SlideShare a Scribd company logo
1 of 49
H AA W
IP
orkforce T
raining
P
RIVACY and H AA
IP
M
ANDAT
ORY
Completion of training is mandatory
under
H AA for the entire workforce of the
IP
M RB
H
Including volunteers, like yourselves.
What is HIPPA?
In 1996 President Clinton signed the Health Insurance
Portability and Accountability Act (HIPAA). This new
law was enacted as part of a broad congressional attempt at
incremental healthcare reform.
HIPAA has two primary purposes. One is to provide
continuous insurance coverage for workers who change
jobs, and the other is to “ reduce the costs and
administrative burdens of health care by making possible
the standardized, electronic transmission of many
administrative and financial transactions that are currently
carried out manually on paper” .
H AA W
IP
orkforce T
raining
HIPAA requires that the
MHRB create HIPAA policies
and procedures that may
affect your work as a Board
member.
T H AA T
his IP
raining
P
rogram will answer…
What does HIPAA do?
Who has to follow the HIPAA law?
What is Protected Health Information?
When do we start?
How does HIPAA affect you?
Why is HIPAA important?
W
hat does H P do?
IP A
H AA is the H
IP
ealth Insurance
P
ortability and Accountability Act of
1996. It is a federal law that…
– Protects the privacy of a client’ s personal and
health information
– Provides for electronic and physical security of
personal and health information
– Simplifies billing and other transactions
An Overview of the L
aw
H IP A A
H e a lt h I n s u r a n c e a n d P o r t a b ilit y A c t o f 1 9 9 6
T it le I
P o r t a b ilit y

T it le I I
A d m in is t r a t iv e
S im p lific a t io n

T it le I I I
M e d ic a l S a v in g s
A c c o u n ts

P R IV A C Y

EDI

S E C U R IT Y

U s e a n d D is c lo s u r e
of PHI

T r a n s a c tio n s

A d m in is tr a tiv e
P ro c e d u re s

In d iv d u a l
R ig h ts

Code
S e ts

P h y s ic a l
S a fe g u a rd s

A d m in is tr a tiv e
R e q u ir e m e n ts

Id e n tifie r s

T e c h n ic a l
S e c u rity
S e r v ic e s
T e c h n ic a l
S e c u rity
M e c h a n is m s

T it le I V
G r o u p H e a lt h P la n
P r o v is io n s

T it le V
R e v e n u e O ffs e t
P r o v is io n
HIPAA is the FLOOR
HIPAA regulations are the minimum
starting point for protecting health
information and do not supersede any rules,
regulations, or standards that are more
stringent. For example, if ODMH rules are
more stringent than HIPAA rules, we must
follow the ODMH rule.
Organizational and
Administrative Requirements
A Privacy Officer must be appointed to
implement and develop privacy policies and
procedures for the agency.
Must train all employees (current and new) on
privacy policies and procedures.
Must amend all business associate contracts
to establish the permitted and required uses
and disclosures of PHI.
Must verify the identity and authority of
person requesting PHI.
Organizational and
Administrative Requirements
Must disseminate a notice of our
privacy practices to existing clients and
all new clients and within 60 days of any
material revision.
Must notify clients every 3 years of the
availability of the notice.
A covered entity with a website must
post their notice on the web.
Organizational and
Administrative Requirements
Must document compliance with notice
requirements and keep copies of
notices issued.
Must document who is responsible for
receiving and processing client inquiries
regarding his/her PHI.
Organizational and
Administrative Requirements
Must provide a process for individuals
to make complaints and document such
complaints and their disposition.
Must develop anti-retaliation policy.
W has to follow H AA?
ho
IP

Everyone!
W Is Impacted?
ho
Health care providers – A provider of medical, psychiatric,
or other health services, and any other person or entity
furnishing health care services or supplies.
Health plans – an individual or group health plan that
provides or pays the cost of medical care.
Clearinghouses – A public or private entity that processes
or facilitates the processing of non-standard data elements
of health information into standard data elements and who
transmits any health information in electronic form in
connection with a transaction covered in the legislation.
Business Associates and Trading Partners
Business Associate
A person or entity to whom a covered entity
discloses protected health information, to
perform a function on behalf of or to
provide services to a covered entity.
Includes lawyers, accountants, consultants,
and accrediting agencies.
Must have a contract obligating them to
safeguard protected health information.
B
usiness Associate Contracts
Must establish the permitted and required uses and
disclosures of protected health information by the
business associate and may not authorize further
disclosure in violation of the regulations
If the covered entity knows of a practice or pattern
of activity that constitutes a material breach of the
business associate’ s obligations under the contract,
the covered entity must take reasonable steps to
ensure cure of the breach or terminate the contract
or report the problem to the Secretary of Health
and Human Services.
B
usiness Associate
Obligations
Must not use or disclose protected health information in
violation of the law or contract.
Implement safeguards against improper use or disclosure.
Ensure that any agents or subcontractors agree to fulfill
contractual and legal obligations.
Afford individual access to records; make available
records for amendment by the individual; account to the
individual for use or disclosure other than for payment,
treatment, or operations.
At termination of the contract, return or destroy protected
health information.
W
hat Is Impacted?
T
RANSACT
IONS
A transaction is the exchange of information
between two parties to carry out financial and
administrative activities related to health care. It
includes:
– H
ealth claims or encounter information,
– H
ealth care payment and E
xplanation of B
enefits
(E ),
OB
W
hat Is Impacted?
T
ransactions Continued

Coordination of benefits,
Enrollment/disenrollment in a health plan,
Eligibility for a health plan,
Health plan premium payments,
Referral certification and authorization,
First report of injury, and
Health claims attachments.
W
hat Is Impacted?
P
ROT CT D H AL H INF
E E E T
ORM ION
AT
Protected Health Information is defined as any information,
whether oral or recorded, in any form or medium, that(A) Is created or received by a provider, health plan, public
health authority, employer, life insurer, school, or
clearinghouse; and
(B) Relates to the past, present or future physical or mental
health or condition of an individual, the provision of health
care to an individual, or the past, present, or future
payment for the provision of health care to an individual.
What is considered
Protected Health Information?
A person’ s name, address, birth
date, age, phone and fax numbers, email address
Medical records, diagnosis, x-rays,
photos, prescriptions, lab work, test
results
Billing records, claim data, referral
authorizations, explanation of
benefits
Research records
The Board may create, use
and share a person’ s PHI for:
Treatment
Billing and Payment
Agency Business
Management and
Operations
Disclosures Required by
Law
Public Health and Other
Governmental Reporting
PHI Consent
Some uses and disclosures of PHI do not
require consent.
The use and disclosure of protected health
information relating to treatment, payment,
or health care operations does not require
prior written consent.
Minimum Necessary Rule
When using or disclosing Protected Health
Information (PHI) or when requesting PHI
from another covered entity, The Board
must make reasonable efforts to limit PHI
to the minimum necessary to accomplish
the intended purpose of the use, disclosure,
or request, unless an exception applies.
Minimum Necessary Rule
Exceptions
The minimum necessary requirement does not apply in the following
instances:
 
