HIPPA Flashcards
PURPOSE
Protect privacy of patients health info, imposes restrictions on use of info, gives pt access and control over medical records
Who is covered by hippaa
Covered entity: health care plans, providers, clearing houses. Billing services and businesses are indirectly
What is covered by hippaa
Protected health info. Oral, paper, electronic, or recorded. Also demographic info
Permitted hippaa uses
Tx, payment, healthcare operations. Authorization of pt or disclosure. Incidental uses. Transfer of records upon sale or merger of covered entity
Hippaa required disclosure
Authorized by individual, dept of HHS for investigations
What is on authorization forms
Describe of PHI to be disclosed. Who and for what purpose. If it will result in financial gain by covered entity. Pt right to revoke it. Date. Pt signature
Written authorization not req when
Facility pt directory, inform agencies during disasters, public health r/t disease control/prevention, report abuse, health oversight, coroners/funeral directors, organ donations, avert serious threat to safety/health, research as ltd data set
Privacy notice does what
1st date of service or after an emergency, gives in print at site of service, notice of PHI policy changes
Pt rights
Privacy notice at first service, have phi communic by alternate means and locations to protect confid, inspect/amend phi or get copies, req hx of non routine disclosures for 6 years prior to request, contact people regarding privacy concerns to favcility and HHS
Rights of minors: when parents dont have control over PHI
States can override it, HIV testing, abuse, parents agreed to give control to minor
Admin compliance does what
Allow patients to see and copy their PHI, Develop a notice of privacy practices document, Develop policies and safeguards for PHI to limit
incidental exposures, Institute a complaints process, File and resolve formal complaints, Contracts with business partners comply with the
privacy rule, Requires a full or part time designated official
responsible for implementing the programs, Contact person or office responsible for receiving
complaints.
Violations
Civil penalty or criminal if someone sold info