HIPAA Security and Breach Notification Rules - Protecting Security of PHI

Speaker

Instructor: Jim Sheldon-Dean
Product ID: 703869

Location
  • Duration: 90 Min
Staying HIPAA compliant entails ensuring you have the right policies, procedures, and documentation, and have performed the appropriate risk analysis of confidentiality, integrity, and availability of the electronic protected health information (PHI). This course will discuss how to create the right breach notification policy for your organization and how to follow through when an incident occurs. In addition, a policy framework to help establish good security practices will be presented.
RECORDED TRAINING
Last Recorded Date: Apr-2015

 

$229.00
1 Person Unlimited viewing for 6 month info Recorded Link and Ref. material will be available in My CO Section
(For multiple locations contact Customer Care)

$399.00
Downloadable file is for usage in one location only. info Downloadable link along with the materials will be emailed within 2 business days
(For multiple locations contact Customer Care)

 

 

Customer Care

Fax: +1-650-362-2367

Email: [email protected]

Read Frequently Asked Questions

Why Should You Attend:

Having a solid information security management process is key to ensuring you can protect your data and avoid breaches, as well as prepare you for breaches that do occur despite your best efforts.

Compliance with the HIPAA Security Rule has always required that the risks to PHI be assessed and any issues be addressed by mitigation as necessary. But new changes to the HIPAA Breach Notification Rule add a new role for risk assessment, in determining whether or not a breach has a “low probability of compromise.” In addition, recent audits and enforcement actions have highlighted the requirement for performing a proper risk analysis as part of the management of security risks, and to satisfy documentation requirements.

This webinar will illustrate why good security controls and protection from breaches go hand-in-hand and are topics of current interest. You need to have good controls in place to help prevent issues that may lead to breaches, and to understand what has happened when a breach may have taken place. This session will explore the relationship of security to breach notification and shows how considering HIPAA requirements together can lead to the most secure, most compliant systems and organizations.

Areas Covered in the Webinar:

  • Being in compliance with HIPAA involves not only ensuring you provide the appropriate patient rights and controls on your uses and disclosures, but also that you ensure you have the right policies, procedures, and documentation, and have performed the appropriate analysis of the risks to the confidentiality, integrity, and availability of electronic protected health information.
  • Using risk analysis can help you make defensible, documented decisions about your compliance in a variety of circumstances, for a variety of regulations. Risk analysis is the key to making your health information privacy and security regulatory compliance work more sensibly as well as defensibly.
  • The HIPAA Breach Notification Rule has been in effect since September 23, 2009 and had recently been significantly modified. The course will discuss the origins of the rule and how it works, including interactions with other HIPAA rules and penalties for violations.
  • HIPAA covered entities and business associates need to know where and what information they have, so they can know if there has been a breach, and then decide if they need to notify or not. The course will cover how the rules have been changed to eliminate the "harm standard" and replace it with a risk assessment.
  • Entities can avoid notification if information has been encrypted according to federal standards. The webinar will cover the guidance from the US Department of Health and Human Services that shows how to encrypt so as to prevent the need for notification in the event of lost data.
  • It will discuss how to create the right breach notification policy for your organization and how to follow through when an incident occurs. In addition, a policy framework to help establish good security practices will be presented.
  • It will cover the essentials of information security methods you can use to keep breaches from happening, and stay compliant with the HIPAA Security Rule as well. The course will also discuss new penalties for non-compliance, including mandatory penalties for "willful neglect" that begin at $10,000.
  • The course will help you understand what isn’t a breach and under what circumstances you don’t have to consider breach notification. Attendees will find out how to report the smaller breaches (less than 500 individuals), and learn why you want to avoid a breach involving more than 500 individuals – media notices, website notices, and immediate notification of HHS, including posting on the HHS breach notification “wall of shame” on the web.
  • The webinar instructor will explain, based on historical analysis of reported breaches, what measures must be taken today to protect information from the most common threats, as well as discuss information security trends and explain what kinds of efforts will need to be undertaken in the future to protect the security of PHI.

