SlideShare uma empresa Scribd logo
1 de 42
Baixar para ler offline
© 2013 Armstrong Teasdale LLP© 2013 Armstrong Teasdale LLP
HIPAA: Navigating the Labyrinth
Anna Selby
Diane Keefe
July 31, 2013
© 2013 Armstrong Teasdale LLP
Navigating the Labyrinth
© 2013 Armstrong Teasdale LLP
Call From Employee
1) Staff Texting Nude Patient Photo.
• Patient is Identifiable.
• Hospital Name is visible on scrubs.
2) Nurses photograph x-ray.
• Post x-ray to Facebook.
• Nurse comments regarding patient.
© 2013 Armstrong Teasdale LLP
HIPAA
 Regulations Apply to:
• Covered Entities (CE)
1) Providers
2) Health Plans
3) Clearinghouses
 Business Associates of CE’s
• Insurance Broker, Benefit Specialists
• Strategic Consultants
© 2013 Armstrong Teasdale LLP
HIPAA Protects
PHI
PERSONAL HEALTH INFORMATION
© 2013 Armstrong Teasdale LLP
PHI Uses & Disclosures
 OK to use PHI for:
1) Treatment
2)Payment
3) Health Care Operations
 General Rule: Other Uses Require an Authorization.
© 2013 Armstrong Teasdale LLP
HIPAA Breach - New Definition
 A Breach is
1. Unauthorized acquisition, access, use or disclosure of
2. Unsecured PHI
3. Compromises the privacy or security of the PHI
 Presumption of Reportable Breach UNLESS
• CE determines there is a low probability the
• PHI has been compromised after risk assessment.
© 2013 Armstrong Teasdale LLP
HIPAA Risk Assessment
 What is Compromised?
• Rule does not tell us.
 Must Perform Risk Assessment.
© 2013 Armstrong Teasdale LLP
HIPAA Risk Assessment
 4 Elements:
1. Nature and extent of PHI involved.
2. The unauthorized person who used PHI or to whom
disclosure was made.
3. Whether PHI was actually acquired or viewed.
4. Extent to which the risk to PHI has been mitigated.
© 2013 Armstrong Teasdale LLP
HIPAA Risk Assessment
 If you do not do a breach notification you
MUST do a Risk Assessment.
 DOCUMENT, DOCUMENT, DOCUMENT.
© 2013 Armstrong Teasdale LLP
HIPAA Breaches
 CVS 2009-Pill bottles thrown in dumpsters.
• $2.25 Million Settlement
• No policies.
• No training.
© 2013 Armstrong Teasdale LLP
HIPAA Breaches
 Million Dollar Subway Ride
• Massachusetts General Hospital employee leaves documents
on subway.
• PHI of 192 patients. (Included HIV/AIDS status)
• $1 Million Settlement.
 Stanford 2011. BA posts PHI on web.
• 20,000 patients X $1,000 = $20 Million
© 2013 Armstrong Teasdale LLP
HIPAA Breaches
 WellPoint—July 11, 2013
 Left Accessible Information on Internet
 $1.7 Million Settlement
 600,000 Patients’ Information
 WellPoint failed to:
1) Have Policies to authorize access to PHI;
2) Perform technical evaluation of software & database;
3) Have technical safeguards to verify identify of persons
accessing PHI.
© 2013 Armstrong Teasdale LLP
HIPAA Breaches-Laptops
 Sutter 2011. Stolen unencrypted laptop.
• 4 million patients X $1,000 nominal damages per patient.
• $1 Billion Potential Damages.
 UCLA 2011.
• Encrypted laptop stolen. Paper also stolen.
• 16,000 patients X $1,000
• $16 Million.
© 2013 Armstrong Teasdale LLP
HIPAA Breaches-Hardware
 Blue Cross Blue Shield Tennessee 2012
• Self Reported 57 unencrypted hard drives stolen.
• 1 Million people. $1.5 Million Settlement.
 Pentagon 2011
• BA lost backup tapes, 4.9 Million Tricare beneficiaries.
• If damages are $1,000 per patient = $4.9 Billion.
• Attempted to use HIPAA for basis of claims.
© 2013 Armstrong Teasdale LLP
Lawsuits Pending
 Plaintiffs claim HIPAA violations. (Negligence Per Se)
 Case law is not clear.
 We argue no private right of action.
 Motions to dismiss granted.
 Breach of Fiduciary Duty & Public Disclosure of Private Fact
claims remain.
 Each suit involved OCR investigation.
© 2013 Armstrong Teasdale LLP
HIPAA Breach
 If you don’t need it for your job=Unauthorized.
Snooping.
© 2013 Armstrong Teasdale LLP
Snooping
 There once was a girl …
 Later goes to psych ward at UCLA…
 People get curious.
 13 fired & 12 disciplined.
 OCR investigates $865,000
 No evidence PHI disclosed or sold.
© 2013 Armstrong Teasdale LLP
Snooping
 Little Rock: News anchor in hospital.
 Physician watches news from home.
 Unit Coordinator & Billing employee.
 2 fired; physician suspended 2 weeks.
• Face prison & fine.
• Each had HIPAA training.
 Mom sues Hospital.
• AR SC allows outrageous behavior claim.
© 2013 Armstrong Teasdale LLP
Yes, Someone Went to Prison.
 Researcher at UCLA
 Reviewed records 323 times in 3 weeks.
 His Boss,
 No Evidence PHI was Used or Sold.
 4 Months in Prison.
© 2013 Armstrong Teasdale LLP
Breach Notifications < 500
 Breach
• Must Notify Individual(s)
− In Writing including what happened & steps taken.
− Within 60 days of date breach discovered.
• Notify HHS Secretary
 Don’t Delay.
© 2013 Armstrong Teasdale LLP
Breach Notifications > 500
 Where a Breach Involves Greater than 500 Residents:
• Notify Individuals in Writing
• Notify HHS Secretary
• Notify Media
− Press Release to “Prominent” media outlets.
− Within 60 days.
© 2013 Armstrong Teasdale LLP
Penalties-Civil
 Per identical violation in a calendar year:
Did Not Know: $100 up to $25,000
Willful Neglect Uncorrected: $50,000 up to $1,500,000
Willful Neglect: Conscious, intentional failure or reckless
indifference.
 Can be Per Record.
 Extend to BA’s.
 Can impose penalty without seeking informal resolution.
© 2013 Armstrong Teasdale LLP
Penalties-Criminal
 People that knowingly obtain or disclose PHI:
• Up to $50,000 AND 1 year imprisonment.
 With False Pretenses:
• Up to $100,000 AND 5 years.
 With Intent to sell or use for personal gain or malicious harm:
• Up to $250,000 AND 10 years.
© 2013 Armstrong Teasdale LLP
When a Breach Occurs:
 Call Us.
 What We Can Do:
• Walk you through whether it is reportable.
− Multiple factors.
• Advise during investigation.
• Assist with Proactive Prevention.
© 2013 Armstrong Teasdale LLP
What Can/Should be Done to Comply?
 Most obvious
• Modify your Business Associate Agreements
• Modify your Notice of Privacy Practices
 Not so obvious…
• Conduct a Risk Assessment
• Review, evaluate and update polices and procedures
• Educate and train staff/employees
© 2013 Armstrong Teasdale LLP
Modifications to the BAA’s
 A statement that the Business Associate (“BA”) now needs to
comply with the administrative, physical, and technical
components of the Security Rule
