SlideShare une entreprise Scribd logo
1  sur  22
Télécharger pour lire hors ligne
HIPAA 2023
Latest Guidance and Compliance Focus
Jim Sheldon-Dean
Director of Compliance Services
Lewis Creek Systems, LLC
www.lewiscreeksystems.com
1
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
Agenda
• Overview of HIPAA Regulatory Expectations
• Telemedicine and Communication during (AND after)
the Public Health Emergency
• Issues in Individual Access of Records under HIPAA
• HIPAA Accounting of Disclosures Changes
• Potential and Proposed Rule Changes
• HIPAA Controls and New Technologies
• Q&A
2
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
HIPAA Privacy, Security, & Breach Rules
• Privacy Rule
– 45 CFR §164.5xx; Enforceable since 2003
– Establishes Rights of Individuals
– Controls on Uses and Disclosures
– Access of PHI is a hot button issue for HHS – FORTY-THREE settlements so far
recently in HHS OCR Right of Access initiative
• Security Rule
– 45 CFR §164.3xx; Enforceable since 2005
– Applies to all electronic PHI
– Flexible, customizable approach to health information security
– Uses Risk Analysis to identify and plan the mitigation of security risks
• Breach Notification Rule
– 45 CFR §164.4xx; Enforceable since February 2010
– Requires reporting of all PHI breaches to HHS and individuals
– Extensive/expensive obligations
– Provides examples of what not to do on the HHS “Wall of Shame”:
https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
3
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
Part 1
• Overview of HIPAA Regulatory Expectations
– New Regulatory Directions
– Rule Modifications and Guidance on the COVID-19
Pandemic
– Overdue Regulatory Action
– Court Ruling Limiting Regulations
4
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
Updated Rules for 42 CFR Part 2
• Keeps 42 CFR Part 2 protections on use of SUD data for prosecution or
investigation (as do the changes under the CARES Act)
• Clarification of when the rules apply, definition of “records”
• Access of central registries (such as PDMPs)
• Generalization of consents (such as to entities) (Under the CARES Act allows
use of Part 2 information under HIPAA-like controls, with consent)
• Clarification on allowable disclosures for payment & operations, with a list of
17 example allowable activities
• Better alignment with HIPAA & Common Rule on research
• Rules on clearing personally-owned-by-staff devices of Part 2 data, including
texts and e-mail
• Also revisions for Medical Emergencies and disasters, investigations of
“extremely serious crimes”, and placement of undercover informants
5
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
November 2022 Proposed Rules
• Coordinate 42 CFR Part 2 Rules with HIPAA
– Single prior consent signed by the patient for all future uses and
disclosures for treatment, payment, and health care operations
– Permit the redisclosure of Part 2 records as permitted by the
HIPAA Privacy Rule by recipients that are Part 2 programs, HIPAA
covered entities, and business associates, with certain exceptions.
– Expand prohibitions on the use and disclosure of Part 2 records in
civil, criminal, administrative, or legislative proceedings
– Right to an accounting of disclosures (HIPAA)
– Right to request restrictions on disclosures for treatment,
payment, and health care operations (HIPAA)
– Require disclosures to the Secretary for enforcement
– Apply HIPAA and HITECH Act civil and criminal penalties to Part 2
violations.
– And more…
6
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
How the HIPAA Safe Harbor Law Fits In
• Effective January 5, 2021, the HIPAA Safe Harbor bill amends
the HITECH act to require the Department of Health and Human
Services to incentivize best practice cybersecurity for meeting
HIPAA requirements.
– The legislation directs HHS to take into account a covered entity’s
or business associate’s use of industry-standard security
practices within the course of 12 months, when investigating and
undertaking HIPAA enforcement actions, or other regulatory
purposes.
– Further, the bill requires that HHS take cybersecurity into
consideration when calculating fines related to security incidents.
HHS is also required to decrease the extent and length of an
audit, if it’s determined the impacted entity has indeed met
industry-standard best practice security requirements.
7
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
Telemedicine, HIPAA, and COVID-19
• HHS has issued an enforcement advisory on telemedicine during the
COVID-19 emergency: Relaxed enforcement for using services that
are non-public facing but may not meet HIPAA requirements (such as
a providing a BAA)
– Apple FaceTime, Facebook Messenger video chat, Google Hangouts video, or
Skype
• BUT: Do NOT use public-facing services that are not private
– Facebook Live, Twitch, TikTok, and similar
• And: Once the emergency is over you will need to use HIPAA
compliant services, under a Business Associate Agreement, according
to a HIPAA Security Risk Analysis
• See: https://www.hhs.gov/hipaa/for-professionals/special-topics/emergency-
preparedness/notification-enforcement-discretion-telehealth/index.html
8
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
Part 2
• Issues in Individual Access of Records under
HIPAA
– New Emphasis on Enforcement of Individual Access
Rules
– New Court Ruling Limiting Third-Party Access
Requests
– New Limitation of Business Associate Liability for
Compliance
9
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
• January 12, 2021: $200,000 settlement and CAP for Banner health system,
for taking too long (five and six months) to deliver records
• February 10, 2021: $75,000 and CAP for Renown Health’s failure to transmit
electronic records to a third party as requested
• February 12, 2021: Number 16: $70K and CAP for Sharp HealthCare for a
second lack of response for records request, even after OCR provided help
after the first complaint was investigated
• March 24, 2021: Slow response to records request, requiring two
interventions by HHS OCR – $65K and a CAP for Arbour Hospital
• March 26, 2021: Slow response to records request – $30K and a CAP for
Village Plastic Surgery
• June 2, 2021: Taking two years to deliver a minor child’s medical record -
$5K and a CAP for The Diabetes, Endocrinology & Lipidology Center, Inc.
(“DELC”) of West Virginia
• September 10, 2021: Failure to satisfy request for minor child’s records by
Children’s Hospital Medical Center of Omaha, Nebraska -- $80K and a CAP
• November 30, 2021: FOUR MORE settlements and ONE civil money
penalty, up to $160K with CAPs
10
2021 Access Enforcement Actions
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
• March 28, 2022: Two Enforcement Actions for Right of Access
–Dr. Donald Brockley, D.D.M., a solo dental practitioner in Butler,
Pennsylvania, failed to provide a patient with a copy of their medical
record: $30,000 and a CAP
–Jacob and Associates, a psychiatric medical services provider with two
offices in California: $28,000 and a CAP for violations of the right of
access standard
• September 20, 2022: 3 more settlements, all with Dental Offices, $25K to
$80K and CAPs – rules apply to dentists, too
• December 15, 2022: $20K and a CAP for Health Specialists of Central
Florida, for not providing access to deceased father’s records
• January 3, 2023: Life Hope Labs took too long to provide records, pays
$16,500 and CAP in penalty #43 in the Individual Right of Access initiative
11
2022 and 2023 Access Enforcement Actions
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
So, what are we allowed to do?
• Do what the patient wants
– Meet HIPAA Requirements
– Accommodate what you reasonably can
– Remember! Patient access of information a high priority at HHS
• Meet the Patient’s Needs
– Communication with the office for Prescription Renewals, Scheduling
etc.
– Discussion of particular health issues
– Access of Medical Records, test results
• Do what you can handle properly
– For Patient Care
– For Medical Records
12
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
Part 3
• HIPAA Accounting of Disclosures Changes
– Current Accounting of Disclosures Requirements
– Required Changes and Difficulties Implementing
Them
– Likely Regulation to be Proposed
13
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
Accounting of Disclosures Today
• Individual has right to an accounting of all disclosures of
health information in last six years
• Except for disclosures:
– For Treatment, Payment, and Healthcare Operations
– To the individual; under authorization; associated with
disclosures under §164.502; for facility directories; for
national security; law enforcement; limited data set…
• The Result?
– Number of Accountings requested very low
– Many hospitals have had NO requests for such accountings
since the rule went in to effect in 2003!
– Time and money spent implementing systems and tracking
that are never used – Cost vs. benefit?
14
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
Part 4
• Potential (and Proposed) Rules Changes
– Acknowledgement of Receipt of Notice of Privacy
Practices
– TCPA and Cell Phone Communications
– Getting Back to Normal After the Pandemic
Emergency: Coming soon!
15
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
16
TCPA and Communicating to Cell Phones
• Telephone Consumer Protection Act of 1991 limits calls and
messages to cell phones without consent
• Limits Robo-calling (including reminder calls)
• There are Penalties for, without consent, calling a cell phone
or leaving:
– A payment related message (voice or text)
– A healthcare related message more than one minute
(voice) or 160 characters (text) long; no more than one per
day or three per week
• Includes healthcare reminders, appointment reminders,
etc.
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
TCPA and Communicating to Cell Phones
• Be cautious, especially for any calls or texts relating to billing
• Get consent up front to call or text the number provided for healthcare &
(especially) financial purposes, including reminders & follow-up
• Consent must be written, or
• Consent is considered provided for Healthcare Communications ONLY (NOT
for Payment communications) if:
– the patient provides a phone number, and
– the Notice of Privacy Practices says the patient may be contacted for Treatment,
Payment, and Healthcare Operations, and
– the Notice is acknowledged as received with a signature
• Proposals have been made to change TCPA to allow communications for TPO
purposes without consent, but not yet!
• Meanwhile, the Proposed Privacy Rule changes would eliminate the signed
acknowledgement as a consent, so you’d have to get that separately,
instead
17
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
Part 5
• HIPAA Controls and New Technologies
– Difficulty in Managing Privacy
– Calls for HIPAA Expansions
18
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
New Technologies
• New technologies in health care every day
– Some new technologies will be very useful
– Some new technologies will be a privacy and security
nightmare
• You can’t deny new technologies
– New Technologies should be addressed head-on
– If you ignore them they don’t go away
– Encourage dialog on new technologies and find ways to
use them productively, securely
• Education addressing new technologies is essential
– Prevent improper uses
– Train in appropriate usage
19
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
20
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
New Technologies and HIPAA
• HIPAA can handle new technologies for PHI
– Security Rule is very flexible, adaptable
• New kinds of information, apps, devices, and various uses outside
the formal HIPAA definition of “Protected Health Information”
• New calls for protection of more kinds of patient information than
HIPAA covers
• Proposed HIPAA Privacy Rule changes would address many issues
more clearly
• Don’t be surprised if new laws and regulations result
– Expanded FTC activity
– State laws may also be in the works
– Expansion of existing state breach rules
21
Your to-do list…
✓ Don’t be in denial – willful neglect costs more than
compliance
✓ Keep your ears out for new rules, laws, guidance
✓ Provide individual access – don’t block information
✓ Be careful adopting new technologies
✓ Step up your Security game
✓ Make sure mobile devices are protected
✓ Document your processes for proper methods of
communications with both patients and professionals
✓ Conduct drills in audit and breach response
✓ Make corrections based on results
✓ Always have a plan for moving forward, and follow it!
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
Thank you!
Any Questions?
For additional information, please contact:
Jim Sheldon-Dean
Lewis Creek Systems, LLC
5675 Spear Street, Charlotte, VT 05445
jim@lewiscreeksystems.com
www.lewiscreeksystems.com
22
© Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved
jim@lewiscreeksystems.com www.lewiscreeksystems.com
Register Now

