Material: HIPAA Compliance Manual
Our HIPAA Online Training with Instructor level 1 & 2 course will help key compliance team members to be compliant with HIPAA job role based training requirement. Our training will help you to understand the HIPAA law requirement for Privacy and Security rule and guide you on how to make your organization HIPAA compliant. As this course is delivered on 1 to 1 basis, the course can be customized to meet your training objectives. We are flexible with the course outline and focus on specific area as per your needs. Our HIPAA Instructors are HIPAA consultants who help organizations meet the HIPAA audit checklist requirements issued by the DHHS. Our Training includes changes to the HIPAA regulations due to Health Information Technology for Economic and Clinical Health (HITECH) Act which is part of American Recovery and Reinvestment Act of 2009 (ARRA) and Omnibus rule published in 2013.
Training schedule for this HIPAA course is flexible, at can be completed in 4 full days OR few hours daily depending on your schedule and needs. Our HIPAA Instructor will contact you to finalize the training dates and time.
HIPAA Compliance Training: Online With Instructor - Day 1
- HIPAA Basics: An overview of the Health Insurance Portability and Accountability Act of 1996 (all provisions)
- HIPAA’s Administrative Simplification Title: Review of the provisions of the Administrative Simplification Title. This includes transaction and code set standards (administrative transactions), national identifiers, privacy requirements and security requirements.
- HIPAA Penalties: Review of the HIPAA enforcement rule including informal and formal remedies, requirements of covered entities, the role of business associates as agents and enforcement bodies.
- HIPAA-Related Organizations: Discussion of entities/organizations specifically designated as standard maintenance organizations and statutorily defined advisory bodies.
- HIPAA Terminology and Definitions Covered Entity: Review of definitions included in the
Administrative Simplification Title related rules (list not inclusive)
- Covered Entity
- Health Plan
- Health Care Provider
- Business Associates
- Trading Partner Agreement
- Organized Health Care Arrangement
HIPAA Transactions, Code Sets and Identifiers
ANSI ASC X12 Standard
- Impacted Health Care Transactions
- Target Entities
HIPAA Code Sets
- Transaction Type 270
- Transaction Type 271
- Transaction Type 276
- Transaction Type 277
- Transaction Type 278 Request and Response
- Transaction Type 820
- Transaction Type 834
- Transaction Type 835
- Transaction Type 837 - Professional
- Transaction Type 837 - Institute
- Transaction Type 837 - Dental
HIPAA National Health Care Identifiers
- ICD-9-CM Volumes 1 and 2
- ICD-9-CM Volume 3
- Provider Identifier
- Employer Identifier
- Health Plan Identifier
- Individual Identifier
HIPAA Compliance Training: Day 2 Privacy
HIPAA Privacy Rule Part 1
- Introduction: Overview of the HIPAA Privacy Rule
- Who is Impacted (e.g., definition of covered entities, business associates)?
- Scope (Activities covered by the rule)
- Exceptions (Specifically included or referenced exceptions that allow use and disclosure of patient/health plan member protected health information (PHI)
- Timeline (Effective date of the rule, timelines related to certain requirements identified in the privacy rule such as accounting of disclosures, document retention requirements, etc.)
- Key Definitions: Review of key definitions associated with the privacy rule and how they apply to rule application and compliance.
- Deidentified Information
- Health Care Operations
- Notice Requirement: Review of the requirements to draft and make available a notice of privacy practices, the content of such notice, revision requirements and availability requirements.
- Core Elements
- Changes to a Notice
- First Interaction
- Authorization versus Consent Requirement: Review the legal definitions of consent and authorization and what they would be used for. Review of the legal requirements related to obtaining authorization, the form of such authorization and content requirements.
- Definition of “consent”
- Definition of “authorization”
- Legal differences between “consent” and “authorization”
- Core Data Elements and Required Statements
- Defective Authorizations
- Key Parties Impacted: A discussion of all entities or individuals directly or indirectly impacted by the rule and why.
- Minimum Necessary: Discussion of the definition of minimum necessary and when it applies to the use and disclosure of PHI (internally and externally)
- Oral and Other Non-electronic Communications: A discussion of what constitutes PHI pursuant to the rule and the related requirements to protect non-electronic PHI, including oral PHI.
- Health-Related Communications, Fund Raising and Marketing: Review of the requirements related to the use of PHI for communications other than treatment, payment and health care operations. Also, a review of the strict requirements relating to the use of PHI for marketing and fund raising.
