Editor’s note: This text-based course is an edited transcript of the webinar, HIPAA for Allied Health Professionals, presented by Kim Cavitt, AuD.
Learning OutcomesAfter this course, participants will be able to:
List the main components of HIPAA.List the 18 pieces of protected health information.Identify specifics of the Privacy Rule and explain how it applies to texting, email, and marketing in a healthcare setting.Components of HIPAAHIPAA was a bipartisan piece of legislation in the Clinton administration. HIPAA stands for the Health Insurance Accountability and Portability Act of 1996. The main website for HIPAA information is https://www.hhs.gov/hipaa/, but you will see specific links in this presentation (copy and paste them into your browser) that will direct you to additional information typically from Health and Human Services in the Office of Civil Rights, specifically related to the government and HIPAA. As links often change, please search from the main website previously listed if the link doesn't work.
After 2013, HIPAA has civil and criminal penalties and addresses the following:
Standard Transaction and Code SetsNational Provider IdentifierNational Employer IdentifierHIPAA 5010SecurityHITECH (Breach Notification)PrivacyMarketingBusiness AssociatesThe first thing to think about regarding HIPAA is, are you a covered entity under HIPAA? A general rule of thumb is if you transmit any information electronically, then you are subject to HIPAA rules. You are a covered entity anytime you're submitting a claim to a third-party entity or submitting health information or medical records to a third party.
Standard Transaction and Code SetsLet's start with standard transaction code sets. HIPAA requires that all covered entities use standard transaction and code sets such as CPT (Current Procedural Terminology), ICD 10 (International Classification of Diseases, 10th revision), or HCPCS (Healthcare Common Procedure Coding System), which are the codes for hardware and the services surrounding the hardware or the pharmaceutical (or that type of entity). These are the code sets that you're supposed to follow.
National Provider Identifier (NPI)Your national provider identifier (NPI) is your unique personal identification number that is now going to follow you for your entire career. That is given out by the national plan and provider enumeration system, or NPPES. You can go to their website at https://nppes.cms.hhs.gov/#/ to get an NPI or look up an NPI, especially if you need it to go out on a claim. Just like the NPI, this number moves with a provider from employer to employer throughout their career. If you submit the information correctly the first time, a new NPI number is usually generated in one to three hours.
National Employer IdentifierThe next item is the national employer identifier (EIN). The EIN is a unique number that's assigned to your business by the Internal Revenue Service. It's oftentimes also known as your tax identification number. Every business has an EIN except for businesses that are sole proprietors, where the business is operating under the social security number of the owner. Your practice or organization needs an organizational NPI. Remember, the NPI is going to be given out by the NPPES system and the EIN is going to be given out by the IRS.
HIPAA 5010HIPAA 5010 was a systems update that went into effect in 2012. This change allowed for the additional characters of ICD 10 and really affected office management systems, electronic health record systems, electronic medical record systems, software vendors, and clearinghouses. Also, this is where they made the switch from working in a CMS 1500 format, where the electronic format mirrored the form, to working in a format now that's called an 837P format.
The 837 claims submission format was set forth by HIPAA 5010. You should ask your office management vendor or electronic health system (EMR) vendor how your system operates. Many systems, except for certified EHRs, still operate in a 1500 format. Your clearinghouse is doing the conversion to the 837 format. The CMS 1500 format is everything around the paper form that's read, including its electronic version. If your system operates in the 1500 format, or you're still using paper, everything is going to be converted to an 837, either at your clearinghouse or the payer.
Protected Health Information (PHI)Let's talk about the 18 pieces of protected health information. All 18 pieces are equally protected. That means that they cannot be shared without the patient's authorization except for three exceptions, which we'll talk about in a moment.
NamesStreet number and name, city, and last two digits of the zip codeDates directly related to the individual (birthdate)Phone numberFax numberEmail addressSocial security numberMedical record numberHealth insurance member numberAccount numbersCertificate or license numbersVehicle identifiers and serial numbersDevice identifiers and serial numbersURLsIP addressesBiometric indicatorsFinger, retinal, and voiceprintsPhotosAny unique identifying number, characteristic or codeSomeone's first and last names are protected. In my case, Kimberly Cavitt is a piece of protected health information. Your street number, name, city, and last two digits of your zip code are protected. For example, 2480 State St., Chicago, 60 is protected. Any dates directly related to the individual, such as a birthday, are protected. Your phone number, whether cell or landline, and your fax number are protected. Your email address and social security number are also PHI. I want to really reiterate here that someone's name is equally protected as their social security number. Your medical record number, health insurance member number, account number, certificate or license number, and vehicle identifiers or serial numbers are protected as well.
