HIPAA Flashcards
What is HIPAA
Health Insurance Portability and Accountability Act of 1996
What does HIPAA do?
Protects privacy and security of certain health information
HIPAA privacy rule?
establishes national standards for the protection of certain health information.
HIPAA security rule?
Establish a national set of security standards for protecting certain health information that is held or transferred in electronic form
What did the HITECH act 2009 do?
Expanded rules to business associates
HIPAA Privacy rule
Intended to protect privacy of all individually identifiable health information
What 2 things does the privacy rule protect?
- Protects privacy of all individually identifiable health information
- Protects identifiable health information held or transmitted by a covered entity or associate in any form
What 3 specific things does protected health information include? (3)
- physical or mental health condition
- provision of health care to the individual
- payment for the provision of health care to the individual.
When is patient authorization not required for disclosure of PHI?? (5)
- Information sharing needed for treatment
- Disclosure to family, friends, others involved in care of the individual as well as for notification purposes
- Information needed to ensure public health and safety
- Information needed to prevent or lessen imminent danger
- Disclosure in facility directories
What must an adequate privacy notice include? (6)
- The required heading
- A statement of uses and disclosures
- A statement of individual rights
- A statement of the covered entity’s duties
- An explanation of how to complain
- Required contact information
What does the security general rule do?
Establishes national standards to protect individuals electronic personal health information that is created, received, used, or maintained by a covered entity.
How does the security rule define confidentiality?
To mean that e-PHI is not available or disclosed to unauthorized persons
What 4 things must covered entities do under the security rule?
- Ensure the confidentiality of all e-PHI
- Protect against reasonably anticipated, impermissible uses
- Protect against reasonably anticipated threats to security
- Ensure compliance by workforce
What is the breach notification rule?
Requires HIPAA covered entities and their business associates to provide notification following a breach of unsecured protected health information
What is the definition of breach?
an impermissible use or disclosure under the Privacy Rule that compromises the security or privacy of the protected health information