EHR Go Knowledge Activity: Introduction to Privacy and Security AK1004.3
1
Archetype Innovations LLC ©2019
Knowledge Activity: Introduction to Privacy and
Security
Learning objectives
1. Differentiate between privacy, security and confidentiality related to the electronic
health record.
2. Discuss how electronic health records affect privacy and security.
3. Recognize threats to security as it relates to the internet, cybersecurity and mobile
devices.
4. Identify when a patient’s health information may be shared without written consent.
5. Discuss the implications and complications of violating HIPAA.
6. Apply current knowledge of electronic health records.
Student instructions
1. If you have questions about this activity, please contact your instructor for assistance.
2. You will review the chart of Daisha Estrada to complete this activity. Your instructor has
provided you with a link to the Introduction to Privacy and Security activity. Click on 2:
Launch EHR to review the patient chart and begin this activity.
3. Refer to the patient chart and any suggested resources to complete this activity.
4. Document your answers directly on this activity document as you complete the activity.
When you are finished, you will save this activity document to your device and upload
this activity document with your answers to your Learning Management System (LMS).
The activity
What is HIPAA?
HIPAA is an acronym that stands for the Health Insurance Portability and Accountability Act.
It’s a US law designed to provide privacy standards to protect patients’ medical records and
other health information provided to health plans, doctors, hospitals and other health care
providers. Developed by the Department of Health and Human Services, these standards
provide patients with access to their medical records and more control over how their personal
EHR Go Knowledge Activity: Introduction to Privacy and Security AK1004.3
2
Archetype Innovations LLC ©2019
health information is used and disclosed. They represent a uniform, federal floor of privacy
protections for consumers across the country.
A Covered Entity is one of the following:
A Health Care
Provider
A Health Plan
A Health Care Clearinghouse
This includes providers
such as:
1. Doctors
2. Clinics
3. Psychologists
4. Dentists
5. Chiropractors
6. Nursing Homes
7. Pharmacies
This includes:
Health insurance companies
HMOs
Company health plans
Government programs that
pay for health care, such as
Medicare, Medicaid, and the
military and veterans’ health
care programs
This includes entities that
process nonstandard health
information they receive from
another entity into a standard
(i.e., standard electronic
format or data content), or
vice versa.
(US Department of Health and Human Services, 2015)
Under HIPAA, “health information” is any information (including genetic information) that is
created or received by a health care provider, health plan, public health authority, employer,
life insurance company, school or university, or health care clearinghouse. This includes a
person’s past, present, or future physical or mental health condition; treatment provided to a
person; or past, present, or future payment for healthcare an individual receives.
Health information can exist in any form or medium, including paper, electronic, or oral
(verbal). When a covered entity creates or receives health information that identifies, or can be
used to identify, a person, HIPAA calls it “individually identifiable health information.”
Individually identifiable health information includes demographic and other information that
identifies a person such as name, address, date of birth, and Social Security number. (Privacy
Rights Clearinghouse, 2015)
Privacy Rule
The Privacy Rule gives individuals rights with respect to their protected health information
(PHI). It also explains how covered entities (those who must comply with HIPAA) can use and
disclose PHI. (Privacy Rights Clearinghouse, 2015)
A major goal of the Privacy Rule is to assure that individuals health information is properly
protected while allowing the flow of health information needed to provide and promote high
quality health care and to protect the public‘s health and well-being. The Rule strikes a balance
that permits important uses of information, while protecting the privacy of people who seek care
and healing. Given that the health care marketplace is diverse, the Rule is designed to be flexible
and comprehensive to cover the variety of uses and disclosures that need to be addressed. (United
State Department of Health and Human Services, 2003)
HIPAA Violation
Maximum Penalty
Individual did not know (and
by exercising reasonable
diligence would not have
known) that he/she violated
HIPAA
$50,000 per violation,
with an annual
maximum of $1.5
million
HIPAA violation due to
reasonable cause and not
due to willful neglect
$50,000 per violation,
with an annual
maximum of $1.5
million
HIPAA violation due to willful
corrected within the required
time period
$10,000 per violation, with an
repeat violations
$50,000 per violation,
maximum of $1.5
million
HIPAA violation is due to
corrected
$50,000 per violation, with an
$50,000 per violation,
maximum of $1.5
million