Public Health Concurrent Session II Jill Moore,

Published  . 0 views
↓ Download
Public Health Concurrent Session II Jill Moore,
1 / 1
Public Health Concurrent Session II Jill Moore, - slide 1 of 26 Public Health Concurrent Session II Jill Moore, - slide 2 of 26 Public Health Concurrent Session II Jill Moore, - slide 3 of 26 Public Health Concurrent Session II Jill Moore, - slide 4 of 26 Public Health Concurrent Session II Jill Moore, - slide 5 of 26 Public Health Concurrent Session II Jill Moore, - slide 6 of 26 Public Health Concurrent Session II Jill Moore, - slide 7 of 26 Public Health Concurrent Session II Jill Moore, - slide 8 of 26 Public Health Concurrent Session II Jill Moore, - slide 9 of 26 Public Health Concurrent Session II Jill Moore, - slide 10 of 26 Public Health Concurrent Session II Jill Moore, - slide 11 of 26 Public Health Concurrent Session II Jill Moore, - slide 12 of 26 Public Health Concurrent Session II Jill Moore, - slide 13 of 26 Public Health Concurrent Session II Jill Moore, - slide 14 of 26 Public Health Concurrent Session II Jill Moore, - slide 15 of 26 Public Health Concurrent Session II Jill Moore, - slide 16 of 26 Public Health Concurrent Session II Jill Moore, - slide 17 of 26 Public Health Concurrent Session II Jill Moore, - slide 18 of 26 Public Health Concurrent Session II Jill Moore, - slide 19 of 26 Public Health Concurrent Session II Jill Moore, - slide 20 of 26 Public Health Concurrent Session II Jill Moore, - slide 21 of 26 Public Health Concurrent Session II Jill Moore, - slide 22 of 26 Public Health Concurrent Session II Jill Moore, - slide 23 of 26 Public Health Concurrent Session II Jill Moore, - slide 24 of 26 Public Health Concurrent Session II Jill Moore, - slide 25 of 26 Public Health Concurrent Session II Jill Moore, - slide 26 of 26
Description: Public Health Concurrent Session II Jill Moore, JD, MPH March 2018 HIPAA highlights: entity Hybrid entity A HIPAA-covered entity that has both covered functions and non-covered functions In other words, the entity has some

Related Topics

Download Presentation

"Public Health Concurrent Session II Jill Moore," is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.

Presentation Transcript

slide1. Public Health Concurrent Session II Jill Moore, JD, MPH
March 2018<br>
slide2. HIPAA highlights: entity<br>
slide3. Hybrid entity A HIPAA-covered entity that has both covered functions and non-covered functions

In other words, the entity has some programs/services/ activities/functions that have to comply with HIPAA and some that don’t<br>
slide4. Definitions<br>
slide5. What goes in the designation of the health care component? Required:
Covered functions: The functions or activities that make the entity a covered entity
Business associate-like functions: Functions or activities that would create a business associate relationship if performed by a separate legal entity
Optional:
The agency may include functions or activities that do not meet either of the above criteria if it chooses<br>
slide6. A person or entity that
creates, receives, maintains, or transmits PHI on behalf of a covered entity, for a HIPAA covered function or activity
provides certain services involving PHI (legal, actuarial, accounting, consulting, data aggregation, management, administrative, accreditation, or financial) What is a business associate?<br>
slide7. What is the “entity” that counts? County If the agency is a county department, then the county is the covered entity
County health department
County consolidated human services agency
The county should be a hybrid entity, and the agency may be a hybrid within a hybrid Agency If the agency is a legal entity that is separate from a single county, then the agency is the covered entity
District health department
Public health authority
The agency itself may be a hybrid entity<br>
slide8. PH OR CHS AGENCY Health care component (covered by HIPAA):
Functions and activities that meet the definition of covered entity
Business associate-like functions or activities within the agency
Other functions/activities that agency chooses to include<br>
slide9. COUNTY PH or CHS agency EMS Covered & BA-like functions BA-like county functions (finance, legal, etc.)<br>
slide10. What to do with the hybrid entity designation Document it
No templates or required forms, but there are specifications in the rule: see 45 CFR 164.105(a)
Retain it
No requirement to file it with anyone, but should know where to find it Use it:
To inform HIPAA policies and procedures
To ensure appropriate workforce training
To help answer questions about uses and disclosures of information, breaches, etc.<br>
slide11. FAQs with answers that depend in part on what the hybrid entity designation says What are the rules for disclosing information? Information may have been disclosed improperly!
Do we have to do HIPAA breach notification? Do we need a business associate agreement? Who has to have HIPAA training?<br>
slide12. Time for a reboot? LHDs are encouraged to revisit their hybrid entity designations, especially if:
New consolidated agency
Programs/services added or ended
Current designation more than a couple years old<br>
slide13. Workforce Who they are Employees, volunteers, trainees, and other persons whose conduct in the performance of work is under the direct control of a covered entity or business associate Covered entity’s obligations Take workforce into account in developing HIPAA policies/procedures
Train workforce in HIPAA policies/procedures
Sanction workforce members who don’t comply<br>
slide14. Hipaa highlights: breach<br>
slide15. Acquisition, access, use, or disclosure of protected health information (PHI) that:
Is not authorized by the HIPAA privacy rule, and
Compromises the privacy and security of the PHI.