Contenu connexe

Tendances

Health care confidentiality and privacy
Health care confidentiality and privacyHealth care confidentiality and privacy
Health care confidentiality and privacy
sawanda
 
HIPAA Basics
HIPAA BasicsHIPAA Basics
HIPAA Basics
Karna *
 
Welcome to HIPAA Training
Welcome to HIPAA TrainingWelcome to HIPAA Training
Welcome to HIPAA Training
Jonathan Montes
 
Patient Protection and Affordable Care Act
Patient Protection and Affordable Care ActPatient Protection and Affordable Care Act
Patient Protection and Affordable Care Act
Paul English
 
Medical Billing Cycle
Medical Billing CycleMedical Billing Cycle
Medical Billing Cycle
sunnymemon
 
Medicare and medicaid
Medicare and medicaidMedicare and medicaid
Medicare and medicaid
tlwhitt
 

Tendances (20)

Health care confidentiality and privacy
Health care confidentiality and privacyHealth care confidentiality and privacy
Health care confidentiality and privacy
 
HIPAA Basics
HIPAA BasicsHIPAA Basics
HIPAA Basics
 
Keys To HIPAA Compliance
Keys To HIPAA ComplianceKeys To HIPAA Compliance
Keys To HIPAA Compliance
 
Welcome to HIPAA Training
Welcome to HIPAA TrainingWelcome to HIPAA Training
Welcome to HIPAA Training
 
Confidentiality
ConfidentialityConfidentiality
Confidentiality
 
Medical Billing and Coding
Medical Billing and CodingMedical Billing and Coding
Medical Billing and Coding
 
Revenue cycle management updated
Revenue cycle management   updatedRevenue cycle management   updated
Revenue cycle management updated
 
Patient Protection and Affordable Care Act
Patient Protection and Affordable Care ActPatient Protection and Affordable Care Act
Patient Protection and Affordable Care Act
 
Privacy and confidentiality
Privacy and confidentialityPrivacy and confidentiality
Privacy and confidentiality
 
HIPAA and How it Applies to You
HIPAA and How it Applies to YouHIPAA and How it Applies to You
HIPAA and How it Applies to You
 
What is the difference between EMR and EHR?
What is the difference between EMR and EHR?What is the difference between EMR and EHR?
What is the difference between EMR and EHR?
 
