Our
HIPAA Compliance Training meets the
HIPAA's Privacy Rule job-role based training
requirement which mandates that every Covered Entity
provide privacy training for all members of its
workforce with respect to the policies and
procedures on use and disclosure of protected health
information (PHI). The HIPAA Compliance course outlines the HIPAA law requirements for
the Privacy and Security rule and guides you on how to make
your organization HIPAA compliant.
Our training reflects
changes to HIPAA regulations due to the Health
Information Technology for Economic and Clinical
Health (HITECH)
Act, which is part of the American Recovery and
Reinvestment Act of 2009 (ARRA).
HIPAA Compliance
Training - Day 1
HIPAA
Fundamentals
- HIPAA Basics:
An overview of the Health Insurance
Portability and Accountability Act of 1996
(all provisions)
- HIPAA's
Administrative Simplification Title:
Review of the provisions of the Administrative
Simplification Title. This includes
transaction and code set standards
(administrative transactions), national
identifiers, privacy requirements and security
requirements.
- HIPAA
Penalties: Review of the HIPAA enforcement
rule including informal and formal remedies,
requirements of Covered Entities, the role of
Business Associates as agents and enforcement
bodies.
- HIPAA-Related
Organizations: Discussion of
entities/organizations specifically designated
as standard maintenance organizations and
statutorily defined advisory bodies.
- HIPAA
Terminology and Definitions:
Review of definitions included in the
Administrative Simplification Title related
rules.
- Covered
Entity
- Health Plan
-
Clearinghouse
- Health Care
Provider
- Business
Associates
- Trading
Partner Agreement
- Workforce
- Organized
Health Care Arrangement
HIPAA
Transactions, Code Sets and Identifiers
- Transactions
- Impacted Health
Care Transactions
- Target Entities
- Scope
- Penalties
- ASCA
ANSI ASC
X12 Standard
- Transaction
Type 270
- Transaction
Type 271
- Transaction
Type 276
- Transaction
Type 277
- Transaction
Type 278 Request and Response
- Transaction
Type 820
- Transaction
Type 834
- Transaction
Type 835
- Transaction
Type 837 - Professional
- Transaction
Type 837 - Institute
- Transaction
Type 837 - Dental
HIPAA Code
Sets
- ICD-9-CM
Volumes 1 and 2
- CPT-4
- CDT
- ICD-9-CM
Volume 3
- NDC
- HCPC
HIPAA
National Health Care Identifiers
- Provider
Identifier
- Employer
Identifier
- Health Plan
Identifier
- Individual
Identifier
HIPAA
Privacy Rule Part 1
- Introduction:
Overview of the HIPAA Privacy Rule
- Who is
Impacted (e.g., definition of Covered
Entities, Business Associates)
- Scope
(activities covered by the rule)
-
Exceptions (specifically included or
referenced exceptions that allow use and
disclosure of patient/health plan member
protected health information (PHI))
- Timeline
(effective date of the rule, timelines
related to certain requirements identified
in the Privacy rule such as accounting of
disclosures, document retention
requirements, etc.)
- Key
Definitions: Review of key definitions
associated with the Privacy rule and how they
apply to rule application and compliance.
- IIHI
- PHI
-
Deidentified Information
- Use
- Disclosure
- Treatment
- Payment
- Health Care
Operations
- Notice
Requirement: Review of the requirements to
draft and make available a notice of privacy
practices, the content of such notice, revision
requirements and availability requirements.
- Core
Elements
- Changes to
a Notice
- First
Interaction
- Authorization
versus Consent Requirement: Review the
legal definitions of consent and authorization
and what they would be used for. Review of
the legal requirements related to obtaining
authorization, the form of such authorization,
and content requirements.
-
Definition of "consent"
- Definition
of "authorization"
- Legal
differences between "consent" and
"authorization"
- Core Data
Elements and Required Statements
- Defective
Authorizations
- Revocations
- Key Parties
Impacted: A discussion of all entities or
individuals directly or indirectly impacted by
the rule and why.
- Minimum
Necessary: Discussion of the definition of
minimum necessary and when it applies to the use
and disclosure of PHI (internally and
externally).
