SlideShare a Scribd company logo
1 of 40
Download to read offline
KEYS TO HIPAA
COMPLIANCE
for CAAP Practice Managers
Amy Wasdin, RN, MBA, CPHRM
Patient Safety Risk Manager II, Dept. of Patient Safety and Risk Management
The Doctors Company
March 17, 2016
DISCLOSURE STATEMENT
The Doctors Company would like to disclose that no one in a
position to control or influence the content of this activity has
reported relevant financial relationships with commercial
interests.
The information and guidelines contained in this activity are
generalized and may not apply to all practice situations. The
faculty recommends that legal advice be obtained from a
qualified attorney for specific application to your practice. The
information is intended for educational purposes and should be
used as a reference guide only.
2 KEYS TO HIPAA COMPLIANCE for Practice Managers
OBJECTIVES
After completing this activity, learners will be able to:
 Review the purpose of the HIPAA Privacy and Security Rules
 Discuss the 2013 Omnibus Rule and its impact on:
− Disclosures of Protected Health Information,
− Patient Rights, and
− Business Associates
 Describe the notifications necessary for a breach of PHI.
 Outline the steps necessary for HIPAA compliance in a medical practice.
KEYS TO HIPAA COMPLIANCE for Practice Managers3
I never had a policy;
I have just tried to do my very best each
and every day.
--Abraham Lincoln
1809-1865
How HIPAA compliant are you?
Select one:
A. I am 100% confident that our practice is HIPAA
compliant.
B. I am fairly certain that our practice is HIPAA
compliant but I’m not sure.
C. Our practice is not HIPAA compliant.
D. What’s HIPAA?
5 KEYS TO HIPAA COMPLIANCE for Practice Managers
KEY CONCEPTS UNDER HIPAA
 Protected Health Information (PHI)
− All individually identifiable health information
− Held or transmitted by a covered entity or its business associate
− In any form or media, whether electronic, paper, or oral
 Covered Entity (CE)
− Health plan or health care clearinghouse
− Health care provider
 Business Associates (BA)
− Persons or organizations that perform certain functions on behalf of a
CE (billing, claims processing, data analysis)
6 KEYS TO HIPAA COMPLIANCE for Practice Managers
OVERVIEW OF HIPAA
Healthcare Insurance Portability and Accountability Act:
the Privacy Rule and the Security Rule
 Protects privacy and confidentiality of PHI
 Assures security of electronic information
 The overall idea:
− Assure information is properly protected, but still promote flow and use
of technology to facilitate care
 Some state laws are more stringent than HIPAA
− If so, state law takes precedent over federal HIPAA
7 KEYS TO HIPAA COMPLIANCE for Practice Managers
HIPAA VIOLATIONS
ON THE RISE…
 Total complaints received thru Dec 31, 2015:
125,4451
 2014 saw a 25% increase in HIPAAA breaches2
− 2013: Loss and theft of laptops and portable devices.
− 2014: “The year of the hacker” - CHS: 4.5 million patients
 Paper records are as vulnerable, or more, than
electronic records3
[1] HHS Compliance and Enforcement Numbers at a Glance. Mar 11 2016. www.hhs.gov
[2] 2014 Saw 25% Increase in HIPAA Breaches. Mar 11 2016. www.hipaajournal.com
[3] HIPAA in a HITECH World: HIPAA Violations on the Rise. Smart Data Collective, March 25, 2013
8 KEYS TO HIPAA COMPLIANCE for Practice Managers
HIPAA FINES…
 Alaska DHHS fined $1.7 million
− USB device stolen from employee vehicle
 Cignet Health fined $4.3 million
− Failure to provide medical records to 41 patients
 UCLA fined $865,500
− Snooping employees
 CVS fined $2.25 million
− Disposal of PHI in trashcans
 Blue Cross of Tennessee fined $1.5 million
− Unencrypted laptops stolen
9 KEYS TO HIPAA COMPLIANCE for Practice Managers
DATA BREACH:
GEORGIA HOSPICE GROUP
Unencrypted company laptop containing personal health
information was stolen from an employee's car in 2013.
Nearly 2,000 patients affected by the breach. Officials say
the laptop contained patient names, addresses, phone
numbers, dates of birth, Social Security numbers, insurance
numbers, clinical diagnoses and provider names.
Healthcare IT News - February 2013
10 KEYS TO HIPAA COMPLIANCE for Practice Managers
CARDIAC SURGERY PRACTICE
April 2012–Phoenix Cardiac Surgery
 $100,000 with Corrective Action Plan
 Failed to implement policies to safeguard PHI
 Failed to document training of employees on Privacy
and Security Rules
 Failed to identify a security official and conduct
risk analysis
 Failed to have BA agreements with Internet based
e-mail and calendar services where provision of the
service included storage of and access to its PHI
11 KEYS TO HIPAA COMPLIANCE for Practice Managers
PHI 18 IDENTIFIERS
 Name
 Medical record number
 Health plan beneficiary number
 Device identifiers and serial
numbers
 Vehicle identifiers and serial
numbers
 Biometric identifiers
(i.e., finger and voice prints)
 Full face photos and other
comparable images
 Any other unique identifying
number, code, or characteristic
 Postal address
 All elements of dates except year
 Telephone number
 Fax number
 E-mail address
 URL address (Uniform Resource
Locator or web address)
 IP security (Internet Protocol
address numbers)
 Social Security number
 Account numbers
 License numbers
12 KEYS TO HIPAA COMPLIANCE for Practice Managers
Patient consent not required for…
 Use in treatment, payment, or operations (TPO)
 When records are subpoenaed
− Check with MPL carrier for subpoena validity
 Public interest or public health activities–required
by law:
− Mandated report of abuse to proper agencies
− Preventing and controlling disease–CDC reports
− FDA
AUTHORIZED
USE AND DISCLOSURE
13 KEYS TO HIPAA COMPLIANCE for Practice Managers
AUTHORIZED
USE AND DISCLOSURE
Most of the time…
 Valid Authorization is required to release records to
another party
Specific consent required for…
 Psychotherapy notes
 Alcohol and drug abuse treatment program notes
 Participation in research studies
−Even for re-disclosure of any of the above
14 KEYS TO HIPAA COMPLIANCE for Practice Managers
(continued)
SECURITY SAFEGUARDS
 Administrative
– Security Risk Assessment
– Designated Privacy Officer
– Policies and Procedures
– Staff training
 Physical
 Technical
15 KEYS TO HIPAA COMPLIANCE for Practice Managers
THE FINAL
OMNIBUS HIPAA RULE
 Effective March 26, 2013
 Enforcement began September 23, 2013
− HITECH Modification
− HIPAA Enforcement Rule
− Breach Notification Rule
16 KEYS TO HIPAA COMPLIANCE for Practice Managers
WHO DID
THE CHANGES AFFECT?
 HIPAA Covered Entities:
− Healthcare providers, health systems, health plans, clearinghouses
 HIPAA Business Associates and subcontractors:
− Vendors who contract with Covered Entities and access protected
health information (PHI)
−Examples: Technology vendors, service organizations,
accountable care organizations, third party administrators
17 KEYS TO HIPAA COMPLIANCE for Practice Managers
OMNIBUS RULE - HITECH
 Holds BA’s directly liable for compliance;
 Strengthens limitation on use and disclosure
of PHI;
 Expands individual’s rights
How does this impact practice? …
Notice of Privacy Practices (NPP)
18 KEYS TO HIPAA COMPLIANCE for Practice Managers
NPP MODIFICATIONS
 Prohibition on the sale of PHI without authorization
 Duty of CE to notify affected individuals of a breach
of unsecured PHI
 Right to restrict disclosures of PHI to health plan for
care that was paid out of pocket in full
