HIPAA Law



             


Thursday, April 10, 2008

Health Insurance, medical insurance and individual health insurance plans.

Health insurance is something that everyone needs today. The rising cost of visiting a health care provider or a hospital stay makes it imperative that everyone have some type of health care coverage. Government statistics estimate that over 40 million people in America are not covered by any type of health insurance on any given day. That's an enormous number of people who really are taking a financial risk.

The best information on individual Health Insurance.

While most Americans are able to obtain some type of health insurance through their place of employment, many others, the underemployed, the self-employed and the unemployed simply don't know where to find good, quality coverage at a fair price. The Census Bureau estimates that nearly 15% of the population has no coverage. The long term effects of this are hard to quantify because it means that young children do not see a health care provider unless they are seriously ill. Unfortunately this approach while appearing to save money can be devastating to the long term health of the child.

Health care providers and other experts all recommend that every one have some type of health insurance for the necessary time when they'll need to visit their Doctor or hospital.

Mike Yeager

http://www.a1-healthinsurance-4u.com/

mjy610@hotmail.com

Labels: , , , ,

Monday, February 4, 2008

HIPAA Compliant FTP Hosting

FTP Hosting ? an overview

?File Transfer Protocol?, commonly known as FTP, is a reliable protocol to exchange large volume of digital information from one computer to another. FTP hosting technique has simplified file transfer process over the Internet. FTP hosting comes with two components ? FTP Server and FTP Client. Moreover, each FTP user will get a unique FTP account with user name and password. Irrespective of file type and file size, FTP account holders can upload the files in FTP Server through their FTP account. Similarly, FTP account holders can download copies of the uploaded files from FTP Server.

FTP hosting services provides complete security in file exchange process. Only authorized FTP account holders can view and access the files. Further, you can restrict a FTP account holder to access other FTP accounts. Irrespective of business volume, companies require to transfer files over the Internet. Though it is true that Hyper Text Transfer Protocol (HTTP) provides the facility to share information over the Internet but due to its limitations, FTP became popular across the globe.

FTP Hosting for Health Care Services

In Medical Transcription or other Health Care Services, medical reports are stored and exchanged in digital format. The growing necessity of exchanging large volume of medical reports and files over the Internet allows the Health care Service providers to use File Transfer Protocol as an alternative of Hyper Text Transfer Protocol. After the introduction of Health Insurance Portability & Accountability Act of 1996, extra guidelines are drawn for FTP hosting. All types of Health Care Services, who store and exchange medical files and reports over the Internet will fall under this Act and have to follow HIPAA regulation throughout the business process to ensure quality service and security of digital medical files and reports.

HIPAA

Health Insurance Portability & Accountability Act, commonly known as HIPAA, is a set rule to protect health related electronic information. The effect of HIPAA rules is applied to all types of health care organizations and support services. According to Health Insurance Portability & Accountability Act, all the health care organizations and support services should maintain necessary security measures to protect personal health information.

Medical institutes and support services prepares and stores health information of the patients in digital format. Based on the requirement, these digital reports are exchanged from one computer to another over the Internet. Health Insurance Portability & Accountability Act ensures complete security of digital health information that includes ? secure storage system and secure transmission of digital information over the Internet.

HIPAA Compliant FTP Hosting

The growing importance of Health Insurance Portability & Accountability Act in health care sector has given the birth of HIPAA compliance FTP hosting services. The objective of HIPAA compliance FTP hosting services is to protect unauthorized people from accessing digital heal information or medical report.

Following are some general features of HIPAA compliance FTP hosting service:

  • HIPAA compliance FTP servers are considered as highly secured data centers.
  • The system will automatically generate and run several threads during transferring digital medical files from one location to another. This is known as Multi-thread File Transfer and makes the process faster than normal File Transfer Protocol.
  • HIPAA compliance FTP hosting service comes with 128-bit transfer encryption. Digital files are transferred in the encrypted form. There is also another process ? symmetric or secret key encryption, which encrypt files and upload them in the server with a unique ?key?. The system will store the encrypted data in HIPAA compliance FTP server. Only the authorized person, who has that ?key?, can download the encrypted digital medical report from the server.
  • Like general FTP hosting services, the methods of uploading and downloading digital medical files are user friendly.
  • HIPAA compliance FTP hosting services allow the users to apply FTP services with existing firewalls.
  • Unique user name and password for HIPAA compliance FTP account holders.
  • HIPAA compliance FTP hosting services restrict anonymous FTP account holder from accessing the server.
  • Some HIPAA compliance FTP hosting services provides ultimate security by using ?Intrusion Detection System? and other security tools, which are compatible with all types of operating systems.