• Should also reflect that the BA is required to implement and
maintain compliance with the administrative, physical, and
technical components of the Security Rule
© 2013 Armstrong Teasdale LLP
Modifications to BAAs
 A statement that the BA must report to the Covered Entity any
breach of unsecured PHI (in addition to any unauthorized use or
disclosure)
• Should reflect exactly what the BA should do in order to notify the
Covered Entity of the breach:
− Date of incident
− Date of discovery of incident (if different than above)
− Categories of the affected information
− Individual(s) who were affected
− Steps for mitigation
− Steps for prevention
© 2013 Armstrong Teasdale LLP
Modifications to BAAs
 A statement that the BA must ensure that any subcontractor
will agree to the same restrictions and conditions that apply
to the BA
• In other words, BAs now need to enter into BAAs with
subcontractors
 A statement requiring the BA to implement a system for
documenting and recording uses and disclosures in
compliance with the Security Rule
 A statement that provides for retention of information for 6
years from the date of the disclosure
© 2013 Armstrong Teasdale LLP
Modifications to BAAs
 Other Aspects to Consider
• Liability is determined on Agency principles, so a statement
that reflects the status of the parties
• Consider modifying or adding insurance requirements
• Consider modifying or adding limitations of liability and
indemnification provisions
© 2013 Armstrong Teasdale LLP
Modifications to BAAs
 Compliance Deadline
• depends on whether there is an existing BAA or whether
there will be a new BAA entered into between the parties
− If existing BAA, then September 22, 2014
− If no existing BAA, then September 23, 2013
© 2013 Armstrong Teasdale LLP
Modifications to Notice of Privacy Practices
 Must now include statements regarding the Sale of PHI
 Must now include statements regarding marketing and other
purposes that require an authorization
 Must now include statement that an individual can opt out of
fundraising communications/efforts
© 2013 Armstrong Teasdale LLP
Modifications to Notice of Privacy Practices
 Must now include statement that the Covered Entity must
agree to restrict disclosures to health plans if the individual
pays out of pocket in full for the health care service
 Must now include a statement about an individual’s right to
receive breach notifications
© 2013 Armstrong Teasdale LLP
Conducting a Risk Assessment
 Elements of a general risk assessment include:
1. Identify the scope – what are potential risks and
vulnerabilities to your organization?
2. Identify where all the PHI is stored, received, maintained
or transmitted
3. Assess current security measures:
− Do you utilize encryption software?
− Are passwords used and changed frequently?
− Are firewalls used?
− Are mobile devices protected?
© 2013 Armstrong Teasdale LLP
Conducting a Risk Assessment
 Other Aspects:
• Determine likelihood of the occurrence of a threat
• Determine the potential impact of that threat
• Determine the level of risk
 Which becomes a mathematical equation…
• Vulnerability x likelihood x impact = level of risk
 Which can then assist in the mitigation that risk
© 2013 Armstrong Teasdale LLP
Conducting a Risk Assessment
Threat Source Terminated EE Calculation
Threat Unauthorized Access to Patient
Information
Vulnerability No formal process in place to notify
the IT department when ee’s are
terminated and periodic reviews
are not performed
3
Likelihood Removal of access for terminated
ee has not been performed
3
Impact PHI is viewed, altered or destroyed 3
Risk Disgruntled ee gains unauthorized
access to PHI after termination,
deleting records
Total = 27
Risk Mitigation IT implements daily automated
program to read ee database in
payroll system and automatically
removes access to network and
application systems for terminated
ees
Risk is now significantly reduced
© 2013 Armstrong Teasdale LLP
Reviewing/Updating Policies and Procedures
 Update policies and procedures on breach notification and
integrate into the policy the four factors of whether a breach
occurred by a risk assessment:
1. Nature and extent of the PHI involved
2. The unauthorized person who used the PHI or to whom the
disclosure was made
3. Whether PHI was actually acquired or viewed
4. Extent to which the risk has been mitigated
© 2013 Armstrong Teasdale LLP
Reviewing/Updating Policies and Procedures
 Use and disclosure of PHI for marketing
• Requires determination of what is and is not considered
marketing
• Once that determination is made, then clarify the policy to
reflect what requires an authorization from the individual
 Sale of PHI
• Selling an individual’s PHI without an authorization is
prohibited
© 2013 Armstrong Teasdale LLP
Reviewing/Updating Policies and Procedures
 Electronic Access to PHI
• May require revisions to job descriptions to clearly delineate who
has access and in what situation
• May require revisions to IT policies and procedures
 Requests for Restrictions
 Use and disclosures of decedent information
 Social media and cell phone policies
© 2013 Armstrong Teasdale LLP
Reviewing/Updating Policies and Procedures
 Covered entities may use any security measures that allow
them to reasonably and appropriately implement the HIPAA
regulations. So, in determining whether to draft new or
revise old policies and procedures, you should consider:
• Size, complexity, and capabilities of the Covered Entity
• Technical infrastructure, hardware, and software
• Costs
• Likelihood and impact of risks or potential risks, i.e., risk
assessment
© 2013 Armstrong Teasdale LLP
Educate and Train Staff/Employees
 Must ensure that the policies and procedures reviewed,
revised, and/or created are implemented by staff/employees.
 Sign-in sheets should be passed around so attendance of staff
members/employees is documented
 Staff/Employee training must be conducted at the following
intervals:
• At the start of employment
• Annual basis
 If staff/employees do not apply these policies to their
everyday practice, then organizations are at risk!
© 2013 Armstrong Teasdale LLP
Questions?
Anna Selby
314.552.6616
aselby@armstrongteasdale.com
Diane Keefe
314.259.4731
dkeefe@armstrongteasdale.com

