Current Developments in Privacy and Security Rule Enforcement

Size: px
Start display at page:

Download "Current Developments in Privacy and Security Rule Enforcement"

Transcription

1 Current Developments in Privacy and Security Rule Enforcement Hamline University College of Law Health Law Institute National Speakers Series Jerome B. Meites, Esq. Chief Regional Civil Rights Counsel Region V United States Department of Health and Human Services Office of the General Counsel

2 Disclaimer These power point slides, along with the remarks of Mr. Meites, are intended to be purely informational and informal in nature. Nothing in the slides or in Mr. Meites statements are intended to represent or reflect the official interpretation or position of the Department of Health and Human Services, the Office for Civil Rights, or the Office of General Counsel. 1

3 Topics 2013: A Major Year for Privacy and Security Recent OCR Enforcement Actions Enforcement Statistics and Upcoming Enforcement Activities Omnibus Regulations and Related Guidance Patients Right to Restrict and the Breach Notification Rule Compliance Audits Other Issues: State AGs and the Accounting Rule OCR Resources 2

4 HIPAA Enforcement Actions: Recent Cases and Trends Security Rule and Privacy Rule Cases from

5 Affinity Settles in Photocopier Security Rule Breach Case for $1,215,780 Affinity Health Plan impermissibly disclosed the protected health information of up to 344,579 individuals when it returned multiple photocopiers to a leasing agent without erasing the data contained on the copier hard drives. OCR s investigation revealed that Affinity failed to incorporate the electronic protected health information stored in copier s hard drives in its analysis of risks and vulnerabilities as required by the Security Rule, and failed to implement policies and procedures when returning the hard drives to its leasing agents. The corrective action plan required Affinity to use its best efforts to retrieve all hard drives that were contained on photocopiers previously leased and that remained in the possession of the leasing agent, and to take certain measures to safeguard all ephi. 4

6 WellPoint pays $1.7 million for leaving information accessible over Internet WellPoint s breach report indicated that security weaknesses in an online application database left the electronic protected health information (ephi) of 612,402 individuals accessible to unauthorized individuals over the Internet. OCR s investigation indicated that WellPoint did not implement appropriate administrative and technical safeguards as required under the HIPAA Security Rule: WellPoint did not adequately implement policies and procedures for authorizing access to the on-line application database. Did not perform an appropriate technical evaluation in response to a software upgrade to its information systems. Did not have technical safeguards in place to verify the person or entity seeking access to electronic protected health information maintained in its application database. 5

7 Hospice of North Idaho, a Small Provider, Pays $50,000 to Settle This was the first case involving a breach report for PHI of fewer than 500 individuals which resulted in the execution of a Resolution Agreement by the CE and the payment of a Resolution Amount to OCR, namely $50,000. In 2010, Hospice of North Idaho (HONI) submitted a breach notification, reporting that a laptop containing the PHI of 441 patients had been stolen. OCR s investigation showed that HONI had not conducted a risk analysis and had not promulgated a policy designed to ensure the security of PHI held on mobile media devices. Since the breach was discovered, HONI did take substantial steps to improve its privacy and security compliance program. 6

8 Adult & Pediatric Dermatology Pays $150,000 to Settle Breach Notification Case OCR received a report that an unencrypted thumb drive containing ephi for 2200 individuals was stolen from a staffer s car. The thumb drive was never recovered. OCR investigation showed that APDerm had not conducted an analysis of risks and vulnerabilities regarding ephi. APDerm did not have a written policy for reporting breaches and training employees on Privacy and Security Rule issues. 7

9 Shasta Regional Medical Center Settles Privacy Rule Case for $275,000 for Impermissible Disclosure SRMC failed to safeguard the patient s protected health information (PHI) from impermissible disclosure by intentionally disclosing PHI to multiple media outlets on at least three separate occasions, without a valid written authorization. OCR s review indicated that senior management at SRMC impermissibly shared details about the patient s medical condition, diagnosis and treatment in an to the entire workforce. In addition, SRMC failed to sanction its workforce members for impermissibly disclosing the patient s records pursuant to its internal sanctions policy. A corrective action plan (CAP) required SRMC to update its policies and procedures on safeguarding PHI from impermissible uses and disclosures and to train its workforce members. The CAP also required fifteen other hospitals or medical centers under the same ownership or operational control as SRMC to attest to their understanding of permissible uses and disclosures of PHI, including disclosures to the media. 8

10 Lessons Learned HIPAA covered entities and their business associates are required to undertake a careful risk analysis to understand the threats and vulnerabilities to individuals data, and have appropriate safeguards in place to protect this information. Take caution when implementing changes to information systems, especially when those changes involve updates to Web-based applications or portals that are used to provide access to consumers health data using the Internet. Senior leadership helps define the culture of an organization and is responsible for knowing and complying with the HIPAA privacy and security requirements to ensure patients rights are fully protected. 9

11 Enforcement Statistics and Upcoming Enforcement Activities 10

12 HIPAA Compliance/Enforcement (As of December 31, 2013) TOTAL (since 2003) Complaints Filed 90,000 Cases Investigated 31,925 Cases with Corrective Action 22,026 Civil Monetary Penalties & Resolution Agreements (since 2008) $18.6 million 11

13 Top Five Issues Nationally in Cases Closed in 2013 with Corrective Action 1. Impermissible Uses and Disclosures of PHI 2. Lack of adequate physical, technical, or administrative safeguards 3. Individuals or their Representatives Being Denied Access to their PHI 4. Minimum Necessary 5. Lack of Mitigation by CE 12

14 Minnesota Statistics Since 2003 Investigated Cases in which no violation of the Privacy or Security Rule was found 12% Cases resolved after Intake and Review with no investigation being undertaken 60% Investigated Cases Resolved with Corrective Action by CE 27% 13

15 Eye to the Future Increased efficiency High-impact cases Audit HHS expects full compliance, no matter the size of a covered entity. Assure that policies relating to privacy, security and breach notification are up- to- date and effectively implemented. 14

16 HIPAA Privacy, Security, Breach Compliance and Enforcement What s to Come Resolution Agreements/Corrective Action Plans Continue to increase activity and resources Maintain focus on fundamentals of compliance programs Address emerging issues Investigated Complaints/Compliance Reviews New web portal for complaints/centralized intake Strategic approach to increase efficiencies, identify cases for investigation Breach Reports Redesigned website for 500+ postings htool.html 15

17 Omnibus Regulations and Related Guidance 16

18 HIPAA/HITECH/GINA Omnibus Final Rule Important Dates Published in Federal Register January 25, 2013 Effective Date March 26, 2013 Compliance Date September 23, 2013 Deadline for Pre-Existing BA Contracts to Conform September 22,

19 HIPAA/HITECH/GINA Omnibus Final Rule What s Included HITECH Privacy & Security Business associates Electronic access Marketing Fundraising Sale of protected health information (PHI) Right to request restrictions HITECH Breach Notification HITECH Enforcement GINA Privacy Other Modifications Research Notice of privacy practices Decedents Student immunizations 18

20 HIPAA/HITECH Guidance What s Done Omnibus Final Rule De-identification Combined Regulation Text Sample BA provisions Refill Reminder Factsheets on Student Immunizations and Decedents Model Notice of Privacy Practices English and Spanish Versions Other Guidance Ability to report serious and imminent threats Permitted mental health disclosures Right to access updated for e-access requirements Law enforcement guide 19

