1,735
edits
(→Additional Information: updated Contact HR URL) |
(→Additional Information: updated Health Insurance Portability and Accountability Act of 1996 link 2x and HIPAA Security Rule link 2x) |
||
| Line 36: | Line 36: | ||
<big>'''Policy on Patient Privacy Investigations and Levels of Violation'''</big><br /><br /> | <big>'''Policy on Patient Privacy Investigations and Levels of Violation'''</big><br /><br /> | ||
==Purpose of Policy== | ==Purpose of Policy== | ||
Nebraska Medicine/UNMC implements reasonable and appropriate access controls in alignment with National Institute of Standards and Technology (NIST) standards and guidance to maintain the minimum necessary access. [https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final NIST Special Publication 800-53] and the [https://www.cdc.gov/phlp/ | Nebraska Medicine/UNMC implements reasonable and appropriate access controls in alignment with National Institute of Standards and Technology (NIST) standards and guidance to maintain the minimum necessary access. [https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final NIST Special Publication 800-53] and the [https://www.cdc.gov/phlp/php/resources/health-insurance-portability-and-accountability-act-of-1996-hipaa.html HIPAA Security Rule] outline considerations for the access control family of security controls. | ||
==Policy== | ==Policy== | ||
Nebraska Medicine/UNMC Workforce members shall report, and the [mailto:privacy@nebraskamed.com Privacy Office] shall investigate, suspected patient Privacy Incidents to ensure patient and employee/patient confidentiality is maintained and to help mitigate any adverse effects resulting from such incidents. Appropriate sanctions shall be consistently applied by Nebraska Medicine/UNMC for violations of patient privacy pursuant to the requirements of the [https://www.cdc.gov/phlp/ | Nebraska Medicine/UNMC Workforce members shall report, and the [mailto:privacy@nebraskamed.com Privacy Office] shall investigate, suspected patient Privacy Incidents to ensure patient and employee/patient confidentiality is maintained and to help mitigate any adverse effects resulting from such incidents. Appropriate sanctions shall be consistently applied by Nebraska Medicine/UNMC for violations of patient privacy pursuant to the requirements of the [https://www.cdc.gov/phlp/php/resources/health-insurance-portability-and-accountability-act-of-1996-hipaa.html Health Insurance Portability and Accountability Act of 1996 (HIPAA)]. | ||
==Procedures== | ==Procedures== | ||
#Suspected Privacy Incidents shall be reported to the Privacy Office immediately for further investigation. | #Suspected Privacy Incidents shall be reported to the Privacy Office immediately for further investigation. | ||
| Line 153: | Line 153: | ||
*UNMC Policy No. 6057, [https://wiki.unmc.edu/index.php/Use_and_Disclosure_of_Protected_Health_Information Use and Disclosure of Protected Health Information] | *UNMC Policy No. 6057, [https://wiki.unmc.edu/index.php/Use_and_Disclosure_of_Protected_Health_Information Use and Disclosure of Protected Health Information] | ||
*Nebraska Medicine Use and Disclosure of Protected Health Information policy, IM.12 | *Nebraska Medicine Use and Disclosure of Protected Health Information policy, IM.12 | ||
*[https://www.cdc.gov/phlp/ | *[https://www.cdc.gov/phlp/php/resources/health-insurance-portability-and-accountability-act-of-1996-hipaa.html Health Insurance Portability and Accountability Act of 1996 (HIPAA)] | ||
*[https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final NIST Special Publication 800-53] | *[https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final NIST Special Publication 800-53] | ||
*[https://www.cdc.gov/phlp/ | *[https://www.cdc.gov/phlp/php/resources/health-insurance-portability-and-accountability-act-of-1996-hipaa.html HIPAA Security Rule] | ||
This page maintained by [mailto:mhurlocker@unmc.edu mh]. | This page maintained by [mailto:mhurlocker@unmc.edu mh]. | ||