HIPAA Privacy Rule Flashcards
(87 cards)
HIPAA acronym
Health Insurance Portability and Accountability Act
Privacy Rule was passed in what year?
2003
Security Rule was passed in what year?
2005
The privacy rule establishes the ______
minimum
(NOTE: if state and federal are diff, follow the most stringent one)
What is privacy?
Freedom from unauthorized intrusion
What is confidentiality?
requires HC providers to protect heath records from unauthorized use
(NOTE: may be written or verbal)
What title # of HIPAA pertains to privacy and security?
Title II
What forms of info does the Privacy rule cover?
oral, written, and electronic
What forms of info does the Security rule cover?
Only electronic info
PHI acronym
Protected health info
What does HIPAA lack?
a private right of action
(NOTE: means that a pt can’t sue for HIPAA violation, only an attorney or general gov)
Purpose of HITECH (2009) (2)
- Strengthens privacy and security of PHI (i.e. use of EHRs)
- increased penalties
What is health info per HIPAA?
Any info (whether oral or recorded in any form) that is created or received by a health care provider, health plan, employer, life insurer, school
AND relates to the past, present, or future phys/mental health of an individual
What happens if health info is not dated?
Applies to the future
(no end date)
What 6 things does HIPAA provide the patient the right of?
- access
- request amendment
- accounting of disclosure
- request confidential communications
- request restrictions
- complain of privacy rule violations
Who does HIPAA apply to? (2)
- Covered entities (+ workforces)
- Business associates (+ workforce and subcontractors)
What is covered under HIPAA?
PHI (and any “HIPAA identifiers” that point to a certain pt)
What is NOT covered under HIPAA? (2)
- De-identifiied info
- personnel and edu records
Three HIPAA CEs:
- Healthcare provider
- Health plan
- Healthcare clearinghouse
CE: Healthcare provider description
doctor
CE: Health plan description
insurance plan
CE: Healthcare Clearinghouse description
3rd party billing vendor
Should HIPAA be politicalized?
No
An example of an organization that would need a business associate agreement is…
a) housekeeping service
b) Hospital where dr refers patients for surgery
c) Healthcare organization’s employees
d) Billing service that the healthcare organization uses
d) Billing service that the healthcare organization uses