21 Guidance and Proposed Rulemaking Regarding Potential Gun Violence On January 13, 2013, OCR issued a letter to health care providers throughout the country reminding them that the Privacy Rule permitted disclosures of an individual s PHI when the provider had a good faith reason to fear that the individual intends imminent harm to himself or others. See 45 C.F.R (j). On April 23, 2013, OCR published an Advanced Notice of Proposed Rulemaking in the Federal Register seeking public input on how to remove barriers states currently face under HIPAA in reporting such concerns without discouraging individuals from seeking necessary mental health services. OCR received over 2000 comments. On January 7, 2014, OCR published a proposed rule in the Federal Register. It allows states and certain CEs greater flexibility than was permitted previously in reporting to the National Instant Criminal Background Check System (NICS) minimum necessary identifying information about individuals who have been involuntarily committed or otherwise found by a lawful authority to be a threat to themselves or others. March 10, 2014 is the last day for the submission of comments on the proposed rule online or by mail. 20

22 Guidance Regarding the Sharing of Mental Health Information In September 2013, OCR issued extensive guidance regarding the issue of when information about an individual who is receiving mental health care treatment can be shared with the individual s family and others involved in his or her care. The guidance also addresses the patient s capacity to agree to or object to the sharing of such information. It also addresses related law enforcement issues. 21

23 Guidance Regarding Marketing and Refill Reminders Also in September 2013, OCR issued guidance regarding the refill exception from the marketing provision of the Privacy Rule. Normally, under the marketing provisions, as amended by the omnibus regulations that took effect in 2013, an individual has to provide written authorization before his or her PHI can be sued for marketing purposes. However, the guidance makes clear that prescription refill reminders and other communications about a currently prescribed drug or biologic are generally exempt from the authorization requirement. In addition, a CE can receive financial remuneration from the drug manufacturer or similar third party provided that the remuneration is reasonably related to the CE s cost of making the communication. 22

24 Guidance Regarding Disclosure of Decedents PHI The omnibus regulations contained changes to the original April 2003 version of the Privacy Rule regarding the ability of family members to access a deceased relative s PHI. Originally, only an executor or administrator could access a decedent s PHI, unless state law permitted other individuals, such as surviving spouses or adult children to do so. Now, in most instances, any member of the family or other person who was involved in the provision of care to a deceased individual has a right to access his or her PHI, even if that person is not the decedent s personal representative. In September 2013, OCR issued guidance regarding these changes to the Privacy Rule. 23

25 Model Notice of Privacy Practices Notice in the form of a booklet; A layered notice that presents a summary of the information on the first page, followed by the full content on the following pages; A notice with the design elements found in the booklet, but formatted for full page presentation. A text only version of the notice; Different versions for plans and health care providers. 24

26 HIPAA/CLIA Final Rule Now in Effect: Patient Right of Access to Test Results Center for Medicare and Medicaid Services Enforcement Amends Clinical Laboratory Improvement Amendments (CLIA) regulations to allow labs to give patients completed test results OCR Enforcement Amends HIPAA right to access to remove exemption for CLIA labs Individual has right to access and get copy of PHI in DRS of labs, including right to electronic copy Access obligations on labs same as for other covered entities Individual can still go through physician to obtain test results Dates Publish in FR -- February 6 Effective Date -- April 7 HIPAA Compliance Date -- October 8 25

27 HIPAA/HITECH Guidance What s to Come Guidance on Omnibus Final Rule Breach Safe Harbor Update Breach Risk Assessment Tool Minimum Necessary More on Marketing Security Rule Updates small provider risk analysis tool More Factsheets on other provision Model Notice Web based version challenge issued Other YouTube new content; more Spanish versions Medscape new module coming soon -- EHRs and HIPAA: Steps for Maintaining the Privacy and Security of Patient Information 26

28 Patients Right To Restrict and The Breach Notification Rule 27

29 Patient Right to Request Restrictions Old Rule Under the April 2003 version of the Privacy Rule, an individual had the right to request a covered entity to place a restriction regarding use and disclosure of his or her PHI for treatment, payment, and health care operations (and certain other reasons). The CE was not required to agree to any restriction. However, if the CE did agree, the CE was bound by the restriction. 28

30 Right to Require Restrictions New Rule as of September 2013 Under the Omnibus Regulations, the CE must agree to an individual s request to restrict the disclosure of PHI to the individual s health plan if: PHI pertains solely to health care for which the individual (or a person on behalf of individual other than the health plan) has paid the CE in full, out-of-pocket; and The disclosure is not required by other law. The CE is encouraged, but not required, to notify downstream providers of the restriction The Preamble to the Omnibus Regulations contained in the January 25, 2013 issue of the Federal Register provides guidance on the scope of the restriction and other potential implementation issues, including a number of illustrative, hypothetical cases. The old permissive rule still applies to all other requests for restrictions from an individual. 29

31 Breach Notification Interim Final Rule Issued in August 2009 & Effective Until September 2013 Pertained to impermissible use or disclosure of unsecured PHI which compromises the security or privacy of the information Compromises meant that the breach posed a significant risk of financial, reputational, or other harm to the individual To determine if it must notify OCR, the Preamble to the interim final rule stated that the CE/BA had to perform a risk assessment, based on at least: What type or amount of PHI was used or disclosed Who received/accessed the information Potential that PHI was actually accessed or acquired What steps were taken to mitigate There were exceptions for inadvertent, harmless mistakes There was also a narrow exception for limited data sets without dates of birth and zip codes 30

32 Definition of Breach New Rule Under the omnibus regulations, the risk of harm standard has been removed Impermissible use/disclosure of (unsecured) PHI is presumed to require the issuance of a breach notification, unless the CE/BA can demonstrate that there is a low probability that PHI has been compromised, based on a risk assessment of at least the following: Nature and extent of the PHI involved Who received/accessed the PHI What is the potential that PHI was actually acquired or viewed The extent to which risk to the data has been mitigated Exceptions for inadvertent, harmless mistakes remain Exception for limited data sets without dates of birth and zip codes has been removed 31

33 Breach Notification Makes permanent the notification and other provisions of the August 2009 interim final rule, with only minor changes/clarifications, e.g., Clarifies that notification to Secretary of smaller breaches to occur within 60 days of end of calendar year in which breaches were discovered (versus occurred) 32

34 Breach Notification Highlights September 2009 through November 6, reports involving over 500 individuals 84,963 reports involving under 500 individuals Top types of large breaches Theft Unauthorized Access/Disclosure Loss Top locations for large breaches Laptops Paper records Desktop Computers Portable Electronic Device 33

35 Spotlight on Largest Breaches of 2012 Hacking network server 780,000 affected Backup tapes stored at hospital cannot be found and are presumed lost 315,000 affected Unencrypted s sent to employee s unsecured address 228,435 affected Theft of laptop from employee s vehicle 116,506 affected Unauthorized access to e-phi stored in database 105,646 affected Hacking database stored on network server 70,000 affected 34

36 Breach Notification: 500+ Breaches by Type of Breach Hacking/IT Incident 7% Loss 14% Improper Disposal 5% Unknown 3% Unauthorized Access/ Disclosure 20% Theft 51% Data as of January

37 Breach Notification: 500+ Breaches by Location of Breach EMR 2% 3% Other 10% Network Server 11% Paper Records 22% Portable Electronic Device 14% Laptop 23% Desktop Computer 15% Data as of January

38 COMPLIANCE AUDITS 37

39 Audit Program HITECH Act Sec Periodic audits to ensure covered entities and business associates comply with requirements of HIPAA and HITECH Audit Objectives Examine mechanisms for compliance Identify best practices Discover risks and vulnerabilities that may not have come to light through complaint investigations and compliance reviews Renew attention of covered entities to health information privacy and security compliance activities 38

40 Compliance and Enforcement: Audit Where We Have Been Description Vendor Status/Timeframe Audit program development study Booz Allen Hamilton Closed 2010 Covered entity identification and cataloguing Booz Allen Hamilton Closed 2011 Develop audit protocol and conduct audits KPMG, Inc. Closed Evaluation of audit program PWC, LLP Closed

