13) HIPPA: The Compliance Plan Flashcards
1
Q
What are the roles of HIPPA?
A
- Standardization of electronic pt health, administrative, and financial data
- Define unique health identifiers
- Security standards protecting confidentiality and integrity of PHI, past, present, or future
2
Q
What are the penalties for non-compliance?
A
- Fines up to $25K for multiple violations in the same calendar yr OR
- Fines up to $250K and/or imprisonment up to 10yrs for knowingly misusing PHI
3
Q
What are compliance requirements?
A
- Initially build organizational awareness of HIPPA
- Have a comprehensive assessment of the org’s privacy practices, information security systems & procedures, and use of electronic transactions
- Have an action plan for compliance w/each rule
- Devo a technical and management infrastructure to implement the plans
4
Q
What are the different aspects of administrative simplification?
A
-
Standards for Electronic Documentation
- Electronic Health Transactions
- Unique Identifiers
- Security Rule
- Privacy Rule
5
Q
Electronic Health Transactions
A
- Health Claims
- Health Plan Eligibility
- Enrollment/Dis-enrollment
- Payment for Care and Health Plan Premiums,
- Claim Status
- 1st Injury Reports
- Coordination of Benefits
- Related Transactions
6
Q
Unique Identifiers
A
- EIN
- NPI
- Health Plan Identifiers
7
Q
Security Rule
A
Facility needs to take measures to ensure that e-PHI isn’t available/disclosed to unauthorized persons
- Requires covered entities to maintain reasonable and appropriate administrative, technical, and physical safeguards for protecting PHI
8
Q
Privacy Rule
A
Intended to protect the privacy of all PHI
- Gives pt’s new rights to access their medical records, request changes, and learn how they have been accessed
- Restrict access by others
- Restrict access to only the people who need to see it
- States that all pt’s need to be informed about the facility’s privacy practices
- Allows pt’s to decide if they want to authorize the disclosure of their PHI for uses other than tx or healthcare business ops
- Establish new criminal and civil sanctions for improper use/disclosure of PHI
- Establish business associate agreements w/business partners that safeguard their use and disclosure of PHI
9
Q
What are the parts of a voluntary compliance program?
A
- Conduct internal monitoring and auditing periodically
- Implement compliance and practice standards through written standards and procedures
- Designate a compliance officer/contact to monitor compliance efforts and enforce practice standards
- Conduct training and education on standards and procedures
- Respond appropriately to detected violations
- Investigate allegations
- Disclosure of incidents to appropriate entities
- Devo lines of communication
- Discussions at staff meetings re avoiding erroneous or fraudulent conduct
- Community bulletin boards to keep people informed
- Enforce disciplinary standards through well-publicized guidelines
- Lock cabinets where PHI is stored
10
Q
What are the steps to implement a HIPPA compliance program?
A
- Conduct an impact assessment to determine gaps btwn existing info practices and policies and HIPPA requirements
- Review fxns and activities of business partners to determine where business associate agreements are needed
- Devo and implement privacy policies
- Update systems to ensure they provide adequate protection of pt data
11
Q
What are some HIPPA concerns for PT’s?
A
- Pt ID
- Eval Procedures
- Sign-in/Out Process
- Facility Layout
- Computer Use