• No results found

HIPAA. Today s Session: 4 Parts. Ministry Principles. Morning Session: o Ministry Principles. o Current Landscape.

N/A
N/A
Protected

Academic year: 2021

Share "HIPAA. Today s Session: 4 Parts. Ministry Principles. Morning Session: o Ministry Principles. o Current Landscape."

Copied!
31
0
0

Loading.... (view fulltext now)

Full text

(1)

HIPAA

What You Need to Know & Do

Today’s Session: 4 Parts

o  Ministry Principles

o  Current Landscape

o  Texting Clients

•  Afternoon Session:

•  Morning Session:

o  How to Use the SRA Tool – Security Risk Assessment

Matthew 10: 1-16

Ministry Principles

(2)

Learning Objectives

•  Know the wolves

•  Be familiar with upcoming changes

•  Understand how changes may impact your organization

The Executive Branch

Joe Biden

President

• Nominate federal judges who support Roe v. Wade

• Reverse Trump administration’s gag rule

• Overturn Trump-era decisions including restrictions on abortion rights • Supports a federal statute legalizing abortion if supreme court

overturns Roe v. Wade

o  Prevents Title X family planning funds for providers that offer abortion referrals

(3)

The Executive Branch

Kamala Harris

Vice President

• Wants to repeal the Hyde Amendment

• NARAL and Emily’s List • Codify Roe v. Wade

o Makes women’s rights to abortion a federal law

• Co-sponsored the Women’s Health Protection Act o States required to get pre-clearance from fed. gov. before

implementing additional abortion-based restriction in states and counties.

Leadership of US Dept. Of Health and Human Services (HHS)

•  Secretary

•  Deputy Secretary

o  part of the President’s executive

branch

(4)

Health & Human Services Nomination Update

Xavier Becerra

Secretary

• 2017 Becerra brought charges against David Daleiden and Sandra Merritt

• 2017 sued Trump administration

o Trump exempted faith-based organization from Obamacare mandate to provide contraceptives – Little Sister of the Poor • Sworn in March 19, 2021

Health & Human Services Nomination Update

Xavier Becerra

Secretary

• 2018 NIFLA vs Becerra

o Reproductive Freedom, Accountability, Comprehensive Care and Transparency Act (FACT)

• 2020 Becerra defended Gov. Newsom’s ban on indoor church services • Oversee the establishment and enforcement of HIPAA & Conscious laws

Health & Human Services Nomination Update

Andrea Palm

Deputy Secretary • Aide to Hillary Clinton • Senior staffer @ HHS

• Intended to appoint Planned Parenthood lobbyist as deputy • Secretary-designee of WI DOH and Human Services • Submitted to US Senate Feb. 22, 2021

• White house policy advisor under Obama administration

(5)

Health & Human Services Nomination Update

Dr. Rachel Levine

Assistant Secretary

• Confirmed March 24, 2021

• PA Physician General and Secretary of PA DOH

• Professor of Pediatrics and Psychiatry at Penn State College of Medicine • Opposed PA HB 1948

o Limits late term abortions

o Restricts dilation and evacuation procedures • Deemed abortion clinics essential services

Health & Human Services Nomination Update

Dr. Rachel Levine

Assistant Secretary

• Public Health Service (PHS) • Provides both strategic and policy direction

Office of the Assistant Secretary for Health Organizational Chart

Dr. Rachel Levine

(6)

Structure of US Dept. Of Health and Human Services (HHS)

Office of

Civil Rights

(OCR)

US Dept. of

Health and

Human

Services

(HHS)

•  Administration

for Children

and Families

•  Centers for

Disease

Control and

Prevention

(CDC)

Health & Human Services Nomination Update

Robinsue Frohboese

• Principal Deputy and Acting Director of OCR • Joined OCR in 2000

• 17 years in Civil Rights Division, US DOJ • Acting director during four administration transitions

• More than 40 years experience in health-related civil rights enforcement and policy

(7)

Dec. 2018

Dec. 2020

What happens AFTER a bill becomes a law?