Mais conteúdo relacionado

Mais procurados

TITAN Group VHMA 2018: Safeguarding Your Controlled Substances
TITAN Group VHMA 2018: Safeguarding Your Controlled SubstancesTITAN Group VHMA 2018: Safeguarding Your Controlled Substances
TITAN Group VHMA 2018: Safeguarding Your Controlled SubstancesTheTitanGroupLLC
 
Substance Abuse Eaton, Michigan
Substance Abuse Eaton, MichiganSubstance Abuse Eaton, Michigan
Substance Abuse Eaton, Michiganrecoveryrestart2
 
HIPAA presentation GAHU v7
HIPAA presentation GAHU v7HIPAA presentation GAHU v7
HIPAA presentation GAHU v7Jason Karn
 
Patton Boggs Employment Law Insight ~ June 2013
Patton Boggs Employment Law Insight ~ June 2013Patton Boggs Employment Law Insight ~ June 2013
Patton Boggs Employment Law Insight ~ June 2013Patton Boggs LLP
 
Background Checks White Paper
Background Checks White PaperBackground Checks White Paper
Background Checks White Paperpattywise
 
Hcc_hipaa hitech training_Basic www.hcctecnologies.com
Hcc_hipaa hitech training_Basic www.hcctecnologies.comHcc_hipaa hitech training_Basic www.hcctecnologies.com
Hcc_hipaa hitech training_Basic www.hcctecnologies.comejazmazhar
 
Healthcare preparedness 2010
Healthcare preparedness 2010Healthcare preparedness 2010
Healthcare preparedness 2010DataMotion
 
Employment Attorney Perspectives on Arizona's Medical Marijuana Law
Employment Attorney Perspectives on Arizona's Medical Marijuana LawEmployment Attorney Perspectives on Arizona's Medical Marijuana Law
Employment Attorney Perspectives on Arizona's Medical Marijuana LawJackson White, P.C.
 
Drug Free Workplace Presentation 5 18
Drug Free Workplace Presentation 5 18Drug Free Workplace Presentation 5 18
Drug Free Workplace Presentation 5 18STrimboli
 
HIPAA MYTHS: HOW MUCH DO YOU KNOW? COMMON MYTHS DEBUNKED & EXPLAINED
HIPAA MYTHS: HOW MUCH DO YOU KNOW? COMMON MYTHS DEBUNKED & EXPLAINEDHIPAA MYTHS: HOW MUCH DO YOU KNOW? COMMON MYTHS DEBUNKED & EXPLAINED
HIPAA MYTHS: HOW MUCH DO YOU KNOW? COMMON MYTHS DEBUNKED & EXPLAINEDCompliancy Group
 
Osha enforcement what is the current state of play
Osha enforcement what is the current state of playOsha enforcement what is the current state of play
Osha enforcement what is the current state of playNational Retail Federation
 
Medical Records Management
Medical Records ManagementMedical Records Management
Medical Records ManagementChoice Legal
 
Medical Device Industry - Government Investigations
Medical Device Industry - Government Investigations  Medical Device Industry - Government Investigations
Medical Device Industry - Government Investigations Rachel Hamilton
 

Mais procurados (16)

TITAN Group VHMA 2018: Safeguarding Your Controlled Substances
TITAN Group VHMA 2018: Safeguarding Your Controlled SubstancesTITAN Group VHMA 2018: Safeguarding Your Controlled Substances
TITAN Group VHMA 2018: Safeguarding Your Controlled Substances
 
Substance Abuse Eaton, Michigan
Substance Abuse Eaton, MichiganSubstance Abuse Eaton, Michigan
Substance Abuse Eaton, Michigan
 
HIPAA presentation GAHU v7
HIPAA presentation GAHU v7HIPAA presentation GAHU v7
HIPAA presentation GAHU v7
 
Patton Boggs Employment Law Insight ~ June 2013
Patton Boggs Employment Law Insight ~ June 2013Patton Boggs Employment Law Insight ~ June 2013
Patton Boggs Employment Law Insight ~ June 2013
 
Background Checks White Paper
Background Checks White PaperBackground Checks White Paper
Background Checks White Paper
 
Hcc_hipaa hitech training_Basic www.hcctecnologies.com
Hcc_hipaa hitech training_Basic www.hcctecnologies.comHcc_hipaa hitech training_Basic www.hcctecnologies.com
Hcc_hipaa hitech training_Basic www.hcctecnologies.com
 
Healthcare preparedness 2010
Healthcare preparedness 2010Healthcare preparedness 2010
Healthcare preparedness 2010
 
Employment Attorney Perspectives on Arizona's Medical Marijuana Law
Employment Attorney Perspectives on Arizona's Medical Marijuana LawEmployment Attorney Perspectives on Arizona's Medical Marijuana Law
Employment Attorney Perspectives on Arizona's Medical Marijuana Law
 
Drug Free Workplace Presentation 5 18
Drug Free Workplace Presentation 5 18Drug Free Workplace Presentation 5 18
Drug Free Workplace Presentation 5 18
 
HIPAA MYTHS: HOW MUCH DO YOU KNOW? COMMON MYTHS DEBUNKED & EXPLAINED
HIPAA MYTHS: HOW MUCH DO YOU KNOW? COMMON MYTHS DEBUNKED & EXPLAINEDHIPAA MYTHS: HOW MUCH DO YOU KNOW? COMMON MYTHS DEBUNKED & EXPLAINED
HIPAA MYTHS: HOW MUCH DO YOU KNOW? COMMON MYTHS DEBUNKED & EXPLAINED
 
Honoring Commitments in Lawyer-Client Relationships
Honoring Commitments in Lawyer-Client RelationshipsHonoring Commitments in Lawyer-Client Relationships
Honoring Commitments in Lawyer-Client Relationships
 
Osha enforcement what is the current state of play
Osha enforcement what is the current state of playOsha enforcement what is the current state of play
Osha enforcement what is the current state of play
 
Medical Records Management
Medical Records ManagementMedical Records Management
Medical Records Management
 
Medical Device Industry - Government Investigations
Medical Device Industry - Government Investigations  Medical Device Industry - Government Investigations
Medical Device Industry - Government Investigations
 
New osha rules spotlight on safety
New osha rules spotlight on safetyNew osha rules spotlight on safety
New osha rules spotlight on safety
 
Clio's The Whole Lawyer series - Confidentiality
Clio's The Whole Lawyer series - ConfidentialityClio's The Whole Lawyer series - Confidentiality
Clio's The Whole Lawyer series - Confidentiality
 

Semelhante a HIPAA Compliance Guide for Navigating Breaches and Risk Assessments

Your Home Health Care Agency is 5xs More Likely to Be Audited By OCR than the...
Your Home Health Care Agency is 5xs More Likely to Be Audited By OCR than the...Your Home Health Care Agency is 5xs More Likely to Be Audited By OCR than the...
Your Home Health Care Agency is 5xs More Likely to Be Audited By OCR than the...LTC Expert Publications
 
Lisa Hancock, RN, MHA
Lisa Hancock, RN, MHALisa Hancock, RN, MHA
Lisa Hancock, RN, MHALisa Hancock
 
Week 9 and 10 prepare for work
Week 9 and 10 prepare for workWeek 9 and 10 prepare for work
Week 9 and 10 prepare for workcatherinejyoung
 
