SlideShare a Scribd company logo
1 of 15
HIPAA & HITECH
HIPAA
• Has been a federal privacy regulation since 2003.
Covers privacy and security of health information.
• Reviewed in annual education
• Taught in new employee orientation
• The facility Security Officer is Michael Boudreaux
• The facility Privacy Officer is Alane Bryan
HITECH
• Does not replace HIPAA—it gives it TEETH!
• Requires a breach notification policy
• Encourages EHR adoption
• Provides strict data protection regulations for
more secure patient privacy
New Fines as of March 26, 2013
Violation Type Each Violation Repeat Violations/Yr.
Did not know $100 - $50,000 $1.5 million
Reasonable Cause $1,000 - $50,000 $1.5 million
Willful Neglect – Corrected $10,000 - $50,000 $1.5 million
Willful Neglect – Not Corrected $50,000 $1.5 million
•Healthcare organizations or providers may be held liable for
violations.
•Individual employees may be prosecuted or may be sued for
civil penalties.
Breach Notifications
 Must notify individuals and HHS and, in some cases the media, of any
substantiated breaches within 60 days.
 Breaches affecting 500 or more patients will be posted to the
HHS.gov website.
 Four factors are used to determine if there is low to high probability of
PHI compromise:
1. The nature and extent of the PHI involved in the incident
• Is the PHI sensitive information i.e. Security numbers, or infectious disease test
results
1. The unauthorized recipient of the PHI
• Is another physician receiving the PHI?
1. Whether the PHI was actually acquired or viewed
2. The extent to which the risk to the PHI has been mitigated
• Was it immediately destroyed?
Documented Breaches
• Mass General
• California Breaches
• BCBS of TN Breach
• Individual Prosecution
• Personal Gain
Top Privacy Violations
• Stolen laptops/computers
• Lost CDs
• ID theft/Social Security Numbers
• Medicare Fraud
• Access to EMR with no job-related need
Privacy Breach Examples
• Using Social Networking to talk about patients
• Discussing PHI with employees or family who
do not have a job-related need
• Looking at EMR out of concern or curiosity
• Telling others that a patient was “in” for
treatment
• Discussing progress or prognosis in front of
family without permission
More Privacy Breach Examples
• Using chart to get information to use against
patient in lawsuit or divorce
• Looking in minor child’s EMR
• Taking a peek for “educational purposes”
• Starting conversations with “Don’t tell anyone
I told you this, but…”
• Sharing computer access/passwords
Permitted HIPAA Exceptions
• Treatment, Payment, Operations
• Some law enforcement exceptions
• Public health reporting
• When in doubt, get a Signed Release
• Disclose “minimal necessary” amount of PHI
HIPAA, HITECH, & YOU
• Patients/family members requesting patient
information AFTER DISCHARGE should be
referred to the HIM Department
• If a patient requests information during an
admission, make sure the report is FINAL before
giving the information to the patient or to their
designee (document the designee). We do not
release information unless it is in a FINAL status.
• Discuss patient information as quietly as possible
HIPAA, HITECH, & YOU
• Try not to say the patient’s name repeatedly
• Make sure paper containing PHI makes it to a shred bin
• Shred bins should be dumped in large bins each day
• Use fax cover sheets with the confidentiality clause
• Do not leave messages with too much information
• Wear your employee ID badge at all times
• Do not take pictures in patient care areas. Patients , their
names, or their family members may be visible without
you realizing it. It is not worth the risk!!
HIPAA, HITECH, & YOU
• Use workstations for intended purposes
– No gaming, no unauthorized downloading of files,
personal emails are subject to access by P&S
Surgical Hospital
• Log-off or lock your computer when you are
not using it
• Make sure others cannot view your computer
screen
HIPAA, HITECH, & YOU
• Keep passwords secure
• Use your own individual password
• Avoid sharing passwords
• Trigger encryption for emails containing PHI
being sent outside the organization
• If photos must be taken of a patient, use a
P&S camera or device; NEVER use your
personal camera or smart phone
HIPAA, HITECH, & YOU
• Never share proprietary or confidential
information in blogs or on social media sites
• Report potential breaches, inappropriate
disclosures, or otherwise suspect behavior to
your direct supervisor, the Privacy Officer, the
Security Officer, or the Corporate Compliance
Officer

