FDOH Information And Privacy Awareness Training Learner .

3y ago
120 Views
6 Downloads
2.00 MB
47 Pages
Last View : 9d ago
Last Download : 3m ago
Upload by : Callan Shouse
Transcription

Florida Department of HealthFDOH Information and PrivacyAwareness TrainingLearner Course GuideDOH Mandatory Training FY 2013-2014To protect, promote & improve the health of all people in Florida through integrated state, county, & community efforts.It's a New Day in Public Health

FDOH Information Security and PrivacyAwareness Training - Learner Course GuideDOH Mandatory TrainingFY 2013-2014It's a New Day in Public HealthTable of ContentsSECTION SLIDE NUMBER - TITLE1PAGESlide 1 – Welcome Slide1Slide 2 – How to Use Navigation1Slide 3 – Section 1 Objectives2Slide 4 – Section 1 Objectives2Slide 5 – Federal and State Policies and Regulations3Slide 6 – What is HIPAA?3Slide 7 – What are the specific HIPAA rules?4Slide 8 – What are the specific HIPAA rules?4Slide 9 – Federal and State Policies and Regulations5Slide 10 – Federal and State Policies and Regulations5Slide 11 – Florida Public Records Act, Chapter 119.07, F.S.6Slide 12 – Florida Public Records Act6Slide 13 – Enterprise Security of Data and Information Technology Act, Chapter282.318, F.S.7Slide 14 – Enterprise Security of Data and Information Technology Act7iFDOH Information and Privacy Awareness Training - Learner Course GuidePowered by DOH Office of Performance & Quality Improvement

FDOH Information Security and PrivacyAwareness Training - Learner Course GuideDOH Mandatory TrainingFY 2013-2014It's a New Day in Public HealthSECTION SLIDE NUMBER – TITLE1PAGESlide 15 – Enterprise Security of Data and Information Technology Act8Slide 16 – Florida Computer Crimes Act, Chapter 815 F.S.8Slide 17 – DOH Information Security and Privacy Policy9Slide 18 – DOH Information Security and Privacy9Slide 19 – Information Security and Privacy Section10Slide 20 – Data Classification Section10Slide 21 – Designation of Security and Privacy Personnel Section11Slide 22 – Designation of Security and Privacy Personnel Section11Slide 23 – Designation of Security and Privacy Personnel Section12Slide 24 – End Slide Section 112iiFDOH Information and Privacy Awareness Training - Learner Course GuidePowered by DOH Office of Performance & Quality Improvement

FDOH Information Security and PrivacyAwareness Training - Learner Course GuideDOH Mandatory TrainingFY 2013-2014It's a New Day in Public HealthTable of ContentsSECTION SLIDE NUMBER - TITLE2PAGESlide 1 – Welcome Slide13Slide 2 – How to Use Navigation13Slide 3 – Section 2 Objectives14Slide 4 – DOH Information Security and Privacy Policy14Slide 5 – Acceptable Use and Confidentiality Agreement Section15Slide 6 – Acceptable Use and Confidentiality Agreement Section15Slide 7 – Acceptable Use and Confidentiality Agreement Section16Slide 8 – Acceptable Use &Confidentiality Agreement Section16Slide 9 – Acceptable Use & Confidentiality Agreement Section17Slide 10 – Acceptable Use & Confidentiality Agreement Section17Slide 11 – Acceptable Use & Confidentiality Agreement Section18Slide 12 – Acceptable Use & Confidentiality Agreement Section18Slide 13 – Security and Privacy Awareness Training Section19Slide 14 – Secured Areas and Physical Security Procedures Section19iiiFDOH Information and Privacy Awareness Training - Learner Course GuidePowered by DOH Office of Performance & Quality Improvement

FDOH Information Security and PrivacyAwareness Training - Learner Course GuideDOH Mandatory TrainingFY 2013-2014It's a New Day in Public HealthSECTION SLIDE NUMBER - TITLE2PAGESlide 15 – Secured Areas & Physical Security Procedures Section20Slide 16 – Secured Areas & Physical Security Procedures Section20Slide 17 – DOH Information Security and Privacy Policy21Slide 18 – Confidential Information Section21Slide 19 – Confidential Information Section22Slide 20 – Confidential Information Section22Slide 21 – Confidential Information Section23Slide 22 – Confidential Information Section23Slide 23 – Confidential Information Section24Slide 24 – Confidential Information Section24Slide 25 – Disclosure of Confidential Information Section25Slide 26 – Disclosure of Confidential Information Section25Slide 27 – Disclosure of Confidential Information Section26Slide 28 – End Slide Section 227ivFDOH Information and Privacy Awareness Training - Learner Course GuidePowered by DOH Office of Performance & Quality Improvement