Any device identifiers or serial numbers are included as PHI. If your patient has hardware, such as a hearing aid or an augmentative communication device, that has a serial number and that number is uniquely assigned to that patient, that serial number is protected. In addition, URLs, IP addresses, and biomedical indicators including finger, retinal, and voiceprints are protected. I cannot stress enough that a patient's image is protected. Before you put a video with a patient on social media, you really need to make sure that you get the patient's authorization to use their image. Again, any unique identifier number, characteristic, or code is also protected.
HIPAA Security RuleThe Security Rule is an extension of the Privacy Policy and went into effect on April 20, 2005. HIPAA security is about protecting the electronic formats that are controlling patient information. Electronic patient health information is called ePHI. HIPAA security is around ePHI and everything that you store. When it comes to security, you have to think about everything in your office that stores or transmits patient information. Providers need to have administrative safeguards, physical safeguards, and technical safeguards. You also need written policies and procedures related to these security provisions. In addition, you need to document how people have been trained and what your audit and sanction processes are in your security policies. We're going to break this down a little bit.
Risk AssessmentThe first thing you need to do is a risk assessment. What do allied health professionals need to think about when they're thinking about HIPAA? You need to think about computers, phones, tablets, fax machines, and answering machines. Remember, a patient's voice and any protected health information they've shared on an answering machine are protected and you need to go through a risk assessment on it. Also think about any test equipment that stores or transmits ePHI as well as your EHR, EMR, and OMS vendors because they have access to your information. While NOAH is unique to audiology, it would also be included in this list. You need policies around anything that is storing or transmitting information and how that information is being protected.
Administrative SafeguardsThe first step is administrative safeguards. What do you have in place to reduce the risk of breaches of protected health information that is stored electronically? What policies and procedures do you have? Every practice needs a security officer. You need to know who is responsible for the securitization of this ePHI. If we are talking about a hospital or large clinic, you probably have a security officer that is the head of IT or the CIO at your entity or facility. Those of you in private practice or nonprofit, you are going to need to assign someone as your security officer. If you have a practice manager in a bigger entity, they or the executive director of a nonprofit would be your security officer. If it's an ownership of a private practice, it's typically the owner that is the security officer.
All the security officers and every facility need to regulate who has access to protected health information and by what means. For example, what equipment can they access PHI on? Can they use personal devices or access the PHI at home? Can every employee access it or do some folks have more access than others? It's all about minimally necessary access. You need to look at each one of your staff members and determine for that position, how, where, and when can they access electronic protected health information. You need training and accountability. You should authorize and document either by individual name or by position who has access to ePHI including where, when, and how. You need to train staff on these policies and procedures once they're created. Audit your staff to make sure you're following the policies and sanction staff who do not comply. That sanction has to be documented. I strongly recommend that you have a process of sanctioning that's outlined in your HR materials including employee manuals. It can include firing or termination.
Physical SafeguardsPhysical safeguards are...
HIPAA for Allied Health Professionals
May 13, 2022
Share:
Related Courses
1
/counseling/ceus/course/hipaa-for-allied-health-professionals-1168
HIPAA for Allied Health Professionals
This course reviews the foundations of HIPAA privacy, security, breach notification, and marketing requirements and guidelines. HIPAA requirements and considerations for telehealth are also covered.
auditory, textual, visual
99
USD
Subscription
Unlimited COURSE Access for $99/year
OnlineOnly
Continued Counseling
www.continued.com/counseling
HIPAA for Allied Health Professionals
This course reviews the foundations of HIPAA privacy, security, breach notification, and marketing requirements and guidelines. HIPAA requirements and considerations for telehealth are also covered.
1168
Online
PT60M
HIPAA for Allied Health Professionals
Presented by Kim Cavitt, AuD
Course: #1168Level: Introductory1 Hour
ASWB ACE/1.0 General; CA (CAADE)/1.0; CA (CADTP)/1.0; CA (CCAPP-EI)/1.0; CE Broker/1.0 Professional Responsibilities, Client/counselor Therapeutic Relationship, CE Broker #20-924064; CE Hours/1.0; CT (CCB)/1.0; GA (ADACBGA)/1.0; IACET/0.1; MO (MCB)/1.0; NAADAC/1.0 Documentation And Record-keeping, Legal Ethical And Professional Development; NBCC CE Hours/1.0; NY-Contact Hours/1.0 Self-Study; OH (OCDP)/1.0 TR1; OK (LPC/LMFT)/1.0; OK (OBLADC)/1.0
This course reviews the foundations of HIPAA privacy, security, breach notification, and marketing requirements and guidelines. HIPAA requirements and considerations for telehealth are also covered.