Disclosures to or requests by a health care entity for purposes of
treatment.
Uses or disclosures made to the individual who is the subject of the
PHI.
Uses or disclosures made pursuant to a valid authorization initiated by
the individual.
Disclosures to the secretary of the Department of Health and Human
Services
(HHS).
Uses or disclosures that are required by law.
Uses or disclosures required for compliance under HIPAA, including
compliance with the implementation specifications for
conducting standard data transactions.
Requests for Disclosure
The Board may rely on a request for disclosure as the minimum necessary
for the stated purpose when:
Making permitted disclosures to public officials, if the public official
represents that the information is the minimum necessary for the stated
purpose(s).
The information is requested by another covered entity.
The information is requested by a professional who is a member of
The Board’ s workforce or is a business associate of Board for the
purpose of providing professional services to The Board if the
professional represents that the information requested is the minimum
necessary for the stated purpose(s).
The information is requested for research purposes and the person
requesting the information has provided documentation or
representations to The Board verifying such intended purpose.
Using and Disclosing PHI
Without Consent
When a disclosure is required
by federal, state, or local law,
judicial or administrative
proceedings, or law
enforcement.
Disclosure without your
consent can occur in certain
emergency treatment situations.
To avoid harm.
For specific government
functions.

For workers'
compensation purposes.
Appointment reminders
and health-related benefits
or services.
For fundraising activities,
public health activities,
organ donations, and for
research purposes.
Verification
In certain instances, as permitted or required by law, The
Board can or must disclose an individual’s PHI, even
where there is no specific consent or authorization from
the individual to do so.
No PHI will be disclosed without precautions being made
to assure that the identity of the person requesting PHI
information is verified and that they have the authority to
have access to the information requested.
Verification of Identity
When the identity of the person seeking disclosure of an individual’s PHI is not known
to The Board, verification of the person’s identity is as follows:
If the request is made in person, presentation of an agency identification badge,
other official credentials, or other proof of government status.
If the request is in writing, the request is on the appropriate government
letterhead
or other accepted proof of identity is documented.
If the disclosure is to a person acting on behalf of a public official, a written
statement on appropriate government letterhead that the person is acting under
the governments’ authority or other evidence or documentation of agency, such
as a contract for services, memorandum of understanding, or purchase order,
that establishes that the person is acting on behalf of the public official.
Verification of Authority
To verify the authority of a public official, The Board may rely on any of the
following:
A written statement of the legal authority under which the information is
requested or,
2. if a written statement is impracticable, an oral statement of such legal
authority,
3. If a request is made pursuant to legal process, a warrant, subpoena, order,
or other legal process issued by a grand jury or a judicial or administrative
tribunal will be presumed to constitute legal authority.
Privacy Notice
Every client is provided with a Notice of Privacy
Practices upon enrollment at a contract agency
The Notice describes”
– How the MHRB can use and share protected health
information, and
– Every client’ s privacy rights

The privacy notice is also published on the
MHRB’ s web page.
Copies of the Notice of Privacy are available from
the Privacy Officer or Secretary.
Clients’ PHI Rights
One of the purposes of the new H AA rule is
IP
to give clients more control over their P I.
H
Such as:
The right to request limits on uses and disclosures
of their PHI.
The right to choose how the agency sends PHI to
them.
The right to view and obtain copies of their PHI.
The right to correct or update their PHI.
How do clients
exercise these rights?
Special forms to request changes,
corrections, copies, etc. are available from
the Privacy Officer.
What client information
must be protected?
We must protect a client’ s personal and
health information that:
– Is created, kept, filed, used or shared
– Is written, spoken, electronic or digital

As already stated HIPAA defines client
personal and health information as
Protected Health Information or “ PHI” for
short.
W
hen do we start?

NOW
!
How will HIPAA
affect your duties?
If you currently see, use, share and/
or
create a person’s protected health
information as part of your job or
duties, H AA will change the way you
IP
work.
You must protect the privacy of the
client and M RB workforce protected
H ’s
health information.
When can you use PHI?
ONLY to do your job or duties!
At all other times, protect a client’ s
information as if it were your own
information!
H can you use P I?
ow
H
You may look at a person’ s
PHI only if you need it to do
your job or duties.
You may use a person’ s PHI
only if you need it to do your job or duties.
You may give a person’ s PHI to
others when it is necessary for them to do their jobs.
You may talk to others about a person’ s PHI only if it is
necessary to do your job or duties.
Why is HIPAA important?
P
rotecting privacy is important!
W all want our P I to be
e
H
private
Our clients want their P I to
H
be private
It’s the right thing to do
It’s the law
What can happen if we
don’ t follow HIPAA?
Someone who does not
protect a person’ s personal
and/or health care privacy
could:
– Lose his/her job
– Pay fines
– Go to jail
F
ines?
Fines range
from $50,000 to
$250,000 per
incident
J
ail?
Jail terms
can be up to
10 years
per incident
Did you know….?

The Board must protect your
personal health information
with as much diligence and
security as we protect clients’
PHI.
W
hen do we have
to protect P I?
H

NOW
!
H AA Stories
IP
Please read the following two
HIPAA stories carefully as
you will be asked to discuss
them
on the quiz.
H AA Story #1: Annie
IP
After serving on the client’s rights appeal committee, I
ran into the customer Annie, who filed the appeal at the
grocery store. She came up to me and started talking
about her appeal, the medications she was placed on
and how she was not feeling any better. I told her I
could not discuss her appeal that it was confidential,
and that it takes time for some medications to work.
Did I do the right thing?
H AA Story #2: B
IP
arry
I happened to be using the copier in the MHRB office
when a fax arrived. I did not read any of the details
but recognized the client name on the incident report.
I did not do anything with the information and kept it
to myself.
Did I do the right thing?
W
here to F Out
ind
M
ore About H AA
IP
The Privacy Notice is on the agency’ s
Internet Website: www.whmhrb.org
Contact Kim Tapie, Compliance and
Privacy Officer with questions and/or
concerns
Review HIPAA materials in the Board’ s
Operations Manual
T E
he nd!

Congratulations! You have completed
The HIPAA Privacy Training
.

More Related Content

What's hot

Keys To HIPAA Compliance
Keys To HIPAA ComplianceKeys To HIPAA Compliance
Keys To HIPAA ComplianceCBIZ, Inc.
 