Triple aim
Triple aimTriple aim
Triple aim
 
HIPAA Complaince
HIPAA ComplainceHIPAA Complaince
HIPAA Complaince
 
Medical Billing Cycle
Medical Billing CycleMedical Billing Cycle
Medical Billing Cycle
 
Medicare and medicaid
Medicare and medicaidMedicare and medicaid
Medicare and medicaid
 
HIPAA Compliance
HIPAA ComplianceHIPAA Compliance
HIPAA Compliance
 
Confidentiality
ConfidentialityConfidentiality
Confidentiality
 
Medical record
Medical recordMedical record
Medical record
 
Electronic Medical Records
Electronic Medical RecordsElectronic Medical Records
Electronic Medical Records
 
Denial series _ Not medical necessary
Denial series _ Not medical necessaryDenial series _ Not medical necessary
Denial series _ Not medical necessary
 

Similaire à HIPAA in 2023: Changes, Updates, and Best Practices

HIPAA and Patient Access of Information - New Rules and Guidelines
HIPAA and Patient Access of Information - New Rules and GuidelinesHIPAA and Patient Access of Information - New Rules and Guidelines
HIPAA and Patient Access of Information - New Rules and Guidelines
Conference Panel
 
HIPAA, Texting, and E-mail — Using Appropriate Patient and Professional Commu...
HIPAA, Texting, and E-mail — Using Appropriate Patient and Professional Commu...HIPAA, Texting, and E-mail — Using Appropriate Patient and Professional Commu...
HIPAA, Texting, and E-mail — Using Appropriate Patient and Professional Commu...
Conference Panel
 
Hipaa privacy and security 03192014
Hipaa privacy and security 03192014Hipaa privacy and security 03192014
Hipaa privacy and security 03192014
Samantha Haas
 
Hi paa and eh rs
Hi paa and eh rsHi paa and eh rs
Hi paa and eh rs
supportc2go
 
Hi paa and eh rs
Hi paa and eh rsHi paa and eh rs
Hi paa and eh rs
supportc2go
 
Rightscale webinar-hipaa-public-cloud
Rightscale webinar-hipaa-public-cloudRightscale webinar-hipaa-public-cloud
Rightscale webinar-hipaa-public-cloud
RightScale
 

Similaire à HIPAA in 2023: Changes, Updates, and Best Practices (20)

HIPAA Changes for 2022 and Beyond - Today's and Tomorrow's HIPAA Compliance
HIPAA Changes for 2022 and Beyond - Today's and Tomorrow's HIPAA ComplianceHIPAA Changes for 2022 and Beyond - Today's and Tomorrow's HIPAA Compliance
HIPAA Changes for 2022 and Beyond - Today's and Tomorrow's HIPAA Compliance
 
HIPAA and Patient Access of Information - New Rules and Guidelines
HIPAA and Patient Access of Information - New Rules and GuidelinesHIPAA and Patient Access of Information - New Rules and Guidelines
HIPAA and Patient Access of Information - New Rules and Guidelines
 
Medical Records Seminar
Medical Records SeminarMedical Records Seminar
Medical Records Seminar
 
HIPAA, Texting, and E-mail — Using Appropriate Patient and Professional Commu...
HIPAA, Texting, and E-mail — Using Appropriate Patient and Professional Commu...HIPAA, Texting, and E-mail — Using Appropriate Patient and Professional Commu...
HIPAA, Texting, and E-mail — Using Appropriate Patient and Professional Commu...
 
PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...
PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...
PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...
 
Hipaa privacy and security 03192014
Hipaa privacy and security 03192014Hipaa privacy and security 03192014
Hipaa privacy and security 03192014
 
Breaking Down the Latest HIPAA Modifications: What's New in 2024 and Beyond
Breaking Down the Latest HIPAA Modifications: What's New in 2024 and BeyondBreaking Down the Latest HIPAA Modifications: What's New in 2024 and Beyond
Breaking Down the Latest HIPAA Modifications: What's New in 2024 and Beyond
 
HIPAA in the Public Cloud: The Rules Have Been Set - RightScale Compute 2013
HIPAA in the Public Cloud: The Rules Have Been Set - RightScale Compute 2013HIPAA in the Public Cloud: The Rules Have Been Set - RightScale Compute 2013
HIPAA in the Public Cloud: The Rules Have Been Set - RightScale Compute 2013
 
Texting and e mail with patients 2020
Texting and e mail with patients 2020Texting and e mail with patients 2020
Texting and e mail with patients 2020
 
Hi paa and eh rs
Hi paa and eh rsHi paa and eh rs
Hi paa and eh rs
 
HIPAA/HITECH Requirements for FQHCs and the New Omnibus Rule
HIPAA/HITECH Requirements for FQHCs and the New Omnibus RuleHIPAA/HITECH Requirements for FQHCs and the New Omnibus Rule
HIPAA/HITECH Requirements for FQHCs and the New Omnibus Rule
 
Hi paa and eh rs
Hi paa and eh rsHi paa and eh rs
Hi paa and eh rs
 
Update on Texting, E-mail, and HIPAA - Communicating with Patients under the ...
Update on Texting, E-mail, and HIPAA - Communicating with Patients under the ...Update on Texting, E-mail, and HIPAA - Communicating with Patients under the ...
Update on Texting, E-mail, and HIPAA - Communicating with Patients under the ...
 
MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...
MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...
MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...
 