AN20230811-3.pptx
AN20230811-3.pptxAN20230811-3.pptx
AN20230811-3.pptxHabibuKumar
 
Chapter 3Risk Management in EmploymentEmployment Re.docx
Chapter 3Risk Management in EmploymentEmployment Re.docxChapter 3Risk Management in EmploymentEmployment Re.docx
Chapter 3Risk Management in EmploymentEmployment Re.docxketurahhazelhurst
 
Certify webinar 6_21_13_final
Certify webinar 6_21_13_finalCertify webinar 6_21_13_final
Certify webinar 6_21_13_finalAshley Emery
 
CHAPTER3 Maintaining ComplianceMANY LAWS AND REGULATIONS.docx
CHAPTER3 Maintaining ComplianceMANY LAWS AND REGULATIONS.docxCHAPTER3 Maintaining ComplianceMANY LAWS AND REGULATIONS.docx
CHAPTER3 Maintaining ComplianceMANY LAWS AND REGULATIONS.docxchristinemaritza
 
Siskinds | Incident Response Plan
Siskinds | Incident Response PlanSiskinds | Incident Response Plan
Siskinds | Incident Response PlanNext Dimension Inc.
 
Fair Credit Reporting Act Basics
Fair Credit Reporting Act BasicsFair Credit Reporting Act Basics
Fair Credit Reporting Act BasicsG&A Partners
 
The changing face of privacy laws
The changing face of privacy lawsThe changing face of privacy laws
The changing face of privacy lawsRussell_Kennedy
 
Hitech changes-to-hipaa
Hitech changes-to-hipaaHitech changes-to-hipaa
Hitech changes-to-hipaageeksikh
 
Intro to ghs w envirox
Intro to ghs w enviroxIntro to ghs w envirox
Intro to ghs w enviroxmtabak111
 
Audit reports for Mcdonalds
Audit reports for McdonaldsAudit reports for Mcdonalds
Audit reports for McdonaldsRachel Dai
 
Personal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochurePersonal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochureJean Luc Creppy
 
Policies and procedure presentation
Policies and procedure presentation Policies and procedure presentation
Policies and procedure presentation rangada shah
 
HIPAA Omnibus Rule for Business Associates
HIPAA Omnibus Rule for Business AssociatesHIPAA Omnibus Rule for Business Associates
HIPAA Omnibus Rule for Business AssociatesJose Ivan Delgado, Ph.D.
 
Cyber Security - NAHU Continuing Education Course
Cyber Security - NAHU Continuing Education CourseCyber Security - NAHU Continuing Education Course
Cyber Security - NAHU Continuing Education CourseScott Diehl
 

Semelhante a HIPAA Compliance Guide for Navigating Breaches and Risk Assessments (20)

Your Home Health Care Agency is 5xs More Likely to Be Audited By OCR than the...
Your Home Health Care Agency is 5xs More Likely to Be Audited By OCR than the...Your Home Health Care Agency is 5xs More Likely to Be Audited By OCR than the...
Your Home Health Care Agency is 5xs More Likely to Be Audited By OCR than the...
 
Lisa Hancock, RN, MHA
Lisa Hancock, RN, MHALisa Hancock, RN, MHA
Lisa Hancock, RN, MHA
 
Week 9 and 10 prepare for work
Week 9 and 10 prepare for workWeek 9 and 10 prepare for work
Week 9 and 10 prepare for work
 
AN20230811-3.pptx
AN20230811-3.pptxAN20230811-3.pptx
AN20230811-3.pptx
 
Chapter 3Risk Management in EmploymentEmployment Re.docx
Chapter 3Risk Management in EmploymentEmployment Re.docxChapter 3Risk Management in EmploymentEmployment Re.docx
Chapter 3Risk Management in EmploymentEmployment Re.docx
 
Certify webinar 6_21_13_final
Certify webinar 6_21_13_finalCertify webinar 6_21_13_final
Certify webinar 6_21_13_final
 
CHAPTER3 Maintaining ComplianceMANY LAWS AND REGULATIONS.docx
CHAPTER3 Maintaining ComplianceMANY LAWS AND REGULATIONS.docxCHAPTER3 Maintaining ComplianceMANY LAWS AND REGULATIONS.docx
CHAPTER3 Maintaining ComplianceMANY LAWS AND REGULATIONS.docx
 
Siskinds | Incident Response Plan
Siskinds | Incident Response PlanSiskinds | Incident Response Plan
Siskinds | Incident Response Plan
 
Whistle blowing
Whistle blowingWhistle blowing
Whistle blowing
 
Fair Credit Reporting Act Basics
Fair Credit Reporting Act BasicsFair Credit Reporting Act Basics
Fair Credit Reporting Act Basics
 
HNI U: HIPAA Essentials
HNI U: HIPAA EssentialsHNI U: HIPAA Essentials
HNI U: HIPAA Essentials
 
The changing face of privacy laws
The changing face of privacy lawsThe changing face of privacy laws
The changing face of privacy laws
 
Hitech changes-to-hipaa
Hitech changes-to-hipaaHitech changes-to-hipaa
Hitech changes-to-hipaa
 
Intro to ghs w envirox
Intro to ghs w enviroxIntro to ghs w envirox
Intro to ghs w envirox
 
Audit reports for Mcdonalds
Audit reports for McdonaldsAudit reports for Mcdonalds
Audit reports for Mcdonalds
 
Personal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochurePersonal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochure
 
Policies and procedure presentation
Policies and procedure presentation Policies and procedure presentation
Policies and procedure presentation
 
2022 Privacy Training
2022 Privacy Training2022 Privacy Training
2022 Privacy Training
 
HIPAA Omnibus Rule for Business Associates
HIPAA Omnibus Rule for Business AssociatesHIPAA Omnibus Rule for Business Associates
HIPAA Omnibus Rule for Business Associates
 
Cyber Security - NAHU Continuing Education Course
Cyber Security - NAHU Continuing Education CourseCyber Security - NAHU Continuing Education Course
Cyber Security - NAHU Continuing Education Course
 

Mais de Armstrong Teasdale

How to Avoid TROUBLE: Legal Ethics for In House Counsel Featuring Larry Tucker
How to Avoid TROUBLE: Legal Ethics for In House Counsel Featuring Larry TuckerHow to Avoid TROUBLE: Legal Ethics for In House Counsel Featuring Larry Tucker
How to Avoid TROUBLE: Legal Ethics for In House Counsel Featuring Larry TuckerArmstrong Teasdale
 
Don't be SORRY for Data Breach Missteps Featuring: Dan Nelson
Don't be SORRY for Data Breach Missteps Featuring: Dan NelsonDon't be SORRY for Data Breach Missteps Featuring: Dan Nelson
Don't be SORRY for Data Breach Missteps Featuring: Dan NelsonArmstrong Teasdale
 
