Contact Us
Categories
- Part 2
- Data Privacy
- Department of Health and Human Services' Office of Civil Rights
- Medical Malpractice
- Medical Cannabis
- Workplace health
- Workplace Violence
- Assisted Living Facilities
- EMTALA
- FDA
- Reproductive Rights
- Roe v. Wade
- SCOTUS
- COVID-19
- Prescription Drugs
- Telemedicine
- Medical Spas
- Code Enforcement
- Corporate
- United States Department of Justice ("DOJ")
- Employee Contracts
- Non-Compete Agreement
- Compliance
- HIPAA
- Kentucky Board of Nursing
- Managed Care Organizations (“MCOs”)
- Anti-Kickback Statute
- False Claims Act
- KASPER
- Kentucky Board of Medical Licensure
- Kentucky’s Department for Medicaid Services
- Medicaid
- Mental Health Care
- Office for Civil Rights ("OCR")
- Office of Inspector General of the United States Department of Health and Human Services (OIG)
- Physician Assistants
- Primary Care Physicians ("PCPs")
- Qui Tam
- Stark Laws
- Accountable Care Organizations (“ACO”)
- Affordable Care Act
- APRNs
- Centers for Medicare & Medicaid Services (“CMS”)
- Charitable Hospitals
- Data Breach
- Electronic Protected Health Information (ePHI)
- Federally Qualified Health Centers (“FQHCs”)
- Health Information Technology for Economic and Clinical Health Act (HITECH Act)
- Health Insurance Portability and Accountability Act of 1996 (HIPAA)
- Health Professional Shortage Area ("HPSA")
- Hospitals
- HPSA
- HRSA
- Medicare
- Mid-Level Practitioners
- Patient Protection and Affordable Care Act (“ACA”)
- Pharmacists
- Rural Health Centers (“RHCs”)
- Rural Health Clinic
- Telehealth
- Business Associate Agreements
- Fraud
- Overpayments
- Part D
- Appeal
- Compliance Programs
- Electronic Health Records (“EHR")
- ERISA
- Hospice
- Advanced Practice Registered Nurses
- Business Associates
- Denied Claims
- Division of Regulated Child Care
- Employee Agreement
- Fair Labor Standards Act (FLSA)
- Licensed practical nurses (LPN)
- Licensure Requirements
- Nurse practitioners (NP)
- Part A
- Part B
- Patient Autonomy
- Personal Health Information
- Personal Service Entities
- Physician Payments
- Qualified Health Plan ("QHP")
- Registered nurses (RN)
- Abuse and Waste
- Occupational Safety and Health Administration (“OSHA”)
- Department of Health and Human Services (HHS)
- Health Insurance
- Healthcare Regulation
- Health Care Law
McBrayer Blogs
Tools for the Trade: Understanding HIPAA
As a result of the intricate details and requirements of the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), it comes as no surprise that HIPAA Privacy and Security Rules can cause challenges and confusion for even the most sophisticated providers. With this in mind, the U.S. Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) has recently provided tools meant to educate both consumers and providers on HIPAA.
Before OCR published this guidance on HIPAA and HITECH on its website, consumers (i.e. patients) routinely accepted and signed HIPAA Notices of Privacy Practice without understanding what rights HIPAA protects. As a result, OCR aimed to familiarize consumers with their health information privacy and security rights by posting factsheets (available in eight languages) on their website. http://www.hhs.gov/ocr/privacy/hipaa/understanding/consumers/ With this new online guidance, patients may come into a provider’s facility more informed and educated about their privacy rights and may demand greater privacy protections from their provider. Thus, the OCR guidance could potentially change the privacy expectations of patients.
However, consumers are not the only parties that the OCR seeks to educate and inform about HIPAA privacy and security. OCR has also posted lots of informational resources for providers. The OCR offers general information on 16 topics and training materials. http://www.hhs.gov/ocr/privacy/hipaa/coveredentities/index.html. However, the OCR’s educational and informational resources are very general and only provide an overview of certain topics.
For providers in small practices, the OCR created a YouTube video, The HIPAA Security Rule, that provides an overview of how to establish basic security safeguards to protect patient health information. http://www.youtube.com/user/USGovHHSOCR. Additionally, there are three new Medscape modules on HIPAA compliance. http://www.medscape.org. These Medscape modules offer free Continuing Medical Education credits for physicians and other health care professionals. These modules are purely educational and are intended to help providers brush up on HIPAA Privacy and Security Rules. However, it is unclear if these modules will be updated whenever a HIPAA regulation or law changes.
While the factsheets and videos offer valuable guidance, they are not a substitute for legal advice, especially with the changing regulatory and legal environment, and will not apply to all incidents your facility may encounter.
If you need assistance with risk management, compliance, or enforcement of HIPAA, contact the health care attorneys at McBrayer.
Services may be performed by others.
This article does not constitute legal advice.

