HIPPA Flashcards
What does HIPPA do?
improves efficiency and effectiveness of health care system by standardizing the electronic exchange of administrative and finanacial data
mandates specific protections for individually identifiable health information
goals of HIPPA
guarentee ongoing health insurance coverage for workers who change jobs
portability of pre-existing condition exemptions between employer group health plans
preventing fraud and abuse in health care
protect patient health information
standardize electronic transactions in healthcare/stimplify administrative reporting
covered entity
all health care plans
all healthcare clearinghousers (billing services)
healthcare provider who transmits any health information in electronic form in connection with a standard transaction
why is HIPPA needed?
to protect sensitive data from being lost, destroyed or misused
why is HIPPA important?
public trust morally and ethically the right thing good for business prevents law suits avoids financial penalties and possible imprisonment
privacy
rights of an individual to limit the use and disclosure of all protected health information
security
obligations of covered entities to safeguard protected health information from improper use of disclosure, especially electronically transmitted or stored information
disclosure
release, transfer, provision of access to or divulging of information outside the entitiy holding the information
use
sharing, employment, application, utilization, examination or analysis of individually identifiable information within an entitiy
workforce
empolyees, volunteers, trainees and other persons whose conduct,, in the performance work, is under the direct control of such entity
business associate
a person or entity that performs a function that requires the creation, use or disclosure of PHI on behalf of a CE but is not considered partof a workforce
facility
the physical premises and the interior and exterior of a building
security incident
attempted or successful unauthorized access, use, disclosure, modification or destruction of information or interference with system operations in an information system
workstation
and eletronic computing device, that performs similar functions and electronic media stored in its immediate environment
malicious software
software designed to damage or disrupt a system
PHI
any information, including demographic information, collected from an individual that is
- created or received by a healthcare provider, health plan, employeer or healthcare clearinghouse
- relates to the past present or future physical or mental health or condition of a individual; provision of health-care to an individual, or to the past present or future payment for the provision of healthcare to an individual
- identifes the individual
- there si reasonable basis to believe that the information can be used to identify the individual
examples of individually identifiable information (PHI)
name address empolyer names of relatives date of birth phone/fax numbers photos cose or characteristics (occupation) email address SSN medical record number account number certificate/liscence number voice/fingerprints
what is NOT considered PHI?
employment records of CE
FERPA
privacy standards
require health care plans and providers to maintain administrative and physical safeguards to protect condifenciality of healht information and to protect against unarthorized access to that information
when does minimum necessary apply?
when using or disclosing protected health infomration or when requesting protected health information from another covered entity, a CE must make reasonable efforts to limit protected health information to the minimum necessary to accomplish the intended purpose of the use, disclosure, or requrest
when does minmum necessary apply?
anyone requesting PHI has a specific reason fofr which the PHI is needed
disclosure should be limited to that PHI needed for the specific purpose
use should be limited to the minimum necessary to perform your job
when is minimum necessary not applied?
when the PHI is for diagnosis or treatment purposes
what are patient rights for HIPPA?
- to request an accounting of health information disclosures
- request an amendment to health information
- to inspect and copy health information
- to receive confidential communications about tealth information
- to request restrictions on disclosures
- to complain to the CE and to DHHS
if a patient requests their PHI, when must you get it to them?
within 30 days of patient’s request