/_media/adv/web/images/2011/20111124_Arthrex_TB-378x82.jpg

Subscriptions

Advertising

Resources

About Us

Contact Us

Create An Account Forgot Your Password?
Trouble logging in or creating an account? click here
Home This Month E-Weekly Newsletter Building a Facility Article Archive Second Opinions
Search:
Benchmarking
General Surgery
Accrediting/Quality
Anesthesia
Code/Bill/Reimburse
Building/Renovating
/_media/adv/web/images/2012/20120126_APIC_LB-154x100.jpg
/_media/adv/web/images/2011/20111226_Soma_LB-154x100.gif
/_media/adv/web/images/2011/20110124_ImageFirst_LB-154x100.gif
/_media/adv/web/images/2011/20111003_Ansell_LB-154x100.gif
Outpatient Surgery E-Weekly

Contact Congress Over Drug Shortage Issues

A Kentucky congressman is urging surgical facilities to contact their members of Congress and request that they sign his letter demanding changes to...

N.J. Posts ASC Inspection Reports Online

State and federal inspection reports of New Jersey's ASCs are now available online, giving patients an opportunity to make more informed choices abo...

Are Opioids Necessary?

While it's not always practical, or even possible, to eliminate opioids from your post-op pain management regiment, reducing their use in favor of n...

Archive > June, 2001 Vol. II, No. 6

Decoding HIPAA: A 6-Point Guide

Time is your most valuable resource when it comes to HIPAA preparation.

Dianne Taylor, Contributing Editor
Recently, an assistant in an OB/GYN clinic began stealing information from the medical records of patients who entered the clinic wearing diamonds and exhibiting other signs of material wealth. In no time, she had adopted several patients' identities and began using their credit cards. Unlike most identity thieves, she ultimately got caught, and one of the victims settled a negligence lawsuit out of court with the clinic.

Unfortunately, this medical assistant is part of a growing legion of women and men who act individually, or as part of crime rings, to purchase items and secure loans using someone else's credit. Identity theft-along with insurance, lending, and employment refusals that can stem from the sharing of diagnostic and genetic information-has created a groundswell of consumer concern about information privacy. It is this outcry that prompted Department of Health and Human Services (HHS) Secretary Tommy G. Thompson to ratify the Health Insurance Portability and Accountability Act (HIPAA) privacy standard earlier this year. The standard takes aim at medical records because these records, with their plethora of identifying patient information, are a valuable target for sophisticated information criminals.

To ensure compliance by the April 14, 2003 due date, you'll need to understand exactly what the standard requires. In the following pages, we'll break down the regulation and put it into ?plain English' to help you understand exactly what it will mean for your facility.

HIPAA Defined
The privacy standard is just one component of the broader, four-part HIPAA law passed in 1996. Overall, HIPAA has two main objectives: To ensure the privacy and security of health information, and to simplify the administrative burden on providers and insurers. To date, the HHS Secretary has signed off on two of the four HIPAA standards: The privacy standard and the transaction and code set standard (see sidebar). The two remaining parts are:

- The security standard, which aims to ensure the security of electronic medical information and will overlap with the privacy standard,

- National identifier standards, which simplify electronic transactions by assigning universal ID numbers to providers, health care plans, and employers.

The Privacy Standard
The HIPAA privacy rule aims to reign in unnecessary sharing of medical information, reduce medical record accessibility (to everyone except patients), give patients control over their health information, and make providers more accountable when they unnecessarily obtain or disclose private health data. Because the privacy standard applies to all providers that use electronic transactions (whether directly or through third parties), essentially all outpatient facilities are subject to it. Importantly, the standard does not apply only to electronic transactions. It applies to any form of "identifiable" health information-including written records, oral communications (e.g., intercoms, general conversations, telephone calls), and electronic transactions (e.g., e-mails, computer records, faxes). The regulation considers medical information "identifiable" when it contains the patient's name, address, birth date, or anything else that can be used to identify the patient. If you remove these identifiers, the record loses its HIPAA protection and you can freely disclose the data. However, codes or encryption keys for tracing the data back to the patient are also considered identifiers.

