SlideShare a Scribd company logo
1
Louisiana Department of Health and Hospitals
Basic HIPAA Privacy Training: Policies and Procedures
01/09/2009
2
OBJECTIVES
 At the end of this session, the participants will be
able to:
 Define and explain the HIPAA
 Identify which information is governed by the HIPAA rule
 Define Protected Health Information (PHI)
 Explain verification requirements
 Explain rules governing obtaining permission to disclose
PHI
 Discuss the employee’s role if they are aware of a HIPAA
violation
3
What Is HIPAA?
 HIPAA (pronounced hippa) is a federal law.
 It’s a set of rules and regulations that affect the
health care industry.
 They focus on the privacy and security of health
care information.
 Health care providers must comply, as HIPAA
covers:
 Health Plans
 Health Care Providers
4
What Does The Privacy Rule Say?
 Sets rules for how private information can be used.
 Keeps clients/participants more informed.
 Limits access by others.
 Requires client/participant permission.
 Allows access by clients/participants.
 Requires that rules be followed.
 Increases safeguards.
 Enforces penalties.
5
 Information about health care or payment for health
care, such as:
 Why a person is visiting the clinic or center;
 The type of treatment a person is receiving; or
 The fact that a person is receiving Medicaid.
 That:
 Identifies the person; or
 Could possibly identify the person.
 Examples of of such information include a
client/participant’s name, address, social security
number, medical record number, or photograph.
Individually Identifiable Health Information
6
Protected Health Information (PHI)
 PHI is all individually identifiable health
information in any form:
 Paper
 Verbal
 Electronic
 Exceptions:
 Employment records (including employees’ medical
information).
 Certain education records.
7
PHI
Computers File Cabinets Desks/Offices
 Protected Health Information can be stored in/on:
Disks/CDs Palm Pilots
8
 You are only allowed access to the minimum amount of
PHI necessary for you to perform your job duties.
 You must only disclose the minimum amount of PHI
necessary to satisfy a request.
 You must only request the minimum amount of PHI you
need at the time.
Minimum Necessary Requirements
9
 The minimum necessary rule does not apply to:
 Disclosures to, or requests by, a health care provider for
treatment;
 Uses or disclosures made to the client/participant;
 Uses or disclosures that the client authorized;
 Disclosure made to the Secretary of HHS; and
 Disclosures required by law.
Minimum Necessary – Not Applicable
10
 Prior to disclosing PHI, you must:
 Verify the identity of the person requesting PHI and the authority
of that person to have access to PHI; and
 When required, get some kind of proof from the person making
the request.
Verification Requirements
11
Permission To Use or Disclose PHI?
 Client/participant authorization is not needed
before you disclose his or her PHI for treatment,
payment, and/or health care operations (TPO) .
 For Abuse Reports and Investigations.
 Generally, however, you do need specific, written
authorization from the client/participant before you
can use or disclose his or her PHI for other reasons
(unless specifically permitted by the Privacy Rule).
12
 Treatment
 Payment
 Health Care Operations (Examples):
 Quality Assessment and Improvement;
 Medical Review and Auditing;
 Planning and Budget
TPO
13
THINGS TO THINK ABOUT
 Situations that often lead to violations of
confidentiality
 Discussing work with family and friends
 Informal discussions with colleagues
 Hallway, elevator, lunch break, grocery store
 Social gathering
 Office parties, etc
 Incoming phone calls
 Attentive repairman
14
Administrative Requirements
 Failure to comply with HIPAA is a violation of
federal law.
 You could even be fined and jailed if you break
the law.
15
If You See A Problem…
 If you see or hear about someone who is in violation
of HIPAA requirements and procedures, you should
tell your supervisor.
 All reports should be investigated.
16
Prohibition on Retaliatory Acts
 An employer is bound by law to protect a
workforce member from harassment or retaliatory
actions if he or she reports a suspected privacy
violation.
17
Crime Victims
 You are allowed to disclose PHI to law enforcement
without the client/participant’s authorization when:
 The PHI disclosed is about the person suspected of a
criminal act; and
 The PHI disclosed is limited to information relevant to
identifying the suspect and the nature of any injury.
18
Remember…
 If you are unsure about how to proceed
in a certain situation involving PHI, ask
your supervisor.
19
Remember…
 Do not discuss any PHI you see or hear while
performing your job with anyone unless necessary!
20
Remember…
 There are significant penalties for misuse of PHI.
21
THE END

