<?xml version="1.0"?>
<rss version="2.0">
   <channel>
      <title>Legal Guide: Health Insurance Portability and Accountability by Christene Walker</title>
      <link>https://padlet.com/christenewalker/9fam80swx40g</link>
      <description>EDG 6305
Angelo State University</description>
      <language>en-us</language>
      <pubDate>2019-10-24 20:49:22 UTC</pubDate>
      <lastBuildDate>2026-03-12 04:04:54 UTC</lastBuildDate>
      <webMaster>hello@padlet.com</webMaster>
      <image>
         <url></url>
      </image>
      <item>
         <title>#1: My Professional Perspective</title>
         <author>christenewalker</author>
         <link>https://padlet.com/christenewalker/9fam80swx40g/wish/402294938</link>
         <description><![CDATA[<div>The topic of this legal guide is the Health Insurance Portability and Accountability Act (HIPAA), specifically the Privacy Rule of Title II, as it pertains to regulations for the use and disclosure of an individual's protected health information (PHI). <br><br>My professional perspective is that of a corporate trainer in the insurance industry. I am currently a Claims Coordinator at Blue Cross Blue Shield of Texas, a division of Health Care Service Corporation (HCSC). HCSC operates Blue Cross Blue Shield plans in Illinois, Montana, New Mexico, Oklahoma, and Texas. <br><br>This topic was chosen due to it being the most significant federal and state law in the insurance and health care industries, affecting employees at all levels. <br><br>This legal guide will serve as a resource to other corporate trainers and learning and development specialists to aid in  the understanding of legal requirements at the federal, state, and corporate levels. </div>]]></description>
         <enclosure url="https://padlet-uploads.storage.googleapis.com/278779256/df7fd7177f2ea0438626b76063f78d5a/hcsc2.jpg" />
         <pubDate>2019-10-24 20:53:05 UTC</pubDate>
         <guid>https://padlet.com/christenewalker/9fam80swx40g/wish/402294938</guid>
      </item>
      <item>
         <title>#2: Interview</title>
         <author>christenewalker</author>
         <link>https://padlet.com/christenewalker/9fam80swx40g/wish/402295279</link>
         <description><![CDATA[<div><br>I interviewed Matthew Lawrence, Senior Privacy and Data Security Coordinator at Health Care Service Corporation. <br><br><strong>HIPAA Importance and Training</strong><br>Mr. Lawrence explained that HIPAA privacy is one of the things in U.S. health care that actually works. Individuals seek health care with the expectation that their very personal and sensitive information will be cared for in a way that shows respect. The law also provides remedies for situations where an individual's privacy has not been handled appropriately. HIPAA impacts training at HCSC in two different ways. First, the law requires training, this is actually  in the language of the law. Training must be done and,  because of the personal nature of the information, there is an intangible cultural impact to our organization. Training is not simply conducted to gain access to systems or to check a box on a list, it is a vital part of the customer experience. HCSC trains its employees to treat our members and their information with respect and care. <br><br><strong>Best Practices</strong></div><ul><li>HCSC regularly monitors impermissible use and disclosure issues, breach notifications, physical and technical safeguards, and confidential communications requests.</li><li>HCSC has maintained a conservative approach to privacy and security. As a result, minimal updates are required related to HIPAA itself. Policies are frequently updated per federal, state, and contractual obligations.  HCSC complies with regulations of  the states  where HCSC operates and the states where our members reside.</li><li>The greatest safeguard of protecting our members' privacy is paying attention. Many of our errors/violations are caused by operators not paying attention or being distracted while handling patient information Ii.e. sending an explanation of benefits to an incorrect address).</li></ul><div><br></div><div><strong>Emerging Issues<br></strong>Mr. Lawrence states currently HIPAA "is what it is" with few issues emerging.  He does anticipate additional privacy and security rules at the state levels. Each state has privacy safeguards in place to protect their citizens and updates are frequently made to enhance these provisions. HIPAA serves as the baseline while each state adds to it. Should America move to a single-payer model, adjustments to HIPAA would be required to balance inconsistencies among states. He concludes that from a privacy perspective, consistency could only be seen as a benefit (M.. Lawrence, personal conversation, December 6, 2019).</div>]]></description>