2023 Proposed HIPAA Amendments: What You Need to Know
2023 Proposed HIPAA Amendments: What You Need to Know2023 Proposed HIPAA Amendments: What You Need to Know
2023 Proposed HIPAA Amendments: What You Need to Know
 
HealthCare Compliance - HIPAA and HITRUST
HealthCare Compliance - HIPAA and HITRUSTHealthCare Compliance - HIPAA and HITRUST
HealthCare Compliance - HIPAA and HITRUST
 
HIPAA Privacy and Security
HIPAA Privacy and SecurityHIPAA Privacy and Security
HIPAA Privacy and Security
 
Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017
 
Hipaa for business associates simple
Hipaa for business associates   simpleHipaa for business associates   simple
Hipaa for business associates simple
 
Rightscale webinar-hipaa-public-cloud
Rightscale webinar-hipaa-public-cloudRightscale webinar-hipaa-public-cloud
Rightscale webinar-hipaa-public-cloud
 

Plus de Conference Panel

2023 ICD-10 Coding Revisions for Home Health Agencies
2023 ICD-10 Coding Revisions for Home Health Agencies2023 ICD-10 Coding Revisions for Home Health Agencies
2023 ICD-10 Coding Revisions for Home Health Agencies
Conference Panel
 
Improving Documentation in Pain Management - Upcoming AMA Changes for 2023
Improving Documentation in Pain Management - Upcoming AMA Changes for 2023Improving Documentation in Pain Management - Upcoming AMA Changes for 2023
Improving Documentation in Pain Management - Upcoming AMA Changes for 2023
Conference Panel
 
2023 Evaluation and Management (E/M) Guideline Changes Webinar
2023 Evaluation and Management (E/M) Guideline Changes Webinar2023 Evaluation and Management (E/M) Guideline Changes Webinar
2023 Evaluation and Management (E/M) Guideline Changes Webinar
Conference Panel
 
2023 ICD-10-CM Coding Updates - ConferencePanel
2023 ICD-10-CM Coding Updates - ConferencePanel2023 ICD-10-CM Coding Updates - ConferencePanel
2023 ICD-10-CM Coding Updates - ConferencePanel
Conference Panel
 
2023 ICD-10-CM Coding Updates – Important Guidelines
2023 ICD-10-CM Coding Updates – Important Guidelines2023 ICD-10-CM Coding Updates – Important Guidelines
2023 ICD-10-CM Coding Updates – Important Guidelines
Conference Panel
 
CMS Emergency Services 2022 | Follow Nursing Standards
CMS Emergency Services 2022 | Follow Nursing StandardsCMS Emergency Services 2022 | Follow Nursing Standards
CMS Emergency Services 2022 | Follow Nursing Standards
Conference Panel
 
HIPAA Training for the Compliance Officer – Get Your Guide
HIPAA Training for the Compliance Officer – Get Your GuideHIPAA Training for the Compliance Officer – Get Your Guide
HIPAA Training for the Compliance Officer – Get Your Guide
Conference Panel
 
Outlook of HIPAA in Post-Roe America – Confusion, Concern, Chaos?
Outlook of HIPAA in Post-Roe America – Confusion, Concern, Chaos?Outlook of HIPAA in Post-Roe America – Confusion, Concern, Chaos?
Outlook of HIPAA in Post-Roe America – Confusion, Concern, Chaos?
Conference Panel
 
Mental Health Challenges in the Workplace
Mental Health Challenges in the WorkplaceMental Health Challenges in the Workplace
Mental Health Challenges in the Workplace
Conference Panel
 

Plus de Conference Panel (20)

Healthcare Compliance Training Webinars.pptx
Healthcare Compliance Training Webinars.pptxHealthcare Compliance Training Webinars.pptx
Healthcare Compliance Training Webinars.pptx
 
Hospital Medical Staff Bylaws Problems and Solutions: Update Now!
Hospital Medical Staff Bylaws Problems and Solutions: Update Now!Hospital Medical Staff Bylaws Problems and Solutions: Update Now!
Hospital Medical Staff Bylaws Problems and Solutions: Update Now!
 
Telehealth, and Telemedicine Regulations by CMS and TJC
Telehealth, and Telemedicine Regulations by CMS and TJCTelehealth, and Telemedicine Regulations by CMS and TJC
Telehealth, and Telemedicine Regulations by CMS and TJC
 
2023 ICD-10 Coding Revisions for Home Health Agencies
2023 ICD-10 Coding Revisions for Home Health Agencies2023 ICD-10 Coding Revisions for Home Health Agencies
2023 ICD-10 Coding Revisions for Home Health Agencies
 
CMS CAH Swing Bed Requirements and Changes
CMS CAH Swing Bed Requirements and ChangesCMS CAH Swing Bed Requirements and Changes
CMS CAH Swing Bed Requirements and Changes
 
CMS Hospital Conditions of Participation 2022 Surgery PACU, and Anesthesia St...
CMS Hospital Conditions of Participation 2022 Surgery PACU, and Anesthesia St...CMS Hospital Conditions of Participation 2022 Surgery PACU, and Anesthesia St...
CMS Hospital Conditions of Participation 2022 Surgery PACU, and Anesthesia St...
 
Understanding Patients Eligibility, Copays, Co-Insurance, Past Due Balances 2...
Understanding Patients Eligibility, Copays, Co-Insurance, Past Due Balances 2...Understanding Patients Eligibility, Copays, Co-Insurance, Past Due Balances 2...
Understanding Patients Eligibility, Copays, Co-Insurance, Past Due Balances 2...
 
Sexual Misconduct in the Healthcare Profession 2022 Updates
Sexual Misconduct in the Healthcare Profession 2022 UpdatesSexual Misconduct in the Healthcare Profession 2022 Updates
Sexual Misconduct in the Healthcare Profession 2022 Updates
 
Healthcare Dress Code and Work Appearance Webinar
Healthcare Dress Code and Work Appearance WebinarHealthcare Dress Code and Work Appearance Webinar
Healthcare Dress Code and Work Appearance Webinar
 
Diffuse the Confusion in Coding Injections Infusions
Diffuse the Confusion in Coding Injections InfusionsDiffuse the Confusion in Coding Injections Infusions
Diffuse the Confusion in Coding Injections Infusions
 
Deconstructing the 2023 Split Shared Services Updates
Deconstructing the 2023 Split Shared Services UpdatesDeconstructing the 2023 Split Shared Services Updates
Deconstructing the 2023 Split Shared Services Updates
 
How to Avoid Claim Denials 2022 Updates
How to Avoid Claim Denials 2022 UpdatesHow to Avoid Claim Denials 2022 Updates
How to Avoid Claim Denials 2022 Updates
 
