaches, inappropriate
disclosures, or otherwise suspect behavior to
your direct supervisor, the Privacy Officer, the
Security Officer, or the Corporate Compliance
Officer

More Related Content

What's hot

Confidentiality slide
Confidentiality slideConfidentiality slide
Confidentiality slidewongy12
 
Patient confidentiality MHA 690
Patient confidentiality MHA 690Patient confidentiality MHA 690
Patient confidentiality MHA 690AMSIMM9932
 
Confidentiality training
Confidentiality trainingConfidentiality training
Confidentiality trainingSherin_26
 
Confidentiality
ConfidentialityConfidentiality
ConfidentialityDeniseMHA
 
Confidentiality in Healthcare
Confidentiality in HealthcareConfidentiality in Healthcare
Confidentiality in Healthcarekmasterson
 
Patient confidentiality training
Patient confidentiality  trainingPatient confidentiality  training
Patient confidentiality trainingtwhit0623
 
Confidentiality in the Workplace
Confidentiality in the WorkplaceConfidentiality in the Workplace
Confidentiality in the Workplacesalvarez63
 
TaylorWk1d2assignment
TaylorWk1d2assignmentTaylorWk1d2assignment
TaylorWk1d2assignmentmya1743
 
Protecting patient privacy and confidentiality
Protecting patient privacy and confidentialityProtecting patient privacy and confidentiality
Protecting patient privacy and confidentialityTiffany Cochran
 
Privacy and confidentiality
Privacy and confidentialityPrivacy and confidentiality
Privacy and confidentialityjohnzinn
 

What's hot (13)

Confidentiality slide
Confidentiality slideConfidentiality slide
Confidentiality slide
 
Patient confidentiality MHA 690
Patient confidentiality MHA 690Patient confidentiality MHA 690
Patient confidentiality MHA 690
 
Confidentiality training
Confidentiality trainingConfidentiality training
Confidentiality training
 
Confidentiality
ConfidentialityConfidentiality
Confidentiality
 
Confidentiality in Healthcare
Confidentiality in HealthcareConfidentiality in Healthcare
Confidentiality in Healthcare
 
Patient confidentiality training
Patient confidentiality  trainingPatient confidentiality  training
Patient confidentiality training
 
Confidentiality in the Workplace
Confidentiality in the WorkplaceConfidentiality in the Workplace
Confidentiality in the Workplace
 
Confidentiality
ConfidentialityConfidentiality
Confidentiality
 
Confidentiality
Confidentiality Confidentiality
Confidentiality
 
Hipaa training
Hipaa trainingHipaa training
Hipaa training
 
TaylorWk1d2assignment
TaylorWk1d2assignmentTaylorWk1d2assignment
TaylorWk1d2assignment
 
Protecting patient privacy and confidentiality
Protecting patient privacy and confidentialityProtecting patient privacy and confidentiality
Protecting patient privacy and confidentiality
 
Privacy and confidentiality
Privacy and confidentialityPrivacy and confidentiality
Privacy and confidentiality
 

Similar to Annual HIPAA Education

Are You HIPAA Safe?
Are You HIPAA Safe?Are You HIPAA Safe?
Are You HIPAA Safe?TriageLogic
 
Hipaa basics.pp2
Hipaa basics.pp2Hipaa basics.pp2
Hipaa basics.pp2martykoepke
 
Welcome to the hippa, privacy and security
Welcome to the hippa, privacy and securityWelcome to the hippa, privacy and security
Welcome to the hippa, privacy and securityveve1728
 
Hipaa101 training2020
Hipaa101 training2020Hipaa101 training2020
Hipaa101 training2020VicHaight
 
HIPAA and Privacy Training
HIPAA and Privacy TrainingHIPAA and Privacy Training
HIPAA and Privacy TrainingJasAmataga
 
Rems hipaa
Rems hipaaRems hipaa
Rems hipaadhexel
 
Patient confidentiality.ppt
Patient confidentiality.pptPatient confidentiality.ppt
Patient confidentiality.pptchwiso8418
 
Hippa health admin week 1 question 2
Hippa health admin week 1 question 2Hippa health admin week 1 question 2
Hippa health admin week 1 question 2Ashford Univeristy
 
William schuch week 1 mha690 capstone ppp
William schuch week 1 mha690 capstone pppWilliam schuch week 1 mha690 capstone ppp
William schuch week 1 mha690 capstone pppWilliam Schuch
 
