Loading...
6.6. ERMUSR 05-16-2006.^~/ Elk River -~ Municipal Utilities 13069 Orono Parkway Elk River, MN 55330 May 8, 2005 To: Elk River Municipal Utilities commission Jerry Takle Jim Tralle John Dietz From: Theresa Slominski Subject: HIPAA security policy phone: 763.441.2020 1'ax: 763.441.8099 Small businesses were required to be in compliance with security of electronic protected health information (ePHI) as of April 20, 2006. There were 18 standards that needed to be addressed and implemented. Elk River Municipal Utilities has completed an internal review and has the necessary procedures in place. I think that the final step in this process would be to have the commission approve the policies that ERMU is following. The policies are attached and also the related forms that would be signed to document our compliance. Elk River Municipal Utilities Health Plan HIPAA Security Policy Elk River Munic~al Utilities ("Plan Sponsor") sponsors one or more health plans ("The Plan(s)" or "Plan(s)") for eligible employees. The Plan(s) is(are) a "Covered Entity" as defined by the Health Insurance Portability and Accountability Act of 1996, Pub. L. 104-191 (HIPAA). Pursuant to the Security Standards contained in HIPAA (45 CFR 160 and 164), the Plan Sponsor adopts this Security Policy ("Policy") for the protection of Electronic Protected Health information (ePHI). The Plan(s) is not (are not) administered by a third party acting as a "Business Associate" of The Plan(s) as defined by 45 CFR § 160.103. 1. Effective Date The Plan's Security Policy is effective Apri120, 2006. The Policy will remain in force until changed or rescinded by The Plan Sponsor's designated Security Official or Board Action. 2. Security Management Process Risk Analysis and Risk Management [§164.308(a)(1)(ii)(A) and §164.308(a)(1)(ii)(B)] The covered entity has conducted a thorough assessment of potential security risks related to any Plan ePHI and made the following risk and vulnerability determinations: 1. The Plan(s) occasionally maintains or transmits limited ePHI, the Plan(s) maintains or transmits no ePHI that is critical to the health or life of Plan members. 2. ePHI maintained by The Plan(s) may be important to Plan operations, but is rarely mission critical. 3. Appropriate security measures implemented by The Plan(s) to protect the confidentiality and integrity of this information are described in this policy. Employee Sanctions [§164.308(a)(1)(ii)(C)] The Plan(s) and Plan Sponsor will apply appropriate employee sanctions, consistent with existing plan sponsor employee discipline and sanction policies, to any employee of The Plan Sponsor who violates The Plan's Security Policy. Sanctions can include termination of employment when appropriate. 3. Security Official The Plan(s) will officially designate a Security Official and maintain written record of the designation. The current Security Official designation is the Finance Director. Responsibilities of The Plan(s) Security Official include: a. Periodically evaluate this Policy and the procedures implemented to protect ePHI. The Security Official will maintain reasonable and appropriate policies and procedures to comply with the HIPAA Security Standards and make appropriate changes when necessary. § 164.308(a)(8), § 164.316(a) b. Regularly review the activity of any information systems involved in the maintenance or transmission of PHI to determine if ePHI has been used or disclosed in an inappropriate manner as required by § 164.308(a)(1)(ii)(D). c. Report to appropriate Plan Administrator and/or corporate office of Plan Sponsor any suspected or known security incidents as defined by § 164.308(a)(6)(ii). 4. Workforce Security [§164.308(a)(3) and §164.308(a)(4), §164.312(d)] Employee authorization to access systems that maintain or transmit ePHI, including determination of appropriate employee clearance level, person authentication, and effective and timely termination of system access for employees who no longer qualify for system access will be the responsibility of The Plan(s) Security Official. The Security Official may delegate these duties to appropriate parties based on exiting plan sponsor information system access policies and procedures. The Plan(s) and Plan Sponsor do not perform clearinghouse functions as defined by HIPAA so no procedures are necessary to meet security standards defined in § 164.308(a)(3)(ii)(B). 5. Security Awareness and Training The Plan(s) will require any employee of The Plan(s) or Plan Sponsor who is involved in the administration or management of The Plan(s) to certify in writing that they have received training and have read and understood The Plan's Security Policy. Employees will also be provided additional existing Plan Sponsor security training when available and appropriate. This training may include (but not be limited to) security reminders, protection from malicious software, and log-in monitoring if The Plan Sponsor has existing procedure to identify inappropriate system access attempts. Employees will be trained on procedures for creating and maintaining appropriate and effective passwords consistent with existing Plan Sponsor information system password policies and procedures. At least once per year, The Plan's Security Officer will review the Security Policy with individuals involved in the administration and management of The Plan(s). 