Improving Documentation in Pain Management - Upcoming AMA Changes for 2023
Improving Documentation in Pain Management - Upcoming AMA Changes for 2023Improving Documentation in Pain Management - Upcoming AMA Changes for 2023
Improving Documentation in Pain Management - Upcoming AMA Changes for 2023
 
2023 Evaluation and Management (E/M) Guideline Changes Webinar
2023 Evaluation and Management (E/M) Guideline Changes Webinar2023 Evaluation and Management (E/M) Guideline Changes Webinar
2023 Evaluation and Management (E/M) Guideline Changes Webinar
 
2023 ICD-10-CM Coding Updates - ConferencePanel
2023 ICD-10-CM Coding Updates - ConferencePanel2023 ICD-10-CM Coding Updates - ConferencePanel
2023 ICD-10-CM Coding Updates - ConferencePanel
 
2023 ICD-10-CM Coding Updates – Important Guidelines
2023 ICD-10-CM Coding Updates – Important Guidelines2023 ICD-10-CM Coding Updates – Important Guidelines
2023 ICD-10-CM Coding Updates – Important Guidelines
 
CMS Emergency Services 2022 | Follow Nursing Standards
CMS Emergency Services 2022 | Follow Nursing StandardsCMS Emergency Services 2022 | Follow Nursing Standards
CMS Emergency Services 2022 | Follow Nursing Standards
 
HIPAA Training for the Compliance Officer – Get Your Guide
HIPAA Training for the Compliance Officer – Get Your GuideHIPAA Training for the Compliance Officer – Get Your Guide
HIPAA Training for the Compliance Officer – Get Your Guide
 
Outlook of HIPAA in Post-Roe America – Confusion, Concern, Chaos?
Outlook of HIPAA in Post-Roe America – Confusion, Concern, Chaos?Outlook of HIPAA in Post-Roe America – Confusion, Concern, Chaos?
Outlook of HIPAA in Post-Roe America – Confusion, Concern, Chaos?
 
Mental Health Challenges in the Workplace
Mental Health Challenges in the WorkplaceMental Health Challenges in the Workplace
Mental Health Challenges in the Workplace
 

Dernier

❤️ Zirakpur Call Girl Service ☎️9878799926☎️ Call Girl service in Zirakpur ☎...
❤️ Zirakpur Call Girl Service  ☎️9878799926☎️ Call Girl service in Zirakpur ☎...❤️ Zirakpur Call Girl Service  ☎️9878799926☎️ Call Girl service in Zirakpur ☎...
❤️ Zirakpur Call Girl Service ☎️9878799926☎️ Call Girl service in Zirakpur ☎...
daljeetkaur2026
 
Top 20 Famous Indian Female Pornstars Name List 2024
Top 20 Famous Indian Female Pornstars Name List 2024Top 20 Famous Indian Female Pornstars Name List 2024
Top 20 Famous Indian Female Pornstars Name List 2024
Sheetaleventcompany
 
Gorgeous Call Girls In Pune {9xx000xx09} ❤️VVIP ANKITA Call Girl in Pune Maha...
Gorgeous Call Girls In Pune {9xx000xx09} ❤️VVIP ANKITA Call Girl in Pune Maha...Gorgeous Call Girls In Pune {9xx000xx09} ❤️VVIP ANKITA Call Girl in Pune Maha...
Gorgeous Call Girls In Pune {9xx000xx09} ❤️VVIP ANKITA Call Girl in Pune Maha...
Sheetaleventcompany
 
Call Girl Service In Mumbai ❤️🍑 9xx000xx09 👄🫦Independent Escort Service Mumba...
Call Girl Service In Mumbai ❤️🍑 9xx000xx09 👄🫦Independent Escort Service Mumba...Call Girl Service In Mumbai ❤️🍑 9xx000xx09 👄🫦Independent Escort Service Mumba...
Call Girl Service In Mumbai ❤️🍑 9xx000xx09 👄🫦Independent Escort Service Mumba...
Sheetaleventcompany
 
Call Girl In Indore 📞9235973566📞Just Call Inaaya📲 Call Girls Service In Indor...
Call Girl In Indore 📞9235973566📞Just Call Inaaya📲 Call Girls Service In Indor...Call Girl In Indore 📞9235973566📞Just Call Inaaya📲 Call Girls Service In Indor...
Call Girl In Indore 📞9235973566📞Just Call Inaaya📲 Call Girls Service In Indor...
Sheetaleventcompany
 
Erotic Call Girls Bangalore {7304373326} ❤️VVIP SIYA Call Girls in Bangalore ...
Erotic Call Girls Bangalore {7304373326} ❤️VVIP SIYA Call Girls in Bangalore ...Erotic Call Girls Bangalore {7304373326} ❤️VVIP SIYA Call Girls in Bangalore ...
Erotic Call Girls Bangalore {7304373326} ❤️VVIP SIYA Call Girls in Bangalore ...
Sheetaleventcompany
 
🍑👄Ludhiana Escorts Service☎️98157-77685🍑👄 Call Girl service in Ludhiana☎️Ludh...
🍑👄Ludhiana Escorts Service☎️98157-77685🍑👄 Call Girl service in Ludhiana☎️Ludh...🍑👄Ludhiana Escorts Service☎️98157-77685🍑👄 Call Girl service in Ludhiana☎️Ludh...
🍑👄Ludhiana Escorts Service☎️98157-77685🍑👄 Call Girl service in Ludhiana☎️Ludh...
dilpreetentertainmen
 
Independent Call Girls Bangalore {7304373326} ❤️VVIP POOJA Call Girls in Bang...
Independent Call Girls Bangalore {7304373326} ❤️VVIP POOJA Call Girls in Bang...Independent Call Girls Bangalore {7304373326} ❤️VVIP POOJA Call Girls in Bang...
Independent Call Girls Bangalore {7304373326} ❤️VVIP POOJA Call Girls in Bang...
Sheetaleventcompany
 

Dernier (20)

❤️ Call Girls service In Panchkula☎️9815457724☎️ Call Girl service in Panchku...
❤️ Call Girls service In Panchkula☎️9815457724☎️ Call Girl service in Panchku...❤️ Call Girls service In Panchkula☎️9815457724☎️ Call Girl service in Panchku...
❤️ Call Girls service In Panchkula☎️9815457724☎️ Call Girl service in Panchku...
 