More Related Content

What's hot

Confidentiality slide
Confidentiality slideConfidentiality slide
Confidentiality slidewongy12
 
Patient confidentiality MHA 690
Patient confidentiality MHA 690Patient confidentiality MHA 690
Patient confidentiality MHA 690AMSIMM9932
 
Confidentiality training
Confidentiality trainingConfidentiality training
Confidentiality trainingSherin_26
 
Confidentiality
ConfidentialityConfidentiality
ConfidentialityDeniseMHA
 
Confidentiality in Healthcare
Confidentiality in HealthcareConfidentiality in Healthcare
Confidentiality in Healthcarekmasterson
 
Patient confidentiality training
Patient confidentiality  trainingPatient confidentiality  training
Patient confidentiality trainingtwhit0623
 
Confidentiality in the Workplace
Confidentiality in the WorkplaceConfidentiality in the Workplace
Confidentiality in the Workplacesalvarez63
 
TaylorWk1d2assignment
TaylorWk1d2assignmentTaylorWk1d2assignment
TaylorWk1d2assignmentmya1743
 
Protecting patient privacy and confidentiality
Protecting patient privacy and confidentialityProtecting patient privacy and confidentiality
Protecting patient privacy and confidentialityTiffany Cochran
 
Privacy and confidentiality
Privacy and confidentialityPrivacy and confidentiality
Privacy and confidentialityjohnzinn
 

What's hot (13)

Confidentiality slide
Confidentiality slideConfidentiality slide
Confidentiality slide
 
Patient confidentiality MHA 690
Patient confidentiality MHA 690Patient confidentiality MHA 690
Patient confidentiality MHA 690
 
Confidentiality training
Confidentiality trainingConfidentiality training
Confidentiality training
 
Confidentiality
ConfidentialityConfidentiality
Confidentiality
 
Confidentiality in Healthcare
Confidentiality in HealthcareConfidentiality in Healthcare
Confidentiality in Healthcare
 
Patient confidentiality training
Patient confidentiality  trainingPatient confidentiality  training
Patient confidentiality training
 
Confidentiality in the Workplace
Confidentiality in the WorkplaceConfidentiality in the Workplace
Confidentiality in the Workplace
 
Confidentiality
ConfidentialityConfidentiality
Confidentiality
 
Confidentiality
Confidentiality Confidentiality
Confidentiality
 
Hipaa training
Hipaa trainingHipaa training
Hipaa training
 
TaylorWk1d2assignment
TaylorWk1d2assignmentTaylorWk1d2assignment
TaylorWk1d2assignment
 
Protecting patient privacy and confidentiality
Protecting patient privacy and confidentialityProtecting patient privacy and confidentiality
Protecting patient privacy and confidentiality
 
Privacy and confidentiality
Privacy and confidentialityPrivacy and confidentiality
Privacy and confidentiality
 

Similar to Annual HIPAA Education

Are You HIPAA Safe?
Are You HIPAA Safe?Are You HIPAA Safe?
Are You HIPAA Safe?TriageLogic
 
Hipaa basics.pp2
Hipaa basics.pp2Hipaa basics.pp2
Hipaa basics.pp2martykoepke
 
Welcome to the hippa, privacy and security
Welcome to the hippa, privacy and securityWelcome to the hippa, privacy and security
Welcome to the hippa, privacy and securityveve1728
 
Hipaa101 training2020
Hipaa101 training2020Hipaa101 training2020
Hipaa101 training2020VicHaight
 
HIPAA and Privacy Training
HIPAA and Privacy TrainingHIPAA and Privacy Training
HIPAA and Privacy TrainingJasAmataga
 