6. Contingency Plan Data Backup Plan and Application and Data Analysis [§164.308(a)(7)(ii)(A), §164.308(a)(1)(ii)(E), §164.310(d)(2)(iv)] The Plan(s) will backup ePHI, and critical applications according to existing Plan Sponsor information system backup procedures and policies. Disaster Recovery, Emergency Mode Operation Plan, Testing and Revision Procedures [§164.308(a)(1)(ii)(B), §164.308(a)(1)(ii)(C), §164.308(a)(1)(ii)(D), §164.312(a)(2)(ii)] It has been determined that a formal disaster recovery operation plan applicable only to ePHI is not reasonable or necessary. The Plan(s) will operate in the event of an emergency based on existing emergency operation procedures of the plan sponsor, including granting access to facilities during an emergency. The Plan's Security Official will periodically review The Plan's contingency procedures to determine if changes or testing of the procedures is appropriate. 7. Business Associate Contracts The Plan(s) will allow a Business Associate of The Plan(s) to create, receive, maintain, or transmit ePHI on behalf of The Plan(s), only once The Plan(s) obtains written assurance through the use of business associate agreements that the Business Associate will appropriately safeguard The Plan's ePHI as required by § 164.314(a). 8. Facility Access Controls The Plan's ePHI is not located in facilities or locations that make it reasonable to implement facility security, access control or maintenance of security records procedures applicable ePHI locations only. Physical access to facilities where ePHI is maintained will be subject to existing Plan Sponsor physical security procedures and policies when applicable. 9. Workstation Use and Security and Access and Audit Controls [§164.310(b), §164.310(c), §164.312(a)(2)(i), §164.312(a)(2)(iii), ~164.312(a)(2)(iv)] The Plan(s) implements the following procedures to control access to ePHI and manage access to workstations that can be used to access ePHI. Employees will be assigned unique user names and passwords for systems used to access ePHI. These unique user IDs maybe assigned according to existing Plan Sponsor system access policies and procedures. The following workstation procedures will be implemented to mirturuze the potential risk of inappropriate use of ePHI to the extent possible and reasonable. a. When accessing ePHI on a workstation, employees will reduce visible windows or close programs whenever they are not physically present at the workstation or when individuals not authorized to access the ePHI can view the workstation. b. Workstation screensavers will be set to engage at a reasonably short timeframe. c. VC~orkstations located in areas where viewing by unauthorized individuak is likely will be equipped with monitor screens that limit the visibility of data to anyone other than the workstation user. d. Users with portable workstations such as laptops or PDAs are not allowed to store ePHI on workstation drives. All ePHI should be stored on Plan Sponsor servers subject to security procedures described in this policy unless The Plan(s) Security Officer determines it is necessary for plan administration purposes to store ePHI on portable workstations. It has been determined that it is not reasonable to develop automatic logoff procedures or data encryption mechanisms specifically for systems used to access ePHI. Automatic logoff and data encryption will be used for systems used to access ePHI if exiting existing Plan Sponsor system access policies and procedures include these capabilities and requirements. When ePHI is accessed by using systems that contain audit control capabilities, The Plan(s) will periodically review audit reports to assist in determining if a security violation has occurred. Employees who have been granted access to ePHI according to The Plan(s) policies and procedures will be subject to The Plan's sanction policy if they allow unauthorized access to ePHI by circumventing access control (e.g. sharing their unique login LD. and password). 10. Device and Media Controls and Integrity of Data [§164.310(d)(1), §164.310(d)(2)(i), §164.310(d)(2)(ii), §164.310(d)(2)(iii), §164.312(c)(1) Any ePHI stored by The Plan(s) in electronic storage media will be subject to the following procedures to ensure that the ePHI is not inappropriately used. • All hardware, storage devices, and electronic media which contains or contained ePHI will be erased, re-formatted or rendered unusable in a technically sufficient manner prior to disposal, or re-use for other purposes, to assure no unauthorized access to ePHI is possible in the future. • The Plan's SecuriryOfficial will be responsible to ensure that electronic media is controlled in accordance with this policy and maintain any reasonable documentation necessary. 1t has been determined that it is not reasonable or necessary to implement technical procedures for automatic data integrity checks for systems used to access ePHI alone. The Plan(s) will use existing Plan Sponsor data integrity procedures and policies, if available and reasonable, to determine if ePHI has been altered or destroyed in an unauthorized manner. 