HIPAA Law



             


Monday, March 10, 2008

Caregiver Stress Accounts for 27% Increase in Health Insurance Benefits by South Florida Employees

27% Increase in Health Insurance Benefits by South Florida Employees accounts for Stress as Caregiver to aging parents.

27% Increase in Health Insurance Benefits by South Florida Employees accounts for Stress as Caregiver to aging parents.

The impact of Elder Care issues on corporate America will continue to grow as our elderly population increases:

  • Employees juggling job responsibilities with care giving are a reality in the workplace of today and the future. Workers are torn between the demands of their job and the ability to provide quality care to their relative.
  • One out of three American workers is also managing the care of an older relative.
  • Loss of productivity resulting from time off to care for an aging relative is estimated at $6100 per employee per year.
  • Caregiver stress accounts for a 27% increase in use of company health insurance benefits.

Seventeen percent (17%) of caregivers quit their jobs to provide care for aging family members, and another 15% reduce their work hours to assist their loved ones. This shocking loss of employee productivity is hitting South Florida businesses very hard as more Boomers have senior parents who require caregiving.

To stop this workforce hemorrhaging South Florida companies are looking for methods to provide assistance in caregiving to employees to keep them on the job and productive, while being sensitive to the needs of the employee.

There have been attempts at Corporate Elder Care programs, however few as comprehensive at A Good Daughter, (www.agooddaughter.com) based in Margate. According to Olga Brunner, President, Our Corporate Elder Care program was developed to help employees balance job responsibilities and caregiving. Our Professional Care Managers plan and organize care and services for the employees of Broward and Palm Beach elderly population, affording families a peace of mind that their loved ones will find and secure services such as ongoing supervision of certified home care assistants, home maintenance and care, medication supervision, coordination of medical appointments and representation at these appointments, legal counsel, specialized air travel escorts, and many other services.

While A Good Daughter works with individuals, the Corporate Elder Care program is ideally suited to the mid-sized company with fifty plus employees.

A Good Daughter, Inc.
www.agooddaughter.com
Olga Brunner
800-963-3877

Professional Marketing Firm reaching the Manufacturing Community Worldwide

Labels: , , , , ,

Friday, January 18, 2008

Use of intranets / extranets for HIPAA compliance

Collaboration among healthcare professionals, particularly in circumstances that require the sharing of confidential patient information, requires an intranet or extranet that offers enhanced security features.

The Health Insurance Portability and Accountability Act (HIPAA) has three major requirements:

* Protect the privacy of individual health information * Provide the necessary security to protect the privacy of individual health information * Provide standardization of electronic data interchange in health care transactions

Addressing this need, intranets and extranets are now available that meet these security requirements. As you consider the implementation of an intranet or extranet, look for the following security features:

* Secure web server with 128bit SSL encryption * Server monitoring * Secure IDs and passwords * Defined authority levels * Viewing permission controls * Session time out after 30 minutes * The ability to disable user-specific cookies, * The ability of users to change their own password, * The ability to create strong passwords. * Complete, un-editable activity log for security audits

Choosing a web-based solution

To speed the implementation of an intranet or extranet with these features, an increasingly popular approach is to use an Application Service Provider (ASP).

In addition to providing an immediate solution that has the appropriate security features in-place, the advantages of a web-based ASP include a lower cost of entry, a proven track-record of performance and no need to install intranet software or extranet software.

Laura Schwiker writes extensively on the use of technology by businesspeople and is an evangelist for online collaboration and collaboration software.

Laura Schwiker writes extensively on the use of technology by businesspeople and is an evangelist for online collaboration and collaboration software.

Labels: , , ,

Tuesday, January 8, 2008

Are you HIPAA Compliant?Matt Sears

By - Matt Sears, Senior Vice President
Athens Benefits Insurance Services, Inc.
A division of The Jenkins Athens Group

HIPAA. Perhaps one of the most significant laws in recent memory; certainly one of the most complex. While this short article won't make anyone an expert, it will, hopefully, demystify this wide ranging set of laws and put you on the path towards compliance.

First, let's answer the question; "What is HIPAA?" HIPAA stands for the Health Insurance Portability and Protection Act of 1996. Although it purports to regulate health insurance, HIPAA provisions extend far beyond insurance. HIPAA introduced broad disclosure and privacy requirements. It also established civil and criminal penalties for each violation (up to $25,000 per person per year in civil penalties and up to $250,000 in criminal fines - along with imprisonment).

