Top Banner
Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419
35

Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

Dec 14, 2015

Download

Documents

Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

Managing Access to Student Health Information per Federal HIPAA

Guidelines

Joan M. Kiel, Ph.D., CHPSDuquesne University

Pittsburgh, Penna412-396-4419

Page 2: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

The Law

• HIPAA: Health Insurance Portability & Accountability Act

• HITECH: Health Information Technology Economic &

Clinical Health Act

Page 3: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

HIPAA is Eleven Parts

• And what were you doing on July 30, 2004?

Page 4: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

Six Parts Are Set

1. T & C 2. Privacy 3. Standard Unique Identifier for Employers 4. Security 5. Standard Unique HC Provider Identifier (NPI) 6. Enforcement Rule

Page 5: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

HIPAA Information

• HIPAA covers:• Oral• Written (and beyond

the medical record)• Electronic• [key: can the individual

be identified]• You will hear the term PHI-

patient health information

Page 6: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

Keep in Mind

• Minimum Necessary [45CFR164.502(b)(1)]

• Emergency Situation [45CFR164.510(3)] ∙ Incidental Disclosure [45CFR164.502(a)(1)(iii)]

Page 7: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

Are You HIPAA or Not?

•YES •NO

Page 8: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

Covered Entity Status

• Health Plan: individual or group plan that provides or pays the cost of medical care

• Healthcare Clearinghouse: public or private entity that does billing, repricing, community health management or information systems, etc. functions

Page 9: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

Covered Entity Status

• Healthcare Provider: transmits any health information in electronic form in connection with a transaction covered by HIPAA

Page 10: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

Sample HIPAA Transactions

• Health care claims or equivalent encounter information

• Health care payment and remittance advice• Coordination of benefits• Health care claims status

Page 11: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

Who Do You Treat

• Students (and how are they defined; ie. LOA)• Non-Students

• For organizations under FERPA, student records are under FERPA (loophole) even with transactions, but non student records are under HIPAA, so you are a covered entity.

• But most strict law generally takes precedent

Page 12: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

You Are HIPAA If…

• You are one or more of the three covered entities

• You conduct one or more of the eleven transactions

• You treat non-students

Page 13: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

College Assessment

• Also look at these areas:• Student, Faculty, and

Employee Training *Nursing *Pharmacy *Allied Health *Music Therapy *Business (I.T.)

Page 14: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

College Assessment

• Health Services & Related Clinics

• Institutional Review Board; research

• Human Resources• Athletics• Vendors as business

associates

Page 15: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

Hybrid Entity

• A single legal entity whose business activities include both covered and non-covered functions (ie. education & healthcare provider or health plan

Page 16: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

Creating a Culture of HIPAA

• Are the policies and procedures set?

• Are they enforced or do they ‘sit on the shelf”

Page 17: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

Compliance Officer Role

• Privacy Officer [45CFR164.530(a)(1)(i)]• Security Officer [45CFR164.308(a)(2)]

• The Federal Government mandates that covered entities have both a privacy officer and a security officer

• If the same person, generally titled, Compliance Officer

Page 18: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

1. HIPAA Committee

• Representatives from records, information technology, student services and management.

Page 19: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

2. Policies & Procedures

• For the six HIPAA Rules to date, develop policies from the law, not secondary sources

• Do not take from the Internet

Page 20: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

3. Training & Awareness

• Live or on-line• Staff meeting

awareness• Integrate awareness to

daily activities

Page 21: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

4. Documentation

• Establish a system, on-site or off-site.

• Documentation must be retained for six years

Page 22: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

5. Risk Assessments & Audits

• Quarterly• Authentication: most

likely passwords• Data integrity checks• Act on the findings

Page 23: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

6. Complaint Process

• Omsbudsman for confidentiality• Post process to file

complaints• Complaints are only to

be HIPAA related• Act on the complaints

Page 24: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

7. Sanction Process

• Sanction only for the HIPAA violation

• Internal investigation or OCR

• Civil and criminal penalties per Enforcement Rule & HITECH

• Follow-up on the sanction and charge

Page 25: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

8. Web Site

• If the covered entity has a web site, the Notice of Health Information Privacy Practices must be prominently displayed on the web site.

• Keep the web site updated

Page 26: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

9. Formage

• Develop forms from the laws.

• May or may not be able to use from other covered entities (ie. addressable Security Rule policies)

• Educate staff on the formage

Page 27: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

10. Business Associate Agreements

• Assess all those external to the workforce who have access to the covered entity’s PHI

• Both the Privacy Rule and the Security Rule mandate BAA’s

Page 28: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

11. Research

• Play an integral role with the covered entity’s Institutional Review Board

• Ensure minimum necessary standards for data used in research

Page 29: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

Determination of HIPAA Research Status

• Does the research involve the collection, use, or dissemination of PHI?

• Is the PHI from a healthcare provider, clearinghouse, or healthcare plan?

• Does the healthcare provider, clearinghouse, or healthcare plan perform one of the eleven covered electronic transactions?

• If yes to these, then HIPAA

Page 30: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

Privacy Rule

• Notice & Notice Verification

• Internet Notice• Amend Records• Authorization• Accounting• Information Destruction• Business Associate

Agreements

Page 31: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

The Notice

• Tells the rights of the organization and the rights of the patient

• Document that is considered the guideline.

Page 32: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

Security Rule

• Technical Security• Administrative Security• Physical Security• Disaster Manual• Access Controls• Log-in Audit Warning• Termination of Access

Page 33: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

Faculty & Staff Access

• Have access to minimum necessary information to accomplish the intended purpose of the request given their role

• Must have an established need to know prior to requesting the information

• Ex. How long absent, but not the condition as it would not change the situation

Page 34: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

Advising Faculty, Staff, & Students

• Is the condition directly academically related such as ADHD

• But must always only request what is minimum necessary

• Have the student only submit and talk on what is minimum necessary

• Ex. Operating room reports, procedures notes, consultation reports, prescriptions

• Ensure who student allows one to talk to

Page 35: Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna 412-396-4419.

Summary

• Follow the Law• Keep it simple• Thank you