HIPAA Flashcards
What is HIPAA
Health Insurance Portability and Accountability Act of 1996
What does HIPAA do?
Protects privacy and security of certain health information
HIPAA privacy rule?
establishes national standards for the protection of certain health information.
HIPAA security rule?
Establish a national set of security standards for protecting certain health information that is held or transferred in electronic form
What did the HITECH act 2009 do?
Expanded rules to business associates
HIPAA Privacy rule
Intended to protect privacy of all individually identifiable health information
What 2 things does the privacy rule protect?
- Protects privacy of all individually identifiable health information
- Protects identifiable health information held or transmitted by a covered entity or associate in any form
What 3 specific things does protected health information include? (3)
- physical or mental health condition
- provision of health care to the individual
- payment for the provision of health care to the individual.
When is patient authorization not required for disclosure of PHI?? (5)
- Information sharing needed for treatment
- Disclosure to family, friends, others involved in care of the individual as well as for notification purposes
- Information needed to ensure public health and safety
- Information needed to prevent or lessen imminent danger
- Disclosure in facility directories
What must an adequate privacy notice include? (6)
- The required heading
- A statement of uses and disclosures
- A statement of individual rights
- A statement of the covered entity’s duties
- An explanation of how to complain
- Required contact information
What does the security general rule do?
Establishes national standards to protect individuals electronic personal health information that is created, received, used, or maintained by a covered entity.
How does the security rule define confidentiality?
To mean that e-PHI is not available or disclosed to unauthorized persons
What 4 things must covered entities do under the security rule?
- Ensure the confidentiality of all e-PHI
- Protect against reasonably anticipated, impermissible uses
- Protect against reasonably anticipated threats to security
- Ensure compliance by workforce
What is the breach notification rule?
Requires HIPAA covered entities and their business associates to provide notification following a breach of unsecured protected health information
What is the definition of breach?
an impermissible use or disclosure under the Privacy Rule that compromises the security or privacy of the protected health information
HIPAA considerations for PT practice (5)
- Patient identification
- Evaluation procedures
- Sign in and out processes
- Physical layout of facility
- Computer security
What are the penalties for violating HIPAA
- Civil or criminal sanction
- civil=fines, usually the result of inadvertent violations
- Criminal involve monetary penalties and jail time
What are 3 causes of improper payment?
- Incorrect coding
- No documentation or insufficient documentation
- Medically unnecessary
How does the fraud prevention system work?
- Monitors 4.5 claims each day
- Alerts generated and consolidated around providers and subsequently prioritized based on risk
- Regional results are provided to the zone program integrity contractor analyst and investigators
- Results available yo CPI and law enforcement
- ZPICs now work the top 100 leads in each zone
What is fraud?
Health Care fraud schemes commonly include purposely billing for services that were not provided or were not medically necessary, billing for a higher level of service than what was provided, misreporting costs or other data to increase payments, paying or receiving kickbacks, illegally marketing products, and or stealing providers or beneficiaries’ identities… Basically inappropriate billing practices
What is abuse?
Practices that either directly or indirectly result in unnecessary costs to Medicare or Medicaid, including misuse of codes on a claim, charging excessively for services or supplies, and billing for services that were not medically necessary
What is the false claims act?
Civil liability for knowingly submitting or causing to be submitted a false or fraudulent claim to the federal government
What is the anti-kickback statute
Criminal offense to knowingly and willfully offer, pay, solicit, or receive remuneration or induce or reward referrals of items or Services reimbursable by a federal health care program
Stark law or physician self referral law
Prohibits referral for health services to an entity in which the physician (or member of immediate family) has ownership slash investment interest or a compensation arrangement