Hippa Flashcards
Hipaa
Is a federal regulation and as such, compliance is mandatory
The 4 entities covered by Hipaa rule
Health care providers, Health plans, Health care clearing house, and their business associates
List examples of identifiable health information that could be send to identify an individual
Name, License, Phone number, photograph, DOB, Address, account number, country, and finger prints
Incidental exposure
Is a disclosure that cannot be reasonably prevented, and is limited in nature. This occurs as a by-product of otherwise permitted use or disclosure. This example would not be an incidental disclosure as it was foreseeable that protected health information could be overhead by others.
Under hipaa
An individuals health information that is shared should be limited to the “minimum necessary”. However, the minimum necessary doesn’t apply to physicians and other health care providers who need full access to medical records in order to provide the best medical care possible care.
The notice of privacy policies
Discloses to the patient that protected health information can be used for payment, treatment, and health care operations. The NPP would also included a summary of Patients Rights, stating that information can be disclosed for other purposes as well, such as appointment reminders and special situations such as law enforcement, court orders, and that the facility is required by law to maintain the privacy of PHI.
What can be said about authorization about HIPAA?
Patients must give authorization before certain information is released. A health care facility cannot deny treatment to a patient that doesn’t sign an authorization form. No authorization is needed to release information for public policy purposes such as public health care activities or law enforcement.
State regulations
Are pre-emptied or over-ridden by HIPAA regulations. If the state laws are more stringent then they should be followed.
Law enforcement can request PHI if?
The information is relevant and material to a legitimate enforcement inquiry, they supply a warrant or a subpoena, Rotherham request is as specific and narrowly drawn as possible.
An authorization is also…
Mandated before protected health information can be disclosed to a business associate for making purposes.