HIPAA - PowerPoint PPT Presentation

1 / 17
About This Presentation
Title:

HIPAA

Description:

Biometric identifiers (finger prints) Full face or comparable photos ... Limited types of information can be released (referred to as a Limited Data Set) ... – PowerPoint PPT presentation

Number of Views:122
Avg rating:3.0/5.0
Slides: 18
Provided by: chery104
Category:

less

Transcript and Presenter's Notes

Title: HIPAA


1
HIPAA Information Privacy
  • SOURCE PHRC Staff Meeting January 8, 2003
    Department of Public Health Sciences

2
What is HIPAA?
  • Health Insurance Portability and Accountability
    Act
  • Became law in August 1996
  • Called for Administrative Simplification
  • Privacy and Security of Health Information
  • Implementation Date April 14, 2003

3
What is Administrative Simplification?
  • Goal
  • To improve the efficiency and effectiveness of
    the health care system.

4
How to Implement Administrative Simplification
  • Adoption of
  • Uniform, national standards for transactions for
    Electronic Data Interchange (EDI)
  • Unique Health Identifiers
  • Code Sets for Data
  • Security of Health Information
  • Electronic Signatures

5
The Privacy Rule
  • Protects the privacy of individually identifiable
    health information
  • by establishing conditions for its use and
    disclosure by a health plan, healthcare
    clearinghouse, and certain healthcare providers.

6
Example
  • Robert Jones, Jr.
  • 123 Medical Center Blvd.
  • Winston-Salem, NC 27157
  • 336-768-1234
  • SS 123-45-6789
  • Diagnosis Diabetes
  • Health care provider ABC Health Plan

7
Privacy Rule Continued
  • Gives certain rights to individuals with regard
    to their health information.
  • New Individual Rights
  • Right to Notice of Privacy Procedures
  • Right of Access and Amendment to Patient
    Information
  • Right to an Accounting of Disclosures of Patient
    Information
  • Right to Request Additional Protections

8
Protected Health Information (PHI)
  • Individually identifiable health information
    including, without limitation, all information,
    data, documentation, and materials, including
    without limitation, demographic, medical and
    financial information, that relates to the past,
    present, or future physical or mental health or
    condition of an individual the provision of
    health care to an individual or the past,
    present, or future payment for the provision of
    health care to an individual and that identifies
    the individual or with respect to which there is
    reasonable basis to believe the information can
    be used to identify the individual.

9
What does that mean?
  • Health information Identifier PHI
  • Applies to information transmitted or maintained
    in any form (paper web-based)
  • Does not include de-identifiable health
    information or biological tissue

10
How does the privacy rule protect individuals?
  • Establishes conditions for use of PHI (who you
    can send PHI to, when, etc.)
  • Establishes conditions for disclosure of PHI (who
    and when to disclose)
  • Has protections for the use and disclosures
    without the persons permission (AE reporting,
    FDA reporting)
  • Gives individuals the rights to information about
    themselves and how it has been disclosed

11
Example
  • Robert Jones, Jr.
  • 123 Medical Center Blvd.
  • Winston-Salem, NC 27157
  • 336-768-1234
  • SS 123-45-6789
  • Diagnosis Diabetes
  • Health care provider ABC Health Plan

12
PHI The 18 Identifiers
  • Names
  • Geographic info (city, state, zip code, etc)
  • Elements of dates
  • Telephone
  • Fax
  • E-mail address
  • SS
  • Medical record, prescription
  • Health plan beneficiary
  • Account
  • Certificate/license
  • VIN or serial , license plate
  • Device identifiers, serial s
  • Web URLs
  • IP addresses
  • Biometric identifiers (finger prints)
  • Full face or comparable photos
  • Unique identifying s

13
What is an Authorization?
  • Authorizations must include
  • Description of info to be used or disclosed that
    identifies the information
  • Name of person (s) authorized to disclose info
  • Name of person (s) who may be requested to
    disclose info
  • Description of each purpose of the requested use
    or disclosure
  • Expiration date (no expiration date is OK)
  • Signature of the individual and date

14
De-identified Information
  • Removal of the 18 elements AND no knowledge that
    remaining information can identify the individual
  • Statistically de-identified (a statistician
    certifies that there is a very small risk that
    the information could identify the individual

15
Limited Data Set with Data Use Agreement
  • Limited types of information can be released
    (referred to as a Limited Data Set)
  • Limited Data Sets can only be used and released
    with a Data Use Agreement between the covered
    entity and the recipient of the data

16
Limited Data Sets DO NOT include
  • Names
  • Postal address info smaller than state
  • Elements of dates
  • Telephone Fax
  • E-mail address
  • SS
  • Medical record, prescription
  • Health plan beneficiary
  • Account
  • Certificate/license
  • VIN or serial , license plate
  • Device identifiers, serial s
  • Web URLs
  • IP addresses
  • Biometric identifiers (finger prints)
  • Full face or comparable photos

17
Minimum Necessary
  • Covered entities must develop policies and
    procedures that limit the PHI
  • To staff
  • To entities we disclose the information to
Write a Comment
User Comments (0)
About PowerShow.com