<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:video="http://www.google.com/schemas/sitemap-video/1.1">
  <url>
    <loc>https://www.prohipaa.com/training/video/hipaa-breaches-violations-and-penalties</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3542.mp4      </video:content_loc>
      <video:title>
HIPAA Violations and Penalties      </video:title>
      <video:description>
In this lesson, we'll cover HIPAA violations and penalties, how penalty amounts are calculated, the role of a Book of Evidence, and a practical example of addressing workstation security risks. HIPAA Penalties &amp;amp; Financial Impacts Since HIPAA enforcement began, penalties have become increasingly common. Penalty amounts depend directly on the seriousness of the violation and the organization's level of responsibility, ranging from around ten thousand dollars to millions of dollars. As of mid-2026, the largest HIPAA settlement on record remains the 2018 Anthem case at $16 million, which followed the largest healthcare data breach in history.  Pro Tip #1: The Book of Evidence: It is critical for covered entities to maintain written policies and procedures, known as a Book of Evidence. Not only is this a legal requirement under HIPAA, but it protects your organization in the event of a breach, violation, or audit.  Workstation Security &amp;amp; Password Protection As demonstrated in the office scenario, managing passwords properly is an essential part of complying with HIPAA security policies. Displaying passwords on sticky notes attached to computer monitors or placing them under keyboards creates an immediate security risk.  Password Security Standards You are required by law to use a password to access PHI, and passwords must be secure and complex. Avoid placing password notes around your workstation or under your keyboard, as these are the very first places unauthorized individuals look when attempting to gain system access.   Pro Tip #2: Addressing Compliance Issues: Privacy officers and team leaders should address security violations promptly and constructively, helping staff implement secure alternatives to keep all systems protected.       </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6327/hipaa-breaches-violations-and-penalties.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
100      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/video/why-cybercriminals-want-phi</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3543.mp4      </video:content_loc>
      <video:title>
Why Cybercriminals Want PHI      </video:title>
      <video:description>
In this lesson, we review why cybercriminals target PHI and ePHI, the financial value of medical records on the dark web, common threat vectors like ransomware and phishing, and how to respond if you receive a suspicious email.  Pop Quiz: Handling Suspicious Emails Question: You just received a strange-looking or unfamiliar email in your inbox. What should you do?  A) Do not open the email B) Delete the email or mark it as junk C) Immediately notify your manager, privacy officer, or IT team D) All of the above   Reveal Correct Answer  Correct Answer: D) All of the above You should never open a suspicious email, always remove or report it, and promptly notify your manager or privacy officer to protect your entire organization.   The Value of PHI on the Dark Web Healthcare is consistently one of the most targeted and costly sectors for data breaches, with hundreds of millions of records exposed in major incidents such as the Change Healthcare breach. Medical records are significantly more valuable to cybercriminals than stolen financial data due to their permanence and versatility:  Financial Data (Credit Cards): Stolen credit card numbers have a limited lifespan and are only useful until the victim cancels the card or account. A stolen card might only sell for a few dollars. Medical Records (PHI): Information contained in medical records does not change, even if compromised. Complete medical records can sell for hundreds of dollars on the dark web, allowing cybercriminals to commit long-term identity theft and fraud.   Pro Tip #1: Because healthcare data retains its value indefinitely and faces constant threats, healthcare professionals and business associates must actively protect PHI and ePHI at all times.  Common Platforms for Electronic Attacks Cybercriminals use multiple delivery methods and platforms to launch ransomware and distribute malware into healthcare networks:  Business Applications &amp;amp; Cloud Services USB Drives: Exercise extreme caution with USB drives, as they are frequently used across multiple locations and can easily transmit infections. Social Media &amp;amp; Website Attachments Email Attachments &amp;amp; Phishing: Phishing emails remain a primary vector for network breaches.   Handling Suspicious Emails If you receive a suspicious or unfamiliar email, NEVER click links or open attachments. Clicking an unverified attachment can immediately trigger a malware infection or data breach. Use the "Report Phishing" button in your email client to flag it for IT, and promptly alert your office manager and Privacy Officer.   Pro Tip #2: Prompt Reporting Protects Everyone: In the office scenario, Nurse Joy did the right thing by avoiding the unfamiliar email and notifying her team immediately. Reporting suspicious activity right away helps safeguard your entire organization from potential security incidents.       </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6329/why-cybercriminals-want-phi.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
168      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/video/hipaa-social-media-mobile-devices-email-and-faxes</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3544.mp4      </video:content_loc>
      <video:title>
HIPAA and Social Media, Mobile Devices, Email and Faxes      </video:title>
      <video:description>
In this lesson, we'll cover how HIPAA applies to electronic Protected Health Information (ePHI) across modern communication channels, including social media, mobile devices, email platforms, and faxes. HIPAA Law &amp;amp; Social Media HIPAA covers all electronic Protected Health Information across all social media platforms, including Facebook, X, Snapchat, and Instagram. Never disclose a patient's name, treatment, or identifiable health details on any social media network under any circumstance.  Personal Liability &amp;amp; Social Media Disclosures Disclosing PHI on social media platforms carries severe risks. Individuals can be held personally liable both financially and criminally for posting protected health information on social channels.  Mobile Devices &amp;amp; Encryption Requirements Mobile devices include smartphones, tablets, and laptops. While mobile devices can be used to share PHI, strict technical safeguards must be in place first:  Encrypted Messaging Required: You must use a dedicated, encrypted texting or chatting platform to transmit PHI. Standard SMS &amp;amp; Messaging Risks: Standard messaging platforms lack sufficient encryption, store data on unapproved third-party servers, and are not HIPAA-compliant.  