Showing posts with label violation. Show all posts
Showing posts with label violation. Show all posts

Friday, October 23, 2015

HIPAA Breach Notification Rule

HIPAA covered entities and their business associates to provide notification following a breach of unsecured protected health information.


The HIPAA Breach Notification Rule, 45 CFR §§ 164.400-414, requires HIPAA covered entities and their business associates to provide notification following a breach of unsecured protected health information. Similar breach notification provisions implemented and enforced by the Federal Trade Commission (FTC), apply to vendors of personal health records and their third party service providers, pursuant to section 13407 of the HITECH Act.


Breach Notification Requirements

Following a breach of unsecured protected health information, covered entities must provide notification of the breach to affected individuals, the Secretary, and, in certain circumstances, to the media. In addition, business associates must notify covered entities if a breach occurs at or by the business associate.

  • Individual Notice
Covered entities must notify affected individuals following the discovery of a breach of unsecured protected health information. Covered entities must provide this individual notice in written form by first-class mail, or alternatively, by e-mail if the affected individual has agreed to receive such notices electronically. If the covered entity has insufficient or out-of-date contact information for 10 or more individuals, the covered entity must provide substitute individual notice by either posting the notice on the home page of its web site for at least 90 days or by providing the notice in major print or broadcast media where the affected individuals likely reside. The covered entity must include a toll-free phone number that remains active for at least 90 days where individuals can learn if their information was involved in the breach. If the covered entity has insufficient or out-of-date contact information for fewer than 10 individuals, the covered entity may provide substitute notice by an alternative form of written notice, by telephone, or other means.  
These individual notifications must be provided without unreasonable delay and in no case later than 60 days following the discovery of a breach and must include, to the extent possible, a brief description of the breach, a description of the types of information that were involved in the breach, the steps affected individuals should take to protect themselves from potential harm, a brief description of what the covered entity is doing to investigate the breach, mitigate the harm, and prevent further breaches, as well as contact information for the covered entity (or business associate, as applicable).
With respect to a breach at or by a business associate, while the covered entity is ultimately responsible for ensuring individuals are notified, the covered entity may delegate the responsibility of providing individual notices to the business associate.  Covered entities and business associates should consider which entity is in the best position to provide notice to the individual, which may depend on various circumstances, such as the functions the business associate performs on behalf of the covered entity and which entity has the relationship with the individual.
  
  • Media Notice
Covered entities that experience a breach affecting more than 500 residents of a State or jurisdiction are, in addition to notifying the affected individuals, required to provide notice to prominent media outlets serving the State or jurisdiction.  Covered entities will likely provide this notification in the form of a press release to appropriate media outlets serving the affected area.  Like individual notice, this media notification must be provided without unreasonable delay and in no case later than 60 days following the discovery of a breach and must include the same information required for the individual notice.

  • Notice to the Secretary
In addition to notifying affected individuals and the media (where appropriate), covered entities must notify the Secretary of breaches of unsecured protected health information. Covered entities will notify the Secretary by visiting the HHS web site (http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/brinstruction.html) and filling out and electronically submitting a breach report form. If a breach affects 500 or more individuals, covered entities must notify the Secretary without unreasonable delay and in no case later than 60 days following a breach. If, however, a breach affects fewer than 500 individuals, the covered entity may notify the Secretary of such breaches on an annual basis. Reports of breaches affecting fewer than 500 individuals are due to the Secretary no later than 60 days after the end of the calendar year in which the breaches are discovered.

  • Notification by a Business Associate
If a breach of unsecured protected health information occurs at or by a business associate, the business associate must notify the covered entity following the discovery of the breach.  A business associate must provide notice to the covered entity without unreasonable delay and no later than 60 days from the discovery of the breach.  To the extent possible, the business associate should provide the covered entity with the identification of each individual affected by the breach as well as any other available information required to be provided by the covered entity in its notification to affected individuals.

When a breach occurs in your office, it is required that you report it!

