Title: Center for Development
1Center for Development Learning Introduction
to Privacy Requirements
2Table of Contents
- Overview of the Privacy Regulation
- Protected Health Information
- Parts of the Privacy Regulation
- Patient Rights
- Requirements for us
- Penalties
3What is HIPAA?
- HIPAA stands for the Health Insurance Portability
and Accountability Act, a federal law passed in
1996 that affects the healthcare and insurance
industries.
4Privacy Regulation Purpose
- HIPAA has several parts including privacy,
security, and computerized claims processing.
This lesson provides an awareness of the Privacy
Regulation. - The main goal of the Privacy Regulation is to
protect the use and sharing of Protected Health
Information (PHI).
5What is PHI?
- Protected Health Information
- PHI is any health information that can be used
to identify a patient and which relates to the
patient, healthcare services provided to the
patient, or the payment for these services. - The following are items that can be used to
identify a patient
6Examples of PHIIdentifiers
- Employer
- Relatives Names
- Telephone Numbers
- Fax Numbers
- E-Mail Address
- Medical Record Number
- Social Security Number
- Codes
- Fingerprints
- Occupation
- Photographs
- Certificate Numbers
7Privacy Regulation Requires
- UNC Hospitals, Rex Healthcare, UNC Physicians
Associates and the UNC School of Medicine are all
required to follow the HIPAA rules. We cannot
use or disclose PHI unless it is required or
allowed by law, or when the patient has given
permission.
8Privacy Rule Principles
- The Privacy Regulation, or Privacy Rule, is made
up of several parts. - These include the following
- Accountability
- Anyone who misuses PHI will be subject to losing
their job along with civil and/or criminal
penalties.
9Privacy Rule Principles cont
- Responsibility to the public
- Addresses the need to keep the public healthy and
safe, but at the same time protect the privacy of
all patients. - Boundaries
- PHI should be used for healthcare purposes only.
10Privacy Rule Principles cont
- Security
- PHI needs to be kept confidential and accessed on
a need to know basis. - Patient Control
- The Patient has the right to ask us for a listing
showing when and to whom their PHI has been
shared.
11Patient Rights
- The Privacy Rule calls for letting patients know
their privacy rights. - These rights are as follows
- The patient has the right to obtain a copy of our
Notice of Privacy Practices. - The patient has the right to access their PHI.
12Patient Rights cont.
- The patient has the right to ask us for a listing
showing when and to whom their PHI has been
shared. - The patient has the right to ask for corrections
in their own PHI.
13Patient Rights (contd)
- The patient has the right to control how PHI
about them is shared. - The patient has the right to file a complaint if
we do not follow our privacy policies.
14Privacy Deadline
- The UNC Health Care System (UNC HCS), which
includes UNC Hospitals, Rex Healthcare, UNC
Physicians Associates and the UNC School of
Medicine, is committed to meet the HIPAA
requirements by April 14, 2003 as required by
HIPAA.
15HIPAA Requirements
- HIPAA has numerous requirements, some of which
we have already met and others are in process - We have created a new privacy policy explaining
who has access to PHI, what these persons will
use it for, and when the PHI can be shared. - We have revised our Information Security policies
to address the additional requirements of HIPAA. - We have appointed Privacy and Security Officers.
16HIPAA Requirements cont
- We are developing procedures that address each of
the patient rights. - We will train all staff about HIPAA and our new
procedures. - We will only provide access to PHI on a need to
know basis. - We will provide all patients with a copy of our
Notice of Privacy Practices. - In most cases, we will share PHI only if
permission has been given by patient.
17How will HIPAA impact me?
- That depends on your specific job.
- Job specific training will be provided beginning
in January. - Current practices will be changed to meet the new
HIPAA requirements.
18Penalties
- There are penalties for not following HIPAA
requirements. - You can lose your job.
- You and your facility can be forced to pay up to
250,000 and spend up to 10 years in jail.
19Patient Questions
- What should I do if a patient asks about a
- right under HIPAA?