More Related Content

Similar to CONFIDENTIALITYANDHIPAA.ppt

Data Security and Privacy Practices
Data Security and Privacy PracticesData Security and Privacy Practices
Data Security and Privacy Practices
Springfield Clinic
 
Dustin HIPAA
Dustin HIPAADustin HIPAA
Dustin HIPAA
Dustin Kinzinger
 
Health Insurance and Portability and Accountability Act
Health Insurance and Portability and Accountability ActHealth Insurance and Portability and Accountability Act
Health Insurance and Portability and Accountability Act
সারন দাস
 
HIPAA Privacy Training by University of Hawaii
HIPAA Privacy Training by University of HawaiiHIPAA Privacy Training by University of Hawaii
HIPAA Privacy Training by University of Hawaii
Atlantic Training, LLC.
 
HIPAA Workforce Training by Wayne-Holmes Mental Health Recovery Board
HIPAA Workforce Training by Wayne-Holmes Mental Health Recovery BoardHIPAA Workforce Training by Wayne-Holmes Mental Health Recovery Board
HIPAA Workforce Training by Wayne-Holmes Mental Health Recovery Board
Atlantic Training, LLC.
 
2018-HIPAA-Renewal-Training.pptx
2018-HIPAA-Renewal-Training.pptx2018-HIPAA-Renewal-Training.pptx
2018-HIPAA-Renewal-Training.pptx
Fariida Osman
 
Week 1 discussion 2 hipaa and privacy training
Week 1 discussion 2 hipaa and privacy trainingWeek 1 discussion 2 hipaa and privacy training
Week 1 discussion 2 hipaa and privacy training
vrgill22
 
Mha 690 week one discussion ii
Mha 690 week one discussion iiMha 690 week one discussion ii
Mha 690 week one discussion ii
beleza1669
 
Mha 690 week one discussion ii
Mha 690 week one discussion iiMha 690 week one discussion ii
Mha 690 week one discussion ii
beleza1669
 
Hipaa
HipaaHipaa
Annual HIPAA Training
Annual HIPAA TrainingAnnual HIPAA Training
Annual HIPAA Training
Cynthia Holland
 
Knowing confidentiality
Knowing confidentialityKnowing confidentiality
Knowing confidentiality
jessie66
 
HIPAA
HIPAAHIPAA
HIPAA
belziebub
 
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)
Sanjeev Bharwan
 
Basic HIPAA Training by CMU
Basic HIPAA Training by CMUBasic HIPAA Training by CMU
Basic HIPAA Training by CMU
Atlantic Training, LLC.
 
UNA HIPAA Training 8-13
UNA HIPAA Training   8-13UNA HIPAA Training   8-13
Notice of privacy rights
Notice of privacy rightsNotice of privacy rights
Notice of privacy rights
Heatherina
 
Notice of privacy rights
Notice of privacy rightsNotice of privacy rights
Notice of privacy rights
Heatherina
 
HIPAA, PHI, & 42 CFR Part 2
HIPAA, PHI, & 42 CFR Part 2HIPAA, PHI, & 42 CFR Part 2
HIPAA, PHI, & 42 CFR Part 2
Hatch Compliance, Inc.
 
This training program is designed to introduce staff
This training program is designed to introduce staffThis training program is designed to introduce staff
This training program is designed to introduce staff
sawanda
 

Similar to CONFIDENTIALITYANDHIPAA.ppt (20)

Data Security and Privacy Practices
Data Security and Privacy PracticesData Security and Privacy Practices
Data Security and Privacy Practices
 
Dustin HIPAA
Dustin HIPAADustin HIPAA
Dustin HIPAA
 
Health Insurance and Portability and Accountability Act
Health Insurance and Portability and Accountability ActHealth Insurance and Portability and Accountability Act
Health Insurance and Portability and Accountability Act
 
HIPAA Privacy Training by University of Hawaii
HIPAA Privacy Training by University of HawaiiHIPAA Privacy Training by University of Hawaii
HIPAA Privacy Training by University of Hawaii
 
HIPAA Workforce Training by Wayne-Holmes Mental Health Recovery Board
HIPAA Workforce Training by Wayne-Holmes Mental Health Recovery BoardHIPAA Workforce Training by Wayne-Holmes Mental Health Recovery Board
HIPAA Workforce Training by Wayne-Holmes Mental Health Recovery Board
 
