SlideShare une entreprise Scribd logo
1  sur  13
Redox Medical
   Center
Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and
                                 Security Rules


                                Roderick Laino

                         MHA690: Health Care Capstone

                               Dr. Sherry Grover

                                 June 28, 2012
Objectives



๏ What is HIPAA?

๏ What is the Organization’s responsibility? Clinician’s responsibility?

๏ What information should be protected?

๏ What can we do as a team, to protect patient health information?

๏ What is the organization’s policy for violators?
What is HIPPA?

๏ The HIPAA Privacy Rule provides federal protections for personal health
  information held by covered entities and gives patients an array of rights, with
  respect to that information. At the same time, the Privacy Rule is balanced so that it
  permits the disclosure of personal health information needed for patient care and
  other important purposes. (www.hhs.gov) 

๏ The Security Rule specifies a series of administrative, physical, and technical
  safeguards for covered entities to use to assure the confidentiality, integrity, and
  availability of electronic protected health information. (www.hhs.gov)
Who ensures HIPPA compliance
๏ Doctors, nurses, and any allied healthcare workers
๏ Pharmacies
๏ Hospitals, clinics, and nursing homes
๏ Health insurance companies
๏ Health maintenance organizations (HMOs)
๏ Employer group health plans
๏ Certain government programs that pay for health care, such as Medicare and
  Medicaid.
๏ The Office for Civil Rights enforces the HIPAA Privacy Rule, which protects the
  privacy of individually identifiable health information; the HIPAA Security Rule,
  which sets national standards for the security of electronic protected health
  information; and the confidentiality provisions of the Patient Safety Rule, which
  protects identifiable information being used to analyze patient safety events and
  improve patient safety. (www.hhs.gov)
๏ Any Healthcare Clearing House. Healthcare Clearing Houses are any private or
  public entity that processes or facilitates the processing of nonstandard data
  elements of health information into standard data elements (www.cms.gov)
How does HIPPA relates to you as a
        “Clinician or Organization”

๏ As an organization, it is our corporate social responsibility to ensure that we
  protect patient health information.
๏ How do we try to accomplish this? As an organization we can do the following.
   ๏ By making sure that our website is secure
   ๏ By educating all of our employees thru annual competency
   ๏ Having an open door policy for reporting any incident that might be a
      HIPPA violation
   ๏ Have an anonymous 1-800 reporting number that it is available 24/7
   ๏ Have a non-retaliatory policy for reporting, in the event that it is a false
      alarm
   ๏ Have password protection on any computer
   ๏ Track all activity by personal log in
How does HIPPA relates to you as a
        “Clinician or Organization”
๏ As a clinician, how can you make sure that you are protecting patient health
  information?

     ๏ Make sure that you don’t talk out loud about patients, especially in public
       areas, like the cafeteria, elevator, bathroom, etc, where anyone can over hear
       patient confidential information.

     ๏ Log off of your computer when unattended

     ๏ Don’t share your password to anyone

     ๏ Call IT if you lose or forget your password

     ๏ All emails that contains PHI will be automatically encrypted for security

     ๏ Report any and all suspicious activity
Responsibility


๏ Any one who has access to patient health information is responsible to ensure that
  we comply with the law, for example clinicians, allied healthcare workers, cashiers,
  medical records employees, medical assistance, etc.

๏ The Organization as a whole is also responsible that we educate, empower and audit
  any reported incidence.

๏ The organization is also responsible that the website, email and any PHI are being
  held in a secured site and being protected against hackers and malicious attacks
  from inside of the company as well as outside.
What information are protected?


๏ Protected Health Information. The Privacy Rule protects all "individually
  identifiable health information" held or transmitted by a covered entity or its
  business associate, in any form or media, whether electronic, paper, or oral. The
  Privacy Rule calls this information "protected health information (PHI)
๏ “Individually identifiable health information” is information, including
  demographic data, that relates to:
    ๏ An individual’s past, present or future physical or mental health or condition,
    ๏ The provision of health care to the individual, or
    ๏ The past, present, or future payment for the provision of health care to the
      individual
What information are protected?