 For CE that stated intent to fundraise in NPP, must
also advise individual of the right to opt out of
receiving fundraising communications from CE
19 KEYS TO HIPAA COMPLIANCE for Practice Managers
NPP NOTIFICATION
TO PATIENTS
 Must make the NPP available upon request on or
after the effective date of the revision
 Must make the NPP available at the service
delivery site and post the NPP in a clear and
prominent location
 A health care provider is required to give a copy of
its NPP only to new patients—and not all
individuals seeking treatment
20 KEYS TO HIPAA COMPLIANCE for Practice Managers
OMNIBUS – HIPAA
ENFORCEMENT RULE
Modifies privacy, security, and enforcement rule
of HIPAA
How does this impact the practice? ...
Penalties
21 KEYS TO HIPAA COMPLIANCE for Practice Managers
OMNIBUS – BREACH
NOTIFICATION RULE
Establishes a process for notifying patients and HHS
when there is a breach of unsecured PHI.
How does this impact the practice? ...
CE’s are required to notify patients.
22 KEYS TO HIPAA COMPLIANCE for Practice Managers
BREACH OF PHI
Any acquisition, access, use or disclosure
not permitted is a Breach…
UNLESS
the CE or BA demonstrates
a low probability of PHI compromise.
23 KEYS TO HIPAA COMPLIANCE for Practice Managers
BREACH NOTIFICATION
OF UNSECURED PHI
 Applies to breach of unsecured PHI
 Applies to covered entities and business associates
 Business Associates notify Covered Entity
 Covered entity has burden to notify
patient (unencrypted)
 Must notify each individual affected by the breach
(written notification within 60 days of discovery)
 Discovery date = first date known
24 KEYS TO HIPAA COMPLIANCE for Practice Managers
BREACH EXCEPTIONS
 Unintentional acquisition, access, or use by
workforce member with no further impermissible use
 Inadvertent disclosure from one authorized person to
another or CE or BA and no further impermissible use
 Recipient could not reasonably have retained the PHI
 Encrypted data per OCR guidance
25 KEYS TO HIPAA COMPLIANCE for Practice Managers
BREACH
NOTIFICATION REQUIREMENTS
 Individual
− Contact by phone if urgent
− Written breach notification – first class mail unless e-mail preferred
 HHS
− <500 = Annual log report
− >500 = Media notice and immediate notice HHS Secretary
Annual report to HHS of all breaches
 Media
− <500 residents of a state or jurisdiction
− Insufficient contact information for 10 or more individuals
26 KEYS TO HIPAA COMPLIANCE for Practice Managers
BREACH
NOTIFICATION REQUIREMENTS
 What happened?
 What information was breached?
 What steps the patient should take for protection?
 What the CE is doing to investigate, mitigate and prevent
future incidents?
 CE contact information
 Adhere to HIPAA Compliance plan for breach
27 KEYS TO HIPAA COMPLIANCE for Practice Managers
(continued)
BREACH RESPONSE
–WHAT IS YOUR PLAN?
 Determine root cause of breach
 Identify gaps in compliance that led to breach
 Provide evidence that root cause has been addressed and
gaps corrected
28 KEYS TO HIPAA COMPLIANCE for Practice Managers
TOP FIVE ISSUES
IN INVESTIGATED CASES
OCR took corrective action most often on…
 Impermissible use and disclosure
 Safeguards
− Not in place–fax, email, computer accessibility, etc.
 Access
− Access to records was granted or not granted improperly
 Minimum necessary
− More information than needed was disclosed (e.g., phone message)
 Notice of privacy practices
– Not given
29 KEYS TO HIPAA COMPLIANCE for Practice Managers
BUSINESS ASSOCIATES
AGREEMENTS
 Business Associate Agreements must be updated to include
specific new provisions
 Existing agreements, entered before January 25, 2013, may
operate until agreement is amended / renewed, or until
September 22, 2014, whichever is earlier
 Covered Entities and Business Associates will need to
modify agreements and allocate risk through use of
insurance requirements and indemnity provisions
30 KEYS TO HIPAA COMPLIANCE for Practice Managers
PUTTING IT ALL TOGETHER
WHAT ACTIONS ARE REQUIRED?
 Perform risk assessment.
 Establish risk management plan to address and manage
areas of vulnerability.
 Designate a HIPAA Security officer.
 Encrypt all devices that contact PHI
 Have written policies on Sanctions and Breach Notification
 Train staff on how to protect PHI and ensure your policies
are compliance with HIPAA
 Audit/Test physical and electronic security policies and
procedures regularly
 Documentation
32 KEYS TO HIPAA COMPLIANCE for Practice Managers
IF NOT ALREADY ADDRESSED…
 Update Notice of Privacy Practices
 Revise all Business Associates Agreements
33 KEYS TO HIPAA COMPLIANCE for Practice Managers
Testing Your Compliance
Select One:
A. I am 100% confident that our practice is HIPAA
compliant.
B. I am fairly certain that our practice is HIPAA
compliant but I’m not sure.
C. Our practice is not HIPAA compliant.
D. What’s HIPAA?
34 KEYS TO HIPAA COMPLIANCE for Practice Managers
TIPS FOR
PRIVACY AND SECURITY
 Limit access to a “need to know” basis
 Do not conduct discussion in elevators, waiting area, or
other public areas
 If you see a patient in a public place, be careful in greeting
him/her
 Obtain patient’s permission before discussing
care/treatment if there is someone with him/her
 Keep voices down when discussing PHI
 Log off computer when done
35 KEYS TO HIPAA COMPLIANCE for Practice Managers
TIPS FOR
PRIVACY AND SECURITY
 Use password protected or encrypted systems
 Never share your password
 Protect zip drives, laptop, PDA from loss
 Never leave documents unattended
 Do not put PHI in the trash
 Avoid taking records out of the office if possible
 Obtain written permission before leaving voicemail
messages or emailing
 Confirm fax numbers before sending and use a
confidentiality statement on your cover sheet
36 KEYS TO HIPAA COMPLIANCE for Practice Managers
(continued)
RESOURCES
 Security Risk Assessment – HealthIT.gov
www.healthit.gov/providers-professionals/security-risk-assessment
 Sample Notice of Privacy Practices-English
www.hhs.gov/ocr/privacy/hipaa/npp_fullpage_hc_provider.pdf
 Sample Business Associates Agreement
www.hhs.gov/ocr/privacy/hipaa/understanding/coveredentities/contractpro
v.html
 Take Steps to Protect and Secure Information When Using a Mobile Device
www.healthit.gov/sites/default/files/fact-sheet-take-steps-to-protect-
information.pdf
 Security Rule Educational Paper Series
http://www.hhs.gov/hipaa/for-professionals/security/guidance/index.html
37 KEYS TO HIPAA COMPLIANCE for Practice Managers
The key to wisdom is
knowing all the right questions.
--John Simone, Sr. --
Contact Information
For additional Patient Safety information,
please visit our Web site at:
www.thedoctors.com
Amy Wasdin, RN, MBA, CPHRM
Patient Safety Risk Manager II, Southeast
Department of Patient Safety and Risk Management
800-421-2368, ext 6728
Email: awasdin@thedoctors.com
----------------------------------------------------------------------------------------------------------------
Nelson Guzman, CIC, CRM
President, CBIZ Trinity
Southeast Regional Healthcare Director, CBIZ Insurance Services
Mobile: 404-791-8822
Email: nguzman@cbiztrinity.com
Evan Orvis, Sales Executive
Mobile: 770-712-3903
Direct: 470-282-2536
Email: eorvis@cbiz.com
Kathy Alba, CISR, CLCS
Senior Account Manager
Direct: 678-389-7858
Email: kalba@cbiz.com
39 KEYS TO HIPAA COMPLIANCE for Practice Managers
THANK YOU
We relentlessly defend, protect, and reward
the practice of good medicine.

