Introduction to HIPAA Flashcards

A general introduction and overview of the federal HIPAA regulations

1
Q

<b> HIPAA </b> stands for

A

<b>H</b>ealth <b>I</b>nsurance <b>P</b>ortability and <b>A</b>ccountability <b>A</b>ct

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

HIPAA’s intent is to…

A

…reform the healthcare industry by reducing costs, simplifying administrative processes and burdens, and improving the privacy and security of individuals’ health information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

<b>PHI</b> stands for

A

<b>P</b>rotected <b>H</b>ealth <b>I</b>nformation (<b>PHI</b>)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

<b>PHI</b> definition

A

<b>PHI</b> is any identifiable health information relating to the past, present, or future health condition of the individual regardless of the form in which it is maintained (electronic, paper, oral format, etc).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

<b>ePHI</b>

A

<i>Electronic</i> Protected Health Information, a subset of PHI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

The two organization types that are regulated under HIPAA:

A

<ol>
<li>Covered Entities</li>
<li>Business Associates</li>
</ol>

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Covered Entities definition

A

the source of of PHI; generate it. they have a direct relationship with individuals with PHI.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Covered Entities are ___ and required to be ____.

A

<i>directly regulated</i>, <i>HIPAA compliant (protecting PHI)</i>

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Healthcare Clearinghouses are…

A

…covered entities that process nonstandard health information they receive from another entity into a standard format, or vice versa.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Business Associates are ____ and required to be ____.

A

<i>directly regulated</i>, <i>HIPAA compliant (protecting PHI)</i>

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Business Associates definition

A

All third party vendors and business partners that create, receive, maintain, or transmit protected health information (PHI) on behalf of a covered entity or another business associate.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Chain of Trust

A

formed by business associate contracts, where a covered entity shares PHI with contracted business associates, with 1 contract per link.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Business Associate contract

A

legal HIPAA document where the Business Associate legally attests to being HIPAA compliant, to either the Covered Entity or another Business Associate.
This enables sharing PHI from the attestee to the attester, wherein the attester becomes legally liable to fines and penalties.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Two main parts of HIPAA

A

<ol>
<li>HIPAA privacy</li>
<li>HIPAA security</li>
</ol>

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

HIPAA privacy

A

protections for PHI from a people standpoint

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

HIPAA security

A

protections for EPHI; minimum tech standards and protections

17
Q

scenario: Dr. J hired an answering service, and later during an audit discovered the service was not HIPAA compliant.
q: what do differently?

A

Dr. J confirm answering service HIPAA compliant upfront, with some due diligence actions.

18
Q

scenario: Dr. J signs a BA contract with a HIPAA compliant service. This service uses an IT company.
Q: What service do to work with IT company?

A

Service ensure IT is HIPAA compliant.

19
Q

Covered Entities types:

A

Healthcare Providers, Health Plans, Healthcare Clearinghouses.

20
Q

Healthcare Providers

A

Physicians, Dentists, Nurses, Clinical Labs, Nursing Homes

21
Q

Health Plans

A

health insurance companies, HMOs, Government healthcare programs

22
Q

Healthcare Clearinghouses

A

entities that process nonstandard health information from another entity into a standard, or vice versa.

23
Q

HIPAA timeline

A

<ol>
<li>1996: HIPAA signed into law</li>
<li>2003: Covered Entities required to comply with Privacy Rule</li>
<li>2005: Covered Entities required to comply with Security Rule</li>
<li>2006: Enforcement begins</li>
<li>2009: ARRA and HITECH signed into law. Business Associates and subcontractors now required to comply</li>
<li>2013: Omnibus Rule takes effect. HITECH rolled back into HIPAA along with more detailed guidance</li>
</ol>

24
Q

ARRA

A

American Recovery and Reinvestment Act of 2009, superset of HIPAA updates which are HITECH Health Information Technology for Economic and Clinical Health Act (subset of ARRA).

25
Q

HITECH Act

A

Health Information Technology for Economic and Clinical Health Act of 2009
expanded
-scope of privacy & security protections available under HIPAA
-enforcement
-penalties

26
Q

Omnibus rule

A

made HITECH part of HIPAA in 2013, with more details

27
Q

HIPAA categories

A

<ol>
<li>Administrative Simplification, relevant to healthcare providers</li>
<li>Insurance Reform, relevant to insurance providers/payers</li>
</ol>

28
Q

Administrative Simplification goals

A

<ul>
<li> - administrative cost (26% of healthcare expenses in 2019)</li>
<li> - vulnerability of Internet-based tech </li>
<li> - fraud &amp; abuse</li>
<li> + efficiency &amp; effectiveness</li>
<li> + privacy </li>
<li> + patient rights</li>
<li> + availability of information for decision</li>
</ul>

29
Q

Administrative Simplification categories

A

<ul>
<li>Transactions, Code Sets, and Identifiers - standardize electronic transactions and data requirements for healthcare exchanges </li>
<li> Privacy - safeguards for PHI</li>
<li> Security - safeguards for ePHI </li>
</ul>

30
Q

HIPAA privacy compliance requires…

A
<ul>
<li>HIPAA privacy officer</li>
<li>employee training</li>
<li>documents and controls</li>
</ul>
31
Q

HIPAA privacy compliant: HIPAA privacy officer

A

individual responsible for HIPAA privacy compliance at organization

32
Q

HIPAA privacy compliant: employee training

A

all employees who have access to PHI must be given HIPAA awareness training every 2 years

33
Q

HIPAA privacy compliant: documents and controls

A

formal documents, controls and policies, and procedures to protect PHI in the org

34
Q

HIPAA security compliance requires…

A
<ul>
<li>HIPAA security officer</li>
<li>employee training</li>
<li>HIPAA security risk assessment</li>
<li>documents and controls</li>
</ul>
35
Q

non-compliance

A

<ul>
<li>non-compliance is a civil offense that carries a penalty from $100-$50,000 per violation, with caps of $25,000-$1.5 million for all identical violations of a single requirement in a calendar year</li>
<li>unauthorized disclosure or misuse of PHI under false pretenses or with intent to sell, transfer, or use for personal gain, or malicious harm is a criminal offense punishable by $250,000 in fines, and up to 10 years in prison</li>
<li>civil penalties are enforced by the Office of Civil Rights within the Department of Health and Human Services</li>
</ul>