Learning Objectives
After completion of the course you’ll be able to:
Privacy Rule: General Topics
List 5 things that the HIPAA Privacy Rule requires the average provider or health plan to do.
Describe how the HIPAA Privacy Rule protects individuals’ medical records and other personal health information.
Covered Entities
Business Associate
Permitted Uses and Disclosures
Minimum Necessary
Right to Access Medical Records
Right to Amend Medical Records
Right to Accounting Disclosures
Incidental Uses and Disclosures
Discuss various situations where incidental uses and disclosures of protected health information are permitted under the Privacy Rule.
Provide examples of reasonable safeguards a covered entity must implement to limit incidental, and avoid prohibited, uses and disclosures of protected health information.
Public Health Uses and Disclosures
Marketing Uses and Disclosures
Define marketing and distinguish between what is marketing and what is not marketing under the HIPAA Privacy Rule.
Discuss situations when an authorization is required from the patient before a provider or health plan can engage in marketing to that individual.
Distinguish between activities for treatment or health care operations versus marketing activities.
Identify two circumstances when a patient’s prior authorization is required for the use and disclosure of protected health information for marketing.
Workers’ Compensation
Limited Data Set
Discuss the requirement of limited data set.
Discuss the use and disclosure of limited data set to a business associate under the HIPAA Privacy Rule.
Notice of Privacy Practices
Discuss the right provided by the Privacy Rule to individuals to receive a notice of privacy practices for protected health information, and specify the content of the notice.
Identify three entities who are not required to develop a notice of privacy practices.
Personal Rep/Parents and Minors
Research Uses and Disclosures
Administrative Simplification
Contents
1. Protecting the Privacy of Patient’s Health Information
v
Overviewv
Patient Protectionsv
Health Plans and Providersv
Outreach and Enforcement2. Summary of the HIPAA Privacy Rule
v
Introductionv
Statutory & Regulatory Backgroundv
Who Is Covered by The Privacy Rulev
Definitionsv
Business Associatesv
What Information Is Protectedv
General Principle for Uses and Disclosuresv
Permitted Uses and Disclosuresv
Authorized Uses and Disclosuresv
Limiting Uses and Disclosures to the Minimum Necessaryv
Notice and Other Individual Rightsv
Administrative Requirementsv
Organizational Optionsv
Other Provisions: Personal Representatives and Minors’ Personal Representativesv
State Lawv
Enforcement and Penalties for Noncompliancev
Compliance Datesv
Copies of the Rule & Related Materialsv
Incidental Uses and Disclosuresv
Minimum Necessaryv
Personal Representativesv
Business Associatesv
Uses and Disclosures for Treatment, Payment, and Health Care Operationsv
Marketingv
Disclosures For Public Health Activitiesv
Researchv
Disclosures For Workers’ Compensation Purposesv
Notice of Privacy Practice For Protected Health Informationv
Restrictions on Government Access to Health Information3. Implementation of Administrative Simplification Requirements by HHS
Overview
Implementation Plan
Standards Adoption Process
Public and Private Sector Input into the Standards Development Process
Implementation Schedule
Understanding CMS’s Compliance Policy
What Is a Contingency Plan?
Steps For Contingency Planning
Health Plan Responsibilities
Review Your Good Faith Efforts to Comply
4. Security Standard
v
General Approachv
Specific Requirementsv
Guidance on Compliance with HIPAA Transactions and Code Sets After the October 16, 2003 ImplementationDeadlineEnforcement Approach
Working Toward Compliance
v
HIPAA Administrative Simplification Compliance Act (ASCA)v
Electronic Transaction Standardsv
Code Set StandardsWhat Is a Code Set
What Code Sets Have Been Adopted as HIPAA Standards?
5. FAQ About HIPAA
v
HIPAA: In Generalv
Privacy Rule: General Topicsv
Protected Health Informationv
Preemption of State Lawv
Covered Entitiesv
Compliance Datesv
Minimum Necessaryv
Business Associatesv
Treatment/Payment/Health Care Operationsv
Right to Access Medical Recordsv
Complaintsv
Right to an Accounting of Disclosuresv
Incidental Uses and Disclosuresv
Public Health Uses and Disclosuresv
Facility Directoriesv
Disclosure to Family and Friendsv
Disclosures Required by Lawv
Disclosures for Rule Enforcementv
Disclosures for Law Enforcement Purposesv
Authorizationsv
Marketing Uses and Disclosuresv
Workers’ Compensation Disclosuresv
Notice of Privacy Practicesv
Personal Reps/Parents and Minorsv
Limited Data Setv
Research Uses and Disclosuresv
Transition ProvisionAppendix A: Notice of Privacy Practices
Appendix B: Sample Business Associate Contract
Appendix C: How to File a Health Information Privacy Complaint With the Office For Civil Rights