๏ Anything that identifies the individual or for which there is a reasonable basis to
  believe can be used to identify the individual. Individually identifiable health
  information includes many common identifiers (e.g., name, address, birth date,
  Social Security Number).
๏ The Privacy Rule excludes from protected health information, employment records
  that a covered entity maintains in its capacity as an employer and education and/or
  certain other records subject to, or defined in, the Family Educational Rights and
  Privacy Act, 20 U.S.C. §1232g. (U.S. Department of Health & Human Services,
  2003, pp.3-4)
How to ensure that we don’t violate
                  HIPPA?
๏ The organization has done everything it can in order to be compliant.

     ๏ We have policies and procedures in place

     ๏ Pamphlets and brochure to educate patients their rights as well as all the
       employees

     ๏ We have annual training as part of annual competency

     ๏ HIPPA information is available 24/7 in the intranet

     ๏ We have a compliance officer for any concerns

     ๏ Every employee have their own password and restricted access to PHI,

     ๏ All computers and instrument that carries PHI activities are tracked 24/7
How to ensure that we don’t violate
                  HIPPA?

๏ The organization has done everything it can in order to be compliant.

     ๏ We have 800 # available for reporting 24/7

     ๏ We have a non-retaliatory policy

     ๏ Anonymous reporting is also available

     ๏ HIPPA consent form is mandatory for any PHI to be release to a third party

     ๏ Automatic log out and save of computer that are idle
Zero tolerance to violators



๏ The company takes the HIPPA Act seriously. All practitioners are only to access
  the PHI of a patient that they have direct contact with. We have a computer alert
  for all practitioners and they must acknowledge that they are in direct contact with
  that patient before access is granted. Violations of the HIPPA rules are grounds for
  termination.

๏ The organization wants to express the seriousness of this issue. We want to make
  sure that we communicate to you our expectation and we wish that you’ll do the
  same.
Discussion 2-Wk1
       Hipaa presentation
๏ References:
U.S. Department of Health & Human Services. (2003). OCR privacy brief:
   Summary of the HIPAA privacy rule.
Center for Medicare and Medicaid Services. (2009). HIPPA compliance review
   analysis and summary of results

Contenu connexe

Tendances

Hippa Powerpoint
Hippa PowerpointHippa Powerpoint
Hippa Powerpointkvanrandall
 
HIPAA and HITECH : What you need to know
HIPAA and HITECH : What you need to knowHIPAA and HITECH : What you need to know
HIPAA and HITECH : What you need to knowShred-it
 
Health insurance portability and act(hipaa)2
Health insurance portability and act(hipaa)2Health insurance portability and act(hipaa)2
Health insurance portability and act(hipaa)29535814851
 
Health Insurance Portability and Accountability Act (HIPPA) - Kloudlearn
Health Insurance Portability and Accountability Act (HIPPA) - KloudlearnHealth Insurance Portability and Accountability Act (HIPPA) - Kloudlearn
Health Insurance Portability and Accountability Act (HIPPA) - KloudlearnKloudLearn
 
Sylvia hipaa powerpoint presentation 2010(2)
Sylvia hipaa powerpoint presentation 2010(2)Sylvia hipaa powerpoint presentation 2010(2)
Sylvia hipaa powerpoint presentation 2010(2)bholmes
 
HIPPA Security Presentation
HIPPA Security PresentationHIPPA Security Presentation
HIPPA Security PresentationRebecca Norman
 
Hippa training on confidentiality
Hippa training on confidentialityHippa training on confidentiality
Hippa training on confidentialitycraig45365
 
2012 HIPAA Refresher
2012 HIPAA Refresher2012 HIPAA Refresher
2012 HIPAA Refreshererikalsm
 
TaylorWk1d2assignment
TaylorWk1d2assignmentTaylorWk1d2assignment
TaylorWk1d2assignmentmya1743
 
Welcome to the hippa, privacy and security
Welcome to the hippa, privacy and securityWelcome to the hippa, privacy and security
Welcome to the hippa, privacy and securityveve1728
 
Shontea shepard hippa training
Shontea shepard hippa trainingShontea shepard hippa training
Shontea shepard hippa trainingsshontea
 
Hippa privacy and security awareness
Hippa privacy and security awarenessHippa privacy and security awareness
Hippa privacy and security awarenessCharles Taft
 

Tendances (20)

