Patient Privacy Investigations and Levels of Violation: Difference between revisions

Jump to navigation Jump to search
m
m (typo)
Line 68: Line 68:
==Definitions==
==Definitions==
===Affiliated Covered Entity (ACE)===
===Affiliated Covered Entity (ACE)===
Legally separate covered entities that are affiliated and designate themselves as a single covered entity for the purpose of HIPAA Compliance. Current ACE members are: The Nebraska Medical Center, UNMC Physicians, UNMC, University Dental Associates, Bellevue Medical Center and Nebraska Pediatric Practice, Inc. d/b/a Children’s Specialty Physicians. ACE membership may change from time to time. The Notice of Privacy Practices lists current ACE members. Access and amendment rights apply to designated record sets throughout the ACE.
Legally separate covered entities that designate themselves as a single covered entity for the purpose of HIPAA Compliance. Current ACE members are: The Nebraska Medical Center, UNMC Physicians, UNMC, University Dental Associates, Bellevue Medical Center and Nebraska Pediatric Practice, Inc. d/b/a Children’s Specialty Physicians. ACE membership may change from time to time. The Notice of Privacy Practices lists current ACE members.  
===Breach of Unsecured PHI ===
===Breach of Unsecured PHI ===
The unauthorized acquisition, access, use or disclosure of PHI which compromises the security or privacy of such information. Unsecured PHI is PHI that is not rendered unusable, unreadable or indecipherable to unauthorized persons, such as e-PHI that has not been encrypted and any physical copy of PHI (e.g., in paper, film or hardcopy) that has not been shredded or destroyed such that it cannot be read or otherwise reconstructed.  
The unauthorized acquisition, access, use or disclosure of PHI which compromises the security or privacy of such information. Unsecured PHI is PHI that is not rendered unusable, unreadable or indecipherable to unauthorized persons, such as e-PHI that has not been encrypted and any physical copy of PHI (e.g., in paper, film or hardcopy) that has not been shredded or destroyed such that it cannot be read or otherwise reconstructed.  
===Business Associate===
===Business Associate===
A third party who performs services on behalf of Nebraska Medicine/UNMC that involve the creation, receipt, maintenance or transmission of PHI. Some examples of such services include claims processing, data analysis, data processing, practice management, utilization review, quality assurance, patient safety activities, billing, benefit management and repricing.
A third party who performs services on behalf of Nebraska Medicine/UNMC that involve the creation, receipt, maintenance or transmission of PHI in any form, even if PHI is not accessed. Some examples of such services include storage, including cloud storage, claims processing, data analysis, data processing, practice management, utilization review, quality assurance, patient safety activities, billing, benefit management and repricing.
===e-PHI ===
===e-PHI ===
Protected Health Information that is transmitted by electronic media and/or maintained in electronic media.
Protected Health Information that is transmitted by electronic media and/or maintained in electronic media.
Line 88: Line 88:
*an Individual’s genetic tests;  
*an Individual’s genetic tests;  
*the genetic tests of an Individual’s family members; or
*the genetic tests of an Individual’s family members; or
*the manifestation of a disease or disorder in such Individual’s family members (i.e., family medical history); or
*the manifestation of a disease or disorder in such Individual’s family members (i.e., family medical history).
*any request for, or receipt of, genetic services (e.g., genetic test, genetic counseling, genetic education), or participation in clinical research which includes genetic services by the Individual or any family member of the Individual.
PHI excludes:
PHI excludes:
*individually identifiable health information of a person who has been deceased for more than fifty (50) years.
*individually identifiable health information of a person who has been deceased for more than fifty (50) years.

Navigation menu