Hcc_hipaa hitech training_Basic www.hcctecnologies.com
Hcc_hipaa hitech training_Basic www.hcctecnologies.comHcc_hipaa hitech training_Basic www.hcctecnologies.com
Hcc_hipaa hitech training_Basic www.hcctecnologies.comejazmazhar
 
PROTECTED HEALTH INFORMATION_PATIENT PRIVACY
PROTECTED HEALTH INFORMATION_PATIENT PRIVACYPROTECTED HEALTH INFORMATION_PATIENT PRIVACY
PROTECTED HEALTH INFORMATION_PATIENT PRIVACYDenise Masella
 
Hipaa training new_staff_december 2018 - compatibility mode
Hipaa training new_staff_december 2018  -  compatibility modeHipaa training new_staff_december 2018  -  compatibility mode
Hipaa training new_staff_december 2018 - compatibility moderobint2125
 
Medical Ethics: Principles of medical ethics, patient rights, confidentiality...
Medical Ethics: Principles of medical ethics, patient rights, confidentiality...Medical Ethics: Principles of medical ethics, patient rights, confidentiality...
Medical Ethics: Principles of medical ethics, patient rights, confidentiality...emdadhussain840
 
Patient confidentiality power point
Patient confidentiality power pointPatient confidentiality power point
Patient confidentiality power pointchwiso8418
 

Similar to Annual HIPAA Education (20)

Are You HIPAA Safe?
Are You HIPAA Safe?Are You HIPAA Safe?
Are You HIPAA Safe?
 
Hipaa basics.pp2
Hipaa basics.pp2Hipaa basics.pp2
Hipaa basics.pp2
 
5 hipaa training
5 hipaa training5 hipaa training
5 hipaa training
 
Welcome to the hippa, privacy and security
Welcome to the hippa, privacy and securityWelcome to the hippa, privacy and security
Welcome to the hippa, privacy and security
 
5 hipaa training
5 hipaa training5 hipaa training
5 hipaa training
 
Hipaa 2012
Hipaa 2012Hipaa 2012
Hipaa 2012
 
Hippa 2021
Hippa 2021Hippa 2021
Hippa 2021
 
Hipaa101 training2020
Hipaa101 training2020Hipaa101 training2020
Hipaa101 training2020
 
HIPAA and Privacy Training
HIPAA and Privacy TrainingHIPAA and Privacy Training
HIPAA and Privacy Training
 
Rems hipaa
Rems hipaaRems hipaa
Rems hipaa
 
Patient confidentiality.ppt
Patient confidentiality.pptPatient confidentiality.ppt
Patient confidentiality.ppt
 
Hippa health admin week 1 question 2
Hippa health admin week 1 question 2Hippa health admin week 1 question 2
Hippa health admin week 1 question 2
 
William schuch week 1 mha690 capstone ppp
William schuch week 1 mha690 capstone pppWilliam schuch week 1 mha690 capstone ppp
William schuch week 1 mha690 capstone ppp
 
Dustin HIPAA
Dustin HIPAADustin HIPAA
Dustin HIPAA
 
Hcc_hipaa hitech training_Basic www.hcctecnologies.com
Hcc_hipaa hitech training_Basic www.hcctecnologies.comHcc_hipaa hitech training_Basic www.hcctecnologies.com
Hcc_hipaa hitech training_Basic www.hcctecnologies.com
 
Phi masella
Phi masellaPhi masella
Phi masella
 
PROTECTED HEALTH INFORMATION_PATIENT PRIVACY
PROTECTED HEALTH INFORMATION_PATIENT PRIVACYPROTECTED HEALTH INFORMATION_PATIENT PRIVACY
PROTECTED HEALTH INFORMATION_PATIENT PRIVACY
 
Hipaa training new_staff_december 2018 - compatibility mode
Hipaa training new_staff_december 2018  -  compatibility modeHipaa training new_staff_december 2018  -  compatibility mode
Hipaa training new_staff_december 2018 - compatibility mode
 
Medical Ethics: Principles of medical ethics, patient rights, confidentiality...
Medical Ethics: Principles of medical ethics, patient rights, confidentiality...Medical Ethics: Principles of medical ethics, patient rights, confidentiality...
Medical Ethics: Principles of medical ethics, patient rights, confidentiality...
 
