Health Care Administration homework- 5 pages

profileWorkSmart
hippa.doc

HIPPA Privacy and Security Threats in Healthcare

1

HIPAA Privacy and Security Threats in Health Care

Kathy Brown

MHA616

Instructor Mohammad Bajwa

April 21, 2014

HIPPA Privacy and Security Threats in Health Care

According to Dr. Amandeep Singh Martharu (1996), the Health Insurance Portability and Accountability Act (HIPAA) is a law designed to improve the efficiency and effectiveness of the health care system. HIPAA directly affects clinical work and the operations of any facility. Understanding HIPAA prepares you to step into health organizations with a clear understanding of complying with requirements for respecting the privacy of protected health information (PHI). As such an important law, the HIPPA Privacy Rule creates national standards which protect the personal health information of individuals which applies to insurance carriers, health care providers, and health care employees. It is intended to place limitations and conditions on the use and disclosure of protected health information without the authorization of the patient. In addition, HIPPA gives patients specific rights regarding his or her health information such as the right to review and receive a copy of his or her health record as well as to request corrections (HHS, 2003). With appropriate administrative, physical and mechanical protections to guarantee the privacy and protection of electronic health information, the HIPPA Security Rule places strict regulations upon providers and organizations which transmit electronic health information.

Being in charge of addressing the issue of security and privacy threats, my role would entail placing safeguards to ensure that all members of the organization maintain the integrity of protected health information and data through proper orientation regarding HIPPA laws and regulations as well as the policies and procedures of the organization, as well as making important data easily available to appropriate users such as health care providers and insurance providers.

With health information systems providing protected information electronically, the integrity of the data as well as security and privacy of information must be maintained. Quality of security and privacy practices require that threats be identified and eliminated. Security initiatives such as password protection for computer users, as well as screen protection to secure the privacy of displayed information must occur to control physical access and prevent inappropriate access to desktop computers and that computer screens are not left unattended.

Patient care can only be as accurate as the information that is used. In other words, if a violation of security occurred which tampered with patient information, the result could be inadequate care for the patient based upon wrong information. The management and staff as well as the organization as a whole must safeguard patient information in order to maintain organizational integrity and accuracy, as well as to comply with HIPPA Security and HIPPA Privacy Rules.

According to HIMMS, the Security Rule and Privacy Rule work cooperatively in order to provide rules for disclosure and access as well as enforcement of standards (Sostrom & Collmann, 2007). Privacy places limitations on the release of protected information to only those who reasonably require disclosure such as health providers and insurance providers. Security of data is used to ensure the privacy and safety of data for the same purpose.

Current conclusions identify threats to security and privacy while offering solutions such as development of information security policies to protect files and restrict the number of network services within database servers used. If staff members are trained appropriately on the procedures to secure and protect health information, there will be fewer threats to identify.

References

HHS (2003). The Privacy rule. Retrieved from http://www.hhs.gov/ocr/privacy/hipaa/administrative/privacyrule/index.html

HHS (2003). The security rule. Retrieved from

http://www.hhs.gov/ocr/privacy/hipaa/administrative/securityrule/index.html .

Sostrom, K & Collmann, J. (2007). Managing Information Privacy & Security in

Healthcare. Healthcare Information and Management Systems Society. Retrieved from

http://www.himss.org/content/files/Code%20165%20Sostrom%20HIPAA%20Final

%20Security%20Rule %20in%20Plain%20English.pdf.