Topics Covered: ROI landscape, release of information, federal compliance, uses and disclosures of PHI, federal healthcare privacy regulations, HIPAA Privacy Rule, HIPAA Security Rule, HIPAA Enforcement Rule, HITECH Act, HIPAA Breach Notification Rule, HIPAA Final Omnibus Rule, HIPAA Reproductive Health Rule, Reproductive Health Privacy Rule, revocation of the RHI Rule, Purl v. U.S. Department of Health and Human Services, patient privacy, protected health information, PHI, electronic protected health information, ePHI, electronic health information, EHI, Office for Civil Rights enforcement, OCR enforcement, HIPAA enforcement structure, civil money penalties, penalty factors, tiered penalty structure, patient rights, electronic copies of records, accounting of disclosures, right to restrictions, individual right of access, individual right to restrict disclosures to health plans, authorization requirements for use of PHI, minimum necessary standard, permitted uses and disclosures without authorization, preemption, more stringent state law, federal versus state law, state law conflicts, state-specific privacy requirements, disclosure turnaround times, faster state disclosure timelines, Colorado disclosure turnaround time, HIPAA 30-day response timeframe, one-time HIPAA extension, Colorado inspection timeframe, Colorado copies timeframe, administrative safeguards, physical safeguards, technical safeguards, risk analysis, workforce security, role-based access, security awareness training, contingency planning, facility access controls, workstation use and security, device and media controls, access controls, audit controls, integrity controls, authentication, transmission security, HIPAA Security Rule NPRM, January 2025 NPRM, cybersecurity framework alignment, mandatory technical safeguards, expanded risk analysis requirements, asset inventory, network map, business associate obligations, incident response, role-based training, steeper penalties, business associates, BA liability, covered entities, CE audits, HHS audits, HITECH Breach Portal, breach notification requirements, presumption of breach, genetic information protections, reproductive health information, RHI, reproductive health privacy disclosures, investigations related to reproductive health care, criminal investigations, civil investigations, administrative investigations, lawfulness of reproductive healthcare, attestation requirements, RHI attestations no longer required, continued HIPAA compliance, release of information education, real-world ROI scenarios, case-based ROI training, subpoena processing, subpoena duces tecum, subpoena validation, subpoena versus court order, court jurisdiction, valid subpoena review, patient authorization, permitted disclosure without authorization, satisfactory assurance, 45 CFR § 164.512(e)(1)(ii), good faith attempt to notify individual, objection opportunity, objection timeframe, state law review for subpoenas, communicating with requestors, maintaining subpoena documentation, legal and compliance escalation, subpoena do’s and don’ts, release only records specifically requested, avoid over-disclosure, avoid unjustified delay, 42 CFR Part 2, substance use disorder records, SUD records, Part 2 programs, federally assisted outpatient clinic, Part 2 protected records, patient discrimination protection, fear of prosecution protection, CARES Act Part 2 alignment, 2024 Part 2 Final Rule, HIPAA alignment for Part 2, SUD Counseling Notes, Part 2 privacy rights, Part 2 enforcement, Part 2 breach notification, Part 2 redisclosure, TPO disclosures, treatment payment and healthcare operations, patient consent for future TPO disclosures, single consent for future TPO requests, 42 CFR § 2.31(a), 42 CFR § 2.33(a)(2), consent requirements, treating provider recipient language, patient right to revoke consent, expiration date, signature and date, redisclosure statement, SUD disclosure do’s and don’ts, written consent for SUD disclosures, plain language consent, staff training on HIPAA versus Part 2, law enforcement requests for Part 2 records, court requests for Part 2 records, valid court order requirement, anti-discrimination rules, 21st Century Cures Act, interoperability, health information access, information blocking, Information Blocking Rule, expedient access without delay, actors under information blocking, providers, Health IT developers, health information exchanges, HIEs, information blocking exceptions, preventing harm exception, privacy exception, security exception, infeasibility exception, Health IT performance exception, content and manner exception, fees exception, licensing exception, patient portal access, automatic release of lab results, automatic release of imaging results, delayed result release, provider review before release, possible autoimmune disorder lab results, documented reason for delay, preventing harm exception, 45 CFR § 171.201, reasonable belief of harm reduction, professional judgment on an individual basis, documented clinical judgment, avoiding blanket exception practices, prompt electronic access, EHR settings, internal policy updates, clinical staff training, administrative staff training, balancing access with privacy, case-by-case ROI judgment, confident and consistent ROI compliance, federal regulations for ROI, recent federal compliance changes, applying federal regulations to real-world scenarios, legal advice disclaimer, Haugen Academy ROI education, health information professional education
It was an excellent presentation!
The presenter was so knowledgeable and organized. The presentation was very easy to follow. Thank you!
Enjoyed the course, I especially liked the scenarios. I would like to see more scenarios included in the presentation.