Patient confidentiality power point
Patient confidentiality power pointPatient confidentiality power point
Patient confidentiality power point
 

More from DirkRhodes

Patient Satisfaction
Patient SatisfactionPatient Satisfaction
Patient SatisfactionDirkRhodes
 
Corporate compliance annual update
Corporate compliance annual updateCorporate compliance annual update
Corporate compliance annual updateDirkRhodes
 
Quality management education
Quality management educationQuality management education
Quality management educationDirkRhodes
 
Hospital safety education
Hospital safety educationHospital safety education
Hospital safety educationDirkRhodes
 
Infection Control
Infection ControlInfection Control
Infection ControlDirkRhodes
 
Quality Management Education
Quality Management EducationQuality Management Education
Quality Management EducationDirkRhodes
 
Cultural sensitivity bariatric patients
Cultural sensitivity bariatric patientsCultural sensitivity bariatric patients
Cultural sensitivity bariatric patientsDirkRhodes
 
Hospital Safety Education
Hospital Safety EducationHospital Safety Education
Hospital Safety EducationDirkRhodes
 

More from DirkRhodes (10)

Abuse
AbuseAbuse
Abuse
 
Patient Satisfaction
Patient SatisfactionPatient Satisfaction
Patient Satisfaction
 
Corporate compliance annual update
Corporate compliance annual updateCorporate compliance annual update
Corporate compliance annual update
 
Quality management education
Quality management educationQuality management education
Quality management education
 
Hospital safety education
Hospital safety educationHospital safety education
Hospital safety education
 
Abuse
AbuseAbuse
Abuse
 
Infection Control
Infection ControlInfection Control
Infection Control
 
Quality Management Education
Quality Management EducationQuality Management Education
Quality Management Education
 
Cultural sensitivity bariatric patients
Cultural sensitivity bariatric patientsCultural sensitivity bariatric patients
Cultural sensitivity bariatric patients
 
Hospital Safety Education
Hospital Safety EducationHospital Safety Education
Hospital Safety Education
 

Recently uploaded

_Math 4-Q4 Week 5.pptx Steps in Collecting Data
_Math 4-Q4 Week 5.pptx Steps in Collecting Data_Math 4-Q4 Week 5.pptx Steps in Collecting Data
_Math 4-Q4 Week 5.pptx Steps in Collecting DataJhengPantaleon
 
Introduction to AI in Higher Education_draft.pptx
Introduction to AI in Higher Education_draft.pptxIntroduction to AI in Higher Education_draft.pptx
Introduction to AI in Higher Education_draft.pptxpboyjonauth
 
microwave assisted reaction. General introduction
microwave assisted reaction. General introductionmicrowave assisted reaction. General introduction
microwave assisted reaction. General introductionMaksud Ahmed
 
PSYCHIATRIC History collection FORMAT.pptx
PSYCHIATRIC   History collection FORMAT.pptxPSYCHIATRIC   History collection FORMAT.pptx
PSYCHIATRIC History collection FORMAT.pptxPoojaSen20
 
Alper Gobel In Media Res Media Component
Alper Gobel In Media Res Media ComponentAlper Gobel In Media Res Media Component
Alper Gobel In Media Res Media ComponentInMediaRes1
 
Introduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher EducationIntroduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher Educationpboyjonauth
 
How to Make a Pirate ship Primary Education.pptx
How to Make a Pirate ship Primary Education.pptxHow to Make a Pirate ship Primary Education.pptx
How to Make a Pirate ship Primary Education.pptxmanuelaromero2013
 
Separation of Lanthanides/ Lanthanides and Actinides
Separation of Lanthanides/ Lanthanides and ActinidesSeparation of Lanthanides/ Lanthanides and Actinides
Separation of Lanthanides/ Lanthanides and ActinidesFatimaKhan178732
 
POINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptx
POINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptxPOINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptx
POINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptxSayali Powar
 
Paris 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activityParis 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activityGeoBlogs
 
The basics of sentences session 2pptx copy.pptx
The basics of sentences session 2pptx copy.pptxThe basics of sentences session 2pptx copy.pptx
The basics of sentences session 2pptx copy.pptxheathfieldcps1
 
APM Welcome, APM North West Network Conference, Synergies Across Sectors
APM Welcome, APM North West Network Conference, Synergies Across SectorsAPM Welcome, APM North West Network Conference, Synergies Across Sectors
APM Welcome, APM North West Network Conference, Synergies Across SectorsAssociation for Project Management
 
Solving Puzzles Benefits Everyone (English).pptx
Solving Puzzles Benefits Everyone (English).pptxSolving Puzzles Benefits Everyone (English).pptx
Solving Puzzles Benefits Everyone (English).pptxOH TEIK BIN
 