FDOH Information Security and PrivacyAwareness Training - Learner Course GuideDOH Mandatory TrainingFY 2013-2014It's a New Day in Public HealthTable of ContentsSECTION SLIDE NUMBER - TITLE3PAGESlide 1 – Welcome Slide28Slide 2 – How to Use Navigation28Slide 3 – Section 3 Objectives29Slide 4 – DOH Information Security and Privacy Policy29Slide 5 – Patient Privacy Rights Section30Slide 6 – Patient Privacy Rights Section30Slide 7 – Patient Privacy Rights Section31Slide 8 – Patient Privacy Rights Section31Slide 9 – Patient Privacy Rights Section32Slide 10 – Patient Privacy Rights Section32Slide 11 – Patient Privacy Rights Section33Slide 12 – Public Health HIPAA Exemptions Section33Slide 13 – Public Health HIPAA Exemptions Section34Slide 14 – Public Health HIPAA Exemptions Section34vFDOH Information and Privacy Awareness Training - Learner Course GuidePowered by DOH Office of Performance & Quality Improvement

FDOH Information Security and PrivacyAwareness Training - Learner Course GuideDOH Mandatory TrainingFY 2013-2014It's a New Day in Public HealthSECTION SLIDE NUMBER - TITLE3PAGESlide 15 – Public Health HIPAA Exemptions Section35Slide 16 – Contract Providers and Business Associates Section35Slide 17 – DOH Information Security and Privacy Policy36Slide 18 – Retention, Archiving and Disposition of Records Section36Slide 19 – Retention, Archiving and Disposition of Records Section37Slide 20 – Risk Analysis Section37Slide 21 – Contingency Planning Section38Slide 22 – Contingency Planning Section: Continuity of Operations forInformation Technology Pans – COOP-IT Plan38Slide 23 – Information Resource Management Security Section39Slide 24 – Have Questions?39Slide 25 – End Slide40viFDOH Information and Privacy Awareness Training - Learner Course GuidePowered by DOH Office of Performance & Quality Improvement

FDOH Information Security and PrivacyAwareness Training - Learner Course GuideDOH Mandatory TrainingFY 2013-2014It's a New Day in Public HealthSection 1Slide 1 – Welcome SlideDOH Mandatory Training FY2013-2014INFORMATION SECURITY &PRIVACY AWARENESSTRAININGWelcome to the Florida Department of Health’sInformation Security and Privacy AwarenessTraining - Section 1.In this section, we will explain the importance ofinformation security and privacy awareness inorder for you to be aware of the rules andregulations and to act accordingly based on theserules.Section 1To protect, promote and improve the health of all people in Florida through integrated state, county, and community efforts.Slide 2 – How to Use NavigationIn order to make your training experience as easy aspossible during the course of this self-paced DOHMandatory Training course, we are providing thesenavigation instructions.When a slide pauses you can do one of three thingsto advance the presentation:You may click directly on the slide with your cursorYou may click on the PLAY button on the bottom leftof the screenorYou may click on the FORWARD button, alsolocated on the bottom left of the screen.If you need to review a previous slide you may clickthe BACK button on the bottom left of the screen.Please keep these instructions in mind as youproceed with this training. You will need to advancethe slide now.1FDOH Information and Privacy Awareness Training - Learner Course GuidePowered by DOH Office of Performance & Quality Improvement

