Alcoholism & Substance Abuse Providers of NYS - Return Home

HIPAA
Health Insurance Portability and Accountability Act

| Listserv | Frequently Asked Questions | Resources | Links |

ASAP HIPAA Listserv

Click here to subscribe: asap-hipaa-subscribe@yahoogroups.com

ASAP HIPAA home page: http://groups.yahoo.com/group/asap-hipaa
Once you have subscribed send group email to : asap-hipaa@yahoogroups.com

 


Frequently Asked Questions

What is HIPAA?

In 1996 Congress passed the Health Insurance Portability and Accountability Act, now commonly known as HIPAA. The major purpose of the act, was administrative simplification, that is, promoting a more efficient health care system by reducing administrative requirements and therefore costs. HIPAA required the U.S. Department of Health and Human Services (DHHS) to adopt separate regulations covering standardized transactions, privacy of individually identifiable health information, security of individually identifiable health information and unique identifiers for individuals, health care plans, employers and health care providers.

Who is covered under HIPAA?

"Covered entities" as defined by HIPAA, include health care providers who transmit health care information in electronic form. There are ten specific covered transactions listed in the regulation including (1) health care claim or encounter, (2) health care payment and remittance advice, (3) coordination of benefits, (4) health care claim status, (5) enrollment and disenrollment in a health plan, (6) eligibility for a plan, (7) health plan premium payments, (8) referral certification and authorization, (9) first report of injury, and (10) health claims attachments. All alcohol and substance treatment providers are health care providers under HIPAA. Therefore, any alcohol and substance provider who electronically submits any one of the ten prescribed health care transactions and/or attachments are covered entities under HIPAA.

When are HIPAA regulations effective?

Separate regulations covering each of the major components of HIPAA are being issued sequentially. The first regulations govern "health care transactions" as described above were adopted and were originally effective in October of 2002. Subsequently, legislation was enacted that postponed the effective date until 10/16/2003. Extensions are NOT automatic however, providers had to submit plans for compliance to the U.S. Department of Health and Human Services by 10/16/2002. Privacy regulations governing use and disclosure and protection of individually identifying health identifying information, have also been adopted and will be effective April 2003. Security and identifier regulations have been drafted but not yet finalized.

HIPAA Administrative Simplification Compliance Deadlines

Date Deadline
October 15, 2002 Deadline to submit a compliance extension form for Electronic Health Care Transactions and Code Sets.
October 16, 2002 Electronic Health Care Transactions and Code Sets - all covered entities except those who filed for an extension and are not a small health plan.
April 14, 2003 Privacy - all covered entities except small health plans.
April 16, 2003 Electronic Health Care Transactions and Code Sets - all covered entities must have started software and systems testing.
October 16, 2003 Electronic Health Care Transactions and Code Sets - all covered entities who filed for an extension and small health plans.
April 14, 2004 Privacy - small health plans.
July 30, 2004 Employer Identifier Standard - all covered entities except small health plans.
August 1, 2005 Employer Identifier Standard - small health plans.

What is the impact of HIPAA?

For health care providers who conduct any one of the above-mentioned health care transactions electronically, the transaction regulations mandate use of a standardized format. The format will be required by all public (Medicaid and Medicare) and private insurers including managed care plans. In additions, the transaction regulations mandate use of prescribed clinical coding systems, e.g., diagnostic and procedure codes. All software systems involving "covered" transactions will need to be HIPAA compliant.

Privacy regulations contain a number of requirements including development/adoption of policies and procedures, patient privacy notices and consent and authorization forms. Providers are also required to designate a Privacy Officer to be responsible for monitoring on-going compliance. It is important to note that once an entity is covered under HIPAA, all personal health information including paper and oral transmissions, is subject to Privacy requirements.


| Listserv | Frequently Asked Questions | Resources | Links | Vendors |

HIPAA Resources
To save the file to your computer, right click on the hyperlink and click on "save target as..."

 

Resources Available to ASAP Members

The following resources are available to ASAP members and staff of agency members. Contact ASAP and identify what material(s) you want we and will them to email you. Send your email request to asap@asapnys.org or asap@asapnys or call our office.

  • ASAP / Legal Action Center HIPAA Presentations.  Power point slides used in the trainings offered in Rochester, Albany and New York City.

  • Sample Privacy and Security Policy (word document)- developed by and with thanks to DePaul Huther-Doyle.

