Thursday Morning—HIPAA Privacy & Security
A fast-paced trip through HIPAA’s privacy and security rules, including changes under the HITECH Act.
“Material covered a wealth of information, and seminar examples did a great job to provide information in anticipation of practical industry matters.”
Agenda
8:00 a.m.
- Registration/Coffee/Danish
8:30 a.m.
- HIPAA’s Privacy Requirements. Overview of the core privacy requirements and examples of common privacy dilemmas.
- What Information and What Entities? What is HIPAA protected health information (PHI)? What information is not protected by HIPAA? Who are covered entities subject to HIPAA privacy rules? HITECH Act and expanded application of privacy rules to business associates.
- Use and Disclosure Rules. Main use and disclosure rules. Employer use and disclosure rules. Disclosures to family and friends and other disclosures exceptions.
- Sharing PHI. Sharing PHI with business associates and the plan sponsor. Issues relating to employment records, enrollment information, and other special rules.
- Other Privacy Rules. Individual rights under the HIPAA privacy rules, including right to receive privacy notice. Administrative requirements for HIPAA privacy.
10:15 a.m.
- Coffee Break
10:30 a.m.
- HIPAA’s Security Requirements. Overview of the core HIPAA security requirements and examples of common security issues for group health plans.
- HIPAA Security Compliance. Regulatory approach to HIPAA security compliance. The HIPAA security compliance process (including procedures for addressable implementation specifications). Administrative, physical, technical, and organizational safeguards and documentation.
- Sharing PHI and Breach Notification. Sharing electronic PHI with business associates and the plan sponsor. HITECH Act and expanded application of security rules to business associates. New breach notification requirements.
- Business Associate Contracts. Modifications for incorporating provisions of the HITECH Act. Transition period for making changes to existing contracts.
- Implementation and Enforcement. Checklists for common group health plan issues. Consequences of noncompliance. Enhanced enforcement and penalties under the HITECH Act.
12:00 Noon
- HIPAA program ends (lunch on your own)