❤️Chandigarh Escorts Service☎️9815457724☎️ Call Girl service in Chandigarh☎️ ...
❤️Chandigarh Escorts Service☎️9815457724☎️ Call Girl service in Chandigarh☎️ ...❤️Chandigarh Escorts Service☎️9815457724☎️ Call Girl service in Chandigarh☎️ ...
❤️Chandigarh Escorts Service☎️9815457724☎️ Call Girl service in Chandigarh☎️ ...
 
Independent Call Girls Service Chandigarh Sector 17 | 8868886958 | Call Girl ...
Independent Call Girls Service Chandigarh Sector 17 | 8868886958 | Call Girl ...Independent Call Girls Service Chandigarh Sector 17 | 8868886958 | Call Girl ...
Independent Call Girls Service Chandigarh Sector 17 | 8868886958 | Call Girl ...
 
❤️Chandigarh Escort Service☎️9814379184☎️ Call Girl service in Chandigarh☎️ C...
❤️Chandigarh Escort Service☎️9814379184☎️ Call Girl service in Chandigarh☎️ C...❤️Chandigarh Escort Service☎️9814379184☎️ Call Girl service in Chandigarh☎️ C...
❤️Chandigarh Escort Service☎️9814379184☎️ Call Girl service in Chandigarh☎️ C...
 
❤️ Zirakpur Call Girl Service ☎️9878799926☎️ Call Girl service in Zirakpur ☎...
❤️ Zirakpur Call Girl Service  ☎️9878799926☎️ Call Girl service in Zirakpur ☎...❤️ Zirakpur Call Girl Service  ☎️9878799926☎️ Call Girl service in Zirakpur ☎...
❤️ Zirakpur Call Girl Service ☎️9878799926☎️ Call Girl service in Zirakpur ☎...
 
Top 20 Famous Indian Female Pornstars Name List 2024
Top 20 Famous Indian Female Pornstars Name List 2024Top 20 Famous Indian Female Pornstars Name List 2024
Top 20 Famous Indian Female Pornstars Name List 2024
 
❤️Amritsar Call Girls Service☎️98151-129OO☎️ Call Girl service in Amritsar☎️ ...
❤️Amritsar Call Girls Service☎️98151-129OO☎️ Call Girl service in Amritsar☎️ ...❤️Amritsar Call Girls Service☎️98151-129OO☎️ Call Girl service in Amritsar☎️ ...
❤️Amritsar Call Girls Service☎️98151-129OO☎️ Call Girl service in Amritsar☎️ ...
 
❤️Chandigarh Escort Service☎️9815457724☎️ Call Girl service in Chandigarh☎️ C...
❤️Chandigarh Escort Service☎️9815457724☎️ Call Girl service in Chandigarh☎️ C...❤️Chandigarh Escort Service☎️9815457724☎️ Call Girl service in Chandigarh☎️ C...
❤️Chandigarh Escort Service☎️9815457724☎️ Call Girl service in Chandigarh☎️ C...
 
💞 Safe And Secure Call Girls Prayagraj 🧿 9332606886 🧿 High Class Call Girl Se...
💞 Safe And Secure Call Girls Prayagraj 🧿 9332606886 🧿 High Class Call Girl Se...💞 Safe And Secure Call Girls Prayagraj 🧿 9332606886 🧿 High Class Call Girl Se...
💞 Safe And Secure Call Girls Prayagraj 🧿 9332606886 🧿 High Class Call Girl Se...
 
Gorgeous Call Girls In Pune {9xx000xx09} ❤️VVIP ANKITA Call Girl in Pune Maha...
Gorgeous Call Girls In Pune {9xx000xx09} ❤️VVIP ANKITA Call Girl in Pune Maha...Gorgeous Call Girls In Pune {9xx000xx09} ❤️VVIP ANKITA Call Girl in Pune Maha...
Gorgeous Call Girls In Pune {9xx000xx09} ❤️VVIP ANKITA Call Girl in Pune Maha...
 
The Events of Cardiac Cycle - Wigger's Diagram
The Events of Cardiac Cycle - Wigger's DiagramThe Events of Cardiac Cycle - Wigger's Diagram
The Events of Cardiac Cycle - Wigger's Diagram
 
Call Girl Service In Mumbai ❤️🍑 9xx000xx09 👄🫦Independent Escort Service Mumba...
Call Girl Service In Mumbai ❤️🍑 9xx000xx09 👄🫦Independent Escort Service Mumba...Call Girl Service In Mumbai ❤️🍑 9xx000xx09 👄🫦Independent Escort Service Mumba...
Call Girl Service In Mumbai ❤️🍑 9xx000xx09 👄🫦Independent Escort Service Mumba...
 
Call Now ☎ 8868886958 || Call Girls in Chandigarh Escort Service Chandigarh
Call Now ☎ 8868886958 || Call Girls in Chandigarh Escort Service ChandigarhCall Now ☎ 8868886958 || Call Girls in Chandigarh Escort Service Chandigarh
Call Now ☎ 8868886958 || Call Girls in Chandigarh Escort Service Chandigarh
 
Call Girl In Indore 📞9235973566📞Just Call Inaaya📲 Call Girls Service In Indor...
Call Girl In Indore 📞9235973566📞Just Call Inaaya📲 Call Girls Service In Indor...Call Girl In Indore 📞9235973566📞Just Call Inaaya📲 Call Girls Service In Indor...
Call Girl In Indore 📞9235973566📞Just Call Inaaya📲 Call Girls Service In Indor...
 
Erotic Call Girls Bangalore {7304373326} ❤️VVIP SIYA Call Girls in Bangalore ...
Erotic Call Girls Bangalore {7304373326} ❤️VVIP SIYA Call Girls in Bangalore ...Erotic Call Girls Bangalore {7304373326} ❤️VVIP SIYA Call Girls in Bangalore ...
Erotic Call Girls Bangalore {7304373326} ❤️VVIP SIYA Call Girls in Bangalore ...
 
💞 Safe And Secure Call Girls Coimbatore 🧿 9332606886 🧿 High Class Call Girl S...
💞 Safe And Secure Call Girls Coimbatore 🧿 9332606886 🧿 High Class Call Girl S...💞 Safe And Secure Call Girls Coimbatore 🧿 9332606886 🧿 High Class Call Girl S...
💞 Safe And Secure Call Girls Coimbatore 🧿 9332606886 🧿 High Class Call Girl S...
 