2
/counseling/ceus/course/creating-psychological-safety-in-workplace-1024
Creating Psychological Safety in the Workplace
Creating Psychological Safety is a course that focuses on fostering a mentally and emotionally safe environment in the workplace. This course will teach the audience what psychological safety is, how to implement it, and what to do to help their colleagues and associates feel psychologically safe at work.
auditory, textual, visual
99
USD
Subscription
Unlimited COURSE Access for $99/year
OnlineOnly
Continued Counseling
www.continued.com/counseling
Creating Psychological Safety in the Workplace
Creating Psychological Safety is a course that focuses on fostering a mentally and emotionally safe environment in the workplace. This course will teach the audience what psychological safety is, how to implement it, and what to do to help their colleagues and associates feel psychologically safe at work.
1024
Online
PT60M
Creating Psychological Safety in the Workplace
Presented by Taeler Hammond, MA
Course: #1024Level: Intermediate1 Hour
CA (CAADE)/1.0; CA (CADTP)/1.0; CA (CCAPP-EI)/1.0; CE Broker/1.0 Counseling Techniques, Community Utilization, Industrial-Organizational Psychology, CE Broker #20-1100722; CE Hours/1.0; CT (CCB)/1.0; GA (ADACBGA)/1.0; IACET/0.1; MO (MCB)/1.0; NAADAC/1.0 Counseling Services, Legal Ethical And Professional Development; NBCC CE Hours/1.0; NY-Contact Hours/1.0 Self-Study; OH (OCDP)/1.0 , TR1, S3; OK (LPC/LMFT)/1.0; OK (OBLADC)/1.0
Creating Psychological Safety is a course that focuses on fostering a mentally and emotionally safe environment in the workplace. This course will teach the audience what psychological safety is, how to implement it, and what to do to help their colleagues and associates feel psychologically safe at work.
3
/counseling/ceus/course/exposure-with-response-prevention-for-1792
Exposure with Response Prevention (ERP) for Obsessive Compulsive Disorder (OCD)
For generalists, the ability to effectively recognize OCD and know when to refer when it is outside the scope of what they are able to provide is an essential skill. This course will help clinicians both build confidence in recognizing and diagnosing OCD as well as develop essential tools for understanding evidence-based practice for treating OCD. The training will discuss the ethics of providing different modalities with OCD, as well as support the clinician's capacity for recognizing the symptom presentation. The training will also support clinicians in working functionally rather than becoming entrenched in content, a vital skill for any clinician.
auditory, textual, visual
99
USD
Subscription
Unlimited COURSE Access for $99/year
OnlineOnly
Continued Counseling
www.continued.com/counseling
Exposure with Response Prevention (ERP) for Obsessive Compulsive Disorder (OCD)
For generalists, the ability to effectively recognize OCD and know when to refer when it is outside the scope of what they are able to provide is an essential skill. This course will help clinicians both build confidence in recognizing and diagnosing OCD as well as develop essential tools for understanding evidence-based practice for treating OCD. The training will discuss the ethics of providing different modalities with OCD, as well as support the clinician's capacity for recognizing the symptom presentation. The training will also support clinicians in working functionally rather than becoming entrenched in content, a vital skill for any clinician.
1792
Online
PT60M
Exposure with Response Prevention (ERP) for Obsessive Compulsive Disorder (OCD)
Presented by Mandy Simmons, PsyD
Course: #1792Level: Introductory1 Hour
ASWB ACE/1.0 General; CA (CAADE)/1.0; CA (CADTP)/1.0; CA (CCAPP-EI)/1.0; CE Broker/1.0 Counseling Techniques, Knowledge Of Psychiatric Factors, Initiation Of Treatment, CE Broker #20-1243428; CE Hours/1.0; CT (CCB)/1.0; GA (ADACBGA)/1.0; IACET/0.1; MO (MCB)/1.0; NAADAC/1.0 Clinical Intake And Screening, Clinical Assessment, Treatment Plan, Counseling Services; NBCC CE Hours/1.0; NY-Contact Hours/1.0 Self-Study; OH (OCDP)/1.0 C2, C4; OK (LPC/LMFT)/1.0; OK (OBLADC)/1.0
For generalists, the ability to effectively recognize OCD and know when to refer when it is outside the scope of what they are able to provide is an essential skill. This course will help clinicians both build confidence in recognizing and diagnosing OCD as well as develop essential tools for understanding evidence-based practice for treating OCD. The training will discuss the ethics of providing different modalities with OCD, as well as support the clinician's capacity for recognizing the symptom presentation. The training will also support clinicians in working functionally rather than becoming entrenched in content, a vital skill for any clinician.