Email Platforms &amp;amp; Business Associate Agreements Free consumer email services should never be used to send or store PHI because consumer providers generally refuse to sign a Business Associate Agreement (BAA), which is legally required to handle protected data. Organizations must use paid enterprise email platforms (such as Google Workspace or Microsoft 365) properly configured for HIPAA compliance and supported by a signed BAA.  Pro Tip: The Cost of Insecure Email: Unsecured email communications lead to major regulatory penalties. In 2019, Solara Medical Supplies agreed to a $3 million OCR settlement following an email breach that exposed over 114,000 patient records.  Fax Machine &amp;amp; eFax Compliance Faxes remain an approved and compliant method for transmitting PHI, provided essential security protocols are followed:  Cover Sheets: Always use a HIPAA-compliant cover sheet before sending PHI through a physical fax machine or eFax service. Erroneous Faxes Sent: If PHI is faxed in error, contact the recipient immediately and instruct them to destroy the transmitted information. Erroneous Faxes Received: If you receive PHI in error, notify the sender right away and destroy the document immediately.  Guidelines for Properly Disposing of PHI So what do you do if you do receive PHI in error or no longer need access to it?&amp;nbsp; Disposing of PHI is of the utmost importance, particularly in our modern digital world where deleted files and posts are rarely ever completely gone. Following these PHI disposal guidelines will help ensure you and your organization remain HIPAA compliant. Click each guideline to learn more about proper disposal protocols:  1. Shredding Hard Copies  Shred all hard copies containing Protected Health Information (PHI) when the copies are no longer needed.   2. Recycling Paper Records  Place hard copies designated for recycling into locked recycle bins whenever available.   3. Deleting Digital Files (Soft Copies)  Delete all soft copy files containing PHI from your workstation computer and local server once the information is no longer required within your record retention requirements.   4. Destroying Removable Media  Physically destroy all disks, CDs, and external media drives that contained PHI prior to disposal.   5. Sanitizing Reusable Media  Do not reuse disks, CDs, or storage drives that previously contained PHI without thoroughly sanitizing them first.   6. Equipment Transfer &amp;amp; IT Protocol  Contact your IT department before transporting or transferring hardware. IT must follow proper procedures to move equipment and sanitize hard drives and storage media.   7. Contractual Returns  Return PHI directly to the original sender if this requirement is stipulated in any contractual agreements.        </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6331/hipaa-social-media-mobile-devices-email-and-faxes.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
113      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/video/hipaa-foundation-conclusion</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3546.mp4      </video:content_loc>
      <video:title>
HIPAA Foundation Conclusion      </video:title>
      <video:description>
In this final lesson, we recap what you have learned throughout your HIPAA course, highlighting key requirements for covered entities and business associates, the value of PHI, and next steps for maintaining organizational compliance. HIPAA &amp;amp; HITECH Foundation Review Both covered entities and business associates share the legal responsibility to safeguard Protected Health Information (PHI) at all times. Because business associates handle critical data, covered entities must ensure that all third-party vendors are trusted partners committed to protecting health information.  Pro Tip #1: Protecting Your Practice's Legacy: Complete medical records can sell for hundreds of dollars on the dark web, making healthcare a top target for cybercriminals. Actively protecting PHI is essential not only for patient security, but also to protect the legacy, reputation, and financial stability of your business.  Navigating Your HIPAA Compliance Journey Achieving and maintaining compliance is an ongoing process. If you do not feel completely confident in your organization's HIPAA compliance status, engaging a trustworthy compliance partner can help you navigate regulatory requirements effectively.  Pro Tip #2: Need Additional Support? If you need further assistance or a compliance guide to navigate your journey, contact our team at ProTrainings.com or call us at 888-406-7487. We are here to serve you!       </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6335/hipaa-foundation-conclusion.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
75      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/video/privacy-and-security-rules</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3540.mp4      </video:content_loc>
      <video:title>
Privacy and Security Rules      </video:title>
      <video:description>
In this lesson, we're going to cover the HIPAA Privacy Rule and the Security Rule. We'll dig into the three safeguards – administrative, physical, and technical – and include rules and examples for each. The HIPAA Privacy Rule establishes standards for protecting patients' medical records and other protected health information (PHI). It specifies two important things:  What rights patients have over their information and requires covered entities to protect that information. What usage and disclosures are authorized or required.  The privacy and security rules allow healthcare providers to share PHI electronically for treatment purposes as long as they apply reasonable safeguards when doing so. A couple of examples of this would be when a physician consults with another physician by secured email regarding a patient's condition, or when a healthcare provider exchanges PHI through electronic medical records for patient care. Covered entities need to engage in safeguards to protect this information. These safeguards include:  Administrative safeguards Physical safeguards Technical safeguards   Pro Tip #1: All covered entities need to perform risk analyses to determine what measures need to be taken to reduce risks and vulnerabilities to an appropriate level.  