Module 7 Flashcards
(11 cards)
The Health Insurance Portability and Accountability Act of 1996, HIPAA
enacted to improve the efficiency of healthcare delivery
Enforcement of HIPAA regulations is the responsibility of the Department of Health and Human Services. HIPAA does not preempt stricter state laws.
Protected health information (or PHI)
is any individually identifiable health information transmitted or maintained in any form or medium that relates to an individual’s past, present, or future physical or mental health or condition; the provision of health care to an individual; or the past, present, or future payment for the provision of health care to the individual.
Electronic protected health information (ePHI)
is any transmitted or maintained in electronic media. This distinction also helps to clarify which healthcare entities are covered by HIPAA.
Privacy and Security Rules (1) HIPAA
specific requirements to protect the privacy and security of health information and provide individuals with certain rights with respect to that health information. Written agreement that must comply with the Privacy Rule’s priva
Privacy and Security Rules (2)
Privacy Rule requires a covered entity to provide a detailed privacy notice at the date of first service delivery. The rule also requires opt-in authorization for use or disclosure of PHI outside of HIPAA guidelines; it limits the use and disclosure of personal health information for business associates and it provides information on how individuals can access and amend their PHI. Covered entities must also have safeguards in place to protect the confidentiality and integrity of all PHI and designate a privacy official to develop and implement privacy protections.
The Genetic Information Nondiscrimination Act, GINA
enacted in 2008 and protects individuals against genetic discrimination by health insurance providers and employers.
The Health Information Technology for Economic and Clinical Health Act of 2009, HITECH,
promoted the adoption and meaningful use of health information technology.
Data minimization:
Refers to PHI including identifiers of the individual. Any data disclosed must be the minimum amount necessary.
Who is responsible for enforcing HIPAA’s Privacy and Security Rules?
Office for Civil Rights (OCR)
Which act is intended to expedite the research process for medical devices and prescription drugs?
21st Century Cures Act
Which act introduced the first medical privacy provisions?
Comprehensive Alcohol Abuse and Alcoholism Prevention, Treatment and Rehabilitation Act.