your role in corporate compliance and hipaa confidentiality n.
Skip this Video
Download Presentation
Your Role in Corporate Compliance and HIPAA Confidentiality

Loading in 2 Seconds...

play fullscreen
1 / 32

Your Role in Corporate Compliance and HIPAA Confidentiality - PowerPoint PPT Presentation

  • Uploaded on

Your Role in Corporate Compliance and HIPAA Confidentiality. Part I: Understanding Your Role in Corporate Compliance. What is Compliance?.

I am the owner, or an agent authorized to act on behalf of the owner, of the copyrighted work described.
Download Presentation

PowerPoint Slideshow about 'Your Role in Corporate Compliance and HIPAA Confidentiality' - felix-combs

Download Now An Image/Link below is provided (as is) to download presentation

Download Policy: Content on the Website is provided to you AS IS for your information and personal use and may not be sold / licensed / shared on other websites without getting consent from its author.While downloading, if for some reason you are not able to download a presentation, the publisher may have deleted the file from their server.

- - - - - - - - - - - - - - - - - - - - - - - - - - E N D - - - - - - - - - - - - - - - - - - - - - - - - - -
Presentation Transcript
what is compliance
What is Compliance?
  • The term compliance has different meanings. In terms of the healthcare industry, compliance means adhering to the requirements stated under the Medicare and Medicaid laws contained within the Social Security Act and the regulations from CMS (Centers for Medicare and Medicaid Services) and other respective federal and state agencies.
  • Our employees’ behavior is a direct reflection on OSF Healthcare. We want to be known as the region’s best health-care system with employees who consistently display high standards of integrity, conduct and ethical behavior.
what does compliance mean to you as an osf employee
What Does Compliance Mean to Youas an OSF Employee?
  • The Vision of OSF Healthcare is that recognizing God’s great gift of life, we will be a community of caregivers pursuing perfection in healthcare quality, safety, service and financial integrity.
  • Our Corporate Compliance Plan is located online at the following address,
  • Our employees’ behavior is a direct reflection on OSF Healthcare. We want to be known as the region’s best health-care system with employees who consistently display high standards of integrity, conduct and ethical behavior..
who is big brother
Who is Big Brother?
  • CMS (Centers for Medicare and Medicaid Services) works with the OIG (Office of the Inspector General) to investigate possible fraud and abuse cases. If CMS believes the hospital has participated in fraudulent activities either knowingly or unknowingly, the OIG investigate.
  • The FBI is the organization that investigates and enforces healthcare compliance.
  • The Department of Justice prosecutes healthcare organizations for healthcare fraud and abuse.
what is a breach of compliance
What is a Breach of Compliance?
  • Understanding how these regulations apply in our daily lives can be difficult.
  • An example of fraud is billing for services not provided. Even mistakenly violating these laws could be abuse and may also result in fines.
  • Examples of possible abuse are repeatedly using the wrong billing codes or making the same error when filing claims.
what is in osf s compliance plan
What is in OSF’s Compliance Plan?
  • Standard of Conduct: Each new employee signs a form located in the HR handbook that is given to them during orientation.
  • The statement reads:

Any OSF Healthcare employee who has knowledge of any activity or behavior which is unethical, immoral or illegal must report this activity or observed behavior to his/her immediate supervisor or to the Director of Human Resources.

  • Identification of High Risk Areas:

These are areas that are identified as a higher risk for potential fraud and abuse therefore require more frequent monitoring by the compliance department.

what is in the compliance plan
What is in the Compliance Plan?
  • Disciplinary Guidelines:

The Corporate Compliance Plan identifies employee obligations to government investigations, compliance chain of command and compliance plan discipline.

the osf healthcare system corporate compliance program promotes
The OSF Healthcare System Corporate Compliance Program promotes:
  • The requirement of a facility compliance officer
  • The identification of a facility compliance officer
  • The identification of chain of command
  • The identification of Integrity Hotline
  • The provision of education to staff regarding compliance
  • The identification of Standards of Conduct
in summary
In Summary.....
  • Compliance means adhering to the requirements stated under the Medicare and Medicaid laws contained within the Social Security Act and the regulations from CMS (Centers for Medicare and Medicaid Services) and other respective federal and state agencies.
  • Doing the right thing, the right way, the first time, all the time!
  • Non-compliance means fraud and/or abuse, penalties, disciplinary action, and public distrust.
what is hipaa
What is HIPAA?

HIPAA stands for:



Portability and


Act of 1996

what is hipaa1
What is HIPAA?

HIPAA is a federal regulation that OSF Healthcare System has to comply with that protects the privacy, security and confidentiality of a patient’s health information.

hipaa privacy rule
HIPAA Privacy Rule

The HIPAA Privacy Rule

  • Standards to protect the privacy of medical records and other patient specific information.
  • Making sure protected health information (PHI) is properly handled by the facility.
hipaa privacy
HIPAA Privacy

What is protected health information?-Information that could be used to identify an individual - Examples would be: name, social security number, (demographic information) - Transmitted or maintained in any form such as oral, written, or electronic information


HIPAA requires that all health care organizations have a Privacy Officer.