Administrative Safeguards Administrative safeguards include office rules and procedures that help keep protected health data secure. To accomplish this, covered entities should designate security officials who are responsible for the following:  Developing and implementing that covered entity's security policies and procedures Determining who should be authorized to access PHI Training all staff in these security policies and procedures Applying the appropriate sanctions against workforce members who violate those policies and procedures Performing periodic risk assessments of how well the security policies and procedures are meeting the requirements of HIPAA's Security Rule  Example of Administrative Safeguard An example of an administrative safeguard would be allowing only office managers to send protected health information in electronic form. Physical Safeguards Physical safeguards under the HIPAA Security Rule include the following:  Limiting physical access to all facilities while also ensuring that only authorized access is allowed Implementing that covered entity's policies and procedures specify the proper use of access to computers and/or the position of screens and monitors in all patient areas Putting into place policies and procedures regarding the physical transfer, removal, disposal, and reuse of all electronic media, such as computer hard drives  Example of Physical Safeguard An example of a physical safeguard would be keeping all patient files in a locked room that only specified and authorized personnel have access to. Technical Safeguards Technical safeguards under the HIPAA Security Rule include the following:  Implementing all hardware, software, and/or procedural mechanisms to record and examine access and other activities in all information systems that contain or use protected health information Implementing policies and procedures to ensure that electronic measures are put in place to confirm that all protected health information is not improperly altered or destroyed Implementing technical security measures that guard against unauthorized access to all PHI that is transmitted over an electronic network  Example of Technical Safeguard A couple of examples of technical safeguards would be using data encryption and also strong passwords to better protect files from unauthorized access.  Pro Tip #2: HIPAA's Privacy Rule gives much-needed flexibility to healthcare providers and plans to create their own privacy policies that are tailored to fit their size and needs. However, no matter the size of the covered entity, whether that entity is a small optometrist office or a large hospital with thousands of employees, each covered entity is required to have a written privacy policy.  In general, all covered entities must do everything they can to secure all patient records that contain personally identifiable information so that information isn't readily available to those people who do not need it. You may recall the list of those 18 PHI identifiers that we provided in the last lesson. Also, covered entities must always release only as much protected health information as is necessary to address the specific needs of the entity that is requesting the information, or what the HIPAA regulation refers to as the minimum amount necessary to satisfy the inquiry. You might also recall from the last lesson, that when it comes to transmitting or sharing protected health information, less is always more.      </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6323/privacy-and-security-rules.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
245      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/video/welcome-to-prohipaa</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3534.mp4      </video:content_loc>
      <video:title>
Welcome to ProHIPAA      </video:title>
      <video:description>
Welcome to your HIPAA compliance training course at ProTrainings! This course is designed for anyone who needs a greater understanding of the importance of safeguarding Protected Health Information (PHI) whether you're a trusted medical professional or a business associate supporting a healthcare organization. In this introductory video, we outline the foundational requirements of HIPAA/HITECH, examine why cybercriminals target healthcare data, and review your legal responsibilities under federal law.  Common Handling Missteps with PHI As demonstrated in the introductory scenario, routine office communications can easily compromise patient privacy if proper protocols are not followed. Always keep the following in mind when handling patient data:  Verbal Disclosures: Avoid stating specific patient names alongside sensitive medical conditions or contact details in open office spaces where unintended listeners can hear. Unencrypted Text Messaging: Texting patient details or care updates to providers over standard SMS is a frequent source of HIPAA violations. Always utilize secure, encrypted communication channels to share Protected Health Information.   What You Will Learn in This Course Throughout this training program, you will gain comprehensive knowledge regarding the current state of HIPAA compliance and your obligations under the law, including:  Why Protected Health Information (PHI) is so valuable to cybercriminals Comprehensive HIPAA and HITECH requirements Real-world data breaches and current industry fines The vital role of encrypted email in daily healthcare operations Your specific legal responsibilities and personal accountability   Pro Tip #1: The primary objective of HIPAA regulations is to establish clear national standards to protect individuals' medical records and other personal health information while facilitating high-quality healthcare delivery.  Course Objectives By completing this ProHIPAA training course, you will be fully prepared to:  Understand and navigate complex government regulations and obligations Evaluate the current state of HIPAA and HITECH standards Properly identify, protect, and handle both physical PHI and electronic PHI (ePHI) in your daily workflow   Pro Tip #2: PHI includes any individually identifiable health information that relates to a patient's physical or mental health condition, the provision of healthcare, or payment for healthcare services. When in doubt, always treat patient data as fully protected!       </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6311/welcome-to-prohipaa.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
104      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/video/what-are-patients-rights-with-phi</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3541.mp4      </video:content_loc>
      <video:title>
What are Patients' Rights with PHI?      </video:title>
      <video:description>