  • Power Point Presentations

Legal Action Center Presentation on Privacy Bob Lebman - Initial presentation on what programs need to do to get ready
John Coppola - Initial Presentation on Security Bob Lebman - NYC presentation on what programs need to do to get ready (revised)
John Coppola - Revised Presentation on Security  Paula Cattat - HIPAA Presentation at the ASAP Annual Conference
John Coppola - Presentation on New Security Standards Chart on Required and Addressable  Security Standards
  •     The following forms and Policies and Forms were developed by DePaul Huther-Doyle
     
    Forms Consent to Release Receipt of Notice Request to access PHI
    Employee confidentiality Pledge Amendment of Records Confidential Communications
    Granting Request for Access Restriction of Disclosures Denial of Request of PHI Denial of Request for Amendment
    Policies Disclosure concerning minors, incapacitated and deceased persons Access and denial to PHI Accounting of Disclosure of PHI
    Business Associates De-Identification of PHI Discipline and Dismissal Fax Transmittal of PHI
    Uses and Disclosures of PHI Mandatory Education and Training Minimum necessary use and disclosure Mitigation after improper PHI use or disclosure
    Non-Retaliation Privacy Practices Printing and Copying PHI Privacy Complaint
    Request for Confidential Communications Restriction of Uses and Disclosures Revocation of Authorization to Release Right to Amend PHI
    Use and Disclosure of Limited Data Sets Use and Disclosure of PHI based Authorization Use and Disclosure of PHI for Facility Directory Use and disclosure without Client Authorization


Resources for All


| Listserv | Frequently Asked Questions | Resources | Links | Vendors |


 

Helpful Websites

 

Administrative Simplification under HIPAA: National Standards for Transactions, Security and Privacy http://www.hhs.gov/news/press/2002pres/hipaa.html

 

CDC National Center for Health Statistics, Web-Based Resource Center http://www.cdc.gov/nchs/otheract/phdsc/wbasedwg_sites.htm#HIPAA%20Implementation

 

Frequently Asked Questions About Code Set Standards Adopted Under HIPAA http://aspe.hhs.gov/admnsimp/faqcode.htm

 

Frequently Asked Questions About Electronic Transaction Standards Adopted Under HIPAA http://aspe.hhs.gov/admnsimp/faqtx.htm

 

Frequently Asked Questions About Security and Electronic Signature Standards http://aspe.os.dhhs.gov/admnsimp/faqsec.htm

 

Health and Human Services - Office of Human Rights - HIPAA

http://www.hhs.gov/ocr/hipaa/whatsnew.html

 

HCFA sponsored listserve

http://aspe.hhs.gov/admnsimp/lsnotify.htm

 

Health Privacy Project

http://www.healthprivacy.org/

 

HIPAA Administrative Simplification Compliance Act (ASCA)
Frequently Asked Questions: http://www.hipaadvisory.com/action/faqs/FAQ_ASCA.htm

 

HIPAA Centers for Medicare & Medicaid Services

Administrative Simplification http://www.cms.gov/hipaa/hipaa2/default.asp

CMS Forms http://www.cms.hhs.gov/forms/

Covered Entity Decision Tools http://cms.hhs.gov/hipaa/hipaa2/support/tools/decisionsupport/
HIPAA Online http://cms.hhs.gov/hipaa/online

Insurance Reform http://cms.hhs.gov/hipaa/hipaa1

One Year Extension http://www.cms.gov/hipaa/hipaa2/ascaform.asp

 

NASADAD HIPAA Information Pages

Help Center  http://www.nasadad.org/Departments/Research/HIPAAHelp/HIPAAHelp.htm

 

New York State Office of Alcoholism and Substance Abuse http://www.oasas.state.ny.us/hps/Hipaa/hipaa_home.htm

 

PUBLIC LAW 104-191 AUG. 21, 1996 HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996 http://aspe.hhs.gov/admnsimp/pl104191.htm

 

Standards for Privacy of Individually Identifiable Health Information
http://aspe.hhs.gov/admnsimp/final/pvcguide1.htm

 

Strategic National Implementation Plan, Workgroup for Electronic Data Interchange: http://snip.wedi.org/

 

 


| Listserv | Frequently Asked Questions | Resources | Links |


Alcoholism & Substance Abuse
Providers of New York State
1 Columbia Place - Albany, New York  12207
Phone: (518) 426-3122  Fax: (518) 426-1046
E-Mail: asap@asapnys.org


Home | About ASAP | Board & Committees | What's New 
Membership | Meeting Schedule | Member Benefits | Newsletter | Conference
Public Policy & Issues| Peer Review | Job Bank | Links | Prevention | Substance Abuse News

©1999-2006 Alcoholism & Substance Abuse
Providers of New York State. All Rights Reserved.
This site was created  on May 1, 1999 and is maintained by
Alcoholism and Substance Abuse Providers of New York State.
This page was most recently updated on Wednesday, May 30, 2007.