More Related Content

What's hot (20)

HIPAA for Dummies
HIPAA for DummiesHIPAA for Dummies
HIPAA for Dummies
 
Hipaa overview 073118
Hipaa overview 073118Hipaa overview 073118
Hipaa overview 073118
 
HIPAA AND INFORMATION TECHNOLOGY
HIPAA AND INFORMATION TECHNOLOGYHIPAA AND INFORMATION TECHNOLOGY
HIPAA AND INFORMATION TECHNOLOGY
 
HIPAA
HIPAAHIPAA
HIPAA
 
HIPAA Compliance
HIPAA ComplianceHIPAA Compliance
HIPAA Compliance
 
Confidentiality
ConfidentialityConfidentiality
Confidentiality
 
HIPAA Audio Presentation
HIPAA  Audio PresentationHIPAA  Audio Presentation
HIPAA Audio Presentation
 
Hipaa for business associates simple
Hipaa for business associates   simpleHipaa for business associates   simple
Hipaa for business associates simple
 
Hippa
HippaHippa
Hippa
 
HIPAA Compliance for Developers
HIPAA Compliance for DevelopersHIPAA Compliance for Developers
HIPAA Compliance for Developers
 
Protecting patients confidentiality slide presentation
Protecting patients confidentiality slide presentationProtecting patients confidentiality slide presentation
Protecting patients confidentiality slide presentation
 
HIPAA Basics by Brian Fleetham
HIPAA Basics by Brian FleethamHIPAA Basics by Brian Fleetham
HIPAA Basics by Brian Fleetham
 
HealthCare Compliance - HIPAA and HITRUST
HealthCare Compliance - HIPAA and HITRUSTHealthCare Compliance - HIPAA and HITRUST
HealthCare Compliance - HIPAA and HITRUST
 
Hipaa ppt june 6 2014
Hipaa ppt june 6 2014Hipaa ppt june 6 2014
Hipaa ppt june 6 2014
 
HIPAA
HIPAAHIPAA
HIPAA
 
The Basics of HIPAA
The Basics of HIPAA The Basics of HIPAA
The Basics of HIPAA
 
HITRUST Certification
HITRUST CertificationHITRUST Certification
HITRUST Certification
 
HIPAA Privacy & Security
HIPAA Privacy & SecurityHIPAA Privacy & Security
HIPAA Privacy & Security
 
ISO 27001:2022 Introduction
ISO 27001:2022 IntroductionISO 27001:2022 Introduction
ISO 27001:2022 Introduction
 
Hipaa training
Hipaa trainingHipaa training
Hipaa training
 

Viewers also liked (13)

Tik bab 6
Tik bab 6Tik bab 6
Tik bab 6
 
El agua
El aguaEl agua
El agua
 
4.28
4.284.28
4.28
 
香港六合彩
香港六合彩香港六合彩
香港六合彩
 
Abdallah Mostafa Salem updated
Abdallah Mostafa Salem updatedAbdallah Mostafa Salem updated
Abdallah Mostafa Salem updated
 
Jon lang
Jon langJon lang
Jon lang
 
Incredibly [Differently] Abled Artists
Incredibly [Differently] Abled ArtistsIncredibly [Differently] Abled Artists
Incredibly [Differently] Abled Artists
 
Case presentation - Recognizing PWD Productivity (TWH)
Case presentation - Recognizing PWD Productivity (TWH)Case presentation - Recognizing PWD Productivity (TWH)
Case presentation - Recognizing PWD Productivity (TWH)
 
Charlotte Brontë
Charlotte BrontëCharlotte Brontë
Charlotte Brontë
 
Top 15 Art Start-Ups in India
Top 15 Art Start-Ups in IndiaTop 15 Art Start-Ups in India
Top 15 Art Start-Ups in India
 
Computational Methods for detection of somatic mutations at 0.1% frequency fr...
Computational Methods for detection of somatic mutations at 0.1% frequency fr...Computational Methods for detection of somatic mutations at 0.1% frequency fr...
Computational Methods for detection of somatic mutations at 0.1% frequency fr...
 
B2B Social Media Strategy
B2B Social Media StrategyB2B Social Media Strategy
B2B Social Media Strategy
 
Glammories Physical Setup Company Profile
Glammories Physical Setup Company ProfileGlammories Physical Setup Company Profile
Glammories Physical Setup Company Profile
 

Similar to Keys To HIPAA Compliance

Health Insurance and Portability and Accountability Act
Health Insurance and Portability and Accountability ActHealth Insurance and Portability and Accountability Act
Health Insurance and Portability and Accountability Actসারন দাস
 
Marc etienne week1 discussion2 presentation
Marc etienne week1 discussion2 presentationMarc etienne week1 discussion2 presentation
Marc etienne week1 discussion2 presentationMarcEtienne6
 
HIPAA INSERVICE 2017
HIPAA INSERVICE 2017 HIPAA INSERVICE 2017
HIPAA INSERVICE 2017 Meg Oser
 
Insurance
InsuranceInsurance
InsuranceJLS10
 
Introduction to HIPAA for Healthcare Professionals by OUP
Introduction to HIPAA for Healthcare Professionals by OUPIntroduction to HIPAA for Healthcare Professionals by OUP
Introduction to HIPAA for Healthcare Professionals by OUPAtlantic Training, LLC.
 
Mha 690 week one discussion ii
Mha 690 week one discussion iiMha 690 week one discussion ii
Mha 690 week one discussion iibeleza1669
 
Mha 690 week one discussion ii
Mha 690 week one discussion iiMha 690 week one discussion ii
Mha 690 week one discussion iibeleza1669
 
HIPAA Final Omnibus Rule Playbook
HIPAA Final Omnibus Rule PlaybookHIPAA Final Omnibus Rule Playbook
HIPAA Final Omnibus Rule PlaybookElizabeth Dimit
 
how to really implement hipaa presentation
how to really implement hipaa presentationhow to really implement hipaa presentation
how to really implement hipaa presentationProvider Resources Group
 
HIPAA-Compliant App Development Guide for the Healthcare Industry.pdf
HIPAA-Compliant App Development Guide for the Healthcare Industry.pdfHIPAA-Compliant App Development Guide for the Healthcare Industry.pdf
HIPAA-Compliant App Development Guide for the Healthcare Industry.pdfSuccessiveDigital
 
The Intersection of OCR Enforcement and Health Care Data Privacy & Security
The Intersection of OCR Enforcement and Health Care Data Privacy & SecurityThe Intersection of OCR Enforcement and Health Care Data Privacy & Security
The Intersection of OCR Enforcement and Health Care Data Privacy & SecurityPolsinelli PC
 
Knowing confidentiality
Knowing confidentialityKnowing confidentiality
Knowing confidentialityjessie66
 
The Health Insurance Portability and Accountability Act 
The Health Insurance Portability and Accountability Act The Health Insurance Portability and Accountability Act 
The Health Insurance Portability and Accountability Act Kartheek Kein
 

Similar to Keys To HIPAA Compliance (20)

Health Insurance and Portability and Accountability Act
Health Insurance and Portability and Accountability ActHealth Insurance and Portability and Accountability Act
Health Insurance and Portability and Accountability Act
 
Marc etienne week1 discussion2 presentation
Marc etienne week1 discussion2 presentationMarc etienne week1 discussion2 presentation
Marc etienne week1 discussion2 presentation
 
HIPAA INSERVICE 2017
HIPAA INSERVICE 2017 HIPAA INSERVICE 2017
HIPAA INSERVICE 2017
 
Insurance
InsuranceInsurance
Insurance
 
Introduction to HIPAA for Healthcare Professionals by OUP
Introduction to HIPAA for Healthcare Professionals by OUPIntroduction to HIPAA for Healthcare Professionals by OUP
Introduction to HIPAA for Healthcare Professionals by OUP
 