The privacy standard, which mandates compliance by April 14, 2003, generally requires outpatient facilities to do the following six things:
  1. Fully inform patients how you may use their medical information.
    You must give all patients a clear, written explanation of how you typically use or disclose their medical information via a "Notice of Privacy Practices for Protected Health Information." The notice must contain six elements (see HIPAA Checklist). "Basically, this is a re-working of the statement of rights and responsibilities," notes Sandra J. Jones, managing partner with Ambulatory Strategies, Inc. HIPAA law requires providers to prominently post the notice, post it electronically on web sites or via e-mail if you have these capabilities, and have paper copies available.

Sign in to continue reading.
Email Address:
Password:
Categories: Not yet reviewed
Keywords:
Act; Ambulatory Strategies, Inc. HIPAA; April; DefinedThe; Department; G. Thompson; HHS Secretary; HIPAA; HIPAA DefinedThe; Health; Health Insurance Portability; Human Services; Identity; Inc. HIPAA; Insurance Portability; National; OB/GYN; Overall, HIPAA; Portability; Practices; Privacy Practices; Privacy StandardThe HIPAA; Secretary; Secretary Tommy G. Thompson; Services; StandardThe HIPAA; Strategies, Inc. HIPAA; Thompson; Tommy G. Thompson; Unlike; accessibility; accountable; act; administrative; adopted; aim; applies; apply; assigning; assistant; back; began; birth; break; burden; care; c... show all keywords
Act; Ambulatory Strategies, Inc. HIPAA; April; DefinedThe; Department; G. Thompson; HHS Secretary; HIPAA; HIPAA DefinedThe; Health; Health Insurance Portability; Human Services; Identity; Inc. HIPAA; Insurance Portability; National; OB/GYN; Overall, HIPAA; Portability; Practices; Privacy Practices; Privacy StandardThe HIPAA; Secretary; Secretary Tommy G. Thompson; Services; StandardThe HIPAA; Strategies, Inc. HIPAA; Thompson; Tommy G. Thompson; Unlike; accessibility; accountable; act; administrative; adopted; aim; applies; apply; assigning; assistant; back; began; birth; break; burden; care; clinic; code; communications; compliance; component; computer; concern; considered; considers; consumer; control; copies; court; created; credit; crime; criminals.To; data; diagnostic; diamonds; directly; disclose; due; e-mail; earlier; electronic; electronically; elements; else's; employers.The; employment; encryption; ensure; entered; essentially; exhibiting; explanation; facilities; form; four-part; freely; general; generally; genetic; give; groundswell; growing; health; identifier; identifiers.The; identify; identifying; identities; identity; inform; information; information-has; information-including; information.You; items; keys; law; lawsuit; legion; loans; loses; main; make; managing; mandates; material; medical; men; negligence; notes; notice; numbers; obtain; oral; outcry; outpatient; overlap; paper; part; partner; parts; passed; patient; patients; plethora; post; privacy; private; prominently; prompted; protection; providers; purchase; put; ratify; re-working; record; reduce; refusals; regulation; reign; remaining; remove; requires; rights; rule; secure; security; set; settled; sharing; signed; signs; simplify; sites; sophisticated; standard; statement; stealing; stem; subject; takes; target; telephone; theft-along; things:Fully; tracing; transaction; typically; ultimately; understand; universal; unnecessarily; unnecessary; valuable; victims; wearing; web; women; written

© Copyright Herrin Publishing Partners LP 2011. REPRODUCTION OF THIS COPYRIGHTED CONTENT IS STRICTLY PROHIBITED. We encourage LINKING to this content; view our linking policy here.

PRODUCT & SERVICE RESOURCES
Did You See This?
A showcase of products and services geared to make your facility better.

Architects' Showcase
Is a beautiful, efficient new facility in your future?
/_media/adv/web/images/2011/20111111_CareFusion_AR-300x250.jpg
Other Articles That May Interest You
InstaPoll: Do You Pay Your Anesthesia Providers a Subsidy?
Safety
Why We Created a "Safety Nurse" Position
APIC: Flu Shots Should Be Mandatory for Employees