In this lesson, we'll go over patients' rights under HIPAA, what information requires authorization, when patient authorization is not required, and real-world examples you may encounter in practice. Covered Entities and Patients' Rights All covered entities (health plans, healthcare clearinghouses, and healthcare providers transmitting PHI electronically) are required to provide individuals a Notice of Privacy Practices upon request. This notice describes how medical information may be used and disclosed, as well as the process for filing complaints. Patients have several key rights regarding their Protected Health Information (PHI), including:  Record Inspection: The right to inspect and obtain copies of their medical records within 30 days. Record Corrections: The right to request corrections or additions if they believe information is inaccurate or incomplete. Communication Restrictions: The right to ask for restrictions on how their health information is shared or communicated. Accounting of Disclosures: The right to request an accounting of disclosures made outside of routine treatment, payment, and healthcare operations.   Pro Tip #1: Out-of-Pocket Payment Exception: If a patient pays for a healthcare service in full out of pocket, they have the right to require that the provider not share information about that specific service with their health plan.  Patient Authorization Requirements Patient authorization is necessary to disclose an individual's personal health information outside of routine healthcare operations, but written authorization is not required in order to treat the patient.  Pro Tip #2: Treating Without Written Authorization: Healthcare providers often ask if they can see a patient without obtaining written authorization. The answer is yes. However, it is always best practice to update the patient's medical record and note the circumstance.  Sharing PHI Without Patient Authorization There are specific legal exceptions where covered entities may disclose PHI without prior written authorization from the patient or parent:  Workers' Compensation &amp;amp; Public Health: Information can be disclosed as required for workers' compensation claims or valid public health reporting. Imminent Danger &amp;amp; Abuse Reporting: Providers may alert law enforcement or official agencies if there is an imminent danger to the patient or others, or if abuse is suspected. Reporting suspected abuse can save a child's or adult's life. School Healthcare Disclosures: Covered healthcare providers may disclose PHI about students to school nurses or school physicians for treatment purposes without written authorization from the parent or student (e.g., a primary care doctor discussing medication management directly with a school nurse).       </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6325/what-are-patients-rights-with-phi.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
125      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/video/the-history-of-hipaa</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3535.mp4      </video:content_loc>
      <video:title>
The History of HIPAA      </video:title>
      <video:description>
In this lesson, we'll go over the history of HIPAA, what it is, what it covers, the evolution of healthcare data privacy, and the key regulatory updates that shape modern patient protections. The Health Insurance Portability and Accountability Act of 1996 (HIPAA) provides landmark data privacy and security provisions for safeguarding medical information across the United States healthcare system. The Evolution of HIPAA Legislation In the 1990s, with the rapid growth of the internet, Congress recognized the need for a system to enforce patient rights and protect the privacy of medical records. Over time, key updates expanded these safeguards as healthcare technology evolved:  HIPAA Act of 1996: Established national standards for the portability of insurance, protection of health data, efficiency in healthcare, and prevention of fraud. HITECH Act of 2009: Introduced the Health Information Technology for Economic and Clinical Health rule as medical records transitioned to digital systems. Omnibus Rule of 2013: Expanded privacy requirements to technology companies and strengthened security policies enforced by the HHS Office for Civil Rights.   Notice of Privacy Practices Requirements Updates aligning 42 CFR Part 2 with HIPAA tightened protections for substance use disorder records, requiring explicit patient consent prior to disclosure. As a result, healthcare organizations must update, post, and distribute their Notice of Privacy Practices to detail these heightened protections.  What HIPAA Covers HIPAA legislation provides comprehensive data privacy and security provisions for safeguarding medical information, including:  Portability of insurance information between covered entities, providers, and insurance companies Protection and privacy of healthcare information transmitted in electronic form Standardization and efficiency across healthcare data systems Prevention of healthcare discrimination and fraud   Pro Tip: The main objective of HIPAA regulations is to protect individual medical privacy while encouraging efficiency and standardization across covered entities and business associates.       </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6313/the-history-of-hipaa.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
102      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/video/how-to-be-proactive-to-be-hipaa-compliant</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3545.mp4      </video:content_loc>
      <video:title>
How to be Proactive to be HIPAA Compliant      </video:title>
      <video:description>
In this lesson, we're going to look at ways you can reduce the risks to your business as it pertains to data breaches. To this end, we'll show the 3 Pillars of Success that should help eliminate your risks and keep you HIPAA compliant. And at the end of the lesson, we'll provide you with a Word about the duties of a HIPAA compliance officer. There are several common issues we've seen over the years that greatly contribute to you or your organization not being HIPAA compliant, which increases your risk of suffering through a data breach. Those issues include:  Your organization's and staff's understanding of HIPAA and HITECH laws Limited or no training on how to properly handle PHI, including ePHI and oral conversations A lack of risk assessments to help identify your risks to PHI A limited, or no, Book of Evidence that includes your organization's policies and procedures Not using the proper business associate agreements (BAAs) The use of Gmail, Yahoo, MSN, AOL, and other unsecure platforms for the transmission of PHI  So, how can you and your organization be more proactive at reducing your risks and becoming more HIPAA compliant? You can institute what we describe as the 3 Pillars of Success The 3 Pillars of Success The 3 Pillars of Success are:  Risk Assessments A Book of Evidence Compliance Training  Let's look at each of these in more detail. Risk Assessments Your business or organization must perform a regularly scheduled compliance risk assessment. We recommend doing this on at least an annual basis to ensure that all staff understand any changes within your organization and/or business environment that could contribute to it being less secure. A Book of Evidence A Book of Evidence is a basic HIPAA requirement and contains all of your organization's policies and procedures on handling PHI and ePHI, including, among other things, your business continuity plan, data breach plan, and how to handle unauthorized access of protected health information. Compliance Training Compliance training is an essential part of any