HIPAA Flashcards
CMS stands for…
Centers for Medicare & Medicaid Services
it is the main federal government agency responsible for Medicare & Medicaid
CMS
HIPAA stands for…
Health Insurance Portability & Accountability Act of 1996
What does HIPAA do?
— protect health info
— ensures coverage for PT
— created industry standards
3 parts of HIPAA
— Privacy Rule
— Security Rule
— Electric Healthcare Transactions & Code Sets (TCS) Rule
What does privacy rule do?
— regulates use & disclosure of PT’s protected health info
What does PHI stands for & what is it?
it stands for Protected Health Info, it is anything that can identify the PT
— identifier + health info = PHI
What are the 3 Covered Entities (CE) that must follow HIPAA?
Payers, Clearinghouse, Provider
What are payers?
they are the insurance companies or health plan
What is a clearinghouse?
it’s the organizations that checks for error on the claim before submitting to the payer
What are examples of Providers?
Nurse Practitioner, Physician Assistant, Medical Dr., Laboratory, Pharmacy
What are business associates?
it is anyone that are personally employed for the CEs
— ex : Biller, Coder, Insurance Specialist, Office Staff, Receptionist, etc.
TPO stands for…
Treatment, Payment, & Healthcare Operations
What is a TPO?
it is an exception to releasing PT’s info w/o a release form
What are other situations where release form is not needed?
— Subpoena (court orders) - Duces Tecum
— Emergency
— Workman Compensation
— Communicable diseases (HIV, COVID)
What does security rule do?
— requires CEs to establish physical & technical safeguards to protect PHI
What does TCS Rule do?
— releasing PT’s data where the “Laymen person” can’t understand
What is a code set?
any group of codes used for encoding data elemets
What does NPI stands for and what is it?
National Provider Identifier — a unique 10-digit identifier given to provider
What does NPP stands for and what is it for?
Notice of Privacy Practices — a form letting PT know how we protect their PHI
What is a Breach?
it is when PHI is leaked w/o permission
HITECH stands for…
and, what does it do?
Health Info Technology for Economic & Clinical Health Act — requires CEs to notify affected individuals ff the discovery of a breach of unsecured HI
What is a breach notification?
it’s a document notifying an individual of a breach (only 60 days)
What is the difference between fraud and abuse?
Fraud is intentional, it’s to gain access and abuse is unintentional due to lack of training or a mistake.