lmc 2005 1 what is hipaa and how to comply with it? health insurance portability and accountability...

29
LMC 2005 1 WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996

Upload: cali-bobb

Post on 14-Dec-2015

215 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: LMC 2005 1 WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996

LMC 20051

WHAT IS HIPAA AND HOW TO COMPLY WITH IT?

Health Insurance Portability and Accountability Act of 1996

Page 2: LMC 2005 1 WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996

LMC 20052

WHAT IS HIPAA?

HIPAA stands for Health Insurance Portability and Accountability Act, a federal law enacted in 1996 to help employees maintain health insurance when they move to a different job, and to receive health insurance regardless of preexisting conditions.

Page 3: LMC 2005 1 WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996

LMC 20053

What is HIPAA…continued

The newest part of HIPAA also ensures privacy for patients and their health information.

  Covered entities include any health

care provider, health care clearing house, and health care plans.

Page 4: LMC 2005 1 WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996

LMC 20054

LMC AND HIPAA

LMC is dedicated to maintaining patient privacy and securing any protected health information (PHI) from inappropriate use or disclosure.

This presentation is intended to introduce you to HIPAA and to the general guideline to help you implement these requirements in your job.

Page 5: LMC 2005 1 WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996

LMC 20055

HIPAA: RIGHTS AND RESPONSIBILITIES

Every patient will be given a Notice of Privacy Practices (NPP) at the first point of service delivery from LMC. The NPP will inform patients of their privacy rights. These rights include: The right to restrict certain release of information,

which the patient can revoke or change at any time. The patient may request that their name not be included on the general registry.

The right to request confidential communications. Examples would include having their medical information mailed to an alternate address, or contacting them at an alternate phone number.

Page 6: LMC 2005 1 WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996

LMC 20056

PATIENTS’ RIGHTS… continued

The right to receive a paper copy of the Notice of Privacy Practices (NPP).

The right to amend protected health information (PHI) through a request to the Privacy Officer.

The right to an accounting of disclosures or releases done without patient authorization. Examples include disease reporting and animal bite reporting.

The right to inspect and copy, and to obtain a copy of their medical record.

Page 7: LMC 2005 1 WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996

LMC 20057

WHO DOES THE PATIENT GO TO FOR THESE SERVICES?

Most of these restrictions can be handled by each department. For those requests that cannot, contact the LMC Privacy Officer:

George Evans

Director of Information Services

803-936-8235

Email: [email protected]

Page 8: LMC 2005 1 WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996

LMC 20058

WHO does HIPAA cover and protect?

HIPAA covers all PATIENTS and their protected health information (PHI).

HIPAA covers ANYONE who deals with patients or their protected health information.

HIPAA covers any ORGANIZATION and their BUSINESS ASSOCIATES who deal with patients and/or their protected health information

Page 9: LMC 2005 1 WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996

LMC 20059

THE PATIENT JOURNEY AND HIPAA

At every point where we come in contact with the patient or with protected health information, we must each do our part to maintain privacy.

Think of the “journey” of a patient through the LMC system:

Page 10: LMC 2005 1 WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996

LMC 200510

WHERE DO WE INTERACT WITH THE PATIENT?

Registration/scheduling process Waiting area Treatment area During transport Billing inquiry requests

Page 11: LMC 2005 1 WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996

LMC 200511

PASSWORD PROTECTION PLAN

PASSWORD DOS AND DON’TS DO protect your password DO use good password choices DO change your password if you feel it has been violated DON’T share your password with anyone DON’T use anyone else’s password DON’T work under anyone else’s password DON’T leave passwords displayed on keyboards or

monitors

Page 12: LMC 2005 1 WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996

LMC 200512

COMPUTER SECURITY

Each user is responsible for maintaining the integrity of his or her computer password.

Your password is linked to ‘you’. Protect yourself by protecting your

password.

Page 13: LMC 2005 1 WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996

LMC 200513

Computer Security …What is the difference between “privacy” and “security?”

Privacy refers to WHAT is protected: Health information about an individual, and the

determination of WHO is permitted to use or disclose or access the information, is protected.

Security refers to HOW private information is safeguarded:

Privacy is ensured by controlling access to information and protecting it from inappropriate disclosure and accidental or intentional destruction or loss.

Page 14: LMC 2005 1 WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996

LMC 200514

Privacy/Security Issues: Types of Violations of HIPAA

Accidentally releasing patient information to a non-intended recipient. Examples include discussing patient information in public location.

Accessing a patient record without a legitimate business need to know

Using another person’s user ID. Allowing another employee to access LMC information

systems with my password. Failure to log off when leaving station, allowing unattended

and unauthorized access. Purposeful break in Confidentiality Agreement.

Page 15: LMC 2005 1 WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996

LMC 200515

Ask Yourself this Question:

Before accessing protected health information:

Do I have a business need to know?

Page 16: LMC 2005 1 WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996

LMC 200516

Who can lodge a complaint?

Privacy related complaints may be made byPatientsFamily membersVisitorsAnyone

Page 17: LMC 2005 1 WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996

LMC 200517

Where can people make complaints?

