Our HIPAA Privacy Training
meet the HIPAA's Privacy Rule job-role based training requirement that mandates that every Covered Entity provide privacy training for all members of its workforce with respect to policies and procedures on use and disclosure of protected health information (PHI). The HIPAA Privacy course educates you about the HIPAA law requirement for the Privacy rule and guides you on how to make your organization HIPAA compliant.
HIPAA Privacy Training - Day 1
- HIPAA Basics: An overview of the Health Insurance Portability and Accountability Act of 1996 (all provisions).
- HIPAA's Administrative Simplification
Title: Review of the provisions of the Administrative Simplification Title.† This includes transaction and code set standards (administrative transactions), national identifiers, privacy requirements and security requirements.
- HIPAA Penalties: Review of the HIPAA Enforcement rule including informal and formal remedies, requirements of Covered Entities, the role of Business Associates as agents and enforcement bodies.
- HIPAA-Related Organizations: Discussion of entities/organizations specifically designated as standard maintenance organizations and statutorily defined advisory bodies.
- HIPAA Terminology and Definitions: Definitions included in the
Administrative Simplification Title related rules.
- Covered Entity
- Health Plan
- Health Care Provider
- Business Associates
- Trading Partner Agreement
- Organized Health Care Arrangement
HIPAA Transactions, Code Sets and Identifiers
- Impacted Health Care Transactions
- Target Entities
ANSI ASC X12 Standard
Type 278 Request and Response
Type 837 - Professional
Type 837 - Institute
Type 837 - Dental
HIPAA Code Sets
- ICD-9-CM Volumes 1 and 2
- ICD-9-CM Volume 3
HIPAA National Health Care Identifiers†
- Provider Identifier
- Employer Identifier
- Health Plan Identifier
- Individual Identifier
HIPAA Privacy Rule Part 1
- Introduction: Overview of the HIPAA
- Who is Impacted (e.g., definition of Covered Entities, Business Associates)?
- Scope (Activities covered by the rule)
- Exceptions (Specifically included or referenced exceptions that allow use and disclosure of patient/health plan member protected health information (PHI))
- Timeline (Effective date of the rule, timelines related to certain requirements identified in the privacy rule such as accounting of disclosures, document retention requirements, etc.)
- Key Definitions: Review of key definitions associated with the privacy rule and how they apply to rule application and compliance.
- Deidentified Information
- Health Care Operations
- Notice Requirement:† Review of the requirements to draft and make available a notice of privacy practices, the content of such notice, revision and availability requirements.
- Core Elements
- Changes to a Notice
- First Interaction
- Authorization versus Consent Requirement: Review the legal definitions of consent and authorization and their purpose. Review legal requirements related to obtaining authorization, the form of such authorization and content requirements.
- Definition of consent
- Definition of authorization
- Legal differences between consent and
- Core Data Elements and Required Statements
- Defective Authorizations
- Key Parties Impacted: A Discussion of all entities or individuals directly or indirectly impacted by the rule and why.
- Minimum Necessary: Discussion of the definition of minimum necessary and when it applies to the use and disclosure of PHI (internally and externally)
- Oral and Other Non-electronic
Communications: A Discussion of what constitutes PHI pursuant to the rule and the related requirements to protect non-electronic PHI, including oral PHI.
- Health-Related Communications, Fundraising and
Marketing: Review of the requirements related to the use of PHI for communications other than treatment, payment and health care
operations. In addition, a review of the strict requirements relating to the use of PHI for marketing and fundraising.
- Research: A Review the requirements related to the use of PHI for research necessary what processes prior to using PHI in research without the patient/health plan member's authorization.
HIPAA Privacy Training - Day 2 Privacy
HIPAA Privacy Rule Part 2
- Policy & Training Requirements: A review of the implied and explicit requirements to develop, implement and maintain privacy policies and procedures and the requirement to provide initial and on-going staff training.
- Preemption Requirements: A review of state law preemption.† This includes a discussion regarding when state law may preempt the rule without specific authorization from the U.S. Department of Health and Human Services (HHS) and when authorization is required prior to state law preemption of HIPAA.
- State Privacy Laws: A general review of state privacy laws that preempt HIPAA (categorized as specially protected health information) with specific reference to select California state laws.
- Federal Privacy Law 42 CFR Part2: A discussion of the more stringent requirements found in 42 CFR Part2 relating to alcohol and chemical dependency.
- Statutory/Rule Conflict Resolution: Discussion of how to respond when federal and/or state laws conflict.
- Case Law: A review of general case law that has impacted the application of HIPAA, state privacy laws and legal risks.
HIPAA Security Rule Part 1
- Threats: General review of threats (real and perceived) prompting Congress to include security requirements in the HIPAA Administrative Simplification Title.
- Definition and Terminology: Review of general definitions of security and specifically how those definitions apply to the rule and what data must be protected by implementation of appropriate security measures.
- Security Services
- Security Mechanism
- Security Rules: Detailed review of the security rule, components of the security rule and specific requirements (including security requirements referenced in the HIPAA Privacy Rule).
- Categories of Safeguards
- Implementation Specifications
- Approach and Philosophy
- Security Principles
- Administrative Safeguards
- Physical Safeguards
- Technical Safeguards
- Organizational Requirements
- Policies and Procedures and Documentation Standards
- Overview:†An overview of the rule and rule requirements including entities and individuals the rule applies to.
- Definitions:†A review of rule definitions including violations, compliance, definition of agent, resolution processes and HHS enforcement powers.
American Recovery and Reinvestment Act of 2009 (ARRA), Title XIII - HITECH
A general overview of Title XIII health information technology (HIT) incentives and requirements provisions.† This discussion focuseson an overview of the role of privacy and security in HIT investment provisions and standards development.
American Recovery and Reinvestment Act of 2009 (ARRA), Title XIII, Subtitle D¬†- HITECH
- Privacy Provision Overview :†Overview of the privacy provisions included in the ARRA and the relationship to the HIPAA Administrative Simplification Title provisions.
Click on Following Links for more details on course:
HIPAA Privacy Training (Level 1) class schedule
HIPAA Privacy Training (Level 1) course overview
Register for HIPAA Privacy Training (Level 1)
HIPAA Training Testimonials
We can skillfully assist you in determining your readiness for accelerated training, and the best HIPAA training course based on your Job role.
Please contact us for more information at Bob@hipaatraining.net or call (515) 865-4591.