🍑👄Ludhiana Escorts Service☎️98157-77685🍑👄 Call Girl service in Ludhiana☎️Ludh...
🍑👄Ludhiana Escorts Service☎️98157-77685🍑👄 Call Girl service in Ludhiana☎️Ludh...🍑👄Ludhiana Escorts Service☎️98157-77685🍑👄 Call Girl service in Ludhiana☎️Ludh...
🍑👄Ludhiana Escorts Service☎️98157-77685🍑👄 Call Girl service in Ludhiana☎️Ludh...
 
💸Cash Payment No Advance Call Girls Nagpur 🧿 9332606886 🧿 High Class Call Gir...
💸Cash Payment No Advance Call Girls Nagpur 🧿 9332606886 🧿 High Class Call Gir...💸Cash Payment No Advance Call Girls Nagpur 🧿 9332606886 🧿 High Class Call Gir...
💸Cash Payment No Advance Call Girls Nagpur 🧿 9332606886 🧿 High Class Call Gir...
 
Independent Call Girls Bangalore {7304373326} ❤️VVIP POOJA Call Girls in Bang...
Independent Call Girls Bangalore {7304373326} ❤️VVIP POOJA Call Girls in Bang...Independent Call Girls Bangalore {7304373326} ❤️VVIP POOJA Call Girls in Bang...
Independent Call Girls Bangalore {7304373326} ❤️VVIP POOJA Call Girls in Bang...
 
💸Cash Payment No Advance Call Girls Kolkata 🧿 9332606886 🧿 High Class Call Gi...
💸Cash Payment No Advance Call Girls Kolkata 🧿 9332606886 🧿 High Class Call Gi...💸Cash Payment No Advance Call Girls Kolkata 🧿 9332606886 🧿 High Class Call Gi...
💸Cash Payment No Advance Call Girls Kolkata 🧿 9332606886 🧿 High Class Call Gi...
 