Title I of HIPAA deals with portability and special enrollment rights for health plans. Those conditions must have been incorporated into your plans by now (original compliance date was 1997). Title II of HIPAA governs a wide ranging set of conditions called, "Administrative Simplification". For those charged with compliance, the notion that HIPAA simplifies anything qualifies as "dark humor". Administrative simplification attempts to create a uniform system for processing and retention of health information and ensuring the security of that information.

For the purposes of this article, we're only concerned with those portions of the law impacting most employers...privacy. Notably the privacy of personal data defined by HIPAA as "Protected Health Information" or "PHI" - information that is personally identifiable. In the broadest summary possible, key components of HIPAA privacy requirements for a plan sponsor are fairly straightforward:

Generally, the employer (Plan Sponsor) is not a HIPAA "Covered Entity" - the Health Plan is. For fully insured plans, this typically means the health insurer, HMO, EAP provider, etc.
As the Covered Entities, health plans bear the brunt of compliance requirements (your responsibilities become exponentially larger as the quantity of data you receive increases)
Meet with every service provider, or ensure that your broker or consultant has reviewed compliance requirements with each
Use protected health information only for needed administration of the benefit programs (HIPAAspeak: "Treatment, Payment and Health Care Operations)
Collect (and release) only the minimum data required to "do the job" (e.g. enroll an employee, file claims, etc.)
Restrict the data to those persons who absolutely must use it
Establish "firewalls" and safeguards to protect the data (separate locked files, restricted access, password protect systems)
Appoint a Privacy Official (not required for fully insured plans that never receive PHI)
Create a Privacy Policy and distribute a Privacy Notice to participants
"Scrub" personally identifiable data from communications pieces, ID Cards, etc.

HIPAA, like COBRA before it, will continually change as new rules and regulations are released (for example, the U.S. Dept. of HHS has yet to release enforcement rules for HIPAA). Ongoing compliance will require vigilance in remaining up to date on the changing laws. It's vital your broker/consultant proactively work with your organization to review plans, identify problems and provide ongoing education to maximize the performance of your benefit plans.
By - Matt Sears, Senior Vice President
Athens Benefits Insurance Services, Inc.
A division of The Jenkins Athens Group

HIPAA. Perhaps one of the most significant laws in recent memory; certainly one of the most complex. While this short article won't make anyone an expert, it will, hopefully, demystify this wide ranging set of laws and put you on the path towards compliance.

First, let's answer the question; "What is HIPAA?" HIPAA stands for the Health Insurance Portability and Protection Act of 1996. Although it purports to regulate health insurance, HIPAA provisions extend far beyond insurance. HIPAA introduced broad disclosure and privacy requirements. It also established civil and criminal penalties for each violation (up to $25,000 per person per year in civil penalties and up to $250,000 in criminal fines - along with imprisonment).

Title I of HIPAA deals with portability and special enrollment rights for health plans. Those conditions must have been incorporated into your plans by now (original compliance date was 1997). Title II of HIPAA governs a wide ranging set of conditions called, "Administrative Simplification". For those charged with compliance, the notion that HIPAA simplifies anything qualifies as "dark humor". Administrative simplification attempts to create a uniform system for processing and retention of health information and ensuring the security of that information.

For the purposes of this article, we're only concerned with those portions of the law impacting most employers...privacy. Notably the privacy of personal data defined by HIPAA as "Protected Health Information" or "PHI" - information that is personally identifiable. In the broadest summary possible, key components of HIPAA privacy requirements for a plan sponsor are fairly straightforward:

Generally, the employer (Plan Sponsor) is not a HIPAA "Covered Entity" - the Health Plan is. For fully insured plans, this typically means the health insurer, HMO, EAP provider, etc.
As the Covered Entities, health plans bear the brunt of compliance requirements (your responsibilities become exponentially larger as the quantity of data you receive increases)
Meet with every service provider, or ensure that your broker or consultant has reviewed compliance requirements with each
Use protected health information only for needed administration of the benefit programs (HIPAAspeak: "Treatment, Payment and Health Care Operations)
Collect (and release) only the minimum data required to "do the job" (e.g. enroll an employee, file claims, etc.)
Restrict the data to those persons who absolutely must use it
Establish "firewalls" and safeguards to protect the data (separate locked files, restricted access, password protect systems)
Appoint a Privacy Official (not required for fully insured plans that never receive PHI)
Create a Privacy Policy and distribute a Privacy Notice to participants
"Scrub" personally identifiable data from communications pieces, ID Cards, etc.

