Find & Ask › Updates

What’s new in your states

Latest additions and revisions for Pennsylvania + Federal · change states

2003-04-14 · Federal · 🆕 newreview

45 CFR 164.524 — HIPAA Privacy Rule: Access of Individuals to Protected Health Information

This section grants individuals a right to inspect and obtain a copy of their protected health information (PHI) in a designated record set, with limited unreviewable and reviewable grounds for denial. It sets time limits and procedures for acting on access requests, the form and format of access, reasonable cost-based fees, requirements for denials and review of denials, and documentation obligations.

2003-04-14 · Federal · 🆕 newreview

45 CFR 164.528 — HIPAA Privacy Rule: Accounting of disclosures of protected health information

Gives individuals the right to receive an accounting of disclosures of their PHI made by a covered entity in the six years prior to the request, subject to enumerated exceptions (such as treatment/payment/operations, disclosures to the individual, and authorized disclosures). It specifies the required content of the accounting, provisions for multiple and research disclosures, temporary suspension for oversight/law enforcement, timeliness and fee limits, and documentation duties.

2003-04-14 · Federal · 🆕 newFYI

45 CFR 164.526 — HIPAA Privacy Rule: Amendment of protected health information

Grants individuals the right to have a covered entity amend PHI or a record about them in a designated record set, and sets the grounds on which an entity may deny amendment. It prescribes timelines for acting on amendment requests, the steps required when accepting an amendment (including informing others), and the process for denials, statements of disagreement, rebuttals, recordkeeping, and future disclosures.

2003-04-14 · Federal · 🆕 newreview

45 CFR 164.520 — HIPAA Privacy Rule: Notice of Privacy Practices for Protected Health Information

This section gives individuals a right to adequate notice of the uses and disclosures of protected health information (PHI) that a covered entity may make, and of the individual's rights and the covered entity's legal duties. It prescribes the required plain-language content of the notice, the timing and manner in which health plans and health care providers must provide and revise it, electronic-notice and joint-notice rules, and documentation requirements.

2003-04-14 · Federal · 🆕 newFYI

45 CFR 164.514 — HIPAA Privacy Rule: Other requirements relating to uses and disclosures of protected health information (de-identification, minimum necessary, limited data set, fundraising, verification)

Establishes additional cross-cutting requirements for uses and disclosures of PHI, including the two methods for de-identifying PHI (expert determination and the Safe Harbor removal of 18 identifiers) and re-identification, the minimum necessary standard for uses, disclosures, and requests, the limited data set and data use agreement rules, fundraising communication conditions, underwriting restrictions, and verification of the identity and authority of persons requesting PHI.

2003-04-14 · Federal · 🆕 newreview

45 CFR 164.530 — HIPAA Privacy Rule: Administrative Requirements

The HIPAA Privacy Rule's administrative-compliance requirements for covered entities — designate a privacy official and complaint contact, train the workforce, maintain safeguards, provide a complaints process, apply sanctions, mitigate harm, refrain from retaliation and rights-waivers, maintain compliant policies and procedures, and document and retain records for six years. Cross-cutting federal baseline for the Privacy & Security (HIPAA) topic.

2003-04-14 · Federal · 🆕 newreview

45 CFR 164.512 — HIPAA Privacy Rule: Uses and disclosures for which an authorization or opportunity to agree or object is not required

Enumerates the situations in which a covered entity may use or disclose PHI without the individual's written authorization and without an opportunity to agree or object, subject to the conditions in each standard. These include disclosures required by law; for public health activities; about victims of abuse, neglect, or domestic violence; for health oversight; for judicial and administrative proceedings; for law enforcement; about decedents; for organ donation; for research; to avert a serious threat to health or safety; for specialized government functions; and for workers' compensation.

2003-04-14 · Federal · 🆕 newreview

45 CFR 164.508 — HIPAA Privacy Rule: Uses and disclosures for which an authorization is required

Establishes that a covered entity may not use or disclose protected health information (PHI) without a valid authorization, except as otherwise permitted or required by the Privacy Rule. It specifies when authorizations are required (including psychotherapy notes, marketing, and sale of PHI), the core elements and required statements that make an authorization valid, prohibitions on compound and conditioned authorizations, and revocation and documentation duties.

2005-04-20 · Federal · 🆕 newreview

45 CFR 164.310 — HIPAA Security Rule: Physical Safeguards

This section requires covered entities and business associates to implement physical safeguards protecting electronic protected health information (ePHI) and the systems that house it. It mandates facility access controls, workstation use and security policies, and controls governing the receipt, removal, disposal, and re-use of hardware and electronic media.

