Protection of a Patient Confidential Information

Protection of a Patient Confidential Information

Abstract

It is necessary to protect a patients’ private information pertaining to their medical condition or history. In this regard, the American congress processed Health Insurance Portability and Accountability Act (HIPAA), which was turned into law on August 21st 1996 by the then US president Bill Clinton. The commencing paper will attempt to investigate the privacy policy enacted by HIPAA. The discussion will endeavor to prove that HIPAA has been vital in ensuring a patient’s health information is protected, and in case of a breach, providers and legal practitioners advise a way forward constructively. The paper will also provide a legal balancing measure to safeguards medical institutions and providers from fraudulent appeals by a patient or patient relatives.

Based on HIPAA, Who can see the information and the responsibility of the provider and the patient

HIPAA empowers the patient to access substantial information regarding personal medical records. Rights stretch valiantly depending on stipulations of the law.  In any case, consumers can access and review their medical records. The privacy policy under (45 CFR 164 524) powers the individual to review their updates online within a period of 30 days. If no information is provided, a cover-entity through written statements powers an individual to request reasons for delay. If this does not happen, the individual is bestowed with a right to file a complaint directly (Sullivan, 76). Secondly, consumers have a right to demand a written summary about their health and financial obligation, and this ensures access to accounting or medical information. Thirdly, consumers are empowered to adjust incoherent information in their medical records. Indeed, HIPAA empowers the individual to file a legal suit within 60 days against information, which he or she disagrees with. This is in line with stipulation (45 CFR 164. 526) of the act. Also, HIPAA compels providers from assigning patients medical conditions without the consent. This is in line with a plethora of consideration including, prescriptions, hospitalizations, telemedicine, and emergency situations. This is vital since the patient will be in a position to engage into substantial decision regarding personal medical conditions. In its operation, providers are expected to provide complete information about the patient medical condition. Conversely, the provider is mandated to request the consent to reveal or not reveal the patient medical condition either to the patient friends or relatives.
How to file a complaint regarding a HIPAA violation with the Office of Civil Rights?

Sullivan (75) argues that a complaint may be filed by an allied health professional, a friend, a patient, a physician, or a relative, who believes that the provider has violated privacy rights under HIPAA were violated. In this case, the filing individual is expected to visit geographical offices located within the jurisdiction or visit the online complaint platform entitled to Office for Civil Rights (OCR). A complaint is required to legally write through email, fax or letter. The complainant should also include the covered entity or the provider involved and describe in acts the various levels of violations, security breach and notification rules. Thirdly, the complaint letter should not last past 180 days from the presumed day or period of violation.

What a covered entity MUST do to notify patients when there’s a breach of unsecured protected health information?

The Covered entity is comprised of three groups including care clearinghouses, health plans and providers who transmit data electronically. In this case, the official in a covered entity complies with the rule of requirements with a goal of protecting health personal health record. Iyer, et al, (170) argues that covered entity is essential since it appoints a privacy official, one who is responsible in receiving complains, analyzing information and filling records. The covered entities are compelled by Protected Health Information (PHI). Primarily, the covered entity categorizes the data on personal patient accounts. In this case, entry information includes; contacts, relatives or photographic information is captured through the use of covered information. Providers are expected to protect this information, and in any event, notify the patient is violations are experienced within the entity. Staggers & Ramona (391) argues that providers should inform patients on the nature, time, and magnitude of violations. The provider is compelled to write a brief description about the consequences of the violations. Secondly, the provider is expected to provide a description of the types of PHI involved in the violations. Thirdly, the provider is expected to educated the individual on steps he or should take protect himself or herself or the subject from harm resulting to breach. Fourthly, the provider is expected to use legal authorities to initiate an investigative platform, which mitigate future losses.

Office for Civil Rights obligations and mandates

Roth-Kauffman (479) establishes that the department of health and human services office of civil rights is responsible for ensuring that privacy protection and rights of consumers, which in this case are patients, who are not infringed or violated practically. The privacy officer assigned to this office is mandated to receive complaint letters on carry out responsive actions to determine; firstly, if PHI was violated or was it used properly. Secondly, does privacy practice requires modifications?  Thirdly, it is prudent to consider whether additional training will be essential to avoid violations. The office depends on whether the complainant followed the required stipulation recommended by HIPAA, whether the name of the entity is inclusive, the complain letter has the subject of violations or any other violations of acts and omissions (Kragger, & Kragger 142). The office of civil rights is the legally recognized institute that is mandated in providing civil penalties to violators. The office is empowered by American Recovery and Reinvestment Act, which determines the amount of penalty to be issued based on violation. Violations are resolved by investigating both the complaint and providers accounts on the suit. In most cases, penalties are issued by attracting financial fines; for instance, a violation which is considered willful neglect, and is not corrected, will attract 50,000 maximum violations or an annual fine of 1.5 million dollars or imprisonment for one year.

Conclusion

This paper has attempted to examine Health Insurance Portability and Accountability Act (HIPAA) legal contribution in protecting privacy concerns of the patient. The discussion has inherently examined to several contributions of the act in the overall rights realization, protection and filing of complaints procedures. In encapsulation, the paper has provided a counter balance to protect providers from illegal filings by patients.

Work Cited

Kragger, Carole., & Krager, Dan. HIPAA for Health Care Professionals. New York: Cengage

Learning, 2008. Print.  

Iyer, Patricia., Levin, Barbara., & Shea, Mary. Medical Legal Aspects of Medical Records.

Lawyers & Judges Publishing Company, 2004. Print.

Roth-Kauffman, Michele. Physician Assistant’s Business Practice and Legal Guide. Jones &

Barlett learning. 2005. Print.

Sullivan, June. HIPAA: A Practical Guide to the Privacy and Security of Health Data. New

York: American Bar Association, 2004. Print.

Staggers, Nancy., & Nelson, Ramona. Health Informatics: An Interprofessional Approach.

Amsterdam, Elsevier Health Sciences, 2013. Print.

 

Use the order calculator below and get started! Contact our live support team for any assistance or inquiry.

[order_calculator]