         <enclosure url="https://www.linkedin.com/in/matthew-lawrence-7bb84344" />
         <pubDate>2019-10-24 20:54:05 UTC</pubDate>
         <guid>https://padlet.com/christenewalker/9fam80swx40g/wish/402295279</guid>
      </item>
      <item>
         <title>#3: Professional Association</title>
         <author>christenewalker</author>
         <link>https://padlet.com/christenewalker/9fam80swx40g/wish/402295366</link>
         <description><![CDATA[<div><strong>AHIP's Response to Modifying HIPAA Rules</strong><br><br>America's Health Insurance Plans (AHIP), formerly the American Association of Health Plans, is the national association representing the health insurance community. The Vice-President of AHIP sent comments to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) after AHIP received a request for information about opportunities to modify HIPAA to improve coordinated care. AHIP made it clear that HIPAA has served as a solid standard for protecting health information and has worked well overall. HIPAA, enacted in 1996, was written well before the digital age when records were primarily paper-based. In the web-based article provided below is a link to the letter sent to HHS by AHIP . In this letter, AHIP outlined areas OCR could focus their resources to improve upon HIPAA's current provisions.<br>These areas include: <br>• overcoming challenges of sharing specific categories of information, <br>• implementing federal standards to preempt state law to streamline protocols,<br>• regulations and guidance for those acting in good faith to assist in an individual's care,<br>• education and outreach to inform people about the risks of sharing their health data in the digital age (i.e. apps, online, devices) and informing lawmakers to broaden the scope of HIPAA regulations (AHIP, 2019).</div>]]></description>
         <enclosure url="https://www.ahip.org/ahip-responds-to-hhs-rfi-on-modifying-hipaa-rules-to-improve-care-coordination/" />
         <pubDate>2019-10-24 20:54:18 UTC</pubDate>
         <guid>https://padlet.com/christenewalker/9fam80swx40g/wish/402295366</guid>
      </item>
      <item>
         <title>#4: Current News Article</title>
         <author>christenewalker</author>
         <link>https://padlet.com/christenewalker/9fam80swx40g/wish/402295613</link>
         <description><![CDATA[<div><strong>HIPAA Training in the Digital Age</strong><br><br>Aligning with AHIP's recommendations for HHS, training for the digital age of HIPAA is making headlines. HIPAA compliance training for 2019 is encouraged to include privacy strategies for digital health technology. The four items Wagenen (2019) highlights for compliance in our modern era include:<br>• Email and Messaging Solutions: these must be easy and secure. Encryption software is now easily available and secure. Simply including "private" or "PHI" in the subject line initiates encryption with many programs.<br>• Cloud Storage: cloud storage providers paid by health care providers to store PHI are considered business associates which are covered entities under HIPAA and must comply with HIPAA regulations.<br>• HIPAA Risk Assessments: understand weaknesses and potential vulnerabilities and how to fix them.<br>• Patient Security and HIPAA Compliance: patients wanting to photograph their test results with smartphones meet reluctance among providers. Patients have the right to view their health data in a form they choose which can include taking a photo. </div>]]></description>
         <enclosure url="https://healthtechmagazine.net/article/2019/02/4-important-items-your-2019-hipaa-compliance-checklist-perfcon" />
         <pubDate>2019-10-24 20:54:56 UTC</pubDate>
         <guid>https://padlet.com/christenewalker/9fam80swx40g/wish/402295613</guid>
      </item>
      <item>
         <title>#5: Current News Article</title>
         <author>christenewalker</author>
         <link>https://padlet.com/christenewalker/9fam80swx40g/wish/402296117</link>
         <description><![CDATA[<div><strong>Enforcement Priorities and Breach Trends<br><br></strong>OCR officials spoke at a conference to present HHS's focus on enforcement for 2020 and trending breaches seen in 2019. OCR emphasized their commitment to enforcement of HIPAA rights of access and  timely reporting of breaches and complaints. The Office also touched on how cases and investigations are selected to pursue by OCR itself,  those with a perceived importance as well as sending a message about compliance to the health care industry. OCR then announced the increasing trend of security breaches by way of hacking or information technology (IT) incidents. These types of breaches accounted for 61% of all breaches in the first quarter of 2019. OCR recommends the increased use of encryption and safeguard improvements to deter these types of breaches (Wilder, Otto, &amp; Kwong, 2019).</div>]]></description>