- Contact
- Entity Privacy Officers,
- Janice Jarrell or Jeffry Low
- UNC HCS Privacy/Security Officer
- Information Officer, Jeffry Low
20Other Questions
- Should you or your staff have any additional
questions that have not been answered by this
presentation, you may contact any of the CDL UNC
HCS HIPAA Policy Committee members listed below - Janice Jarrell janice.jarrell_at_cdl.unc.edu
- Jeffry Low jeffry.low_at_cdl.unc.edu
21HIPAA Review
- You have completed the introduction to HIPAA
Privacy. Lets see what you have learned
22HIPAA Review cont
- What is the main goal of the Privacy Regulation?
- To make PHI public
- To make medical information available for
Environmental Services - To protect the use and disclosure of PHI
- To allow covered entities to sell PHI
Answer C
23HIPAA Review cont
- Which is an Example of PHI?
- Information related to an individuals mental
health - Information related to an individuals physical
health - A physical description of an individual
- All of the above
Answer D
24HIPAA Review cont
- According to the Privacy Regulation, because we
must comply with the Privacy Regulation, we must
make patients aware of _____. - The constitution
- Patient Rights with respect to HIPAA
- The sanitation grade
- The location of the Health Information Management
Department
Answer B
25HIPAA Review cont
- Which one of the following is NOT one of the
patient rights under HIPAA? - The right to destroy your own medical record
- The right to copy, amend, and access your own
Protected Health Information - The right to receive the healthcare providers
Notice of Privacy Practices - The right to file a complaint if the healthcare
providers policies are violated.
Answer A
26HIPAA Review cont
- The compliance deadline for the Privacy
Regulation is ______. - April 15, 2002
- April 14, 2003
- January 1, 2003
- September 20, 1996
Answer B
27HIPAA Review cont
- Which of the following is NOT one of the patient
rights under HIPAA? - The right to request that inaccuracies in PHI be
changed - The right to control whom a patients PHI is
disclosed to - The right to obtain a copy of your mothers
medical record - The right to file a complaint if HIPAA guidelines
are not followed
Answer C
28HIPAA Review cont
- In order to comply with HIPAA, UNC HCS must
______. - Appoint a Privacy Officer
- Obtain JCAHO accreditation
- Must appoint an OSHA Officer
- Have a computer network
Answer A
29HIPAA Review cont
- HIPAA is a Federal law.
- True
- False
Answer A
30HIPAA Review cont
- HIPAA is only the law in North Carolina.
- True
- False
Answer B
31HIPAA Review cont
- If you wanted to file a complaint or you had a
question about HIPAA, who would be the most
appropriate person to talk to? - CFO (Chief Financial Officer)
- CEO (Chief Executive Officer)
- PO (Privacy Officer)
- FBI (Federal Bureau of Investigation)
Answer C
32HIPAA Review cont
- Each employee is responsible for keeping PHI
confidential. - True
- False
Answer A
33HIPAA Review cont
- I can go to jail if I break HIPAA laws.
- True
- False
Answer A
34HIPAA Review cont
- All staff is required to know about ______.
- HIPAA Laws
- JCAHO Laws
- PHI Laws
- Mosaic Laws
Answer A
35HIPAA Review cont
- Which one of the following is NOT an identifier
of PHI? - Telephone numbers
- Social Security Numbers
- Medical Record numbers
- None of the above
Answer D
36HIPAA Review cont
- Employees should use a patients PHI for personal
reasons. - True
- False
Answer B
37CENTER FOR THE STUDY OF DEVELOPMENT AND
LEARNINGUNIVERSITY OF NORTH CAROLINA AT CHAPEL
HILL HIPAA Training Certification
I, ________________________________________ do
hereby certify that I received HIPAA Training on
_______________________________. I understand
that as a UNC HeathCare employee I must adhere to
the federal laws associated with The Health
Insurance Portability and Accountability Act.
Signature______________________________________
_____________