Health Information System

profileHelpm31990
Chapter021.ppt

CHAPTER

© 2012 The McGraw-Hill Companies, Inc. All rights reserved.

McGraw-Hill

2

HIPAA, HITECH, and Medical Records

*

© 2012 The McGraw-Hill Companies, Inc. All rights reserved.

Learning Outcomes

When you finish this chapter, you will be able to:

2.1 List several legal uses of a patient’s medical record.

2.2 Define HIPAA and HITECH, and name the three types of covered entities that must comply with them.

2.3 Discuss how the HIPAA Privacy Rule protects patients’ protected health information (PHI).

2.4 Discuss how the HIPAA Security Rule protects electronic protected health information (ePHI).

2.5 Explain the purpose of the HITECH breach notification rule.

2-2

*

© 2012 The McGraw-Hill Companies, Inc. All rights reserved.

Learning Outcomes (Continued)

When you finish this chapter, you will be able to:

2.6 State the goal of the HIPAA Electronic Health Care Transactions and Code Sets (TCS) standards and list the HIPAA transactions and code sets standards that will be required in the future.

2.7 Discuss some of the most common threats to the privacy and security of electronic information and ways in which the HITECH Act addresses them.

2.8 Define fraud and abuse in health care and cite an example of each.

2-3

*

© 2012 The McGraw-Hill Companies, Inc. All rights reserved.

Learning Outcomes (Continued)

When you finish this chapter, you will be able to:

2.9 Describe the various government agencies that are responsible for enforcing HIPAA.

2.10 Identify the parts of a compliance plan and the types of documentation used to demonstrate compliance.

2-4

*

© 2012 The McGraw-Hill Companies, Inc. All rights reserved.

Key Terms

  • abuse
  • Acknowledgment of Receipt of Notice of Privacy Practices
  • ASC X12 Version 5010
  • audit
  • breach
  • breach notification
  • business associate
  • Centers for Medicare and Medicaid Services (CMS)

2-5

  • clearinghouse
  • code set
  • covered entity
  • electronic data interchange (EDI)
  • electronic protected health information (ePHI)
  • encryption
  • fraud
  • Health Care Fraud and Abuse Control Program

Teaching Notes: There are a lot of key terms, but many of them might already be familiar to your students. Give a pop quiz of the terms to see how many your students know. The quiz could be multiple-choice, matching, or simply a list of the terms with blanks where the students can write definitions. Grade the quiz in class and use the results to focus your lecture on the terms that most or all of the students missed.

*

© 2012 The McGraw-Hill Companies, Inc. All rights reserved.

Key Terms (Continued)

  • Health Information Technology for Economic and Clinical Health (HITECH) Act
  • HIPAA Electronic Health Care Transactions and Code Sets (TCS)
  • HIPAA National Identifiers
  • HIPAA Privacy Rule
  • HIPAA Security Rule

2-6

National Provider Identifier (NPI)

Notice of Privacy Practices (NPP)

protected health information (PHI)

release of information (ROI)

treatment, payment, and health care operations (TPO)

Teaching Notes: See notes on Slide 5.

*

© 2012 The McGraw-Hill Companies, Inc. All rights reserved.

2.1 The Legal Medical Record

2-7

Medical records serve legal purposes, such as:

  • providing a physician with defense against accusations that patients were not treated correctly,
  • providing appropriate documentation,
  • proving medical necessity,
  • proving medical professional liability was met.

Learning Outcome: 2.1 List several legal uses of a patient’s medical record.

Teaching Notes: Stress to students that the legal status of medical records is one of the reasons why documentation and accurate record keeping is CRITICAL in a medical office or practice. Even with electronic health records making data easier to maintain, training and responsibility are key for any health care professional.

*

© 2012 The McGraw-Hill Companies, Inc. All rights reserved.

2.2 Health Care Regulation

2-8

  • Centers for Medicare and Medicaid Services (CMS)—federal agency in the Department of Health and Human Services that runs Medicare, Medicaid, clinical laboratories, and other government health programs; responsible for enforcing all HIPAA standards other than the privacy and security standards
  • Electronic data interchange (EDI)—computer-to-computer exchange of routine business information using publicly available electronic standards

Learning Outcome: 2.2 Define HIPAA and HITECH, and name the three types of covered entities that must comply with them.

Teaching Notes: CMS helps to ensure the quality of healthcare by regulating all lab testing (other than research) performed on humans, preventing discrimination based on health status for people buying health insurance, researching the effectiveness of health care management, and evaluating the quality of facilities and services.

Discuss with students the benefits and drawbacks of using an EDI. Stress that the transactions exchanged within an EDI are not visible; they happen behind the scenes, so to speak. Direct students to the example on page 55 of the textbook that compares EDI transactions to what happens when someone makes an ATM withdrawal.