security plan and ensures that you and your staff understand how to better protect PHI and follow all of your organization's policies and procedures. The human firewall is the best kind of firewall, but it cannot properly function without training and education. The more you and your employees understand the risks involved and how to handle PHI, the better your organization's chances of reducing the risks of data breaches and the subsequent risks to your business. A Word About the Duties of a HIPAA Compliance Officer HIPAA requires that one or more people within a covered entity or business associate is assigned the duties of a HIPAA Compliance Officer. How much work is involved depends on the size of the covered entity or business associate along with the amount of PHI involved. And in smaller organizations, it is often the case that the duties of a HIPAA Compliance Officer are divided between a Privacy Officer and a Security Officer. (Our crystal ball says that we'll be digging into these roles in later lessons.) The typical duties of a HIPAA Compliance Officer include:  Gaining a thorough knowledge of the HIPAA Privacy and Security Rules and the solutions available that will allow him or her to develop a HIPAA compliance program. After developing a HIPAA compliance program, the compliance officer should document progress towards its implementation, which would include creating a system that enables the officer to monitor the status of the organization's HIPAA compliance. That system should allow the officer to prioritize efforts towards compliance and communicate priorities to others in the organization. It should also act as a conduit through which compliance concerns can be raised and organizational changes coordinated. The HIPAA Compliance Officer is responsible for developing training programs and executing training courses. These should be designed to help employees understand HIPAA compliance and how any changes implemented will affect their specific duties. The HIPAA Compliance Officer is also responsible for monitoring the Department of Health &amp;amp; Human Services' and their state's regulatory requirements. When new regulations or guidelines are introduced, the officer must adjust their organization's HIPAA compliance program to reflect those changes.  It's important to understand that HIPAA regulations do not define exactly what the duties of a HIPAA Compliance Officer are. Instead, HIPAA leaves it to each covered entity or business associate to establish their own duties according to their specific requirements. Thus, in order for an organization to effectively establish the duties of a HIPAA Compliance Officer, it is necessary for that organization to first understand what those specific requirements are. And part of that would entail undertaking a risk assessment.      </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6333/how-to-be-proactive-to-be-hipaa-compliant.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
104      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/video/what-is-hipaa</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3933.mp4      </video:content_loc>
      <video:title>
What is HIPAA?      </video:title>
      <video:description>
In this lesson, you'll learn what HIPAA is, the role it plays in healthcare, and who is mandated to follow its requirements, along with relevant real-world examples. What is HIPAA? The federal law known as HIPAA stands for the Health Insurance Portability and Accountability Act of 1996. Congress passed this landmark law to provide the following:  Portability of insurance Protection and privacy of healthcare information Standardization and efficiency in healthcare data Prevention of discrimination and fraud  What is HIPAA's Role in Healthcare? HIPAA gives the U.S. Department of Health and Human Services the responsibility of adopting rules to help individuals and companies keep important personal health information private. HIPAA protects against unauthorized disclosure of any protected health information (PHI) that pertains to healthcare patients. It establishes a national set of security standards for protecting health information held or transferred in electronic form (ePHI). In addition to privacy and security, administrative provisions were included to improve system efficiency, including:  Specific transaction standards and code sets National standard unique identifiers Data security and electronic signatures   Pro Tip #1: HIPAA compliance is highly dependent on the size, function, administration, and type of entity or business associate. Therefore, this training module is not intended to be a complete or comprehensive guide to HIPAA compliance.   Legal Compliance Disclaimer Entities and business associates regulated by the Privacy and Security Rules are obligated to comply with all federal and state requirements and should not rely on this training alone as a source of legal information or advice. To ensure compliance, covered entities and business associates should regularly perform risk assessments to track access to PHI, periodically evaluate security effectiveness, and re-evaluate potential risks.  Who is Mandated to Follow HIPAA's Requirements? HIPAA law applies directly to two particular groups: Covered Entities and Business Associates. What is a Covered Entity? Covered Entities are health plans, healthcare clearinghouses, and healthcare providers that transmit PHI electronically in connection with a covered transaction. (Note: Simply holding PHI does not by itself make an entity a covered entity.)  Healthcare Providers: Any provider of medical or health services, or any organization or person who transmits health information electronically in the normal course of business (e.g., physicians, nurses, dentists, hospitals, pharmacies, ambulance companies, social workers). Health Plans: Any individual or group plan that provides or pays the cost of healthcare, such as an insurance company, Medicare, or Medicaid. Healthcare Clearinghouses: A public or private entity that transforms healthcare transactions from one format into a required format (e.g., an outside billing service).   Pro Tip #2: HIPAA applies to employers only to the extent that they operate in one or more of these three groups. If a company offers healthcare services on-site (such as an on-site clinic), the employer would be considered a covered entity and required to follow HIPAA rules.  What is a Business Associate? A business associate is any company or individual with access to Protected Health Information (PHI) or ePHI. Examples include IT vendors, laboratories, call centers, court reporters, cloud providers, and legal services. Business associates are required to maintain a risk assessment, training, policies, and procedures. They must also safeguard PHI at all times, notify covered entities of any data breaches, and execute a Business Associate Agreement (BAA).  Contractual &amp;amp; Regulatory Violations If a business associate violates HIPAA, they are not only in violation of their contract with the covered entity, but also in violation of federal HIPAA law itself and will be held accountable for penalties under both. Furthermore, if a business associate uses subcontractors, contractual agreements (BAAs) are required to hold those subcontractors to the exact same standards.       </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/7075/what-is-hipaa-new.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