Armstrong Teasdale Kansas City Employment & Labor Seminar Featuring: Dan O'To...
Armstrong Teasdale Kansas City Employment & Labor Seminar Featuring: Dan O'To...Armstrong Teasdale Kansas City Employment & Labor Seminar Featuring: Dan O'To...
Armstrong Teasdale Kansas City Employment & Labor Seminar Featuring: Dan O'To...Armstrong Teasdale
 
Armstrong Teasdale Employment & Labor Seminar Featuring: Dan O'Toole, J.P. Ha...
Armstrong Teasdale Employment & Labor Seminar Featuring: Dan O'Toole, J.P. Ha...Armstrong Teasdale Employment & Labor Seminar Featuring: Dan O'Toole, J.P. Ha...
Armstrong Teasdale Employment & Labor Seminar Featuring: Dan O'Toole, J.P. Ha...Armstrong Teasdale
 
Drop the Phone & Drive: Limits on Lawyer Communications with Non-Lawyers Feat...
Drop the Phone & Drive: Limits on Lawyer Communications with Non-Lawyers Feat...Drop the Phone & Drive: Limits on Lawyer Communications with Non-Lawyers Feat...
Drop the Phone & Drive: Limits on Lawyer Communications with Non-Lawyers Feat...Armstrong Teasdale
 
Cyber Readiness in the Securities and Brokerage Industries Featuring Armstron...
Cyber Readiness in the Securities and Brokerage Industries Featuring Armstron...Cyber Readiness in the Securities and Brokerage Industries Featuring Armstron...
Cyber Readiness in the Securities and Brokerage Industries Featuring Armstron...Armstrong Teasdale
 
Challenging the Validity of a Patent Before the PTAB Featuring Scott Eidson &...
Challenging the Validity of a Patent Before the PTAB Featuring Scott Eidson &...Challenging the Validity of a Patent Before the PTAB Featuring Scott Eidson &...
Challenging the Validity of a Patent Before the PTAB Featuring Scott Eidson &...Armstrong Teasdale
 
Multijurisdictional practice issues for traveling lawyers ethics michael_downey
Multijurisdictional practice issues for traveling lawyers ethics michael_downeyMultijurisdictional practice issues for traveling lawyers ethics michael_downey
Multijurisdictional practice issues for traveling lawyers ethics michael_downeyArmstrong Teasdale
 
BUCKLE UP! How the NLRB is Changing the Rules of the Road
BUCKLE UP!  How the NLRB is Changing the Rules of the RoadBUCKLE UP!  How the NLRB is Changing the Rules of the Road
BUCKLE UP! How the NLRB is Changing the Rules of the RoadArmstrong Teasdale
 
China 2014: Law Changes and Opportunities in 7% GDP Growth Environment
China 2014: Law Changes and Opportunities in 7% GDP Growth EnvironmentChina 2014: Law Changes and Opportunities in 7% GDP Growth Environment
China 2014: Law Changes and Opportunities in 7% GDP Growth EnvironmentArmstrong Teasdale
 
Employment & Labor Seminar Presentation 2014 - Kansas City
Employment & Labor Seminar Presentation 2014 - Kansas CityEmployment & Labor Seminar Presentation 2014 - Kansas City
Employment & Labor Seminar Presentation 2014 - Kansas CityArmstrong Teasdale
 
Avoiding Legal Road Hazards While Traveling the Interactive Web
Avoiding Legal Road Hazards While Traveling the Interactive Web Avoiding Legal Road Hazards While Traveling the Interactive Web
Avoiding Legal Road Hazards While Traveling the Interactive Web Armstrong Teasdale
 
Employment & Labor Seminar Presentation 2014 - St. Louis
Employment & Labor Seminar Presentation 2014 - St. LouisEmployment & Labor Seminar Presentation 2014 - St. Louis
Employment & Labor Seminar Presentation 2014 - St. LouisArmstrong Teasdale
 
2014 Missouri Legislative Preview -Kansas City
2014 Missouri Legislative Preview -Kansas City2014 Missouri Legislative Preview -Kansas City
2014 Missouri Legislative Preview -Kansas CityArmstrong Teasdale
 
2014 Missouri Legislative Preview-St. Louis
2014 Missouri Legislative Preview-St. Louis2014 Missouri Legislative Preview-St. Louis
2014 Missouri Legislative Preview-St. LouisArmstrong Teasdale
 
"The Importance of Being Earnest" How to Dodge Legal Pitfalls that Confront F...
"The Importance of Being Earnest" How to Dodge Legal Pitfalls that Confront F..."The Importance of Being Earnest" How to Dodge Legal Pitfalls that Confront F...
"The Importance of Being Earnest" How to Dodge Legal Pitfalls that Confront F...Armstrong Teasdale
 
Fundamental Intellectual Property Strategies
Fundamental Intellectual Property StrategiesFundamental Intellectual Property Strategies
Fundamental Intellectual Property StrategiesArmstrong Teasdale
 
USLFG Corporate & Securities Presentation
USLFG Corporate & Securities PresentationUSLFG Corporate & Securities Presentation
USLFG Corporate & Securities PresentationArmstrong Teasdale
 
Sense and Sensibility: The Pros and Cons of New Alternatives To Patent Litiga...
Sense and Sensibility: The Pros and Cons of New Alternatives To Patent Litiga...Sense and Sensibility: The Pros and Cons of New Alternatives To Patent Litiga...
Sense and Sensibility: The Pros and Cons of New Alternatives To Patent Litiga...Armstrong Teasdale
 
Super Sized Strikes: Nonunion Strikes Can Burn Unprepared Employers
Super Sized Strikes: Nonunion Strikes Can Burn Unprepared EmployersSuper Sized Strikes: Nonunion Strikes Can Burn Unprepared Employers
Super Sized Strikes: Nonunion Strikes Can Burn Unprepared EmployersArmstrong Teasdale
 

Mais de Armstrong Teasdale (20)

How to Avoid TROUBLE: Legal Ethics for In House Counsel Featuring Larry Tucker
How to Avoid TROUBLE: Legal Ethics for In House Counsel Featuring Larry TuckerHow to Avoid TROUBLE: Legal Ethics for In House Counsel Featuring Larry Tucker
How to Avoid TROUBLE: Legal Ethics for In House Counsel Featuring Larry Tucker
 
Don't be SORRY for Data Breach Missteps Featuring: Dan Nelson
Don't be SORRY for Data Breach Missteps Featuring: Dan NelsonDon't be SORRY for Data Breach Missteps Featuring: Dan Nelson
Don't be SORRY for Data Breach Missteps Featuring: Dan Nelson
 
Armstrong Teasdale Kansas City Employment & Labor Seminar Featuring: Dan O'To...
Armstrong Teasdale Kansas City Employment & Labor Seminar Featuring: Dan O'To...Armstrong Teasdale Kansas City Employment & Labor Seminar Featuring: Dan O'To...
Armstrong Teasdale Kansas City Employment & Labor Seminar Featuring: Dan O'To...
 