- Research: A review of the requirements related to the use of PHI for research including what processes must be followed prior to allowing the use of PHI in research without the patient/health plan member’s authorization.
HIPAA Privacy Rule Part 2
- Policy & Training Requirements: A review of the implied and explicit requirements to develop, implement and maintain privacy policies and procedures and the requirement to provide initial and on-going staff training.
- Preemption Requirements: A review of state law preemption. This includes a discussion regarding when state law may preempt the rule without specific authorization from the US Department of Health and Human Services (HHS) and when authorization is required prior to state law preemption of HIPAA
- State Privacy Laws: A general review of state privacy laws that preempt HIPAA (categorized as specially protected health information) with specific reference to select California state laws.
- Federal Privacy Law – 42 CFR Pt. 2: A discussion of the more stringent requirements found in 42 CFR Pt. 2 relating to alcohol and chemical dependency
- Statutory/Rule Conflict Resolution: Discussion of how to respond when federal and/or state law conflicts.
- Case Law: A review of general case law that has impacted the application of HIPAA, state privacy laws and impacts legal risks.
HIPAA Compliance Training: Day 3 Security
HIPAA Security Rule Part 1
- Threats: General review of threats (real and perceived) prompting Congress to include security requirements in the HIPAA Administrative Simplification Title.
- Definition and Terminology: Review of general definitions of security and specifically how those definitions apply to the rule and what data must be protected by implementation of appropriate security measures.
HIPAA Security Rule Part 1
- Security Services
- Security Mechanisms
- General (continued):
- Security Rules: Detailed review of the security rule, components of the security rule and specific requirements (including reference back to security requirements referenced in the HIPAA Privacy Rule).
- Categories of Safeguards
- Implementation Specifications
- Approach and Philosophy
- Security Principles
- Administrative Safeguards
- Physical Safeguards
- Technical Safeguards
- Organizational Requirements
- Policies and Procedures, and Documentation Standards
- Administrative Safeguards: Definition of “administrative safeguards” as they relate to security and the rule. A review of required administrative safeguards and their application within a covered entity and business associate.
- Administrative Safeguards
- Security Management Process
- Assigned Security Responsibility
- Workforce Security
- Information Access Management
- Security Awareness and Training
- Security Incident Procedures
- Contingency Plan
- Business Associate Contracts Standard
- Physical Safeguards: Definition of “physical safeguards” as they relate to security and the rule. A review of required physical safeguards and their application within a covered entity and business associate.
- Facility Access Controls
- Workstation Use
- Workstation Security
- Device and Media Controls
- Physical Safeguards Review
HIPAA Security Rule Part 1
- Technical Safeguards (general): Definition of “technical safeguards” as they relate to security and the rule. A review of required technical safeguards and their application within a covered entity and business associate.
- Access Control
- Audit Controls
- Person or Entity Authentication
- Security Compliance process: Risk Analysis, Vulnerability Assessment, Remediation, Contingency Planning, Audit & Evaluation
- Transmission Security
- Technical Safeguards (technical details): A review of required technical safeguards including a more technical review of required or addressable safeguards, implementation and on-going maintenance.
- TCP/IP Network Infrastructure
- Firewall Systems
- Virtual Private Networks (VPNs)
- Wireless Transmission Security
- Overview of Windows XP and Vista Security
HIPAA Compliance Training: Day 4 Security, Enforcement Rule & ARRA 2009
HIPAA Security Rule Part 2
- Digital Signatures & Certificates: A review of the use of higher forms of individual or entity authentication that is quickly becoming a requirement legally and to reduce legal risk.
- Digital Signatures
- Digital Certificates
- Public Key Infrastructure (PKI)
- Solution Alternatives
- Identity theft prevention and HIPAA
- Security Policy A review of the requirements to document security program practices and processes in policy and related workforce training requirements. Also a review of required policy maintenance and retention.
- Risks, Risk Management and Policy Development/Implementation
- General Security Standards Impact on Policy Development
- Policy Training Requirements
- Security Policy Considerations
- Overview: An overview of the rule and rule requirements including entities and individuals the rule applies to.
- Definitions: A review of rule definitions including (not inclusive) what represents a violation, compliance, definition of agent, resolution processes and HHS enforcement powers.
- Informal resolution process: A discussion of what an informal resolution is and what it entails. Also, a review of the rule’s emphasis on informal resolution and language allowing such resolution at any phase of violation investigation, penalty assessment and appeal.