11. Transmission Security [§164.312(e)(1), §164.312(e)(2)(i)] The Plan(s) will implement the following measures to protect ePHI that is being transmitted over electronic communications networks including the Internet. It has been determined that it is not reasonable or necessary to implement transmission integrity controk or email and electronic communication encryption procedures only for systems used to access or transmit ePHI. The Plan(s) will use existing Plan Sponsor transmission integrity and email and communication encryption procedures, if available and reasonable, to protect ePHI transmitted over electronic networks. If the Plan Sponsor does not have existing transmission integrity or encryption procedures available, The Plan will implement the following procedures to protect ePHI transmitted over electronic networks: a. ePHI sent via email will be contained in a separate file sent as an attachment whenever reasonable. Files containing ePHI will be protected bya password when possible. Passwords necessary to access the file will be sent to the recipient via separate communication. 12. Group Health Plan Document Requirements The Plan's Plan Documents are amended to require that the Plan Sponsor reasonably and appropriately safeguards ePHI that it receives, maintains or transmits on behalf of the group healt}i plan. 13. Documentation [§164.316(b)(1), §164.316(b)(2)(i)] The Plan(s) will maintain written (which may be in electronic form) policies and procedures necessary to comply with the HIPAA Security Standards. • Documentation will be retained for 6 years from the date of its creation or the date when it was last in effect, whichever is later. • The documentation will be made available to persons responsible for implementing the procedures to which the documentation pertains. • The Plan(s) mill review all documentation periodically, and update as needed, in response to environmental or operational changes affecting the security of the ePHI. HIPAA Designation of Security Official Elk River Municipal Utilities, the "Plan Sponsor", hereby designates the Finance Director as the HIPAA Security Official for the Plan Sponsor's health care benefit plans as required by 164.308(a)(2). This designation shall remain in force until changed in writing by an Officer of the Plan Sponsor or Plan Sponsor's Board of Directors. Signed Title Date Plan Sponsor's HIPAA Privacy Rule Certification Form I, , on behalf of Elk River Municipal Utilities, am (OH'ner, or Ofl7cer Name) authorized to make the following certification for each of the employee benefits plans. 1. The Plan Sponsor will not further use or disclose protected health information (PHI) except as required by the plan documents or by law. 2. The Plan Sponsor will ensure that the Plan Sponsors' agents and subcontractors comply with the Employer's HIPAA Privacy Policy. 3. The Plan Sponsor will not use or disclose the PHI for employment-related actions or decisions. 4. The Plan Sponsor will not use or disclose the PHI in connection with any other benefit or employee benefit plan of the sponsor except as permitted under HIPAA. 5. The Plan Sponsor will self-report any disclosure violations to the plan. 6. The Plan Sponsor will meet certain administrative requirements applicable to health plans. 7. The Plan Sponsor will make its internal practices, books and records related to use and disclosure of PHI received from the plan available to the Secretary of Health and Human Services for compliance review. 8. Where feasible, the Plan Sponsor will return or destroy all PHI received from the plan when done with it. 9. The Plan Sponsor will maintain adequate separation between the group health plan and the sponsor. Signature of Owner or Officer Date Name of Employee Benefit Plan sponsored by Employer: Elk River Municipal Utilities Medical Health Plan, Long Term Disability Plan, Life Insurance Plan. HIPAA Privacy Rule Employee Confidentiality Form I, ,have read and understand Elk River Municipal (Employee Name) Utilities policies regarding the privacy of individually identifiable health information (or protected health information (PHI), as mandated by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the State of Minnesota. In addition, I acknowledge that I have received training in Elk River Municipal Utilities policies concerning PHI use, disclosure, storage and destruction as required by HIPAA. In consideration of my employment or compensation from Elk River Municipal Utilities, I hereby agree that I will not at any time -either during my employment or association with Elk River Municipal Utilities or after my employment or association ends -use, access or disclose PHI to any person or entity, internally or externally, except as is required and permitted in the course of my duties and responsibilities with Elk River Municipal Utilities, as set forth in Elk River Municipal Utilities privacy policy and procedures or as permitted under HIPAA. I understand that this obligation extends to any PHI that I may acquire during the course of my employment or association with Elk River Municipal Utilities, whether in oral, written or electronic form and regardless of the manner in which access was obtained. I understand and acknowledge my responsibility to apply Elk River Municipal Utilities policies and procedures during the course of my employment or