Call Girls in Dwarka Mor Delhi Contact Us 9654467111
Call Girls in Dwarka Mor Delhi Contact Us 9654467111Call Girls in Dwarka Mor Delhi Contact Us 9654467111
Call Girls in Dwarka Mor Delhi Contact Us 9654467111Sapana Sha
 
Industrial Policy - 1948, 1956, 1973, 1977, 1980, 1991
Industrial Policy - 1948, 1956, 1973, 1977, 1980, 1991Industrial Policy - 1948, 1956, 1973, 1977, 1980, 1991
Industrial Policy - 1948, 1956, 1973, 1977, 1980, 1991RKavithamani
 
Grant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingGrant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingTechSoup
 
Concept of Vouching. B.Com(Hons) /B.Compdf
Concept of Vouching. B.Com(Hons) /B.CompdfConcept of Vouching. B.Com(Hons) /B.Compdf
Concept of Vouching. B.Com(Hons) /B.CompdfUmakantAnnand
 
Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3JemimahLaneBuaron
 

Recently uploaded (20)

_Math 4-Q4 Week 5.pptx Steps in Collecting Data
_Math 4-Q4 Week 5.pptx Steps in Collecting Data_Math 4-Q4 Week 5.pptx Steps in Collecting Data
_Math 4-Q4 Week 5.pptx Steps in Collecting Data
 
Introduction to AI in Higher Education_draft.pptx
Introduction to AI in Higher Education_draft.pptxIntroduction to AI in Higher Education_draft.pptx
Introduction to AI in Higher Education_draft.pptx
 
microwave assisted reaction. General introduction
microwave assisted reaction. General introductionmicrowave assisted reaction. General introduction
microwave assisted reaction. General introduction
 
PSYCHIATRIC History collection FORMAT.pptx
PSYCHIATRIC   History collection FORMAT.pptxPSYCHIATRIC   History collection FORMAT.pptx
PSYCHIATRIC History collection FORMAT.pptx
 
Código Creativo y Arte de Software | Unidad 1
Código Creativo y Arte de Software | Unidad 1Código Creativo y Arte de Software | Unidad 1
Código Creativo y Arte de Software | Unidad 1
 
Alper Gobel In Media Res Media Component
Alper Gobel In Media Res Media ComponentAlper Gobel In Media Res Media Component
Alper Gobel In Media Res Media Component
 
Introduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher EducationIntroduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher Education
 
How to Make a Pirate ship Primary Education.pptx
How to Make a Pirate ship Primary Education.pptxHow to Make a Pirate ship Primary Education.pptx
How to Make a Pirate ship Primary Education.pptx
 
Separation of Lanthanides/ Lanthanides and Actinides
Separation of Lanthanides/ Lanthanides and ActinidesSeparation of Lanthanides/ Lanthanides and Actinides
Separation of Lanthanides/ Lanthanides and Actinides
 
POINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptx
POINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptxPOINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptx
POINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptx
 
Paris 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activityParis 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activity
 
The basics of sentences session 2pptx copy.pptx
The basics of sentences session 2pptx copy.pptxThe basics of sentences session 2pptx copy.pptx
The basics of sentences session 2pptx copy.pptx
 
APM Welcome, APM North West Network Conference, Synergies Across Sectors
APM Welcome, APM North West Network Conference, Synergies Across SectorsAPM Welcome, APM North West Network Conference, Synergies Across Sectors
APM Welcome, APM North West Network Conference, Synergies Across Sectors
 
Model Call Girl in Bikash Puri Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in Bikash Puri  Delhi reach out to us at 🔝9953056974🔝Model Call Girl in Bikash Puri  Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in Bikash Puri Delhi reach out to us at 🔝9953056974🔝
 
Solving Puzzles Benefits Everyone (English).pptx
Solving Puzzles Benefits Everyone (English).pptxSolving Puzzles Benefits Everyone (English).pptx
Solving Puzzles Benefits Everyone (English).pptx
 
Call Girls in Dwarka Mor Delhi Contact Us 9654467111
Call Girls in Dwarka Mor Delhi Contact Us 9654467111Call Girls in Dwarka Mor Delhi Contact Us 9654467111
Call Girls in Dwarka Mor Delhi Contact Us 9654467111
 
Industrial Policy - 1948, 1956, 1973, 1977, 1980, 1991
Industrial Policy - 1948, 1956, 1973, 1977, 1980, 1991Industrial Policy - 1948, 1956, 1973, 1977, 1980, 1991
Industrial Policy - 1948, 1956, 1973, 1977, 1980, 1991
 