Corporate Compliance/Privacy Officer

John Evancho


Each OSF entity has their own Privacy Officer.

OSFSFMC – Dan Blunier (655-2734)

privacy officers
Privacy Officers

Responsibilities include:

  • Overseeing the privacy functions at the facility.
  • Serve as a resource for questions and concerns.
  • Handle any privacy related complaints.
  • Develop privacy policies and procedures.
  • Provide training to staff.
hipaa why is training necessary
HIPAA – Why is training necessary?

Confidentiality is so important, that OSF

requires that:

  • All employees and workforce members be informed of their responsibility to protect confidentiality.
  • Proven violation of the confidentiality of patient information shall include immediate disciplinary action up to and including termination.
hipaa policy
HIPAA – Policy
  • Our policy states that patient protected health information (PHI) will be kept private and confidential
  • Our policy also guides us on who should have access to patient information
        • Direct access to patient information shall only be permitted to those employees who have a “need to know” to perform their job functions.
        • Minimum necessary information to perform their jobs.
hipaa policy1
HIPAA - Policy
  • What patient information does OSF require me to keep confidential?
    • Demographic information
      • Examples: Name, social security number, date of birth, address, etc.
    • Information about injury, illness or condition – including symptoms, diagnosis or treatment
    • Conversations between the patient and health care workers
what information can i provide to persons seeking information about a patient
What information can I provide to persons seeking information about a patient?
  • Facility Directory information:

1. The patient’s location with the facility;

2. The patient’s condition stated in general

terms (i.e. good, fair, poor);

3. The patient’s religious affiliation

(available only to clergy).

hipaa policy2
HIPAA - Policy

Our Confidentiality Policy also guides us on when and where we can discuss patient information.

  • Discuss patient information privately; never in elevators, lobbies, cafeterias, or corridors
  • Make sure requisitions, forms, and computer screens with patient names and information are not easily viewed by others
  • Dispose of unnecessary patient information in proper receptacles for shredding, not ordinary trash bins
how do i protect the privacy of my co workers
HOW do I protect the privacy of my co-workers?
  • Take special care to respect the privacy of co-workers and colleagues who are patients.
  • Do NOT discuss the health care services of your co-workers with anyone who is not directly involved in their care.

- Do NOT access their private health information unless it is for patient care purposes

hipaa how do our patient s know their privacy rights
HIPAA – How do our patient’s know their Privacy Rights?
  • We are required to provide a Notice of Privacy Practices to all patients that describes their rights over their PHI
  • Patients will sign an acknowledgement form stating that they received a copy of the Privacy Notice
reporting possible violations
Reporting Possible Violations

Can employees report possible violations of the privacy rule?

  • Employees are encouraged to report possible violations of the privacy rule to us. Employees should feel comfortable to know that we will not take any retaliatory action when employees file complaints
  • Submit complaints to your immediate supervisor, Privacy Officer or the Integrity Line at 1 - 800 – 547 – 2822.
why comply with the hipaa rule
Why Comply With the HIPAA Rule?
  • Ethics – it’s the right thing to do
  • Civil Penalties – fines of $100 for every accidental violation
  • Criminal Penalties – up to $250,000 for violations committed knowingly/purposefully and up to 10 years in federal prison
hipaa security rule
HIPAA Security Rule

The Privacy Rules identifies what information is

protected, whether it be in electronic, oral or paper

form, and who may have access to that information


The Security Rules identifies steps for ensuring that

only those who should have access to electronic PHI

(ePHI) will actually have access.

administrative safeguards
Administrative Safeguards
  • The Administrative Safeguards require that facilities develop processes, policies and procedures to prevent, detect, contain, and correct security violations.
physical safeguards
Physical Safeguards

The purpose of physical safeguards is to help protect the physical computer systems and related buildings and equipment from:

- Fire

- Other natural and environmental hazards

- Unauthorized access.

technical safeguards
Technical Safeguards

Some of the processes used to promote compliance with the

Technical Safeguard rule include:

  • Computer system access, such as passwords
  • Assigning security levels based on user identify or job responsibility
  • Proper identification of individuals requesting access to ePHI
  • Audit trails that record system activity as it occurs
security safeguards
Security Safeguards

Passwords - don’t share and don’t post .

Workstations - secure your workstation, use screen savers, lock your computer if unattended, log off when not in use, log off at night.

E-mail - avoid sending sensitive/confidential patient information.

Removable media (disks, CDs,) - lock up and store, dispose/destroy properly.

Internet - firewalls, monitor and audit usage, utilize virus protection.