This information was supplied by: http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/

For more information on this and other topics related to HIPAA, HR, OSHA, and Medicare, please emailsupport@hcsiinc.com or visit our website at http://www.hcsiinc.com

Be sure to become a member of our Linkedin group by visiting; http://bit.ly/1FWmtq6

To subscribe to this blog, enter your email address:

Delivered by FeedBurner

Monday, October 19, 2015

5 Common HIPAA Pitfalls

HIPAA Pitfalls at Physicians Practices


The following is a list of common HIPAA violations seen regularly in physician offices. Check your practice against this list to see if your staff commits the same common violations, and if so, address these problems in advance:


  • Not providing the Notice of Privacy Practices (NPP), even though they require patients to sign a statement indicating they had been provided with, and read, the NPP.
  • Not having documented internal information security and privacy policies for staff members to follow.
  • Exposing PHI to anyone within the office facilities e.g., patient file folders left out on the check-in desk unattended, patient file folders left in the wall pockets outside examination rooms with health information facing out and visible, etc.
  • Healthcare workers asking for verbal confirmation of PHI in the waiting room or in front of other patients.
  • Not obtaining consent from patients to photograph or film them and then use the photos, video, or audio of the patient for marketing purposes.
Avoiding HIPAA pitfalls is something that can be accomplished with an effective compliance program that covers both HIPAA Privacy and HIPAA Security. Be sure your compliance program is effective enough to protect your office.


For more information on this and other topics related to HIPAA, HR, OSHA, and Medicare, please emailsupport@hcsiinc.com or visit our website at http://www.hcsiinc.com

 

Be sure to become a member of our Linkedin group by visiting; http://bit.ly/1FWmtq6

To subscribe to this blog, enter your email address:

Delivered by FeedBurner

Tuesday, September 22, 2015

Proper PHI Disposal

Dispose of PHI properly and help eliminate this area of potential liability



When PHI and ePHI is no longer needed by your office or you have maintained your archived records for the specified period of time, it is vital that these documents and electronic document be disposed of properly. By disposing of these documents and electronic documents properly, you are greatly lessening your chance of this critical area of compliance being a liability for your organization or practice.

In general, examples of proper disposal methods may include, but are not limited to:
• For PHI in paper records, shredding, burning, pulping, or pulverizing the records so that PHI is rendered essentially unreadable, indecipherable, and otherwise cannot be reconstructed.
• Maintaining labeled prescription bottles and other PHI in opaque bags in a secure area and using a disposal vendor as a business associate to pick up and shred or otherwise destroy the PHI.
• For PHI on electronic media, clearing (using software or hardware products to overwrite media with non-sensitive data), purging (degaussing or exposing the media to a strong magnetic field in order to disrupt the recorded magnetic domains), or destroying the media (disintegration, pulverization, melting, incinerating, or shredding).

In addition to the properly disposing of PHI and ePHI, it is important to remember that you must also properly dispose of all PHI that has been accessed by any electronic device. If the device is no longer going to be used, it is very difficult to properly dispose of the ePHI files on these devices, so HIPAA suggest the entire device is destroyed.

Properly disposing of all PHI and ePHI is improve greatly reduce the risk of a health information breach, thus improving your chances of avoiding a violation fine.

For more information on protecting your office with this issue and other HIPAA, HR, OSHA, and Medicare topics, please visit our web site: http://www.hcsiinc.com or email support at support@hcsiinc.com.

Source: http://bit.ly/1MGGOlm

Tuesday, September 15, 2015

HIPAA Violations and Social Networking

Social Networking Is Putting Your Practice at Risk

Many healthcare organizations are using social networks (Facebook, Twitter, Instagram, etc.) as a means of connected with their client base, or as a means of advertising their services. Whether your practice is using these social networks or not, you
can reasonably assume that your employees are using these sites to expand their own personal social network. This can present a huge problem! 

Employees who frequently use these sites as a way of sharing the events of their personal lives are very likely to discuss work on-line as well. Social network sites create a huge risk for HIPAA violations, and also for employee relation problems.

HIPAA violations occurring on these popular social media sites demand employers establish guidelines for social network use. Because healthcare workers normally access them on personal time away from work, employers should discuss the importance of these guidelines.

Employers should generally prohibit employees from including any information about patients on their social network pages, even if patients have given them permission to do so. It is also recommended that you prohibit your employees from linking to a patient’s social network page. We encourage you to prohibit your employees from accessing these social networking pages while at work using your office computer.

Individuals are free to disclose any information they choose on their social network pages, including their own personal PHI. However, you should be sensitive about your employees linking to these pages at work because of the appearance of impropriety and the distinct possibility of a HIPAA violation. Employers cannot control their employee’s lives and social media activity, EXCEPT as it relates to work.