What does PHI stand for?
Protected Health Information
At what age must the client give written consent to disclose SUD treatment information?
14
Who can be held responsible for a HIPAA Breach?
The organization as well as the individual whom committed the breach?
What forms of PHI are protected by HIPAA?
Paper, Electronic and Verbal
What is the standard for accessing patient information?
Only access the minimum necessary information needed for the performance of your job.
Who does a HIPAA Breach Affect
The Client, The employee & The organization
Access to PHI is determined by:
Your role in the organization.
When are you authorized to access a co-workers medical record?
When you are directly involved in their care.
How much time do we have to notify a client they have been affected by a breach?
60 Days
EVERYONE! Breaches or Potential Breaches should be reported immediately by whoever discovers the incident.
What must be done if a breach affects greater than 500 people
Notify the OCR within 60 days and release a public statement regarding the breach
Physical, Technical & Administrative
What are exceptions to needing authorization?
Court Orders, addressing public health issues, or reporting Abuse/Neglect
How can a breach be reported
Immediately tell a supervisor/manager, director or the privacy officer or submit an RL 6