Mha 690 week one discussion ii
Mha 690 week one discussion iiMha 690 week one discussion ii
Mha 690 week one discussion ii
 
Mha 690 week one discussion ii
Mha 690 week one discussion iiMha 690 week one discussion ii
Mha 690 week one discussion ii
 
Hipaa basics
Hipaa basicsHipaa basics
Hipaa basics
 
Hipaa
HipaaHipaa
Hipaa
 
Hipaa inservice
Hipaa inserviceHipaa inservice
Hipaa inservice
 
Joint Commission Inservice Hipaa
Joint Commission Inservice HipaaJoint Commission Inservice Hipaa
Joint Commission Inservice Hipaa
 
HIPAA Final Omnibus Rule Playbook
HIPAA Final Omnibus Rule PlaybookHIPAA Final Omnibus Rule Playbook
HIPAA Final Omnibus Rule Playbook
 
how to really implement hipaa presentation
how to really implement hipaa presentationhow to really implement hipaa presentation
how to really implement hipaa presentation
 
Dustin HIPAA
Dustin HIPAADustin HIPAA
Dustin HIPAA
 
HIPAA, PHI, & 42 CFR Part 2
HIPAA, PHI, & 42 CFR Part 2HIPAA, PHI, & 42 CFR Part 2
HIPAA, PHI, & 42 CFR Part 2
 
HIPAA-Compliant App Development Guide for the Healthcare Industry.pdf
HIPAA-Compliant App Development Guide for the Healthcare Industry.pdfHIPAA-Compliant App Development Guide for the Healthcare Industry.pdf
HIPAA-Compliant App Development Guide for the Healthcare Industry.pdf
 
HiPAA info
HiPAA infoHiPAA info
HiPAA info
 
The Intersection of OCR Enforcement and Health Care Data Privacy & Security
The Intersection of OCR Enforcement and Health Care Data Privacy & SecurityThe Intersection of OCR Enforcement and Health Care Data Privacy & Security
The Intersection of OCR Enforcement and Health Care Data Privacy & Security
 
Knowing confidentiality
Knowing confidentialityKnowing confidentiality
Knowing confidentiality
 
The Health Insurance Portability and Accountability Act 
The Health Insurance Portability and Accountability Act The Health Insurance Portability and Accountability Act 
The Health Insurance Portability and Accountability Act 
 

More from CBIZ, Inc.

BIZGrowth Strategies — Cybersecurity Special Edition 2023
BIZGrowth Strategies — Cybersecurity Special Edition 2023BIZGrowth Strategies — Cybersecurity Special Edition 2023
BIZGrowth Strategies — Cybersecurity Special Edition 2023CBIZ, Inc.
 
BIZGrowth Strategies - Back to Basics Special Edition
BIZGrowth Strategies - Back to Basics Special EditionBIZGrowth Strategies - Back to Basics Special Edition
BIZGrowth Strategies - Back to Basics Special EditionCBIZ, Inc.
 
The Advantage — Summer 2023
The Advantage — Summer 2023The Advantage — Summer 2023
The Advantage — Summer 2023CBIZ, Inc.
 
BIZGrowth Strategies - Workforce & Talent Optimization Special Edition
BIZGrowth Strategies - Workforce & Talent Optimization Special EditionBIZGrowth Strategies - Workforce & Talent Optimization Special Edition
BIZGrowth Strategies - Workforce & Talent Optimization Special EditionCBIZ, Inc.
 
BIZGrowth Newsletter - Economic Slowdown Solutions Special Edition
BIZGrowth Newsletter - Economic Slowdown Solutions Special EditionBIZGrowth Newsletter - Economic Slowdown Solutions Special Edition
BIZGrowth Newsletter - Economic Slowdown Solutions Special EditionCBIZ, Inc.
 
BIZGrowth Strategies - Cybersecurity Special Edition
BIZGrowth Strategies - Cybersecurity Special EditionBIZGrowth Strategies - Cybersecurity Special Edition
BIZGrowth Strategies - Cybersecurity Special EditionCBIZ, Inc.
 
Connections Help Law Practice Efficiently Obtain $5 Million Line of Credit
Connections Help Law Practice Efficiently Obtain $5 Million Line of CreditConnections Help Law Practice Efficiently Obtain $5 Million Line of Credit
Connections Help Law Practice Efficiently Obtain $5 Million Line of CreditCBIZ, Inc.
 
Custom Communication Plan & Active Enrollment Result in Increased Consumerism
Custom Communication Plan & Active Enrollment Result in Increased ConsumerismCustom Communication Plan & Active Enrollment Result in Increased Consumerism
Custom Communication Plan & Active Enrollment Result in Increased ConsumerismCBIZ, Inc.
 
Experienced Consulting Approach Leads Engineering Firm to the Right CFO
Experienced Consulting Approach Leads Engineering Firm to the Right CFOExperienced Consulting Approach Leads Engineering Firm to the Right CFO
Experienced Consulting Approach Leads Engineering Firm to the Right CFOCBIZ, Inc.
 
BIZGrowth Strategies - Summer 2022
BIZGrowth Strategies - Summer 2022BIZGrowth Strategies - Summer 2022
BIZGrowth Strategies - Summer 2022CBIZ, Inc.
 
Inflation, Interest Rates & the Disruption to CRE
Inflation, Interest Rates & the Disruption to CREInflation, Interest Rates & the Disruption to CRE
Inflation, Interest Rates & the Disruption to CRECBIZ, Inc.
 
CBIZ Quarterly Manufacturing and Distribution "Hot Topics" Newsletter (May-Ju...
CBIZ Quarterly Manufacturing and Distribution "Hot Topics" Newsletter (May-Ju...CBIZ Quarterly Manufacturing and Distribution "Hot Topics" Newsletter (May-Ju...
CBIZ Quarterly Manufacturing and Distribution "Hot Topics" Newsletter (May-Ju...CBIZ, Inc.
 
Rethinking Total Compensation to Retain Top Talent
Rethinking Total Compensation to Retain Top TalentRethinking Total Compensation to Retain Top Talent
Rethinking Total Compensation to Retain Top TalentCBIZ, Inc.
 
Common Labor Shortage Risks & Tips to Mitigate Your Exposures
Common Labor Shortage Risks & Tips to Mitigate Your ExposuresCommon Labor Shortage Risks & Tips to Mitigate Your Exposures
Common Labor Shortage Risks & Tips to Mitigate Your ExposuresCBIZ, Inc.
 
How the Great Resignation Affects the Tax Function
How the Great Resignation Affects the Tax FunctionHow the Great Resignation Affects the Tax Function
How the Great Resignation Affects the Tax FunctionCBIZ, Inc.
 
Using Technology to Secure Talent
Using Technology to Secure TalentUsing Technology to Secure Talent
Using Technology to Secure TalentCBIZ, Inc.
 
Experienced Consulting Approach Leads Engineering Firm to the Right CFO
Experienced Consulting Approach Leads Engineering Firm to the Right CFOExperienced Consulting Approach Leads Engineering Firm to the Right CFO
Experienced Consulting Approach Leads Engineering Firm to the Right CFOCBIZ, Inc.
 
BIZGrowth Strategies - The Great Resignation Special Edition
BIZGrowth Strategies - The Great Resignation Special EditionBIZGrowth Strategies - The Great Resignation Special Edition
BIZGrowth Strategies - The Great Resignation Special EditionCBIZ, Inc.
 
Tax incentive alert KS
Tax incentive alert KSTax incentive alert KS
Tax incentive alert KSCBIZ, Inc.
 
