HIPAA
What You Need to Know & Do
Today’s Session: 4 Parts
o Ministry Principles
o Current Landscape
o Texting Clients
• Afternoon Session:
• Morning Session:
o How to Use the SRA Tool – Security Risk Assessment
Matthew 10: 1-16
Ministry Principles
Learning Objectives
• Know the wolves
• Be familiar with upcoming changes
• Understand how changes may impact your organization
The Executive Branch
Joe Biden
President
• Nominate federal judges who support Roe v. Wade
• Reverse Trump administration’s gag rule
• Overturn Trump-era decisions including restrictions on abortion rights • Supports a federal statute legalizing abortion if supreme court
overturns Roe v. Wade
o Prevents Title X family planning funds for providers that offer abortion referrals
The Executive Branch
Kamala Harris
Vice President
• Wants to repeal the Hyde Amendment
• NARAL and Emily’s List • Codify Roe v. Wade
o Makes women’s rights to abortion a federal law
• Co-sponsored the Women’s Health Protection Act o States required to get pre-clearance from fed. gov. before
implementing additional abortion-based restriction in states and counties.
Leadership of US Dept. Of Health and Human Services (HHS)
• Secretary
• Deputy Secretary
o part of the President’s executive
branch
Health & Human Services Nomination Update
Xavier Becerra
Secretary
• 2017 Becerra brought charges against David Daleiden and Sandra Merritt
• 2017 sued Trump administration
o Trump exempted faith-based organization from Obamacare mandate to provide contraceptives – Little Sister of the Poor • Sworn in March 19, 2021
Health & Human Services Nomination Update
Xavier Becerra
Secretary
• 2018 NIFLA vs Becerra
o Reproductive Freedom, Accountability, Comprehensive Care and Transparency Act (FACT)
• 2020 Becerra defended Gov. Newsom’s ban on indoor church services • Oversee the establishment and enforcement of HIPAA & Conscious laws
Health & Human Services Nomination Update
Andrea Palm
Deputy Secretary • Aide to Hillary Clinton • Senior staffer @ HHS
• Intended to appoint Planned Parenthood lobbyist as deputy • Secretary-designee of WI DOH and Human Services • Submitted to US Senate Feb. 22, 2021
• White house policy advisor under Obama administration
Health & Human Services Nomination Update
Dr. Rachel Levine
Assistant Secretary
• Confirmed March 24, 2021
• PA Physician General and Secretary of PA DOH
• Professor of Pediatrics and Psychiatry at Penn State College of Medicine • Opposed PA HB 1948
o Limits late term abortions
o Restricts dilation and evacuation procedures • Deemed abortion clinics essential services
Health & Human Services Nomination Update
Dr. Rachel Levine
Assistant Secretary
• Public Health Service (PHS) • Provides both strategic and policy direction
Office of the Assistant Secretary for Health Organizational Chart
Dr. Rachel Levine
Structure of US Dept. Of Health and Human Services (HHS)
Office of
Civil Rights
(OCR)
US Dept. of
Health and
Human
Services
(HHS)
• Administration
for Children
and Families
• Centers for
Disease
Control and
Prevention
(CDC)
Health & Human Services Nomination Update
Robinsue Frohboese
• Principal Deputy and Acting Director of OCR • Joined OCR in 2000
• 17 years in Civil Rights Division, US DOJ • Acting director during four administration transitions
• More than 40 years experience in health-related civil rights enforcement and policy
Dec. 2018
Dec. 2020
What happens AFTER a bill becomes a law?
Sent to Dept. for enforcement/audit/modification
Request for
Information
(RFI)
Interim Final
Rule
(IFR)
Final Rule
(FR)
Notice of
Proposed
Rule Making
(NPRM)
• Comment period: 45-day extension from March 22
ndto May 6
th• Shortens response time for patient access from 30 days to 15 days
Ø Only Paper requests, request must be made in person, or limiting
access through an online portal
Ø 18
thRight of Access case
Ø One-time 15-day extension
• Disallows organizations from imposing unreasonable measures to request
access
Notice of Proposed Rule Making (NPRM)
• Allows individuals access to their PHI free of charge (i.e., a person could copy
PHI using their own device).
•
Clarifies the minimum necessary standard with respect to care coordination and
case management activities.
Expressly allows covered entities to disclose
PHI to social service agencies and other third parties (i.e., community-based
support programs) that may not themselves be healthcare providers, but that
would provide health-related services to individuals.
Notice of Proposed Rule Making (NPRM)
Notice of Proposed Rule Making (NPRM)
• Removes the requirement for a covered entity to obtain a patient's signature
affirming receipt of the Notice of Privacy Practices (NPP).
• Clarifies and facilitates family and caregiver involvement in the care of
individuals experiencing emergencies or health crises.
• Compliance likely required within 180 days.
• Amends the definition of health care operation to permit disclosure of client
information for care coordination and case management.
