1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.

26
1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved

Transcript of 1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.

Page 1: 1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.

1

Privacy Plan of Action

© HIPAA Pros 2002 All rights reserved

Page 2: 1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.

2

Team Assignments

Assign security responsibilities to one or more individuals. 

Record the names and/or job titles of the people who are responsible for addressing requests to view or amend protected health information.

Page 3: 1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.

3

Team Assignments

Record the names and/or job titles of the people who are responsible for processing requests for an “accounting of disclosures”.

Page 4: 1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.

4

Team Assignments

Designate a privacy official who is responsible for development and implementation of privacy policies and procedures.

Designate a contact person responsible for receiving complaints.

Page 5: 1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.

5

Create an inventory of PHI and note the processes in place for handling it.

Determine how PHI is used.

Determine how PHI is disclosed.

Establish Procedures for Handling, Processing and Storing Protected Health

Information (PHI)

Page 6: 1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.

6

Establish Procedures for Handling, Processing and Storing Protected Health

Information (PHI)

Determine the kinds of information to which each staff member should have access.

Update your employee manual to include sanctions for any employees who leave a secure area unlocked, or who fail to follow established privacy and security procedures.

Page 7: 1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.

7

Prepare a list of all routine and non-routine uses and disclosures.

Establish minimum necessary access policies and procedures for staff.

Establish Procedures for Handling, Processing and Storing Protected Health

Information (PHI)

Page 8: 1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.

8

Ensure Adequate Physical Security to Safeguard PHI Keep track of who has keys to the office itself

and to the secure areas inside.

Place door locks on storage rooms where archives are stored.

Develop strategies to handle PHI trash disposal.

Put locks on chart filing cabinets located in public areas.

Page 9: 1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.

9

Keep computer servers that contain PHI in rooms that are open only to essential personnel.

Position workstations so that the screens are not easily viewable by passersby.

Ensure Adequate Physical Security to Safeguard PHI

Page 10: 1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.

10

Ensure Adequate Physical Security to Safeguard PHI

Develop policies and procedures for backups of data.

Document procedures for bringing hardware and software into and out of the facility.

Page 11: 1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.

11

Establish Clear Rules to Ensure Client Privacy

Establish personnel clearance procedures.

Establish personnel termination procedures.

Give each employee a written copy of the client privacy rules for your office.

Page 12: 1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.

12

Establish Clear Rules to Ensure Client Privacy

Make sure each employee understands that they are permitted to use or disclose only the minimum amount of PHI necessary to accomplish the intended purpose.

Page 13: 1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.

13

Establish Client Amendment Procedures

LOCATION OF PHI TIME LIMIT

PHI that is maintained in the office. Provide approval and access or notice of denial within 30 days of the request.

PHI that is maintained outside the office (i.e., a storage facility).

Provide approval and access or notice of denial within 60 days.

Time Limits in Which You Must Respond to Requests for PHI

Page 14: 1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.

14

Establish Client Amendment Procedures

Obtain one 30-day extension.

Will only be granted if you give the client written notice explaining the delay, including a date when the request will be completed.

Page 15: 1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.

15

Establish Client Amendment Procedures

A written record of all client requests for PHI.

Identify two “reviewing individuals” who are licensed health care professionals to help address client appeals.

Page 16: 1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.

16

Establish Client Amendment Procedures

Establish a process for approvals and denials.

Establish a reasonable fee for copying PHI.

Page 17: 1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.

17

Establish Client Amendment Procedures

Incorporate HIPAA compliance into your clinical research consent forms.

Keep psychotherapy “process” notes separate from the rest of the medical record.

Page 18: 1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.

18

Establish a Formal Complaint Procedure

Incorporate complaint procedure into your notice of privacy practices.

Develop a system to keep detailed records of all complaints, and document how and when these complaints were addressed.

Page 19: 1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.

19

Establish a Formal Complaint Procedure

Make sure that staff understands that they are not allowed to pressure any client to waive their right to file a complaint.

Create a logbook to document all complains.

Page 20: 1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.

20

Establish a Formal Complaint Procedure

Be certain that no staff intimidate or retaliate against any individual who files a complaint or exercises any other right guaranteed under HIPAA regulations.

Page 21: 1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.

21

Publish a Notice of Privacy Practices and

Adhere To It Write and publish a notice of privacy

practices.

Keep copies of past notices of privacy practices.

Create a written acknowledgement of receipt of the notice of privacy practices.

Page 22: 1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.

22

Publish a Notice of Privacy Practices and

Adhere To It Obtain authorization for uses and

disclosures associated with purposes other than treatment, payment, or health care operations.

Retain all acknowledgement forms and authorization forms.

Page 23: 1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.

23

Vendor Relationships

Establish a chain of trust agreement with each organization with which you exchange PHI electronically.

Page 24: 1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.

24

Vendor Relationships

Establish a business associate agreement with any organization that provides a service that involves the use or disclosure of PHI.

Take steps to cure any known breach of the business associate agreement.

Page 25: 1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.

25

Train the Workforce

Make sure all staff receive privacy and security training.

Develop security awareness in the workforce.

Teach physical security habits.

Page 26: 1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.

26

Train the Workforce

Ensure that everyone understands policies and procedures.

Use periodic security reminders.