HIPAA Flashcards
Who must follow HIPAA?
HIPAA applies to “covered entities” which include:
1) Health Plans – health insurance companies, HMOs, company health plans, government health care programs like Medicare, Medicaid, military and veterans health care programs
2) Data Clearinghouses – entities that process non standardized health information they receive from other entities into a standard format (e.g. middleman between providers and health plans, etc.)
3) Health Care Providers – physicians, clinics, psychologists, dentists, chiropractors, nursing homes, pharmacies – only affects providers who transmit any information in an electronic form in connection with a transaction for which HHS has adopted a standard
Who must follow HIPAA?
– In addition to “covered entities,” HIPAA also applies to…
“business associates”
An entity or person who performs functions or activities involving the use or disclosure of protected health information on behalf of or providing services to a covered entity
Examples: third party administrators assisting health plans with claims processing, attorneys, CPA firms and accountants, medical transcriptionists, pharmacy benefits managers,
HIPAA applies to “covered entities” which include:
- Health Plans
- Clearinghouses
- Health Care Providers including pharmacist
- Business Associate who assist covered entities with provision of health care
Protected Heath Information (PHI)
Information protected under HIPAA
Includes all heath care information related to patients health/condition, treatment/ care, payment and any information that identifies or could be reasonably expected to identify the patient
-
Examples of Protected Health Information
Names and address
Dates (birth, admit/discharge, death)
Phone/fax numbers
Email address
Social security number
Medical record number
Health plan beneficiary number
Account numbers
Certificate/license numbers
VIN vehicle identification numbers and serial numbers, license plate numbers URL address
IP address
Device identifiers
Biometric identifiers (finger prints, voice print)
Full face photos/images
Any other unique identifying numbers, characteristics or code
HIPAA is a establishment of national standards for
- electronic health care transactions and national provider identifier (NPI) number
- rules on security and privacy of heath care information
security
protects information (confidentially and availability)
Privacy
patients right and how their information may be used
Health Information Technology for Economic and Clinical Health Act (HITECH)
- amends HiPPA
- requires breach notification
How is PHI defined in 45 CFR 160.103
- individually identifiable health information
- transmitted or maintained by electric media or in any form or medium
- by a covered entity or business associate
How must pharmacies provide notice of privacy practices ?
- in paper on the first day patient uses the pharmacy (must be sent electronically)
- Posted in a prominent location in the pharmacy and provided if requested by any person ( not limited to patients)
- on the pharmacy’s website
Knowledge of Notice
- must acquire written acknowledgment from the patient that they received the information
- one acknowledgment per persons, once!
- allowed to refuse to sign and pharmacy cannot refuse to serve ( document a good faith effort)
- signatures kept in logbook
- may mail notice to pt and request it sent back
- can be sent electronically
Is it a violation if pharmacy made a good faith effort for acknowledgment from patient and documented they tried?
It is not considered a violation as long as the pharmacy tried to obtain it and documented that they tried
who are able to sign for the patient acknowledgment ?
- personal representatives (parent-child, legal guardian, power of attorney)
- others may pick up prescriptions, but not permitted to sign the acknowledgment if they are not personal representatives
Do Children under 18 have to sign the acknowledgment?
No
how long should records of signatures for acknowledgment be kept
6 years from date signed or from the date the last prescription for the ration was dispensed
When should pharmacy employees use or disclose health information
for treatment, payment, regular health care operations
How much PHI can the Pharmacy Disclose?
- “minimum necessary amount”
- the amount needed to carry out the service you are engaging in for the patient
What are exceptions where pharmacist may disclose a PHI ?
- communication to the patient
- communication with other health care providers treating the patient
- if patient authorizes disclosure
- as required by HHS to determine compliance and enforce HIPAA
- if required by law