Hippa Powerpoint
Hippa PowerpointHippa Powerpoint
Hippa Powerpoint
 
HIPAA Compliance
HIPAA ComplianceHIPAA Compliance
HIPAA Compliance
 
HIPAA
HIPAAHIPAA
HIPAA
 
HIPAA and HITECH : What you need to know
HIPAA and HITECH : What you need to knowHIPAA and HITECH : What you need to know
HIPAA and HITECH : What you need to know
 
Health insurance portability and act(hipaa)2
Health insurance portability and act(hipaa)2Health insurance portability and act(hipaa)2
Health insurance portability and act(hipaa)2
 
HIPAA HITECH training 7-9-12
HIPAA HITECH training 7-9-12HIPAA HITECH training 7-9-12
HIPAA HITECH training 7-9-12
 
The Basics of HIPAA
The Basics of HIPAA The Basics of HIPAA
The Basics of HIPAA
 
Health Insurance Portability and Accountability Act (HIPPA) - Kloudlearn
Health Insurance Portability and Accountability Act (HIPPA) - KloudlearnHealth Insurance Portability and Accountability Act (HIPPA) - Kloudlearn
Health Insurance Portability and Accountability Act (HIPPA) - Kloudlearn
 
HIPAA Complaince
HIPAA ComplainceHIPAA Complaince
HIPAA Complaince
 
Sylvia hipaa powerpoint presentation 2010(2)
Sylvia hipaa powerpoint presentation 2010(2)Sylvia hipaa powerpoint presentation 2010(2)
Sylvia hipaa powerpoint presentation 2010(2)
 
HIPPA Security Presentation
HIPPA Security PresentationHIPPA Security Presentation
HIPPA Security Presentation
 
Hippa training on confidentiality
Hippa training on confidentialityHippa training on confidentiality
Hippa training on confidentiality
 
2012 HIPAA Refresher
2012 HIPAA Refresher2012 HIPAA Refresher
2012 HIPAA Refresher
 
Hippa training 2017
Hippa training 2017Hippa training 2017
Hippa training 2017
 
TaylorWk1d2assignment
TaylorWk1d2assignmentTaylorWk1d2assignment
TaylorWk1d2assignment
 
Welcome to the hippa, privacy and security
Welcome to the hippa, privacy and securityWelcome to the hippa, privacy and security
Welcome to the hippa, privacy and security
 
Shontea shepard hippa training
Shontea shepard hippa trainingShontea shepard hippa training
Shontea shepard hippa training
 
Hippa privacy and security awareness
Hippa privacy and security awarenessHippa privacy and security awareness
Hippa privacy and security awareness
 
Hitech Act
Hitech ActHitech Act
Hitech Act
 
Hipaa and You
Hipaa and YouHipaa and You
Hipaa and You
 

Similaire à Hippa

Mandatory hippa and information security
Mandatory hippa and information securityMandatory hippa and information security
Mandatory hippa and information securityHiggi123
 
Mandatory hippa and information security
Mandatory hippa and information securityMandatory hippa and information security
Mandatory hippa and information securityHiggi123
 
Patient Confidentiality wk1_dq2_mha690
Patient Confidentiality wk1_dq2_mha690Patient Confidentiality wk1_dq2_mha690
Patient Confidentiality wk1_dq2_mha690BrooklynRose1267
 
Patient confidentiality training
Patient confidentiality  trainingPatient confidentiality  training
Patient confidentiality trainingtwhit0623
 
Overview of hipaa & tools for hipaa compliance
Overview of hipaa & tools for hipaa complianceOverview of hipaa & tools for hipaa compliance
Overview of hipaa & tools for hipaa complianceSquare 9
 
HIPAA Audit Implementation
HIPAA Audit ImplementationHIPAA Audit Implementation
HIPAA Audit ImplementationValency Networks
 
Hipaa and patient medical record confidentiality
Hipaa and patient medical record confidentialityHipaa and patient medical record confidentiality
Hipaa and patient medical record confidentialityvflores007
 
health insurance portability and accountability act.pptx
health insurance portability and accountability act.pptxhealth insurance portability and accountability act.pptx
health insurance portability and accountability act.pptxamartya2087
 
Confidentiality, security, and integrity of information
Confidentiality, security, and integrity of informationConfidentiality, security, and integrity of information
Confidentiality, security, and integrity of informationsmallwoods
 