320      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/video/hipaa-breach-notification-requirements</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/7666.mp4      </video:content_loc>
      <video:title>
HIPAA Breach Notification Requirements      </video:title>
      <video:description>
In this lesson, we'll go over what happens when PHI is lost, inappropriately shared, or stolen, and review the key requirements outlined in the Breach Notification Rule. What is the Breach Notification Rule? The Breach Notification Rule sets clear standards for how organizations must handle potential compromises of Protected Health Information (PHI). If PHI was used or disclosed in a manner not permitted under HIPAA, it is presumed to be a breach unless a thorough risk assessment demonstrates a low probability that the data was actually compromised.  Pro Tip: Your Primary Role as an Employee: Your job is simple: if you know of or suspect a possible breach, report it immediately to your supervisor and privacy officer within the timeframe and guidelines established by your organization's policies.  Breach Notification Requirements &amp;amp; Timelines Once an incident is determined to be a breach, your organization must follow specific reporting protocols based on the scope and size of the breach:  Affected Individuals: Must be notified without unreasonable delay, and no later than 60 days after the breach is discovered. Large Breaches (500+ Individuals): Must be reported to the Department of Health and Human Services (HHS) at the same time affected individuals are notified, as well as to prominent local media outlets in the affected area. Smaller Breaches (Fewer than 500 Individuals): Must be logged and reported to HHS no later than 60 days after the end of the calendar year in which the breach was discovered.   State Laws and Faster Deadlines The federal 60-day notification window is an absolute outer limit. Many state laws mandate much faster reporting deadlines for security incidents, so organizations must always verify and adhere to the specific privacy rules in the states where affected individuals reside.       </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/13932/hipaa-breach-notification-requirements.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
80      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/video/important-hipaa-terminology</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3537.mp4      </video:content_loc>
      <video:title>
Important HIPAA Terminology      </video:title>
      <video:description>
In this lesson, we will go through some essential HIPAA definitions and core terms to help you better understand the law, including encryption standards, business associate liabilities, and risk assessment structures. Key HIPAA Terms &amp;amp; Definitions  HIPAA: Health Insurance Portability and Accountability Act of 1996. HITECH: Health Information Technology for Economic and Clinical Health Act of 2009. HITECH promotes the adoption and meaningful use of health IT while significantly expanding HIPAA privacy rules and security standards. PHI (Protected Health Information): Any personal health information that identifies or pertains to a patient. ePHI (Electronic Protected Health Information): Personal health information stored or transmitted electronically, including faxes, emails, cloud providers, data backups, patient portals, removable media, and secure texting.   Encryption &amp;amp; "Reasonable and Appropriate" Standards All ePHI should be encrypted at rest and in transit wherever reasonable and appropriate. "Reasonable and appropriate" is not a matter of opinion; it refers to what a careful organization of your size, resources, and risk level would do to protect data. If encryption is not feasible, the reason must be documented and an equivalent safeguard implemented instead.  Business Associate Requirements A Business Associate is any individual or entity that supports the healthcare industry and performs functions on behalf of a covered entity. Under HITECH regulations, business associates must comply directly with HITECH rules and assume financial liability for data breaches caused by their organization or employees. Business associates are required to maintain:  Formal Risk Assessments Employee Training Programs A customized Book of Evidence (policies and procedures)  Understanding Risk Assessments A Risk Assessment consists of government-mandated questions to identify potential security gaps and risk levels. It requires a corresponding risk report featuring a clear roadmap to resolution. Questionnaires cover three main domains (Administrative, Technical, and Physical) and utilize three implementation levels:  Standard: Measures compliance to ensure confidentiality, integrity, and availability of ePHI. Required: Mandatory implementation for all covered entities and business associates. Addressable: Provides operational flexibility based on risk level. However, addressable does not mean optional; organizations must apply appropriate security measures to manage the risk.   Pro Tip #1: A Book of Evidence is your customized set of written policies and procedures explaining how your organization manages PHI and ePHI, including data breach notification protocols, disaster recovery, and privacy policies.   Pro Tip #2: Covered entities must provide patients with a copy of their Privacy Policy upon request. Business associates must make their privacy policies available to internal employees, downstream suppliers, and government auditors.       </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6317/important-hipaa-terminology.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
244      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/video/what-is-protected-health-information</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3539.mp4      </video:content_loc>
      <video:title>
What is PHI?      </video:title>
      <video:description>