HIPAA INSERVICE 2017
HIPAA INSERVICE 2017 HIPAA INSERVICE 2017
HIPAA INSERVICE 2017 Meg Oser
 
Supervisor Drug Awareness and Reasonable Suspicion by P&A Consulting Services
Supervisor Drug Awareness and Reasonable Suspicion by P&A Consulting ServicesSupervisor Drug Awareness and Reasonable Suspicion by P&A Consulting Services
Supervisor Drug Awareness and Reasonable Suspicion by P&A Consulting ServicesAtlantic Training, LLC.
 
Introduction to HIPAA and Confidentiality for Employees
Introduction to HIPAA and Confidentiality for EmployeesIntroduction to HIPAA and Confidentiality for Employees
Introduction to HIPAA and Confidentiality for EmployeesHouse of New Hope
 
Corporate Compliance (Physicians)
Corporate Compliance (Physicians)Corporate Compliance (Physicians)
Corporate Compliance (Physicians)justinschreiber
 
HIPPA-Health Insurance Portability and Accountability Act
HIPPA-Health Insurance Portability and Accountability ActHIPPA-Health Insurance Portability and Accountability Act
HIPPA-Health Insurance Portability and Accountability ActHarshit Trivedi
 
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)Sanjeev Bharwan
 
Introduction to HIPAA for Healthcare Professionals by OUP
Introduction to HIPAA for Healthcare Professionals by OUPIntroduction to HIPAA for Healthcare Professionals by OUP
Introduction to HIPAA for Healthcare Professionals by OUPAtlantic Training, LLC.
 
Health Insurance Portability and Accountability Act (HIPAA) Compliance
Health Insurance Portability and Accountability Act (HIPAA) ComplianceHealth Insurance Portability and Accountability Act (HIPAA) Compliance
Health Insurance Portability and Accountability Act (HIPAA) ComplianceControlCase
 
Personal Health Records & HIPAA
Personal Health Records & HIPAAPersonal Health Records & HIPAA
Personal Health Records & HIPAAMargery Lynn
 
Hipaa overview 073118
Hipaa overview 073118Hipaa overview 073118
Hipaa overview 073118robint2125
 

What's hot (20)

Keys To HIPAA Compliance
Keys To HIPAA ComplianceKeys To HIPAA Compliance
Keys To HIPAA Compliance
 
HIPAA for Dummies
HIPAA for DummiesHIPAA for Dummies
HIPAA for Dummies
 
HIPAA
HIPAAHIPAA
HIPAA
 
HIPAA INSERVICE 2017
HIPAA INSERVICE 2017 HIPAA INSERVICE 2017
HIPAA INSERVICE 2017
 
HIPAA Privacy & Security
HIPAA Privacy & SecurityHIPAA Privacy & Security
HIPAA Privacy & Security
 
Supervisor Drug Awareness and Reasonable Suspicion by P&A Consulting Services
Supervisor Drug Awareness and Reasonable Suspicion by P&A Consulting ServicesSupervisor Drug Awareness and Reasonable Suspicion by P&A Consulting Services
Supervisor Drug Awareness and Reasonable Suspicion by P&A Consulting Services
 
Introduction to HIPAA and Confidentiality for Employees
Introduction to HIPAA and Confidentiality for EmployeesIntroduction to HIPAA and Confidentiality for Employees
Introduction to HIPAA and Confidentiality for Employees
 
Corporate Compliance (Physicians)
Corporate Compliance (Physicians)Corporate Compliance (Physicians)
Corporate Compliance (Physicians)
 
HIPPA-Health Insurance Portability and Accountability Act
HIPPA-Health Insurance Portability and Accountability ActHIPPA-Health Insurance Portability and Accountability Act
HIPPA-Health Insurance Portability and Accountability Act
 
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)
 
UNA HIPAA Training 8-13
UNA HIPAA Training   8-13UNA HIPAA Training   8-13
UNA HIPAA Training 8-13
 
Hipaa training
Hipaa trainingHipaa training
Hipaa training
 
Introduction to HIPAA for Healthcare Professionals by OUP
Introduction to HIPAA for Healthcare Professionals by OUPIntroduction to HIPAA for Healthcare Professionals by OUP
Introduction to HIPAA for Healthcare Professionals by OUP
 
Health Insurance Portability and Accountability Act (HIPAA) Compliance
Health Insurance Portability and Accountability Act (HIPAA) ComplianceHealth Insurance Portability and Accountability Act (HIPAA) Compliance
Health Insurance Portability and Accountability Act (HIPAA) Compliance
 
HIPAA Basics by Brian Fleetham
HIPAA Basics by Brian FleethamHIPAA Basics by Brian Fleetham
HIPAA Basics by Brian Fleetham
 
Annual HIPAA Training
Annual HIPAA TrainingAnnual HIPAA Training
Annual HIPAA Training
 
Personal Health Records & HIPAA
Personal Health Records & HIPAAPersonal Health Records & HIPAA
Personal Health Records & HIPAA
 
HIPAA and How it Applies to You
HIPAA and How it Applies to YouHIPAA and How it Applies to You
HIPAA and How it Applies to You
 
Hipaa overview 073118
Hipaa overview 073118Hipaa overview 073118
Hipaa overview 073118
 
Corporate compliance
Corporate complianceCorporate compliance
Corporate compliance
 

Viewers also liked

HIPAA 101 Privacy and Security Training by University of Californa San Francisco
HIPAA 101 Privacy and Security Training by University of Californa San FranciscoHIPAA 101 Privacy and Security Training by University of Californa San Francisco
HIPAA 101 Privacy and Security Training by University of Californa San FranciscoAtlantic Training, LLC.
 
Hazard Communication by Maine Dept. of Labor
Hazard Communication by Maine Dept. of LaborHazard Communication by Maine Dept. of Labor
Hazard Communication by Maine Dept. of LaborAtlantic Training, LLC.
 
Slips, Trips and Falls by Connecticut DOL
Slips, Trips and Falls by Connecticut DOLSlips, Trips and Falls by Connecticut DOL
Slips, Trips and Falls by Connecticut DOLAtlantic Training, LLC.
 
Hazard Communication Training by Maine Department of Labor
Hazard Communication Training by Maine Department of LaborHazard Communication Training by Maine Department of Labor
Hazard Communication Training by Maine Department of LaborAtlantic Training, LLC.
 
Preventing Slips, Trips and Falls in the Health Care Industry by GTRI
Preventing Slips, Trips and Falls in the Health Care Industry by GTRIPreventing Slips, Trips and Falls in the Health Care Industry by GTRI
Preventing Slips, Trips and Falls in the Health Care Industry by GTRIAtlantic Training, LLC.
 
Hazard Communication Training by Oklahoma State University
Hazard Communication Training by Oklahoma State UniversityHazard Communication Training by Oklahoma State University
Hazard Communication Training by Oklahoma State UniversityAtlantic Training, LLC.
 
