It is important to note that our HIPAA Privacy Training program is tailored to the HIPAA Privacy Rule training requirements necessary to train all covered entities that are required to adhere to procedures and policies related to the confidentiality of PHI. The HIPAA privacy training program will help you and provide necessary guidance on factors pertaining to HIPAA rules and regulations and how you or your entity can be HIPAA compliant. Our HIPAA training comprises updates on the HIPAA regulation which is a result of the Health Information Technology for Economic and Clinical Health Act (HITECH) which forms a part of the American Recovery and Reinvestment Act of 2009 (ARRA) and Omnibus rule published in 2013.
Total Cost: $1500
HIPAA Privacy Training – Day 1
- HIPAA Basics: An overview of the Health Insurance Portability and Accountability Act of 1996 (all provisions)
- HIPAA’s Administrative Simplification Title: Review of the provisions of the Administrative Simplification Title. This includes transaction and code set standards (administrative transactions), national identifiers, privacy requirements, and security requirements.
- HIPAA Penalties: Review of the HIPAA enforcement rule including informal and formal remedies, requirements of Covered Entities, the role of business Associates as agents and enforcement bodies.
- HIPAA-Related Organizations: Discussion of entities/organizations specifically designated as standard maintenance organizations and statutorily defined advisory bodies.
- HIPAA Terminology and Definitions Covered Entity: Review of definitions included in the
Administrative Simplification Title-related rules.
- Covered Entity
- Health Plan
- Health Care Provider
- Business Associates
- Trading Partner Agreement
- Organized Health Care Arrangement
HIPAA Transactions, Code Sets, and Identifiers
- Impacted Health Care Transactions
- Target Entities
ANSI ASC X12 Standard
- Transaction Type 270
- Transaction Type 271
- Transaction Type 276
- Transaction Type 277
- Transaction Type 278 Request and Response
- Transaction Type 820
- Transaction Type 834
- Transaction Type 835
- Transaction Type 837 – Professional
- Transaction Type 837 – Institute
- Transaction Type 837 – Dental
HIPAA Code Sets
- ICD-9-CM Volumes 1 and 2
- ICD-9-CM Volume 3
HIPAA National Health Care Identifiers
- Provider Identifier
- Employer Identifier
- Health Plan Identifier
- Individual Identifier
HIPAA Privacy Rule Part 1
- Introduction: Overview of the HIPAA Privacy Rule
- Who is Impacted (e.g., the definition of Covered Entities, Business Associates)?
- Scope (Activities covered by the rule)
- Exceptions (Specifically included or referenced exceptions that allow use and disclosure of patient/health plan member protected health information (PHI))
- Timeline (Effective date of the rule, timelines related to certain requirements identified in the privacy rule such as accounting of disclosures, document retention requirements, etc.)
- Key Definitions: Review of key definitions associated with the Privacy Rule and how they apply to rule application and compliance.
- Deidentified Information
- Health Care Operations
- Notice Requirement: Review of the requirements to draft and make available a notice of privacy practices, the content of such notice, revision requirements, and availability requirements.
- Core Elements
- Changes to a Notice
- First Interaction
- Authorization versus Consent Requirement: Review the legal definitions of consent and authorization and what they would be used for. Review of the legal requirements related to obtaining authorization, the form of such authorization, and content requirements.
- Definition of “consent”
- Definition of “authorization”
- Legal differences between “consent” and “authorization”
- Core Data Elements and Required Statements
- Defective Authorizations
- Key Parties Impacted: A discussion of all entities or individuals directly or indirectly impacted by the rule and why.
- Minimum Necessary: Discussion of the definition of the minimum necessary and when it applies to the use and disclosure of PHI (internally and externally)
- Oral and Other Non-electronic Communications: A discussion of what constitutes PHI pursuant to the rule and the related requirements to protect non-electronic PHI, including oral PHI.
- Health-Related Communications, Fund Raising, and Marketing: Review of the requirements related to the use of PHI for communications other than treatment, payment, and health care operations. Also, a review of the strict requirements relating to the use of PHI for marketing and fundraising.
- Research: A review of the requirements related to the use of PHI for research including what processes must be followed prior to allowing the use of PHI in research without the patient/health plan member’s authorization.
HIPAA Privacy Training – Day 2 Privacy
HIPAA Privacy Rule Part 2
- Policy & Training Requirements: A review of the implied and explicit requirements to develop, implement and maintain privacy policies and procedures and the requirement to provide initial and ongoing staff training.
- Preemption Requirements: A review of state law preemption. This includes a discussion regarding when state law may preempt the rule without specific authorization from the US Department of Health and Human Services (HHS) and when authorization is required prior to state law preemption of HIPAA.
- State Privacy Laws: A general review of state privacy laws that preempt HIPAA (categorized as specially protected health information) with specific reference to select California state laws.
- Federal Privacy Law – 42 CFR Pt. 2: A discussion of the more stringent requirements found in 42 CFR Pt. 2 relating to alcohol and chemical dependency
- Statutory/Rule Conflict Resolution: Discussion of how to respond when federal and/or state law conflicts.
- Case Law: A review of general case law that has impacted the application of HIPAA, state privacy laws, and impacts legal risks.
HIPAA Security Rule Part 1
- Threats: General review of threats (real and perceived) prompting Congress to include security requirements in the HIPAA Administrative Simplification Title.
- Definition and Terminology: Review of general definitions of security and specifically how those definitions apply to the rule and what data must be protected by the implementation of appropriate security measures.
- Security Services
- Security Mechanism
- Security Rules: Detailed review of the security rule, components of the security rule, and specific requirements (including a reference back to security requirements referenced in the HIPAA Privacy Rule).
- Categories of Safeguards
- Implementation Specifications
- Approach and Philosophy
- Security Principles
- Administrative Safeguards
- Physical Safeguards
- Technical Safeguards
- Organizational Requirements
- Policies and Procedures, and Documentation Standards
- Overview: This is normally an overview of the HIPAA rule and its requirements which include individuals and entities subject to it.
- Definitions: It comprises of reviews on rule definitions including what is; a violation, to be HIPAA compliant, the definition of an agent, HHS enforcement powers, and resolution processes.
American Recovery and Reinvestment Act of 2009 (ARRA), Title XIII – HITECH
This is the general overview of the required provisions and incentives of Title XIII Health Information Technology (HIT). The overview is meant to cover the role of security and privacy in investment provisions and the development of standards of HIT.
American Recovery and Reinvestment Act of 2009 (ARRA), Title XIII, Subtitle D – HITECH
- Privacy Provision Overview: This should be a brief introduction to the privacy provisions which are part of ARRA and their relationship to HIPAA Administrative Simplification Title provisions.
Omnibus Rule of January 2013
- Breach Notification Rule
- New Limits on Uses and Disclosures of PHI
- Business Associates
- Increased Patient Rights
- Notice of Privacy Practices
- Increased Enforcement
If you need additional information for this course, contact us at Bob@supremusgroup.com or call (515) 865-4591.