Confidentiality, security, and integrity of information
Confidentiality, security, and integrity of informationConfidentiality, security, and integrity of information
Confidentiality, security, and integrity of informationsmallwoods
 
Confidentiality, security, and integrity of information
Confidentiality, security, and integrity of informationConfidentiality, security, and integrity of information
Confidentiality, security, and integrity of informationsmallwoods
 
Confidentiality
ConfidentialityConfidentiality
Confidentialityshydoll414
 
Confidentiality
ConfidentialityConfidentiality
Confidentialityshydoll414
 
Hipaa.ppt3
Hipaa.ppt3Hipaa.ppt3
Hipaa.ppt3akwei2
 
Hipaa.ppt5
Hipaa.ppt5Hipaa.ppt5
Hipaa.ppt5akwei2
 
Hipaa.ppt4
Hipaa.ppt4Hipaa.ppt4
Hipaa.ppt4akwei2
 
Hipaa.ppt6
Hipaa.ppt6Hipaa.ppt6
Hipaa.ppt6akwei2
 
Hipaa.ppt1
Hipaa.ppt1Hipaa.ppt1
Hipaa.ppt1akwei2
 
Hipaa.ppt2
Hipaa.ppt2Hipaa.ppt2
Hipaa.ppt2akwei2
 

Similaire à Hippa (20)

Mandatory hippa and information security
Mandatory hippa and information securityMandatory hippa and information security
Mandatory hippa and information security
 
Mandatory hippa and information security
Mandatory hippa and information securityMandatory hippa and information security
Mandatory hippa and information security
 
Patient Confidentiality wk1_dq2_mha690
Patient Confidentiality wk1_dq2_mha690Patient Confidentiality wk1_dq2_mha690
Patient Confidentiality wk1_dq2_mha690
 
Patient confidentiality training
Patient confidentiality  trainingPatient confidentiality  training
Patient confidentiality training
 
Overview of hipaa & tools for hipaa compliance
Overview of hipaa & tools for hipaa complianceOverview of hipaa & tools for hipaa compliance
Overview of hipaa & tools for hipaa compliance
 
HIPAA Audit Implementation
HIPAA Audit ImplementationHIPAA Audit Implementation
HIPAA Audit Implementation
 
Hipaa and patient medical record confidentiality
Hipaa and patient medical record confidentialityHipaa and patient medical record confidentiality
Hipaa and patient medical record confidentiality
 
health insurance portability and accountability act.pptx
health insurance portability and accountability act.pptxhealth insurance portability and accountability act.pptx
health insurance portability and accountability act.pptx
 
Confidentiality, security, and integrity of information
Confidentiality, security, and integrity of informationConfidentiality, security, and integrity of information
Confidentiality, security, and integrity of information
 
Confidentiality, security, and integrity of information
Confidentiality, security, and integrity of informationConfidentiality, security, and integrity of information
Confidentiality, security, and integrity of information
 
Confidentiality, security, and integrity of information
Confidentiality, security, and integrity of informationConfidentiality, security, and integrity of information
Confidentiality, security, and integrity of information
 
Hipaa inservice
Hipaa inserviceHipaa inservice
Hipaa inservice
 
Confidentiality
ConfidentialityConfidentiality
Confidentiality
 
Confidentiality
ConfidentialityConfidentiality
Confidentiality
 
Hipaa.ppt3
Hipaa.ppt3Hipaa.ppt3
Hipaa.ppt3
 
Hipaa.ppt5
Hipaa.ppt5Hipaa.ppt5
Hipaa.ppt5
 
Hipaa.ppt4
Hipaa.ppt4Hipaa.ppt4
Hipaa.ppt4
 
Hipaa.ppt6
Hipaa.ppt6Hipaa.ppt6
Hipaa.ppt6
 
Hipaa.ppt1
Hipaa.ppt1Hipaa.ppt1
Hipaa.ppt1
 
Hipaa.ppt2
Hipaa.ppt2Hipaa.ppt2
Hipaa.ppt2
 

Dernier

Employee wellbeing at the workplace.pptx
Employee wellbeing at the workplace.pptxEmployee wellbeing at the workplace.pptx
Employee wellbeing at the workplace.pptxNirmalaLoungPoorunde1
 
mini mental status format.docx
mini    mental       status     format.docxmini    mental       status     format.docx
mini mental status format.docxPoojaSen20
 