*

© 2012 The McGraw-Hill Companies, Inc. All rights reserved.

2.2 Health Care Regulation (Continued)

2-9

  • HIPAA is a law designed to:
  • ensure the security and privacy of health information,
  • ensure the portability of employer-provided health insurance coverage for workers and their families when they change or lose their jobs,
  • increase accountability and decrease fraud and abuse in health care, and
  • improve the efficiency of health care delivery by creating standards for electronic transmission of health care transactions.

Learning Outcome: 2.2 Define HIPAA and HITECH, and name the three types of covered entities that must comply with them.

Teaching Notes: Present various scenarios and ask students whether or not HIPAA was violated in each one. Examples might include two nurses talking about a patient in an elevator, a receptionist complying with a patient’s request to see his medical chart, a patient’s aunt asking to see her niece’s chart and the receptionist declining.

*

© 2012 The McGraw-Hill Companies, Inc. All rights reserved.

2.2 Health Care Regulation (Continued)

2-10

  • Health Information Technology for Economic and Clinical Health (HITECH) Act—provisions in the ARRA of 2009 that extend and reinforce HIPAA and contain new breach notification requirements for covered entities and business associates, guidance on ways to encrypt or destroy PHI to prevent a breach, requirements for informing individuals when a breach occurs, higher monetary penalties for HIPAA violations, and stronger enforcement of the Privacy and Security Rules

Learning Outcome: 2.2 Define HIPAA and HITECH, and name the three types of covered entities that must comply with them.

Teaching Notes: As an in-class or homework assignment, have students research breaches of health information that occurred prior to the enactment of HITECH. Ask them to write a short paper summarizing what they learned and whether the breaches they wrote about could have been prevented if a provision like HITECH had been in place.

Discuss with students why they believe a protective act like HITECH was not enacted sooner.

*

© 2012 The McGraw-Hill Companies, Inc. All rights reserved.

2.2 Health Care Regulation (Continued)

2-11

  • Covered entity—under HIPAA, a health plan, clearinghouse, or provider who transmits any health information in electronic form in connection with a HIPAA transaction
  • Clearinghouse—a company that processes electronic health information and executes electronic transactions for providers
  • Business associate—a person or organization that requires access to PHI to perform a function or activity on behalf of a covered entity but is not part of its workforce

Learning Outcome: 2.2 Define HIPAA and HITECH, and name the three types of covered entities that must comply with them.

Teaching Notes: Direct students to the bulleted list in their textbook (page 57) that shows the various groups and organizations that are considered “business associates” under HIPAA; point out that “temporary office personnel” are on the list. No one in an office is exempt from knowing and applying HIPAA statutes.

*

© 2012 The McGraw-Hill Companies, Inc. All rights reserved.

2.3 HIPAA Privacy Rule

2-12

  • HIPAA Privacy Rule—law that regulates the use and disclosure of patients’ protected health information
  • Protected health information (PHI)—individually identifiable health information transmitted or maintained by electronic media or in any other form or medium
  • The minimum necessary standard means using reasonable safeguards to protect PHI from being accidentally released to those not needing the information during an appropriate use or disclosure.

Learning Outcome: 2.3 Discuss how the HIPAA Privacy Rule protects patients’ protected health information (PHI).

Teaching Notes: Reference Table 2.1 in the textbook, which lists information considered PHI. Ask students if anything on the list surprises them or if they think anything is missing.

Discuss with students what might happen if each item on the list was NOT protected. Some items are easier to understand than others. The social security number, for example, makes sense, but items like photographic images or voiceprints might be a little more difficult to understand at first glance.

*

© 2012 The McGraw-Hill Companies, Inc. All rights reserved.

2.3 HIPAA Privacy Rule (Continued)

2-13

  • Notice of Privacy Practices (NPP)—HIPAA-mandated document stating the privacy policies and procedures of a covered entity
  • Acknowledgment of Receipt of Notice of Privacy Practices—form accompanying a covered entity’s Notice of Privacy Practices
  • Release of information (ROI)—process followed by employees of covered entities when releasing patient information

Learning Outcome: 2.3 Discuss how the HIPAA Privacy Rule protects patients’ protected health information (PHI).

Teaching Notes: Ask students if they have ever been asked to sign an Acknowledgement of Receipt of Notice of Privacy Practices form when they went to a medical appointment. Discuss whether or not students read the form, or just signed it. Ask them what the reason for signing the form might be if no one reads it. Is it necessary? Do they think it is a waste of paper to just have someone sign on the line? Why or why not?