Rems hipaa
Rems hipaaRems hipaa
Rems hipaadhexel
 
Patient confidentiality.ppt
Patient confidentiality.pptPatient confidentiality.ppt
Patient confidentiality.pptchwiso8418
 
Hippa health admin week 1 question 2
Hippa health admin week 1 question 2Hippa health admin week 1 question 2
Hippa health admin week 1 question 2Ashford Univeristy
 
William schuch week 1 mha690 capstone ppp
William schuch week 1 mha690 capstone pppWilliam schuch week 1 mha690 capstone ppp
William schuch week 1 mha690 capstone pppWilliam Schuch
 
Hcc_hipaa hitech training_Basic www.hcctecnologies.com
Hcc_hipaa hitech training_Basic www.hcctecnologies.comHcc_hipaa hitech training_Basic www.hcctecnologies.com
Hcc_hipaa hitech training_Basic www.hcctecnologies.comejazmazhar
 
PROTECTED HEALTH INFORMATION_PATIENT PRIVACY
PROTECTED HEALTH INFORMATION_PATIENT PRIVACYPROTECTED HEALTH INFORMATION_PATIENT PRIVACY
PROTECTED HEALTH INFORMATION_PATIENT PRIVACYDenise Masella
 
Hipaa training new_staff_december 2018 - compatibility mode
Hipaa training new_staff_december 2018  -  compatibility modeHipaa training new_staff_december 2018  -  compatibility mode
Hipaa training new_staff_december 2018 - compatibility moderobint2125
 
Medical Ethics: Principles of medical ethics, patient rights, confidentiality...
Medical Ethics: Principles of medical ethics, patient rights, confidentiality...Medical Ethics: Principles of medical ethics, patient rights, confidentiality...
Medical Ethics: Principles of medical ethics, patient rights, confidentiality...emdadhussain840
 
Patient confidentiality power point
Patient confidentiality power pointPatient confidentiality power point
Patient confidentiality power pointchwiso8418
 

Similar to Annual HIPAA Education (20)

Are You HIPAA Safe?
Are You HIPAA Safe?Are You HIPAA Safe?
Are You HIPAA Safe?
 
Hipaa basics.pp2
Hipaa basics.pp2Hipaa basics.pp2
Hipaa basics.pp2
 
5 hipaa training
5 hipaa training5 hipaa training
5 hipaa training
 
Welcome to the hippa, privacy and security
Welcome to the hippa, privacy and securityWelcome to the hippa, privacy and security
Welcome to the hippa, privacy and security
 
5 hipaa training
5 hipaa training5 hipaa training
5 hipaa training
 
Hipaa 2012
Hipaa 2012Hipaa 2012
Hipaa 2012
 
Hippa 2021
Hippa 2021Hippa 2021
Hippa 2021
 
Hipaa101 training2020
Hipaa101 training2020Hipaa101 training2020
Hipaa101 training2020
 
HIPAA and Privacy Training
HIPAA and Privacy TrainingHIPAA and Privacy Training
HIPAA and Privacy Training
 
Rems hipaa
Rems hipaaRems hipaa
Rems hipaa
 
Patient confidentiality.ppt
Patient confidentiality.pptPatient confidentiality.ppt
Patient confidentiality.ppt
 
Hippa health admin week 1 question 2
Hippa health admin week 1 question 2Hippa health admin week 1 question 2
Hippa health admin week 1 question 2
 
William schuch week 1 mha690 capstone ppp
William schuch week 1 mha690 capstone pppWilliam schuch week 1 mha690 capstone ppp
William schuch week 1 mha690 capstone ppp
 
Dustin HIPAA
Dustin HIPAADustin HIPAA
Dustin HIPAA
 
Hcc_hipaa hitech training_Basic www.hcctecnologies.com
Hcc_hipaa hitech training_Basic www.hcctecnologies.comHcc_hipaa hitech training_Basic www.hcctecnologies.com
Hcc_hipaa hitech training_Basic www.hcctecnologies.com
 
