HIPAA Flashcards
HIPAA
Health Insurance Portability and Accountability Act of 1996 provides data privacy and security provisions for safeguarding medical information.
HITECH
Health Information Technology for Economic and Clinical Health Act of 2009. The goal is to promote the adoption and meaningful use of health information technology and significantly expands the HIPAA privacy rule and security standards and adds new requirements concerning the privacy and security of PHI
PHI
Protected Health Information
ePHI
Electronic Personal Health Information such as personal health information stored and transmitted electronically. Examples are faxes, emails, data backup, and cloud providers, patient portals, removable media, and secure text.
All this data must be encrypted at rest and in transit.
Business Associate
Anybody that supports the healthcare industry and performs functions or activities in support of a covered entity.
Risk Assessment
A set of government mandated questions to help you identify your gaps in risk, to your business, and to a covered entity.
Three sections of questions
Administrative, Technical, and Physical.
Covered Entities
Must comply with the applicable standards provided in the Security Rule with respect to all ePHI.
Addressable
You must determine the level of risk to PHI and address it to ensure it is reasonable and appropriate security measures are applied.
Book of Evidence
The customized book of policies and procedures you are required to create and explains how you handle PHI and ePHI
Privacy Policy
How a covered entity and business associate handle all PHI