2018-HIPAA-Renewal-Training.pptx
2018-HIPAA-Renewal-Training.pptx2018-HIPAA-Renewal-Training.pptx
2018-HIPAA-Renewal-Training.pptx
 
Week 1 discussion 2 hipaa and privacy training
Week 1 discussion 2 hipaa and privacy trainingWeek 1 discussion 2 hipaa and privacy training
Week 1 discussion 2 hipaa and privacy training
 
Mha 690 week one discussion ii
Mha 690 week one discussion iiMha 690 week one discussion ii
Mha 690 week one discussion ii
 
Mha 690 week one discussion ii
Mha 690 week one discussion iiMha 690 week one discussion ii
Mha 690 week one discussion ii
 
Hipaa
HipaaHipaa
Hipaa
 
Annual HIPAA Training
Annual HIPAA TrainingAnnual HIPAA Training
Annual HIPAA Training
 
Knowing confidentiality
Knowing confidentialityKnowing confidentiality
Knowing confidentiality
 
HIPAA
HIPAAHIPAA
HIPAA
 
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)
 
Basic HIPAA Training by CMU
Basic HIPAA Training by CMUBasic HIPAA Training by CMU
Basic HIPAA Training by CMU
 
UNA HIPAA Training 8-13
UNA HIPAA Training   8-13UNA HIPAA Training   8-13
UNA HIPAA Training 8-13
 
Notice of privacy rights
Notice of privacy rightsNotice of privacy rights
Notice of privacy rights
 
Notice of privacy rights
Notice of privacy rightsNotice of privacy rights
Notice of privacy rights
 
HIPAA, PHI, & 42 CFR Part 2
HIPAA, PHI, & 42 CFR Part 2HIPAA, PHI, & 42 CFR Part 2
HIPAA, PHI, & 42 CFR Part 2
 
This training program is designed to introduce staff
This training program is designed to introduce staffThis training program is designed to introduce staff
This training program is designed to introduce staff
 

Recently uploaded

一比一原版(BCU毕业证书)伯明翰城市大学毕业证如何办理
一比一原版(BCU毕业证书)伯明翰城市大学毕业证如何办理一比一原版(BCU毕业证书)伯明翰城市大学毕业证如何办理
一比一原版(BCU毕业证书)伯明翰城市大学毕业证如何办理
dwreak4tg
 
My burning issue is homelessness K.C.M.O.
My burning issue is homelessness K.C.M.O.My burning issue is homelessness K.C.M.O.
My burning issue is homelessness K.C.M.O.
rwarrenll
 
Learn SQL from basic queries to Advance queries
Learn SQL from basic queries to Advance queriesLearn SQL from basic queries to Advance queries
Learn SQL from basic queries to Advance queries
manishkhaire30
 
办(uts毕业证书)悉尼科技大学毕业证学历证书原版一模一样
办(uts毕业证书)悉尼科技大学毕业证学历证书原版一模一样办(uts毕业证书)悉尼科技大学毕业证学历证书原版一模一样
办(uts毕业证书)悉尼科技大学毕业证学历证书原版一模一样
apvysm8
 
一比一原版(UCSB文凭证书)圣芭芭拉分校毕业证如何办理
一比一原版(UCSB文凭证书)圣芭芭拉分校毕业证如何办理一比一原版(UCSB文凭证书)圣芭芭拉分校毕业证如何办理
一比一原版(UCSB文凭证书)圣芭芭拉分校毕业证如何办理
nuttdpt
 
原版制作(swinburne毕业证书)斯威本科技大学毕业证毕业完成信一模一样
原版制作(swinburne毕业证书)斯威本科技大学毕业证毕业完成信一模一样原版制作(swinburne毕业证书)斯威本科技大学毕业证毕业完成信一模一样
原版制作(swinburne毕业证书)斯威本科技大学毕业证毕业完成信一模一样
u86oixdj
 
一比一原版(UMN文凭证书)明尼苏达大学毕业证如何办理
一比一原版(UMN文凭证书)明尼苏达大学毕业证如何办理一比一原版(UMN文凭证书)明尼苏达大学毕业证如何办理
一比一原版(UMN文凭证书)明尼苏达大学毕业证如何办理
nyfuhyz
 