Phi masella
Phi masellaPhi masella
Phi masella
 
PROTECTED HEALTH INFORMATION_PATIENT PRIVACY
PROTECTED HEALTH INFORMATION_PATIENT PRIVACYPROTECTED HEALTH INFORMATION_PATIENT PRIVACY
PROTECTED HEALTH INFORMATION_PATIENT PRIVACY
 
Hipaa training new_staff_december 2018 - compatibility mode
Hipaa training new_staff_december 2018  -  compatibility modeHipaa training new_staff_december 2018  -  compatibility mode
Hipaa training new_staff_december 2018 - compatibility mode
 
Medical Ethics: Principles of medical ethics, patient rights, confidentiality...
Medical Ethics: Principles of medical ethics, patient rights, confidentiality...Medical Ethics: Principles of medical ethics, patient rights, confidentiality...
Medical Ethics: Principles of medical ethics, patient rights, confidentiality...
 
Patient confidentiality power point
Patient confidentiality power pointPatient confidentiality power point
Patient confidentiality power point
 

More from DirkRhodes

Patient Satisfaction
Patient SatisfactionPatient Satisfaction
Patient SatisfactionDirkRhodes
 
Corporate compliance annual update
Corporate compliance annual updateCorporate compliance annual update
Corporate compliance annual updateDirkRhodes
 
Quality management education
Quality management educationQuality management education
Quality management educationDirkRhodes
 
Hospital safety education
Hospital safety educationHospital safety education
Hospital safety educationDirkRhodes
 
Infection Control
Infection ControlInfection Control
Infection ControlDirkRhodes
 
Quality Management Education
Quality Management EducationQuality Management Education
Quality Management EducationDirkRhodes
 
Cultural sensitivity bariatric patients
Cultural sensitivity bariatric patientsCultural sensitivity bariatric patients
Cultural sensitivity bariatric patientsDirkRhodes
 
Hospital Safety Education
Hospital Safety EducationHospital Safety Education
Hospital Safety EducationDirkRhodes
 

More from DirkRhodes (10)

Abuse
AbuseAbuse
Abuse
 
Patient Satisfaction
Patient SatisfactionPatient Satisfaction
Patient Satisfaction
 
Corporate compliance annual update
Corporate compliance annual updateCorporate compliance annual update
Corporate compliance annual update
 
Quality management education
Quality management educationQuality management education
Quality management education
 
Hospital safety education
Hospital safety educationHospital safety education
Hospital safety education
 
Abuse
AbuseAbuse
Abuse
 
Infection Control
Infection ControlInfection Control
Infection Control
 
Quality Management Education
Quality Management EducationQuality Management Education
Quality Management Education
 
Cultural sensitivity bariatric patients
Cultural sensitivity bariatric patientsCultural sensitivity bariatric patients
Cultural sensitivity bariatric patients
 
Hospital Safety Education
Hospital Safety EducationHospital Safety Education
Hospital Safety Education
 

Recently uploaded

Earth Day Presentation wow hello nice great
Earth Day Presentation wow hello nice greatEarth Day Presentation wow hello nice great
Earth Day Presentation wow hello nice greatYousafMalik24
 
Integumentary System SMP B. Pharm Sem I.ppt
Integumentary System SMP B. Pharm Sem I.pptIntegumentary System SMP B. Pharm Sem I.ppt
Integumentary System SMP B. Pharm Sem I.pptshraddhaparab530
 
Karra SKD Conference Presentation Revised.pptx
Karra SKD Conference Presentation Revised.pptxKarra SKD Conference Presentation Revised.pptx
Karra SKD Conference Presentation Revised.pptxAshokKarra1
 
GRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTS
GRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTSGRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTS
GRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTSJoshuaGantuangco2
 
What is Model Inheritance in Odoo 17 ERP
What is Model Inheritance in Odoo 17 ERPWhat is Model Inheritance in Odoo 17 ERP
What is Model Inheritance in Odoo 17 ERPCeline George
 
