What is the Hippocratic Oath?
An oath of ethics taken by physicians to protect patient confidentiality.
What does the Hippocratic Oath say about confidentiality?
Physicians must not divulge anything seen or heard in their profession that should not be published.
Why is privacy important for medical records?
How can privacy protect employees?
Prevents discrimination based on treatment costs, medications, or stigma.
What does HIPAA stand for?
Health Insurance Portability and Accountability Act
What was HIPAA originally designed to do?
Improve health care efficiency by shifting reimbursement to electronic format.
What are the key privacy elements of HIPAA?
What is Protected Health Information?
(PHI)
Identifiable health information held by covered entities or their associates.
What is electronic PHI?
(ePHI)
PHI stored or shared electronically.
Who qualifies as a covered entity under HIPAA?
Who is a business associate under HIPAA?
Non-workforce persons or organizations providing services for covered entities involving PHI.
Example: claims processing, data analysis, consulting, financial services.
Who is not considered a covered entity?
Who enforces HIPAA?
How did HHS OCR adjust HIPAA rules during COVID-19 pandemic?
Permitted non-public-facing videoconferencing even if not fully HIPAA-compliant, with secure login.
What was suspended by the DEA for telemedicine?
Parts of the Ryan Haight Act requiring in-person exams before prescribing controlled substances.
What is the IMLC?
What does California’s Reader Privacy Act restrict?
Access to records about reading material, especially on health topics.
What must be shown to access reader records under CA law?
A compelling interest must be demonstrated by government or litigants.
When is notice not required under HIPAA?
In indirect treatment relationships or medical emergencies.
What uses and disclosures are authorized under HIPAA?
Treatment, payment, operations (TPO), and compliance purposes.
What is the ‘minimum necessary’ standard?
Use or disclose only the minimum PHI needed to accomplish the purpose.
What safeguards does HIPAA require?
Administrative, technical, and physical controls
To protect confidentiality, integrity, and availability.
What accountability measures are required under HIPAA?
What is the HIPAA Safe Harbor Law?
OCR must consider recent implementation of safeguards and may apply leniency.