         <enclosure url="https://www.hldataprotection.com/2019/10/articles/health-privacy-hipaa/ocr-provides-insight-into-enforcement-priorities-and-breach-trends/" />
         <pubDate>2019-10-24 20:56:07 UTC</pubDate>
         <guid>https://padlet.com/christenewalker/9fam80swx40g/wish/402296117</guid>
      </item>
      <item>
         <title>#6: Original Source of Law</title>
         <author>christenewalker</author>
         <link>https://padlet.com/christenewalker/9fam80swx40g/wish/402296319</link>
         <description><![CDATA[<div><strong>Constitutional Law<br><br>Fourth Amendment<br></strong>Although the right to privacy is not explicitly mentioned in the Constitution, the Fourth Amendment is often argued as protecting citizens' right to privacy. The Fourth Amendment states it is the right of the people to be secure against unreasonable searches and seizures (U.S. Const. amend IV).</div>]]></description>
         <enclosure url="https://www.senate.gov/civics/constitution_item/constitution.htm#amdt_4_1791" />
         <pubDate>2019-10-24 20:56:46 UTC</pubDate>
         <guid>https://padlet.com/christenewalker/9fam80swx40g/wish/402296319</guid>
      </item>
      <item>
         <title>#7: Original Source of Law</title>
         <author>christenewalker</author>
         <link>https://padlet.com/christenewalker/9fam80swx40g/wish/402296382</link>
         <description><![CDATA[<div><strong>Statutory/Public Law <br><br>Health Insurance Portability and Accountability Act of 1996<br></strong>Passed in 1996 by President Bill Clinton, HIPAA was enacted to improve portability and continuity of health insurance coverage in various markets, to combat fraud, waste, and abuse in health insurance and health care delivery, to promote increased use of medical savings accounts, to improve access to long-term care coverage and services, to simplify the administration of health insurance, and to protect the privacy of individually identifiable health information. All covered entities are required to be HIPAA-compliant. These entities include health insurance companies, health maintenance organizations (HMO’s), company health plans, health care providers, and government programs paying for health care, such as Medicare and Medicaid. These entities are required to have physical, network, and process security measures in place to secure PHI (Health Insurance Portability and Accountability Act, § 264).</div><div><br></div>]]></description>
         <enclosure url="https://www.govinfo.gov/content/pkg/PLAW-104publ191/pdf/PLAW-104publ191.pdf" />
         <pubDate>2019-10-24 20:56:58 UTC</pubDate>
         <guid>https://padlet.com/christenewalker/9fam80swx40g/wish/402296382</guid>
      </item>
      <item>
         <title>#9: Original Source of Law</title>
         <author>christenewalker</author>
         <link>https://padlet.com/christenewalker/9fam80swx40g/wish/402296429</link>
         <description><![CDATA[<div><strong>Judicial Law<br><br>Connecticut Supreme Court<br></strong>In<strong> </strong><em>Byrne v. Avery Center</em> (2014), Connecticut's highest court paved the way for individuals to use HIPAA violations as a case for negligence. Byrne was a patient at the Avery Center for Obstetrics when her ex-boyfriend/child's father subpoenaed the center for her medical records in a paternity suit. The Avery Center sent a copy of her records to the court without contesting the subpoena or notifying Byrne. The ex-boyfriend  accessed the records via the court file and used information in the medical record to harass and extort money from Byrne. The trial court dismissed the case stating HIPAA does not allow private plaintiffs to bring action based on a public statute or federal common law. The Connecticut Supreme Court remanded the case back to the trial court who dismissed the case yet again (<em>Byrne v. Avery Center</em>, 2014). After further appeal by Byrne, the Supreme Court stated a person suffering harm as a result of a breach of confidentiality was entitled to damages. A jury in trial court decided in favor of Byrne and awarded $853,000 in damages (HIPAA Journal, 2018).</div>]]></description>
         <enclosure url="https://casetext.com/case/byrne-v-avery-ctr-for-obstetrics-gynecology-pc" />
         <pubDate>2019-10-24 20:57:09 UTC</pubDate>