Influence of Marketing Strategy and Market Competition on Business Plan
Influence of Marketing Strategy and Market Competition on Business PlanInfluence of Marketing Strategy and Market Competition on Business Plan
Influence of Marketing Strategy and Market Competition on Business Plan
jerlynmaetalle
 
一比一原版(Harvard毕业证书)哈佛大学毕业证如何办理
一比一原版(Harvard毕业证书)哈佛大学毕业证如何办理一比一原版(Harvard毕业证书)哈佛大学毕业证如何办理
一比一原版(Harvard毕业证书)哈佛大学毕业证如何办理
zsjl4mimo
 
一比一原版(爱大毕业证书)爱丁堡大学毕业证如何办理
一比一原版(爱大毕业证书)爱丁堡大学毕业证如何办理一比一原版(爱大毕业证书)爱丁堡大学毕业证如何办理
一比一原版(爱大毕业证书)爱丁堡大学毕业证如何办理
g4dpvqap0
 
End-to-end pipeline agility - Berlin Buzzwords 2024
End-to-end pipeline agility - Berlin Buzzwords 2024End-to-end pipeline agility - Berlin Buzzwords 2024
End-to-end pipeline agility - Berlin Buzzwords 2024
Lars Albertsson
 
06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...
06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...
06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...
Timothy Spann
 
University of New South Wales degree offer diploma Transcript
University of New South Wales degree offer diploma TranscriptUniversity of New South Wales degree offer diploma Transcript
University of New South Wales degree offer diploma Transcript
soxrziqu
 
Natural Language Processing (NLP), RAG and its applications .pptx
Natural Language Processing (NLP), RAG and its applications .pptxNatural Language Processing (NLP), RAG and its applications .pptx
Natural Language Processing (NLP), RAG and its applications .pptx
fkyes25
 
06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...
06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...
06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...
Timothy Spann
 
一比一原版(Chester毕业证书)切斯特大学毕业证如何办理
一比一原版(Chester毕业证书)切斯特大学毕业证如何办理一比一原版(Chester毕业证书)切斯特大学毕业证如何办理
一比一原版(Chester毕业证书)切斯特大学毕业证如何办理
74nqk8xf
 
一比一原版(UofS毕业证书)萨省大学毕业证如何办理
一比一原版(UofS毕业证书)萨省大学毕业证如何办理一比一原版(UofS毕业证书)萨省大学毕业证如何办理
一比一原版(UofS毕业证书)萨省大学毕业证如何办理
v3tuleee
 
一比一原版(UO毕业证)渥太华大学毕业证如何办理
一比一原版(UO毕业证)渥太华大学毕业证如何办理一比一原版(UO毕业证)渥太华大学毕业证如何办理
一比一原版(UO毕业证)渥太华大学毕业证如何办理
aqzctr7x
 
Population Growth in Bataan: The effects of population growth around rural pl...
Population Growth in Bataan: The effects of population growth around rural pl...Population Growth in Bataan: The effects of population growth around rural pl...
Population Growth in Bataan: The effects of population growth around rural pl...
Bill641377
 
一比一原版(Adelaide毕业证书)阿德莱德大学毕业证如何办理
一比一原版(Adelaide毕业证书)阿德莱德大学毕业证如何办理一比一原版(Adelaide毕业证书)阿德莱德大学毕业证如何办理
一比一原版(Adelaide毕业证书)阿德莱德大学毕业证如何办理
slg6lamcq
 

Recently uploaded (20)

一比一原版(BCU毕业证书)伯明翰城市大学毕业证如何办理
一比一原版(BCU毕业证书)伯明翰城市大学毕业证如何办理一比一原版(BCU毕业证书)伯明翰城市大学毕业证如何办理
一比一原版(BCU毕业证书)伯明翰城市大学毕业证如何办理
 
My burning issue is homelessness K.C.M.O.
My burning issue is homelessness K.C.M.O.My burning issue is homelessness K.C.M.O.
My burning issue is homelessness K.C.M.O.
 