HIPAA in 2023: Changes, Updates, and Best Practices

  • 1. HIPAA 2023 Latest Guidance and Compliance Focus Jim Sheldon-Dean Director of Compliance Services Lewis Creek Systems, LLC www.lewiscreeksystems.com 1 © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 2. Agenda • Overview of HIPAA Regulatory Expectations • Telemedicine and Communication during (AND after) the Public Health Emergency • Issues in Individual Access of Records under HIPAA • HIPAA Accounting of Disclosures Changes • Potential and Proposed Rule Changes • HIPAA Controls and New Technologies • Q&A 2 © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 3. HIPAA Privacy, Security, & Breach Rules • Privacy Rule – 45 CFR §164.5xx; Enforceable since 2003 – Establishes Rights of Individuals – Controls on Uses and Disclosures – Access of PHI is a hot button issue for HHS – FORTY-THREE settlements so far recently in HHS OCR Right of Access initiative • Security Rule – 45 CFR §164.3xx; Enforceable since 2005 – Applies to all electronic PHI – Flexible, customizable approach to health information security – Uses Risk Analysis to identify and plan the mitigation of security risks • Breach Notification Rule – 45 CFR §164.4xx; Enforceable since February 2010 – Requires reporting of all PHI breaches to HHS and individuals – Extensive/expensive obligations – Provides examples of what not to do on the HHS “Wall of Shame”: https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf 3 © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 4. Part 1 • Overview of HIPAA Regulatory Expectations – New Regulatory Directions – Rule Modifications and Guidance on the COVID-19 Pandemic – Overdue Regulatory Action – Court Ruling Limiting Regulations 4 © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 5. Updated Rules for 42 CFR Part 2 • Keeps 42 CFR Part 2 protections on use of SUD data for prosecution or investigation (as do the changes under the CARES Act) • Clarification of when the rules apply, definition of “records” • Access of central registries (such as PDMPs) • Generalization of consents (such as to entities) (Under the CARES Act allows use of Part 2 information under HIPAA-like controls, with consent) • Clarification on allowable disclosures for payment & operations, with a list of 17 example allowable activities • Better alignment with HIPAA & Common Rule on research • Rules on clearing personally-owned-by-staff devices of Part 2 data, including texts and e-mail • Also revisions for Medical Emergencies and disasters, investigations of “extremely serious crimes”, and placement of undercover informants 5 © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 6. November 2022 Proposed Rules • Coordinate 42 CFR Part 2 Rules with HIPAA – Single prior consent signed by the patient for all future uses and disclosures for treatment, payment, and health care operations – Permit the redisclosure of Part 2 records as permitted by the HIPAA Privacy Rule by recipients that are Part 2 programs, HIPAA covered entities, and business associates, with certain exceptions. – Expand prohibitions on the use and disclosure of Part 2 records in civil, criminal, administrative, or legislative proceedings – Right to an accounting of disclosures (HIPAA) – Right to request restrictions on disclosures for treatment, payment, and health care operations (HIPAA) – Require disclosures to the Secretary for enforcement – Apply HIPAA and HITECH Act civil and criminal penalties to Part 2 violations. – And more… 6 © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 7. How the HIPAA Safe Harbor Law Fits In • Effective January 5, 2021, the HIPAA Safe Harbor bill amends the HITECH act to require the Department of Health and Human Services to incentivize best practice cybersecurity for meeting HIPAA requirements. – The legislation directs HHS to take into account a covered entity’s or business associate’s use of industry-standard security practices within the course of 12 months, when investigating and undertaking HIPAA enforcement actions, or other regulatory purposes. – Further, the bill requires that HHS take cybersecurity into consideration when calculating fines related to security incidents. HHS is also required to decrease the extent and length of an audit, if it’s determined the impacted entity has indeed met industry-standard best practice security requirements. 7 © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 8. Telemedicine, HIPAA, and COVID-19 • HHS has issued an enforcement advisory on telemedicine during the COVID-19 emergency: Relaxed enforcement for using services that are non-public facing but may not meet HIPAA requirements (such as a providing a BAA) – Apple FaceTime, Facebook Messenger video chat, Google Hangouts video, or Skype • BUT: Do NOT use public-facing services that are not private – Facebook Live, Twitch, TikTok, and similar • And: Once the emergency is over you will need to use HIPAA compliant services, under a Business Associate Agreement, according to a HIPAA Security Risk Analysis • See: https://www.hhs.gov/hipaa/for-professionals/special-topics/emergency- preparedness/notification-enforcement-discretion-telehealth/index.html 8 © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 9. Part 2 • Issues in Individual Access of Records under HIPAA – New Emphasis on Enforcement of Individual Access Rules – New Court Ruling Limiting Third-Party Access Requests – New Limitation of Business Associate Liability for Compliance 9 © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 10. • January 12, 2021: $200,000 settlement and CAP for Banner health system, for taking too long (five and six months) to deliver records • February 10, 2021: $75,000 and CAP for Renown Health’s failure to transmit electronic records to a third party as requested • February 12, 2021: Number 16: $70K and CAP for Sharp HealthCare for a second lack of response for records request, even after OCR provided help after the first complaint was investigated • March 24, 2021: Slow response to records request, requiring two interventions by HHS OCR – $65K and a CAP for Arbour Hospital • March 26, 2021: Slow response to records request – $30K and a CAP for Village Plastic Surgery • June 2, 2021: Taking two years to deliver a minor child’s medical record - $5K and a CAP for The Diabetes, Endocrinology & Lipidology Center, Inc. (“DELC”) of West Virginia • September 10, 2021: Failure to satisfy request for minor child’s records by Children’s Hospital Medical Center of Omaha, Nebraska -- $80K and a CAP • November 30, 2021: FOUR MORE settlements and ONE civil money penalty, up to $160K with CAPs 10 2021 Access Enforcement Actions © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 11. • March 28, 2022: Two Enforcement Actions for Right of Access –Dr. Donald Brockley, D.D.M., a solo dental practitioner in Butler, Pennsylvania, failed to provide a patient with a copy of their medical record: $30,000 and a CAP –Jacob and Associates, a psychiatric medical services provider with two offices in California: $28,000 and a CAP for violations of the right of access standard • September 20, 2022: 3 more settlements, all with Dental Offices, $25K to $80K and CAPs – rules apply to dentists, too • December 15, 2022: $20K and a CAP for Health Specialists of Central Florida, for not providing access to deceased father’s records • January 3, 2023: Life Hope Labs took too long to provide records, pays $16,500 and CAP in penalty #43 in the Individual Right of Access initiative 11 2022 and 2023 Access Enforcement Actions © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 12. So, what are we allowed to do? • Do what the patient wants – Meet HIPAA Requirements – Accommodate what you reasonably can – Remember! Patient access of information a high priority at HHS • Meet the Patient’s Needs – Communication with the office for Prescription Renewals, Scheduling etc. – Discussion of particular health issues – Access of Medical Records, test results • Do what you can handle properly – For Patient Care – For Medical Records 12 © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 13. Part 3 • HIPAA Accounting of Disclosures Changes – Current Accounting of Disclosures Requirements – Required Changes and Difficulties Implementing Them – Likely Regulation to be Proposed 13 © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 14. Accounting of Disclosures Today • Individual has right to an accounting of all disclosures of health information in last six years • Except for disclosures: – For Treatment, Payment, and Healthcare Operations – To the individual; under authorization; associated with disclosures under §164.502; for facility directories; for national security; law enforcement; limited data set… • The Result? – Number of Accountings requested very low – Many hospitals have had NO requests for such accountings since the rule went in to effect in 2003! – Time and money spent implementing systems and tracking that are never used – Cost vs. benefit? 14 © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 15. Part 4 • Potential (and Proposed) Rules Changes – Acknowledgement of Receipt of Notice of Privacy Practices – TCPA and Cell Phone Communications – Getting Back to Normal After the Pandemic Emergency: Coming soon! 15 © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 16. 16 TCPA and Communicating to Cell Phones • Telephone Consumer Protection Act of 1991 limits calls and messages to cell phones without consent • Limits Robo-calling (including reminder calls) • There are Penalties for, without consent, calling a cell phone or leaving: – A payment related message (voice or text) – A healthcare related message more than one minute (voice) or 160 characters (text) long; no more than one per day or three per week • Includes healthcare reminders, appointment reminders, etc. © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 17. TCPA and Communicating to Cell Phones • Be cautious, especially for any calls or texts relating to billing • Get consent up front to call or text the number provided for healthcare & (especially) financial purposes, including reminders & follow-up • Consent must be written, or • Consent is considered provided for Healthcare Communications ONLY (NOT for Payment communications) if: – the patient provides a phone number, and – the Notice of Privacy Practices says the patient may be contacted for Treatment, Payment, and Healthcare Operations, and – the Notice is acknowledged as received with a signature • Proposals have been made to change TCPA to allow communications for TPO purposes without consent, but not yet! • Meanwhile, the Proposed Privacy Rule changes would eliminate the signed acknowledgement as a consent, so you’d have to get that separately, instead 17 © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 18. Part 5 • HIPAA Controls and New Technologies – Difficulty in Managing Privacy – Calls for HIPAA Expansions 18 © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 19. New Technologies • New technologies in health care every day – Some new technologies will be very useful – Some new technologies will be a privacy and security nightmare • You can’t deny new technologies – New Technologies should be addressed head-on – If you ignore them they don’t go away – Encourage dialog on new technologies and find ways to use them productively, securely • Education addressing new technologies is essential – Prevent improper uses – Train in appropriate usage 19 © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 20. 20 © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com New Technologies and HIPAA • HIPAA can handle new technologies for PHI – Security Rule is very flexible, adaptable • New kinds of information, apps, devices, and various uses outside the formal HIPAA definition of “Protected Health Information” • New calls for protection of more kinds of patient information than HIPAA covers • Proposed HIPAA Privacy Rule changes would address many issues more clearly • Don’t be surprised if new laws and regulations result – Expanded FTC activity – State laws may also be in the works – Expansion of existing state breach rules
  • 21. 21 Your to-do list… ✓ Don’t be in denial – willful neglect costs more than compliance ✓ Keep your ears out for new rules, laws, guidance ✓ Provide individual access – don’t block information ✓ Be careful adopting new technologies ✓ Step up your Security game ✓ Make sure mobile devices are protected ✓ Document your processes for proper methods of communications with both patients and professionals ✓ Conduct drills in audit and breach response ✓ Make corrections based on results ✓ Always have a plan for moving forward, and follow it! © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com
  • 22. Thank you! Any Questions? For additional information, please contact: Jim Sheldon-Dean Lewis Creek Systems, LLC 5675 Spear Street, Charlotte, VT 05445 jim@lewiscreeksystems.com www.lewiscreeksystems.com 22 © Copyright 2023 Lewis Creek Systems, LLC All Rights Reserved jim@lewiscreeksystems.com www.lewiscreeksystems.com Register Now