The Control of Hazardous Energy by SAPPI
The Control of Hazardous Energy by SAPPIThe Control of Hazardous Energy by SAPPI
The Control of Hazardous Energy by SAPPIAtlantic Training, LLC.
 
Hazard Communication Training Program by MIOSHA
 Hazard Communication Training Program by MIOSHA Hazard Communication Training Program by MIOSHA
Hazard Communication Training Program by MIOSHAAtlantic Training, LLC.
 
Personal Protective Equipment Training by San Diego State University
Personal Protective Equipment Training by San Diego State UniversityPersonal Protective Equipment Training by San Diego State University
Personal Protective Equipment Training by San Diego State UniversityAtlantic Training, LLC.
 
Slips, Trips, and Fall Prevention Training by SIA
Slips, Trips, and Fall Prevention Training by SIASlips, Trips, and Fall Prevention Training by SIA
Slips, Trips, and Fall Prevention Training by SIAAtlantic Training, LLC.
 
Personal Protective Equipment in the Construction Industry Training by NMENV
Personal Protective Equipment in the Construction Industry Training by NMENVPersonal Protective Equipment in the Construction Industry Training by NMENV
Personal Protective Equipment in the Construction Industry Training by NMENVAtlantic Training, LLC.
 

Viewers also liked (20)

HIPAA 101 Privacy and Security Training by University of Californa San Francisco
HIPAA 101 Privacy and Security Training by University of Californa San FranciscoHIPAA 101 Privacy and Security Training by University of Californa San Francisco
HIPAA 101 Privacy and Security Training by University of Californa San Francisco
 
Hazard Communication by Maine Dept. of Labor
Hazard Communication by Maine Dept. of LaborHazard Communication by Maine Dept. of Labor
Hazard Communication by Maine Dept. of Labor
 
Slips, Trips and Falls by Connecticut DOL
Slips, Trips and Falls by Connecticut DOLSlips, Trips and Falls by Connecticut DOL
Slips, Trips and Falls by Connecticut DOL
 
Hazard Communication Training by Maine Department of Labor
Hazard Communication Training by Maine Department of LaborHazard Communication Training by Maine Department of Labor
Hazard Communication Training by Maine Department of Labor
 
Slips, Trips, and Falls by Signalmutual
Slips, Trips, and Falls by SignalmutualSlips, Trips, and Falls by Signalmutual
Slips, Trips, and Falls by Signalmutual
 
Preventing Slips, Trips and Falls in the Health Care Industry by GTRI
Preventing Slips, Trips and Falls in the Health Care Industry by GTRIPreventing Slips, Trips and Falls in the Health Care Industry by GTRI
Preventing Slips, Trips and Falls in the Health Care Industry by GTRI
 
Energy Control Program by MCIEAST
Energy Control Program by MCIEASTEnergy Control Program by MCIEAST
Energy Control Program by MCIEAST
 
Hazardous Energy Control by MSHA
Hazardous Energy Control by MSHAHazardous Energy Control by MSHA
Hazardous Energy Control by MSHA
 
Hazard Communication Training by Oklahoma State University
Hazard Communication Training by Oklahoma State UniversityHazard Communication Training by Oklahoma State University
Hazard Communication Training by Oklahoma State University
 
Lock Out-Tag Out Training by Ryko
Lock Out-Tag Out Training by RykoLock Out-Tag Out Training by Ryko
Lock Out-Tag Out Training by Ryko
 
The Control of Hazardous Energy by SAPPI
The Control of Hazardous Energy by SAPPIThe Control of Hazardous Energy by SAPPI
The Control of Hazardous Energy by SAPPI
 
Lockout Tagout by Snohomish County
Lockout Tagout by Snohomish CountyLockout Tagout by Snohomish County
Lockout Tagout by Snohomish County
 
Lockout Tagout by FirstSource
Lockout Tagout by FirstSourceLockout Tagout by FirstSource
Lockout Tagout by FirstSource
 
Hazard Communication Training Program by MIOSHA
 Hazard Communication Training Program by MIOSHA Hazard Communication Training Program by MIOSHA
Hazard Communication Training Program by MIOSHA
 
Slips, Trips and Falls Training by WITC
Slips, Trips and Falls Training by WITCSlips, Trips and Falls Training by WITC
Slips, Trips and Falls Training by WITC
 
Personal Protective Equipment Training by San Diego State University
Personal Protective Equipment Training by San Diego State UniversityPersonal Protective Equipment Training by San Diego State University
Personal Protective Equipment Training by San Diego State University
 
Manufacturing Lockout Tagout by FMIC
Manufacturing Lockout Tagout by FMICManufacturing Lockout Tagout by FMIC
Manufacturing Lockout Tagout by FMIC
 
Slips, Trips, and Fall Prevention Training by SIA
Slips, Trips, and Fall Prevention Training by SIASlips, Trips, and Fall Prevention Training by SIA
Slips, Trips, and Fall Prevention Training by SIA
 
Personal Protective Equipment in the Construction Industry Training by NMENV
Personal Protective Equipment in the Construction Industry Training by NMENVPersonal Protective Equipment in the Construction Industry Training by NMENV
Personal Protective Equipment in the Construction Industry Training by NMENV
 
Hazard Communication Training by
Hazard Communication Training by Hazard Communication Training by
Hazard Communication Training by
 

Similar to Understanding HIPAA Privacy and Security Training

Week 1 discussion 2 hipaa and privacy training
Week 1 discussion 2 hipaa and privacy trainingWeek 1 discussion 2 hipaa and privacy training
Week 1 discussion 2 hipaa and privacy trainingvrgill22
 
Mha 690 week one discussion ii
Mha 690 week one discussion iiMha 690 week one discussion ii
Mha 690 week one discussion iibeleza1669
 
Mha 690 week one discussion ii
Mha 690 week one discussion iiMha 690 week one discussion ii
Mha 690 week one discussion iibeleza1669
 
Knowing confidentiality
Knowing confidentialityKnowing confidentiality
Knowing confidentialityjessie66
 
HIPAA Training - 2011
HIPAA Training - 2011HIPAA Training - 2011
HIPAA Training - 2011darichardson
 
health insurance portability and accountability act.pptx
health insurance portability and accountability act.pptxhealth insurance portability and accountability act.pptx
health insurance portability and accountability act.pptxamartya2087
 
Marc etienne week1 discussion2 presentation
Marc etienne week1 discussion2 presentationMarc etienne week1 discussion2 presentation
Marc etienne week1 discussion2 presentationMarcEtienne6
 
MHS NOPP - 1 OCT 13
MHS NOPP - 1 OCT 13MHS NOPP - 1 OCT 13
MHS NOPP - 1 OCT 131 SOMDG
 

Similar to Understanding HIPAA Privacy and Security Training (20)

Week 1 discussion 2 hipaa and privacy training
Week 1 discussion 2 hipaa and privacy trainingWeek 1 discussion 2 hipaa and privacy training
Week 1 discussion 2 hipaa and privacy training
 