41 Pilot Process Audit Pilot Completed Tiered approach for snapshot of compliance across covered entity types, sizes, complexity Sample of 115 covered entities selected spread across 4 tiers All audits were completed by December 2012 OCR published audit protocol Issued final reports to entities audited in pilot 40

42 Audit Pilot Observations Completed Audits of 115 entities 61 Providers, 47 Health Plans, 7 Clearinghouses No findings or negative observations for 13 entities (11%) 2 Providers, 9 Health Plans, 2 Clearinghouses Total 979 audit findings and observations 293 Privacy 592 Security 94 Breach Notification Percentage of Security Rule findings and observations was double what would have been expected based on the protocol Smaller entities (Level 4) struggled with all three areas 41

43 Summary of Entities Audited Level 1 Entities Large Provider / Payer Extensive use of HIT - complicated HIT enabled clinical /business work streams Revenues and or assets greater than $1 billion Level 2 Entities Large regional hospital system (3-10 hospitals/region) / Regional Insurance Company Paper and HIT enabled work flows Revenues and or assets between $300 million and $1 billion Level 3 Entities Community hospitals, outpatient surgery, regional pharmacy / All Self-Insured entities that don t adjudicate their claims Some but not extensive use of HIT mostly paper based workflows Revenues between $50 million and $300 million Level 4 Entities Small Providers (10 to 50 Provider Practices, Community or rural pharmacy) Little to no use of HIT almost exclusively paper based workflows Revenues less than $50 million 42

44 Size/Type of Entities Audited Level 1 Level 2 Level 3 Level 4 Total Health Plans Healthcare Providers Healthcare Clearinghouses Total Data as of December

45 Types of Privacy Rule Audit Findings 50% 45% 40% 35% 30% 25% 20% 15% 10% 5% 0% 20% Notice of Privacy Practices 2% Restriction Requests & Alternative Communications 16% Individual Right of Access 18% Administrative Standards 44% Uses and Disclosures of PHI Data as of December

46 Types of Security Rule Audit Findings 20% 18% 18% 16% 14% 12% 10% 12% 14% 9% 14% 14% 8% 6% 4% 2% 0% Risk Analysis Access Management Security Incident Procedures Contingency Planning Audit Controls and Monitoring Movement and Destruction of Media Data as of December

47 Compliance and Enforcement Audit What s Ahead in 2014 Formal Program Evaluation 2013 Internal analysis for follow up and next steps Creation of technical assistance based on results Determine where entity follow up is appropriate Identify leading practices Revise Protocol to reflect Omnibus Rule Ongoing program design and focus Business Associates Accreditation /Certification correlations 46

48 Resumption of Audits in 2014 OCR will be conducting a second round of compliance audits on its own beginning later in 2014 and continuing into OCR selected from a very large data base an oversupply of 1200 organizations as possible subjects of the new round of audits. OCR is currently making determinations about the listed organizations to determine their suitability for audit. Roughly 800 of the organizations are covered entities and 400 are business associates. 47

49 New Issues Likely to be Covered in Audits OCR expects to revise its 2012 audit protocol to include changes brought by the Omnibus Regulations. OCR also expects a more intensive focus on organizations analysis of potential risks and vulnerabilities involving the PHI which they generate and which comes in their custody as OCR found the lack of any and/or adequate risks analysis to be very high in the 2012 audit. 48

50 Other Issues State AGs and the Accounting Rule 49

51 OCR and State Attorneys General Under the HITECH Act, enacted in 2009, state attorneys general were authorized, for the first time, to bring actions for injunction in federal district court to enforce the Privacy and Security Rule. State AGs must inform OCR prior to their commencement of such actions. Under the HITECH Act, OCR (HHS) can intervene in any such litigation as of right. 50

52 Result of AG Intervention So far, AGs have brought cases in five different states, including the Accretive litigation in Minnesota. OCR has not yet chosen to intervene in any of the AG cases. In 2010, OCR provided extensive training to the AGs from all 50 states. The training manuals are on the OCR website. OCR regional attorneys continue to work closely with the AGs, providing guidance when requested. 51

53 Accounting for Disclosures Final Rule When OCR issued as proposed rules, most of the provisions which became the final Omnibus Regulations in 2013, the proposed rules included significant changes to the original 2003 requirements for covered entities to provide accountings to individuals as to who accessed the individual s PHI. Industry publications indicated that many compliance officers and other representatives of covered entities had serious reservations or objections to the proposed changes regarding the accounting provisions and submitted comments to OCR, expressing their concerns. OCR did not include a final version of the accounting provisions in the omnibus regulations. OCR has stated publicly that it is still reviewing the comments it received regarding the accounting issues and does not know when it will publish a further issuance regarding accountings in the Federal Register. 52

54 OCR RESOURCES 53

55 We ve Been Busy New Compliance Assistance Tools for Covered Entities and Business Associates The HIPAA Omnibus Rule X-QL9PoePU 54

56 New OCR Resource Center at Medscape.org Video Programs module imbedded into page for dynamic interest OCR Educational Links, Including Mobile Device Content 55

57 Two New Learning Modules for Free CME and CE Credit The goal of this activity is to describe steps in analyzing and managing risks related to the security of protected health information The goal of this activity is to describe steps healthcare practices should take to assess and improve the security of protected health information on mobile devices. 56

58 Your Mobile Device and Health Information Privacy and Security Posting Date: 9/13/13 13,969 Total Learners 28,518 Total Page Views 7,657 MD Learners 3,627 Nurse Learners 252 Pharmacist Learners 586 Physician Assistants 1,847 (Other HCP s) 3,378 MD Test Takers Credits 57

59 Consumer Awareness and Engagement Your New Rights Under HIPAA - Consumers =3-wV23_E4eQ Over 262,000 views since September 4, 2013 Visit us at 58

60 OCR s YouTube Videos Your New Rights Under HIPAA 264,781 Views The HIPAA Omnibus Rule 273,927 Views Your Health Information, Your Rights 116,291 Views The Right to Access Your Health Information 84,909 Views EHRs: Privacy and Security 5,645 Views Su Informacion de Salud, Sus Derechos 503,898 Views Treatment, Payment and Health Care Operations 77,967 Views Communicating with Friends and Family 97,428 Views Explaining the Notice of Privacy Practices 124,888 Views HIPAA Security Rule 291,263 Views 1,840,997 TOTAL VIEWS FROM FEB to JAN 30, 2013 Visit us at 59

61 Contact Information Jerome B. Meites Chief Regional Civil Rights Counsel Office of the General Counsel Region V United States Department of Health and Human Services 233 North Michigan Avenue Suite 700 Chicago, Illinois Jerome.Meites@hhs.gov 60

Breach Notification and Enforcement

Breach Notification and Enforcement Breach Notification and Enforcement Sponsored by Health Information and Technology Practice Group June 14, 2012 Presenter: Patricia A. Markus, Esquire, Smith Moore Leatherwood LLP, Raleigh, NC, Trish.Markus@smithmoorelaw.com

More information

UNDERSTANDING THE HIPAA/HITECH BREACH NOTIFICATION RULE 2/25/14

UNDERSTANDING THE HIPAA/HITECH BREACH NOTIFICATION RULE 2/25/14 UNDERSTANDING THE HIPAA/HITECH BREACH NOTIFICATION RULE 2/25/14 RULES Issued August 19, 2009 Requires Covered Entities to notify individuals of a breach as well as HHS without reasonable delay or within

More information

Patient Privacy and Security: Data Breach Reporting and other HIPAA Changes

Patient Privacy and Security: Data Breach Reporting and other HIPAA Changes Patient Privacy and Security: Data Breach Reporting and other HIPAA Changes Paul T. Smith, Partner, Davis Wright Tremaine James B. Wieland, Shareholder, Ober Kaler 1 Developments The Health Information