Armstrong Teasdale Employment & Labor Seminar Featuring: Dan O'Toole, J.P. Ha...
Armstrong Teasdale Employment & Labor Seminar Featuring: Dan O'Toole, J.P. Ha...Armstrong Teasdale Employment & Labor Seminar Featuring: Dan O'Toole, J.P. Ha...
Armstrong Teasdale Employment & Labor Seminar Featuring: Dan O'Toole, J.P. Ha...
 
Drop the Phone & Drive: Limits on Lawyer Communications with Non-Lawyers Feat...
Drop the Phone & Drive: Limits on Lawyer Communications with Non-Lawyers Feat...Drop the Phone & Drive: Limits on Lawyer Communications with Non-Lawyers Feat...
Drop the Phone & Drive: Limits on Lawyer Communications with Non-Lawyers Feat...
 
Cyber Readiness in the Securities and Brokerage Industries Featuring Armstron...
Cyber Readiness in the Securities and Brokerage Industries Featuring Armstron...Cyber Readiness in the Securities and Brokerage Industries Featuring Armstron...
Cyber Readiness in the Securities and Brokerage Industries Featuring Armstron...
 
Challenging the Validity of a Patent Before the PTAB Featuring Scott Eidson &...
Challenging the Validity of a Patent Before the PTAB Featuring Scott Eidson &...Challenging the Validity of a Patent Before the PTAB Featuring Scott Eidson &...
Challenging the Validity of a Patent Before the PTAB Featuring Scott Eidson &...
 
Multijurisdictional practice issues for traveling lawyers ethics michael_downey
Multijurisdictional practice issues for traveling lawyers ethics michael_downeyMultijurisdictional practice issues for traveling lawyers ethics michael_downey
Multijurisdictional practice issues for traveling lawyers ethics michael_downey
 
BUCKLE UP! How the NLRB is Changing the Rules of the Road
BUCKLE UP!  How the NLRB is Changing the Rules of the RoadBUCKLE UP!  How the NLRB is Changing the Rules of the Road
BUCKLE UP! How the NLRB is Changing the Rules of the Road
 
China 2014: Law Changes and Opportunities in 7% GDP Growth Environment
China 2014: Law Changes and Opportunities in 7% GDP Growth EnvironmentChina 2014: Law Changes and Opportunities in 7% GDP Growth Environment
China 2014: Law Changes and Opportunities in 7% GDP Growth Environment
 
Employment & Labor Seminar Presentation 2014 - Kansas City
Employment & Labor Seminar Presentation 2014 - Kansas CityEmployment & Labor Seminar Presentation 2014 - Kansas City
Employment & Labor Seminar Presentation 2014 - Kansas City
 
Avoiding Legal Road Hazards While Traveling the Interactive Web
Avoiding Legal Road Hazards While Traveling the Interactive Web Avoiding Legal Road Hazards While Traveling the Interactive Web
Avoiding Legal Road Hazards While Traveling the Interactive Web
 
Employment & Labor Seminar Presentation 2014 - St. Louis
Employment & Labor Seminar Presentation 2014 - St. LouisEmployment & Labor Seminar Presentation 2014 - St. Louis
Employment & Labor Seminar Presentation 2014 - St. Louis
 
2014 Missouri Legislative Preview -Kansas City
2014 Missouri Legislative Preview -Kansas City2014 Missouri Legislative Preview -Kansas City
2014 Missouri Legislative Preview -Kansas City
 
2014 Missouri Legislative Preview-St. Louis
2014 Missouri Legislative Preview-St. Louis2014 Missouri Legislative Preview-St. Louis
2014 Missouri Legislative Preview-St. Louis
 
"The Importance of Being Earnest" How to Dodge Legal Pitfalls that Confront F...
"The Importance of Being Earnest" How to Dodge Legal Pitfalls that Confront F..."The Importance of Being Earnest" How to Dodge Legal Pitfalls that Confront F...
"The Importance of Being Earnest" How to Dodge Legal Pitfalls that Confront F...
 
Fundamental Intellectual Property Strategies
Fundamental Intellectual Property StrategiesFundamental Intellectual Property Strategies
Fundamental Intellectual Property Strategies
 
USLFG Corporate & Securities Presentation
USLFG Corporate & Securities PresentationUSLFG Corporate & Securities Presentation
USLFG Corporate & Securities Presentation
 
Sense and Sensibility: The Pros and Cons of New Alternatives To Patent Litiga...
Sense and Sensibility: The Pros and Cons of New Alternatives To Patent Litiga...Sense and Sensibility: The Pros and Cons of New Alternatives To Patent Litiga...
Sense and Sensibility: The Pros and Cons of New Alternatives To Patent Litiga...
 
Super Sized Strikes: Nonunion Strikes Can Burn Unprepared Employers
Super Sized Strikes: Nonunion Strikes Can Burn Unprepared EmployersSuper Sized Strikes: Nonunion Strikes Can Burn Unprepared Employers
Super Sized Strikes: Nonunion Strikes Can Burn Unprepared Employers
 

Último

Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Roland Driesen
 
Pharma Works Profile of Karan Communications
Pharma Works Profile of Karan CommunicationsPharma Works Profile of Karan Communications
Pharma Works Profile of Karan Communicationskarancommunications
 
The Coffee Bean & Tea Leaf(CBTL), Business strategy case study
The Coffee Bean & Tea Leaf(CBTL), Business strategy case studyThe Coffee Bean & Tea Leaf(CBTL), Business strategy case study
The Coffee Bean & Tea Leaf(CBTL), Business strategy case studyEthan lee
 
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756dollysharma2066
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayNZSG
 
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756dollysharma2066
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Dave Litwiller
 
Grateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdfGrateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdfPaul Menig
 
7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...Paul Menig
 
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779Delhi Call girls
 
RSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors DataRSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors DataExhibitors Data
 
Cracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptxCracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptxWorkforce Group
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMANIlamathiKannappan
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...amitlee9823
 
Regression analysis: Simple Linear Regression Multiple Linear Regression
Regression analysis:  Simple Linear Regression Multiple Linear RegressionRegression analysis:  Simple Linear Regression Multiple Linear Regression
Regression analysis: Simple Linear Regression Multiple Linear RegressionRavindra Nath Shukla
 
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...rajveerescorts2022
 
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...lizamodels9
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Neil Kimberley
 
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...lizamodels9
 

Último (20)

Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...
 
