HIPAA and HITECH Study Notes
INTRODUCTION AND REVIEW - PART F: HIPAA AND HITECH
Overview of HIPAA
The Health Insurance Portability and Accountability Act (HIPAA) was enacted in 1996.
Oversight of HIPAA is assigned to the U.S. Department of Health and Human Services (HHS).
Its regulations are focused on:
Ensuring privacy and security of patient health information.
Standardizing healthcare transactions.
Assigning administrative identifiers for health care providers.
Enforcing compliance with these regulations.
Overview of HITECH
The Health Information Technology for Economic and Clinical Health Act (HITECH Act) was enacted in 2009.
It is part of the American Recovery and Reinvestment Act.
Modifications under HITECH include:
Changes to HIPAA Privacy and Security Rules.
Standards for Current Dental Terminology (CDT) procedure codes.
New Breach Notification Rules.
Transition from Paper to Electronic Systems
Prior to HIPAA, there were no universally accepted security standards for protecting health information.
The healthcare industry began transitioning to electronic information systems for:
Claims processing.
Eligibility inquiries.
Health information provision.
Other administrative functions.
Current technologies include:
Computerized Physician Order Entry (CPOE) systems.
Electronic Health Records (EHR).
Systems for radiology, pharmacy, and laboratory functions.
Increased use of technology enhances mobility and efficiency but also raises security risks.
Goals of the HIPAA Security Rule
Protect individual health information privacy.
Facilitate the adoption of new technologies to improve patient care.
The Security Rule is designed to be flexible and scalable based on the organization’s size, structure, and risk environment.
Key Acronyms and Definitions
HIPAA: Health Insurance Portability and Accountability Act
HITECH Act: Health Information Technology for Economic and Clinical Health Act
OCR: Office for Civil Rights
CDT: Current Dental Terminology (procedure codes)
NPI: National Provider Identification, a unique 10-digit identifier.
PHI: Protected Health Information, encompassing health details, billing information, and personal data.
ePHI: Electronic Protected Health Information
TPO: Treatment, Payment, and Operations
BA: Business Associate
HHS: Health and Human Services department overseeing HIPAA compliance.
Key Definitions
Covered Entity
All healthcare providers who electronically transmit health information for specific transactions are considered Covered Entities.
Transactions include:
Claims processing.
Benefit eligibility inquiries.
Referral authorization requests.
Covered Entities include institutional providers (hospitals) and non-institutional providers (physicians, dentists).
Business Associates
A business associate is an entity that performs functions for or services to a Covered Entity and may access PHI.
Examples include:
Claims processing.
Data analysis.
Billing.
Business associates are not considered as such if their access to PHI is merely incidental.
Business Associates Grant Requirements
When engaging a contractor as a business associate, the Covered Entity must ensure:
Specific protections for the information in a business associate agreement.
Business associates cannot use PHI in ways that violate HIPAA.
Protecting Health Information
The Privacy Rule safeguards all individually identifiable health information held by a Covered Entity or its associates regardless of format (electronic, paper, or oral).
Individually identifiable health information includes:
Demographic data.
Information pertaining to health conditions, treatments, or payment.
Covered entities can only use/disclose PHI as permitted by the Privacy Rule or with the individual's consent.
Security Rule Requirements
Fundamental Elements for Security
Confidentiality: Ensure that PHI is not disclosed to unauthorized persons.
Integrity: Protect information from being altered or destroyed by unauthorized individuals.
Availability: Ensure that authorized individuals can access and use the information when needed.
Standards of Compliance
Compliance is categorized into:
Administrative Safeguards: Documented practices for selecting and implementing security measures.
Physical Safeguards: Security measures to control physical access to systems.
Technical Safeguards: Measures to protect and monitor electronic access to systems.
Compliance standards include required and addressable specifications:
Required: Must be implemented.
Addressable: Should be implemented based on risk analysis.
Required Disclosures
Obligatory Disclosures
A Covered Entity must disclose PHI to:
Individuals requesting access to their PHI.
HHS during compliance investigations.
Permitted Uses and Disclosures
Covered Entities may use or disclose PHI without individual authorization in various circumstances:
Disclosures to individuals upon written request.
For treatment, payment, and operations (TPO).
Opportunity for informal consent or objection.