INTRODUCTION TO CATHOLIC CHRISTOLOGY.pptx
INTRODUCTION TO CATHOLIC CHRISTOLOGY.pptxINTRODUCTION TO CATHOLIC CHRISTOLOGY.pptx
INTRODUCTION TO CATHOLIC CHRISTOLOGY.pptxHumphrey A Beña
 
Q4-PPT-Music9_Lesson-1-Romantic-Opera.pptx
Q4-PPT-Music9_Lesson-1-Romantic-Opera.pptxQ4-PPT-Music9_Lesson-1-Romantic-Opera.pptx
Q4-PPT-Music9_Lesson-1-Romantic-Opera.pptxlancelewisportillo
 
Influencing policy (training slides from Fast Track Impact)
Influencing policy (training slides from Fast Track Impact)Influencing policy (training slides from Fast Track Impact)
Influencing policy (training slides from Fast Track Impact)Mark Reed
 
AUDIENCE THEORY -CULTIVATION THEORY - GERBNER.pptx
AUDIENCE THEORY -CULTIVATION THEORY -  GERBNER.pptxAUDIENCE THEORY -CULTIVATION THEORY -  GERBNER.pptx
AUDIENCE THEORY -CULTIVATION THEORY - GERBNER.pptxiammrhaywood
 
Daily Lesson Plan in Mathematics Quarter 4
Daily Lesson Plan in Mathematics Quarter 4Daily Lesson Plan in Mathematics Quarter 4
Daily Lesson Plan in Mathematics Quarter 4JOYLYNSAMANIEGO
 
Music 9 - 4th quarter - Vocal Music of the Romantic Period.pptx
Music 9 - 4th quarter - Vocal Music of the Romantic Period.pptxMusic 9 - 4th quarter - Vocal Music of the Romantic Period.pptx
Music 9 - 4th quarter - Vocal Music of the Romantic Period.pptxleah joy valeriano
 
Active Learning Strategies (in short ALS).pdf
Active Learning Strategies (in short ALS).pdfActive Learning Strategies (in short ALS).pdf
Active Learning Strategies (in short ALS).pdfPatidar M
 
Inclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdf
Inclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdfInclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdf
Inclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdfTechSoup
 
Transaction Management in Database Management System
Transaction Management in Database Management SystemTransaction Management in Database Management System
Transaction Management in Database Management SystemChristalin Nelson
 
Global Lehigh Strategic Initiatives (without descriptions)
Global Lehigh Strategic Initiatives (without descriptions)Global Lehigh Strategic Initiatives (without descriptions)
Global Lehigh Strategic Initiatives (without descriptions)cama23
 
4.16.24 Poverty and Precarity--Desmond.pptx
4.16.24 Poverty and Precarity--Desmond.pptx4.16.24 Poverty and Precarity--Desmond.pptx
4.16.24 Poverty and Precarity--Desmond.pptxmary850239
 
How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17Celine George
 
Field Attribute Index Feature in Odoo 17
Field Attribute Index Feature in Odoo 17Field Attribute Index Feature in Odoo 17
Field Attribute Index Feature in Odoo 17Celine George
 
ROLES IN A STAGE PRODUCTION in arts.pptx
ROLES IN A STAGE PRODUCTION in arts.pptxROLES IN A STAGE PRODUCTION in arts.pptx
ROLES IN A STAGE PRODUCTION in arts.pptxVanesaIglesias10
 

Recently uploaded (20)

Earth Day Presentation wow hello nice great
Earth Day Presentation wow hello nice greatEarth Day Presentation wow hello nice great
Earth Day Presentation wow hello nice great
 
Integumentary System SMP B. Pharm Sem I.ppt
Integumentary System SMP B. Pharm Sem I.pptIntegumentary System SMP B. Pharm Sem I.ppt
Integumentary System SMP B. Pharm Sem I.ppt
 
Karra SKD Conference Presentation Revised.pptx
Karra SKD Conference Presentation Revised.pptxKarra SKD Conference Presentation Revised.pptx
Karra SKD Conference Presentation Revised.pptx
 
GRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTS
GRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTSGRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTS
GRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTS
 
YOUVE_GOT_EMAIL_PRELIMS_EL_DORADO_2024.pptx
YOUVE_GOT_EMAIL_PRELIMS_EL_DORADO_2024.pptxYOUVE_GOT_EMAIL_PRELIMS_EL_DORADO_2024.pptx
YOUVE_GOT_EMAIL_PRELIMS_EL_DORADO_2024.pptx
 
What is Model Inheritance in Odoo 17 ERP
What is Model Inheritance in Odoo 17 ERPWhat is Model Inheritance in Odoo 17 ERP
What is Model Inheritance in Odoo 17 ERP
 
INTRODUCTION TO CATHOLIC CHRISTOLOGY.pptx
INTRODUCTION TO CATHOLIC CHRISTOLOGY.pptxINTRODUCTION TO CATHOLIC CHRISTOLOGY.pptx
INTRODUCTION TO CATHOLIC CHRISTOLOGY.pptx
 
Q4-PPT-Music9_Lesson-1-Romantic-Opera.pptx
Q4-PPT-Music9_Lesson-1-Romantic-Opera.pptxQ4-PPT-Music9_Lesson-1-Romantic-Opera.pptx
Q4-PPT-Music9_Lesson-1-Romantic-Opera.pptx
 
Influencing policy (training slides from Fast Track Impact)
Influencing policy (training slides from Fast Track Impact)Influencing policy (training slides from Fast Track Impact)
Influencing policy (training slides from Fast Track Impact)
 
AUDIENCE THEORY -CULTIVATION THEORY - GERBNER.pptx
AUDIENCE THEORY -CULTIVATION THEORY -  GERBNER.pptxAUDIENCE THEORY -CULTIVATION THEORY -  GERBNER.pptx
AUDIENCE THEORY -CULTIVATION THEORY - GERBNER.pptx
 
Daily Lesson Plan in Mathematics Quarter 4
Daily Lesson Plan in Mathematics Quarter 4Daily Lesson Plan in Mathematics Quarter 4
Daily Lesson Plan in Mathematics Quarter 4
 
Music 9 - 4th quarter - Vocal Music of the Romantic Period.pptx
Music 9 - 4th quarter - Vocal Music of the Romantic Period.pptxMusic 9 - 4th quarter - Vocal Music of the Romantic Period.pptx
Music 9 - 4th quarter - Vocal Music of the Romantic Period.pptx
 
Active Learning Strategies (in short ALS).pdf
Active Learning Strategies (in short ALS).pdfActive Learning Strategies (in short ALS).pdf
Active Learning Strategies (in short ALS).pdf
 
Inclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdf
Inclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdfInclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdf
Inclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdf
 
Transaction Management in Database Management System
Transaction Management in Database Management SystemTransaction Management in Database Management System
Transaction Management in Database Management System
 
Global Lehigh Strategic Initiatives (without descriptions)
Global Lehigh Strategic Initiatives (without descriptions)Global Lehigh Strategic Initiatives (without descriptions)
Global Lehigh Strategic Initiatives (without descriptions)
 
4.16.24 Poverty and Precarity--Desmond.pptx
4.16.24 Poverty and Precarity--Desmond.pptx4.16.24 Poverty and Precarity--Desmond.pptx
4.16.24 Poverty and Precarity--Desmond.pptx
 
How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17
 
Field Attribute Index Feature in Odoo 17
Field Attribute Index Feature in Odoo 17Field Attribute Index Feature in Odoo 17
Field Attribute Index Feature in Odoo 17
 
ROLES IN A STAGE PRODUCTION in arts.pptx
ROLES IN A STAGE PRODUCTION in arts.pptxROLES IN A STAGE PRODUCTION in arts.pptx
ROLES IN A STAGE PRODUCTION in arts.pptx
 

