HIPAA and HITECH Study Notes

INTRODUCTION AND REVIEW - PART F: HIPAA AND HITECH

Overview of HIPAA

  • The Health Insurance Portability and Accountability Act (HIPAA) was enacted in 1996.

  • Oversight of HIPAA is assigned to the U.S. Department of Health and Human Services (HHS).

  • Its regulations are focused on:

    • Ensuring privacy and security of patient health information.

    • Standardizing healthcare transactions.

    • Assigning administrative identifiers for health care providers.

    • Enforcing compliance with these regulations.

Overview of HITECH

  • The Health Information Technology for Economic and Clinical Health Act (HITECH Act) was enacted in 2009.

  • It is part of the American Recovery and Reinvestment Act.

  • Modifications under HITECH include:

    • Changes to HIPAA Privacy and Security Rules.

    • Standards for Current Dental Terminology (CDT) procedure codes.

    • New Breach Notification Rules.

Transition from Paper to Electronic Systems

  • Prior to HIPAA, there were no universally accepted security standards for protecting health information.

  • The healthcare industry began transitioning to electronic information systems for:

    • Claims processing.

    • Eligibility inquiries.

    • Health information provision.

    • Other administrative functions.

  • Current technologies include:

    • Computerized Physician Order Entry (CPOE) systems.

    • Electronic Health Records (EHR).

    • Systems for radiology, pharmacy, and laboratory functions.

  • Increased use of technology enhances mobility and efficiency but also raises security risks.

Goals of the HIPAA Security Rule

  • Protect individual health information privacy.

  • Facilitate the adoption of new technologies to improve patient care.

  • The Security Rule is designed to be flexible and scalable based on the organization’s size, structure, and risk environment.

Key Acronyms and Definitions

  • HIPAA: Health Insurance Portability and Accountability Act

  • HITECH Act: Health Information Technology for Economic and Clinical Health Act

  • OCR: Office for Civil Rights

  • CDT: Current Dental Terminology (procedure codes)

  • NPI: National Provider Identification, a unique 10-digit identifier.

  • PHI: Protected Health Information, encompassing health details, billing information, and personal data.

  • ePHI: Electronic Protected Health Information

  • TPO: Treatment, Payment, and Operations

  • BA: Business Associate

  • HHS: Health and Human Services department overseeing HIPAA compliance.

Key Definitions

Covered Entity

  • All healthcare providers who electronically transmit health information for specific transactions are considered Covered Entities.

  • Transactions include:

    • Claims processing.

    • Benefit eligibility inquiries.

    • Referral authorization requests.

  • Covered Entities include institutional providers (hospitals) and non-institutional providers (physicians, dentists).

Business Associates

  • A business associate is an entity that performs functions for or services to a Covered Entity and may access PHI.

  • Examples include:

    • Claims processing.

    • Data analysis.

    • Billing.

  • Business associates are not considered as such if their access to PHI is merely incidental.

Business Associates Grant Requirements

  • When engaging a contractor as a business associate, the Covered Entity must ensure:

    • Specific protections for the information in a business associate agreement.

    • Business associates cannot use PHI in ways that violate HIPAA.

Protecting Health Information

  • The Privacy Rule safeguards all individually identifiable health information held by a Covered Entity or its associates regardless of format (electronic, paper, or oral).

  • Individually identifiable health information includes:

    • Demographic data.

    • Information pertaining to health conditions, treatments, or payment.

  • Covered entities can only use/disclose PHI as permitted by the Privacy Rule or with the individual's consent.

Security Rule Requirements

Fundamental Elements for Security

  1. Confidentiality: Ensure that PHI is not disclosed to unauthorized persons.

  2. Integrity: Protect information from being altered or destroyed by unauthorized individuals.

  3. Availability: Ensure that authorized individuals can access and use the information when needed.

Standards of Compliance

  • Compliance is categorized into:

    • Administrative Safeguards: Documented practices for selecting and implementing security measures.

    • Physical Safeguards: Security measures to control physical access to systems.

    • Technical Safeguards: Measures to protect and monitor electronic access to systems.

  • Compliance standards include required and addressable specifications:

    • Required: Must be implemented.

    • Addressable: Should be implemented based on risk analysis.

Required Disclosures

Obligatory Disclosures

  • A Covered Entity must disclose PHI to:

    1. Individuals requesting access to their PHI.

    2. HHS during compliance investigations.

Permitted Uses and Disclosures

Covered Entities may use or disclose PHI without individual authorization in various circumstances:

  1. Disclosures to individuals upon written request.

  2. For treatment, payment, and operations (TPO).

  3. Opportunity for informal consent or objection.

  4. Incidental disclosures may occur when reasonable safeguards are in place.

  5. Public interest and benefit activities (e.g., legal actions requiring access to records).

Patient Authorization Requirements

  • Required for any disclosures not falling under the TPO scope.