HIPAA Audio Presentation
HIPAA  Audio PresentationHIPAA  Audio Presentation
HIPAA Audio Presentation
 
Hippa training v2
Hippa training v2Hippa training v2
Hippa training v2
 
Hippa
HippaHippa
Hippa
 
Chapter 3: Ethics
Chapter 3: EthicsChapter 3: Ethics
Chapter 3: Ethics
 
Mha 690 week one discussion ii
Mha 690 week one discussion iiMha 690 week one discussion ii
Mha 690 week one discussion ii
 
Mha 690 week one discussion ii
Mha 690 week one discussion iiMha 690 week one discussion ii
Mha 690 week one discussion ii
 
HIPAA Complaince
HIPAA ComplainceHIPAA Complaince
HIPAA Complaince
 
CONFIDENTIALITYANDHIPAA.ppt
CONFIDENTIALITYANDHIPAA.pptCONFIDENTIALITYANDHIPAA.ppt
CONFIDENTIALITYANDHIPAA.ppt
 
Knowing confidentiality
Knowing confidentialityKnowing confidentiality
Knowing confidentiality
 
The Basics of HIPAA
The Basics of HIPAA The Basics of HIPAA
The Basics of HIPAA
 
HIPAA HITECH training 7-9-12
HIPAA HITECH training 7-9-12HIPAA HITECH training 7-9-12
HIPAA HITECH training 7-9-12
 
HIPAA Training - 2011
HIPAA Training - 2011HIPAA Training - 2011
HIPAA Training - 2011
 
HIPAA & PHI Training
HIPAA & PHI TrainingHIPAA & PHI Training
HIPAA & PHI Training
 
HIPAA, PHI, & 42 CFR Part 2
HIPAA, PHI, & 42 CFR Part 2HIPAA, PHI, & 42 CFR Part 2
HIPAA, PHI, & 42 CFR Part 2
 
health insurance portability and accountability act.pptx
health insurance portability and accountability act.pptxhealth insurance portability and accountability act.pptx
health insurance portability and accountability act.pptx
 
Marc etienne week1 discussion2 presentation
Marc etienne week1 discussion2 presentationMarc etienne week1 discussion2 presentation
Marc etienne week1 discussion2 presentation
 
Dustin HIPAA
Dustin HIPAADustin HIPAA
Dustin HIPAA
 
HIPAA
HIPAAHIPAA
HIPAA
 
MHS NOPP - 1 OCT 13
MHS NOPP - 1 OCT 13MHS NOPP - 1 OCT 13
MHS NOPP - 1 OCT 13
 

More from Atlantic Training, LLC.

Stress and Worker Safety by Pennsylvania L&I
Stress and Worker Safety by Pennsylvania L&IStress and Worker Safety by Pennsylvania L&I
Stress and Worker Safety by Pennsylvania L&IAtlantic Training, LLC.
 
Workplace Harassment Prevention by UT EAP
Workplace Harassment Prevention by  UT EAPWorkplace Harassment Prevention by  UT EAP
Workplace Harassment Prevention by UT EAPAtlantic Training, LLC.
 
Preventing Falls, Slips and Trips by MGSU
Preventing Falls, Slips and Trips by MGSUPreventing Falls, Slips and Trips by MGSU
Preventing Falls, Slips and Trips by MGSUAtlantic Training, LLC.
 
Preventing Workplace Harassment by Pennsylvania L&I
Preventing Workplace Harassment by Pennsylvania L&IPreventing Workplace Harassment by Pennsylvania L&I
Preventing Workplace Harassment by Pennsylvania L&IAtlantic Training, LLC.
 
Warehouses In Emergencies by WFP Logistics
Warehouses In Emergencies by WFP LogisticsWarehouses In Emergencies by WFP Logistics
Warehouses In Emergencies by WFP LogisticsAtlantic Training, LLC.
 
Sexual Harassment in the Workplace Training by Shumaker
Sexual Harassment in the Workplace Training by ShumakerSexual Harassment in the Workplace Training by Shumaker
Sexual Harassment in the Workplace Training by ShumakerAtlantic Training, LLC.
 
New Employee Safety Orientation by Oregon State University
New Employee Safety Orientation by Oregon State UniversityNew Employee Safety Orientation by Oregon State University
New Employee Safety Orientation by Oregon State UniversityAtlantic Training, LLC.
 

More from Atlantic Training, LLC. (20)

Wellness for Supervisors by SWOSU
Wellness for Supervisors by SWOSUWellness for Supervisors by SWOSU
Wellness for Supervisors by SWOSU
 
Workplace Wellness by PHA
Workplace Wellness by PHAWorkplace Wellness by PHA
Workplace Wellness by PHA
 
Stress Management Training by SG
Stress Management Training by  SGStress Management Training by  SG
Stress Management Training by SG
 
Stress Management Training by SW
Stress Management Training by SWStress Management Training by SW
Stress Management Training by SW
 
Stress and Worker Safety by Pennsylvania L&I
Stress and Worker Safety by Pennsylvania L&IStress and Worker Safety by Pennsylvania L&I
Stress and Worker Safety by Pennsylvania L&I
 
Respectful Workplace by RDTC
Respectful Workplace by RDTCRespectful Workplace by RDTC
Respectful Workplace by RDTC
 
Workplace Harassment by CLGW
Workplace Harassment by CLGWWorkplace Harassment by CLGW
Workplace Harassment by CLGW
 
Workplace Harassment Prevention by UT EAP
Workplace Harassment Prevention by  UT EAPWorkplace Harassment Prevention by  UT EAP
Workplace Harassment Prevention by UT EAP
 
Welding Safety by Pennsylvania L&I
Welding Safety by Pennsylvania L&IWelding Safety by Pennsylvania L&I
Welding Safety by Pennsylvania L&I
 
Slips Trips & Falls Training by Signal
Slips Trips & Falls Training by SignalSlips Trips & Falls Training by Signal
Slips Trips & Falls Training by Signal
 
Preventing Falls, Slips and Trips by MGSU
Preventing Falls, Slips and Trips by MGSUPreventing Falls, Slips and Trips by MGSU
Preventing Falls, Slips and Trips by MGSU
 
Preventing Workplace Harassment by Pennsylvania L&I
Preventing Workplace Harassment by Pennsylvania L&IPreventing Workplace Harassment by Pennsylvania L&I
Preventing Workplace Harassment by Pennsylvania L&I
 
Warehouses In Emergencies by WFP Logistics
Warehouses In Emergencies by WFP LogisticsWarehouses In Emergencies by WFP Logistics
Warehouses In Emergencies by WFP Logistics
 
Prevention of Sexual Harassment by USMC
Prevention of Sexual Harassment by USMCPrevention of Sexual Harassment by USMC
Prevention of Sexual Harassment by USMC
 