CBIZ Quarterly Commercial Real Estate "Hot Topics" Newsletter (Jan-Feb 2022)
CBIZ Quarterly Commercial Real Estate "Hot Topics" Newsletter (Jan-Feb 2022)CBIZ Quarterly Commercial Real Estate "Hot Topics" Newsletter (Jan-Feb 2022)
CBIZ Quarterly Commercial Real Estate "Hot Topics" Newsletter (Jan-Feb 2022)CBIZ, Inc.
 

More from CBIZ, Inc. (20)

BIZGrowth Strategies — Cybersecurity Special Edition 2023
BIZGrowth Strategies — Cybersecurity Special Edition 2023BIZGrowth Strategies — Cybersecurity Special Edition 2023
BIZGrowth Strategies — Cybersecurity Special Edition 2023
 
BIZGrowth Strategies - Back to Basics Special Edition
BIZGrowth Strategies - Back to Basics Special EditionBIZGrowth Strategies - Back to Basics Special Edition
BIZGrowth Strategies - Back to Basics Special Edition
 
The Advantage — Summer 2023
The Advantage — Summer 2023The Advantage — Summer 2023
The Advantage — Summer 2023
 
BIZGrowth Strategies - Workforce & Talent Optimization Special Edition
BIZGrowth Strategies - Workforce & Talent Optimization Special EditionBIZGrowth Strategies - Workforce & Talent Optimization Special Edition
BIZGrowth Strategies - Workforce & Talent Optimization Special Edition
 
BIZGrowth Newsletter - Economic Slowdown Solutions Special Edition
BIZGrowth Newsletter - Economic Slowdown Solutions Special EditionBIZGrowth Newsletter - Economic Slowdown Solutions Special Edition
BIZGrowth Newsletter - Economic Slowdown Solutions Special Edition
 
BIZGrowth Strategies - Cybersecurity Special Edition
BIZGrowth Strategies - Cybersecurity Special EditionBIZGrowth Strategies - Cybersecurity Special Edition
BIZGrowth Strategies - Cybersecurity Special Edition
 
Connections Help Law Practice Efficiently Obtain $5 Million Line of Credit
Connections Help Law Practice Efficiently Obtain $5 Million Line of CreditConnections Help Law Practice Efficiently Obtain $5 Million Line of Credit
Connections Help Law Practice Efficiently Obtain $5 Million Line of Credit
 
Custom Communication Plan & Active Enrollment Result in Increased Consumerism
Custom Communication Plan & Active Enrollment Result in Increased ConsumerismCustom Communication Plan & Active Enrollment Result in Increased Consumerism
Custom Communication Plan & Active Enrollment Result in Increased Consumerism
 
Experienced Consulting Approach Leads Engineering Firm to the Right CFO
Experienced Consulting Approach Leads Engineering Firm to the Right CFOExperienced Consulting Approach Leads Engineering Firm to the Right CFO
Experienced Consulting Approach Leads Engineering Firm to the Right CFO
 
BIZGrowth Strategies - Summer 2022
BIZGrowth Strategies - Summer 2022BIZGrowth Strategies - Summer 2022
BIZGrowth Strategies - Summer 2022
 
Inflation, Interest Rates & the Disruption to CRE
Inflation, Interest Rates & the Disruption to CREInflation, Interest Rates & the Disruption to CRE
Inflation, Interest Rates & the Disruption to CRE
 
CBIZ Quarterly Manufacturing and Distribution "Hot Topics" Newsletter (May-Ju...
CBIZ Quarterly Manufacturing and Distribution "Hot Topics" Newsletter (May-Ju...CBIZ Quarterly Manufacturing and Distribution "Hot Topics" Newsletter (May-Ju...
CBIZ Quarterly Manufacturing and Distribution "Hot Topics" Newsletter (May-Ju...
 
Rethinking Total Compensation to Retain Top Talent
Rethinking Total Compensation to Retain Top TalentRethinking Total Compensation to Retain Top Talent
Rethinking Total Compensation to Retain Top Talent
 
Common Labor Shortage Risks & Tips to Mitigate Your Exposures
Common Labor Shortage Risks & Tips to Mitigate Your ExposuresCommon Labor Shortage Risks & Tips to Mitigate Your Exposures
Common Labor Shortage Risks & Tips to Mitigate Your Exposures
 
How the Great Resignation Affects the Tax Function
How the Great Resignation Affects the Tax FunctionHow the Great Resignation Affects the Tax Function
How the Great Resignation Affects the Tax Function
 
Using Technology to Secure Talent
Using Technology to Secure TalentUsing Technology to Secure Talent
Using Technology to Secure Talent
 
Experienced Consulting Approach Leads Engineering Firm to the Right CFO
Experienced Consulting Approach Leads Engineering Firm to the Right CFOExperienced Consulting Approach Leads Engineering Firm to the Right CFO
Experienced Consulting Approach Leads Engineering Firm to the Right CFO
 
BIZGrowth Strategies - The Great Resignation Special Edition
BIZGrowth Strategies - The Great Resignation Special EditionBIZGrowth Strategies - The Great Resignation Special Edition
BIZGrowth Strategies - The Great Resignation Special Edition
 
Tax incentive alert KS
Tax incentive alert KSTax incentive alert KS
Tax incentive alert KS
 
CBIZ Quarterly Commercial Real Estate "Hot Topics" Newsletter (Jan-Feb 2022)
CBIZ Quarterly Commercial Real Estate "Hot Topics" Newsletter (Jan-Feb 2022)CBIZ Quarterly Commercial Real Estate "Hot Topics" Newsletter (Jan-Feb 2022)
CBIZ Quarterly Commercial Real Estate "Hot Topics" Newsletter (Jan-Feb 2022)
 

Recently uploaded

dehradun Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
dehradun Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetdehradun Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
dehradun Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetCall Girls Service
 
Mangalore Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Mangalore Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetMangalore Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Mangalore Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetCall Girls Service
 
Independent Call Girls Hyderabad 💋 9352988975 💋 Genuine WhatsApp Number for R...
Independent Call Girls Hyderabad 💋 9352988975 💋 Genuine WhatsApp Number for R...Independent Call Girls Hyderabad 💋 9352988975 💋 Genuine WhatsApp Number for R...
Independent Call Girls Hyderabad 💋 9352988975 💋 Genuine WhatsApp Number for R...Ahmedabad Call Girls
 
Call Girls Patiala Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Patiala Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Patiala Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Patiala Just Call 8250077686 Top Class Call Girl Service AvailableDipal Arora
 
Call Girls in Udaipur Girija Udaipur Call Girl ✔ VQRWTO ❤️ 100% offer with...
Call Girls in Udaipur  Girija  Udaipur Call Girl  ✔ VQRWTO ❤️ 100% offer with...Call Girls in Udaipur  Girija  Udaipur Call Girl  ✔ VQRWTO ❤️ 100% offer with...
Call Girls in Udaipur Girija Udaipur Call Girl ✔ VQRWTO ❤️ 100% offer with...mahaiklolahd
 
raisen Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
raisen Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetraisen Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
raisen Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetCall Girls Service
 
Tirupati Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Tirupati Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetTirupati Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Tirupati Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetCall Girls Service
 
VIP Call Girls Noida Sia 9711199171 High Class Call Girl Near Me
VIP Call Girls Noida Sia 9711199171 High Class Call Girl Near MeVIP Call Girls Noida Sia 9711199171 High Class Call Girl Near Me
VIP Call Girls Noida Sia 9711199171 High Class Call Girl Near Memriyagarg453
 
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Me
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near MeVIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Me
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Memriyagarg453
 
Call Girl in Bangalore 9632137771 {LowPrice} ❤️ (Navya) Bangalore Call Girls ...
Call Girl in Bangalore 9632137771 {LowPrice} ❤️ (Navya) Bangalore Call Girls ...Call Girl in Bangalore 9632137771 {LowPrice} ❤️ (Navya) Bangalore Call Girls ...
Call Girl in Bangalore 9632137771 {LowPrice} ❤️ (Navya) Bangalore Call Girls ...mahaiklolahd
 