In this lesson, we'll be going into some detail on what PHI is. At the end of the lesson, we'll dig into when PHI really isn't PHI, or in other words, exceptions to PHI. In a nutshell, PHI (protected health information) is any information that is individual to a patient – past, present, or future – about the care provided, whether physical or mental, for an individual. This can include documentation of doctor visits, charts and notes made by physicians and other healthcare staff, healthcare payment information, claim status, and the coordination of healthcare benefits.  Pro Tip #1: It's worth noting that HIPAA covers all forms of PHI, including electronic, paper, and even oral/spoken. Many people forget that PHI is also covered under spoken word. Be especially mindful when disclosing healthcare-related information with anyone – other patients, staff, and business associates.  You may recall from the corresponding video for this lesson that one patient overheard two healthcare employees talking about another patient's health information. When in doubt, always assume that someone might be listening. And do everything you can to make sure private conversations take place in private locations. Think of PHI the way you would classified information. You have been given clearance to see it. But it's your responsibility to keep it safe and from falling into the wrong hands at all times. A More In-Depth Look at PHI Under HIPAA rules and regulations, PHI is considered as any identifiable health information that is used, maintained, stored, or transmitted by covered entities and business associates. As mentioned above, PHI is health information in any form, including physical records, electronic records, or spoken information. This means that PHI includes health records, health histories, lab test results, and medical bills.  Pro Tip #2: The key point to remember regarding PHI, is that to be considered PHI, it must include individual identifiers, such as patient names, social security numbers, driver's license numbers, insurance details, and birth dates, when they are linked with health information. Demographic information can also be considered PHI under HIPAA Rules.  There are in total 18 identifiers for PHI and these include the following:  Names Dates, except year Telephone numbers Geographic data Fax numbers Social security numbers Email addresses Medical record numbers Account numbers Health plan beneficiary numbers Certificate/license numbers Vehicle identifiers and serial numbers including license plates Web URLs Device identifiers and serial numbers Internet protocol addresses Full face photos and comparable images Biometric identifiers, such as retinal scans and fingerprints Any unique identifying number or code  Can PHI be Disclosed for Public Health Activities? The short answer is, yes. However, it's limited to the CDC (Center for Disease Control and Prevention), public health authorities – federal or state – and OSHA. OSHA is unique because it can request information without authorization or the need to sign a business association agreement.  Pro Tip #3: One caveat to remember, though, is that covered entities should reasonably limit the amount of PHI given in these circumstances to what is considered a necessary amount and nothing more. Remember, less is more when it comes to sharing personal health information.  So, why would OSHA request PHI? They could do so in the event of a natural disaster or a state of emergency in an attempt to determine the demographics of an affected area. Perhaps they need to mobilize the national guard, first responders, or military personnel to aid such an emergency. It's important to remember, that if contacted by someone in the government about sharing PHI, you must ensure their legitimacy. Request relevant phone numbers and email addresses and ask for a written request. A Word About the Exceptions to PHI You may be tempted to think that all health information is considered PHI under HIPAA, but this isn't true, and there are some exceptions. One determining factor is who records the information. A good example of this would be health trackers, such as physical devices worn on the body or apps on mobile phones. These devices can record health information such as heart rate or blood pressure, which would be considered PHI under HIPAA rules if the information was recorded by a healthcare provider or was used by a health plan. However, under the HIPAA rules, this information only applies to HIPAA covered entities and their business associates. This means that if a device manufacturer or app developer hasn't been contracted by a HIPAA covered entity and also isn't a business associate, the information recorded would not be considered PHI under HIPAA rules. The same rules apply to education or employment records. Let's say a hospital holds data on its employees, which can include some health information like allergies or blood types. However, HIPAA rules do not apply to this type of information. Also, it's important to remember that under HIPAA, PHI ceases to be PHI if it's stripped of all identifiers listed above that can tie the information to an individual. When those identifiers are removed, the health information is technically referred to as de-identified PHI, and thus, HIPAA rules no longer apply.      </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6321/what-is-protected-health-information.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
259      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/video/who-is-required-to-comply-with-hipaa-laws</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3536.mp4      </video:content_loc>
      <video:title>
Who is required to comply with HIPAA laws?      </video:title>
      <video:description>
In this lesson, we'll go over who is required to comply with HIPAA laws and the two key groups the law directly applies to: covered entities and business associates. Who Must Comply with HIPAA Laws? HIPAA applies directly to two main groups that handle, transmit, or support operations involving Protected Health Information (PHI):  Covered Entities: Include health plans, healthcare clearinghouses, and healthcare providers that transmit PHI electronically in connection with a covered transaction. Business Associates: Perform services for covered entities and require direct or incidental access to PHI in support of business operations.  What is a Covered Entity? A covered entity is any provider of medical or other health services, or an organization that handles PHI. Key examples include:  Healthcare Providers: Physicians, nurses, hospitals, clinics, and allied health professionals. Health Plans: Any individual or group plan that provides or pays the cost of healthcare, such as an HMO, insurance company, Medicaid, or Medicare. Billing &amp;amp; Payment Entities: Organizations and individuals that provide billing services or receive payment in connection with healthcare services in the normal course of business.   Pro Tip #1: Repetition is a key part of mastering HIPAA standards. While you may notice some overlap with previous lessons on general HIPAA guidelines, reinforcing these core definitions ensures clear compliance across your organization.  What is a Business Associate? A business associate is any company or individual with direct or incidental access to PHI or ePHI while supporting a covered entity. Business associates must maintain strict operational safeguards, often documented in what is known as a book of evidence. Examples of business associates include:  IT vendors Call centers Court reporters Cloud providers Legal services providers Suppliers and manufacturers with access to PHI and ePHI   Business Associate Requirements &amp;amp; Breach Reporting Business associates are held to strict standards under HIPAA law. They are required to maintain risk assessments, employee training, and formal policies and procedures. Furthermore, business associates are legally required to notify covered entities of any potential or active data breaches to ensure PHI is protected at all times.   Pro Tip #2: Business associates must sign a formal Business Associate Agreement (BAA) with covered entities before gaining access to PHI. This contract legally binds them to safeguard patient information under federal law.       </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6315/who-is-required-to-comply-with-hipaa-laws.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
