In accordance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), our office must ensure the confidentiality, integrity and availability of all the protected health information (“PHI”) it creates, receives, maintains or transmits. Our office must also protect against any reasonably anticipated hazards to the security and integrity of PHI. The following information and guidelines should provide all employees the information needed to properly handle and maintain PHI.
PHI is generally identifiable information that is transmitted or maintained by electronic, oral, or paper-based, that relates to an individual’s physical or mental health, treatment, payment for services or healthcare operations. To be PHI, the information must identify the individual or provide a reasonable basis for identifying the individual.
Example:
Example:
We may maintain records related to the diagnosis, treatment, or referral for treatment of a substance use disorder. These records are protected by federal law (42 CFR Part 2) in addition to HIPAA.
Substance use disorder records may be used and disclosed for treatment, payment, and health care operations as permitted by law. These records may not be used or disclosed for law enforcement purposes or in civil, criminal, administrative, or legislative proceedings against you without proper legal authority.
Recognizing and responding to HIPAA violations is a critical responsibility of all staff members. If a potential breach or non-compliance act is witnessed, it is crucial to report to a supervisor or our designated HIPAA Privacy Officer without delay.