1 / 16

HIPAA and FERPA

ECURE 2002. HIPAA and FERPA. (or, Is Your HIPAA Eating Your FERPA?) C.W. Goldsmith The University of Texas System. Comparison of FERPA and HIPAA. History of FERPA and HIPAA Administrative Rule versus Law What’s Covered? What are the Penalties? Similarities Coping Strategies

dino
Download Presentation

HIPAA and FERPA

An Image/Link below is provided (as is) to download presentation Download Policy: Content on the Website is provided to you AS IS for your information and personal use and may not be sold / licensed / shared on other websites without getting consent from its author. Content is provided to you AS IS for your information and personal use only. Download presentation by click this link. While downloading, if for some reason you are not able to download a presentation, the publisher may have deleted the file from their server. During download, if you can't get a presentation, the file might be deleted by the publisher.

E N D

Presentation Transcript


  1. ECURE 2002 HIPAA and FERPA (or, Is Your HIPAA Eating Your FERPA?) C.W. Goldsmith The University of Texas System

  2. Comparison of FERPA and HIPAA • History of FERPA and HIPAA • Administrative Rule versus Law • What’s Covered? • What are the Penalties? • Similarities • Coping Strategies • Who’s Not Covered? • Opportunity

  3. Why FERPA? 1960s Berkeley Free Speech Loss of loco parentis 1974 FERPA (Buckley) in Response to Abuse Why HIPAA? 1996 Failure to Leverage Technology to Reduce Costs History

  4. Difference Between Administrative Rule and Law • Rule Offers More Less Formal Steps to Discover Problems/Answers to Resolve Issues/Complaints Before Going to Court • HIPAA is Both • Enforcement Through the Office of Civil Rights • FERPA is Both

  5. FERPA Education Records/Privacy HIPAA Code Sets Privacy Security Identifiers What’s Covered ?

  6. FERPA 1974 HIPAA Code Sets – October 16, 2002 Privacy – April 14, 2003 Security – Identifiers -- ?? Implementation Dates

  7. FERPA Penalties Institutional Sanctions Loss of Federal Funding HIPAA Penalties Security: A Maximum of $25,000 Privacy: Intent: to $50,000, one year in jail False pretenses: $100,000, 5 years jail Commercial or personal gain: $250,000, 10 years jail What are the Penalties?

  8. FERPA Penalties No right of personal action, Civil Rights Cause of Action May Exist Against Public Institutions HIPAA Penalties Transactions/codes/identifiers: $100 per incident/up to $25,000 per year per standard What are the Penalties?

  9. FERPA Directory Information opt out HIPAA Directory Information opt in Any Similarities?

  10. What does HIPAA say about FERPA? • HIPAA says FERPA is to be followed for student medical record • FERPA says student medical record not covered • HIPAA says medical records seen by other than physician/nurse is an education record and must be handled accordingly

  11. FERPA Culture and education History HIPAA Use HIPAA to Refresh Campus Understanding of FERPA Compliance and Federal Sentencing Guidelines Encourage Training Everyone(!) UAB Committee Structure Coping Strategies

  12. UAB HIPAA Steering Committee Clair Goldsmith, PhD Lucy Hicks, JD Joan Lorden, PhD Michael R. Waldrum, MD Advisory Staff J Hicks; J Piazza, JD; T Tatum, JD Technical Advisory Don Fast; Landy Manderson UAB Clinics Employees Research HSIS / Children's Students Tusc / Hunstville Clinics Roger McCullough All UAB Campus and affiliated Viva / VA William Fulcher, MD Allen Bolton Training/Insurance William Grizzle, MD, PhD Amanda Dorsey Hunstville / Tusc? All Campus and Hunstville Tusc EDI EDI EDI EDI EDI Privacy Privacy Privacy Privacy Privacy Security Security Security Security Security Identifiers Identifiers Identifiers Identifiers Identifiers

  13. Communities Not Covered by FERPA and HIPAA • Human Research Subjects in Other Disciplines • Psychology, Education • IRB Responsibility/Waiver • What is Done With Personally Identifiable Research Information when Investigator Leaves the Institution?

  14. Conclusion FERPA and HIPAA Are Great Platforms for the Exercise of Leadership in Protecting Privacy of Individuals

  15. But… Why hasn’t Higher Education Taken a Stronger Role in the use of Technology to Protect Privacy?

  16. http://www.educause.edu/pub/er/erm01/erm015w.htmlemail:cgoldsmith@utsystem.eduhttp://www.educause.edu/pub/er/erm01/erm015w.htmlemail:cgoldsmith@utsystem.edu

More Related