Breach is presumed unless:
A specific exception in the rule applies, or
A risk assessment shows a low probability that PHI was compromised. What is a breach?<br>
slide16. PHI could not reasonably be retained
Access is unintentional and by a workforce member or business associate acting in good faith
Inadvertent disclosure is made to another person within the CE or BA who is authorized to access PHI What are the exceptions?<br>
slide17. Risk assessment What it is: Analysis you undertake to demonstrate low probability that PHI was compromised
Demonstrated low probability of compromise defeats the presumption that unauthorized acquisition, access, use, or disclosure was a breach Minimum factors: Nature and extent of PHI, including types of identifiers & likelihood of re-identification
Unauthorized person who received disclosure or used PHI
Whether PHI was actually acquired and viewed
Extent to which any risk to PHI has been mitigated<br>
slide18. Don’t have to notify if:
PHI was encrypted, or
PHI was disposed in keeping with HHS guidance on secure disposal Safe harbor<br>
slide19. Was it encrypted or disposed per rules (safe harbor)? Low probability of compromise per risk assessment? STOP Did acquisition, access, use, or disclosure involve PHI? Notification required Yes No Does an exception apply? No No No Yes Yes Yes STOP<br>
slide20. Notification prep: date check If required to notify, must do so “without unreasonable delay” – no later than 60 days after breach discovered
Breach deemed discovered even if no actual knowledge, if reasonable diligence would have revealed it<br>
slide21. Notification Timeframes<br>
slide22. Notice Content What happened?
Description of incident
Description of types of PHI involved (e.g., name, address, record number, DOB, diagnosis, etc.)
When did it happen? When did you realize it happened?
Description of incident must include dates of breach and of discovery of breach
What should people do?
Steps individuals should take to minimize potential harm from the breach What is the covered entity doing?
Brief description of CE actions to investigate and mitigate the breach, and protect against future breaches
What if I want to know more?
Contact information and procedures for individuals to ask questions or learn more about breach<br>
slide23. Breach: unauthorized access to or acquisition of records or data with “personal information,” which means name plus something that could be used to commit ID theft or threaten finances (SSN, DL number, financial account numbers, etc.)
State law requires breach notification, if:
Illegal use of the information has occurred, or
Illegal use of the information is reasonably likely to occur, or
The incident creates a material risk of harm to a consumer. State law on breaches<br>
slide24. Investigate the circumstances

Mitigate harm to individuals

Account for disclosures (include in accounting log or other mechanism you use to provide accounting to individuals who request it)

Follow-up with employees – apply sanctions, review training What else should you do?<br>
slide25. hot and late-breaking topics<br>
slide26. Questions?<br>