Advantages of HIPAA compliance FTP Hosting

The main advantage of HIPAA compliance FTP hosting services is data encryption. HIPAA compliance FTP hosting services will encrypt each data files in separate pieces of data, which are known as ?key?. You have to use the software xTyFTP during the process of uploading medical records in the FTP server. The software will encrypt the digital file in the computer and provide the ?key? to the authorized user decrypt.

HIPAA compliance hosting services will store the encrypted file in the server. However, if any unauthorized user accesses the file from the FTP server, he/she will get the encrypted form and the content will remain hidden without the right ?key?.

Apart from data encryption, which is considered as the core feature of HIPAA regulation, HIPAA compliance FTP hosting service requires secure procedure in data handling and serious maintenance of necessary policies, e.g., restricting unauthorized users from damaging digital information.

Adam is a Network Engineer with "InstantFTPsites.com". You can learn more about "FTP Hosting" services online at http://www.InstantFTPsites.com.

? 2006 InstantFTPsites http://www.InstantFTPsites.com You may reprint this article online and in print provided the links remain live and the content remains unaltered (including the "Author Biography").

Labels: , , , , , , ,

Tuesday, January 29, 2008

HIPAA Made Easy

HIPAA made easy

In 1996, a major legislative act was passed affecting health care administration called the Health Insurance Portability & Accountability Act or HIPAA. Whenever the legislature writes new laws it's up to the rest of society to understand the legal jargon and find how what the new law is all about. That's the aim of this article- to help simplify and state the main concepts of HIPAA.

There are two main parts to HIPAA that need to be understood. * The first part of HIPAA amended the Internal Revenue Service Code of 1986. * The second part is directed at streamlining and standardizing some of the administrative aspects of health care administration and information systems.

The second role of HIPAA is what will be focused and discussed as this is the part which mostly affects health care providers. Again the purpose of HIPAA was to simplify health care administration. There are deadlines for compliance; HIPAA does provide penalties and legal action for noncompliance. There are four parts to HIPAA: * Standards for Electronic Transactions * Unique Identifiers Standards * Security Rule * Privacy Rule Before HIPAA there really wasn't much standardization among health care providers regarding filing claims and identification. This created a lot of problems, headaches and extra work. HIPAA aims at saving time and making the process more efficient. It affects how health care providers file and process claims and conduct other business electronically. HIPAA also makes provisions for how health care providers are identified. There was no standardized way of identifying health care providers in: (1) being identified to Medicare and other government health organizations and (2) in being identified with other health care providers. The security and privacy rules were created to ensure secure transmission of electronic data and to protect individuals' personal medical information.

Many health care providers use electronic means for filing, billing and claim work. There has yet to be any adopted standards for this, with each individual provider using whichever forms they like. This led to complications in filing claims with Medicare and in transferring information from provider to provider. HIPAA has changed that though making electronic filing forms standardized. When filing electronic claims or when sending an electronic medical record providers will now be using the same forms. Medicare will require that all providers use the same form when filing an electronic claim with them. Providers who do not file or process claims electronically will not be affected by HIPAA. Also a standardized set of codes must be used on records in relation to physical conditions, diseases, health, etc. Most providers and institutions already use this practice. There will be enforcement of compliance; HIPAA has set deadlines for when providers must be using the approved forms.

Also new with HIPAA is how providers will be identified. Health care providers, doctors, hospitals and health plans are required to have a unique identifier and current they are using either tax-id numbers or employer identification number.

The security and privacy rules contain provisions to ensure that people's personal records and information will be protected and kept confidential. Along with all other privacy laws there will be penalties for non compliance, HIPAA provides for fines up to $250,000 and possible jail time for severe enough violations. But don't be worried about too many places avoiding compliance, HIPAA was created to make the massive process of health care administration easier.

Rick Lorenzen writes for 10x Marketing. To learn more about HIPAA compliance, electronic claim software and electronic medical record software visit www.AdvancedMD.com.