Learn SQL from basic queries to Advance queries
Learn SQL from basic queries to Advance queriesLearn SQL from basic queries to Advance queries
Learn SQL from basic queries to Advance queries
 
办(uts毕业证书)悉尼科技大学毕业证学历证书原版一模一样
办(uts毕业证书)悉尼科技大学毕业证学历证书原版一模一样办(uts毕业证书)悉尼科技大学毕业证学历证书原版一模一样
办(uts毕业证书)悉尼科技大学毕业证学历证书原版一模一样
 
一比一原版(UCSB文凭证书)圣芭芭拉分校毕业证如何办理
一比一原版(UCSB文凭证书)圣芭芭拉分校毕业证如何办理一比一原版(UCSB文凭证书)圣芭芭拉分校毕业证如何办理
一比一原版(UCSB文凭证书)圣芭芭拉分校毕业证如何办理
 
原版制作(swinburne毕业证书)斯威本科技大学毕业证毕业完成信一模一样
原版制作(swinburne毕业证书)斯威本科技大学毕业证毕业完成信一模一样原版制作(swinburne毕业证书)斯威本科技大学毕业证毕业完成信一模一样
原版制作(swinburne毕业证书)斯威本科技大学毕业证毕业完成信一模一样
 
一比一原版(UMN文凭证书)明尼苏达大学毕业证如何办理
一比一原版(UMN文凭证书)明尼苏达大学毕业证如何办理一比一原版(UMN文凭证书)明尼苏达大学毕业证如何办理
一比一原版(UMN文凭证书)明尼苏达大学毕业证如何办理
 
Influence of Marketing Strategy and Market Competition on Business Plan
Influence of Marketing Strategy and Market Competition on Business PlanInfluence of Marketing Strategy and Market Competition on Business Plan
Influence of Marketing Strategy and Market Competition on Business Plan
 
一比一原版(Harvard毕业证书)哈佛大学毕业证如何办理
一比一原版(Harvard毕业证书)哈佛大学毕业证如何办理一比一原版(Harvard毕业证书)哈佛大学毕业证如何办理
一比一原版(Harvard毕业证书)哈佛大学毕业证如何办理
 
一比一原版(爱大毕业证书)爱丁堡大学毕业证如何办理
一比一原版(爱大毕业证书)爱丁堡大学毕业证如何办理一比一原版(爱大毕业证书)爱丁堡大学毕业证如何办理
一比一原版(爱大毕业证书)爱丁堡大学毕业证如何办理
 
End-to-end pipeline agility - Berlin Buzzwords 2024
End-to-end pipeline agility - Berlin Buzzwords 2024End-to-end pipeline agility - Berlin Buzzwords 2024
End-to-end pipeline agility - Berlin Buzzwords 2024
 
06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...
06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...
06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...
 
University of New South Wales degree offer diploma Transcript
University of New South Wales degree offer diploma TranscriptUniversity of New South Wales degree offer diploma Transcript
University of New South Wales degree offer diploma Transcript
 
Natural Language Processing (NLP), RAG and its applications .pptx
Natural Language Processing (NLP), RAG and its applications .pptxNatural Language Processing (NLP), RAG and its applications .pptx
Natural Language Processing (NLP), RAG and its applications .pptx
 
06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...
06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...
06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...
 
一比一原版(Chester毕业证书)切斯特大学毕业证如何办理
一比一原版(Chester毕业证书)切斯特大学毕业证如何办理一比一原版(Chester毕业证书)切斯特大学毕业证如何办理
一比一原版(Chester毕业证书)切斯特大学毕业证如何办理
 
一比一原版(UofS毕业证书)萨省大学毕业证如何办理
一比一原版(UofS毕业证书)萨省大学毕业证如何办理一比一原版(UofS毕业证书)萨省大学毕业证如何办理
一比一原版(UofS毕业证书)萨省大学毕业证如何办理
 
一比一原版(UO毕业证)渥太华大学毕业证如何办理
一比一原版(UO毕业证)渥太华大学毕业证如何办理一比一原版(UO毕业证)渥太华大学毕业证如何办理
一比一原版(UO毕业证)渥太华大学毕业证如何办理
 
Population Growth in Bataan: The effects of population growth around rural pl...
Population Growth in Bataan: The effects of population growth around rural pl...Population Growth in Bataan: The effects of population growth around rural pl...
Population Growth in Bataan: The effects of population growth around rural pl...
 