Sexual Harassment by DEOMI
Sexual Harassment by DEOMISexual Harassment by DEOMI
Sexual Harassment by DEOMI
 
Sexual Harassment in the Workplace Training by Shumaker
Sexual Harassment in the Workplace Training by ShumakerSexual Harassment in the Workplace Training by Shumaker
Sexual Harassment in the Workplace Training by Shumaker
 
Sexual Harassment Training by NAP
Sexual Harassment Training by NAPSexual Harassment Training by NAP
Sexual Harassment Training by NAP
 
Scaffolds Training by Pennsylvania L&I
Scaffolds Training by Pennsylvania L&IScaffolds Training by Pennsylvania L&I
Scaffolds Training by Pennsylvania L&I
 
Supervision
SupervisionSupervision
Supervision
 
New Employee Safety Orientation by Oregon State University
New Employee Safety Orientation by Oregon State UniversityNew Employee Safety Orientation by Oregon State University
New Employee Safety Orientation by Oregon State University
 

Recently uploaded

BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,noida100girls
 
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfIntro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfpollardmorgan
 
Market Sizes Sample Report - 2024 Edition
Market Sizes Sample Report - 2024 EditionMarket Sizes Sample Report - 2024 Edition
Market Sizes Sample Report - 2024 EditionMintel Group
 
Ten Organizational Design Models to align structure and operations to busines...
Ten Organizational Design Models to align structure and operations to busines...Ten Organizational Design Models to align structure and operations to busines...
Ten Organizational Design Models to align structure and operations to busines...Seta Wicaksana
 
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...lizamodels9
 
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu MenzaYouth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu Menzaictsugar
 
2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis Usage2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis UsageNeil Kimberley
 
Call Girls Miyapur 7001305949 all area service COD available Any Time
Call Girls Miyapur 7001305949 all area service COD available Any TimeCall Girls Miyapur 7001305949 all area service COD available Any Time
Call Girls Miyapur 7001305949 all area service COD available Any Timedelhimodelshub1
 
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdfNewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdfKhaled Al Awadi
 
Lean: From Theory to Practice — One City’s (and Library’s) Lean Story… Abridged
Lean: From Theory to Practice — One City’s (and Library’s) Lean Story… AbridgedLean: From Theory to Practice — One City’s (and Library’s) Lean Story… Abridged
Lean: From Theory to Practice — One City’s (and Library’s) Lean Story… AbridgedKaiNexus
 
Islamabad Escorts | Call 03274100048 | Escort Service in Islamabad
Islamabad Escorts | Call 03274100048 | Escort Service in IslamabadIslamabad Escorts | Call 03274100048 | Escort Service in Islamabad
Islamabad Escorts | Call 03274100048 | Escort Service in IslamabadAyesha Khan
 
Case study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detailCase study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detailAriel592675
 
Global Scenario On Sustainable and Resilient Coconut Industry by Dr. Jelfina...
Global Scenario On Sustainable  and Resilient Coconut Industry by Dr. Jelfina...Global Scenario On Sustainable  and Resilient Coconut Industry by Dr. Jelfina...
Global Scenario On Sustainable and Resilient Coconut Industry by Dr. Jelfina...ictsugar
 
MAHA Global and IPR: Do Actions Speak Louder Than Words?
MAHA Global and IPR: Do Actions Speak Louder Than Words?MAHA Global and IPR: Do Actions Speak Louder Than Words?
MAHA Global and IPR: Do Actions Speak Louder Than Words?Olivia Kresic
 
Marketing Management Business Plan_My Sweet Creations
Marketing Management Business Plan_My Sweet CreationsMarketing Management Business Plan_My Sweet Creations
Marketing Management Business Plan_My Sweet Creationsnakalysalcedo61
 
Kenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith PereraKenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith Pereraictsugar
 
Digital Transformation in the PLM domain - distrib.pdf
Digital Transformation in the PLM domain - distrib.pdfDigital Transformation in the PLM domain - distrib.pdf
Digital Transformation in the PLM domain - distrib.pdfJos Voskuil
 
8447779800, Low rate Call girls in Tughlakabad Delhi NCR
8447779800, Low rate Call girls in Tughlakabad Delhi NCR8447779800, Low rate Call girls in Tughlakabad Delhi NCR
8447779800, Low rate Call girls in Tughlakabad Delhi NCRashishs7044
 

Recently uploaded (20)

BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
 
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfIntro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
 
Market Sizes Sample Report - 2024 Edition
Market Sizes Sample Report - 2024 EditionMarket Sizes Sample Report - 2024 Edition
Market Sizes Sample Report - 2024 Edition
 
Ten Organizational Design Models to align structure and operations to busines...
Ten Organizational Design Models to align structure and operations to busines...Ten Organizational Design Models to align structure and operations to busines...
Ten Organizational Design Models to align structure and operations to busines...
 
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
 
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu MenzaYouth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
 
Corporate Profile 47Billion Information Technology
Corporate Profile 47Billion Information TechnologyCorporate Profile 47Billion Information Technology
Corporate Profile 47Billion Information Technology
 
2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis Usage2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis Usage
 
Call Girls Miyapur 7001305949 all area service COD available Any Time
Call Girls Miyapur 7001305949 all area service COD available Any TimeCall Girls Miyapur 7001305949 all area service COD available Any Time
Call Girls Miyapur 7001305949 all area service COD available Any Time
 
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdfNewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
 
Japan IT Week 2024 Brochure by 47Billion (English)
Japan IT Week 2024 Brochure by 47Billion (English)Japan IT Week 2024 Brochure by 47Billion (English)
Japan IT Week 2024 Brochure by 47Billion (English)
 
Lean: From Theory to Practice — One City’s (and Library’s) Lean Story… Abridged
Lean: From Theory to Practice — One City’s (and Library’s) Lean Story… AbridgedLean: From Theory to Practice — One City’s (and Library’s) Lean Story… Abridged
Lean: From Theory to Practice — One City’s (and Library’s) Lean Story… Abridged
 
Islamabad Escorts | Call 03274100048 | Escort Service in Islamabad
Islamabad Escorts | Call 03274100048 | Escort Service in IslamabadIslamabad Escorts | Call 03274100048 | Escort Service in Islamabad
Islamabad Escorts | Call 03274100048 | Escort Service in Islamabad
 
Case study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detailCase study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detail
 
Global Scenario On Sustainable and Resilient Coconut Industry by Dr. Jelfina...
Global Scenario On Sustainable  and Resilient Coconut Industry by Dr. Jelfina...Global Scenario On Sustainable  and Resilient Coconut Industry by Dr. Jelfina...
Global Scenario On Sustainable and Resilient Coconut Industry by Dr. Jelfina...
 
