1 of 12

HIPAA-�1st lets quiz

Federal Privacy and Security Laws that Protect Patient Information

2 of 12

HIPAA

  • HIPPA is the Health Insurance Portability and Accountability Act of 1996 (Privacy and Security Rule.)

3 of 12

The Individuals’ Rights �Under HIPAA

  • Receive facility’s Notice of Private Practices
  • Inspect and obtain a copy of health records
  • Request restriction of releasing ANY info outside of Health Dept.
  • Request confidential communications.
  • Request amendment to make sure info is correct
  • Info not released without patient consent.

4 of 12

The Covered Entity’s Responsibilities under HIPPA

  • Provide Notice of Privacy Practices to patients with health services.
  • Implement policies and procedures to safeguard individual health and info.
  • Educate entire workforce.
  • Designate private officer
  • & Security officer to monitor compliance and handle complaints.

5 of 12

Who Has to Comply With HIPPA

  • Healthcare Providers

  • Health plans

  • Healthcare clearing houses

  • The Health Department is a covered entity and ALL workforce members must understand and follow HIPPA policies.

6 of 12

Lets Practice

7 of 12

Workforce Member

Workforce members include employees, volunteers, trainees, contractors, and other persons who perform to work for the covered entity regardless of whether they are paid for their services or not.

8 of 12

Protected Health Info

PHI is the individually identifiable info in written, electronic, or verbal form that is created, used, stored and/or disclosed that relates to the past, present, or future physical or mental health of an individual.

9 of 12

PHI Identifiers

  • Patient name, DOB, DOD, Date of Service
  • Geographical subdivisions smaller than a State.
  • Phone #’s, Fax #’s, email address
  • Health plan benefit #’s
  • Certificate/license #’s
  • Vehicle identifiers & serial #’s; license plate #’s.
  • Device identifiers and serial #’s
  • URLs and IP addresses
  • Biometric identifiers
  • Full face photos

10 of 12

Responsibility to Safeguard PHI

  • May work with paper medical records
  • May work with computerized patient info
  • May work have a laptop/PDA w/ patient info
  • May have temporary requested info. Made copies or notes that contain PHI
  • Employees are responsibilities for safeguarding the info they contain.

11 of 12

What If I Don’t Handle PHI.

-You may here individual health info as

you do your day to day work

--DO NOT discuss any info you may have heard

-You may see a neighbor or a friend in one of the clinics.

--Act professionally; be sensitive to the situation.

-You may find a patient record in a place it’s not supposed to be. For instance, you see a used chart folder in the trash can and notice that the patient label has not been removed or marked through.

--You should remedy the situation by removing or marking through the indentifying information. Use your judgment, it may be appropriate to notify a supervisor or the privacy officer.

12 of 12

Questions?

Your assignment for today:

Get into groups of 2-3 people write a script that displays 2 HIPPA Violation. Then rewrite the script to show the correct way a situation should be handled. You group will then act out your scripts in front of the class. Every person in the group should have a part.