         <guid>https://padlet.com/christenewalker/9fam80swx40g/wish/402296429</guid>
      </item>
      <item>
         <title>#8: Original Source of Law</title>
         <author>christenewalker</author>
         <link>https://padlet.com/christenewalker/9fam80swx40g/wish/402296520</link>
         <description><![CDATA[<div><strong>Administrative Law<br><br>DHHS Privacy Rule</strong><br>Federal law establishes regulations for the Department of Health and Human Services to safeguard the privacy of individually identifiable health information, known as the Privacy Rule. The Privacy Rule bestows certain rights on individuals, including rights to access and amend their health care information and to request a record of when and why their PHI has been shared with others and for what purpose. This law protects all patient information held or transmitted by a covered entity and defines and limits the circumstances in which PHI may be used or disclosed (45 C.F.R. § 164.500-534).</div>]]></description>
         <enclosure url="https://gov.ecfr.io/cgi-bin/text-idx?SID=b8b601ef678955fbd6f453ac1c5da0a5&amp;mc=true&amp;node=pt45.2.164&amp;rgn=div5#sp45.2.164.e" />
         <pubDate>2019-10-24 20:57:23 UTC</pubDate>
         <guid>https://padlet.com/christenewalker/9fam80swx40g/wish/402296520</guid>
      </item>
      <item>
         <title>#10: Local Administrative Law/Policy/Rule</title>
         <author>christenewalker</author>
         <link>https://padlet.com/christenewalker/9fam80swx40g/wish/402296977</link>
         <description><![CDATA[<div><strong>Texas' Privacy Policy<br><br></strong>The Department of State Health Services’ Privacy Policy, in compliance with the Texas Medical Privacy Act, requires covered entities to provide employee training regarding the maintenance and protection of PHI. Training must be customized to the entities' operations as well as the employee’s scope of employment. The law also requires Texas to publish patients’ privacy rights, a list of state agencies that govern covered entities with contact information, and each agency’s complaint enforcement process. Other provisions under the Privacy Policy include consequences of violations of compliance, breaches of PHI, and penalties<strong> </strong>(25 T.A.C. § 1.501).</div>]]></description>
         <enclosure url="https://texreg.sos.state.tx.us/public/readtac$ext.TacPage?sl=R&amp;app=9&amp;p_dir=&amp;p_rloc=&amp;p_tloc=&amp;p_ploc=&amp;pg=1&amp;p_tac=&amp;ti=25&amp;pt=1&amp;ch=1&amp;rl=501" />
         <pubDate>2019-10-24 20:58:47 UTC</pubDate>
         <guid>https://padlet.com/christenewalker/9fam80swx40g/wish/402296977</guid>
      </item>
      <item>
         <title>#11: Ethical Principle</title>
         <author>christenewalker</author>
         <link>https://padlet.com/christenewalker/9fam80swx40g/wish/402297039</link>
         <description><![CDATA[<div><strong> HCSC's Code of Ethics and Conduct<br><br></strong>HCSC’s Code of Ethics and Conduct requires its employees to protect the PHI of it members, providers, and its own employees. The Code emphasizes protection of this information, both internally and externally, to avoid improper use and disclosure, violations of federal and state laws, and violation of the organization’s agreements with customers and government agencies (Health Care Service Corporation, 2018).</div>]]></description>
         <enclosure url="http://www.hcsc.com/pdf/hcsc_code_conduct.pdf" />
         <pubDate>2019-10-24 20:59:00 UTC</pubDate>
         <guid>https://padlet.com/christenewalker/9fam80swx40g/wish/402297039</guid>
      </item>
      <item>
         <title>#12: Non-Law Source</title>
         <author>christenewalker</author>
         <link>https://padlet.com/christenewalker/9fam80swx40g/wish/402297118</link>
         <description><![CDATA[<div>This presentation provides an overview of the basics of HIPAA. Topics include the background and purpose of the HIPAA Privacy Rule, how HIPAA applies to those in the health care industry, a glossary of HIPAA terms, and consequences of failure to comply. The presentation is designed for those in patient care settings; however, the information provided is succinct and informative for all industries subject to HIPAA compliance (Medical Protective, 2015).</div>]]></description>
         <enclosure url="https://www.medpro.com/documents/10502/3281585/HIPAA+Basics+2015.pdf" />
         <pubDate>2019-10-24 20:59:14 UTC</pubDate>
         <guid>https://padlet.com/christenewalker/9fam80swx40g/wish/402297118</guid>
      </item>
      <item>
         <title>#13: Recommendations/Best Practices for Compliance</title>
         <author>christenewalker</author>