Pharma Works Profile of Karan Communications
Pharma Works Profile of Karan CommunicationsPharma Works Profile of Karan Communications
Pharma Works Profile of Karan Communications
 
The Coffee Bean & Tea Leaf(CBTL), Business strategy case study
The Coffee Bean & Tea Leaf(CBTL), Business strategy case studyThe Coffee Bean & Tea Leaf(CBTL), Business strategy case study
The Coffee Bean & Tea Leaf(CBTL), Business strategy case study
 
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabiunwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
 
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 May
 
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
 
Grateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdfGrateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdf
 
7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...
 
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
 
RSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors DataRSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors Data
 
Cracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptxCracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptx
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMAN
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
 
Regression analysis: Simple Linear Regression Multiple Linear Regression
Regression analysis:  Simple Linear Regression Multiple Linear RegressionRegression analysis:  Simple Linear Regression Multiple Linear Regression
Regression analysis: Simple Linear Regression Multiple Linear Regression
 
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
 
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023
 
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
 

HIPAA Compliance Guide for Navigating Breaches and Risk Assessments

  • 1. © 2013 Armstrong Teasdale LLP© 2013 Armstrong Teasdale LLP HIPAA: Navigating the Labyrinth Anna Selby Diane Keefe July 31, 2013
  • 2. © 2013 Armstrong Teasdale LLP Navigating the Labyrinth
  • 3. © 2013 Armstrong Teasdale LLP Call From Employee 1) Staff Texting Nude Patient Photo. • Patient is Identifiable. • Hospital Name is visible on scrubs. 2) Nurses photograph x-ray. • Post x-ray to Facebook. • Nurse comments regarding patient.
  • 4. © 2013 Armstrong Teasdale LLP HIPAA  Regulations Apply to: • Covered Entities (CE) 1) Providers 2) Health Plans 3) Clearinghouses  Business Associates of CE’s • Insurance Broker, Benefit Specialists • Strategic Consultants
  • 5. © 2013 Armstrong Teasdale LLP HIPAA Protects PHI PERSONAL HEALTH INFORMATION
  • 6. © 2013 Armstrong Teasdale LLP PHI Uses & Disclosures  OK to use PHI for: 1) Treatment 2)Payment 3) Health Care Operations  General Rule: Other Uses Require an Authorization.
  • 7. © 2013 Armstrong Teasdale LLP HIPAA Breach - New Definition  A Breach is 1. Unauthorized acquisition, access, use or disclosure of 2. Unsecured PHI 3. Compromises the privacy or security of the PHI  Presumption of Reportable Breach UNLESS • CE determines there is a low probability the • PHI has been compromised after risk assessment.
  • 8. © 2013 Armstrong Teasdale LLP HIPAA Risk Assessment  What is Compromised? • Rule does not tell us.  Must Perform Risk Assessment.
  • 9. © 2013 Armstrong Teasdale LLP HIPAA Risk Assessment  4 Elements: 1. Nature and extent of PHI involved. 2. The unauthorized person who used PHI or to whom disclosure was made. 3. Whether PHI was actually acquired or viewed. 4. Extent to which the risk to PHI has been mitigated.
  • 10. © 2013 Armstrong Teasdale LLP HIPAA Risk Assessment  If you do not do a breach notification you MUST do a Risk Assessment.  DOCUMENT, DOCUMENT, DOCUMENT.
  • 11. © 2013 Armstrong Teasdale LLP HIPAA Breaches  CVS 2009-Pill bottles thrown in dumpsters. • $2.25 Million Settlement • No policies. • No training.
  • 12. © 2013 Armstrong Teasdale LLP HIPAA Breaches  Million Dollar Subway Ride • Massachusetts General Hospital employee leaves documents on subway. • PHI of 192 patients. (Included HIV/AIDS status) • $1 Million Settlement.  Stanford 2011. BA posts PHI on web. • 20,000 patients X $1,000 = $20 Million
  • 13. © 2013 Armstrong Teasdale LLP HIPAA Breaches  WellPoint—July 11, 2013  Left Accessible Information on Internet  $1.7 Million Settlement  600,000 Patients’ Information  WellPoint failed to: 1) Have Policies to authorize access to PHI; 2) Perform technical evaluation of software & database; 3) Have technical safeguards to verify identify of persons accessing PHI.
  • 14. © 2013 Armstrong Teasdale LLP HIPAA Breaches-Laptops  Sutter 2011. Stolen unencrypted laptop. • 4 million patients X $1,000 nominal damages per patient. • $1 Billion Potential Damages.  UCLA 2011. • Encrypted laptop stolen. Paper also stolen. • 16,000 patients X $1,000 • $16 Million.
  • 15. © 2013 Armstrong Teasdale LLP HIPAA Breaches-Hardware  Blue Cross Blue Shield Tennessee 2012 • Self Reported 57 unencrypted hard drives stolen. • 1 Million people. $1.5 Million Settlement.  Pentagon 2011 • BA lost backup tapes, 4.9 Million Tricare beneficiaries. • If damages are $1,000 per patient = $4.9 Billion. • Attempted to use HIPAA for basis of claims.
  • 16. © 2013 Armstrong Teasdale LLP Lawsuits Pending  Plaintiffs claim HIPAA violations. (Negligence Per Se)  Case law is not clear.  We argue no private right of action.  Motions to dismiss granted.  Breach of Fiduciary Duty & Public Disclosure of Private Fact claims remain.  Each suit involved OCR investigation.
  • 17. © 2013 Armstrong Teasdale LLP HIPAA Breach  If you don’t need it for your job=Unauthorized. Snooping.
  • 18. © 2013 Armstrong Teasdale LLP Snooping  There once was a girl …  Later goes to psych ward at UCLA…  People get curious.  13 fired & 12 disciplined.  OCR investigates $865,000  No evidence PHI disclosed or sold.
  • 19. © 2013 Armstrong Teasdale LLP Snooping  Little Rock: News anchor in hospital.  Physician watches news from home.  Unit Coordinator & Billing employee.  2 fired; physician suspended 2 weeks. • Face prison & fine. • Each had HIPAA training.  Mom sues Hospital. • AR SC allows outrageous behavior claim.
  • 20. © 2013 Armstrong Teasdale LLP Yes, Someone Went to Prison.  Researcher at UCLA  Reviewed records 323 times in 3 weeks.  His Boss,  No Evidence PHI was Used or Sold.  4 Months in Prison.
  • 21. © 2013 Armstrong Teasdale LLP Breach Notifications < 500  Breach • Must Notify Individual(s) − In Writing including what happened & steps taken. − Within 60 days of date breach discovered. • Notify HHS Secretary  Don’t Delay.
  • 22. © 2013 Armstrong Teasdale LLP Breach Notifications > 500  Where a Breach Involves Greater than 500 Residents: • Notify Individuals in Writing • Notify HHS Secretary • Notify Media − Press Release to “Prominent” media outlets. − Within 60 days.
  • 23. © 2013 Armstrong Teasdale LLP Penalties-Civil  Per identical violation in a calendar year: Did Not Know: $100 up to $25,000 Willful Neglect Uncorrected: $50,000 up to $1,500,000 Willful Neglect: Conscious, intentional failure or reckless indifference.  Can be Per Record.  Extend to BA’s.  Can impose penalty without seeking informal resolution.
