Course Overview
Learning Objectives
- HIPAA overview & HIPAA privacy rule
- What is protected health information (phi)
- What information is covered
- What is minimum necessary & when it does not apply
- The notice of privacy practices (npp)
- What is mandatory requirements
- What is use and disclosure of phi
- Required disclosures
- Disclosure of phi for treatment, payment and health care operations (TPO)
- TPO use - Psychotherapy notes
- When authorization not required
- Organizational requirements
- Documentation requirement
- Required policies, procedures & sanctions
- Sanctions
- Individual privacy rights
- When record access can be denied.
- Rights to request amendment
- Privacy breaches
- Business associates & examples
- Other privacy laws, HIPAA & state law
- HIPAA Security rule overview
- Administrative safeguards overview
- Security management process
- Workforce security
- Information access management
- Security awareness and training
- Password management
- Contingency plan
- Additional standards
- Physical safeguards standards
- Facility access controls
- Device and media controls
- Other standards
- Technical safeguards standards
- Access control
- Transmission security
- Remote Access
- Other standards
- Breach Notification
- Organizational requirements
- Business associates contracts
- Other arrangements
- Policy and documentation requirement
- Administrative safeguards overview
- The Omnibus Rule August 2013 (New)
Framework Connections
The materials within this course focus on the NICE Framework Task, Knowledge, and Skill statements identified within the indicated NICE Framework component(s):