2005-04-20 · Federal · 🆕 newreview

45 CFR 164.316 — HIPAA Security Rule: Policies and procedures and documentation requirements

Requires covered entities and business associates to implement reasonable and appropriate policies and procedures to comply with the HIPAA Security Rule and to maintain documentation of those policies, procedures, actions, activities, and assessments in written (which may be electronic) form. It sets a six-year retention period, an availability requirement, and a duty to review and update documentation as needed.

2003-04-14 · Federal · 🆕 newreview

45 CFR 164.502 — HIPAA Privacy Rule: Uses and Disclosures of PHI, General Rules

This section states the general rules governing when a covered entity or business associate may or must use or disclose protected health information (PHI). It sets the minimum necessary standard, prohibits certain uses (genetic information for underwriting, sale of PHI, and uses relating to reproductive health care investigations), and addresses business associate disclosures, de-identified information, personal representatives, deceased individuals, and whistleblower disclosures.

2009-09-23 · Federal · 🆕 newreview

45 CFR 164.408 — HIPAA Breach Notification Rule: Notification to the Secretary

This section requires a covered entity to notify the Secretary of HHS following discovery of a breach of unsecured protected health information. Breaches involving 500 or more individuals must be reported contemporaneously with individual notice; breaches involving fewer than 500 individuals must be logged and reported to the Secretary no later than 60 days after the end of the calendar year.

2009-09-23 · Federal · 🆕 newreview

45 CFR 164.404 — HIPAA Breach Notification: Notification to Individuals

The HIPAA Breach Notification Rule's requirement that a covered entity notify each affected individual following discovery of a breach of unsecured protected health information — without unreasonable delay and no later than 60 calendar days after discovery — specifying the required content, plain-language standard, and methods of notice (written first-class mail or email, substitute notice, and urgent additional notice). Cross-cutting federal baseline for the Privacy & Security (HIPAA) topic.

2018-01-13 · Federal · 🆕 newreview

42 CFR 484.80 — Condition of Participation: Home Health Aide Services

Federal home health Condition of Participation governing home health aide qualifications, the 75-hour training program and required subject areas, RN-conducted competency evaluation, 12 hours of annual in-service training, aide assignments and duties, and the supervisory visit schedule (14-day supervisory assessments for skilled patients, 60-day RN visits for non-skilled patients, plus annual/semi-annual on-site observation and mandatory retraining on deficiencies). Cross-cutting federal baseline for the Caregiver Qualifications/Training, In-Service, and Supervision topics.

2018-01-13 · Federal · 🆕 newreview

42 CFR 484.65 — Condition of Participation: Quality Assessment and Performance Improvement (QAPI)

Federal home health Condition of Participation requiring each HHA to develop, implement, evaluate, and maintain an effective, ongoing, data-driven, agency-wide QAPI program — covering program scope, data (including OASIS), performance improvement activities, annual performance improvement projects, and governing-body executive responsibilities. Cross-cutting federal baseline for the QAPI framework topic.

2018-01-13 · Federal · 🆕 newFYI

42 CFR 484.70 — Condition of Participation: Infection Prevention and Control

Federal home health Condition of Participation requiring each HHA to maintain and document an infection prevention and control program — following accepted standards of practice and standard precautions, operating a coordinated agency-wide surveillance and control program integral to QAPI, and providing infection control education to staff, patients, and caregivers. Cross-cutting federal baseline for the Infection Prevention & Control topic.

2018-01-13 · Federal · 🆕 newreview

42 CFR 484.55 — Condition of Participation: Comprehensive Assessment of Patients

Federal home health Condition of Participation requiring a patient-specific comprehensive assessment — an RN-led initial assessment visit within 48 hours, completion of the comprehensive assessment within 5 days of start of care, required content (including a full medication review and OASIS items), and updates at defined intervals (every 60 days, after a 24-hour+ hospitalization, and at discharge). Cross-cutting federal baseline for the Client Assessment & Reassessment topic.

2018-01-13 · Federal · 🆕 newFYI

42 CFR 484.102 — Condition of Participation: Emergency Preparedness

This Condition of Participation requires HHAs to establish and maintain an emergency preparedness program including an all-hazards emergency plan, policies and procedures, a communication plan, and a training-and-testing program, each reviewed and updated at least every 2 years. It fills the emergency-preparedness framework topic for home health.

2005-04-20 · Federal · 🆕 newFYI

45 CFR 164.314 — HIPAA Security Rule: Organizational requirements

Sets the organizational requirements under the HIPAA Security Rule for business associate contracts (or other arrangements) and for group health plans. It requires that business associate contracts obligate the business associate to comply with the Security Rule, ensure subcontractor compliance, and report security incidents; and that group health plan documents require plan sponsors to safeguard electronic PHI.