More information

AMERICAN RECOVERY & REINVESTMENT ACT OF 2009 TITLE XIII HEALTH INFORMATION TECHNOLOGY ANALYSIS OF PRIVACY AND SECURITY REQUIREMENTS (SUBPART D)

AMERICAN RECOVERY & REINVESTMENT ACT OF 2009 TITLE XIII HEALTH INFORMATION TECHNOLOGY ANALYSIS OF PRIVACY AND SECURITY REQUIREMENTS (SUBPART D) Introduction: AMERICAN RECOVERY & REINVESTMENT ACT OF 2009 TITLE XIII HEALTH INFORMATION TECHNOLOGY ANALYSIS OF PRIVACY AND SECURITY REQUIREMENTS (SUBPART D) The purpose of this document is to provide

More information

Investigating Privacy Breaches under HITECH and HIPAA

Investigating Privacy Breaches under HITECH and HIPAA Investigating Privacy Breaches under HITECH and HIPAA Barry Herrin Smith Moore Leatherwood LLP 1180 W. Peachtree St. NW, Suite 2300 Atlanta, Georgia 30309 T (404) 962-1027 F (404) 962-1200 Presented by:

More information

HIPAA Enforcement and Settlements. Alissa Smith, Partner Dorsey & Whitney LLP Des Moines, IA

HIPAA Enforcement and Settlements. Alissa Smith, Partner Dorsey & Whitney LLP Des Moines, IA HIPAA Enforcement and Settlements Alissa Smith, Partner Dorsey & Whitney LLP Des Moines, IA 1 Objectives Describe HIPAA s Enforcement Rule Review numerous government enforcement actions under HIPAA Review

More information

EXHIBIT G PRIVACY AND INFORMATION SECURITY PROVISIONS

EXHIBIT G PRIVACY AND INFORMATION SECURITY PROVISIONS Page 1 of 24 EXHIBIT G PRIVACY AND INFORMATION SECURITY PROVISIONS This Exhibit G is intended to protect the privacy and security of specified Department information that Contractor may access, receive,

More information

Health Information Technology for Economic and Clinical Health (HITECH) Act Privacy and Security Provisions

Health Information Technology for Economic and Clinical Health (HITECH) Act Privacy and Security Provisions Health Information Technology for Economic and Clinical Health (HITECH) Act Privacy and Security Provisions (Subtitle D of Title XIII of Division A of the American Recovery and Reinvestment Act (ARRA)

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT WHEREAS, the American Osteopathic Board of Orthopedic Surgery (AOBOS) provides certain board certification services to osteopathic physicians who complete appropriate postdoctoral

More information

Model Business Associate Agreement

Model Business Associate Agreement Model Business Associate Agreement Instructions: The Texas Health Services Authority (THSA) has developed a model BAA for use between providers (Covered Entities) and HIEs (Business Associates). The model

More information

RESOLUTION AGREEMENT. I. Recitals

RESOLUTION AGREEMENT. I. Recitals RESOLUTION AGREEMENT I. Recitals 1. Parties. The Parties to this Resolution Agreement ( Agreement ) are the United States Department of Health and Human Services, Office for Civil Rights ( HHS ) and Affinity

More information

HIPAA BUSINESS ASSOCIATE AGREEMENT. ( BUSINESS ASSOCIATE ) and is effective as of ( Effective Date ). RECITALS

HIPAA BUSINESS ASSOCIATE AGREEMENT. ( BUSINESS ASSOCIATE ) and is effective as of ( Effective Date ). RECITALS HIPAA BUSINESS ASSOCIATE AGREEMENT This HIPAA Business Associate Agreement ( Agreement ) is entered into by and between the Trustees of the University of Pennsylvania as owner and operator of the University

More information

rdd Doc 825 Filed 12/11/17 Entered 12/11/17 16:29:55 Main Document Pg 1 of 4

rdd Doc 825 Filed 12/11/17 Entered 12/11/17 16:29:55 Main Document Pg 1 of 4 17-22770-rdd Doc 825 Filed 12/11/17 Entered 12/11/17 16:29:55 Main Document Pg 1 of 4 UNITED STATES BANKRUPTCY COURT SOUTHERN DISTRICT OF NEW YORK ) In re: ) Chapter 11 ) 21st CENTURY ONCOLOGY HOLDINGS,

More information

HIPAA Compliance During Litigation and Discovery

HIPAA Compliance During Litigation and Discovery Presenting a live 90-minute webinar with interactive Q&A HIPAA Compliance During Litigation and Discovery Safeguarding PHI and Avoiding Violations When Responding to Subpoenas and Discovery Requests THURSDAY,

More information

HIPAA DATA USE AGREEMENT

HIPAA DATA USE AGREEMENT HIPAA DATA USE AGREEMENT This Data Use Agreement (this "Agreement") is entered into effective as of 20 and until months thereafter the Effective Date by and among St. Jude Children s Research Hospital,

More information

Right to Request Access to Designated Record Set

Right to Request Access to Designated Record Set HIPAA Procedure 5002B Right to Request Access and Amendment to Designated Record Effective Date: April 14, 2003 Revised Date: November 2, 2016 Right to Request Access to Designated Record... 1 Denial of

More information

BUSINESS ASSOCIATE AGREEMENT WITH COVERED ENTITY

BUSINESS ASSOCIATE AGREEMENT WITH COVERED ENTITY BUSINESS ASSOCIATE AGREEMENT WITH COVERED ENTITY Date: 09/23/2013 Business Associate: Name: BeneFLEX HR Resources, Inc. Address: 10805 Sunset Office Drive, Ste 401 St. Louis, MO 63127 Covered Entity: This

More information

COMMONWEALTH OF MASSACHUSETTS. ) COMMONWEALTH OF MASSACHUSETTS, ) ) Plaintiff, ) ) v. ) ) SOUTH SHORE HOSPITAL, INC., ) ) Defendant.

COMMONWEALTH OF MASSACHUSETTS. ) COMMONWEALTH OF MASSACHUSETTS, ) ) Plaintiff, ) ) v. ) ) SOUTH SHORE HOSPITAL, INC., ) ) Defendant. COMMONWEALTH OF MASSACHUSETTS SUFFOLK, ss. SUPERIOR COURT CIVIL ACTION NO. ) COMMONWEALTH OF MASSACHUSETTS, ) ) Plaintiff, ) ) v. ) ) SOUTH SHORE HOSPITAL, INC., ) ) Defendant. ) ) FINAL JUDGMENT BY CONSENT

More information

Peg Schmidt, RHIA CHPS and Amy Derlink, RHIA, CHA April 10, 2015

Peg Schmidt, RHIA CHPS and Amy Derlink, RHIA, CHA April 10, 2015 Peg Schmidt, RHIA CHPS and Amy Derlink, RHIA, CHA April 10, 2015 1 Step One Gather the facts Who is the requestor? Why are they requesting (purpose)? What type of PHI are they asking for? (record type)

More information

HIPAA Crimes: How the New Crime Wave Affects You. May 17, 2016

HIPAA Crimes: How the New Crime Wave Affects You. May 17, 2016 HIPAA Crimes: How the New Crime Wave Affects You May 17, 2016 Michele L. Adelman, Partner, Foley Hoag LLP White Collar Crime & Government Investigations Practice Speakers Michele brings over a decade of

More information

A Compliance Guide for Covered Entities and Business Associates

A Compliance Guide for Covered Entities and Business Associates A Compliance Guide for Covered Entities and Business Associates Kate Borten, CISSP, CISM A Compliance Guide for Covered Entities and Business Associates Kate Borten, CISSP, CISM : A Compliance Guide for

More information

KAISER FOUNDATION HOSPITALS ON BEHALF OF KAISER FOUNDATION HEALTH PLAN OF THE MID-ATLANTIC STATES, INC.