When talking about ROI, stress the reasons for putting a process like this in place; what might happen if there were no processes dealing with releasing patient records? If you choose, present various examples of breaches of the process – what were the ramifications and why was information released improperly?

*

© 2012 The McGraw-Hill Companies, Inc. All rights reserved.

2.3 HIPAA Privacy Rule (Continued)

2-14

  • Treatment, payment, and health care operations (TPO)—under HIPAA, three conditions under which patients’ protected health information may be released without their consent

Learning Outcome: 2.3 Discuss how the HIPAA Privacy Rule protects patients’ protected health information (PHI).

Teaching Notes: After discussing TPO, ask students why they think these three circumstances allow release of information WITHOUT patient consent.

*

© 2012 The McGraw-Hill Companies, Inc. All rights reserved.

2.4 HIPAA Security Rule

2-15

  • HIPAA Security Rule—law that requires covered entities to establish administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of health information
  • Electronic protected health information (ePHI)—PHI that is created, received, maintained, or transmitted in electronic form
  • Regulations under the HIPAA Security Rule apply to ePHI.

Learning Outcome: 2.4 Discuss how the HIPAA Security Rule protects electronic protected health information (ePHI).

Teaching Notes: Direct students’ attention to Figure 2.4 in the textbook so they can see how confidentiality, integrity, and availability are interrelated – if one aspect fails, it compromises the entire relationship.

IMPORTANT: The Security law is intentionally flexible – there are NO rigid requirements. This allows for practices to customize according to individual needs.

*

© 2012 The McGraw-Hill Companies, Inc. All rights reserved.

2.4 HIPAA Security Rule (Continued)

2-16

  • The HIPAA Security Rule contains requirements for three types of safeguards to prevent security breaches:
  • Administrative
  • Physical
  • Technical
  • Encryption—process of converting electronic information into an unreadable format before it is distributed

Learning Outcome: 2.4 Discuss how the HIPAA Security Rule protects electronic protected health information (ePHI).

Teaching Notes: Ask students to provide an example of an administrative, physical, and technical safeguard that might be put in place. If they struggle, direct their attention to the textbook for examples OR provide some of your own, fleshing out and explaining as needed.

*

© 2012 The McGraw-Hill Companies, Inc. All rights reserved.

2.5 HITECH Breach Notification Rule

2-17

  • Breach—under the HIPAA Privacy Rule, impermissible use or disclosure that compromises the security or privacy of PHI that could pose a significant risk of financial, reputational, or other harm to the affected person
  • Breach notification—document used by a covered entity to notify individuals of a breach in their PHI required under the new HITECH breach notification rules

Learning Outcome: 2.5 Explain the purpose of the HITECH breach notification rule.

Teaching Notes: Explain that a proper breach notification must include five pieces of information:

  • Brief description of what happened, including dates
  • Description of the types of unsecured information involved in the breach (SSN, address, etc.)
  • Steps individuals must take to protect themselves
  • Brief description of what the party at fault is doing to investigate, resolve, and protect from further breaches
  • Contact information for individuals who might have questions or concerns

Ask students to write a sample brief notification letter based on a scenario you provide.

*

© 2012 The McGraw-Hill Companies, Inc. All rights reserved.

2.6 HIPAA Electronic Health Care Transactions and Code Sets, and National Identifiers

2-18

  • HIPAA Electronic Health Care Transactions and Code Sets (TCS)—HIPAA rule governing the electronic exchange of health information
  • Establishes standards that apply to electronic formats, code sets, and identifiers
  • ASC X12 Version 5010—updated electronic data standard for transmitting HIPAA X12 documents
  • Code set—alphabetic and/or numeric representations for data

Learning Outcome: 2.6 State the goal of the HIPAA Electronic Health Care Transactions and Code Sets (TCS) standards and list the HIPAA transactions and code sets standards that will be required in the future.

Teaching Notes:

IMPORTANT: All providers who do business electronically are required to use the same code sets and electronic formats.

Link this information back to EHRs and EMRs. . . . if one chart will serve as a comprehensive record of care, it makes sense that a standard method of record-keeping and coding be in place.

*

© 2012 The McGraw-Hill Companies, Inc. All rights reserved.

2.6 HIPAA Electronic Health Care Transactions and Code Sets, and National Identifiers (Cont.)

2-19

  • HIPAA National Identifiers—HIPAA-mandated identification system for employers, health care providers, health plans, and patients
  • National Provider Identifier (NPI)—under HIPAA, system for identifying all health care providers using unique ten-digit identifiers

Learning Outcome: 2.6 State the goal of the HIPAA Electronic Health Care Transactions and Code Sets (TCS) standards and list the HIPAA transactions and code sets standards that will be required in the future.