Grant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingGrant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy Consulting
 
Concept of Vouching. B.Com(Hons) /B.Compdf
Concept of Vouching. B.Com(Hons) /B.CompdfConcept of Vouching. B.Com(Hons) /B.Compdf
Concept of Vouching. B.Com(Hons) /B.Compdf
 
Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3
 

Annual HIPAA Education

  • 2. HIPAA • Has been a federal privacy regulation since 2003. Covers privacy and security of health information. • Reviewed in annual education • Taught in new employee orientation • The facility Security Officer is Michael Boudreaux • The facility Privacy Officer is Alane Bryan
  • 3. HITECH • Does not replace HIPAA—it gives it TEETH! • Requires a breach notification policy • Encourages EHR adoption • Provides strict data protection regulations for more secure patient privacy
  • 4. New Fines as of March 26, 2013 Violation Type Each Violation Repeat Violations/Yr. Did not know $100 - $50,000 $1.5 million Reasonable Cause $1,000 - $50,000 $1.5 million Willful Neglect – Corrected $10,000 - $50,000 $1.5 million Willful Neglect – Not Corrected $50,000 $1.5 million •Healthcare organizations or providers may be held liable for violations. •Individual employees may be prosecuted or may be sued for civil penalties.
  • 5. Breach Notifications  Must notify individuals and HHS and, in some cases the media, of any substantiated breaches within 60 days.  Breaches affecting 500 or more patients will be posted to the HHS.gov website.  Four factors are used to determine if there is low to high probability of PHI compromise: 1. The nature and extent of the PHI involved in the incident • Is the PHI sensitive information i.e. Security numbers, or infectious disease test results 1. The unauthorized recipient of the PHI • Is another physician receiving the PHI? 1. Whether the PHI was actually acquired or viewed 2. The extent to which the risk to the PHI has been mitigated • Was it immediately destroyed?
  • 6. Documented Breaches • Mass General • California Breaches • BCBS of TN Breach • Individual Prosecution • Personal Gain
  • 7. Top Privacy Violations • Stolen laptops/computers • Lost CDs • ID theft/Social Security Numbers • Medicare Fraud • Access to EMR with no job-related need
  • 8. Privacy Breach Examples • Using Social Networking to talk about patients • Discussing PHI with employees or family who do not have a job-related need • Looking at EMR out of concern or curiosity • Telling others that a patient was “in” for treatment • Discussing progress or prognosis in front of family without permission
  • 9. More Privacy Breach Examples • Using chart to get information to use against patient in lawsuit or divorce • Looking in minor child’s EMR • Taking a peek for “educational purposes” • Starting conversations with “Don’t tell anyone I told you this, but…” • Sharing computer access/passwords
  • 10. Permitted HIPAA Exceptions • Treatment, Payment, Operations • Some law enforcement exceptions • Public health reporting • When in doubt, get a Signed Release • Disclose “minimal necessary” amount of PHI
  • 11. HIPAA, HITECH, & YOU • Patients/family members requesting patient information AFTER DISCHARGE should be referred to the HIM Department • If a patient requests information during an admission, make sure the report is FINAL before giving the information to the patient or to their designee (document the designee). We do not release information unless it is in a FINAL status. • Discuss patient information as quietly as possible
  • 12. HIPAA, HITECH, & YOU • Try not to say the patient’s name repeatedly • Make sure paper containing PHI makes it to a shred bin • Shred bins should be dumped in large bins each day • Use fax cover sheets with the confidentiality clause • Do not leave messages with too much information • Wear your employee ID badge at all times • Do not take pictures in patient care areas. Patients , their names, or their family members may be visible without you realizing it. It is not worth the risk!!
  • 13. HIPAA, HITECH, & YOU • Use workstations for intended purposes – No gaming, no unauthorized downloading of files, personal emails are subject to access by P&S Surgical Hospital • Log-off or lock your computer when you are not using it • Make sure others cannot view your computer screen
  • 14. HIPAA, HITECH, & YOU • Keep passwords secure • Use your own individual password • Avoid sharing passwords • Trigger encryption for emails containing PHI being sent outside the organization • If photos must be taken of a patient, use a P&S camera or device; NEVER use your personal camera or smart phone
  • 15. HIPAA, HITECH, & YOU • Never share proprietary or confidential information in blogs or on social media sites • Report potential breaches, inappropriate disclosures, or otherwise suspect behavior to your direct supervisor, the Privacy Officer, the Security Officer, or the Corporate Compliance Officer