- Formal resolution process (i.e., penalties, administrative hearings, appeal process, etc.): A discussion of what would likely trigger a formal resolution process, HHS requirements and authority to investigate, rights and responsibilities of covered entities and resulting actions if civil penalties are levied and paid by the covered entity.
- Compliance audits: A discussion of the authority to conduct compliance audits, current audit activity and prospective audit activity.
Identity Theft Protection Laws
A general review of existing identity theft protection laws and breach notification requirements. Includes specific discussion of California identity theft and medical identity theft protection laws.
American Recovery and Reinvestment Act of 2009 (ARRA), Title XIII
A general overview of Title XIII health information technology (HIT) incentives and requirements provisions. This discussion will focus on an overview of the role of privacy and security in HIT investment provisions and standards development.
American Recovery and Reinvestment Act of 2009 (ARRA), Title XIII, Subtitle D
- Privacy Provision Overview: Overview of the privacy provisions included ARRA and the relationship to the HIPAA Administrative Simplification Title provisions.
American Recovery and Reinvestment Act of 2009 (ARRA), Title XIII, Subtitle D
- Business Associates – New Requirements: A discussion of business associates’ new requirement to statutorily adhere to the provisions of the HIPAA Administrative Simplification Title Privacy and Security Rules. The discussion includes a review of the timeline for compliance and the implications for business associates.
- National Identity Theft Protection Provisions: A discussion of the requirements of the new identity theft protection provisions, what is considered a breach or inappropriate disclosure, breach notification requirements and entities/individuals covered. Discussion also includes new reporting requirements by entity/individual, HHS and the Federal Trade Commission (FTC).
- Marketing Prohibitions and Restrictions: An overview of the enhanced restrictions related to the use and disclosure of PHI where the entity or individual is paid for such use and disclosure and stricter prohibitions against using PHI for marketing purposes.
- Enforcement Provisions: A discussion of the new enforcement provisions, entities/individuals covered and how such enforcement relates to the HIPAA Enforcement Rule and current compliance audits. The discussion also includes a discussion of changes in penalties and the addition of a newly defined criminal act (formerly a civil violation).
- Reporting Requirements: A discussion of new requirements for the reporting of breaches to HHS and/or the FTC and annual reports relating to compliance, rule violations, breaches, etc. to Congress and the public.
Red Flag Rules
With identity theft and other problems on the increase, additional effort needed to be made to combat this new avenue of fraud against healthcare. With so much information available and in the hands of some many people delivering care, processing payment, and handling the operational and regulatory uses of this information, it was inevitable that healthcare would become a target for exploitation. Changes to the law has helped, and this chapter covers the following topics to better protect your information resources:
HIPAA Solutions – Parts 1 & 2
- Red Flag Rule Overview
- Definition of “red flags” and how to spot them
- State Identity Theft Protection Laws & ARRA Breach Notification Requirements
- Identity Theft Protection Program Requirements
- Implementation Tips
One of the cornerstones of a successful HIPAA security
program is the performance of a risk analysis and the
creation of a risk management program. These two chapters
will walk you through a program of risk analysis and show
your how to perform one that focuses on the specific areas
that HIPAA requires. You will learn techniques to set a
severity scale that is specific to your organization;
evaluate and compare risk elements against it; identify
and quantify your assets; clarify threats and
vulnerabilities that can compromise those assets; develop
a strategy to protect against those threats that is both
operationally effective and economically efficient. When
you complete this section, you will be ready to help get
your organization compliant now, and keep it that way into
Meaningful Use is one of the hottest current topics in
Healthcare. In stages, the Meaningful Use program lays out
a series of accomplishments and metrics that over time
lead to achieving the objective of securely automating
healthcare institutions and providers. In addition to
having a program of steps over the years of 2011-2016, the
US Government has outlined a financial incentive program
to further encourage participation and compliance, and
reduce the impact of this pervasive change. This module
- ARRA & Meaningful Use Rule Overview
- Meaningful Use Requirements – Stage 1 & 2
- Privacy & Security Related Measures
- Meeting Core Requirement 15 (HIPAA Compliance)
- Vendor Requirements
- How to Prepare
Upon completion, the attendee will know what is required,
how it will be measured, and how to achieve and measure
HIPAA Compliance Training: Next Steps
- Discuss compliance process next steps like risk analysis, policy & procedure creation, HIPAA contingency planning and HIPAA audit requirements.
To discuss how we can customize course to meet your business (covered entity, health plan OR business associate) HIPAA training goals, contact Bob Mehta at 515-865-4591 or Bob@training-hipaa.net