+ All Categories
Home > Documents > HEALTH INFORMATION SECURITY & COMPLIANCE Charles Nwasor, Xcellent Technologies.

HEALTH INFORMATION SECURITY & COMPLIANCE Charles Nwasor, Xcellent Technologies.

Date post: 15-Dec-2015
Category:
Upload: tre-mitchum
View: 217 times
Download: 0 times
Share this document with a friend
Popular Tags:
21
HEALTH INFORMATION SECURITY & COMPLIANCE Charles Nwasor, Xcellent Technologies
Transcript
Page 1: HEALTH INFORMATION SECURITY & COMPLIANCE Charles Nwasor, Xcellent Technologies.

HEALTH INFORMATION SECURITY & COMPLIANCE

Charles Nwasor,Xcellent Technologies

Page 2: HEALTH INFORMATION SECURITY & COMPLIANCE Charles Nwasor, Xcellent Technologies.

Agenda

2

HIPAA1

Internal Compliance3

2 The New Healthcare Paradigm

Conclusion4

Page 3: HEALTH INFORMATION SECURITY & COMPLIANCE Charles Nwasor, Xcellent Technologies.

3

HIPAA1

Page 4: HEALTH INFORMATION SECURITY & COMPLIANCE Charles Nwasor, Xcellent Technologies.

4

HIPAA – Overview

Sets standards to assure the Confidentiality, Integrity, and Availability of PHI

Health Insurance Portability & Accountability Act (HIPAA)Privacy – individuals’ rights of privacy and standardsSecurity – security of ePHIBreach Notification – reporting breach information

Limits the use and disclosure of confidential information:Protected Health Information (PHI)Electronic Protected Health Information (ePHI)

Page 5: HEALTH INFORMATION SECURITY & COMPLIANCE Charles Nwasor, Xcellent Technologies.

HIPAA – PHI

5

PHI and Personally Identifiable InformationAny information (verbal, electronic, or written) that relates

to a person’s physical or mental health or payment information

Name

Postal Address

All elements of Date

Telephone Number

Fax Number

Email Address

URL

IP Address

Social Security Number

Account Numbers

License Number

Medical Record Number

Health Plan Number

Device Identifier

Vehicle Identifier

Biometric Identifier

Full-face Photos

Any other unique identifying number

Genetic information

Page 6: HEALTH INFORMATION SECURITY & COMPLIANCE Charles Nwasor, Xcellent Technologies.

HIPAA – CIA Triad

6

Confidentiality – keeping information from unauthorized access

Integrity – safeguarding against unauthorized modification

Availability – assuring the constant availability of information

Page 7: HEALTH INFORMATION SECURITY & COMPLIANCE Charles Nwasor, Xcellent Technologies.

HIPAA – Privacy Rule

7

Establishes rights of privacy and standards for disclosure

Permitted Disclosures Personal Representatives

Treatment, Payment and Healthcare Operations

Written Authorization/Verbal Consent

De-identified Data

Required Disclosures Public Health Activities

Law Enforcement

Verification Requirements

Notice of Privacy Practices

Page 8: HEALTH INFORMATION SECURITY & COMPLIANCE Charles Nwasor, Xcellent Technologies.

HIPAA – Security Rule

8

Requires control measures to safeguard the confidentiality, integrity and availability of electronic Protected Health Information (ePHI)

Organizational Requirements – Business Associate Agreements (BAAs)

Security Standards Administrative

Physical

Technical

Security Management Process

Information Access Management

Security Awareness and Training

Page 9: HEALTH INFORMATION SECURITY & COMPLIANCE Charles Nwasor, Xcellent Technologies.

HIPAA – Breach Notification Rule

9

Requires notifications to authorities and/or patients when unsecured PHI has been breached

Defines Breach as the inappropriate use or disclosure that compromises the security and privacy of PHI

Exceptions Unintentional Acquisition by a workforce member

Inadvertent Disclosure between workforce members

Recipient can not reasonably retain the information

Unsecured PHI – is PHI that has not been rendered unreadable or indecipherable to unauthorized persons

Page 10: HEALTH INFORMATION SECURITY & COMPLIANCE Charles Nwasor, Xcellent Technologies.

10

2 The New Healthcare Paradigm

Page 11: HEALTH INFORMATION SECURITY & COMPLIANCE Charles Nwasor, Xcellent Technologies.

The New Healthcare Paradigm

11

Page 12: HEALTH INFORMATION SECURITY & COMPLIANCE Charles Nwasor, Xcellent Technologies.

12

Internal Compliance3

Page 13: HEALTH INFORMATION SECURITY & COMPLIANCE Charles Nwasor, Xcellent Technologies.

Internal Compliance Framework

13

Assess Risk •Security Risk Assessment

Plan Corrective Action •Prioritize Controls

Create & Implement Control Measures

•Remediate

Page 14: HEALTH INFORMATION SECURITY & COMPLIANCE Charles Nwasor, Xcellent Technologies.

Internal Compliance Framework

14

Information Security Policy & Technical Controls Acceptable Use Access controls & Physical Security Secure Software & Malicious Code Security Incident Management Sanctions Breach Notification Workforce Security Security Awareness and Training

Proper Conduct and Authorized Disclosures

Page 15: HEALTH INFORMATION SECURITY & COMPLIANCE Charles Nwasor, Xcellent Technologies.

Internal Compliance Framework

15

Page 16: HEALTH INFORMATION SECURITY & COMPLIANCE Charles Nwasor, Xcellent Technologies.

Impacts of Non-Compliance

16

Regulatory Fines

Lawsuits and Liability

Loss of Business

Professional Sanctions

Page 17: HEALTH INFORMATION SECURITY & COMPLIANCE Charles Nwasor, Xcellent Technologies.

Current Examples

17

Hospice of North Idaho - $50,000

Massachusetts Eye and Ear Associates Inc. - $1.5 Million

River Falls Medical Clinic – 2,400 Patient Records stolen

Shands Jacksonville Clinic – 261 Patient Records photographed

Goldthwait Associates, a Billing Service Provider - $140,000

Phoenix Cardiac Surgery, P.C. - $100,000

Page 18: HEALTH INFORMATION SECURITY & COMPLIANCE Charles Nwasor, Xcellent Technologies.

18

Conclusion4

Page 19: HEALTH INFORMATION SECURITY & COMPLIANCE Charles Nwasor, Xcellent Technologies.

19

Assuring the Privacy and Security of Patients’ Information is a vital component of providing healthcare.

Page 20: HEALTH INFORMATION SECURITY & COMPLIANCE Charles Nwasor, Xcellent Technologies.

Questions

20

Page 21: HEALTH INFORMATION SECURITY & COMPLIANCE Charles Nwasor, Xcellent Technologies.

21

Xcellent Technologies43155 Main Street Suite 2210-DNovi, MI 48375

(248) 956.0538 [email protected]

http://www.xcellenttechnologies.com


Recommended