         <link>https://padlet.com/christenewalker/9fam80swx40g/wish/402297287</link>
         <description><![CDATA[<div><br>The following are recommendations/best practices for maintaining compliance with HIPAA regulations at the federal, state, and local levels. These measures should be included in training and practices across the organization.</div><ul><li>Safeguards for access to patient information , such as encryption and password protection, for various types of devices (Becker, 2017). </li><li>Frequently evaluate policies and procedures to ensure documentation is up to date (Becker, 2017).</li><li>Only supply the minimum amount of information necessary for inquiries of a legitimate business need.</li><li>Limit business processes focusing on sensitive information to specific roles or severity levels.</li><li>Personal initiative to remain current on HIPAA policies and regulations.</li><li>Regular internal review of policies and compliance audits (M. Lawrence, personal communication, December 6, 2019).</li><li>Keep training relevant to the employee's role with less focus on the background and history of HIPAA (HIPAA Journal, 2019).</li></ul>]]></description>
         <enclosure url="" />
         <pubDate>2019-10-24 20:59:47 UTC</pubDate>
         <guid>https://padlet.com/christenewalker/9fam80swx40g/wish/402297287</guid>
      </item>
      <item>
         <title>References</title>
         <author>christenewalker</author>
         <link>https://padlet.com/christenewalker/9fam80swx40g/wish/416955076</link>
         <description><![CDATA[<div>America's Health Insurance Plans (2019). AHIP responds to HHS RFI on modifying HIPAA rules to improve care coordination. Retrieved from <a href="https://www.ahip.org/ahip-responds-to-hhs-rfi-on-modifying-hipaa-rules-to-improve-care-coordination/">https://www.ahip.org/ahip-responds-to-hhs-rfi-on-modifying-hipaa-rules-to-improve-care-coordination/</a><br><br>Becker, B. (2017, May 16). Questions and answers to improve security and avoid penalties. Retrieved from <a href="https://www.hipaajournal.com/hipaa-compliance-best-practices-8809/">https://www.hipaajournal.com/hipaa-compliance-best-practices-8809/</a><br><br>Emily Byrne v. Avery Center for Obstetrics and Gynecology, P.C., 314 Conn. 433 (2014).<br><br>Health Care Service Corporation (2018). Code of Ethics and Conduct § 3.1. Retrieved from http://www.hcsc.com/pdf/hcsc_code_conduct.pdf<br><br>Health Insurance Portability and Accountability Act of 1996, Pub. L. No. 104-191, § 264, 110 Stat. 1936-2103(1996).<br><br>HIPAA Journal (2018, December 21). $853,000 awarded to patient whose PHI was impermissibly disclosed to former boyfriend. Retrieved from <a href="https://www.hipaajournal.com/853000-awarded-to-patient-whose-phi-was-impermissibly-disclosed-to-former-boyfriend/">https://www.hipaajournal.com/853000-awarded-to-patient-whose-phi-was-impermissibly-disclosed-to-former-boyfriend/</a> </div><div><br>HIPAA Journal (2019). HIPAA training requirements. Retrieved from <a href="https://www.hipaajournal.com/hipaa-training-requirements/">https://www.hipaajournal.com/hipaa-training-requirements/</a><br><br>Medical Protective (2015). HIPAA basic privacy training. Retrieved from <a href="https://www.medpro.com/documents/10502/3281585/HIPAA+Basics+2015.pdf">https://www.medpro.com/documents/10502/3281585/HIPAA+Basics+2015.pdf</a><br><br>Privacy of Health Information under the Health Insurance Portability and Accountability Act of 1996, 25 Tex. Admin. Code § 1.501 (2012). <br><br>Privacy of Individually Identifiable Health Information, 45 C.F.R. § 164.500-534 (2013).<br><br>U.S. Const. amend. IV<br><br>Wagenen, J.V. (2019, February 19). 4 important items on your 2019 HIPAA compliance checklist. Retrieved from <a href="https://healthtechmagazine.net/article/2019/02/4-important-items-your-2019-hipaa-compliance-checklist-perfcon">https://healthtechmagazine.net/article/2019/02/4-important-items-your-2019-hipaa-compliance-checklist-perfcon</a><br><br>Wilder, M., Otto, P., &amp; Kwong, K. (2019, October 21). </div><h1>OCR provides insight into enforcement priorities and breach trends. Retrieved from <a href="https://www.hldataprotection.com/2019/10/articles/health-privacy-hipaa/ocr-provides-insight-into-enforcement-priorities-and-breach-trends/">https://www.hldataprotection.com/2019/10/articles/health-privacy-hipaa/ocr-provides-insight-into-enforcement-priorities-and-breach-trends/</a></h1>]]></description>
         <enclosure url="" />
         <pubDate>2019-11-27 01:05:58 UTC</pubDate>
         <guid>https://padlet.com/christenewalker/9fam80swx40g/wish/416955076</guid>
      </item>
   </channel>
</rss>
