PRIVACY POLICIES AND PROCEDURES

Similar documents
RECEIPT OF NOTICE OF PRIVACY PRACTICES WRITTEN ACKNOWLEDGEMENT FORM. I,, have received a copy of Dr. Andy Hand s Notice of Privacy Practice.

NOTICE OF PRIVACY PRACTICES

SUMMARY OF NOTICE OF PRIVACY PRACTICES

NOTICE OF PRIVACY PRACTICES MOUNT CARMEL HEALTH SYSTEM

NOTICE OF PRIVACY PRACTICES

NOTICE OF PRIVACY PRACTICES

CAPITAL SURGEONS GROUP, PLLC

If you have any questions about this notice, please contact our privacy officer Dr. Jev Sikes at

Orthopedic Specialty Clinic, Ltd. Updated 05/2014

PARAGOULD DOCTORS CLINIC PRIVACY NOTICE

J.C. Blair Memorial Hospital Huntingdon, PA

NOTICE OF PRIVACY PRACTICES

NOTICE OF PRIVACY PRACTICES

NuSpine Chiropractic NOTICE OF PRIVACY PRACTICES. This notice takes effect on March1, 2007 and remain in effect until we replace it.

JOINT NOTICE OF PRIVACY PRACTICES

Notice of HIPAA Privacy Practices Updates

physicians, nurses, and technicians and other Facility personnel for review and learning purposes. We may also combine the medical information we

Privacy Practices Home Visit Doctor, LLC July 2017

NOTICE OF PRIVACY PRACTICES

ERIE COUNTY MEDICAL CENTER CORPORATION NOTICE OF PRIVACY PRACTICES. Effective Date : April 14, 2003 Revised: August 22, 2016

Notice of Privacy Practices for Protected Health Information (PHI)

NOTICE OF PRIVACY PRACTICES

NOTICE OF PRIVACY PRACTICES

FAMILY PHARMACEUTICAL SERVICES NOTICE OF PRIVACY PRACTICES effective 9/23/2013

NOTICE OF PRIVACY PRACTICES

Advanced Oral & Maxillofacial Surgery, Ltd. NOTICE OF PRIVACY PRACTICES

Commonwealth Health Corporation Notice of Privacy Practices CHC COMMONWEALTH HEALTH CORPORATION

Notice of Health Information Privacy Practices Acknowledgement

HIPAA PRIVACY NOTICE

NOTICE OF PRIVACY PRACTICES FOR MAYO CLINIC ARIZONA

NOTICE OF PRIVACY PRACTICES

NOTICE OF PRIVACY PRACTICES

NOTICE OF PRIVACY PRACTICES

WAKE FOREST BAPTIST HEALTH NOTICE OF PRIVACY PRACTICES

PATIENT NOTICE OF PRIVACY PRACTICES Effective Date: June 1, 2012 Updated: May 9, 2017

Balance Fitness and Nutrition

NOTICE OF PRIVACY PRACTICES

Johns Hopkins Notice of Privacy Practices for Health Care Providers

MURRAY MEDICAL CENTER HIPAA NOTICE OF PRIVACY PRACTICES

HIPAA NOTICE OF PRIVACY PRACTICES

This notice describes Florida Hospital DeLand s practices and that of: All departments and units of Florida Hospital DeLand.

GREATER HUDSON VALLEY HEALTH SYSTEM ORANGE REGIONAL MEDICAL CENTER CATSKILL REGIONAL MEDICAL CENTER Policy/Procedure

NOTICE OF PRIVACY PRACTICES

NOTICE OF PRIVACY PRACTICES UNIVERSITY OF CALIFORNIA RIVERSIDE CAMPUS HEALTH CENTER

CHI Mercy Health. Definitions

Notice of Privacy Practices

Associated Pediatric Dentistry Belleville, Edwardsville, O Fallon, IL

PRIVACY POLICY USES AND DISCLOSURES FOR TREATMENT, PAYMENT, AND HEALTH CARE OPERATIONS

Pediatric Dental Specialists

HARDY, MILSTEAD, VAUGHT & MADONNA, M.D., P.A. PRIVACY PRACTICES Effective: 1/1/03

NOTICE OF PRIVACY PRACTICES

NOTICE OF PRIVACY PRACTICES Mid-Atlantic Women s Care, PLC Effective Date: September 23, 2013 Last Revised: February 15, 2018

SUNY DOWNSTATE MEDICAL CENTER UNIVERSITY HOSPITAL OF BROOKLYN POLICY AND PROCEDURE

HH Health System-Shoals, LLC dba Helen Keller Hospital Notice of Privacy Practices

NOTICE OF PRIVACY PRACTICES Occupations, Inc. 15 Fortune Road West Middletown, NY 10941