  • Specific wording is necessary for the authorization, which may include disclosures to third parties like insurance companies.

Minimum Necessary Principle

  • Covered Entities must limit PHI use and disclosure to the minimum necessary for the intended purpose.

  • Policies should limit access to PHI by workforce members based on their roles.

Designation of Privacy Officer

  • Required in every dental practice to manage privacy policies and procedures.

  • Responsible for handling HIPAA-related complaints and ensuring proper training of staff.

Notice of Privacy Practices

  • Must be provided, detailing:

    • Uses and disclosures of PHI.

    • The Covered Entity’s responsibilities regarding privacy.

    • Individuals' rights under the Privacy Rule.

    • A point of contact for privacy concerns.

Acknowledgement of Receipt

  • Providers must make efforts to obtain written acknowledgment from patients regarding the receipt of the notice.

  • Documentation is required for any failure to obtain such acknowledgment.

Complaints Procedure

  • Covered Entities must have clear procedures for handling complaints about compliance with their privacy policies and the Privacy Rule.

Compliance Penalties

Civil Penalties

  • Civil penalties of $100 per violation, not exceeding $25,000 per year for multiple similar violations.

Criminal Penalties

  • Knowingly violating HIPAA can lead to fines ranging from $50,000 to $250,000, with imprisonment terms also varying from one year to ten years depending on the nature of the violation.

Administrative Requirements

Transactions and Identification Numbers

  • Compliance includes using standardized codes for diagnosing and procedures as specified by HIPAA.

  • Employers and healthcare providers must have standard national identifiers:

    • Employer Identification Number (EIN): Assigned by IRS for employers.

    • National Provider Identifier (NPI): A unique 10-digit number for healthcare providers.

Required Documentation for Compliance

  • Every Covered Entity dental practice must maintain a HIPAA Privacy and Policy Procedure Manual, which must include:

    • Policies on regulation implementation.

    • Documented training protocols.

    • Maintenance of patient electronic records (EHR).

    • Designation of Privacy/Security Officer.

    • Procedures for oral communication.

    • Staff discipline policies for breaches.

Required Administrative Safeguards

  • Initial and periodic risk analyses to assess security.

  • Regular record reviews (audit logs, access reports, etc.).

  • Response protocols for security incidents.

  • Staff training and sanction policies for security violations.

  • Designation of a Security Officer.

  • Access levels based on job requirements.

  • Data backup plans and disaster recovery protocols.

Required Physical Safeguards

  • Limitation of physical access to information systems.

  • Policies ensuring workstation security and proper disposal of electronic media.

Required Technical Safeguards

  • Implementing access controls, audit controls, and authentication processes.

  • Automatic logoff mechanisms and encryption for sensitive data.

Steps Toward Compliance with Privacy and Breach of Security

  • 1: Choose a Privacy Officer.

  • 2: Create, implement, and maintain privacy policies.

  • 3: Write and disclose your Notice of Privacy Practices.

  • 4: List your Designated Record Sets.

  • 5: Adhere to Minimum Necessary Policy:

    • Limit workforce access to patient information.

    • Develop rules for routine disclosures.

  • 6: Verify identity before disclosing information.

  • 7: Understand necessary disclosures.

  • 8: Obtain patient authorization when needed.

  • 9: Do not engage in marketing without authorization.

  • 10: Manage breach notifications appropriately.

Training Requirements

  • Coverage must include HIPAA and HITECH Act training for all personnel.

  • New employees must train within 30 days, with documentation of training kept in the manual.

  • Annual training and updates are required, particularly after complaints or changes.

Compliance with California State Laws

  • State specifics on patient access to records and amendments:

    • Access (5 days), Copies (15 days), Electronic Copies (15 days).

  • Amendments must justify the request, and offices have 60 days to respond.

Data Breach Notification Requirements

  • In case of a breach, required notifications to HHS must be detailed and include:

    • Description of events, patient protection steps, etc.

  • California requirements also dictate specific details for notifications.

Recommendations for Managing Patient Records and Financial Information

  • Avoid storing sensitive financial information on-site.

  • Retain dental records indefinitely but require shredding/disposal after amassing a seven-year period following practice closure.

Conclusion

  • Compliance with HIPAA and HITECH is essential, as violations remain common and penalties are severe.

  • Regular updates and training can ensure that healthcare providers maintain effective privacy and security protocols.