MAHA Global and IPR: Do Actions Speak Louder Than Words?
MAHA Global and IPR: Do Actions Speak Louder Than Words?MAHA Global and IPR: Do Actions Speak Louder Than Words?
MAHA Global and IPR: Do Actions Speak Louder Than Words?
 
Marketing Management Business Plan_My Sweet Creations
Marketing Management Business Plan_My Sweet CreationsMarketing Management Business Plan_My Sweet Creations
Marketing Management Business Plan_My Sweet Creations
 
Kenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith PereraKenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith Perera
 
Digital Transformation in the PLM domain - distrib.pdf
Digital Transformation in the PLM domain - distrib.pdfDigital Transformation in the PLM domain - distrib.pdf
Digital Transformation in the PLM domain - distrib.pdf
 
8447779800, Low rate Call girls in Tughlakabad Delhi NCR
8447779800, Low rate Call girls in Tughlakabad Delhi NCR8447779800, Low rate Call girls in Tughlakabad Delhi NCR
8447779800, Low rate Call girls in Tughlakabad Delhi NCR
 

Understanding HIPAA Privacy and Security Training

  • 1. H AA W IP orkforce T raining P RIVACY and H AA IP
  • 2. M ANDAT ORY Completion of training is mandatory under H AA for the entire workforce of the IP M RB H Including volunteers, like yourselves.
  • 3. What is HIPPA? In 1996 President Clinton signed the Health Insurance Portability and Accountability Act (HIPAA). This new law was enacted as part of a broad congressional attempt at incremental healthcare reform. HIPAA has two primary purposes. One is to provide continuous insurance coverage for workers who change jobs, and the other is to “ reduce the costs and administrative burdens of health care by making possible the standardized, electronic transmission of many administrative and financial transactions that are currently carried out manually on paper” .
  • 4. H AA W IP orkforce T raining HIPAA requires that the MHRB create HIPAA policies and procedures that may affect your work as a Board member.
  • 5. T H AA T his IP raining P rogram will answer… What does HIPAA do? Who has to follow the HIPAA law? What is Protected Health Information? When do we start? How does HIPAA affect you? Why is HIPAA important?
  • 6. W hat does H P do? IP A H AA is the H IP ealth Insurance P ortability and Accountability Act of 1996. It is a federal law that… – Protects the privacy of a client’ s personal and health information – Provides for electronic and physical security of personal and health information – Simplifies billing and other transactions
  • 7. An Overview of the L aw H IP A A H e a lt h I n s u r a n c e a n d P o r t a b ilit y A c t o f 1 9 9 6 T it le I P o r t a b ilit y T it le I I A d m in is t r a t iv e S im p lific a t io n T it le I I I M e d ic a l S a v in g s A c c o u n ts P R IV A C Y EDI S E C U R IT Y U s e a n d D is c lo s u r e of PHI T r a n s a c tio n s A d m in is tr a tiv e P ro c e d u re s In d iv d u a l R ig h ts Code S e ts P h y s ic a l S a fe g u a rd s A d m in is tr a tiv e R e q u ir e m e n ts Id e n tifie r s T e c h n ic a l S e c u rity S e r v ic e s T e c h n ic a l S e c u rity M e c h a n is m s T it le I V G r o u p H e a lt h P la n P r o v is io n s T it le V R e v e n u e O ffs e t P r o v is io n
  • 8. HIPAA is the FLOOR HIPAA regulations are the minimum starting point for protecting health information and do not supersede any rules, regulations, or standards that are more stringent. For example, if ODMH rules are more stringent than HIPAA rules, we must follow the ODMH rule.
  • 9. Organizational and Administrative Requirements A Privacy Officer must be appointed to implement and develop privacy policies and procedures for the agency. Must train all employees (current and new) on privacy policies and procedures. Must amend all business associate contracts to establish the permitted and required uses and disclosures of PHI. Must verify the identity and authority of person requesting PHI.
  • 10. Organizational and Administrative Requirements Must disseminate a notice of our privacy practices to existing clients and all new clients and within 60 days of any material revision. Must notify clients every 3 years of the availability of the notice. A covered entity with a website must post their notice on the web.
  • 11. Organizational and Administrative Requirements Must document compliance with notice requirements and keep copies of notices issued. Must document who is responsible for receiving and processing client inquiries regarding his/her PHI.
  • 12. Organizational and Administrative Requirements Must provide a process for individuals to make complaints and document such complaints and their disposition. Must develop anti-retaliation policy.
  • 13. W has to follow H AA? ho IP Everyone!
  • 14. W Is Impacted? ho Health care providers – A provider of medical, psychiatric, or other health services, and any other person or entity furnishing health care services or supplies. Health plans – an individual or group health plan that provides or pays the cost of medical care. Clearinghouses – A public or private entity that processes or facilitates the processing of non-standard data elements of health information into standard data elements and who transmits any health information in electronic form in connection with a transaction covered in the legislation. Business Associates and Trading Partners
  • 15. Business Associate A person or entity to whom a covered entity discloses protected health information, to perform a function on behalf of or to provide services to a covered entity. Includes lawyers, accountants, consultants, and accrediting agencies. Must have a contract obligating them to safeguard protected health information.
  • 16. B usiness Associate Contracts Must establish the permitted and required uses and disclosures of protected health information by the business associate and may not authorize further disclosure in violation of the regulations If the covered entity knows of a practice or pattern of activity that constitutes a material breach of the business associate’ s obligations under the contract, the covered entity must take reasonable steps to ensure cure of the breach or terminate the contract or report the problem to the Secretary of Health and Human Services.
  • 17. B usiness Associate Obligations Must not use or disclose protected health information in violation of the law or contract. Implement safeguards against improper use or disclosure. Ensure that any agents or subcontractors agree to fulfill contractual and legal obligations. Afford individual access to records; make available records for amendment by the individual; account to the individual for use or disclosure other than for payment, treatment, or operations. At termination of the contract, return or destroy protected health information.
  • 18. W hat Is Impacted? T RANSACT IONS A transaction is the exchange of information between two parties to carry out financial and administrative activities related to health care. It includes: – H ealth claims or encounter information, – H ealth care payment and E xplanation of B enefits (E ), OB
  • 19. W hat Is Impacted? T ransactions Continued Coordination of benefits, Enrollment/disenrollment in a health plan, Eligibility for a health plan, Health plan premium payments, Referral certification and authorization, First report of injury, and Health claims attachments.
  • 20. W hat Is Impacted? P ROT CT D H AL H INF E E E T ORM ION AT Protected Health Information is defined as any information, whether oral or recorded, in any form or medium, that(A) Is created or received by a provider, health plan, public health authority, employer, life insurer, school, or clearinghouse; and (B) Relates to the past, present or future physical or mental health or condition of an individual, the provision of health care to an individual, or the past, present, or future payment for the provision of health care to an individual.
  • 21. What is considered Protected Health Information? A person’ s name, address, birth date, age, phone and fax numbers, email address Medical records, diagnosis, x-rays, photos, prescriptions, lab work, test results Billing records, claim data, referral authorizations, explanation of benefits Research records