KAISER FOUNDATION HOSPITALS ON BEHALF OF KAISER FOUNDATION HEALTH PLAN OF THE MID-ATLANTIC STATES, INC. KAISER FOUNDATION HOSPITALS ON BEHALF OF KAISER FOUNDATION HEALTH PLAN OF THE MID-ATLANTIC STATES, INC. KP CONTRACTOR AFFILIATE WEB SITES LICENSE PROVIDER ENTITY AGREEMENT License Subject to the terms

More information

HIPAA Privacy Compliance Initiative: Final Rules Impact Employer Health Plans

HIPAA Privacy Compliance Initiative: Final Rules Impact Employer Health Plans HIPAA Privacy Compliance Initiative: Final Rules Impact Employer Health Plans www.morganlewis.com Presenters: Sage Fattahian Lauren Licastro Georgina O Hara Date: February 8, 2013 Time: 12:30-1:30 p.m.

More information

The Lawyer s Ethical and Legal Duties to protect Private Information

The Lawyer s Ethical and Legal Duties to protect Private Information The Lawyer s Ethical and Legal Duties to protect Private Information Claude E. Ducloux Attorney At Law Board Certified Texas Board of Legal Specialization Civil Trial Law Civil Appellate Law Director of

More information

H I P AA B U S I N E S S AS S O C I ATE AGREEMENT

H I P AA B U S I N E S S AS S O C I ATE AGREEMENT H I P AA B U S I N E S S AS S O C I ATE AGREEMENT This HIPAA BUSINESS ASSOCIATE AGREEMENT (the BAA ) is entered into by and between Educators Mutual Insurance Association of Utah and its subsidiaries (

More information

TRICARE Operations Manual M, April 1, 2015 Administration. Chapter 1 Section 5

TRICARE Operations Manual M, April 1, 2015 Administration. Chapter 1 Section 5 Administration Chapter 1 Section 5 Revision: 1.0 GENERAL 1.1 Contractors shall comply with all federal laws which apply to the administration of TRICARE health plans. In many situations where federal law

More information

Delaware State Supplemental Rebate Agreement And (Manufacturer) As used in this Agreement, the following terms have the following

Delaware State Supplemental Rebate Agreement And (Manufacturer) As used in this Agreement, the following terms have the following Delaware State Supplemental Rebate Agreement And (Manufacturer) The Delaware Department of Health and Social Services, Division of Medicaid and Medical Assistance (hereinafter Department or DMMA ) and

More information

Site Access Agreement. (hereinafter referred to as the

Site Access Agreement. (hereinafter referred to as the Site Access Agreement Business Name: Site ) (hereinafter referred to as the Business Address: THIS AGREEMENT made effective as of this day of, 20 (hereinafter the Agreement ), between The Cooper Health

More information

Security Breach Notification Chart

Security Breach Notification Chart Security Breach Notification Chart Perkins Coie's Privacy & Security practice maintains this comprehensive chart of state laws regarding security breach notification. The chart is for informational purposes

More information

[Enter Organization Logo] DISCLOSURES OF SUBSTANCE USE DISORDER PATIENT RECORDS. Policy Number: [Enter] Effective Date: [Enter]

[Enter Organization Logo] DISCLOSURES OF SUBSTANCE USE DISORDER PATIENT RECORDS. Policy Number: [Enter] Effective Date: [Enter] DISCLOSURES OF SUBSTANCE USE DISORDER PATIENT RECORDS Policy Number: [Enter] Effective Date: [Enter] [GPM Note: In January 2017, the Department of Health and Human Services, Substance Abuse and Mental

More information

Commonwealth of Massachusetts County of Suffolk The Superior Court NOTICE OF DOCKET ENTRY

Commonwealth of Massachusetts County of Suffolk The Superior Court NOTICE OF DOCKET ENTRY Commonwealth of Massachusetts County of Suffolk The Superior Court CIVIL DOCKET#: SUCV2012-01925-B RE: Massachusetts v South Shore Hospital Inc TO: Shannon C Choy-Seymour, Esquire Mass Atty General's Office

More information

Security Breach Notification Chart

Security Breach Notification Chart Security Breach Notification Chart Perkins Coie's Privacy & Security practice maintains this comprehensive chart of state laws regarding security breach notification. The chart is for informational purposes

More information

BILL NO. 42. Health Information Act

BILL NO. 42. Health Information Act HOUSE USE ONLY CHAIR: WITH / WITHOUT 4th SESSION, 64th GENERAL ASSEMBLY Province of Prince Edward Island 63 ELIZABETH II, 2014 BILL NO. 42 Health Information Act Honourable Doug W. Currie Minister of Health

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT THIS BUSINESS ASSOCIATE AGREEMENT (the Agreement ) is effective this day of, 2008 (the Effective Date ) by and between, (the Covered Entity ) and (the Business Associate ).

More information

Security Breach Notification Chart

Security Breach Notification Chart Security Breach Notification Chart Perkins Coie's Privacy & Security practice maintains this comprehensive chart of state laws regarding security breach notification. The chart is for informational purposes

More information

Technical Corrections to the HIPAA Privacy, Security, and Enforcement Rules. AGENCY: Office for Civil Rights, Department of Health and Human Services.

Technical Corrections to the HIPAA Privacy, Security, and Enforcement Rules. AGENCY: Office for Civil Rights, Department of Health and Human Services. This document is scheduled to be published in the Federal Register on 06/07/2013 and available online at http://federalregister.gov/a/2013-13472, and on FDsys.gov DEPARTMENT OF HEALTH AND HUMAN SERVICES

More information

HITECH Omnibus Business Associate Agreement DU Hybrid CE ra FINAL

HITECH Omnibus Business Associate Agreement DU Hybrid CE ra FINAL BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement (the Agreement ) by and between Drexel University ( Hybrid Entity ), with a principal address at 3141 Chestnut Street, Philadelphia, PA 19104,

More information

Security Breach Notification Chart

Security Breach Notification Chart Security Breach Notification Chart Perkins Coie's Privacy & Security practice maintains this comprehensive chart of state laws regarding security breach notification. The chart is for informational purposes

More information

Health Information Technology Provisions in the Recovery Act

Health Information Technology Provisions in the Recovery Act HEALTH INFORMATION TECHNOLOGY PROVISIONS IN THE RECOVERY ACT Driving Business Advantage Health Information Technology Provisions in the Recovery Act by Brian P. Carey & Paul T. Kim April 2009 The following

More information

Government Investigations Into Cybersecurity Breaches In Healthcare

Government Investigations Into Cybersecurity Breaches In Healthcare 11 February 2016 Practice Groups: Cyber Law and Cybersecurity; Global Government Solutions; Government Enforcement; Health Care Government Investigations Into Cybersecurity Breaches In Healthcare By: Mark

More information

ELECTRONIC TRANSACTIONS TRADING PARTNER AGREEMENT BETWEEN DIRECT SUBMITTER AND WELLPOINT, INC

ELECTRONIC TRANSACTIONS TRADING PARTNER AGREEMENT BETWEEN DIRECT SUBMITTER AND WELLPOINT, INC ELECTRONIC TRANSACTIONS TRADING PARTNER AGREEMENT BETWEEN DIRECT SUBMITTER AND WELLPOINT, INC This Electronic Transactions Trading Partner Agreement, ("Agreement") is entered into by and between you "Direct

More information

1 HB By Representative Williams (P) 4 RFD: Technology and Research. 5 First Read: 13-FEB-18. Page 0

1 HB By Representative Williams (P) 4 RFD: Technology and Research. 5 First Read: 13-FEB-18. Page 0 1 HB410 2 191614-1 3 By Representative Williams (P) 4 RFD: Technology and Research 5 First Read: 13-FEB-18 Page 0 1 191614-1:n:02/13/2018:CMH*/bm LSA2018-168 2 3 4 5 6 7 8 SYNOPSIS: This bill would create