一比一原版(Adelaide毕业证书)阿德莱德大学毕业证如何办理
一比一原版(Adelaide毕业证书)阿德莱德大学毕业证如何办理一比一原版(Adelaide毕业证书)阿德莱德大学毕业证如何办理
一比一原版(Adelaide毕业证书)阿德莱德大学毕业证如何办理
 

CONFIDENTIALITYANDHIPAA.ppt

  • 1. 1 Louisiana Department of Health and Hospitals Basic HIPAA Privacy Training: Policies and Procedures 01/09/2009
  • 2. 2 OBJECTIVES  At the end of this session, the participants will be able to:  Define and explain the HIPAA  Identify which information is governed by the HIPAA rule  Define Protected Health Information (PHI)  Explain verification requirements  Explain rules governing obtaining permission to disclose PHI  Discuss the employee’s role if they are aware of a HIPAA violation
  • 3. 3 What Is HIPAA?  HIPAA (pronounced hippa) is a federal law.  It’s a set of rules and regulations that affect the health care industry.  They focus on the privacy and security of health care information.  Health care providers must comply, as HIPAA covers:  Health Plans  Health Care Providers
  • 4. 4 What Does The Privacy Rule Say?  Sets rules for how private information can be used.  Keeps clients/participants more informed.  Limits access by others.  Requires client/participant permission.  Allows access by clients/participants.  Requires that rules be followed.  Increases safeguards.  Enforces penalties.
  • 5. 5  Information about health care or payment for health care, such as:  Why a person is visiting the clinic or center;  The type of treatment a person is receiving; or  The fact that a person is receiving Medicaid.  That:  Identifies the person; or  Could possibly identify the person.  Examples of of such information include a client/participant’s name, address, social security number, medical record number, or photograph. Individually Identifiable Health Information
  • 6. 6 Protected Health Information (PHI)  PHI is all individually identifiable health information in any form:  Paper  Verbal  Electronic  Exceptions:  Employment records (including employees’ medical information).  Certain education records.
  • 7. 7 PHI Computers File Cabinets Desks/Offices  Protected Health Information can be stored in/on: Disks/CDs Palm Pilots
  • 8. 8  You are only allowed access to the minimum amount of PHI necessary for you to perform your job duties.  You must only disclose the minimum amount of PHI necessary to satisfy a request.  You must only request the minimum amount of PHI you need at the time. Minimum Necessary Requirements
  • 9. 9  The minimum necessary rule does not apply to:  Disclosures to, or requests by, a health care provider for treatment;  Uses or disclosures made to the client/participant;  Uses or disclosures that the client authorized;  Disclosure made to the Secretary of HHS; and  Disclosures required by law. Minimum Necessary – Not Applicable
  • 10. 10  Prior to disclosing PHI, you must:  Verify the identity of the person requesting PHI and the authority of that person to have access to PHI; and  When required, get some kind of proof from the person making the request. Verification Requirements
  • 11. 11 Permission To Use or Disclose PHI?  Client/participant authorization is not needed before you disclose his or her PHI for treatment, payment, and/or health care operations (TPO) .  For Abuse Reports and Investigations.  Generally, however, you do need specific, written authorization from the client/participant before you can use or disclose his or her PHI for other reasons (unless specifically permitted by the Privacy Rule).
  • 12. 12  Treatment  Payment  Health Care Operations (Examples):  Quality Assessment and Improvement;  Medical Review and Auditing;  Planning and Budget TPO
  • 13. 13 THINGS TO THINK ABOUT  Situations that often lead to violations of confidentiality  Discussing work with family and friends  Informal discussions with colleagues  Hallway, elevator, lunch break, grocery store  Social gathering  Office parties, etc  Incoming phone calls  Attentive repairman
  • 14. 14 Administrative Requirements  Failure to comply with HIPAA is a violation of federal law.  You could even be fined and jailed if you break the law.
  • 15. 15 If You See A Problem…  If you see or hear about someone who is in violation of HIPAA requirements and procedures, you should tell your supervisor.  All reports should be investigated.
  • 16. 16 Prohibition on Retaliatory Acts  An employer is bound by law to protect a workforce member from harassment or retaliatory actions if he or she reports a suspected privacy violation.
  • 17. 17 Crime Victims  You are allowed to disclose PHI to law enforcement without the client/participant’s authorization when:  The PHI disclosed is about the person suspected of a criminal act; and  The PHI disclosed is limited to information relevant to identifying the suspect and the nature of any injury.
  • 18. 18 Remember…  If you are unsure about how to proceed in a certain situation involving PHI, ask your supervisor.
  • 19. 19 Remember…  Do not discuss any PHI you see or hear while performing your job with anyone unless necessary!
  • 20. 20 Remember…  There are significant penalties for misuse of PHI.