association. I also understand that unauthorized use or disclosure of PHI will result in disciplinary action, up to and including termination of employment or association with Elk River Municipal Utilities and the imposition of civil penalties and criminal penalties under applicable federal and state law, as well as professional disciplinary action as appropriate. I understand that this obligation will survive the termination of my employment or end of my association with Elk River Municipal Utilities, regardless of the reason for such termination. Signature Date Name HIPAA Privacy and Security Policy Acknowledgment Form This notice tells all employees how and why personal information about employees will be collected, how it will be handled and secured, and with whom the information is shared. ~y'e respect the privacy of personal information and maintain it securely according to the privacy and security rules under HIPAA. This notice applies to information regarding all current and former employees. Why we collect personal information: • To determine eligibility for health care coverage • To transmit premium payments to the health insurance carrier • To provide test results to an officer of the company, government regulatory agencies, or companies that require certain tests under contract • For pre-employment physicals and to determine fitness-for-duty of the employee's job • To evaluate work-related injuries and comply with workers' compensation laws • For requests for accommodation under the ADA • To administer leave under FMLA (where applicable) • To comply with OSHA, MSHA, and similar state laws • For judicial or administrative proceedings Personal information we collect from employees: We ask people seeking employment and benefits to provide certain information when they begin employment and enroll in a benefit plan. This information includes but is not limited to: • Name, address, and phone number • Social Security Number • Birth date • Marital status • Information regarding current illnesses, injuries, or disabilities that may affect the ability to perform the job. • Consent to release all applicable information, including physical exam, drug screening and fitness-for- duty results to the company and its agents and service providers How ~~'e protect personal information under federal la~v: Employee personal medical information is maintained in accordance with HIPAA and/or any other state or federal law to protect the privacy of such information. The confidentiality, integrity, and availability of any electronic protected health information (ePHI) will be ensured via appropriate safeguards as specified under HIPAA's security rule beginning on or before the rule's effective date (4/21/06 for small health plans; 4/21/05 for all other covered entities). How we protect personal information under state law: Employee personal medical information is maintained in accordance with state law where such rules are more stringent than, but not contrary to, the federal law to protect the privacy of such information. In general, state laws that are contrary to HIPAA's privacy rule are preempted by the federal requirements, which mean that the federal requirements will apply. The HIPAA privacy rule provides exceptions to the general rule of federal preemption for contrary state laws that require certain health plan reporting, provide greater privacy protections, or provide for the reporting of disease or injury, child abuse, birth, or death. If you want more information on HIPAA as it applies to your personal health information, please contact the owner or an officer of the company or customer service for: Elk River Municipal Utilities Health Care Plan Acknowledgment of receipt: Employee Date HIPAA Privacy Rule Authorization for Release of Health Information I, (Employee Name) protected health information as follows: authorize the specified person(s) to disclose 1. Person authorized to make disclosure: Elk River Municipal Utilities Health Care Plan. 2. Person authorized to receive the disclosed information: Elk River Municipal Utilities. 3. Specific description of the protected health information that may be used or disclosed: 4. I understand that the information received pursuant to this authorization may be disclosed by° the recipient and might lose its protected status. 5. I understand that I may revoke this authorization at any time by giving written notice to (Financial Director) 6. I understand that I am entitled to receive a copy of this authorization. 7. I understand that after this information is disclosed, federal law might not protect it and the recipient might re-disclose it. S. I understand that my initial and continued employment and position are subject to my agreement to this authorization, and any additional authorization Elk River Municipal Utilities requests. 9. I understand that this authorization will expire when my employment with Elk River Municipal Utilities terminates or when I am no longer covered by the company's employee benefits plan or COBRA plan, whichever is later. Signature of Employee: Name: Date: If a Personal Representative executes this form, that Representative warrants that he or she has authority to sign this form on the basis of: (Description of personal representative's authority)