HIPAA & HITECH Part 2: Complaints & Breaches

所在平台: Udemy

课程主页: https://www.udemy.com/course/hipaa-hitech-part-2-complaints-breaches/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:HIPAA & HITECH 第二部分:投诉与违规 课程概述:尽管进行了最佳努力,但错误、员工不合规行为、投诉和违规情况仍然会发生。HIPAA 和 HITECH 强调在规定的时间内监测和解决这些问题的责任。本课程的投诉和违规报告过程概述了这一关键行政保护措施的要素,并纳入了HITEC风险评估和HIPAA综合规则下的通知要求。 第一部分:健康信息管理 - 被覆盖实体(Covered Entity)有责任及时记录、调查和解决所有投诉和违规情况,隐私和安全官员也需落实此保护措施。商业合作伙伴(Business Associates)是健康信息管理流程中的一部分,并对被覆盖实体负责。 第二部分:投诉管理流程 - 本部分提供了行政保护措施的要素,要求及时调查HIPAA投诉的框架。提供了投诉报告和调查流程的发展模板,以及隐私和安全投诉政策的模板和示例投诉表。根据本部分开发的文档可在OCR审计中用以证明被覆盖实体/商业合作伙伴的合规努力。 第三部分:违规管理与报告 - HIPAA综合规则要求及时记录和调查所有违规和安全事件(“违规”),并明确了不在违规通知要求之外的特定例外。此部分提供了指导违规报告和调查流程发展的模板,以及识别通知要求例外的指导;包含违规通知信所需元素的指导和示例通知信,及隐私和安全投诉政策的模板和示例投诉表。根据本部分开发的文档可在OCR审计中用以证明被覆盖实体/商业合作伙伴的合规努力。 第四部分:制裁、员工培训及案例研究 - 本部分专注于被覆盖实体、商业合作伙伴和/或员工因不合规和违规行为承担的责任。真实的HHS调查案例研究显示了所需的监管监督及因不合规而处以数十万美元罚款的情况。责任是合规计划的重要组成部分,且有效的员工培训程序至关重要。

课程评论(0条)

课程详情

Despite best efforts - errors, workforce non-compliance, complaints and breaches do occur. HIPAA and HITECH impose the duty to monitor and resolve these issues in a mandated timeframe. The complaint and breach report process addressed in Part 2 outlines the elements of this key administrative safeguard and incorporates the HITECH risk assessment and notification requirements of the HIPAA Omnibus Rule.Section 1: Health Information Management - It is the responsibility of the Covered Entity to document, investigate, and resolve all complaints and breaches that come to its attention in a timely manner as well as the responsibility of privacy and security officers to implement this safeguard. Business Associates are an element of and accountable to the Covered Entity in its Health Information Management process.Section 2: Complaint Management Process - This section provides an outline of the elements of the administrative safeguard requiring the investigation of HIPAA complaints in a timely manner. It provides a template to guide development of a complaint report and investigation process and a template for a Privacy and Security Complaint Policy with sample complaint forms. Documentation developed form this section can be produced in an OCR audit to demonstrate the Covered Entity's/Business Associate's compliance efforts.Section 3: Breach Management and Reporting - The HIPAA Omnibus Rule requires the documentation and investigation of all breaches and security incidents ("breaches") in a timely manner, and has outlined specific exceptions which fall outside of the breach notification requirement. This section provides a template to guide the development of a breach report and investigation process, as well as how to identify exceptions to the notification requirement; guidance about the required elements for a breach notification letter with a sample breach notification letter, and a template for a Privacy and Security Complaint Policy with sample complaint forms. Documents developed from this section can be produced in an OCR audit to demonstrate the Covered Entity's/Business Associate's compliance efforts.Section 4: Sanctions, Workforce Training, and Case Studies - This section focuses on the liability of the Covered Entity, Business Associate and/or individual employees for non-compliance and violations.Case studies taken from actual HHS investigations demonstrate the regulatory oversight required and sanctions into the hundreds of thousands of dollars assessed for non-compliance to date.Accountability is an essential aspect of a Compliance Plan and meaningful workforce training programs.

课程标签

0人关注该课程

主题相关的课程