Top Banner
“ Technology Working For People” Intro to HIPAA and Small Practice Implementation
29

“ Technology Working For People” Intro to HIPAA and Small Practice Implementation.

Dec 27, 2015

Download

Documents

Darcy Jacobs
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: “ Technology Working For People” Intro to HIPAA and Small Practice Implementation.

“ Technology Working For People”

Intro to HIPAA and

Small Practice Implementation

Page 2: “ Technology Working For People” Intro to HIPAA and Small Practice Implementation.

“ Technology Working For People”

Overview

What is HIPAA?

Transactions

Privacy

Security

Implementation Manual/Process

Page 3: “ Technology Working For People” Intro to HIPAA and Small Practice Implementation.

“ Technology Working For People”

Insurance Reform[Portability]

Insurance Reform[Portability]

Administrative Simplification[Accountability]

Health Insurance Portability and Accountability Act (HIPAA)

Transactions, Compliance

Date: 10/16/2003

Privacy Compliance

Date: 4/14/2003

Security Compliance

Date: 4/21/2005

What is HIPAA?

Page 4: “ Technology Working For People” Intro to HIPAA and Small Practice Implementation.

“ Technology Working For People”

Who is affected ?“Covered Entities” which include:

•Health Plans•Healthcare Clearinghouse•Healthcare Provider who transmits health information in electronic format

(Us )

Page 5: “ Technology Working For People” Intro to HIPAA and Small Practice Implementation.

“ Technology Working For People”

Is it Mostly ProcessOr Mostly “Things” to purchase?

20%

80%

Technical

Process

Page 6: “ Technology Working For People” Intro to HIPAA and Small Practice Implementation.

“ Technology Working For People”

HIPAA Compliance Deadlines

Transaction & Code Sets October 16, 2003 (with extension)

Privacy RegulationApril 14, 2003

Security RegulationsApril 21, 2005 or April 21, 2006 for

small health plans

Page 7: “ Technology Working For People” Intro to HIPAA and Small Practice Implementation.

“ Technology Working For People”

COMPLY?

$100 for each violation

Maximum of $25,000 per year per specific

provision

Penalties up to $250,000 Prison time up to 10 years

Non-Compliance

Unauthorized Disclosure or Misuse of Patient Information

Page 8: “ Technology Working For People” Intro to HIPAA and Small Practice Implementation.

“ Technology Working For People”

Transactions, Codes, & Identifiers

What are they, and why do we care ?

Is it something I control ?

How do we comply?

Page 9: “ Technology Working For People” Intro to HIPAA and Small Practice Implementation.

“ Technology Working For People”

Transaction, Codes, and Identifiers

Verify your vendor or clearinghouse has

been certified?

Tested your electronic claims submission for accuracy?

Page 10: “ Technology Working For People” Intro to HIPAA and Small Practice Implementation.

“ Technology Working For People”

Privacy Regulations Require Designating a Privacy

Officer Educate the Privacy Officer

Take this training moduleBecome familiar with helpful web

sites Begin Implementing the new

Procedures & Policies

Page 11: “ Technology Working For People” Intro to HIPAA and Small Practice Implementation.

“ Technology Working For People”

Privacy Regulation

The Privacy Rule has 3 General AreasPatient RightsCommunicationsAdministration

Page 12: “ Technology Working For People” Intro to HIPAA and Small Practice Implementation.

“ Technology Working For People”

Privacy Regulation

Patient RightsNotice of Privacy PracticeAuthorization FormAccess and Amendment PolicyAccounting and Restrictions Policy

Page 13: “ Technology Working For People” Intro to HIPAA and Small Practice Implementation.

“ Technology Working For People”

Privacy RegulationCommunications

Phone and Face-to-FaceEmail Policy (Optional)Fax PolicyMedical RecordsDe-Identification

Page 14: “ Technology Working For People” Intro to HIPAA and Small Practice Implementation.

“ Technology Working For People”

Privacy RegulationAdministration

Privacy OfficerBusiness Associate Privacy ContractTrackingSafeguardsPre-emption of State LawTraining

Page 15: “ Technology Working For People” Intro to HIPAA and Small Practice Implementation.