1029 - Danh muc Sach Giao Khoa 10 . pdf
1029 -  Danh muc Sach Giao Khoa 10 . pdf1029 -  Danh muc Sach Giao Khoa 10 . pdf
1029 - Danh muc Sach Giao Khoa 10 . pdfQucHHunhnh
 
BASLIQ CURRENT LOOKBOOK LOOKBOOK(1) (1).pdf
BASLIQ CURRENT LOOKBOOK  LOOKBOOK(1) (1).pdfBASLIQ CURRENT LOOKBOOK  LOOKBOOK(1) (1).pdf
BASLIQ CURRENT LOOKBOOK LOOKBOOK(1) (1).pdfSoniaTolstoy
 
1029-Danh muc Sach Giao Khoa khoi 6.pdf
1029-Danh muc Sach Giao Khoa khoi  6.pdf1029-Danh muc Sach Giao Khoa khoi  6.pdf
1029-Danh muc Sach Giao Khoa khoi 6.pdfQucHHunhnh
 
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdfssuser54595a
 
Advanced Views - Calendar View in Odoo 17
Advanced Views - Calendar View in Odoo 17Advanced Views - Calendar View in Odoo 17
Advanced Views - Calendar View in Odoo 17Celine George
 
A Critique of the Proposed National Education Policy Reform
A Critique of the Proposed National Education Policy ReformA Critique of the Proposed National Education Policy Reform
A Critique of the Proposed National Education Policy ReformChameera Dedduwage
 
Introduction to AI in Higher Education_draft.pptx
Introduction to AI in Higher Education_draft.pptxIntroduction to AI in Higher Education_draft.pptx
Introduction to AI in Higher Education_draft.pptxpboyjonauth
 
Web & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdfWeb & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdfJayanti Pande
 
Organic Name Reactions for the students and aspirants of Chemistry12th.pptx
Organic Name Reactions  for the students and aspirants of Chemistry12th.pptxOrganic Name Reactions  for the students and aspirants of Chemistry12th.pptx
Organic Name Reactions for the students and aspirants of Chemistry12th.pptxVS Mahajan Coaching Centre
 
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...Marc Dusseiller Dusjagr
 
The basics of sentences session 2pptx copy.pptx
The basics of sentences session 2pptx copy.pptxThe basics of sentences session 2pptx copy.pptx
The basics of sentences session 2pptx copy.pptxheathfieldcps1
 
Beyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactBeyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactPECB
 
Sanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdfSanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdfsanyamsingh5019
 
Interactive Powerpoint_How to Master effective communication
Interactive Powerpoint_How to Master effective communicationInteractive Powerpoint_How to Master effective communication
Interactive Powerpoint_How to Master effective communicationnomboosow
 
Mastering the Unannounced Regulatory Inspection
Mastering the Unannounced Regulatory InspectionMastering the Unannounced Regulatory Inspection
Mastering the Unannounced Regulatory InspectionSafetyChain Software
 

Dernier (20)

Employee wellbeing at the workplace.pptx
Employee wellbeing at the workplace.pptxEmployee wellbeing at the workplace.pptx
Employee wellbeing at the workplace.pptx
 
mini mental status format.docx
mini    mental       status     format.docxmini    mental       status     format.docx
mini mental status format.docx
 
1029 - Danh muc Sach Giao Khoa 10 . pdf
1029 -  Danh muc Sach Giao Khoa 10 . pdf1029 -  Danh muc Sach Giao Khoa 10 . pdf
1029 - Danh muc Sach Giao Khoa 10 . pdf
 
Mattingly "AI & Prompt Design: The Basics of Prompt Design"
Mattingly "AI & Prompt Design: The Basics of Prompt Design"Mattingly "AI & Prompt Design: The Basics of Prompt Design"
Mattingly "AI & Prompt Design: The Basics of Prompt Design"
 
BASLIQ CURRENT LOOKBOOK LOOKBOOK(1) (1).pdf
BASLIQ CURRENT LOOKBOOK  LOOKBOOK(1) (1).pdfBASLIQ CURRENT LOOKBOOK  LOOKBOOK(1) (1).pdf
BASLIQ CURRENT LOOKBOOK LOOKBOOK(1) (1).pdf
 