FDOH Information Security and PrivacyAwareness Training - Learner Course GuideDOH Mandatory TrainingFY 2013-2014It's a New Day in Public HealthSlide 3 – Section 1 ObjectivesSection 1 ObjectivesRecognize HIPAA rules, the federal & state rules,& regulations related to information security &privacy:1.Public Records Act 119.07, F.S.2.Enterprise Security of Data & Information TechnologyAct Chapter 282.318, F.S.3.Florida Computer Crimes Act Chapter 815, F.S.Upon completion of this section, you will be able torecognize HIPAA rules, the federal and state rules,and regulations related to information security andprivacy, such as1. The Public Records Act, Chapter 119.07,Florida Statute, and2. The Enterprise Security of Data andInformation Technology Act, Chapter282.318, Florida Statute, and3. The Florida Computer Crimes Act, Chapter815, Florida StatuteDOH Mandatory Training FY2013-2014Slide 4 – Section 1 ObjectivesSection 1 ObjectivesIdentify DOH Information Security & Privacy PolicySections:1.Information Security & Privacy2.Data Classification3.Designation of Key Security & Privacy PersonnelYou will also be able to identify the followingsections of the Department of Health’s InformationSecurity and Privacy policy:1. Information Security and Privacy2. Data Classification and3. Designation of Key Security and PrivacyPersonnelDOH Mandatory Training FY2013-20142FDOH Information and Privacy Awareness Training - Learner Course GuidePowered by DOH Office of Performance & Quality Improvement

FDOH Information Security and PrivacyAwareness Training - Learner Course GuideDOH Mandatory TrainingFY 2013-2014It's a New Day in Public HealthSlide 5 – Federal and State Policies and RegulationsFederal & State Policies &RegulationsThis first section will give you a general idea about theFederal and State, Information Security and Privacypolicy, statutes and regulations. We will answer thesethree questions: What is HIPAA? What are the specific HIPAA rules?What is HIPAA?What are the specific HIPAA rules? andWhat are the Federal and State InformationSecurity and Privacy policy statutes andregulations? What are the Federal & StateInformation Security & Privacy policystatutes & regulations?DOH Mandatory Training FY2013-2014Slide 6 – What is HIPAA?What is HIPAA?Health Insurance Portability & AccountabilityAct, Public Law 104-191 Establishes standards to improve the efficiency &effectiveness of the country’s health care systemHIPAA is the acronym for the Health InsurancePortability and Accountability Act. It establishesstandards to improve the efficiency andeffectiveness of the country’s health care system.HIPAA applies such practices to all health careproviders in the United States and strengthenspenalties for violations. Applies such practices to all health care providers in theUnited States Strengthens penalties for violationsDOH Mandatory Training FY2013-20143FDOH Information and Privacy Awareness Training - Learner Course GuidePowered by DOH Office of Performance & Quality Improvement

FDOH Information Security and PrivacyAwareness Training - Learner Course GuideDOH Mandatory TrainingFY 2013-2014It's a New Day in Public HealthSlide 7 – What are the specific HIPAA rules?What are the specific HIPAArules?HIPAA Security Rule Sets national standards for the security of protectedhealth informationThere are only two HIPAA rules, and they guide DOHinformation security and privacy. The first is the HIPAASecurity Rule. It sets national standards for the security ofprotected health information. The second is the HIPAAPrivacy Rule. It protects the privacy of individuallyidentifiable health information.HIPAA Privacy Rule Protects the privacy of individually identifiable healthinformationDOH Mandatory Training FY2013-2014Slide 8 – What are the specific HIPAA rules?What are the specific HIPAArules?HIPAA Privacy Rule Sets boundaries on use & release of health records Holds people accountable if they violate patient rights Provides complaint mechanism for non-compliance Safeguards protected health information (PHI) forindividually identifiable health informationThe HIPAA Privacy Rule sets boundaries on the useand release of health records. It is designed to holdpeople accountable if they violate patient rights. Thisrule provides complaint mechanisms for noncompliance and safeguards protected healthinformation (PHI) that refers to individuallyidentifiable health information.All employees must comply with HIPAA. You canget more information from the U.S. Department ofHealth & Human Services.All employees must comply with HIPAA rulesDOH Mandatory Training FY2013-20144FDOH Information and Privacy Awareness Training - Learner Course GuidePowered by DOH Office of Performance & Quality Improvement