Incidental disclosures may occur when reasonable safeguards are in place.
Public interest and benefit activities (e.g., legal actions requiring access to records).
Patient Authorization Requirements
Required for any disclosures not falling under the TPO scope.
Specific wording is necessary for the authorization, which may include disclosures to third parties like insurance companies.
Minimum Necessary Principle
Covered Entities must limit PHI use and disclosure to the minimum necessary for the intended purpose.
Policies should limit access to PHI by workforce members based on their roles.
Designation of Privacy Officer
Required in every dental practice to manage privacy policies and procedures.
Responsible for handling HIPAA-related complaints and ensuring proper training of staff.
Notice of Privacy Practices
Must be provided, detailing:
Uses and disclosures of PHI.
The Covered Entity’s responsibilities regarding privacy.
Individuals' rights under the Privacy Rule.
A point of contact for privacy concerns.
Acknowledgement of Receipt
Providers must make efforts to obtain written acknowledgment from patients regarding the receipt of the notice.
Documentation is required for any failure to obtain such acknowledgment.
Complaints Procedure
Covered Entities must have clear procedures for handling complaints about compliance with their privacy policies and the Privacy Rule.
Compliance Penalties
Civil Penalties
Civil penalties of $100 per violation, not exceeding $25,000 per year for multiple similar violations.
Criminal Penalties
Knowingly violating HIPAA can lead to fines ranging from $50,000 to $250,000, with imprisonment terms also varying from one year to ten years depending on the nature of the violation.
Administrative Requirements
Transactions and Identification Numbers
Compliance includes using standardized codes for diagnosing and procedures as specified by HIPAA.
Employers and healthcare providers must have standard national identifiers:
Employer Identification Number (EIN): Assigned by IRS for employers.
National Provider Identifier (NPI): A unique 10-digit number for healthcare providers.
Required Documentation for Compliance
Every Covered Entity dental practice must maintain a HIPAA Privacy and Policy Procedure Manual, which must include:
Policies on regulation implementation.
Documented training protocols.
Maintenance of patient electronic records (EHR).
Designation of Privacy/Security Officer.
Procedures for oral communication.
Staff discipline policies for breaches.
Required Administrative Safeguards
Initial and periodic risk analyses to assess security.
Regular record reviews (audit logs, access reports, etc.).
Response protocols for security incidents.
Staff training and sanction policies for security violations.
Designation of a Security Officer.
Access levels based on job requirements.
Data backup plans and disaster recovery protocols.
Required Physical Safeguards
Limitation of physical access to information systems.
Policies ensuring workstation security and proper disposal of electronic media.
Required Technical Safeguards
Implementing access controls, audit controls, and authentication processes.
Automatic logoff mechanisms and encryption for sensitive data.
Steps Toward Compliance with Privacy and Breach of Security
1: Choose a Privacy Officer.
2: Create, implement, and maintain privacy policies.
3: Write and disclose your Notice of Privacy Practices.
4: List your Designated Record Sets.
5: Adhere to Minimum Necessary Policy:
Limit workforce access to patient information.
Develop rules for routine disclosures.
6: Verify identity before disclosing information.
7: Understand necessary disclosures.
8: Obtain patient authorization when needed.
9: Do not engage in marketing without authorization.
10: Manage breach notifications appropriately.
Training Requirements
Coverage must include HIPAA and HITECH Act training for all personnel.
New employees must train within 30 days, with documentation of training kept in the manual.
Annual training and updates are required, particularly after complaints or changes.
Compliance with California State Laws
State specifics on patient access to records and amendments:
Access (5 days), Copies (15 days), Electronic Copies (15 days).
Amendments must justify the request, and offices have 60 days to respond.
Data Breach Notification Requirements
In case of a breach, required notifications to HHS must be detailed and include:
Description of events, patient protection steps, etc.
California requirements also dictate specific details for notifications.
Recommendations for Managing Patient Records and Financial Information
Avoid storing sensitive financial information on-site.
Retain dental records indefinitely but require shredding/disposal after amassing a seven-year period following practice closure.
Conclusion
Compliance with HIPAA and HITECH is essential, as violations remain common and penalties are severe.
Regular updates and training can ensure that healthcare providers maintain effective privacy and security protocols.