  • 24. © 2013 Armstrong Teasdale LLP Penalties-Criminal  People that knowingly obtain or disclose PHI: • Up to $50,000 AND 1 year imprisonment.  With False Pretenses: • Up to $100,000 AND 5 years.  With Intent to sell or use for personal gain or malicious harm: • Up to $250,000 AND 10 years.
  • 25. © 2013 Armstrong Teasdale LLP When a Breach Occurs:  Call Us.  What We Can Do: • Walk you through whether it is reportable. − Multiple factors. • Advise during investigation. • Assist with Proactive Prevention.
  • 26. © 2013 Armstrong Teasdale LLP What Can/Should be Done to Comply?  Most obvious • Modify your Business Associate Agreements • Modify your Notice of Privacy Practices  Not so obvious… • Conduct a Risk Assessment • Review, evaluate and update polices and procedures • Educate and train staff/employees
  • 27. © 2013 Armstrong Teasdale LLP Modifications to the BAA’s  A statement that the Business Associate (“BA”) now needs to comply with the administrative, physical, and technical components of the Security Rule • Should also reflect that the BA is required to implement and maintain compliance with the administrative, physical, and technical components of the Security Rule
  • 28. © 2013 Armstrong Teasdale LLP Modifications to BAAs  A statement that the BA must report to the Covered Entity any breach of unsecured PHI (in addition to any unauthorized use or disclosure) • Should reflect exactly what the BA should do in order to notify the Covered Entity of the breach: − Date of incident − Date of discovery of incident (if different than above) − Categories of the affected information − Individual(s) who were affected − Steps for mitigation − Steps for prevention
  • 29. © 2013 Armstrong Teasdale LLP Modifications to BAAs  A statement that the BA must ensure that any subcontractor will agree to the same restrictions and conditions that apply to the BA • In other words, BAs now need to enter into BAAs with subcontractors  A statement requiring the BA to implement a system for documenting and recording uses and disclosures in compliance with the Security Rule  A statement that provides for retention of information for 6 years from the date of the disclosure
  • 30. © 2013 Armstrong Teasdale LLP Modifications to BAAs  Other Aspects to Consider • Liability is determined on Agency principles, so a statement that reflects the status of the parties • Consider modifying or adding insurance requirements • Consider modifying or adding limitations of liability and indemnification provisions
  • 31. © 2013 Armstrong Teasdale LLP Modifications to BAAs  Compliance Deadline • depends on whether there is an existing BAA or whether there will be a new BAA entered into between the parties − If existing BAA, then September 22, 2014 − If no existing BAA, then September 23, 2013
  • 32. © 2013 Armstrong Teasdale LLP Modifications to Notice of Privacy Practices  Must now include statements regarding the Sale of PHI  Must now include statements regarding marketing and other purposes that require an authorization  Must now include statement that an individual can opt out of fundraising communications/efforts
  • 33. © 2013 Armstrong Teasdale LLP Modifications to Notice of Privacy Practices  Must now include statement that the Covered Entity must agree to restrict disclosures to health plans if the individual pays out of pocket in full for the health care service  Must now include a statement about an individual’s right to receive breach notifications
  • 34. © 2013 Armstrong Teasdale LLP Conducting a Risk Assessment  Elements of a general risk assessment include: 1. Identify the scope – what are potential risks and vulnerabilities to your organization? 2. Identify where all the PHI is stored, received, maintained or transmitted 3. Assess current security measures: − Do you utilize encryption software? − Are passwords used and changed frequently? − Are firewalls used? − Are mobile devices protected?
  • 35. © 2013 Armstrong Teasdale LLP Conducting a Risk Assessment  Other Aspects: • Determine likelihood of the occurrence of a threat • Determine the potential impact of that threat • Determine the level of risk  Which becomes a mathematical equation… • Vulnerability x likelihood x impact = level of risk  Which can then assist in the mitigation that risk
  • 36. © 2013 Armstrong Teasdale LLP Conducting a Risk Assessment Threat Source Terminated EE Calculation Threat Unauthorized Access to Patient Information Vulnerability No formal process in place to notify the IT department when ee’s are terminated and periodic reviews are not performed 3 Likelihood Removal of access for terminated ee has not been performed 3 Impact PHI is viewed, altered or destroyed 3 Risk Disgruntled ee gains unauthorized access to PHI after termination, deleting records Total = 27 Risk Mitigation IT implements daily automated program to read ee database in payroll system and automatically removes access to network and application systems for terminated ees Risk is now significantly reduced
  • 37. © 2013 Armstrong Teasdale LLP Reviewing/Updating Policies and Procedures  Update policies and procedures on breach notification and integrate into the policy the four factors of whether a breach occurred by a risk assessment: 1. Nature and extent of the PHI involved 2. The unauthorized person who used the PHI or to whom the disclosure was made 3. Whether PHI was actually acquired or viewed 4. Extent to which the risk has been mitigated
  • 38. © 2013 Armstrong Teasdale LLP Reviewing/Updating Policies and Procedures  Use and disclosure of PHI for marketing • Requires determination of what is and is not considered marketing • Once that determination is made, then clarify the policy to reflect what requires an authorization from the individual  Sale of PHI • Selling an individual’s PHI without an authorization is prohibited
  • 39. © 2013 Armstrong Teasdale LLP Reviewing/Updating Policies and Procedures  Electronic Access to PHI • May require revisions to job descriptions to clearly delineate who has access and in what situation • May require revisions to IT policies and procedures  Requests for Restrictions  Use and disclosures of decedent information  Social media and cell phone policies
  • 40. © 2013 Armstrong Teasdale LLP Reviewing/Updating Policies and Procedures  Covered entities may use any security measures that allow them to reasonably and appropriately implement the HIPAA regulations. So, in determining whether to draft new or revise old policies and procedures, you should consider: • Size, complexity, and capabilities of the Covered Entity • Technical infrastructure, hardware, and software • Costs • Likelihood and impact of risks or potential risks, i.e., risk assessment
  • 41. © 2013 Armstrong Teasdale LLP Educate and Train Staff/Employees  Must ensure that the policies and procedures reviewed, revised, and/or created are implemented by staff/employees.  Sign-in sheets should be passed around so attendance of staff members/employees is documented  Staff/Employee training must be conducted at the following intervals: • At the start of employment • Annual basis  If staff/employees do not apply these policies to their everyday practice, then organizations are at risk!
  • 42. © 2013 Armstrong Teasdale LLP Questions? Anna Selby 314.552.6616 aselby@armstrongteasdale.com Diane Keefe 314.259.4731 dkeefe@armstrongteasdale.com