(Deeksha) 💓 9920725232 💓High Profile Call Girls Navi Mumbai You Can Get The S...
(Deeksha) 💓 9920725232 💓High Profile Call Girls Navi Mumbai You Can Get The S...(Deeksha) 💓 9920725232 💓High Profile Call Girls Navi Mumbai You Can Get The S...
(Deeksha) 💓 9920725232 💓High Profile Call Girls Navi Mumbai You Can Get The S...Ahmedabad Call Girls
 
Hubli Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Hubli Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetHubli Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Hubli Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetCall Girls Service
 
💚 Punjabi Call Girls In Chandigarh 💯Lucky 🔝8868886958🔝Call Girl In Chandigarh
💚 Punjabi Call Girls In Chandigarh 💯Lucky 🔝8868886958🔝Call Girl In Chandigarh💚 Punjabi Call Girls In Chandigarh 💯Lucky 🔝8868886958🔝Call Girl In Chandigarh
💚 Punjabi Call Girls In Chandigarh 💯Lucky 🔝8868886958🔝Call Girl In ChandigarhSheetaleventcompany
 
Call Girls Service Anantapur 📲 6297143586 Book Now VIP Call Girls in Anantapur
Call Girls Service Anantapur 📲 6297143586 Book Now VIP Call Girls in AnantapurCall Girls Service Anantapur 📲 6297143586 Book Now VIP Call Girls in Anantapur
Call Girls Service Anantapur 📲 6297143586 Book Now VIP Call Girls in Anantapurgragmanisha42
 
Call Girl Gorakhpur * 8250192130 Service starts from just ₹9999 ✅
Call Girl Gorakhpur * 8250192130 Service starts from just ₹9999 ✅Call Girl Gorakhpur * 8250192130 Service starts from just ₹9999 ✅
Call Girl Gorakhpur * 8250192130 Service starts from just ₹9999 ✅gragmanisha42
 
Call Girls Service In Goa 💋 9316020077💋 Goa Call Girls By Russian Call Girl...
Call Girls Service In Goa  💋 9316020077💋 Goa Call Girls  By Russian Call Girl...Call Girls Service In Goa  💋 9316020077💋 Goa Call Girls  By Russian Call Girl...
Call Girls Service In Goa 💋 9316020077💋 Goa Call Girls By Russian Call Girl...russian goa call girl and escorts service
 
Ozhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Ozhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetOzhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Ozhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetCall Girls Service
 
Best Lahore Escorts 😮‍💨03250114445 || VIP escorts in Lahore
Best Lahore Escorts 😮‍💨03250114445 || VIP escorts in LahoreBest Lahore Escorts 😮‍💨03250114445 || VIP escorts in Lahore
Best Lahore Escorts 😮‍💨03250114445 || VIP escorts in LahoreDeny Daniel
 
Jalna Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Jalna Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetJalna Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Jalna Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetCall Girls Service
 

Recently uploaded (20)

dehradun Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
dehradun Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetdehradun Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
dehradun Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
Mangalore Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Mangalore Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetMangalore Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Mangalore Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
Independent Call Girls Hyderabad 💋 9352988975 💋 Genuine WhatsApp Number for R...
Independent Call Girls Hyderabad 💋 9352988975 💋 Genuine WhatsApp Number for R...Independent Call Girls Hyderabad 💋 9352988975 💋 Genuine WhatsApp Number for R...
Independent Call Girls Hyderabad 💋 9352988975 💋 Genuine WhatsApp Number for R...
 
Call Girls Patiala Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Patiala Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Patiala Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Patiala Just Call 8250077686 Top Class Call Girl Service Available
 
Call Girls in Udaipur Girija Udaipur Call Girl ✔ VQRWTO ❤️ 100% offer with...
Call Girls in Udaipur  Girija  Udaipur Call Girl  ✔ VQRWTO ❤️ 100% offer with...Call Girls in Udaipur  Girija  Udaipur Call Girl  ✔ VQRWTO ❤️ 100% offer with...
Call Girls in Udaipur Girija Udaipur Call Girl ✔ VQRWTO ❤️ 100% offer with...
 
raisen Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
raisen Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetraisen Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
raisen Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
Tirupati Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Tirupati Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetTirupati Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Tirupati Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
VIP Call Girls Noida Sia 9711199171 High Class Call Girl Near Me
VIP Call Girls Noida Sia 9711199171 High Class Call Girl Near MeVIP Call Girls Noida Sia 9711199171 High Class Call Girl Near Me
VIP Call Girls Noida Sia 9711199171 High Class Call Girl Near Me
 
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Me
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near MeVIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Me
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Me
 
Call Girl in Bangalore 9632137771 {LowPrice} ❤️ (Navya) Bangalore Call Girls ...
Call Girl in Bangalore 9632137771 {LowPrice} ❤️ (Navya) Bangalore Call Girls ...Call Girl in Bangalore 9632137771 {LowPrice} ❤️ (Navya) Bangalore Call Girls ...
Call Girl in Bangalore 9632137771 {LowPrice} ❤️ (Navya) Bangalore Call Girls ...
 
(Deeksha) 💓 9920725232 💓High Profile Call Girls Navi Mumbai You Can Get The S...
(Deeksha) 💓 9920725232 💓High Profile Call Girls Navi Mumbai You Can Get The S...(Deeksha) 💓 9920725232 💓High Profile Call Girls Navi Mumbai You Can Get The S...
(Deeksha) 💓 9920725232 💓High Profile Call Girls Navi Mumbai You Can Get The S...
 
Hubli Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Hubli Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetHubli Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Hubli Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
💚 Punjabi Call Girls In Chandigarh 💯Lucky 🔝8868886958🔝Call Girl In Chandigarh
💚 Punjabi Call Girls In Chandigarh 💯Lucky 🔝8868886958🔝Call Girl In Chandigarh💚 Punjabi Call Girls In Chandigarh 💯Lucky 🔝8868886958🔝Call Girl In Chandigarh
💚 Punjabi Call Girls In Chandigarh 💯Lucky 🔝8868886958🔝Call Girl In Chandigarh
 
Call Girls Service Anantapur 📲 6297143586 Book Now VIP Call Girls in Anantapur
Call Girls Service Anantapur 📲 6297143586 Book Now VIP Call Girls in AnantapurCall Girls Service Anantapur 📲 6297143586 Book Now VIP Call Girls in Anantapur
Call Girls Service Anantapur 📲 6297143586 Book Now VIP Call Girls in Anantapur
 
Call Girl Gorakhpur * 8250192130 Service starts from just ₹9999 ✅
Call Girl Gorakhpur * 8250192130 Service starts from just ₹9999 ✅Call Girl Gorakhpur * 8250192130 Service starts from just ₹9999 ✅
Call Girl Gorakhpur * 8250192130 Service starts from just ₹9999 ✅
 
Call Girls Service In Goa 💋 9316020077💋 Goa Call Girls By Russian Call Girl...
Call Girls Service In Goa  💋 9316020077💋 Goa Call Girls  By Russian Call Girl...Call Girls Service In Goa  💋 9316020077💋 Goa Call Girls  By Russian Call Girl...
Call Girls Service In Goa 💋 9316020077💋 Goa Call Girls By Russian Call Girl...
 