- Oral and Other
Non-electronic Communications: A
discussion of what constitutes PHI pursuant to
the rule and the related requirements to protect
non-electronic PHI, including oral PHI.
- Health-Related
Communications, Fund Raising and Marketing:
Review of the requirements related to the use of
PHI for communications other than treatment,
payment and health care operations. Also,
a review of the strict requirements relating to
the use of PHI for marketing and fundraising.
- Research:
A review of the requirements related to the use
of PHI for research including what processes
must be followed prior to allowing the use of
PHI in research without the patient/health plan
member's authorization.
HIPAA Compliance
Training - Day 2
HIPAA
Privacy Rule Part 2
- Policy &
Training Requirements: A review of the
implied and explicit requirements to develop,
implement, and maintain privacy policies and
procedures and the requirement to provide
initial and ongoing staff training.
- Preemption
Requirements: A review of state law
preemption. This includes a discussion
regarding when state law may preempt the rule
without specific authorization from the U.S.
Department of Health and Human Services (HHS)
and when authorization is required prior to
state law preemption of HIPAA.
- State Privacy
Laws: A general review of state privacy
laws that preempt HIPAA (categorized as
specially protected health information) with
specific reference to select California state
laws.
- Federal Privacy
Law - 42 CFR Pt. 2: A discussion of the
more stringent requirements found in 42 CFR Pt.
2 relating to alcohol and chemical dependency.
- Statutory/Rule
Conflict Resolution: Discussion of how to
respond when federal and/or state law conflicts.
- Case Law:
A review of general case law that has impacted
the application of HIPAA, state privacy laws and
impacts legal risks.
HIPAA
Security Rule Part
1
- Threats:
General review of threats (real and perceived)
prompting Congress to include security
requirements in the HIPAA Administrative
Simplification Title.
- Definition and
Terminology: Review of general definitions
of security and specifically how those
definitions apply to the rule and what data must
be protected by implementation of appropriate
security measures.
-
Security
- Security
Services
- Security
Mechanism
- Security Rules:
Detailed review of the Security rule, components
of the Security rule, and specific requirements
(including reference back to security
requirements referenced in the HIPAA Privacy
Rule).
-
Categories of Safeguards
-
Implementation Specifications
- Approach
and Philosophy
- Security
Principles
- Administrative
Safeguards
- Physical
Safeguards
- Technical
Safeguards
- Organizational
Requirements
- Policies, Procedures, and Documentation Standards
HIPAA Compliance
Training - Day 3
-
Definition of administrative safeguards as
they relate to security and the rule. A
review of required administrative safeguards and
their application within a Covered Entity and
Business Associate.
-
Administrative Safeguards
- Security
Management Process
- Assigned
Security Responsibility
- Workforce
Security
- Information
Access Management
- Security
Awareness and Training
- Security
Incident Procedures
- Contingency
Plan
- Evaluation
- Business
Associate Contracts Standard
-
Definition of physical safeguards as they
relate to security and the rule. A review
of required physical safeguards and their
application within a Covered Entity and Business
Associate.
-
Requirements
- Facility
Access Controls
- Workstation
Use
- Workstation
Security
- Device and
Media Controls
- Physical
Safeguards Review
-
Definition of technical safeguards as they
relate to security and the rule. A review
of required technical safeguards and their
application within a Covered Entity and Business
Associate.
- Requirements
- Access
Control
- Audit
Controls
- Integrity
- Person or
Entity Authentication
- Security
Compliance process: Risk Analysis,
Vulnerability Assessment, Remediation,
Contingency Planning, Audit and Evaluation
- Transmission
Security
-
A review of required technical safeguards
including a more technical review of required
or addressable safeguards, implementation, and
ongoing maintenance.
- TCP/IP
Network Infrastructure
- Firewall
Systems
- Virtual
Private Networks (VPNs)
- Wireless
Transmission Security
- Encryption
- Overview of
Windows XP and Vista Security
HIPAA Compliance
Training - Day 4
- Digital
Signatures & Certificates :
A review of the use of higher forms of
individual or entity authentication that is
quickly becoming a requirement legally and to
reduce legal risk.