Secretary of Department of Health and Human Services (federal government)

LMC Privacy Officer

NOTE: All privacy-related complaints handled by LMC staff must be forwarded to the LMC Privacy Officer for tracking purposes according to the law.

Page 18: LMC 2005 1 WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996

LMC 200518

What are LMC Privacy Policies and Where Can I Find Them?

The LMC Privacy Policies are: Protected Health Information Privacy Compliance Notice of Privacy Practices Business Associates Patient Complaints and GrievancesThese policies may be viewed as needed upon arrival to

Lexington Medical Center via access to the Intranet

Page 19: LMC 2005 1 WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996

LMC 200519

Here’s the situation. What would you do?

You notice that your department has a broken computer that can no longer be used. What should you do?

1. Call Help Desk at 2022 so they can pick up the computer.

2. Take computer and have it repaired and then take it home.

3. Throw it in the dumpster.

Correct Answer:1. Call Help Desk at 2022 so they can pick up the

computer.

Press ‘enter’ to see answer

Page 20: LMC 2005 1 WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996

LMC 200520

What would you do?

You have printed too many copies of a document containing PHI. What should you do with the extra copies?

1. Throw copies in the nearest waste basket.

2. Shred copies and throw them away.3. Dispose of copies in locked recycle bin.

Correct Answer:

3. Dispose of copies in locked recycle bin.

Press ‘enter’ to see answer

Page 21: LMC 2005 1 WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996

LMC 200521

What would you do?

Your friend is having lab work done today. She contacts you at work and requests that you access her lab results on the computer and let her know the outcome. What should you do?1. Look up her labs and call her back with her

results.2. Do not look up her labs. Tell her to contact her

physician for the results. Correct Answer:2. Do not look up her labs. Tell her to contact her

physician for the results.

Press ‘enter’ to see answer

Page 22: LMC 2005 1 WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996

LMC 200522

What would you do?

A “Mayday” is called for ICU Bed 1. You are concerned about a coworker who was admitted to ICU during the night. It is OK for you to access the patient record online to see if this is your coworker. 

1. True

2. False

Press ‘enter’ to see answerCorrect Answer:2. False. It is NOT OK for you to

access the patient record online to see if this is your coworker. 

Page 23: LMC 2005 1 WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996

LMC 200523

What would you do?

You see a well-known local football coach waiting in the ED with his family. He is also a family friend. You are concerned. What should you do?

1. Go online and search for medical information pertaining to your friend and or his family member.

2. Ask a co-worker why this family is here.3. Say hello to your friend and respect their right to

privacy. Press ‘enter’ to see answerCorrect Answer:3. Say hello to your friend and respect their right

to privacy.

Page 24: LMC 2005 1 WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996

LMC 200524

What is HIPAA?

1. Health Insurance Portability and Accountability Act

2. Health Insurance Privacy and Authorization Act3. Health Insurance Procurement Action Act

HealthInsurance Portability

and Accountabilit

y Act

Press ‘enter’ to see answer

Page 25: LMC 2005 1 WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996

LMC 200525

True or False ?

The following indicators are considered PHI (protected health information):

1. Patient’s name2. Patient’s date of birth3. Patient’s diagnosis4. Patient’s visit or account number for billing purposes5. Patient’s social security number6. Patient’s billing information

Press ‘enter’ to see answer

Correct Answer:True. Any individual identifiable

health information is considered PHI.

Page 26: LMC 2005 1 WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996

LMC 200526

HIPAA Reminders:

Be aware of  WHERE you discuss patient information

SHRED paper containing PHI LOG OFF computer  before you walk  away Do not access PHI in any medium unless  you

have the RIGHT OR NEED TO KNOW DO NOT SHARE your computer LOGIN

or password KEEP patient RECORDS  in SECURE location

Page 27: LMC 2005 1 WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996

LMC 200527

THIS IS SERIOUS: CIVIL AND CRIMINAL PENALTIES

CAN BE APPLIED TO INDIVIDUALS OR ORGANIATION

$100.00 per violation, not to exceed $25,000 per violation per person or incident

$50,000 and up to one year in prison for knowingly obtaining or disclosing individual identifiable health information (IIHI) illegally

$100,000 and up to 5 years in prison if done under false pretenses.

$250,000 and up to ten years in prison if done with the intent to sell, transfer, or use for commercial advantage, personal gain or malicious harm.

Page 28: LMC 2005 1 WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996

LMC 200528

How to get more information on HIPAA:

Ask your supervisor or directorGo to

Contact George Evans, Director of Information Services & LMC Privacy Officer or

Contact Tammy Grubbs in Information Services

Both can be reached at 803-936-8235

or via email: [email protected]

Page 29: LMC 2005 1 WHAT IS HIPAA AND HOW TO COMPLY WITH IT? Health Insurance Portability and Accountability Act of 1996

LMC 200529

DOCUMENTATION OF TRAINING:

Your clinical rotation group will be asked to sign a “HIPAA Training Confirmation” Form along with a “Confidentiality Acknowledgement” upon arrival to clinical areas.