+ All Categories
Home > Documents > HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box...

HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box...

Date post: 29-May-2020
Category:
Upload: others
View: 2 times
Download: 0 times
Share this document with a friend
33
HIPAA 101 September 28, 2014
Transcript
Page 1: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

HIPAA 101

September 28, 2014

Page 2: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

Health Insurance Portability and Accountability Act of

1996

It was designed to:

• Make health insurance portable

• Move health care onto a nationally standardized

electronic billing platform

• Prevent fraud, waste and abuse in the health care

system

Page 3: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

There are two parts to HIPAA

• Privacy Rule – What we have to protect

• Security Rule – How we have to protect it

Page 4: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

Protected Health Information (PHI) is individually identifiable health information that is: Created or received by a health care provider, health

plan, employer, or health care clearinghouse that Relates to the past, present, or future physical or

mental health or condition of an individual;

Relates to the provision of health care to an individual

The past, present or future payment for the provision of health care to an individual.

Page 5: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

PHI is so much more than just the medical

record.

PHI includes information by which the

identity of a patient can be determined with

reasonable accuracy and speed either directly

or by reference to other publicly available

information.

Page 6: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

Names Medical Record Numbers Social Security Numbers Account Numbers License/Certification numbers Vehicle Identifiers/Serial numbers/License plate

numbers Internet protocol addresses Health plan numbers Full face photographic images and any

comparable images

Page 7: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

Web universal resource locaters (URLs)

Any dates related to any individual (date of birth)

Telephone numbers

Fax numbers

Email addresses

Biometric identifiers including finger and voice

prints

Any other unique identifying number,

characteristic or code

Page 8: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

You may ask, what is the risk if someone has

identifiable information

Corruption of the medical record

Identity theft

Quinzella Romer

Page 9: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

The Minimum Necessary doctrine seems to trip

up a lot of organizations both in terms of over

disclosing and in “handcuffing”

Use or disclose/release only the minimum

necessary to accomplish intended purposes of

the use, disclosure, or request.

Page 10: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

Internal – what information is needed for the

staff member to be able to perform his or her

job?

External – only that information needed to

accomplish the purpose for which the request

was made

Page 11: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

HIPAA provides for use/disclosure without

authorization for:

• Treatment – providing care

• Payment – getting paid for that care

• Operations – normal business activities of the health

care provider

Page 12: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

Every Covered Entity must have a Privacy

Officer and the designation must be in writing –

board resolution

The designated person to receive and address

all privacy related complaints

Staff HIPAA training

Page 13: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

Administrative, physical and technical

Limit intentional or unintentional use or

disclosure of PHI

Even those that occur as a result of a permitted

use ( i.e. conversations in the hallway)

Page 14: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

Having policies that comply with the Privacy

and Breach Notification rules is not enough

Without written procedures the policy is not

viewed as being effective

Essential to review policies and procedures

periodically and note the review date on the

document

Page 15: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

What is a breach?

An impermissible use or disclosure of

unsecured PHI is presumed to be a breach

unless it can be demonstrated there was a low

probability the PHI was compromised as shown

through a risk assessment

Page 16: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

Unsecured – PHI that has not been rendered

unusable, unreadable or indecipherable to

unauthorized persons through the use of

technology or a method required by the rule

Encryption = secured

Page 17: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

Pursuant to the Final Rule there is a 4 factor

test:

The nature and extent of the PHI involved

(types of identifiers and likelihood of re-

identification)

To whom was the disclosure made (who saw

the PHI)

Was the PHI actually viewed

How was the risk mitigated

Page 18: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

Essential the risk assessment be thorough,

performed in good faith and based on facts

If the risk assessment demonstrates anything

other than a low probability of compromise,

notification of the breach is required

Page 19: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

Over 500 individuals affected requires

notification to media and immediate reporting

to OCR

Less than 500 individuals affected does not

require media notification and can be reported

on an annual basis

Both require notice to the individuals affected

Page 20: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

Cannot over emphasize the importance of

conducting a Security Risk Assessment

Phase 2 audits by OCR are starting now

Without a Security Risk Assessment you are

behind the 8 ball

Page 21: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

Administrative safeguards – policies and

procedures

Technical – firewalls, security patches, etc.

Physical – Where do we put the copier?

Page 22: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

Required Specifications

Addressable Specifications

Page 23: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

Access audits – regular system of monitoring

activity within the system

• System troubleshooting

• Monitor policy enforcement

• Mitigate risks of a security incident

• Monitor employee activities within the record – click

path audit

Page 24: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

Faxes

Automobiles

Mobile devices

• Catholic Health Care Services – lost iPhone resulted

in $600,000 settlement

Page 25: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

Paper – locked shred bins. Avoid the copy

paper box top next to the desk

Electronic media – certified shredder or blunt

destruction

Essential to have a policy on how documents or

media containing PHI are disposed of

Page 26: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

What is a Business Associate?

Company or person that performs or assists in

the performance of a function or activity

involving the use or disclosure of PHI (could

include legal, accounting, etc.)

VERY important to know who your Business

Associates are

Page 27: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

North Memorial Health Care of Minnesota

Unencrypted password protected laptop was

stolen from the locked vehicle of an employee

of a Business Associate with PHI of nearly

10,000 individuals

Page 28: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

North Memorial did not have a business

associate agreement in place with the company

yet gave the company access to the information

systems of the hospital

Failed to conduct a system wide risk

assessment to determine the vulnerabilities of

the system

1.55 million dollar settlement

Page 29: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

No longer complaint based enforcement, now

affirmative cases brought by OCR

Penalties and settlements are growing

Public is becoming hypersensitive to

impermissible use/disclosure of protected

information as the result of the increase in

cyber crimes

Page 30: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

Minimum - $10,000 per violation with an

annual maximum of $250,000 for repeat

violations

Maximum - $50,000 per violation with an

annual maximum of $1.5 million for repeat

violations

Page 31: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

New policies – easy to understand, easy to

follow

Risk Assessment – in process

Considering options for addressing identified

risks (encryption, mobile devices, paper record

storage, etc.)

Increased level of awareness

Page 32: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

Two kinds of organizations – those who have

had a breach and those who are about to have a

breach

When it comes to HIPAA, the old adage is true,

an ounce of prevention is worth a pound of cure

Page 33: HIPAA 101 September 28, 2014 · notification of the breach is required ... Avoid the copy paper box top next to the desk ... breach When it comes to HIPAA, the old adage is true,

Gary N. Jones J.D. CHC, CHPC

[email protected]

Midwest Compliance Associates, LLC

721 W. 1st Street

Cedar Falls, Iowa 50613


Recommended