Sent to Dept. for enforcement/audit/modification

Request for

Information

(RFI)

Interim Final

Rule

(IFR)

Final Rule

(FR)

Notice of

Proposed

Rule Making

(NPRM)

•  Comment period: 45-day extension from March 22

nd

to May 6

th

•  Shortens response time for patient access from 30 days to 15 days

Ø  Only Paper requests, request must be made in person, or limiting

access through an online portal

Ø  18

th

Right of Access case

Ø  One-time 15-day extension

•  Disallows organizations from imposing unreasonable measures to request

access

Notice of Proposed Rule Making (NPRM)

•  Allows individuals access to their PHI free of charge (i.e., a person could copy

PHI using their own device).

Clarifies the minimum necessary standard with respect to care coordination and

case management activities.

Expressly allows covered entities to disclose

PHI to social service agencies and other third parties (i.e., community-based

support programs) that may not themselves be healthcare providers, but that

would provide health-related services to individuals.

Notice of Proposed Rule Making (NPRM)

(8)

Notice of Proposed Rule Making (NPRM)

•  Removes the requirement for a covered entity to obtain a patient's signature

affirming receipt of the Notice of Privacy Practices (NPP).

•  Clarifies and facilitates family and caregiver involvement in the care of

individuals experiencing emergencies or health crises.

•  Compliance likely required within 180 days.

•  Amends the definition of health care operation to permit disclosure of client

information for care coordination and case management.

Is texting my

client a HIPAA

(9)

Learning Objectives

•  Determine if sending PHI via a standard SMS text message

is a HIPAA violation

•  Identify the technical safeguards related to texting

•  Select characteristics of a HIPAA compliant texting application/

platform

Security Rule Safeguards

(10)

Security Rule: Overview of Technical Safeguards

Standards

Technical Safeguards

Implementation Specifications

Required

Addressable

Security Rule: Overview of Technical Safeguards

•  Access Controls •  Audit Controls •  Integrity Controls •  Identity Authentication •  Transmission Security

Standards

Technical Safeguards

Security Rule: Overview of Technical Safeguards

(11)

Standards

Technical Safeguards

•  Access Controls •  Audit Controls •  Integrity Controls •  Identity Authentication •  Transmission Security

Security Rule: Overview of Technical Safeguards

(R) Unique User ID

(R) Emergency Access Procedures

(A) Automatic logoff

(A) Message encryption

Implementation Specifications

Standards

Technical Safeguards

•  Access Controls •  Audit Controls •  Integrity Controls •  Identity Authentication •  Transmission Security

Security Rule: Overview of Technical Safeguards

Record Examine

Standards

Technical Safeguards

•  Access Controls •  Audit Controls •  Integrity Controls •  Identity Authentication •  Transmission Security

Security Rule: Overview of Technical Safeguards

NONE

(12)

Standards

Technical Safeguards

•  Access Controls •  Audit Controls •  Integrity Controls •  Identity Authentication •  Transmission Security

Security Rule: Overview of Technical Safeguards

Not altered Not destroyed

Standards

Technical Safeguards

•  Access Controls •  Audit Controls •  Integrity Controls •  Identity Authentication •  Transmission Security

Security Rule: Overview of Technical Safeguards

(A) Mechanism to authentiacate ePHI

Implementation Specifications

Standards

Technical Safeguards

•  Access Controls •  Audit Controls •  Integrity Controls •  Identity Authentication •  Transmission Security

Security Rule: Overview of Technical Safeguards

Username

Password

PIN

(13)

Standards

Technical Safeguards

•  Access Controls •  Audit Controls •  Integrity Controls •  Identity Authentication •  Transmission Security

Security Rule: Overview of Technical Safeguards

Implementation Specifications

NONE

Standards

Technical Safeguards

•  Access Controls •  Audit Controls •  Integrity Controls •  Identity Authentication •  Transmission Security

Security Rule: Overview of Technical Safeguards

Unauthorized Access

Transmitted

Electronic communication network

Standards

Technical Safeguards

•  Access Controls •  Audit Controls •  Integrity Controls •  Identity Authentication •  Transmission Security

Security Rule: Overview of Technical Safeguards

(A) Integrity controls

(A) Encryption

(14)
(15)

Learning Objectives

•  Know how/where to download SRA tool

•  Install SRA tool

•  Set up SRA tool for your organization

•  Know the sections of the SRA Tool

•  Become familiar with SRA tool reports

(16)
(17)
(18)
(19)
(20)
(21)
(22)
(23)

Security Rule: Overview of Technical Safeguards

Standards

Technical Safeguards

Implementation Specifications

(24)

YES

NO

I DON’T KNOW

FLAG THIS QUESTION FOR

LATER

Q2. Do you review and update your SRA?

