
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>we made it to Friday!  HIPAA Review????</title>
<link>https://www.askascent.com/forums/posts.aspx?topic=1140089</link>
<description></description>
<lastBuildDate>Sat, 6 Jun 2026 16:35:10 GMT</lastBuildDate>
<pubDate>Fri, 28 Aug 2015 19:50:38 GMT</pubDate>
<copyright>Copyright &#xA9; 2015 ASCENT | Administrator Support Community for ENT</copyright>
<atom:link href="https://www.askascent.com/forums/topic_rss.asp?id=1140089" rel="self" type="application/rss+xml"></atom:link>
<item>
<title>we made it to Friday!  HIPAA Review????</title>
<link>https://www.askascent.com/forums/posts.aspx?topic=1140089</link>
<guid>https://www.askascent.com/forums/posts.aspx?topic=1140089</guid>
<description><![CDATA[<p>ok, HIPAA is the one that is with us at all times and we never forget.</p>
<p>&nbsp;</p>
<p>Some small facts about it----which U.S. Department implemented the Privacy Rule?</p>
<p>&nbsp;</p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; answer: &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; HHS or the Department of Health and Human Services</p>
<p>&nbsp;</p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Who enforces the Privacy Rule</p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Office of Civil Rights&nbsp; (OCR) from wthin the HHS</p>
<p>&nbsp;&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Everyone remembers what PHI Stands for?&nbsp; </p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Protected Health Information</p>
<p>&nbsp;</p>
<p> </p>
<p></p>
<p>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Who is subject to the Privacy Rule?&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </p>
<p>&nbsp;</p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; All covered&nbsp; "entities" which includes all providers of service &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; who furnishes, bills or is paid for healthcare.</p>
<p></p>]]></description>
<pubDate>Fri, 28 Aug 2015 19:48:36 GMT</pubDate>
</item>
<item>
<title></title>
<link>https://www.askascent.com/forums/posts.aspx?topic=1140101</link>
<guid>https://www.askascent.com/forums/posts.aspx?topic=1140101</guid>
<description><![CDATA[<br /><br />Review what encompasses PHI---which is basically anything which could specifically identify an individual receiving any type of care.  <br /><br />One of the major requirements for a covered entity is to develop and implement privacy policies, most commonly known in our offices as the HIPAA Manual.<br /><br />These policies should include:<br /><br />The name of the designated Privacy Official.<br />Who to contact with issues or complaints<br />Training and management<br />Sanctions imposed for violations<br /><br />these are just a few.  The complete Privacy, Security and Breach Notification Audit Program can be found at  http://www.hhs.gov/ocr/privacy/hipaa/enforcement/audit/index.html<br /><br />some things to think about for HIPAA--are the following violations?<br /><br />Employee sends physician's schedule to him via their personal cell phone which is password protected.<br /><br />Nurse at hospital sends photo of patient's post-operative wound to physician from their cell phone at the surgeon's request.<br /><br />Patients in waiting room can hear telephone conversation in the reception area.<br /><br />Patient in exam room can hear physician talking to his assistant regarding another patient in hallway of office<br /><br />Faxing patient records to another physicians office.<br /><br />Messaging within your EHR regarding specific patients.<br /><br />Sending information via email to another physicians office.<br /><br />Leaving laptop with access to PHI in examination room <br /><br />Texting from personal cell phones to physician regarding specific patients.<br /><br /><br /><br /><br /><br />                     ]]></description>
<pubDate>Fri, 28 Aug 2015 20:41:09 GMT</pubDate>
</item>
<item>
<title></title>
<link>https://www.askascent.com/forums/posts.aspx?topic=1140103</link>
<guid>https://www.askascent.com/forums/posts.aspx?topic=1140103</guid>
<description><![CDATA[  <br />If we didn't have enough rules--the following "simplication statute and rules" offer some more<br /><br />HIPAA Administrative Simplification Statute and Rules <br />To improve the efficiency and effectiveness of the health care system, the Health Insurance Portability and Accountability Act of 1996 (HIPAA), Public Law 104-191, included Administrative Simplification provisions that required HHS to adopt national standards for electronic health care transactions and code sets, unique health identifiers, and security. At the same time, Congress recognized that advances in electronic technology could erode the privacy of health information. Consequently, Congress incorporated into HIPAA provisions that mandated the adoption of Federal privacy protections for individually identifiable health information.  <br />HHS published a final Privacy Rule in December 2000, which was later modified in August 2002. This Rule set national standards for the protection of individually identifiable health information by three types of covered entities: health plans, health care clearinghouses, and health care providers who conduct the standard health care transactions electronically.  Compliance with the Privacy Rule was required as of April 14, 2003 (April 14, 2004, for small health plans). <br />HHS published a final Security Rule in February 2003. This Rule sets national standards for protecting the confidentiality, integrity, and availability of electronic protected health information. Compliance with the Security Rule was required as of April 20, 2005 (April 20, 2006 for small health plans).<br />OCR administers and enforces the Privacy Rule and the Security Rule.<br />Other HIPAA Administrative Simplification Rules are administered and enforced by the Centers for Medicare & Medicaid Services, and include:<br />	Transactions and Code Sets Standards<br />	Employer Identifier Standard<br />	National Provider Identifier Standard<br />The Enforcement Rule provides standards for the enforcement of all the Administrative Simplification Rules.<br />All of the HIPAA Administrative Simplification Rules are located at 45 CFR Parts 160, 162, and 164.<br /><br />The website for the Department of Human Services actually does offer tools for dealing the multitude of HIPAA requirements so you may want to spend a little time taking a look.<br />]]></description>
<pubDate>Fri, 28 Aug 2015 20:50:38 GMT</pubDate>
</item>
</channel>
</rss>