FDOH Information Security and PrivacyAwareness Training - Learner Course GuideDOH Mandatory TrainingFY 2013-2014It's a New Day in Public HealthSlide 9 – Federal and State Policies and RegulationsFederal & State Policies &Regulations Public Law 111-5 - The American Recovery &Reinvestment Act of 2009 Title 45 Code of Federal Regulations - Federal lawgoverning the operations & existence of the Department Chapter 119.07, F.S. - Defines a public record, thepublic’s right of access, retention requirements &exceptions to the ruleThe Department’s Information Security and Privacy Policyis governed by a number of federal and state rules,statutes and regulations. All employees should be familiarwith this legislation.We will list some of these rules and regulations, and thenexplain the more important ones specifically. The rules,statutes, and regulations include, but are not limited, to thefollowing: Chapter 282.318, F.S. - Establishes Department’sinformation security program & requirements DOH Mandatory Training FY2013-2014 Public Law 111-5, The American Recovery andReinvestment Act of 2009Title 45 Code of Federal Regulations is thefederal law governing the operations andexistence of the Department of Health through theDepartment of Health and Human ServicesChapter 119.07, Florida Statute, which defines apublic record, the public’s right of access,retention requirements and the exceptions to therule andChapter 282.318, Florida Statute, whichestablishes the Department’s information securityprogram and requirementsSlide 10 – Federal and State Policies and RegulationsFederal & State Policies &Regulations F.A.C. 60DD - Rules concerning the State TechnologyOffice Chapter 815, F.S. – defines Florida Computer CrimesAct & the penalties for violation of this act. This chapterprohibits: Introduction of fraudulent records into a computer systemUnauthorized use of computer facilitiesAlteration or destruction of computerized informationStealing of data from computer filesDOH Mandatory Training FY2013-2014Florida Administrative Code 60DD is the ruleestablished by the Department of ManagementServices concerning the State Technology Office;and finally,Chapter 815, Florida Statute, which defines theFlorida Computer Crimes Act and the penalties forviolation of this act. It prohibits the introduction offraudulent records into a computer system, theunauthorized use of computer facilities, thealteration, or destruction of computerized informationand the stealing of data from computer files.Members of the DOH workforce who have access toa work computer and confidential information shouldbe familiar with these policies.5FDOH Information and Privacy Awareness Training - Learner Course GuidePowered by DOH Office of Performance & Quality Improvement

FDOH Information Security and PrivacyAwareness Training - Learner Course GuideDOH Mandatory TrainingFY 2013-2014It's a New Day in Public HealthSlide 11 – Florida Public Records Act, Chapter 119.07, F.S.Florida Public Records ActChapter 119.07, F.S. All state, county & municipal records are openfor personal inspection & copying by any person Each agency is responsible for providing accessto public recordsAll DOH employees must comply with thisActLet’s look at each rule and regulation in order tocomprehend the basics. We will start with the FloridaPublic Records Act, Chapter 119.07, Florida Statute.Chapter 119.07, Florida Statute, states that all state,county and municipal records are open for personalinspection and copying by any person, and each agency isresponsible for providing access to public records. AllDOH employees must comply with the Florida PublicRecords Act.DOH Mandatory Training FY2013-2014Slide 12 – Florida Public Records ActFlorida Public Records ActWhat records are & are not exempt frompublic disclosure? Refer to: Public Records Request Policy, DOHP 30-1The Public Records Act allows that some publicrecords are exempt from disclosure. In order todetermine which records are and are not exemptfrom public disclosure, you can use the followingresources: DOH Employee Handbook Health Information Management Training Guidelines The Public Records Request Policy, DOHP30-1The DOH Employee Handbook andThe Health Information ManagementTraining GuidelinesDOH Mandatory Training FY2013-20146FDOH Information and Privacy Awareness Training - Learner Course GuidePowered by DOH Office of Performance & Quality Improvement

