WELCOME to The University of Toledo Lynn Hutt

  • Slides: 28
Download presentation
WELCOME to The University of Toledo Lynn Hutt Compliance/Privacy Officer

WELCOME to The University of Toledo Lynn Hutt Compliance/Privacy Officer

Topics o Compliance o HIPAA o Privacy o Security o Family Educational Rights and

Topics o Compliance o HIPAA o Privacy o Security o Family Educational Rights and Privacy Act - FERPA o Public Records o Obama Administration - 2010

Who is the Compliance Officer? Lynn Hutt

Who is the Compliance Officer? Lynn Hutt

Health Insurance Portability and Accountability Act (HIPAA) o Privacy – covers certain health information

Health Insurance Portability and Accountability Act (HIPAA) o Privacy – covers certain health information in any form. Written, spoken, electronic or any other form. o Security – covers information that is stored or transmitted electronically. Internet, computer networks.

What is HIPAA? o Law created to improve access to health insurance, protect the

What is HIPAA? o Law created to improve access to health insurance, protect the privacy of health information and promote standardization of electronic healthcare related records to improve and safeguard their use. o Not: Hospitals In Pain, Aguish, and Agony

Patient privacy is everyone’s concern. It’s a basic part of patient care.

Patient privacy is everyone’s concern. It’s a basic part of patient care.

What can happen if you don’t follow the Privacy Rule? o There may be

What can happen if you don’t follow the Privacy Rule? o There may be a fine for each violation of the rule. Total fines can go up to $1. 5 million per year. o A person can be fined or sent to prison. o “Fifteen fired, eight disciplined for looking at medical records of octuplet mother. ” Fox. News. com March 2009 o “CVS Pays $2. 25 Million to Settle HIPAA Privacy Case” HHS. gov Feb 2009 o “Staff nurse faces jail time for copying medical record with intent to do malicious harm. Possible 10 years in prison, fine of $250, 000. The nursing board is seeking to revoke her license. ” Renal and Urology News Oct. 2008

A Closer look at PHI o Pay attention to information that gives details about

A Closer look at PHI o Pay attention to information that gives details about who a person is: o o o o Name Social Security Number, Account Number, MRN All or part of an address Phone or fax number Drivers License number, license plate Date of Birth Admission or discharge date Tattoo's When combined with health information these could be considered PHI. Health Information is protected if it could be used to identify somebody.

Examples of PHI: o o Medical record Prescription label An x-ray Doctor’s notes about

Examples of PHI: o o Medical record Prescription label An x-ray Doctor’s notes about a patient o A letter giving patient test results o Facesheet o Waste material that contains personal information- patient label o Information sent from one place to anothercomputer, fax, phone or mail. o Computer monitors that can be seen by the public o Information that you say ALOUD. o Facebook, pictures of patients. To name a few!!!

HIPAA Rule: Minimum Necessary o Only access PHI you need to do your job.

HIPAA Rule: Minimum Necessary o Only access PHI you need to do your job. o Any time you share PHI with others provide only the information the other person or organization needs.

General rules for disclosing and using PHI o You may disclose or use PHI

General rules for disclosing and using PHI o You may disclose or use PHI for health-care purposes. Treat a patient Get payment for health-care services Continuity of Care Quality Assessment Fraud and Compliance programs Competency activities –accreditation Federal/State Agencies Suspected abuse or neglect Organ donation

Permitted disclosures o T-Treatment o P-Payment o O-Health care operations In all instances, strict

Permitted disclosures o T-Treatment o P-Payment o O-Health care operations In all instances, strict regulations apply.

Incidental disclosures of PHI o When PHI is seen or heard by someone who

Incidental disclosures of PHI o When PHI is seen or heard by someone who does not need to know. o Even though UTMC has taken appropriate steps to limit the information shared or keep the information private. Example-nurses stations or two patients in the same room

Getting authorization to disclose information o Authorization to disclose PHI must be obtained when

Getting authorization to disclose information o Authorization to disclose PHI must be obtained when o Provided to insurer or other business for marketing o Information is communicated to an employer (pre-employment physical)

Some Do’s and Don’ts when talking about patients DO’s DON’Ts o Speak quietly when

Some Do’s and Don’ts when talking about patients DO’s DON’Ts o Speak quietly when possible o Avoid using patient names in hallways and public areas o Share information needed to treat the patient o Use a private space to discuss patient information o Share PHI with people who don’t need to know it to do their job o Share PHI you are not authorized to disclose o Let privacy issues keep you from treating the patient properly

Safeguard guidelines o Shut and lock doors when leaving o PHI should be not

Safeguard guidelines o Shut and lock doors when leaving o PHI should be not visible or audible o Computer monitors should be turned away from the direction of public view o Copy only the minimum necessary o Securely dispose of all PHI o Home offices subject as well o Record storage areas must be secure

Safeguard guidelines cont. o Printers and Fax Machines must be secure o Unauthorized personnel

Safeguard guidelines cont. o Printers and Fax Machines must be secure o Unauthorized personnel may not be left alone without supervision o Policies apply to any Portable Device or LAPTOP o Visitors must be accompanied o EVERYONE is responsible for PHI o DO NOT SHARE YOUR LOG-IN OR PASSWORDS!

Protect printed PHI o Where is printed PHI? o o o o Patient chart

Protect printed PHI o Where is printed PHI? o o o o Patient chart Wrist tag Prescription bottle Lab report X-ray Log sheets/patient lists Patient mailing list Faxes o ALWAYS use a shred bin for printed PHI!

Patient rights o They have them o They know them o Respect them

Patient rights o They have them o They know them o Respect them

Your responsibility o Know policies and practice appropriate procedures within your unit o If

Your responsibility o Know policies and practice appropriate procedures within your unit o If unsure, ASK

FERPA o The Family Educational Rights and Privacy Act of 1974 o Protects students

FERPA o The Family Educational Rights and Privacy Act of 1974 o Protects students educational/treatm ent records.

Public records o The University of Toledo’s operational functions are considered public records. o

Public records o The University of Toledo’s operational functions are considered public records. o Emails o Reports o Contracts

President Obama legislative changes to HIPAA o Health Care Reform o American Recovery &

President Obama legislative changes to HIPAA o Health Care Reform o American Recovery & Reinvestment Act of 2009 (ARRA) o New requirements will include: o o o Notification of HIPAA breaches Application of HIPAA to BA’s Restrictions requested by patients Electronic Health Records Increased penalties and enforcement o HITECH Act

How do I report…. o Report concerns in these steps: o o First to

How do I report…. o Report concerns in these steps: o o First to your professor Advisor or Dean of College Student Academic Affairs Compliance/Privacy Officer, x 6933

What are my rights…. o Non-retaliation policy o Qui tam provisions (“whistleblower” )

What are my rights…. o Non-retaliation policy o Qui tam provisions (“whistleblower” )

Quiz questions o o o Who’s the Compliance/Privacy Officer? Name 3 safeguards for PHI?

Quiz questions o o o Who’s the Compliance/Privacy Officer? Name 3 safeguards for PHI? What does HIPAA stand for? Name 3 examples of PHI. Can you be held personally responsible for a HIPAA violation? o What is minimum necessary? o If you are unsure, what should you do? o PHI used for TPO are permitted disclosures, what does TPO stand for?

COMPLIANCE It’s YOUR Responsibility.

COMPLIANCE It’s YOUR Responsibility.

Questions?

Questions?