NOTICE OF PRIVACY PRACTICES

BON SECOURS RICHMOND NOTICE OF PRIVACY PRACTICES

Form B - For those enrolled in other insurance

Notice of Privacy Practices

Notice of Privacy Practices

HIPAA Policies and Procedures Manual

NOTICE OF PRIVACY PRACTICES

Acknowledgement of Receipt of Notice of Privacy Practices

NOTICE OF PRIVACY PRACTICES Effective Date: April 14, 2003

NOTICE OF PRIVACY PRACTICE UNIVERSITY OF CALIFORNIA SAN FRANCISCO DENTAL CENTER

If you have any questions about this notice, please contact the SSHS Privacy Officer at:

Ashe Memorial Hospital, Inc. 200 Hospital Avenue, Jefferson, NC (336) JOINT NOTICE OF PRIVACY PRACTICES

Senior Care Pharmacy Wichita

Pain Management Specialists of Southfield Michigan. Michigan Orthopaedic Institute. Thank you for choosing us for your Pain Management Services.

Notice of Privacy Practices

ETSU COLLEGE OF NURSING NOTICE OF PRIVACY PRACTICES

Joseph Bikowski, M.D., Associates

Greenwood Connections Notice of Privacy Practice

PATIENT INFORMATION Please Print

Patient name (print) Signature of Patient/ Legal Representative. Relationship to Patient FOR OFFICE USE ONLY

HIPAA Notice of Privacy Practices DFD Russell Medical Center Effective April 14, 2003 Updated April 10, 2013

MSK Group, PC NOTICE O F PRIVACY PRACTICES Effective Date: December 30, 2015

MEMPHIS LUNG PHYSICIANS FOUNDATION AN OFFICE OF BAPTIST MEDICAL GROUP NOTICE OF PRIVACY PRACTICES

Notice of Privacy Practices

NOTICE OF PRIVACY PRACTICES

Sample Notice of Privacy Practices 2 of 6 cda.org/practicesupport

JOINT NOTICE OF PRIVACY PRACTICES

Opp Health and Rehabilitation, LLC 115 Paulk Avenue P.O. Box 730 Opp, AL Phone Number: (334)

PATIENT BILL OF RIGHTS & NOTICE OF PRIVACY PRACTICES

Patient Registration Form Pediatrics

OUR LEGAL DUTY PERSONS COVERED BY THIS NOTICE

NOTICE OF PRIVACY PRACTICES

REVISED NOTICE OF PRIVACY PRACTICES ORIGINAL DATE: JANUARY 1, 2003 REVISED: JANUARY 16, 2014 REVISED: NOVEMBER 27, 2017 PLEASE REVIEW IT CAREFULLY

ADVANCED PLASTIC SURGERY, PLLC. NOTICE OF PRIVACY PRACTICES

NOTICE OF HOSPICE EL PASO S PRIVACY PRACTICES

MAIN STREET RADIOLOGY

always legally required to follow the privacy practices described in this Notice.

INFORMED CONSENT FOR TREATMENT

Mental Health. Notice of Privacy Practices

HIPAA Notice of Privacy Practices

FAMILY MEDICAL ASSOCIATES OF RALEIGH 3500 Bush Street Raleigh, NC P: (919) F: (919)

Notice of Privacy Practices

BASSIN CENTER FOR PLASTIC SURGERY. Dr. Roger Bassin NOTICE OF PRIVACY PRACTICES

NOTICE OF PRIVACY PRACTICES

Accommodate reasonable requests you may have to communicate health information by alternative means or at alternative locations.

Transcription:

Vinay M. Reddy, M.D., Ethelynda Jaojoco, M.D. Karen D. Cain, PA-C Julie J. Stackhouse, PA-C Jacie Touart, PA-C Brian Vaccarezza, PA-C Physical Medicine & Rehabilitation Electrodiagnostic Medicine Disorders of the Spine Interventional Spinal Injections Myofascial Pain / Fibromyalgia Workers Compensation QME / AME evaluations PRIVACY POLICIES AND PROCEDURES GENERAL PRIVACY POLICY The law requires us to keep our patients protected health information ( PHI ) private in accordance with our Notice of Privacy Practices ( Notice ), as long as the Notice remains in effect. Additionally, our Practice takes our patients privacy seriously and expects our employees, agents and business associates to do the same. If you ever have any questions regarding privacy or security of patient s PHI, please contact our Privacy Officer. OUR LEGAL DUTIES Minimum Necessary. In all cases in which we use or disclose a patient s PHI, we must only do so to the minimum extent necessary to accomplish the underlying purpose of the use or disclosure. If you are unsure whether a use or disclosure meets this requirement, contact our Privacy Officer for clarification. Uses and Disclosures. We may use or disclose PHI for treatment, payment, or health care operations. The followings are some examples of permitted uses or disclosures: Treatment. A patient s PHI may be used by or disclosed to any physicians or other health care providers involved with the medical services provided to that patient. Payment. PHI may be used or disclosed in order to collect payment for the medical services provided to our patients. Health Care Operations. PHI may be used or disclosed as part of quality of care audits of staff and affiliates, conducting training programs, accreditation, certification, licensing, or credentialing activities. Authorizations. If we have received written authorization from a patient, we use or disclose PHI for any purpose consistent with that Authorization. We may not require such an authorization as a condition of treatment. A patient may revoke an authorization at any time by writing to the Privacy Officer. However, such revocation will no affect any prior authorized uses or disclosures. Family Members and Friends. With the patient s permission, or in some emergencies, we may disclose PHI to family members, friends, or other people to aid in treatment or collection of payment. A disclosure of PHI may also be made if we determine it is reasonably necessary or in the patient s best interests for such purposes as allowing a person acting on the patient s behalf to receive filled prescriptions, medical supplies, X rays, etc.

2 Locating Responsible Parties. PHI may be disclosed in order to locate, identify or notify a family member, personal representative, or other person responsible for a patient s care. A patient may prohibit or restrict the extent or recipients of such disclosure, unless we determine in our reasonable professional judgment that a patient is incapable of doing so. If we so determine, we must limit the amount of PHI disclosed to the minimum necessary. Disasters. We may use or disclose PHI to any public c or private entity authorized by law or by its charter to assist in disaster relief efforts. Required by Law. We must use or disclose medical information when we are required to do so by law. For example, PHI may be released when required by privacy laws workers compensation or similar laws, public health laws, court or administrative orders, subpoenas, certain discovery requests, or other laws, regulations or legal processes. Under certain regarding an inmate, lawful detainee, suspect, fugitive, material witness, missing person, or a victim or suspected victim of abuse, neglect, domestic violence or other crimes. We may disclose PHI to the extent reasonably necessary to avert a serious threat to a patient s health or safety or the health or safety of others. We may disclose PHI when necessary to assist law enforcement officials to capture a third party who has admitted to committing a crime against the patient or who has escaped from lawful custody. If you are unsure of the lawful authority of the person requesting the PHI, contact the Privacy Officer prior to making any use or disclosure under this section. Deceased Persons. We may disclose PHI of a deceased patient to a coroner, medical examiner, funeral director, or organ procurement organization in limited circumstances. Research. PHI may also be used or disclosed for research purposes only in those limited circumstances not requiring a written authorization, such as those which have been approved by an institutional review board that has established procedures for ensuring the privacy of your PHI. Prior to conducting any research under this section, please obtain the approval of our Privacy Officer to ensure that all procedural requirements have been met. Military and National Security. We may disclose to military authorities the medical information of Armed Forces personnel under certain circumstances. When required by law, we may disclose PHI for intelligence, counterintelligence, and other national security activities. Contact the Privacy Officer prior to making any use or disclosure of PHI under this section. Continuing Care. We may provide patients with information concerning health issues, benefits and services, or treatment alternatives based upon their PHI. We may disclose PHI to a business associate to assist us in these activities. By notifying our Privacy Officer, a patient may opt out of receiving such information, except that which is contained in a general newsletter, is presented in person or is for nominally valued items. Fundraising. We may use demographic information and the dates of a patient s health care to contact them for fundraising purposes. We may disclose this information to a business associate to assist us in fundraising activities. A patient may opt out of receiving such information by notifying our Privacy Officer. Access and Copies. In most cases patients have the right to review or to purchase copies of their PHI by requesting access or copies in writing to our Privacy Officer. All such requests should be