9316020077📞Goa Call Girls Numbers, Call Girls Whatsapp Numbers Goa
9316020077📞Goa  Call Girls  Numbers, Call Girls  Whatsapp Numbers Goa9316020077📞Goa  Call Girls  Numbers, Call Girls  Whatsapp Numbers Goa
9316020077📞Goa Call Girls Numbers, Call Girls Whatsapp Numbers Goa
 
Ozhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Ozhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetOzhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Ozhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
Best Lahore Escorts 😮‍💨03250114445 || VIP escorts in Lahore
Best Lahore Escorts 😮‍💨03250114445 || VIP escorts in LahoreBest Lahore Escorts 😮‍💨03250114445 || VIP escorts in Lahore
Best Lahore Escorts 😮‍💨03250114445 || VIP escorts in Lahore
 
Jalna Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Jalna Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetJalna Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Jalna Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 

Keys To HIPAA Compliance

  • 1. KEYS TO HIPAA COMPLIANCE for CAAP Practice Managers Amy Wasdin, RN, MBA, CPHRM Patient Safety Risk Manager II, Dept. of Patient Safety and Risk Management The Doctors Company March 17, 2016
  • 2. DISCLOSURE STATEMENT The Doctors Company would like to disclose that no one in a position to control or influence the content of this activity has reported relevant financial relationships with commercial interests. The information and guidelines contained in this activity are generalized and may not apply to all practice situations. The faculty recommends that legal advice be obtained from a qualified attorney for specific application to your practice. The information is intended for educational purposes and should be used as a reference guide only. 2 KEYS TO HIPAA COMPLIANCE for Practice Managers
  • 3. OBJECTIVES After completing this activity, learners will be able to:  Review the purpose of the HIPAA Privacy and Security Rules  Discuss the 2013 Omnibus Rule and its impact on: − Disclosures of Protected Health Information, − Patient Rights, and − Business Associates  Describe the notifications necessary for a breach of PHI.  Outline the steps necessary for HIPAA compliance in a medical practice. KEYS TO HIPAA COMPLIANCE for Practice Managers3
  • 4. I never had a policy; I have just tried to do my very best each and every day. --Abraham Lincoln 1809-1865
  • 5. How HIPAA compliant are you? Select one: A. I am 100% confident that our practice is HIPAA compliant. B. I am fairly certain that our practice is HIPAA compliant but I’m not sure. C. Our practice is not HIPAA compliant. D. What’s HIPAA? 5 KEYS TO HIPAA COMPLIANCE for Practice Managers
  • 6. KEY CONCEPTS UNDER HIPAA  Protected Health Information (PHI) − All individually identifiable health information − Held or transmitted by a covered entity or its business associate − In any form or media, whether electronic, paper, or oral  Covered Entity (CE) − Health plan or health care clearinghouse − Health care provider  Business Associates (BA) − Persons or organizations that perform certain functions on behalf of a CE (billing, claims processing, data analysis) 6 KEYS TO HIPAA COMPLIANCE for Practice Managers
  • 7. OVERVIEW OF HIPAA Healthcare Insurance Portability and Accountability Act: the Privacy Rule and the Security Rule  Protects privacy and confidentiality of PHI  Assures security of electronic information  The overall idea: − Assure information is properly protected, but still promote flow and use of technology to facilitate care  Some state laws are more stringent than HIPAA − If so, state law takes precedent over federal HIPAA 7 KEYS TO HIPAA COMPLIANCE for Practice Managers
  • 8. HIPAA VIOLATIONS ON THE RISE…  Total complaints received thru Dec 31, 2015: 125,4451  2014 saw a 25% increase in HIPAAA breaches2 − 2013: Loss and theft of laptops and portable devices. − 2014: “The year of the hacker” - CHS: 4.5 million patients  Paper records are as vulnerable, or more, than electronic records3 [1] HHS Compliance and Enforcement Numbers at a Glance. Mar 11 2016. www.hhs.gov [2] 2014 Saw 25% Increase in HIPAA Breaches. Mar 11 2016. www.hipaajournal.com [3] HIPAA in a HITECH World: HIPAA Violations on the Rise. Smart Data Collective, March 25, 2013 8 KEYS TO HIPAA COMPLIANCE for Practice Managers
  • 9. HIPAA FINES…  Alaska DHHS fined $1.7 million − USB device stolen from employee vehicle  Cignet Health fined $4.3 million − Failure to provide medical records to 41 patients  UCLA fined $865,500 − Snooping employees  CVS fined $2.25 million − Disposal of PHI in trashcans  Blue Cross of Tennessee fined $1.5 million − Unencrypted laptops stolen 9 KEYS TO HIPAA COMPLIANCE for Practice Managers
  • 10. DATA BREACH: GEORGIA HOSPICE GROUP Unencrypted company laptop containing personal health information was stolen from an employee's car in 2013. Nearly 2,000 patients affected by the breach. Officials say the laptop contained patient names, addresses, phone numbers, dates of birth, Social Security numbers, insurance numbers, clinical diagnoses and provider names. Healthcare IT News - February 2013 10 KEYS TO HIPAA COMPLIANCE for Practice Managers
  • 11. CARDIAC SURGERY PRACTICE April 2012–Phoenix Cardiac Surgery  $100,000 with Corrective Action Plan  Failed to implement policies to safeguard PHI  Failed to document training of employees on Privacy and Security Rules  Failed to identify a security official and conduct risk analysis  Failed to have BA agreements with Internet based e-mail and calendar services where provision of the service included storage of and access to its PHI 11 KEYS TO HIPAA COMPLIANCE for Practice Managers
  • 12. PHI 18 IDENTIFIERS  Name  Medical record number  Health plan beneficiary number  Device identifiers and serial numbers  Vehicle identifiers and serial numbers  Biometric identifiers (i.e., finger and voice prints)  Full face photos and other comparable images  Any other unique identifying number, code, or characteristic  Postal address  All elements of dates except year  Telephone number  Fax number  E-mail address  URL address (Uniform Resource Locator or web address)  IP security (Internet Protocol address numbers)  Social Security number  Account numbers  License numbers 12 KEYS TO HIPAA COMPLIANCE for Practice Managers
  • 13. Patient consent not required for…  Use in treatment, payment, or operations (TPO)  When records are subpoenaed − Check with MPL carrier for subpoena validity  Public interest or public health activities–required by law: − Mandated report of abuse to proper agencies − Preventing and controlling disease–CDC reports − FDA AUTHORIZED USE AND DISCLOSURE 13 KEYS TO HIPAA COMPLIANCE for Practice Managers
  • 14. AUTHORIZED USE AND DISCLOSURE Most of the time…  Valid Authorization is required to release records to another party Specific consent required for…  Psychotherapy notes  Alcohol and drug abuse treatment program notes  Participation in research studies −Even for re-disclosure of any of the above 14 KEYS TO HIPAA COMPLIANCE for Practice Managers (continued)
  • 15. SECURITY SAFEGUARDS  Administrative – Security Risk Assessment – Designated Privacy Officer – Policies and Procedures – Staff training  Physical  Technical 15 KEYS TO HIPAA COMPLIANCE for Practice Managers
  • 16. THE FINAL OMNIBUS HIPAA RULE  Effective March 26, 2013  Enforcement began September 23, 2013 − HITECH Modification − HIPAA Enforcement Rule − Breach Notification Rule 16 KEYS TO HIPAA COMPLIANCE for Practice Managers
  • 17. WHO DID THE CHANGES AFFECT?  HIPAA Covered Entities: − Healthcare providers, health systems, health plans, clearinghouses  HIPAA Business Associates and subcontractors: − Vendors who contract with Covered Entities and access protected health information (PHI) −Examples: Technology vendors, service organizations, accountable care organizations, third party administrators 17 KEYS TO HIPAA COMPLIANCE for Practice Managers