HIPAA, like COBRA before it, will continually change as new rules and regulations are released (for example, the U.S. Dept. of HHS has yet to release enforcement rules for HIPAA). Ongoing compliance will require vigilance in remaining up to date on the changing laws. It's vital your broker/consultant proactively work with your organization to review plans, identify problems and provide ongoing education to maximize the performance of your benefit plans. Setting-up Your New Computer: How To Move Your Old Files to Your New ComputerSteven PresarYou've got a new computer for your office. It's cleaner, better, faster and you can't wait to start to use it!

However, your satisfaction of making a fresh start with a new computer is tempered by the fact that all of your "stuff" is still on your old computer. Everything that made your old computer YOUR computer: your personal settings, your business files, your company spreadsheets are still loaded on your old computer.

You find yourself with a new computer that's not so great without a whole lot of the useful file information that is still stored on your old computer. How are you going to get all of that information onto your new computer?

The process is called "data migration" and it can be a tedious and time-consuming task for you and your business.

Here are some suggestions to make this data migration go a little easier for you.

CDs

One option is to copy ("burn") everything to recordable CDs.

Blank CDs are cheap, at about $1 apiece, and can hold more than 600 megabytes each. That much storage space should be enough for most small businessess to transfer old data files from one hard drive to a new.

Two drawbacks to the CD method of data transfer are that:

~ It may take a while to burn each CD and
~ That you may not have a recordable CD drive on your old PC.

Recordable CD units are standard on newer PCs but if older computers have a CD unit, it was insatlled as later add-on hardware feature. Thus, depending on the age of your older computer, it may not have a recordable CD drive installed at all. To install a recordable CD drive on your older computer now, may be more of a time-consuming effort when compared with other alternatives to moving your data files.

Portable Drives

Iomega has a pre-packaged solution designed to bridge the gap between old and new computers. They offer a software "moving kit" for individuals who have recently bought a new computer with Microsoft's Windows XP.

The software works with Iomega Zip, Jaz and Peerless drives. It allows individuals to "pack" the files they have on their old computer onto a portable high-capacity disks and then "unpack" the same files onto your new computer.

The transfer software uses Microsoft's "files & settings transfer wizard," a feature included in Windows XP.

After connecting a high-capacity drive to your old computer, you need to download the transfer tool, which primes a disk to prompt you to begin the transfer process the next time it is inserted into a drive. Setting up the disk also requires a CD with the Windows XP operating system.

Keep in mind, software moving kits, have the ability to move everything. Thus, if you are not aware of what files that you are transferring, you may be transferring unneeded problem or virus files to your new computer.

Link Transfers

There are other options if you do not want to shuffle CDs or portable drives.

With the link transfer software option your computers are linked through a serial cable or USB cable. After the software program has been installed on both of your computers (the "source" the old computer and "target" the new computer), you click through a question-and-answer wizard to describe what files you want to transfer. And for transfers on the fly, you can drag and drop folders or files between the two panes in the program representing each computer.

Some link transfer software packages that work with Microsoft's Windows are: PCsync, IntelliMover, PC Relocator, and PC Upgrade Commander.

In each case, the software must be installed on both your old and new computers. The software scans your old computer hard drive, to inventory the folders, subfolder, and files and then you select the data files that you would like to transfer to your new computer.

It sounds like a fairly simple way to handle your data transfer. However, be aware:

~ Generally, these programs want to move all the contents of your old computer to your new computer. That's OK for your data files but moving the program files that run your applications may cause problems because older applications may not be supported by your new computer operating system. Transferring a Windows 95-era program to a computer preloaded with the Windows XP operating system could be a problem because many of those programs haven't been upgraded to run under Windows XP.

~ When you move the full contents of a computer system, everything moves over, including those obscure files that had your old computer running sluggish in its final days.

~ Moving data through a USB cable isn't fast, but it is faster than data transfer through a parallel port.