3 handled quickly and efficiently but should not interfere with our treatment of other patients. We require that a patient schedule an appointment to review PHI at our office. Our Privacy Officer is responsible for setting copying fee. Disclosure Accounting. We are required by law to maintain a Disclosure Accounting log of the instances, if any, in which PHI is disclosed for purpose other than those described in the following sections above: Use and Disclosures, Facility Directories, Family Members and Friends, Locating Responsible Parties, and Access and Copies. For each 12-month period, a patient has the right, upon request, to receive on free copy of an accounting certain details surrounding such disclosures that occurred after April 13, 2003. If a patient requests a disclosure accounting more than once in a 12-month period, we will charge fee for each additional request. Please contact our Privacy Officer regarding these fees. Additional Restrictions. A patient may request that we place additional restrictions on our use or disclosure of PH, but we are not required to honor such a request. We will be bound by such restrictions only if we agree to do so in writing sign4ed by our Privacy Officer. Alternate Communications. Patients have the right to request that we communicate with them about their PHI by alternative means or in alternative locations. We will accommodate any reasonable request if it specifies in writing the alternative means or location, and provides a satisfactory explanation of how future payments will be handled. Amendments to PHI. A patient has the right to request that we amend his or her PHI. Any such request must be in writing and contain a detailed explanation for the requested amendment. Under certain circumstances, we may deny the request but must provide you a written explanation of the denial. A patient has the right to send us a Statement of Disagreement, which we must file with the disputed PHI entry. We may then prepare and file a rebuttal to the patient s Statement of Disagreement, a copy of which must be provided to the patient at no cost. Please contact our Privacy Officer before changing or amending any medical record or other PHI. Complaints. A patient is entitled to file a complaint with us or with the Secretary of the U.S. Department of Health and Human Services if he or she believes we have violated any privacy rights with respect to our Notice of Privacy Practices. We shall not retaliate in any way if a patient chooses to file such a complaint. All such complaints must be forwarded to the Privacy Officer. CONFIDENTIALITY PROCEDURES In-Office Procedures. 1. Sign-in Sheets. Public sign-in sheets should request only the patient s name. Any other information collected from the patient should be kept private. 2. Oral Communications. Discussions about PHI should be held behind closed doors and/or out of earshot of those who have no right to access the PHI discussed. Use only the patient s name when calling him or her form the waiting room. 3. Patient Files. All reasonable efforts must be used to prevent unauthorized persons from accessing patient files. Files should be monitored by staff to ensure they are accessed only by authorized personnel. Unattended files should be kept in a locked room or

4 cabinet. Patient files shall not be altered, copied or removed from the premises without first notifying the Privacy Officer. 4. Confidentiality Agreement. Anyone with access to patient records, files or other PHI must sign a confidentiality agreement. Violation of the confidentiality agreement should result in a reprimand, such as removal, demotion, suspension, or termination. 5. Fax Confidentiality. PHI should be faxed only in emergencies. In all other cases, PHI should be sent by mail or hand delivery, marked confidential. PHI should not be faxed on or to a machine that is accessible to the general public. Indicate the confidential nature of the fax on the cover sheet as well as each sheet of the document. The coversheet should also request that any erroneous recipient destroy or return the fax. Always notify the recipient of a forthcoming confidential fax and verify the fax number before faxing PHI. Wait to send the confidential fax until you are able to contact the recipient. Verify the fax number once again on the fax confirmation sheet after the fax is sent. If an error occurred, contact the accidental recipient and request the return or destruction of the fax. 6. Remote Consultation Confidentiality. Patient privacy and confidentiality must be maintained whenever PHI is viewed or discussed during a medical consultation session conducted over the telephone, internet or similar remote communication device. The provider who is consulting must confirm that the consultation is attended only by individuals who have a legitimate interest in the patient s care. Additionally, all PHI presented shall remain confidential. 7. Transcription confidentiality. All employees, independent contractors, agents, or business associates involved in dictation, transcription, maintenance, storage, and retrieval of transcribed data must protect the privacy and confidentiality of any PHI to which they have access. The transcription system and all transcribed data are part of the property of Practice. Anyone using such equipment shall have no right to privacy in their use of the transcription system or its data. Practice reserves the right to monitor, audit and read transcribed documents as well as the content and usage of the transcription system to support operational, maintenance, auditing, security and investigate services. Dictation and dictation playback must be done in a secure environment that protects the information from being overheard by unauthorized persons. PHI may not be dictated into cellular phones or into public telephones where others can overhear the dictation or into equipment, such as an answering machine. Dictation may be maintained in a recorded voice format only until it has been transcribed and reviewed and must immediately thereafter be erased. Transcription media shall not be reused until it is first erased. After a transcription is completed, it must be authenticated by an identifier assigned by the Privacy Officer. 8. Email Confidentiality. PHI should not be sent by email or other electronic transmission unless it conforms to the appropriate encryption standard. The e-mail system and all messages generated or handled by e-mail, including backup copies, are property of Practice. E-mail users have no right to privacy in their use of the computer system, including e-mail. Practice may monitor the content and usage of the computer system, including, e-mail, at any time and for any reason. E-mail users should restrict us of the e- mail system to proper business purposes. Any personal e-mail use should be avoided and may result in removal, demotion, suspension, or termination in some circumstances.

5 Electronic Data Confidentiality. Officers, agents, employees, independent contractors, business associates and others using portable data media, including, diskettes, tapes, CE-ROMs, portable computers or other electronic data media may not download, maintain, or transmit confidential patient or other information without the written authorization of the Privacy Officer. Failure to comply with this provision may result in removal, demotion, suspension, or termination