1029-Danh muc Sach Giao Khoa khoi 6.pdf
1029-Danh muc Sach Giao Khoa khoi  6.pdf1029-Danh muc Sach Giao Khoa khoi  6.pdf
1029-Danh muc Sach Giao Khoa khoi 6.pdf
 
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
 
Advanced Views - Calendar View in Odoo 17
Advanced Views - Calendar View in Odoo 17Advanced Views - Calendar View in Odoo 17
Advanced Views - Calendar View in Odoo 17
 
A Critique of the Proposed National Education Policy Reform
A Critique of the Proposed National Education Policy ReformA Critique of the Proposed National Education Policy Reform
A Critique of the Proposed National Education Policy Reform
 
Introduction to AI in Higher Education_draft.pptx
Introduction to AI in Higher Education_draft.pptxIntroduction to AI in Higher Education_draft.pptx
Introduction to AI in Higher Education_draft.pptx
 
TataKelola dan KamSiber Kecerdasan Buatan v022.pdf
TataKelola dan KamSiber Kecerdasan Buatan v022.pdfTataKelola dan KamSiber Kecerdasan Buatan v022.pdf
TataKelola dan KamSiber Kecerdasan Buatan v022.pdf
 
INDIA QUIZ 2024 RLAC DELHI UNIVERSITY.pptx
INDIA QUIZ 2024 RLAC DELHI UNIVERSITY.pptxINDIA QUIZ 2024 RLAC DELHI UNIVERSITY.pptx
INDIA QUIZ 2024 RLAC DELHI UNIVERSITY.pptx
 
Web & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdfWeb & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdf
 
Organic Name Reactions for the students and aspirants of Chemistry12th.pptx
Organic Name Reactions  for the students and aspirants of Chemistry12th.pptxOrganic Name Reactions  for the students and aspirants of Chemistry12th.pptx
Organic Name Reactions for the students and aspirants of Chemistry12th.pptx
 
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
 
The basics of sentences session 2pptx copy.pptx
The basics of sentences session 2pptx copy.pptxThe basics of sentences session 2pptx copy.pptx
The basics of sentences session 2pptx copy.pptx
 
Beyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactBeyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global Impact
 
Sanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdfSanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdf
 
Interactive Powerpoint_How to Master effective communication
Interactive Powerpoint_How to Master effective communicationInteractive Powerpoint_How to Master effective communication
Interactive Powerpoint_How to Master effective communication
 
Mastering the Unannounced Regulatory Inspection
Mastering the Unannounced Regulatory InspectionMastering the Unannounced Regulatory Inspection
Mastering the Unannounced Regulatory Inspection
 

