Basics for providers: Privacy, Security, Breach Notification
Health Insurance Portability & Accountability (HIPPA)
- it protects patience health record identity, HIPAA est standards to protect people's medical records and other protected health information (PHI). (HEALTH PLAN// HEALTH CARE CLEARINGHOUSE// HEALTH CARE PROVIDER THAT CONDUCTS CERTAIN HEALTH CARE TRANSACTIONS ELECTRONICALLY)
- EST IN 1996 , was est in USA.
- Pass to set national standards
PHI
3 KEY GROUPS
- HEALTH CARE CLEARING HOUSE
- Middle man for data
- taking the data in 1 format
- translate the data so that insurance company can read it easily.
- BPO is also considered a middle in HCCH.
- BUSINESS ASSOCIATES - covered idea
-A Business Associate is any third party that:
Creates, receives, maintains, or transmits PHI on behalf of a covered entity,
Or provides services involving PHI access.
Examples include:
Billing companies
Cloud storage or data hosting providers
IT support services
Medical transcriptionists
Law firms, auditors, or accountants handling PHI
Claims processing companies
Consultants analyzing healthcare data
COVERED ENTITY
- Hospitals, Psychiatrist, Doctors, Pharmacies,
3 RULES in healthcare
- PRIVACY RULE :
- Protects your patients PHI while letting you securely exchange info
- CORE OF THE 3 PILLARS
- examine and get a copoy of their medical records including an electronic copy -request corrections
- treatment, payment/ healthcare operations (PHI are allowed to acccess)
PHI (Privacy Health Informartion)
- protects PHI that you hold or transmit in any form inc. electronic, paper, or verbal, PHI
- piece of information that connects a person's identity to their health
THE 18 IDENTIFIERS OF PHI Names All geographic subdivisions smaller than a state (e.g., street address, city, county, precinct, zip code) All elements of dates (except year) for dates directly related to an individual Telephone numbers Fax numbers Email addresses Social Security numbers Medical record numbers Health plan beneficiary numbers Account numbers Certificate/license numbers Vehicle identifiers and serial numbers Device identifiers and serial numbers Web URLs IP addresses Biometric identifiers (including finger and voice prints) Full-face photographs and any comparable images Any other unique identifying number, characteristic, or code
Requirements:
- Notify patients about their privacy rights an how you use their info
- Adopt privacy procedures and train employees to follow them
- Assign employee to make sure you're adopting and following privacy procedures
- Secures patient records containing PHI, so they arent readly available to those who dont need to see them
INCIDENTAL DISCLOSURES
- Oops situation/ unintentional incidents
- Only acceptable if you talk reasonable precautions.
- SECURITY RULE
- Includes security requirements to protect patients electornic PHI confidentiality, integrity, and availability.
- technical armor of HIPAA
- protects electronic records
(3 TYPES OF SAFEGUARDS) Administrative safeguards Physical safeguards Technical safeguards
- BREACH NOTIFICATION RULE:
- you must follow the BNR. If the breach involves PHI. That means you must notify affected patients. HHS, and ,some cases, the media. A breach usually happens when PHI is used/ shared in a way that isnt allowed under the HIPAA Privacy Rule and that use or disclosure put the privacy or security 0f the info at risk. Any use or disclosure of PHI that isnt permited is considered a breach unless theres a low probability the PHI has been compramised, based on a risk assesment of:
- breach means PHI has been accessed
⚠️ Types of HIPAA Breaches- RESCUE PLAN WHEN THINGS GO WRONG
- 🧾 Unintentional Breach
An accidental disclosure of PHI — not malicious, but still a violation if safeguards weren’t followed.
🔹 Examples:
Sending a patient’s lab results to the wrong email address.
Leaving printed records in a public area by mistake.
Accidentally sharing PHI with an unauthorized staff member.
🔹 Prevention:
Double-check recipients before sending emails or faxes.
Train staff on privacy procedures.
Implement “minimum necessary” access.
- 🏢 Physical Breach
Occurs when paper files, devices, or physical media containing PHI are lost, stolen, or improperly handled.
🔹 Examples:
Theft of laptops, USB drives, or printed records.
Improper disposal of documents (not shredding).
Unauthorized entry into secure medical record storage areas.
🔹 Prevention:
Lock storage areas and workstations.
Use privacy screens and physical barriers.
Securely dispose of or wipe old devices and documents.
- 💻 Cyber Breach
Involves electronic PHI (ePHI) being accessed or stolen through cyberattacks or system vulnerabilities.
🔹 Examples:
Phishing or ransomware attacks.
Hacking into servers, email, or cloud systems.
Weak passwords or unencrypted data transmission.
🔹 Prevention:
Use strong passwords and multi-factor authentication.
Encrypt data in storage and transit.
Conduct regular security audits and software updates.
Train staff on identifying phishing emails.
- 🗣️ Verbal Breach
Occurs when PHI is spoken or overheard without proper authorization.
🔹 Examples:
Discussing a patient’s condition in a hallway or elevator.
Calling out patient names and diagnoses in a waiting area.
Sharing PHI verbally with unauthorized individuals.
🔹 Prevention:
Speak quietly in private areas.
Avoid using full names or identifiers in public spaces.
Train staff on discretion and verbal privacy etiquette.
Who must Conplky with HIPAA rules? HIPAA applies to two main groups:
- Covered Entities
- Business Associates
Who enforces HIPAA rules?
- The HHS OCR enforces the HIPAA Privacy, security, and Breach Notification Riles.
- investigate complaints from patients when violation happens