  • 22. The Board may create, use and share a person’ s PHI for: Treatment Billing and Payment Agency Business Management and Operations Disclosures Required by Law Public Health and Other Governmental Reporting
  • 23. PHI Consent Some uses and disclosures of PHI do not require consent. The use and disclosure of protected health information relating to treatment, payment, or health care operations does not require prior written consent.
  • 24. Minimum Necessary Rule When using or disclosing Protected Health Information (PHI) or when requesting PHI from another covered entity, The Board must make reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose of the use, disclosure, or request, unless an exception applies.
  • 25. Minimum Necessary Rule Exceptions The minimum necessary requirement does not apply in the following instances:   Disclosures to or requests by a health care entity for purposes of treatment. Uses or disclosures made to the individual who is the subject of the PHI. Uses or disclosures made pursuant to a valid authorization initiated by the individual. Disclosures to the secretary of the Department of Health and Human Services (HHS). Uses or disclosures that are required by law. Uses or disclosures required for compliance under HIPAA, including compliance with the implementation specifications for conducting standard data transactions.
  • 26. Requests for Disclosure The Board may rely on a request for disclosure as the minimum necessary for the stated purpose when: Making permitted disclosures to public officials, if the public official represents that the information is the minimum necessary for the stated purpose(s). The information is requested by another covered entity. The information is requested by a professional who is a member of The Board’ s workforce or is a business associate of Board for the purpose of providing professional services to The Board if the professional represents that the information requested is the minimum necessary for the stated purpose(s). The information is requested for research purposes and the person requesting the information has provided documentation or representations to The Board verifying such intended purpose.
  • 27. Using and Disclosing PHI Without Consent When a disclosure is required by federal, state, or local law, judicial or administrative proceedings, or law enforcement. Disclosure without your consent can occur in certain emergency treatment situations. To avoid harm. For specific government functions. For workers' compensation purposes. Appointment reminders and health-related benefits or services. For fundraising activities, public health activities, organ donations, and for research purposes.
  • 28. Verification In certain instances, as permitted or required by law, The Board can or must disclose an individual’s PHI, even where there is no specific consent or authorization from the individual to do so. No PHI will be disclosed without precautions being made to assure that the identity of the person requesting PHI information is verified and that they have the authority to have access to the information requested.
  • 29. Verification of Identity When the identity of the person seeking disclosure of an individual’s PHI is not known to The Board, verification of the person’s identity is as follows: If the request is made in person, presentation of an agency identification badge, other official credentials, or other proof of government status. If the request is in writing, the request is on the appropriate government letterhead or other accepted proof of identity is documented. If the disclosure is to a person acting on behalf of a public official, a written statement on appropriate government letterhead that the person is acting under the governments’ authority or other evidence or documentation of agency, such as a contract for services, memorandum of understanding, or purchase order, that establishes that the person is acting on behalf of the public official.
  • 30. Verification of Authority To verify the authority of a public official, The Board may rely on any of the following: A written statement of the legal authority under which the information is requested or, 2. if a written statement is impracticable, an oral statement of such legal authority, 3. If a request is made pursuant to legal process, a warrant, subpoena, order, or other legal process issued by a grand jury or a judicial or administrative tribunal will be presumed to constitute legal authority.
  • 31. Privacy Notice Every client is provided with a Notice of Privacy Practices upon enrollment at a contract agency The Notice describes” – How the MHRB can use and share protected health information, and – Every client’ s privacy rights The privacy notice is also published on the MHRB’ s web page. Copies of the Notice of Privacy are available from the Privacy Officer or Secretary.
  • 32. Clients’ PHI Rights One of the purposes of the new H AA rule is IP to give clients more control over their P I. H Such as: The right to request limits on uses and disclosures of their PHI. The right to choose how the agency sends PHI to them. The right to view and obtain copies of their PHI. The right to correct or update their PHI.
  • 33. How do clients exercise these rights? Special forms to request changes, corrections, copies, etc. are available from the Privacy Officer.
  • 34. What client information must be protected? We must protect a client’ s personal and health information that: – Is created, kept, filed, used or shared – Is written, spoken, electronic or digital As already stated HIPAA defines client personal and health information as Protected Health Information or “ PHI” for short.
  • 35. W hen do we start? NOW !
  • 36. How will HIPAA affect your duties? If you currently see, use, share and/ or create a person’s protected health information as part of your job or duties, H AA will change the way you IP work. You must protect the privacy of the client and M RB workforce protected H ’s health information.
  • 37. When can you use PHI? ONLY to do your job or duties! At all other times, protect a client’ s information as if it were your own information!
  • 38. H can you use P I? ow H You may look at a person’ s PHI only if you need it to do your job or duties. You may use a person’ s PHI only if you need it to do your job or duties. You may give a person’ s PHI to others when it is necessary for them to do their jobs. You may talk to others about a person’ s PHI only if it is necessary to do your job or duties.
  • 39. Why is HIPAA important? P rotecting privacy is important! W all want our P I to be e H private Our clients want their P I to H be private It’s the right thing to do It’s the law
  • 40. What can happen if we don’ t follow HIPAA? Someone who does not protect a person’ s personal and/or health care privacy could: – Lose his/her job – Pay fines – Go to jail
  • 41. F ines? Fines range from $50,000 to $250,000 per incident
  • 42. J ail? Jail terms can be up to 10 years per incident
  • 43. Did you know….? The Board must protect your personal health information with as much diligence and security as we protect clients’ PHI.
  • 44. W hen do we have to protect P I? H NOW !
  • 45. H AA Stories IP Please read the following two HIPAA stories carefully as you will be asked to discuss them on the quiz.
  • 46. H AA Story #1: Annie IP After serving on the client’s rights appeal committee, I ran into the customer Annie, who filed the appeal at the grocery store. She came up to me and started talking about her appeal, the medications she was placed on and how she was not feeling any better. I told her I could not discuss her appeal that it was confidential, and that it takes time for some medications to work. Did I do the right thing?
  • 47. H AA Story #2: B IP arry I happened to be using the copier in the MHRB office when a fax arrived. I did not read any of the details but recognized the client name on the incident report. I did not do anything with the information and kept it to myself. Did I do the right thing?
  • 48. W here to F Out ind M ore About H AA IP The Privacy Notice is on the agency’ s Internet Website: www.whmhrb.org Contact Kim Tapie, Compliance and Privacy Officer with questions and/or concerns Review HIPAA materials in the Board’ s Operations Manual
  • 49. T E he nd! Congratulations! You have completed The HIPAA Privacy Training .