Hippa

  • 1. Redox Medical Center Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules Roderick Laino MHA690: Health Care Capstone Dr. Sherry Grover June 28, 2012
  • 2. Objectives ๏ What is HIPAA? ๏ What is the Organization’s responsibility? Clinician’s responsibility? ๏ What information should be protected? ๏ What can we do as a team, to protect patient health information? ๏ What is the organization’s policy for violators?
  • 3. What is HIPPA? ๏ The HIPAA Privacy Rule provides federal protections for personal health information held by covered entities and gives patients an array of rights, with respect to that information. At the same time, the Privacy Rule is balanced so that it permits the disclosure of personal health information needed for patient care and other important purposes. (www.hhs.gov)  ๏ The Security Rule specifies a series of administrative, physical, and technical safeguards for covered entities to use to assure the confidentiality, integrity, and availability of electronic protected health information. (www.hhs.gov)
  • 4. Who ensures HIPPA compliance ๏ Doctors, nurses, and any allied healthcare workers ๏ Pharmacies ๏ Hospitals, clinics, and nursing homes ๏ Health insurance companies ๏ Health maintenance organizations (HMOs) ๏ Employer group health plans ๏ Certain government programs that pay for health care, such as Medicare and Medicaid. ๏ The Office for Civil Rights enforces the HIPAA Privacy Rule, which protects the privacy of individually identifiable health information; the HIPAA Security Rule, which sets national standards for the security of electronic protected health information; and the confidentiality provisions of the Patient Safety Rule, which protects identifiable information being used to analyze patient safety events and improve patient safety. (www.hhs.gov) ๏ Any Healthcare Clearing House. Healthcare Clearing Houses are any private or public entity that processes or facilitates the processing of nonstandard data elements of health information into standard data elements (www.cms.gov)
  • 5. How does HIPPA relates to you as a “Clinician or Organization” ๏ As an organization, it is our corporate social responsibility to ensure that we protect patient health information. ๏ How do we try to accomplish this? As an organization we can do the following. ๏ By making sure that our website is secure ๏ By educating all of our employees thru annual competency ๏ Having an open door policy for reporting any incident that might be a HIPPA violation ๏ Have an anonymous 1-800 reporting number that it is available 24/7 ๏ Have a non-retaliatory policy for reporting, in the event that it is a false alarm ๏ Have password protection on any computer ๏ Track all activity by personal log in
  • 6. How does HIPPA relates to you as a “Clinician or Organization” ๏ As a clinician, how can you make sure that you are protecting patient health information? ๏ Make sure that you don’t talk out loud about patients, especially in public areas, like the cafeteria, elevator, bathroom, etc, where anyone can over hear patient confidential information. ๏ Log off of your computer when unattended ๏ Don’t share your password to anyone ๏ Call IT if you lose or forget your password ๏ All emails that contains PHI will be automatically encrypted for security ๏ Report any and all suspicious activity
  • 7. Responsibility ๏ Any one who has access to patient health information is responsible to ensure that we comply with the law, for example clinicians, allied healthcare workers, cashiers, medical records employees, medical assistance, etc. ๏ The Organization as a whole is also responsible that we educate, empower and audit any reported incidence. ๏ The organization is also responsible that the website, email and any PHI are being held in a secured site and being protected against hackers and malicious attacks from inside of the company as well as outside.
  • 8. What information are protected? ๏ Protected Health Information. The Privacy Rule protects all "individually identifiable health information" held or transmitted by a covered entity or its business associate, in any form or media, whether electronic, paper, or oral. The Privacy Rule calls this information "protected health information (PHI) ๏ “Individually identifiable health information” is information, including demographic data, that relates to: ๏ An individual’s past, present or future physical or mental health or condition, ๏ The provision of health care to the individual, or ๏ The past, present, or future payment for the provision of health care to the individual
  • 9. What information are protected? ๏ Anything that identifies the individual or for which there is a reasonable basis to believe can be used to identify the individual. Individually identifiable health information includes many common identifiers (e.g., name, address, birth date, Social Security Number). ๏ The Privacy Rule excludes from protected health information, employment records that a covered entity maintains in its capacity as an employer and education and/or certain other records subject to, or defined in, the Family Educational Rights and Privacy Act, 20 U.S.C. §1232g. (U.S. Department of Health & Human Services, 2003, pp.3-4)
  • 10. How to ensure that we don’t violate HIPPA? ๏ The organization has done everything it can in order to be compliant. ๏ We have policies and procedures in place ๏ Pamphlets and brochure to educate patients their rights as well as all the employees ๏ We have annual training as part of annual competency ๏ HIPPA information is available 24/7 in the intranet ๏ We have a compliance officer for any concerns ๏ Every employee have their own password and restricted access to PHI, ๏ All computers and instrument that carries PHI activities are tracked 24/7
  • 11. How to ensure that we don’t violate HIPPA? ๏ The organization has done everything it can in order to be compliant. ๏ We have 800 # available for reporting 24/7 ๏ We have a non-retaliatory policy ๏ Anonymous reporting is also available ๏ HIPPA consent form is mandatory for any PHI to be release to a third party ๏ Automatic log out and save of computer that are idle
  • 12. Zero tolerance to violators ๏ The company takes the HIPPA Act seriously. All practitioners are only to access the PHI of a patient that they have direct contact with. We have a computer alert for all practitioners and they must acknowledge that they are in direct contact with that patient before access is granted. Violations of the HIPPA rules are grounds for termination. ๏ The organization wants to express the seriousness of this issue. We want to make sure that we communicate to you our expectation and we wish that you’ll do the same.
  • 13. Discussion 2-Wk1 Hipaa presentation ๏ References: U.S. Department of Health & Human Services. (2003). OCR privacy brief: Summary of the HIPAA privacy rule. Center for Medicare and Medicaid Services. (2009). HIPPA compliance review analysis and summary of results