EBIA's HIPAA Privacy & Security: Agenda
A fast-paced trip through HIPAA’s privacy and security rules, including HITECH provisions.
“Great examples. Very helpful when translating technical law to practical/operational applications.”
8:00 a.m.
Registration/Coffee/Danish
8:30 a.m.
HIPAA’s Privacy Requirements. Overview of the core privacy requirements and examples of common privacy dilemmas.
What Information and What Entities? What is HIPAA protected health information (PHI)? What information is not protected by HIPAA? Who are covered entities subject to HIPAA privacy rules? HITECH Act and application of privacy rules to business associates.
Use and Disclosure Rules. Main use and disclosure rules. Employer use and disclosure rules. Disclosures to family and friends and other disclosure exceptions.
Sharing PHI. Sharing PHI with business associates and the plan sponsor. Issues relating to employment records, enrollment information, and other special rules.
Other Privacy Rules. Individual rights under the HIPAA privacy rules, including the right to receive privacy notice. Administrative requirements for HIPAA privacy.
10:15 a.m.
Coffee Break
10:30 a.m.
HIPAA’s Security Requirements. Overview of the core HIPAA security requirements and examples of common security issues for group health plans.
HIPAA Security Compliance. Regulatory approach to HIPAA security compliance. The HIPAA security compliance process (including procedures for addressable implementation specifications). Administrative, physical, technical, and organizational safeguards and documentation.
Breach Notification. HITECH Act breach notification requirements.
Business Associate Contracts. Addressing HITECH Act provisions. Subcontractors of business associates.
Electronic Transactions. New standards and operating rules.
Implementation and Enforcement. Checklists for common group health plan issues. Consequences of noncompliance. Enhanced enforcement and penalties under the HITECH Act. HHS’s new HIPAA audit program.
12:00 Noon
HIPAA program ends (lunch on your own)