2005-04-20 · Federal · 🆕 newreview

45 CFR 164.308 — HIPAA Security Rule: Administrative Safeguards

The HIPAA Security Rule's administrative safeguards for electronic protected health information — a security management process (risk analysis, risk management, sanctions, activity review), an assigned security official, workforce security, information access management, security awareness and training, security incident procedures, a contingency plan, periodic evaluation, and written business associate assurances. Cross-cutting federal baseline for the Privacy & Security (HIPAA) topic.

2018-01-13 · Federal · 🆕 newFYI

42 CFR 484.100 — Condition of Participation: Compliance with Federal, State, and Local Laws and Regulations Related to the Health and Safety of Patients

This Condition of Participation requires HHAs and their staff to operate in compliance with all applicable federal, state, and local health-and-safety laws, be licensed where required, disclose ownership and management information, and meet CLIA laboratory-service requirements. It fills the licensure / ownership-disclosure / legal-compliance framework topic for home health.

2009-09-23 · Federal · 🆕 newreview

45 CFR 164.410 — HIPAA Breach Notification Rule: Notification by a business associate

Requires a business associate to notify the covered entity following discovery of a breach of unsecured PHI, treating a breach as discovered on the first day it is known or would have been known by exercising reasonable diligence. The notification must be provided without unreasonable delay and no later than 60 calendar days after discovery, and must identify affected individuals and include the other information the covered entity needs for individual notification.

2009-09-23 · Federal · 🆕 newreview

45 CFR 164.406 — HIPAA Breach Notification Rule: Notification to the media

Requires a covered entity to notify prominent media outlets serving a State or jurisdiction following the discovery of a breach of unsecured PHI involving more than 500 residents of that State or jurisdiction. The notification must be provided without unreasonable delay and no later than 60 calendar days after discovery, and must meet the content requirements of § 164.404(c).

2018-01-13 · Federal · 🆕 newFYI

42 CFR 484.105 — Condition of Participation: Organization and Administration of Services

This Condition of Participation requires the HHA to organize and administer its resources with a governing body, an administrator, a clinical manager, controlled parent-branch relationships, written agreements for services under arrangement, defined services furnished, institutional planning, and a patient acceptance-to-service policy. It fills the governance / organization-and-administration framework topic for home health.

2018-01-13 · Federal · 🆕 newFYI

42 CFR 484.115 — Condition of Participation: Personnel Qualifications

This Condition of Participation sets the minimum education, licensure, and certification qualifications for HHA staff, including the administrator, clinical manager, nurses, therapists and assistants, social workers, home health aides, and physicians. It fills the personnel-qualifications / credentialing framework topic for home health.

2018-01-13 · Federal · 🆕 newFYI

42 CFR 484.110 — Condition of Participation: Clinical Records

This Condition of Participation requires the HHA to maintain an accurate clinical record for every patient with specified contents, authenticate all entries, retain records at least 5 years, protect records under HIPAA, and make records available to the patient upon request. It fills the clinical-records / documentation / record-retention framework topic for home health.

2018-01-13 · Federal · 🆕 newFYI

42 CFR 484.50 — Condition of Participation: Patient Rights

This Condition of Participation requires home health agencies (HHAs) to inform patients and their representatives of their rights, protect and promote the exercise of those rights, investigate complaints, and comply with transfer/discharge and accessibility standards. It fills the patient-rights / notice-of-rights and grievance framework topic for federally certified home health providers.

2018-01-13 · Federal · 🆕 newFYI

42 CFR 484.60 — Condition of Participation: Care Planning, Coordination of Services, and Quality of Care

Federal home health Condition of Participation requiring an individualized, physician-signed written plan of care with defined required content (including all medications and treatments), conformance with physician/allowed-practitioner orders (including verbal-order documentation), review and revision at least every 60 days, communication of revisions, coordination of care across all disciplines, and written care instructions to the patient and caregiver. Cross-cutting federal baseline for the Plan of Care & Service Delivery and Medication Management topics.

2005-04-20 · Federal · 🆕 newreview

45 CFR 164.312 — HIPAA Security Rule: Technical Safeguards

This section requires covered entities and business associates to implement technical safeguards for electronic protected health information (ePHI). It mandates access controls, audit controls, integrity protections, person or entity authentication, and transmission security to guard ePHI in information systems and during electronic transmission.

Don’t check this page — the weekly digest email carries the same feed for your states. Subscribe on the home page.