Choosing a Data Migration Software Package

~ Does the software allow you to pick and choose which files are moved, or does it move EVERYTHING -- even the junk files?

~ How is the data transferred? A wireless network is faster than a USB cable, which is faster than a USB cable, which is faster than a parallel cable. Are you prepared to wait hours or even days for this transfer to take place?

~ If you're using the Internet as a holding place for your data, check your connection and upload speeds. It could take hours to move those files.

~ Consider investing in a high-capacity external hard drive, a plug-and-play device that you'll simply connect to your new computer. The drive, though more expensive, will get far more use than one-time migration software.

Getting Ready for Your Data Migration

~ Get rid of all of your old files. Fill your recycle bin on your old computer with as much as you can. There's nothing worse than bringing useless data to the new computer.

~ Make a software checklist. Is your versions of current program applications compatible with Windows XP? Look on the Web for free Windows XP upgrades to new versions of the programs you need, such as your Palm desktop software.

~ Does your new computer have preloaded software on it? Chances are good the latest Internet browser is already pre-load on your new computer and thus you do not have to transfer the older browser version.

~ Make a list of user names and passwords that are stored in files on your old computer and automatically appear when you visit Web sites. They could be lost in the move, denying you access on your new computer.
Steven Presar is a recognized small business technology coach, Internet publisher, author, speaker, and trainer. He provides personal, home, and computer security solutions at www.ProtectionConnect.com. He provides business software reviews at www.OnlineSoftwareGuide.com. In addition, he publishes articles for starting and running a small business at www.Agora-Business-Center.com. Be sure to sign-up for the SOHO newsletter at the site.

 

Labels: , , , ,

Monday, December 17, 2007

HIPAA and the Internet: Requirements for Intranet Collaboration Software

Sharing private health information over the internet can be a risky business. Unfortunately, as people become accustomed to doing most if not all of their personal business online, the demand for accessing this information online will grow to the point that health care providers will have no choice but to either provide access to this private health information or lose their customers.

The Health Insurance Portability and Accountability Act (HIPAA) was enacted to assure the confidentiality of patient information. This requires that health care providers employ stringent measures to assure that information shared on the internet is protected from unauthorized access.

The HIPAA Act requires health-providing entities to:

 

     

     

  • Assign responsibility for security to a person or organization.

     

     

  • Assess security risks and determine the major threats to the security and privacy of protected health information.

     

     

  • Establish a program to address physical security, personnel security, technical security controls, and security incident response and disaster recovery.

     

     

  • Certify the effectiveness of security controls.

     

     

  • Develop policies, procedures and guidelines for use of personal computing devices (workstations, laptops, hand-held devices), and for ensuring mechanisms are in place that allow, restrict and terminate access (access control lists, user accounts, etc.) appropriate to an individual's status, change of status or termination.

     

     

  • Implement access controls that may include encryption, context-based access, role-based access, or user-based access; audit control mechanisms, data authentication, and entity authentication

 

This law has serious implications for organizations that allow unauthorized access resulting in a breach in confidentiality.

Security is the key

Since the HIPAA law provides for both civil and criminal penalties for violations, data and access security is of the utmost importance. To assure HIPAA compliance, online document management must include a number of security features:

 

     

     

  • Secure web server – a server running secure socket layers is the minimum needed.

     

     

  • Encrypted database – all data must be encrypted. Software is available that will encrypted all data sent between two computer over the internet.

     

     

  • Secure access control -- in addition to a traditional user id and password, it may be a good idea to use a strong password or smart card as additional security.

     

     

  • Session timeout – this assures that confidential data is not left on an unattended screen.

     

     

  • Server monitoring – the secure web server needs to be strictly monitored to detect break-in attempts.

     

     

  • Regular security audits – regular audits are required to make sure all security precautions are working properly.

     

     

  • Personnel – system maintenance should be in the hands of qualified personnel familiar with HIPPA requiremen

    Rick Mosenkis is the President and CEO of Trichys, the creators of WorkZone hosted intranet and extranet software, including a higher-security version for HIPAA compliance. With customers around the world, among large and small companies, Trichys develops easy-to-use web-based software that allows non-technical business professionals to leverage the power of the Internet without IT support.

Labels: , , , , , , ,