Teaching Notes: Note that the unique NPI numbers are stand-alone identifiers – that is, they do not contain coded information such as state, address, name, etc., like drivers’ licenses do.

*

© 2012 The McGraw-Hill Companies, Inc. All rights reserved.

2.7 Threats to Privacy and Security

2-20

  • Common threats to information security include:
  • Utility failures
  • Natural disasters
  • Problems with computer systems and software
  • Malware
  • Identity theft
  • Subversive employees or contractors
  • Outsiders who try to damage or steal information
  • HITECH Act makes business associates subject to the same privacy and security requirements as covered entities.

Learning Outcome: 2.7 Discuss some of the most common threats to the privacy and security of electronic information and ways in which the HITECH Act addresses them.

Teaching Notes: As an in-class assignment (group or individual), have students identify at least one specific example of how each threat to information security could cause a breach. For example, a computer system problem might be an insufficient firewall which allows hackers to breach the system.

Use student responses to start a discussion of threats and solutions.

*

© 2012 The McGraw-Hill Companies, Inc. All rights reserved.

2.8 Fraud and Abuse Regulations

2-21

  • Health Care Fraud and Abuse Control Program—government program to uncover misuse of funds in federal health care programs run by the Office of the Inspector General
  • Fraud—intentional act of deception to take financial advantage of another person
  • Example—forging another person’s signature on a check

Learning Outcome: 2.8 Define fraud and abuse in health care and cite an example of each.

Teaching Notes: When discussing differences between FRAUD and ABUSE, cite specific examples or ask students to provide them.

Stress that the HCFaACP has sanctions built in to protect whistleblowers; use this information to discuss the issue of whistleblowing. Why are so many people afraid to “blow the whistle”? Do students think that this program will cause more whistleblowers to step forward? Why or why not?

*

© 2012 The McGraw-Hill Companies, Inc. All rights reserved.

2.8 Fraud and Abuse Regulations (Continued)

2-22

  • Abuse—actions that improperly use another person’s resources
  • Abuse may or may not be intentional.
  • Example—an ambulance service billing Medicare for transporting a patient to the hospital when the patient did not need ambulance service

Learning Outcome: 2.8 Define fraud and abuse in health care and cite an example of each.

Teaching Notes: See notes on slide 21.

*

© 2012 The McGraw-Hill Companies, Inc. All rights reserved.

2.9 Enforcement and Penalties

2-23

  • Several government agencies help to enforce HIPAA:
  • Office for Civil Rights—handles civil violations
  • Department of Justice—handles criminal violations
  • Centers for Medicare and Medicaid Services—enforces all the HIPAA standards except the privacy and security standards
  • Office of Inspector General—combats fraud and abuse in health insurance and health care delivery
  • Audit—formal examination or review

Learning Outcome: 2.9 Describe the various government agencies that are responsible for enforcing HIPAA.

Teaching Notes: Direct students’ attention to Table 2.5 in the text. Do they think the monetary penalties are fair for each violation? Too high? Too low? Ask them to justify their opinions.


Ask students whether they think monetary penalties are an effective way to ensure HIPAA compliance.

*

© 2012 The McGraw-Hill Companies, Inc. All rights reserved.

2.10 Compliance Plans

2-24

  • According to the OIG, a voluntary compliance plan should contain seven elements:

Consistent written policies and procedures

Appointment of a compliance officer and committee

Training plans

Communication guidelines

Disciplinary systems

Auditing and monitoring

Responding to and correcting errors

Learning Outcome: 2.10 Identify the parts of a compliance plan and the types of documentation used to demonstrate compliance.

Teaching Notes: The seven pieces of a compliance plan come together in the hopes of accomplishing three goals:

  • Preventing fraud and abuse
  • Ensuring compliance with all applicable federal, state, and local laws
  • Helping to defend the practice if it is investigated or prosecuted for fraud

IMPORTANT: Students must understand that physicians are ultimately responsible for the actions of ALL employees who work for them. If any staff member behaves in an improper manner, the supervising physician can ultimately be held liable for that employee’s actions. (Law of respondeat superior)

*

© 2012 The McGraw-Hill Companies, Inc. All rights reserved.

2.10 Compliance Plans (Continued)

2-25

  • Common compliance documentation includes:
  • Retaining written or electronic results of risk analysis
  • Documenting the results of an audit
  • Developing and implementing comprehensive privacy and security policies and procedures
  • Documenting staff training and security incident threats

Learning Outcome: 2.10 Identify the parts of a compliance plan and the types of documentation used to demonstrate compliance.

Teaching Notes: EVERYTHING must be in writing! Documentation serves to protect a practice.

*