A Process for Gathering Information Pertaining to a Hipaa Compliance Audit Assessment Questions
Autor: ajones64 • December 10, 2015 • Coursework • 1,460 Words (6 Pages) • 2,018 Views
Page 1 of 6
Define a Process for Gathering Information Pertaining to a HIPAA Compliance Audit
Assessment Questions
- What are four parts of the administrative simplification requirements of HIPAA?
- Electronic transaction and code sets standards requirements
- Privacy requirements
- Security requirements
- National identifier requirements
- Name 3 factors used to determine whether you need to comply with HIPAA.
- Whether the health plan is self-insured or fully insured
- Whether the plan sponsor receives PHI or SHI
- How the plan sponsor utilizes SHI.
- What are the three categories of entities affected by HIPAA Medical Privacy Regulations?
- Health Care Providers: Any provider of medical or other health services, or supplies, who transmits any health information in electronic form in connection with a transaction for which standard requirements have been adopted.
- Health Plans: Any individual or group plan that provides or pays the cost of health care.
- Health Care Clearinghouses: A public or private entity that transforms health care transactions from one format to another.
- What would Business Associates of covered entities consist of as it pertains to HIPAA’s regulation?
- HIPAA defines a business associate as an individual or corporate "person" that: performs on behalf of the covered entity any function or activity involving the use or disclosure of protected health information (PHI); and is not a member of the covered entity's workforce.
- Who is covered by the Privacy Rule in HPAA? Give some examples.
- Health care providers who transmit any health information electronically in connection with certain transactions.
- Health plans
- Healthcare Clearinghouse - Covered entities are defined in the HIPAA rules as (1) health plans, (2) health care clearinghouses, and (3) health care providers who electronically transmit any health information in connection with transactions for which HHS has adopted standards.
- What information is protected in HIPAA?
- Healthcare claims or equivalent encounter information
- Healthcare payment and remittance advice
- Coordination or benefits
- Healthcare claim status
- Enrollment or disenrollment in a health plan
- Eligibility for a health plan
- Health plan premium payments
- Referral certification and authorization
- Describe the Basic Principle and Required Disclosures of HIPAA.
- The basic principle of the HIPAA Privacy Rule is that a covered entity may not use or disclose protected health information, except when the Privacy Rule explicitly permits it or the individual subject of the information authorizes it.
- The HIPAA Privacy Rule does not require the disclosure of health information, except in two instances:
- To the individual subject to the information.
- To HHS when conducting a compliance investigation.
- Is a health information organization (HIO) covered by the HIPAA Privacy Rule?
- Generally, no. The HIPAA Privacy Rule applies to health plans, health care clearinghouses, and health care providers that conduct covered transactions. The functions a HIO typically performs do not make it a health plan, health care clearinghouse, or covered health care provider. Thus, a HIO is generally not a HIPAA covered entity. However, a HIO that performs certain functions or activities on behalf of, or provides certain services to, a covered entity which require access to PHI would be a business associate under the Privacy Rule. See 45 C.F.R. § 160.103 (definition of “business associate”). HIPAA covered entities must enter into contracts or other agreements with their business associates that require the business associates to safeguard and appropriately protect the privacy of protected health information. See 45 C.F.R. §§ 164.502(e), 164.504(e). (See also the relevant business associate requirements in the HIPAA Security Rule at 45 C.F.R. §§ 164.308(b), 164.314(a).) For instance, a HIO that manages the exchange of PHI through a network on behalf of multiple covered health care providers is a business associate of the covered providers, and thus, one or more business associate agreements would need to be in place between the covered providers and the HIO.
- Does the HIPAA Privacy Rule inhibit electronic health information exchange across different states or jurisdictions?
- No. The Privacy Rule establishes a federal baseline of privacy protections and rights, which applies to covered entities consistently across state borders. The Privacy Rule, however, as required by HIPAA, does not preempt State laws that provide greater privacy protections and rights. Thus, as with covered entities that conduct business today on paper in a multi-jurisdictional environment, covered entities participating in electronic health information exchange need to be cognizant of States with more stringent privacy laws that will affect the exchange of electronic health information across State lines. In addition, other Federal laws also may apply more stringent or different requirements to such exchanges depending on the circumstances. Covered entities and health information organizations (acting as their business associates) which participate in multi-jurisdictional electronic health information exchange should establish privacy policies for the network that accommodate these variances.
- How should a covered entity respond to any HIPAA Privacy Rule violation of a health information organization (HIO) acting as its business associate?
- The Privacy Rule establishes a series of steps a covered entity should take in response to any complaints or other evidence it receives that a HIO has violated its business associate agreement, which include the following:
- Investigation of any complaint received, as well as of other information containing credible evidence of a violation;
- Reasonable steps to cure/end any material breaches or violations it becomes aware of;
- Termination of the agreement where attempts to cure a material breach are unsuccessful;
- In the event termination of the agreement is not feasible, the report of violation(s) to the Secretary of HHS, through OCR. See 45 C.F.R. § 164.504(e).
- True or False. As a patient, your doctor must have you sign a HIPAA Consent and Release Form to share your ePHI or PHI with insurance providers who pay for your medical bills. This is part of the HIPAA Privacy Rule.
- True
- After consent and permission is provided by the patient to the medical practice or covered entity, what agreement is needed between the medical practice and its downstream medical insurance claims processor or downstream medical specialist that requires the patient’s ePHI?
- Not use or further disclose the information other than as permitted or required by the contract or as required by law;
- Use appropriate safeguards to prevent use or disclosure of the information other than as provided for by its contract;
- Report to the covered entity any use or disclosure of the information not provided for by its contract of which it becomes aware;
- Ensure that any agents, including a subcontractor, to whom it provides, protected health information received from, or created or received by the business associate on behalf of, the covered entity agrees to the same restrictions and conditions that apply to the business associate with respect to such information.
- Why is security awareness training for all employees within a healthcare organization a major component of HIPAA compliance?
- The HIPAA privacy and security rules require formal education and training of the workforce to ensure ongoing accountability for privacy and security of protected health information (PHI). HIPAA's privacy and security rules independently address training requirements. Like most standards, the training requirements are non-prescriptive, giving organizations flexibility in implementation.
- Under the HIPAA Security Rule, it is a requirement for a healthcare organization to have a security incident response plan and team to handle potential security incidents and breaches. Why is this a requirement?
- The main goal of the HIPAA Security Rule is to protect the confidentiality, integrity and availability of electronic protected health information (EPHI).
- Confidentiality is the “property that data or information is not made available or disclosed to unauthorized persons or processes.”
- Integrity is the “property that data or information has not been altered or destroyed in an unauthorized manner.”
- Availability is “the property that data or information is accessible and usable upon demand by an authorized person.”
- True or False. It is a requirement for a healthcare organization to secure the transmission of ePHI through the public Internet.
- False
...