New “HIPAA Compliance Manual for
Small Mental Health Practices in New York State, Second Edition - 2007” just
written by Bruce V. Hillowe J.D., Ph.D. The book contains all the instructions,
checklists and forms needed for compliance with all of the HIPAA Rules i.e., the
Privacy Rule and the newer Security and Transaction Rules.
Bruce V. Hillowe, J.D., Ph.D.
is a healthcare and mental health attorney with a law practice in Mineola,
New York. A graduate of Binghamton University, Duke University School of Law,
and Adelphi University Institute of Advanced Psychological, he formerly
practiced as a psychologist-psychoanalyst, including as a coordinator of
clinical training and director of a forensic mental health service. He was a
teaching attending psychologist in law and ethics at a major teaching hospital
for 15 years. He is currently legal counsel to numerous mental health
facilities, institutes, and practitioners and sponsors legal plans for
professional associations. He has written articles and book chapters including
for law reviews and healthcare publications. He is listed in the
Martindale-Hubbell Bar Register of Preeminent Lawyers™ in healthcare law.
The 2003 edition of the Manual addressed compliance only with the then newly
established Privacy Rule. Compliance with the Privacy Rule is not the same as
compliance with the newer Security Rule. The new Manual contains an essential
HIPAA Security Standards Matrix in order for compliance with the Security Rule
to be established and maintained. The Manual is designed to be an accurate,
simple, and cost-effective compliance system especially for psychotherapy
practices.
The new edition of the Manual also contains as supplements basic record-keeping
templates for psychotherapists (Intake and Treatment Planning form, Progress
Note, Consultation Note and Termination Summary) and informed consent forms for
individual, child, couple and family, and group therapy. Finally, a CD-ROM (pdf
file) containing the entire Manual is included with this new edition.
Even practitioners who are not HIPAA compliant will find much of the information
and many of the forms useful; HIPAA has established new standards of care for
the privacy and security of patient health information that are relevant for all
practitioners.
Table of Contents
FAQ’s: Introduction and
Instructions
HIPAA Checklists
Physical and Operational Safeguards
Administrative Systems and Technical Procedures
Privacy-Security Officer and Staff Policies
Primary HIPAA Documentation
HIPAA Policy and Procedures Handbook
- Protected
Health Information: Use and Disclosure
- PHI and
EPHI Defined
- Related
Definitions
- Related
Exclusion
- Use or
Disclosure Without Patient Authorization, TPH
- Use of
Disclosure Without Patient Authorization, By Law
- Obtaining
Written Patient Authorization
- Special
Handling of Psychotherapy Notes, HIV Information
- Special
Authorizations, Psychotherapy Notes, HIV, Alcohol
- Special
Authorization, Disclosures to Attorneys
- Personal
Notes and Observations
- The Minimum
Necessary Standard
- Mitigation
of Harmful Effects of Violations
- Record of
Disclosures
-
Confidentiality Notices
- Patient Rights
- Notice of
Privacy Practices
- Requests
for Restrictions on Use
- Requests
for Means of Confidential Communication
- Access to
Medical Records and Exceptions
- Right to
Amend Record
- Right to
Accounting of Disclosures
- No
Retaliatory Actions or Waivers
- The
Privacy-Security Officer and Staff Training
- Administrative,
Physical and Technical Safeguards
- Safeguards of PHI
- Safeguards of EPHI
- Business
Associate Agreement
- Complaint
Procedures
- Documentation
and Record Retention
Form 1. Authorization Form (HIPAA)
Form 2. Authorization for Release of HIV Information (NYSDOH-AIDS Institute)
Form 3. Authorization Form (HIPAA/Alcohol-Substance Abuse)
Form 4. Authorization Form, Disclosures to Attorneys (OCA 960)
Form 5. Record of Disclosures of PHI
Form 6. Fax Cover Letter
Form 7. Confidentiality Notices for Mail and Email
Form 8. Additional Notice for HIV Information
Form 9. Notice of Privacy Practices
Form 10. Acknowledgment of Receipt of Notice of Privacy Practices
Form 11. Patient Request for Confidential Communications
Form 12. Denial of Access to Patient Information and Appeal Form
Form 13. Patient Request for Accounting of Disclosures
Form 14. HIPAA Security Standards Matrix
Form 15. Business Associate Agreement
Form 16. Staff Training Record Sheet
Form 17. Employee Acknowledgment of HIPAA Policies
Supplement A: Psychotherapy
Record-Keeping Forms
Intake and Treatment
Planning
Progress Note
Consultation Note
Termination of Treatment Summary
Supplement B: Informed
Consent Forms
Individual Psychotherapy
Child Psychotherapy
Couple or Family Psychotherapy
Group Psychotherapy