4
/counseling/ceus/course/grief-in-family-systems-1281
Grief in Family Systems
Grief is a process and it impacts families in various ways. This webinar explores the impact of loss and grief on family systems.
auditory, textual, visual
99
USD
Subscription
Unlimited COURSE Access for $99/year
OnlineOnly
Continued Counseling
www.continued.com/counseling
Grief in Family Systems
Grief is a process and it impacts families in various ways. This webinar explores the impact of loss and grief on family systems.
1281
Online
PT60M
Grief in Family Systems
Presented by Tami J. Micsky, DSW, MSSA, LSW, CT
Course: #1281Level: Introductory1 Hour
ASWB ACE/1.0 General; CA (CAADE)/1.0; CA (CADTP)/1.0; CA (CCAPP-EI)/1.0; CE Broker/1.0 Counseling Theories, Counseling, CE Broker #20-936038; CE Hours/1.0; CT (CCB)/1.0; GA (ADACBGA)/1.0; IACET/0.1; MO (MCB)/1.0; NAADAC/1.0 Counseling Services; NBCC CE Hours/1.0; NY-Contact Hours/1.0 Self-Study; OH (OCDP)/1.0 C5; OK (LPC/LMFT)/1.0; OK (OBLADC)/1.0
Grief is a process and it impacts families in various ways. This webinar explores the impact of loss and grief on family systems.
5
/counseling/ceus/course/introduction-to-body-focused-repetitive-1793
Introduction to Body-Focused Repetitive Behaviors
This course will provide foundational knowledge for the assessment, diagnosis, and treatment of body-focused repetitive behaviors (BFRB), the often overlooked, much stigmatized cousin of Obsessive Compulsive Disorder (OCD). This course will address common misconceptions about BFRBs, as well as support clinicians in enhancing their clinical skills in the diagnosis and treatment of BFRBs by discussing the use of habit reversal training, functional behavioral analysis, and the Comprehensive Behavioral Model (ComB), developed by Charles Mansueto.
auditory, textual, visual
99
USD
Subscription
Unlimited COURSE Access for $99/year
OnlineOnly
Continued Counseling
www.continued.com/counseling
Introduction to Body-Focused Repetitive Behaviors
This course will provide foundational knowledge for the assessment, diagnosis, and treatment of body-focused repetitive behaviors (BFRB), the often overlooked, much stigmatized cousin of Obsessive Compulsive Disorder (OCD). This course will address common misconceptions about BFRBs, as well as support clinicians in enhancing their clinical skills in the diagnosis and treatment of BFRBs by discussing the use of habit reversal training, functional behavioral analysis, and the Comprehensive Behavioral Model (ComB), developed by Charles Mansueto.
1793
Online
PT60M
Introduction to Body-Focused Repetitive Behaviors
Presented by Mandy Simmons, PsyD
Course: #1793Level: Introductory1 Hour
ASWB ACE/1.0 Clinical; CA (CAADE)/1.0; CA (CADTP)/1.0; CA (CCAPP-EI)/1.0; CE Broker/1.0 Counseling Theories, Knowledge Of Psychiatric Factors, CE Broker #20-1248524; CE Hours/1.0; CT (CCB)/1.0; GA (ADACBGA)/1.0; IACET/0.1; MO (MCB)/1.0; NAADAC/1.0 Counseling Services; NBCC CE Hours/1.0; NY-Contact Hours/1.0 Self-Study; OH (OCDP)/1.0 TR1; OK (LPC/LMFT)/1.0; OK (OBLADC)/1.0
This course will provide foundational knowledge for the assessment, diagnosis, and treatment of body-focused repetitive behaviors (BFRB), the often overlooked, much stigmatized cousin of Obsessive Compulsive Disorder (OCD). This course will address common misconceptions about BFRBs, as well as support clinicians in enhancing their clinical skills in the diagnosis and treatment of BFRBs by discussing the use of habit reversal training, functional behavioral analysis, and the Comprehensive Behavioral Model (ComB), developed by Charles Mansueto.