Who Will Benefit:

This webinar will provide valuable assistance to all personnel in medical offices, practice groups, hospitals, academic medical centers, insurers, business associates (shredding, data storage, systems vendors, billing services, etc.). The titles are:

  • Compliance Director
  • CEO
  • CFO
  • Privacy Officer
  • Security Officer
  • Information Systems Manager
  • HIPAA Officer
  • Chief Information Officer
  • Health Information Manager
  • Healthcare Counsel/Lawyer
  • Office Manager
  • Contracts Manager

Instructor Profile:

Jim Sheldon-Dean is the founder and director of compliance services at Lewis Creek Systems, LLC, a Vermont-based consulting firm founded in 1982, providing information privacy and security regulatory compliance services to a variety of health care providers, businesses, universities, small and large hospitals, urban and rural mental health and social service agencies, health insurance plans, and health care business associates. He serves on the HIMSS Information Systems Security Workgroup, has co-chaired the Electronic Data Interchange Privacy and Security Workgroup, currently serves on the WEDI Breach Notification sub-workgroup, and is a recipient of the 2011 WEDI Award of Merit. He is a frequent speaker regarding HIPAA and information privacy and security compliance issues at seminars and conferences, including speaking engagements at AHIMA national and regional conventions and WEDI national conferences, and before regional HFMA chapter meetings and state hospital associations.

Jim Sheldon-Dean is the founder and director of compliance services at Lewis Creek Systems, LLC, a Vermont-based consulting firm founded in 1982, providing information privacy and security regulatory compliance services to a variety of health care providers, businesses, universities, small and large hospitals, urban and rural mental health and social service agencies, health insurance plans, and health care business associates. He serves on the HIMSS Information Systems Security Workgroup, has co-chaired the Electronic Data Interchange Privacy and Security Workgroup, currently serves on the WEDI Breach Notification sub-workgroup, and is a recipient of the 2011 WEDI Award of Merit. He is a frequent speaker regarding HIPAA and information privacy and security compliance issues at seminars and conferences, including speaking engagements at AHIMA national and regional conventions and WEDI national conferences, and before regional HFMA chapter meetings and state hospital associations.

Topic Background:

Compliance with HIPAA rules requires being able to make decisions about how to implement the rules in your own circumstances, and using a risk analysis approach can make that process more logical and better documented. The HIPAA Security Rule requires that all entities periodically evaluate the risks to the confidentiality, integrity, and availability of PHI, and the rules are now backed up with new fines, and penalties, and a new enforcement effort. The changes to the rules create new challenges for HIPAA entities, and new risks for non-compliance and penalties.

Any violation of the HIPAA Privacy Rule may be a reportable breach under the HIPAA Breach Notification rules, requiring notification of individuals and HHS when information security is breached. Any incident involving a HIPAA issue must be evaluated to see if it is reportable, and any decisions or actions must be fully documented.

Follow us :

 

 

Refund Policy

Our refund policy is governed by individual products and services refund policy mentioned against each of offerings. However in absence of specific refund policy of an offering below refund policy will be effective.
Registrants may cancel up to two working days prior to the course start date and will receive a letter of credit to be used towards a future course up to one year from date of issuance. ComplianceOnline would process/provide refund if the Live Webinar has been cancelled. The attendee could choose between the recorded version of the webinar or refund for any cancelled webinar. Refunds will not be given to participants who do not show up for the webinar. On-Demand Recordings can be requested in exchange. Webinar may be cancelled due to lack of enrolment or unavoidable factors. Registrants will be notified 24hours in advance if a cancellation occurs. Substitutions can happen any time. On-Demand Recording purchases will not be refunded as it is available for immediate streaming. However if you are not able to view the webinar or you have any concern about the content of the webinar please contact us at below email or by call mentioning your feedback for resolution of the matter. We respect feedback/opinions of our customers which enables us to improve our products and services. To contact us please email [email protected] call +1-888-717-2436 (Toll Free).

 

 

+1-888-717-2436

6201 America Center Drive Suite 240, San Jose, CA 95002, USA

Follow Us

facebook twitter linkedin youtube

 

Copyright © 2023 ComplianceOnline.com MetricStream
Our Policies: Terms of use | Privacy

PAYMENT METHOD: 100% Secure Transaction

payment method