(25)

Q2. Do you review and update your security documentation, including policies and procedures? Q4. Is the security officer involved in all security policy and procedure updates? Q6. How long are information security management and risk management documents kept: Q7. Do you make sure that information security and risk management documentation is available to those who need it?

(26)

Q2. Do you identify and document the role and responsibilities of the security officer? Q8. Do you screen you workforce members to verify trustworthiness?

Q10. Do you ensure that all workforce members (including management) are given security training? Q13. Are procedures in place for monitoring log-in attempts and reporting discrepancies? Q15. What password security elements are covered in your security training?

Q16. Do you ensure workforce members maintain ongoing awareness of security requirements? Q18. Do you have a sanction policy to enforce security procedures?

Q4. How much access to ePHI is granted to users or other entities? Q5. How are individual users identified when accessing ePHI? Q8. Do you use encryption to control access to ePHI? Q10. Do you use alternative safeguards in place of encryption?

Q17. Do you use security settings and mechanisms to record an examine system activity? Q21. Do you ensure users accessing ePHI are who they claim to be?

Q27. Have you implemented mechanisms to record activity on information systems which create or use ePHI?

Q15. What requirement are in place for retention of audit reports?

Q17. How do you maintain awareness of the movement of electronic devices and media? Q18. Are electronic devices secured?

Q7. Do you keep an inventory and location record of all of its electronic devices? Q4. Do you manage workforce member, visitor, and third party access to electronic devices?

Q10. How do you validate a person’s access to your facility?

(27)

Q4. How does your practice enforce or monitor access for each of these business associates? Q7. How do you maintain awareness of business associate security practices? (e.g. in addition to Business Associate Agreements)

Q9. What terms are in your BAA’s to outline how your business associates ensure subcontractors access ePHI securely?

Q11. Have you updated all your BAA’s to reflect the requirements in the 2013 Omnibus updates to HIPAA? Q12. How does your practice document all of its business associates requiring access to ePHI?

Q2. Is your contingency plan documented?

Q4. How do you ensure that your contingency plan is effective and updated appropriately? Q8. Does your practice have policies and procedures in place to prevent, detect, and respond to security incidents?

Q9. How does your practice prevent, detect, and respond to security incidents? Q15. Do you have a plan for backing up and restoring critical data?

(28)

Percent of responses sorted into “Areas for Review” across the whole assessment.

(29)
(30)

•  Know how/where to download SRA tool

o  Learning Is Created.com

o  Click ‘Free HIPAA Resources’

o  Click to download the free tool

o  Scroll down further to download SRA Tool user guide

•  Install the SRA Tool

o  Click the downloaded executable file

Summary

o  Assessment – Sections 1 - 7

o  Summary – Risk/Detailed/Flagged Reports

•  Know the sections of the SRA Tool

o  Home – Welcome/definition/steps

o  Practice Information – Demographic/Assets/Documents

Summary

•  Set up SRA tool for your organization

o  Fill in demographic information for your organization

ü  Assets

Ø  One at a time or bulk upload via template

ü  Business Associates

Ø  One at a time or bulk upload via template

ü  Supporting Documentation

(31)

Summary

•  Become familiar with SRA tool reports

o  Risk report is a summary

o  Detailed report:

ü  Breaks down each section:

ü  Site demographics

ü  Asset Information

ü  Business Associates and vendors list

o  Flagged Report provides a list of all questions flagged for later

“I would have despaired unless I had believed that I

would see the goodness of the LORD in the land of the

living.”

References

Related documents