Annual HIPAA Education

  • 2. HIPAA • Has been a federal privacy regulation since 2003. Covers privacy and security of health information. • Reviewed in annual education • Taught in new employee orientation • The facility Security Officer is Michael Boudreaux • The facility Privacy Officer is Alane Bryan
  • 3. HITECH • Does not replace HIPAA—it gives it TEETH! • Requires a breach notification policy • Encourages EHR adoption • Provides strict data protection regulations for more secure patient privacy
  • 4. New Fines as of March 26, 2013 Violation Type Each Violation Repeat Violations/Yr. Did not know $100 - $50,000 $1.5 million Reasonable Cause $1,000 - $50,000 $1.5 million Willful Neglect – Corrected $10,000 - $50,000 $1.5 million Willful Neglect – Not Corrected $50,000 $1.5 million •Healthcare organizations or providers may be held liable for violations. •Individual employees may be prosecuted or may be sued for civil penalties.
  • 5. Breach Notifications  Must notify individuals and HHS and, in some cases the media, of any substantiated breaches within 60 days.  Breaches affecting 500 or more patients will be posted to the HHS.gov website.  Four factors are used to determine if there is low to high probability of PHI compromise: 1. The nature and extent of the PHI involved in the incident • Is the PHI sensitive information i.e. Security numbers, or infectious disease test results 1. The unauthorized recipient of the PHI • Is another physician receiving the PHI? 1. Whether the PHI was actually acquired or viewed 2. The extent to which the risk to the PHI has been mitigated • Was it immediately destroyed?
  • 6. Documented Breaches • Mass General • California Breaches • BCBS of TN Breach • Individual Prosecution • Personal Gain
  • 7. Top Privacy Violations • Stolen laptops/computers • Lost CDs • ID theft/Social Security Numbers • Medicare Fraud • Access to EMR with no job-related need
  • 8. Privacy Breach Examples • Using Social Networking to talk about patients • Discussing PHI with employees or family who do not have a job-related need • Looking at EMR out of concern or curiosity • Telling others that a patient was “in” for treatment • Discussing progress or prognosis in front of family without permission
  • 9. More Privacy Breach Examples • Using chart to get information to use against patient in lawsuit or divorce • Looking in minor child’s EMR • Taking a peek for “educational purposes” • Starting conversations with “Don’t tell anyone I told you this, but…” • Sharing computer access/passwords
  • 10. Permitted HIPAA Exceptions • Treatment, Payment, Operations • Some law enforcement exceptions • Public health reporting • When in doubt, get a Signed Release • Disclose “minimal necessary” amount of PHI
  • 11. HIPAA, HITECH, & YOU • Patients/family members requesting patient information AFTER DISCHARGE should be referred to the HIM Department • If a patient requests information during an admission, make sure the report is FINAL before giving the information to the patient or to their designee (document the designee). We do not release information unless it is in a FINAL status. • Discuss patient information as quietly as possible
  • 12. HIPAA, HITECH, & YOU • Try not to say the patient’s name repeatedly • Make sure paper containing PHI makes it to a shred bin • Shred bins should be dumped in large bins each day • Use fax cover sheets with the confidentiality clause • Do not leave messages with too much information • Wear your employee ID badge at all times • Do not take pictures in patient care areas. Patients , their names, or their family members may be visible without you realizing it. It is not worth the risk!!
  • 13. HIPAA, HITECH, & YOU • Use workstations for intended purposes – No gaming, no unauthorized downloading of files, personal emails are subject to access by P&S Surgical Hospital • Log-off or lock your computer when you are not using it • Make sure others cannot view your computer screen
  • 14. HIPAA, HITECH, & YOU • Keep passwords secure • Use your own individual password • Avoid sharing passwords • Trigger encryption for emails containing PHI being sent outside the organization • If photos must be taken of a patient, use a P&S camera or device; NEVER use your personal camera or smart phone
  • 15. HIPAA, HITECH, & YOU • Never share proprietary or confidential information in blogs or on social media sites • Report potential breaches, inappropriate disclosures, or otherwise suspect behavior to your direct supervisor, the Privacy Officer, the Security Officer, or the Corporate Compliance Officer