Is texting my
client a HIPAA
Learning Objectives
• Determine if sending PHI via a standard SMS text message
is a HIPAA violation
• Identify the technical safeguards related to texting
• Select characteristics of a HIPAA compliant texting application/
platform
Security Rule Safeguards
Security Rule: Overview of Technical Safeguards
Standards
Technical Safeguards
Implementation Specifications
Required
Addressable
Security Rule: Overview of Technical Safeguards
• Access Controls • Audit Controls • Integrity Controls • Identity Authentication • Transmission Security
Standards
Technical Safeguards
Security Rule: Overview of Technical Safeguards
Standards
Technical Safeguards
• Access Controls • Audit Controls • Integrity Controls • Identity Authentication • Transmission SecuritySecurity Rule: Overview of Technical Safeguards
(R) Unique User ID
(R) Emergency Access Procedures
(A) Automatic logoff
(A) Message encryption
Implementation Specifications
Standards
Technical Safeguards
• Access Controls • Audit Controls • Integrity Controls • Identity Authentication • Transmission SecuritySecurity Rule: Overview of Technical Safeguards
Record Examine
Standards
Technical Safeguards
• Access Controls • Audit Controls • Integrity Controls • Identity Authentication • Transmission SecuritySecurity Rule: Overview of Technical Safeguards
NONE
Standards
Technical Safeguards
• Access Controls • Audit Controls • Integrity Controls • Identity Authentication • Transmission SecuritySecurity Rule: Overview of Technical Safeguards
Not altered Not destroyed
Standards
Technical Safeguards
• Access Controls • Audit Controls • Integrity Controls • Identity Authentication • Transmission SecuritySecurity Rule: Overview of Technical Safeguards
(A) Mechanism to authentiacate ePHI
Implementation Specifications
Standards
Technical Safeguards
• Access Controls • Audit Controls • Integrity Controls • Identity Authentication • Transmission SecuritySecurity Rule: Overview of Technical Safeguards
Username
Password
PIN
Standards
Technical Safeguards
• Access Controls • Audit Controls • Integrity Controls • Identity Authentication • Transmission SecuritySecurity Rule: Overview of Technical Safeguards
Implementation Specifications
NONE
Standards
Technical Safeguards
• Access Controls • Audit Controls • Integrity Controls • Identity Authentication • Transmission SecuritySecurity Rule: Overview of Technical Safeguards
Unauthorized Access
Transmitted
Electronic communication network
Standards
Technical Safeguards
• Access Controls • Audit Controls • Integrity Controls • Identity Authentication • Transmission SecuritySecurity Rule: Overview of Technical Safeguards
(A) Integrity controls
(A) Encryption
Learning Objectives
• Know how/where to download SRA tool
• Install SRA tool
• Set up SRA tool for your organization
• Know the sections of the SRA Tool
• Become familiar with SRA tool reports
Security Rule: Overview of Technical Safeguards
Standards
Technical Safeguards
Implementation Specifications
YES
NO
I DON’T KNOW
FLAG THIS QUESTION FOR
LATER
Q2. Do you review and update your SRA?
Q2. Do you review and update your security documentation, including policies and procedures? Q4. Is the security officer involved in all security policy and procedure updates? Q6. How long are information security management and risk management documents kept: Q7. Do you make sure that information security and risk management documentation is available to those who need it?
Q2. Do you identify and document the role and responsibilities of the security officer? Q8. Do you screen you workforce members to verify trustworthiness?
Q10. Do you ensure that all workforce members (including management) are given security training? Q13. Are procedures in place for monitoring log-in attempts and reporting discrepancies? Q15. What password security elements are covered in your security training?
Q16. Do you ensure workforce members maintain ongoing awareness of security requirements? Q18. Do you have a sanction policy to enforce security procedures?
Q4. How much access to ePHI is granted to users or other entities? Q5. How are individual users identified when accessing ePHI? Q8. Do you use encryption to control access to ePHI? Q10. Do you use alternative safeguards in place of encryption?
Q17. Do you use security settings and mechanisms to record an examine system activity? Q21. Do you ensure users accessing ePHI are who they claim to be?
Q27. Have you implemented mechanisms to record activity on information systems which create or use ePHI?
Q15. What requirement are in place for retention of audit reports?
Q17. How do you maintain awareness of the movement of electronic devices and media? Q18. Are electronic devices secured?
Q7. Do you keep an inventory and location record of all of its electronic devices? Q4. Do you manage workforce member, visitor, and third party access to electronic devices?
Q10. How do you validate a person’s access to your facility?
Q4. How does your practice enforce or monitor access for each of these business associates? Q7. How do you maintain awareness of business associate security practices? (e.g. in addition to Business Associate Agreements)
Q9. What terms are in your BAA’s to outline how your business associates ensure subcontractors access ePHI securely?
Q11. Have you updated all your BAA’s to reflect the requirements in the 2013 Omnibus updates to HIPAA? Q12. How does your practice document all of its business associates requiring access to ePHI?
Q2. Is your contingency plan documented?
Q4. How do you ensure that your contingency plan is effective and updated appropriately? Q8. Does your practice have policies and procedures in place to prevent, detect, and respond to security incidents?
Q9. How does your practice prevent, detect, and respond to security incidents? Q15. Do you have a plan for backing up and restoring critical data?
Percent of responses sorted into “Areas for Review” across the whole assessment.