Labels: , , , , , ,

Wednesday, December 26, 2007

The Modern Medical Office: Balancing Success, Technology, and HIPAA

The medical field has always depended on technology for improving patient care. Thanks to advances in technology, administrative functions of healthcare offices have greatly increased their efficiency and customer relations. For example, there is technology that allows doctors to share information with offices across street or across the nation instantly with just a few clicks of the mouse. These advances not only free up hours of paperwork, but also quickly provides information vital to patient’s care.

The Electronic Medical Office & HIPAA

A clinic can in the end be more profitable by offering these innovative services. Nearly half of the people interviewed in a Forrester Research study said they would be willing to pay more for online features; such email access to their doctors. (1)

While technology can be tremendously beneficial there are serious cautions that must be heeded. In 2003, the privacy rule of HIPAA was enacted and the rules governing protected health information (PHI) of patients became far more stringent. The rule governs the way in which information is handled. It requires every level of communication and storage of the PHI to be secure and private.(2) Examples of the ways violations occur are:

  • Computer screens visible from waiting room
  • Files left out around the office
  • PHI not disposed of properly, such as securely shredded
  • Records sent to the wrong home or email address

 

Due to these changes all modes of communication have a heavier burden of responsibility placed upon them since the inclusion of the privacy rule, but none more than electronic transmissions. Keeping the information protected when sending emails, which can be intercepted, can in itself be a daunting task.

HIPAA’s Penalties

If an action taken by any employee, whether intentional, unintentional, or simply neglectful leads to improper recipient of PHI, the practice involved could face serious consequences.

 

  • The civil penalties range from "$100 per incident, up to $25,000 per person, per year, per standard that is violated."(3)
  • The criminal penalties range in three main groups. The first is up to $50,000 and 1 year in prison, moving up to $100,000 and 5 years, or $250,000 and 10 years in prison.

 

Each tier of the criminal penalties has different qualifications leading up to the knowingly disclosing PHI with the intent for malicious harm. (3)

Keeping Your Practice HIPAA Compliant

It’s important for today’s electronic medical office to have several layers of digital protection. This ensures PHI or any other private information cannot go outside the confines of the practices’ systems without the proper digital rights. These rights can be controlled by moderators or even the sender and have the ability to dictate what permissions the receiver may have.

One large step is to protect your practice from accidentally sending information into the wrong hands. This can be done through email anti-theft solutions which encrypts the data sent via email. By using these types of programs, the sender may control not only the security of the file but also subsequent actions that may be carried out by the file’s recipient(s).

email anti-theft programs allow the user to establish who can view, edit, print and forwarding these important health records. Permissions set with email anti-theft software stays with the documents once they’ve left the clinic’s computer.

What Happens if My Practice’s Computer is Stolen?

Email anti-theft software can also protect the data on the computer if the machine is ever misplaced or stolen. This can be done through remote laptop security. All the victim of theft has to do is log into the program and there remotely block access to all protected files on the missing laptop. Without improvement in the means of securing and transmitting their files many practices will continue to commit violations of HIPAA, losing money and patients along the way.

HIPAA Compliance & Patient Trust

It is obvious that one must comply with HIPAA because of the financial penalties that go with noncompliance. There are however, far better reasons for compliance than avoiding punishment.

HIPAA Violations can break the trust between doctors and patients, but compliance along with new technology can strengthen relationships. When patients have new services such as the ability to ask questions to doctors via email the doctors can enhance their trust levels. This is especially important for small practices as interpersonal relationships play key roles for the retention of patients.

The advantages of technology will continue to provide new ways of serving patients. As the digital age comes the computer will increasingly become the focus of record keeping. With an industries like medical & healthcare so dependent on keeping detailed yet secure records, it is going to be ever important to stay current with strong security programs to encrypt and protect files.

 

  1. Bradford J. Holmes, Eric G. Brown, Elizabeth W. Boehm, Lynne Bishop, "Trends In Healthcare Consumer Technology Adoption" Forrester Research, 15 July 2004.
  2. Title 45 Code of Federal Regulations, Pt 164.
  3. United States Department of Health and Human Services. Protecting the Privacy of Patients' Health Information Summary of the Final Regulation. 2005. http://aspe.hhs.gov/admnsimp/final/pvcfact1.htm

    Michael L. David is a member of the marketing team at Essential Security Software (ESS), the leading provider of email anti-theft software for small business. He is a regular contributor to http://www.Iwantmyess.com

Labels: , , , , , ,