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT This BUSINESS ASSOCIATE AGREEMENT ( Agreement ) effective as of the laterdated signature hereto ( Effective Date ), identifies and clarifies the relationship and responsibilities

More information

- 79th Session (2017) Assembly Bill No. 474 Committee on Health and Human Services

- 79th Session (2017) Assembly Bill No. 474 Committee on Health and Human Services Assembly Bill No. 474 Committee on Health and Human Services CHAPTER... AN ACT relating to drugs; requiring certain persons to make a report of a drug overdose or suspected drug overdose; revising provisions

More information

IN THE WAKE OF THE SCOTUS'S AFFORDABLE CARE ACT DECISION: WHAT'S NEXT FOR HEALTH CARE PROVIDERS? [OBER KALER]

IN THE WAKE OF THE SCOTUS'S AFFORDABLE CARE ACT DECISION: WHAT'S NEXT FOR HEALTH CARE PROVIDERS? [OBER KALER] IN THE WAKE OF THE SCOTUS'S AFFORDABLE CARE ACT DECISION: WHAT'S NEXT FOR HEALTH CARE PROVIDERS? Publication IN THE WAKE OF THE SCOTUS'S AFFORDABLE CARE ACT DECISION: WHAT'S NEXT FOR HEALTH CARE PROVIDERS?

More information

Limited Data Set Data Use Agreement

Limited Data Set Data Use Agreement Limited Data Set Data Use Agreement This Agreement is made and entered into by and between (hereinafter Applicant ) and the State of Florida Agency for Health Care Administration, Florida Center for Health

More information

Comments on the Draft Digital Information Security in Healthcare Act

Comments on the Draft Digital Information Security in Healthcare Act Comments on the Draft Digital Information Security in Healthcare Act Shweta Mohandas and Amber Sinha The Centre for Internet and Society April 21, 2018 Preliminary 2 About CIS 2 General Comments 2 Privacy

More information

HIPAA Privacy Rule Compliance Issues

HIPAA Privacy Rule Compliance Issues HIPAA Privacy Rule Compliance Issues Presentation for AAPM Myra N. Moran J.D. HHS/OCR August 2, 2006 DISCLAIMER My goal in speaking with you today is to explain Privacy Rule compliance issues. I can make

More information

DATA COLLECTION AGREEMENT MASTER TERMS RECITALS

DATA COLLECTION AGREEMENT MASTER TERMS RECITALS DATA COLLECTION AGREEMENT MASTER TERMS RECITALS WHEREAS, CDR has developed the U.S. Wound Registry ( USWR ), to collect and report on standardized national clinical wound care data in connection with different

More information

OHIO MEDICAID SUPPLEMENTAL REBATE AGREEMENT

OHIO MEDICAID SUPPLEMENTAL REBATE AGREEMENT Ohio Department of Medicaid OHIO MEDICAID SUPPLEMENTAL REBATE AGREEMENT This Agreement is entered into by the following parties on the date last signed below: Pharmaceutical Manufacturer ( Manufacturer

More information

1 SB By Senators Orr and Holley. 4 RFD: Governmental Affairs. 5 First Read: 13-FEB-18. Page 0

1 SB By Senators Orr and Holley. 4 RFD: Governmental Affairs. 5 First Read: 13-FEB-18. Page 0 1 SB318 2 192523-4 3 By Senators Orr and Holley 4 RFD: Governmental Affairs 5 First Read: 13-FEB-18 Page 0 1 SB318 2 3 4 ENGROSSED 5 6 7 A BILL 8 TO BE ENTITLED 9 AN ACT 10 11 Relating to consumer protection;

More information

Subtitle F Medical Device Innovations

Subtitle F Medical Device Innovations 130 STAT. 1121 (B) unless specifically stated, have any effect on authorities provided under other sections of this Act, including any regulations issued under such sections.. (b) CONFORMING AMENDMENTS.

More information

DATA USE AGREEMENT FOR ACCESS TO PROTECTED HEALTH INFORMATION

DATA USE AGREEMENT FOR ACCESS TO PROTECTED HEALTH INFORMATION DATA USE AGREEMENT FOR ACCESS TO PROTECTED HEALTH INFORMATION This Data Use Agreement (the Agreement ) is effective between the Greenville Hospital System and Data User(s) (the Data Users ): 1. (List name

More information

1 SB By Senators Orr and Holley. 4 RFD: Governmental Affairs. 5 First Read: 13-FEB-18. Page 0

1 SB By Senators Orr and Holley. 4 RFD: Governmental Affairs. 5 First Read: 13-FEB-18. Page 0 1 SB318 2 192523-5 3 By Senators Orr and Holley 4 RFD: Governmental Affairs 5 First Read: 13-FEB-18 Page 0 1 SB318 2 3 4 ENROLLED, An Act, 5 Relating to consumer protection; to require certain 6 entities

More information

Corporate Litigation: Standing to Bring Consumer Data Breach Claims

Corporate Litigation: Standing to Bring Consumer Data Breach Claims Corporate Litigation: Standing to Bring Consumer Data Breach Claims Joseph M. McLaughlin * Simpson Thacher & Bartlett LLP April 14, 2015 Security experts say that there are two types of companies in the

More information

WASHINGTON COUNTY GUIDELINES AND PROCEDURES FOR MINNESOTA GOVERNMENT DATA PRACTICES ACT

WASHINGTON COUNTY GUIDELINES AND PROCEDURES FOR MINNESOTA GOVERNMENT DATA PRACTICES ACT General Administration Policy #1300 - Manual WASHINGTON COUNTY GUIDELINES AND PROCEDURES FOR MINNESOTA GOVERNMENT DATA PRACTICES ACT Manual #1300 Adopted by the Washington County Board of Commissioners

More information

MISSISSIPPI MEDICAID SUPPLEMENTAL DRUG REBATE AGREEMENT

MISSISSIPPI MEDICAID SUPPLEMENTAL DRUG REBATE AGREEMENT State of Mississippi Division of Medicaid MISSISSIPPI MEDICAID SUPPLEMENTAL DRUG REBATE AGREEMENT This Agreement is entered into by the following parties on the date last signed below: Pharmaceutical Manufacturer

More information

PRACTICE DIRECTION [ ] DISCLOSURE PILOT FOR THE BUSINESS AND PROPERTY COURTS

PRACTICE DIRECTION [ ] DISCLOSURE PILOT FOR THE BUSINESS AND PROPERTY COURTS Draft at 2.11.17 PRACTICE DIRECTION [ ] DISCLOSURE PILOT FOR THE BUSINESS AND PROPERTY COURTS 1. General 1.1 This Practice Direction is made under Part 51 and provides a pilot scheme for disclosure in

More information

Cops and Docs: Law Enforcement Access to Patients and Information

Cops and Docs: Law Enforcement Access to Patients and Information Cops and Docs: Law Enforcement Access to Patients and Information HIPAA Collaborative of Wisconsin October 19, 2012 Diane Welsh, von Briesen & Roper, s.c. dwelsh@vonbriesen.com or 608.661.3961 David Perlman,

More information

Sales Order (Processing Services)

Sales Order (Processing Services) SO# DIRECT CUST# INDIRECT CUST# Sales Order (Processing Services) Note: RelayHealth will assign CUST# s and SO# will be completed upon receipt. Sold To ( End User ): Bill To: Note: cannot be a P.O. Box

More information

Provider Electronic Trading Partner Agreement

Provider Electronic Trading Partner Agreement This Electronic Trading Partner Agreement ( Agreement ) is entered into as of the Day day of, 20 ( Effective Date ), by and between Blue Cross Month Year and Blue Shield of South Carolina and its subsidiaries,

