Lec 10 - Student HIPAA Fraud Flashcards
What does HIPAA stand for?
Health Insurance Portability and Accountability Act of 1996
HIPAA protects what?
Privacy and security of certain health information
What is the privacy rule?
Establishes national standards for the protection of certain health information
What is security rule?
Establish a national set of security standards for protecting certain health info that is held or transferred in electronic form
HITECH Act, 2009 - what did this do?
Expanded rules to business associates
Many health care providers are aware of the _________ _______ of HIPAA
Privacy requirements
HIPAA also has significant impact on __________ of _______
Standardization of data
Covered entities: A health care provider includes:
Doctors Clinics Psychologists Dentists Chiros Nursing homes Pharmacies ... but only if they transmit information in an electronic form in connection with a transaction for with HHS has adopted a standard
Covered entities: What does a health plan include?
Health insurance companies
HMOs
Company health plans
Government programs that pay for health care, such as:
Medicare, Medicaid, and the military and veterans health care programs
Covered entities: A Health Care Clearinghouse includes:
Entities that process NONSTANDARD health information they receive from another entity into a standard, or vice versa
Business associates: A person or entities that performs certain functions or activities that involve the use of ______ of protected health information on behalf of, or provides services to, a ___________
Disclosure
Covered entity
Business associates: Perform certain function of activities on behalf of the _________
Covered entity
Covered entity workforce not ___________
Business associates
Business associates: may include: (6)
1) claims processing
2) data analysis
3) quality assurance
4) certain patient safety activities
5) utilization review
6) billing
Business associates: T/F: Can be Legal Actuarial Accounting Consulting Data aggregation Information technology management Administrative Accreditation Financial services
True……
Business associates: Some contractors that perform services for a ______ are not business associates because the services do not involve the use or disclosure of _____
CE
PHI
What are three HIPAA Rules?
Privacy Rule
Security Rule
Breach Notification Rule
The privacy rule is intended to…
Protect privacy of all individually identifiable health information
Privacy Rule: Gives pts new rights to access their ___________, to request _______, and to learn how they have been _______.
Medical records
Changes
Accessed
Privacy Rule: Restricts access by _____
OTHERS
Privacy Rule: Restricts access to the ________ ______ for healthcare treatment and business operations
Minimum needed
Privacy Rule: Provides that all patients are informed about ____ ______ _____/_______
Entity privacy practices/policies
Privacy Rule: Enables pt decisions on ________ for disclosure of PHI beyond treatment/business operations
Authorization
Privacy Rule: Protects most __________________ held or transmitted by a covered entity of business associate, in any form or media, whether electronic, paper, or oral
INDIVIDUALLY IDENTIFIABLE HEALTH INFORMATION
What does PHI stand for?
Protected health information
What is PHI?
Individually identifiable health information is information including demographic information
PHI demographic information relates to: (3)
1) Pt’s past, present or future physical or mental health condition
2) The provision of health care to the individual
3) The past, present, or future PAYMENT of health care to individual
What does individually identifiable health information do?
IDs the individual or there is a reasonable basis to believe it can be used to ID the individual
When PT authorizations not required for disclosure of PHI: (5)
- Info sharing needed for Tx
- Disclosures to family, friends, and others involved in the care of the individual as well as for notification purposes
- Info needed to ensure public health and safety
- Info need to prevent or lessen imminent danger
- Disclosures in facility directories
HIPAA Privacy Rule Notices: An adequate privacy note must include all of the following (6)
- Required heading
- Statement of use and disclosures
- Statement of individual rights
- Statement of covered entity’s duties
- Explanation of how to complain
- Required contact info
What is the security rule?
Establishes national standard to protect individuals’ ELECTRONIC personal health information that is created, received, used or maintained by covered entity.
The security rule requires appropriate _____, ______ and _______ safeguards to ensure the ______, ______, and _________ of electronic PHI
Administrative
Physical
Technical
Confidentiality
Integrity
Security
The security rule defines confidentiality to mean that _______ is not available to disclosed to unauthorized persons
E-PHI
The security rule requires covered entities to maintain responsible and appropriate _____, ______, and ______ safeguards for protecting e-PHI
Administrative
Technical
Physical
In security general rules, covered entities must:
Ensure the confidentiality, integrity, and availability of all e-PHI they _____, _____, _____, or ______
Create
Receive
Maintain
Transmit
In security general rules, covered entities must: ID and protect against reasonably anticipated ______ to the security or integrity of the info
Threats
In security general rules, covered entities must: Protect against reasonably anticipated, ___________ uses or disclosures
Impermissible
In security general rules, covered entities must: Ensure _______ by their workforce
COMPLIANCE
What is the breach notification rule?
Requires HIPAA covered entities and their business associates to provide notification following a breach of unsecured protected health info
Definition of breach:
An impermissible use or disclosure under the privacy rule that compromises the security of privacy of the PHI
HIPAA considerations for PT practice: (5)
Patient identification Eval procedures Sign in and out processes Physical layout of facility Computer security
What are the penalties for violating HIPAA:
Breaking HIPAA’s privacy or security rules can mean either a _____ or ______ sanction
Civil
Criminal
What are the penalties for violating HIPAA: What are civil penalties?
Usually fines
What are the penalties for violating HIPAA: Civil penalties are usually the result of _________, not necessarily resulting in personal gain
Inadvertent violations
What are the penalties for violating HIPAA: What are criminal sanctions?
Involve monetary penalties and jail time
Intent and fine: Did not know or could not have known ?
100- 50,000
Intent and fine: Reasonable cause and not willful neglect?
1,000-50,000
Intent and fine: Willful neglect, but corrected within 30 days
10,000-50,000
Willful neglect and not corrected within 30 days
50,000