  • 18. OMNIBUS RULE - HITECH  Holds BA’s directly liable for compliance;  Strengthens limitation on use and disclosure of PHI;  Expands individual’s rights How does this impact practice? … Notice of Privacy Practices (NPP) 18 KEYS TO HIPAA COMPLIANCE for Practice Managers
  • 19. NPP MODIFICATIONS  Prohibition on the sale of PHI without authorization  Duty of CE to notify affected individuals of a breach of unsecured PHI  Right to restrict disclosures of PHI to health plan for care that was paid out of pocket in full  For CE that stated intent to fundraise in NPP, must also advise individual of the right to opt out of receiving fundraising communications from CE 19 KEYS TO HIPAA COMPLIANCE for Practice Managers
  • 20. NPP NOTIFICATION TO PATIENTS  Must make the NPP available upon request on or after the effective date of the revision  Must make the NPP available at the service delivery site and post the NPP in a clear and prominent location  A health care provider is required to give a copy of its NPP only to new patients—and not all individuals seeking treatment 20 KEYS TO HIPAA COMPLIANCE for Practice Managers
  • 21. OMNIBUS – HIPAA ENFORCEMENT RULE Modifies privacy, security, and enforcement rule of HIPAA How does this impact the practice? ... Penalties 21 KEYS TO HIPAA COMPLIANCE for Practice Managers
  • 22. OMNIBUS – BREACH NOTIFICATION RULE Establishes a process for notifying patients and HHS when there is a breach of unsecured PHI. How does this impact the practice? ... CE’s are required to notify patients. 22 KEYS TO HIPAA COMPLIANCE for Practice Managers
  • 23. BREACH OF PHI Any acquisition, access, use or disclosure not permitted is a Breach… UNLESS the CE or BA demonstrates a low probability of PHI compromise. 23 KEYS TO HIPAA COMPLIANCE for Practice Managers
  • 24. BREACH NOTIFICATION OF UNSECURED PHI  Applies to breach of unsecured PHI  Applies to covered entities and business associates  Business Associates notify Covered Entity  Covered entity has burden to notify patient (unencrypted)  Must notify each individual affected by the breach (written notification within 60 days of discovery)  Discovery date = first date known 24 KEYS TO HIPAA COMPLIANCE for Practice Managers
  • 25. BREACH EXCEPTIONS  Unintentional acquisition, access, or use by workforce member with no further impermissible use  Inadvertent disclosure from one authorized person to another or CE or BA and no further impermissible use  Recipient could not reasonably have retained the PHI  Encrypted data per OCR guidance 25 KEYS TO HIPAA COMPLIANCE for Practice Managers
  • 26. BREACH NOTIFICATION REQUIREMENTS  Individual − Contact by phone if urgent − Written breach notification – first class mail unless e-mail preferred  HHS − <500 = Annual log report − >500 = Media notice and immediate notice HHS Secretary Annual report to HHS of all breaches  Media − <500 residents of a state or jurisdiction − Insufficient contact information for 10 or more individuals 26 KEYS TO HIPAA COMPLIANCE for Practice Managers
  • 27. BREACH NOTIFICATION REQUIREMENTS  What happened?  What information was breached?  What steps the patient should take for protection?  What the CE is doing to investigate, mitigate and prevent future incidents?  CE contact information  Adhere to HIPAA Compliance plan for breach 27 KEYS TO HIPAA COMPLIANCE for Practice Managers (continued)
  • 28. BREACH RESPONSE –WHAT IS YOUR PLAN?  Determine root cause of breach  Identify gaps in compliance that led to breach  Provide evidence that root cause has been addressed and gaps corrected 28 KEYS TO HIPAA COMPLIANCE for Practice Managers
  • 29. TOP FIVE ISSUES IN INVESTIGATED CASES OCR took corrective action most often on…  Impermissible use and disclosure  Safeguards − Not in place–fax, email, computer accessibility, etc.  Access − Access to records was granted or not granted improperly  Minimum necessary − More information than needed was disclosed (e.g., phone message)  Notice of privacy practices – Not given 29 KEYS TO HIPAA COMPLIANCE for Practice Managers
  • 30. BUSINESS ASSOCIATES AGREEMENTS  Business Associate Agreements must be updated to include specific new provisions  Existing agreements, entered before January 25, 2013, may operate until agreement is amended / renewed, or until September 22, 2014, whichever is earlier  Covered Entities and Business Associates will need to modify agreements and allocate risk through use of insurance requirements and indemnity provisions 30 KEYS TO HIPAA COMPLIANCE for Practice Managers
  • 31. PUTTING IT ALL TOGETHER
  • 32. WHAT ACTIONS ARE REQUIRED?  Perform risk assessment.  Establish risk management plan to address and manage areas of vulnerability.  Designate a HIPAA Security officer.  Encrypt all devices that contact PHI  Have written policies on Sanctions and Breach Notification  Train staff on how to protect PHI and ensure your policies are compliance with HIPAA  Audit/Test physical and electronic security policies and procedures regularly  Documentation 32 KEYS TO HIPAA COMPLIANCE for Practice Managers
  • 33. IF NOT ALREADY ADDRESSED…  Update Notice of Privacy Practices  Revise all Business Associates Agreements 33 KEYS TO HIPAA COMPLIANCE for Practice Managers
  • 34. Testing Your Compliance Select One: A. I am 100% confident that our practice is HIPAA compliant. B. I am fairly certain that our practice is HIPAA compliant but I’m not sure. C. Our practice is not HIPAA compliant. D. What’s HIPAA? 34 KEYS TO HIPAA COMPLIANCE for Practice Managers
  • 35. TIPS FOR PRIVACY AND SECURITY  Limit access to a “need to know” basis  Do not conduct discussion in elevators, waiting area, or other public areas  If you see a patient in a public place, be careful in greeting him/her  Obtain patient’s permission before discussing care/treatment if there is someone with him/her  Keep voices down when discussing PHI  Log off computer when done 35 KEYS TO HIPAA COMPLIANCE for Practice Managers
  • 36. TIPS FOR PRIVACY AND SECURITY  Use password protected or encrypted systems  Never share your password  Protect zip drives, laptop, PDA from loss  Never leave documents unattended  Do not put PHI in the trash  Avoid taking records out of the office if possible  Obtain written permission before leaving voicemail messages or emailing  Confirm fax numbers before sending and use a confidentiality statement on your cover sheet 36 KEYS TO HIPAA COMPLIANCE for Practice Managers (continued)
  • 37. RESOURCES  Security Risk Assessment – HealthIT.gov www.healthit.gov/providers-professionals/security-risk-assessment  Sample Notice of Privacy Practices-English www.hhs.gov/ocr/privacy/hipaa/npp_fullpage_hc_provider.pdf  Sample Business Associates Agreement www.hhs.gov/ocr/privacy/hipaa/understanding/coveredentities/contractpro v.html  Take Steps to Protect and Secure Information When Using a Mobile Device www.healthit.gov/sites/default/files/fact-sheet-take-steps-to-protect- information.pdf  Security Rule Educational Paper Series http://www.hhs.gov/hipaa/for-professionals/security/guidance/index.html 37 KEYS TO HIPAA COMPLIANCE for Practice Managers
  • 38. The key to wisdom is knowing all the right questions. --John Simone, Sr. --
  • 39. Contact Information For additional Patient Safety information, please visit our Web site at: www.thedoctors.com Amy Wasdin, RN, MBA, CPHRM Patient Safety Risk Manager II, Southeast Department of Patient Safety and Risk Management 800-421-2368, ext 6728 Email: awasdin@thedoctors.com ---------------------------------------------------------------------------------------------------------------- Nelson Guzman, CIC, CRM President, CBIZ Trinity Southeast Regional Healthcare Director, CBIZ Insurance Services Mobile: 404-791-8822 Email: nguzman@cbiztrinity.com Evan Orvis, Sales Executive Mobile: 770-712-3903 Direct: 470-282-2536 Email: eorvis@cbiz.com Kathy Alba, CISR, CLCS Senior Account Manager Direct: 678-389-7858 Email: kalba@cbiz.com 39 KEYS TO HIPAA COMPLIANCE for Practice Managers
  • 40. THANK YOU We relentlessly defend, protect, and reward the practice of good medicine.