More information

HEALTH INFORMATION ACT

HEALTH INFORMATION ACT Province of Alberta HEALTH INFORMATION ACT Revised Statutes of Alberta 2000 Current as of June 13, 2016 Office Consolidation Published by Alberta Queen s Printer Alberta Queen s Printer Suite 700, Park

More information

Issue Brief. A Public Policy Paper of the National Association of Mutual Insurance Companies July 2005

Issue Brief. A Public Policy Paper of the National Association of Mutual Insurance Companies July 2005 A Public Policy Paper of the National Association of Mutual Insurance Companies July 2005 By David B. Reddick State Affairs Manager Southeast Region Executive Summary State legislators have moved quickly

More information

Security Video Surveillance Policy

Security Video Surveillance Policy Security Video Surveillance Policy Policy Statement The Municipality of Central Elgin (the Municipality) recognizes the need to balance an individual s right to privacy and the need to ensure the safety

More information

Florida Senate SB 518 By Senator Saunders

Florida Senate SB 518 By Senator Saunders By Senator Saunders 1 A bill to be entitled 2 An act relating to controlled substances; 3 creating s. 831.311, F.S.; prohibiting the 4 sale, manufacture, alteration, delivery, 5 uttering, or possession

More information

ABA Privacy and Data Security Update May 14, 2013

ABA Privacy and Data Security Update May 14, 2013 ABA Privacy and Data Security Update May 14, 2013 David Keating Paul Martino Kim Peretti Bruce Sarkisian Overview Cybersecurity Legislative Developments Health Privacy Privacy and Technology International

More information

State Data Breach Notification Laws

State Data Breach Notification Laws State Data Breach Notification Laws This chart should be used for informational purposes only because the recommended actions an entity should take if it experiences a security event, incident, or breach

More information

Data, Social Media, and Users: Can We All Get Along?

Data, Social Media, and Users: Can We All Get Along? INSIGHTi Data, Social Media, and Users: Can We All Get Along? nae redacted Analyst in Cybersecurity Policy April 4, 2018 Introduction In March 2018, media reported that voter-profiling company Cambridge

More information

HP0557, LD 821, item 2, 124th Maine State Legislature, Amendment C "A", Filing Number H-625, Sponsored by

HP0557, LD 821, item 2, 124th Maine State Legislature, Amendment C A, Filing Number H-625, Sponsored by PLEASE NOTE: Legislative Information cannot perform research, provide legal advice, or interpret Maine law. For legal assistance, please contact a qualified attorney. Amend the bill by striking out everything

More information

FEDERAL AND STATE PROGRAM COMPLIANCE VERIFICATION

FEDERAL AND STATE PROGRAM COMPLIANCE VERIFICATION FEDERAL AND STATE PROGRAM COMPLIANCE VERIFICATION The Oregon Health & Science University (OHSU) integrity program requires that OHSU not employ individuals who are excluded from participation in federal

More information

Interstate Commission for Adult Offender Supervision

Interstate Commission for Adult Offender Supervision Interstate Commission for Adult Offender Supervision Privacy Policy Interstate Compact Offender Tracking System Version 3.0 Approved 04/23/2009 Revised on 4/18/2017 1.0 Statement of Purpose The goal of

More information

Contract Assurances Attachment 4. Contract Assurances

Contract Assurances Attachment 4. Contract Assurances Contract Assurances 1) The Contracting Agency assures that it and its subrecipients will establish in accordance with WIA Section 184, fiscal control and fund accounting procedures that may be necessary

More information

NOTICE TO THE INDIVIDUAL SIGNING THE ILLINOIS STATUTORY SHORT FORM POWER OF ATTORNEY FOR HEALTH CARE

NOTICE TO THE INDIVIDUAL SIGNING THE ILLINOIS STATUTORY SHORT FORM POWER OF ATTORNEY FOR HEALTH CARE NOTICE TO THE INDIVIDUAL SIGNING THE ILLINOIS STATUTORY SHORT FORM POWER OF ATTORNEY FOR HEALTH CARE (NOTICE: THE FORM THAT YOU WILL BE SIGNING IS A LEGAL DOCUMENT. IT IS GOVERNED BY THE ILLINOIS POWER

More information

STATE DATA SECURITY BREACH LEGISLATION SURVEY

STATE DATA SECURITY BREACH LEGISLATION SURVEY STATE DATA SECURITY BREACH LEGISLATION SURVEY State and Timing/ Alaska H.B. 65 Signed into law June 13, 2008. Alaska Stat. Tit. 45, Ch. 48, 10 to 90 Alaska residents. Any person doing business, any person

More information

Kim K. Ogg. Harris County District Attorney COMMUNITY ACTION PLAN. Evidence Integrity

Kim K. Ogg. Harris County District Attorney COMMUNITY ACTION PLAN. Evidence Integrity Kim K. Ogg Harris County District Attorney COMMUNITY ACTION PLAN Evidence Integrity A Policy/Program Plan Based On 2017 Community Transition Committee Recommendations. Committee Members: Sandra Guerra

More information

Sub. for HB 2183 enacts and amends several provisions in Kansas law related to the Department of Health and Environment (KDHE). Generally, the bill:

Sub. for HB 2183 enacts and amends several provisions in Kansas law related to the Department of Health and Environment (KDHE). Generally, the bill: Designation and Control of Infectious and Contagious Diseases; Office of Laboratory Services Operating Fund; Kansas Health Information Technology Act; Medical Assistance Recovery Program; Sub. for HB 2183

More information

THE SURVEILLANCE AND COMMUNITY SAFETY ORDINANCE

THE SURVEILLANCE AND COMMUNITY SAFETY ORDINANCE THE SURVEILLANCE AND COMMUNITY SAFETY ORDINANCE Whereas, the City Council finds it is essential to have an informed public debate as early as possible about decisions related to surveillance technology;

More information

Student/Queensland Health Terms of Agreement Information for Students

Student/Queensland Health Terms of Agreement Information for Students School of Health and Rehabilitation Sciences Head of School Professor Louise Hickson BSpThy(Hons), MAud, PhD CRICOS PROVIDER NUMBER 00025B Student/Queensland Health Terms of Agreement Information for Students

More information

Restatement I of the Data Use and Reciprocal Support Agreement (DURSA)

Restatement I of the Data Use and Reciprocal Support Agreement (DURSA) Restatement I of the Data Use and Reciprocal Support Agreement (DURSA) Version Date: September 30, 2014 Restatement I of the Data Use and Reciprocal Support Agreement Overview Introduction In 2008, as

More information

BUSINESS ASSOCIATE AGREEMENT (BETWEEN GIOSTARCHICAGO.COM AND GIOSTARORTHOPEDICS.COM AND GODADDY)

BUSINESS ASSOCIATE AGREEMENT (BETWEEN GIOSTARCHICAGO.COM AND GIOSTARORTHOPEDICS.COM AND GODADDY) BUSINESS ASSOCIATE AGREEMENT (BETWEEN GIOSTARCHICAGO.COM AND GIOSTARORTHOPEDICS.COM AND GODADDY) This HIPAA Business Associate Agreement ( Agreement ) is entered into by and between GoDaddy.com, LLC, a

More information

NOTICE TO THE INDIVIDUAL SIGNING THE ILLINOIS STATUTORY SHORT FORM POWER OF ATTORNEY FOR HEALTH CARE

NOTICE TO THE INDIVIDUAL SIGNING THE ILLINOIS STATUTORY SHORT FORM POWER OF ATTORNEY FOR HEALTH CARE NOTICE TO THE INDIVIDUAL SIGNING THE ILLINOIS STATUTORY SHORT FORM POWER OF ATTORNEY FOR HEALTH CARE PLEASE READ THIS NOTICE CAREFULLY. The form that you will be signing is a legal document. It is governed