FDOH Information Security and PrivacyAwareness Training - Learner Course GuideDOH Mandatory TrainingFY 2013-2014It's a New Day in Public HealthSlide 13 – Enterprise Security of Data and Information Technology Act, Chapter 282.318, F.S.Enterprise Security of Data &Information Technology Act,Chapter 282.318, F.S.The State Technology Office: Consults with each state agency head Is responsible & accountable for assuring adequate levelof security for all agency data & information technologyresourcesThe next statute we will cover is the Enterprise Security ofData and Information Technology Act, Chapter 282.318,Florida Statute. Information resources are valuable assetsof the state and as such should be managed effectively.The Enterprise Security of Data and InformationTechnology Act states that the State Technology Office, inconsultation with each state agency head, is responsibleand accountable for assuring an adequate level of securityfor all data and information technology resources of eachagency.DOH Mandatory Training FY2013-2014Slide 14 – Enterprise Security of Data and Information Technology ActEnterprise Security of Data &Information Technology ActEach agency is responsible for the following:Under the Enterprise Security of Data andInformation Technology Act, each agency isresponsible for the following: Designate an information security manager Conduct & update a comprehensive risk analysis Develop & update written internal policies & procedures DOH Mandatory Training FY2013-2014Designation of an information securitymanager, who shall administer the agencysecurity programConduct and update a comprehensive riskanalysis to determine the security threats tothe data and information technologyresources andTo develop and update written internalpolicies and procedures to assure thesecurity of agency resources7FDOH Information and Privacy Awareness Training - Learner Course GuidePowered by DOH Office of Performance & Quality Improvement

FDOH Information Security and PrivacyAwareness Training - Learner Course GuideDOH Mandatory TrainingFY 2013-2014It's a New Day in Public HealthSlide 15 – Enterprise Security of Data and Information Technology ActEnterprise Security of Data &Information Technology ActAdditional agency responsibilities under the EnterpriseSecurity of Data and Information Technology Act are to:Additional Agency responsibilities: Implement appropriate cost-effective safeguards Ensure that periodic internal audits & evaluations of thesecurity program Include appropriate security requirements in writtenspecifications for procuring resources & services Implement appropriate cost-effective safeguardsto reduce, eliminate, or recover from the identifiedrisksEnsure that periodic internal audits andevaluations of the security program are conductedInclude appropriate security requirements inwritten specifications for the solicitation andprocuring of information technology resources andservicesDOH Mandatory Training FY2013-2014Slide 16 – Florida Computer Crimes Act, Chapter 815, Florida StatuteFlorida Computer Crimes ActChapter 815, F.S.The Florida Computer Crimes Act, Chapter 815,Florida Statute, prohibits the followin

ii It's a New Day in Public Health DOH Mandatory Training FY 2013-2014 FDOH Information Security and Privacy Awareness Training - Learner Course Guide

Related Documents:

FDOH Medical Errors: A Public Health Perspective Learner Course Guide Medical Errors: A Public Health Perspective Office of Performance and Quality Improvement Public Health Practice, Provider 50 -712 Julie A. D. Tindall, MSN, RN 2 Continuing Education Credit Hours To Protect, promote an

2018 Cause Awareness Day Calendar January Alzheimer’s Disease Awareness Month Cervical Health Awareness Month Dry January National Blood Donor Month National Glaucoma Awareness Month Thyroid Awareness Month 8-14 – Obesity Awareness Week 11 – National Human Trafficking Awareness

1 Disability Related Awareness Dates JANUARY January is Awareness Month For: Co-dependency Awareness Month - (U.S.) Glaucoma Awareness Month - (U.S.) Weight Loss Awareness Month Awareness Days in January: January 4 - World Braille Day

U.S. Department of the Interior PRIVACY IMPACT ASSESSMENT Introduction The Department of the Interior requires PIAs to be conducted and maintained on all IT systems whether already in existence, in development or undergoing modification in order to adequately evaluate privacy risks, ensure the protection of privacy information, and consider privacy

marketplace activities and some prominent examples of consumer backlash. Based on knowledge-testing and attitudinal survey work, we suggest that Westin’s approach actually segments two recognizable privacy groups: the “privacy resilient” and the “privacy vulnerable.” We then trace the contours of a more usable

The DHS Privacy Office Guide to Implementing Privacy 4 The mission of the DHS Privacy Office is to preserve and enhance privacy protections for

Why should I use a 3M privacy filter (compared to other brands or switchable privacy)? When it comes to protecting your data, don't compromise, use the best in class "black out" privacy filters from 3M. Ŕ Zone of privacy, protection from just 30-degree either side for best in class security against visual hackers

sharpen your reading comprehension Do the Level A practice exer cises and score your results Review the answers and explanations for all Level A questions When you have mastered Level A exercises, progress to Levels B and C It’s Your Path to a Higher Test Score Choose Barron’s Method for Success on the SAT’s Critical Reading Sections ISBN-13: 978-0-7641-3381-7 EAN 14.99 Canada 21.99 .