“ Technology Working For People”

Security Regulation

Three Categories of Security StandardsAdministrativePhysicalTechnical

Page 16: “ Technology Working For People” Intro to HIPAA and Small Practice Implementation.

“ Technology Working For People”

Security Regulation

In All 3 Categories, the Standards are:Required

orAddressable

Page 17: “ Technology Working For People” Intro to HIPAA and Small Practice Implementation.

“ Technology Working For People”

Security - General RuleEnsure the confidentiality, integrity and availability

of all EPHIProtect against any reasonably anticipated threat

or hazard to security or integrityProtect against reasonably anticipated uses or

disclosure that are nor permitted under the Privacy Rule

Ensure compliance by your workforce

Page 18: “ Technology Working For People” Intro to HIPAA and Small Practice Implementation.

“ Technology Working For People”

Security Flexibility•Size, complexity and capabilities of office

•Technical infrastructure, hardware and software security capability of office

•Costs of security measures

•Probability and criticality of potential risks

Page 19: “ Technology Working For People” Intro to HIPAA and Small Practice Implementation.

“ Technology Working For People”

Security – Administrative Security Management Responsibility Workforce Security Information Access Management Security Awareness & Training Incident Procedures Contingency Plan Evaluation Business Associate Contract

Page 20: “ Technology Working For People” Intro to HIPAA and Small Practice Implementation.

“ Technology Working For People”

Security - PhysicalFacility Access ControlWorkstation UseWorkstation SecurityDevice & Media Controls

Page 21: “ Technology Working For People” Intro to HIPAA and Small Practice Implementation.

“ Technology Working For People”

Security - TechnicalAccess ControlAudit Controls IntegrityEntitiy AuthenticationTransmission Security

Page 22: “ Technology Working For People” Intro to HIPAA and Small Practice Implementation.

“ Technology Working For People”

ImplementationThe Head of Practice Overview

Office Manager Steps

Transaction/Code Certification

Staff Training

Privacy

Security

Maintenance

Page 23: “ Technology Working For People” Intro to HIPAA and Small Practice Implementation.

“ Technology Working For People”

Office Manager Steps

Appointed Privacy & Security Officer

Studies the HIPAA Office Manual

Makes any modifications to the forms, policies and procedures for this specific practice

Calls a staff meeting for HIPAA training

Page 24: “ Technology Working For People” Intro to HIPAA and Small Practice Implementation.

“ Technology Working For People”

Transaction/Code Certification

Obtain certification of compliance from Billing/Admin software vendor

Obtain certification of compliance from all clearinghouse vendors

Confirm accuracy of transactions

Page 25: “ Technology Working For People” Intro to HIPAA and Small Practice Implementation.

“ Technology Working For People”

Staff Training

Staff read the awareness essay

Read and sign employee confidentiality form

Attend the HIPAA overview training

Attend Security Awareness Training

Page 26: “ Technology Working For People” Intro to HIPAA and Small Practice Implementation.

“ Technology Working For People”

Privacy

Post Privacy Notice

Process for patients receiving and signing Notice of Privacy Practice

Post Fax and Email Policies

Create “Entities” log

Issue/Collect Business Associate contracts

Page 27: “ Technology Working For People” Intro to HIPAA and Small Practice Implementation.

“ Technology Working For People”

SecurityVeroTek & Office Manager Produce:

Risk Assessment/Plan Access Control Workstation Security Staff Security Training Anti-Virus Procedures Backup Procedures Internet/Firewall System Disaster Recovery Plan

Page 28: “ Technology Working For People” Intro to HIPAA and Small Practice Implementation.

“ Technology Working For People”

Maintenance

Quarterly review by Office Manager for compliance

Bi-Annual Security Audit by VeroTek

“As Required” updates as regulations change

Page 29: “ Technology Working For People” Intro to HIPAA and Small Practice Implementation.

“ Technology Working For People”

Questions?Call VTSHelpDesk

@ 858-483-1692

or Email [email protected]