More information

NOTICE TO THE INDIVIDUAL SIGNING THE ILLINOIS STATUTORY SHORT FORM POWER OF ATTORNEY FOR HEALTH CARE:

NOTICE TO THE INDIVIDUAL SIGNING THE ILLINOIS STATUTORY SHORT FORM POWER OF ATTORNEY FOR HEALTH CARE: NOTICE TO THE INDIVIDUAL SIGNING THE ILLINOIS STATUTORY SHORT FORM POWER OF ATTORNEY FOR HEALTH CARE: PLEASE READ THIS NOTICE CAREFULLY. The form that you will be signing is a legal document. It is governed

More information

Sexual Assault Survivors DNA Justice Act

Sexual Assault Survivors DNA Justice Act Sexual Assault Survivors DNA Justice Act Sample Statutory Language All copyright laws apply to the proper use and crediting of these materials. This chart is supported by Grant No. 2011 TA AX K048 awarded

More information

Health Information Privacy Code 1994

Health Information Privacy Code 1994 Health Information Privacy Code 1994 Incorporating amendments Privacy Commissioner Te Mana Matapono Matatapu New Zealand The Code of Practice comprises clauses 1-7 and rules 1-12. To assist with the use

More information

Although we encourage your participation during the presentation, it is entirely voluntary.

Although we encourage your participation during the presentation, it is entirely voluntary. M. Scott LeBlanc, JD & Thomas N. Shorter, JD FACHE Godfrey & Kahn, S.C. Friday, April 27, 2018, 1:35-2:25 pm Country Springs Hotel, Waukesha, WI 1 Although we encourage your participation during the presentation,

More information

HARVARD PILGRIM HEALTH CARE, INC. PRIVACY AND SECURITY AGREEMENT

HARVARD PILGRIM HEALTH CARE, INC. PRIVACY AND SECURITY AGREEMENT HARVARD PILGRIM HEALTH CARE, INC. PRIVACY AND SECURITY AGREEMENT THIS PRIVACY AND SECURITY AGREEMENT ( Agreement ) is made effective as of, 20 (the Effective Date ) by and between Harvard Pilgrim Health

More information

THE GENERAL ASSEMBLY OF PENNSYLVANIA HOUSE BILL

THE GENERAL ASSEMBLY OF PENNSYLVANIA HOUSE BILL PRIOR PRINTER'S NO. PRINTER'S NO. THE GENERAL ASSEMBLY OF PENNSYLVANIA HOUSE BILL No. 1 Session of 01 INTRODUCED BY ELLIS, IRVIN, RABB, MILNE, PICKETT, BAKER, DAVIS, QUIGLEY, BOBACK, CHARLTON, O'NEILL,

More information

ARKANSAS SECRETARY OF STATE

ARKANSAS SECRETARY OF STATE ARKANSAS SECRETARY OF STATE Rules on Vote Centers May 7, 2014 Revised April 6, 2018 1.0 TITLE 1.01 These rules shall be known as the Rules on Vote Centers. 2.0 AUTHORITY AND PURPOSE 2.01 These rules are

More information

STATE DATA SECURITY BREACH NOTIFICATION LAWS

STATE DATA SECURITY BREACH NOTIFICATION LAWS STATE DATA SECURITY BREACH NOTIFICATION LAWS Please note: This chart is for informational purposes only and does not constitute legal advice or opinions regarding any specific facts relating to specific

More information

Health Care Fraud and Abuse Laws Affecting Medicare and Medicaid: An Overview

Health Care Fraud and Abuse Laws Affecting Medicare and Medicaid: An Overview Health Care Fraud and Abuse Laws Affecting Medicare and Medicaid: An Overview name redacted Legislative Attorney July 22, 2016 Congressional Research Service 7-... www.crs.gov RS22743 Summary A number

More information

2ND SESSION, 41ST LEGISLATURE, ONTARIO 66 ELIZABETH II, Bill 87. (Chapter 11 of the Statutes of Ontario, 2017)

2ND SESSION, 41ST LEGISLATURE, ONTARIO 66 ELIZABETH II, Bill 87. (Chapter 11 of the Statutes of Ontario, 2017) 2ND SESSION, 41ST LEGISLATURE, ONTARIO 66 ELIZABETH II, 2017 Bill 87 (Chapter 11 of the Statutes of Ontario, 2017) An Act to implement health measures and measures relating to seniors by enacting, amending

More information

AGREEMENT BETWEEN KIDS IN DISTRESS, INC., AND BROWARD COUNTY FOR SUBSTANCE ABUSE SERVICES Contract Number: KID-BARC-CFS-2017

AGREEMENT BETWEEN KIDS IN DISTRESS, INC., AND BROWARD COUNTY FOR SUBSTANCE ABUSE SERVICES Contract Number: KID-BARC-CFS-2017 Exhibit 2 AGREEMENT BETWEEN KIDS IN DISTRESS, INC., AND BROWARD COUNTY FOR SUBSTANCE ABUSE SERVICES Contract Number: KID-BARC-CFS-2017 This is an Agreement ("Agreement"), made and entered into by and between

More information

ACTION: Update and amend OPM/ GOVT 5, Recruiting, Examining, and Placement Records.

ACTION: Update and amend OPM/ GOVT 5, Recruiting, Examining, and Placement Records. This document is scheduled to be published in the Federal Register on 03/26/2014 and available online at http://federalregister.gov/a/2014-06593, and on FDsys.gov OFFICE OF PERSONNEL MANAGEMENT Privacy

More information

SUMMARY: The Department of Veterans Affairs (VA) is making technical amendments

SUMMARY: The Department of Veterans Affairs (VA) is making technical amendments This document is scheduled to be published in the Federal Register on 09/12/2014 and available online at http://federalregister.gov/a/2014-21790, and on FDsys.gov DEPARTMENT OF VETERANS AFFAIRS 8320-01

More information

STATE DATA SECURITY BREACH NOTIFICATION LAWS

STATE DATA SECURITY BREACH NOTIFICATION LAWS STATE DATA SECURITY BREACH NOTIFICATION LAWS Please note: This chart is for informational purposes only and does not constitute legal advice or opinions regarding any specific facts relating to specific

More information

Submitted to: Healthcare Supply Chain Association 2025 M Street, NW, Suite 800 Washington DC Prepared by:

Submitted to: Healthcare Supply Chain Association 2025 M Street, NW, Suite 800 Washington DC Prepared by: Activities and Perspectives of the Office of Inspector General in the U.S. Department of Health and Human Services Regarding Group Purchasing Organizations (GPOs) Submitted to: Healthcare Supply Chain

More information

RENOWN HEALTH NETWORK POLICY

RENOWN HEALTH NETWORK POLICY Page 1 of 7 Title: Patient Right to Request an Amendment Melinda Montoya, Revision History: Scope: This policy applies to all Renown-affiliated facilities including, but not limited to, hospitals, ambulatory

More information

A Bill Regular Session, 2017 SENATE BILL 339

A Bill Regular Session, 2017 SENATE BILL 339 Stricken language would be deleted from and underlined language would be added to present law. Act of the Regular Session 0 State of ArkansasAs Engrossed: S// S// S// S// S// H// st General Assembly A

More information

GUIDELINES FOR THE USE OF ELECTORAL PRODUCTS

GUIDELINES FOR THE USE OF ELECTORAL PRODUCTS GUIDELINES FOR THE USE OF ELECTORAL PRODUCTS June 2017 Status: Approved Print Date: 6/29/2017 Page 1 of 18 Section 1: Introduction GUIDELINES FOR THE USE OF ELECTORAL PRODUCTS The Election Act requires

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement ( Agreement ) is entered into by and between eclinicalworks, LLC, a Massachusetts limited liability company ( eclinicalworks ), and ( Customer

More information