-
Requirements
- Digital
Signatures
- Digital
Certificates
- Public Key
Infrastructure (PKI)
- Solution
Alternatives
- Identity
theft prevention and HIPAA
- Security
Policy :
A review of the requirements to document
security program practices and processes in
policy and related workforce training
requirements. In addition, a review of required
policy maintenance and retention.
- Risks, Risk
Management, and Policy
Development/Implementation
- General
Security Standards Impact on Policy
Development
- Policy
Training Requirements
- Security
Policy Considerations
Enforcement
Rule
- Overview:
An overview of the rule and rule requirements
including entities and individuals the rule
applies to.
- Definitions:
A review of rule definitions including what represents a violation,
compliance, definition of agent, resolution
processes and HHS enforcement, powers.
- Informal
resolution process: A discussion of what
an informal resolution is and what it entails.
Also, a review of the rules emphasis on
informal resolution and language allowing such
resolution at any phase of violation
investigation, penalty assessment, and appeal.
- Formal
resolution process (i.e., penalties,
administrative hearings, appeal process, etc.):
A discussion of what would likely trigger a
formal resolution process, HHS requirements, and
authority to investigate, rights and
responsibilities of Covered Entities and
resulting actions if civil penalties are levied
and paid by the Covered Entity.
- Compliance
Audits: A discussion of the authority to
conduct compliance audits, current audit
activity and prospective audit activity.
Identity
Theft Protection
Laws
A general review of existing identity theft
protection laws and breach notification
requirements. Includes specific discussion
of California identity theft and medical
identity theft protection laws.
American
Recovery and Reinvestment Act
of 2009 (ARRA),
Title
XIII
A general overview of Title XIII health
information technology (HIT) incentives and
requirements provisions. This discussion
will focus on an overview of the role of privacy
and security in HIT investment provisions and
standards development.
American
Recovery and Reinvestment Act of 2009 (ARRA),
Title XIII, Subtitle D HITECH
- Privacy
Provision Overview :
Overview of the privacy provisions included ARRA
and the relationship to the HIPAA Administrative
Simplification Title provisions.
American
Recovery and Reinvestment Act of 2009 (ARRA),
Title XIII, Subtitle D
HITECH
- Business
Associates New Requirements :
A discussion of Business Associates new
requirement to statutorily adhere to the
provisions of the HIPAA Administrative
Simplification Title Privacy and Security Rules.
The discussion includes a review of the timeline
for compliance and the implications for Business
Associates.
- National
Identity Theft Protection Provisions :
A discussion of the requirements of the new
identity theft protection provisions, what is
considered a breach or inappropriate disclosure,
breach notification requirements and
entities/individuals covered. Discussion
also includes new reporting requirements by
entity/individual, HHS and the Federal Trade
Commission (FTC).
- Marketing
Prohibitions and Restrictions :
An overview of the enhanced restrictions related
to the use and disclosure of PHI where the
entity or individual is paid for such use and
disclosure and stricter prohibitions against
using PHI for marketing purposes.
- Enforcement
Provisions :
A discussion of the new enforcement provisions,
entities/individuals covered and how such
enforcement relates to the HIPAA Enforcement
Rule and current compliance audits. The
discussion also includes a discussion of changes
in penalties and the addition of a newly defined
criminal act (formerly a civil violation).
- Reporting
Requirements :
A discussion of new requirements for the
reporting of breaches to HHS and/or the FTC and
annual reports relating to compliance, rule
violations, breaches, etc. to Congress and the
public.
Click on
Following Links for more details on course:
HIPAA
Compliance Training (Level 1 & 2) class schedule
HIPAA Compliance
Training (Level 1 & 2) course overview
Register for
HIPAA Compliance Training (Level 1 & 2)
HIPAA Training
Testimonials
We can skillfully assist you in determining your
readiness for accelerated training, and the best HIPAA training
course based on your job role. Please contact us for more
information at
Sales@hipaatraining.net or call (515) 865-4591.