HIPAA Flashcards
What does Abyde do?
Technology company of HIPAA experts with HIPAA education and solutions
What does HIPAA stand for?
Health insurance portability and accountability act
When was HIPAA established?
1996
What is the purpose of HIPAA?
US Law designed to provide privacy standards to protect medical records and other health information provided by health plans, doctors, hospitals, and other health care providers
When were Medicare/Medicaid programs created?
1965
When was the Health Care Financing Administration created?
1977
When was the Department of Health and Human Services born?
1980
Which president signed HIPAA into law?
Bill Clinton 1996
What is the order of the HIPPA rules?
2003 privacy rule, 2005 security rule, 2006 breach enforcement rule, 2013 omnibus rule
What percent of covered entities are HIPAA compliant according to OCR audits?
6%
What is the office for civil rights?
OCR issues guidance documents, records HIPAA complaints, collects fines and focuses on patient right of access and enforcement
What is the definition of HIPAA compliant?
Documented proof that there is a culture of compliance within your organization
What is the first step in an organization’s security rule compliance efforts?
Risk analysis— documented
What are the two phases to compliance?
Security rule and privacy rule
What goes into the privacy rule?
Risk mitigation, HIPAA training, policies and procedures, patient consent forms, HIPAA manual, business associate agreements, and updated risk analysis
How often is HIPAA training conducted?
Minimum once per year, quiz required
What are the first two HIPAA penalties and fees for compliant entities?
Tier 1 Complaint- violation could not have been reasonably avoided min. $100 and Tier 2 Compliant- violation should have been corrected min. $1000
What are the HIPAA penalties and fees for the non compliant tiers?
Tier 3 Not Compliant- made attempt to correct violation min. $10,000 and Tier 4 Not Compliant- no attempt made to correct violation min. $50,000
What is the tier 1 penalty for criminal action?
Tier 1- 1 year max jail time- reasonable cause or no knowledge of violation
What is the tier 2 penalty for criminal action?
Tier 2- 5 years max jail time- obtained PHI under false pretenses
What is the tier 3 penalties for criminal action?
Tier 3- 10 years max jail time- obtaining PHI for personal gain or with malicious intent
What were the the takeaways from the fine examples?
Have policies in place for off boarding employees and know who has access to PHI and how—have a canned response for online reviews and have policies that address social media and disclosures
Who can receive public health information during a public health emergency?
A public health authority figure, individuals at risk, and disaster relief organizations
What are telehealth and cybersecurity options are HIPAA compliant?
Updox, Zoom for healthcare, skype for business, google G suite hangouts meet
What is the application of HIPAA with students?
1) sharing among fellow students 2) you are already liable 3) PHI in a lecture setting still protected 4) professional communications should have minimum info necessary and encryption for sharing