97      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/video/what-is-a-covered-entity</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3538.mp4      </video:content_loc>
      <video:title>
What is a Covered Entity?      </video:title>
      <video:description>
In this lesson, we'll go over the basics of covered entities, including what covered entities are, common examples across the healthcare industry, and the core requirements all covered entities share. What is a Covered Entity? As a reminder, a covered entity is one of three things: a health plan, a healthcare clearinghouse, or a healthcare provider that transmits Protected Health Information (PHI) electronically in connection with a covered transaction. Common examples of covered entities include:  Doctors, dentists, and nurses Social workers Laboratories and pharmacies Durable medical equipment providers Hospitals and ambulance companies   Call Centers: Covered Entity vs. Business Associate Call centers present a unique caveat under HIPAA regulations based on ownership and operations:  Owned &amp;amp; Operated by a Covered Entity: Must follow HIPAA regulations as a covered entity. Third-Party Call Center: If handling PHI on behalf of a covered entity, they must follow HIPAA regulations as a business associate.   Compliance Requirements for Covered Entities All covered entities are legally required to comply with HIPAA regulations to ensure patient data remains protected. Every covered entity must maintain:  Risk Assessment: A comprehensive evaluation to identify potential vulnerabilities and risk gaps. Staff Compliance Training: Ongoing education to ensure employees properly handle and protect PHI. Book of Evidence: A customized set of written policies and procedures explaining how the organization handles and safeguards PHI.   Pro Tip #1: The defining characteristic of all covered entities is that they directly handle or transmit PHI electronically in connection with healthcare transactions. When evaluating an organization, always look at how data is transmitted to determine regulatory status.  A Word About the Differences Between Covered Entities &amp;amp; Business Associates First, let's define what a business associate is. What is a Business Associate? A business associate is any business or person that provides a service for a covered entity, or a certain function or activity, when that service, function or activity involves the access to PHI that is maintained by the covered entity. Examples of business associates include, but aren't limited to:  Lawyers Accountants IT contractors Billing companies Cloud storage services Email encryption services  The key phrase from above that really defines a business associate is this: the access to PHI that is maintained by the covered entity.  Pro Tip #2: So, what is the Difference? Covered entities have PHI (protected health information) while business associates merely have access to PHI. It's a bit of an ambiguous distinction, but an important distinction, nonetheless.       </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6319/what-is-a-covered-entity.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
62      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/leaders/video/welcome-to-prohipaa</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3534.mp4      </video:content_loc>
      <video:title>
Welcome to ProHIPAA      </video:title>
      <video:description>
Welcome to your HIPAA compliance training course at ProTrainings! This course is designed for anyone who needs a greater understanding of the importance of safeguarding Protected Health Information (PHI) whether you're a trusted medical professional or a business associate supporting a healthcare organization. In this introductory video, we outline the foundational requirements of HIPAA/HITECH, examine why cybercriminals target healthcare data, and review your legal responsibilities under federal law.  Common Handling Missteps with PHI As demonstrated in the introductory scenario, routine office communications can easily compromise patient privacy if proper protocols are not followed. Always keep the following in mind when handling patient data:  Verbal Disclosures: Avoid stating specific patient names alongside sensitive medical conditions or contact details in open office spaces where unintended listeners can hear. Unencrypted Text Messaging: Texting patient details or care updates to providers over standard SMS is a frequent source of HIPAA violations. Always utilize secure, encrypted communication channels to share Protected Health Information.   What You Will Learn in This Course Throughout this training program, you will gain comprehensive knowledge regarding the current state of HIPAA compliance and your obligations under the law, including:  Why Protected Health Information (PHI) is so valuable to cybercriminals Comprehensive HIPAA and HITECH requirements Real-world data breaches and current industry fines The vital role of encrypted email in daily healthcare operations Your specific legal responsibilities and personal accountability   Pro Tip #1: The primary objective of HIPAA regulations is to establish clear national standards to protect individuals' medical records and other personal health information while facilitating high-quality healthcare delivery.  Course Objectives By completing this ProHIPAA training course, you will be fully prepared to:  Understand and navigate complex government regulations and obligations Evaluate the current state of HIPAA and HITECH standards Properly identify, protect, and handle both physical PHI and electronic PHI (ePHI) in your daily workflow   Pro Tip #2: PHI includes any individually identifiable health information that relates to a patient's physical or mental health condition, the provision of healthcare, or payment for healthcare services. When in doubt, always treat patient data as fully protected!       </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6311/welcome-to-prohipaa.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
104      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/leaders/video/what-are-patients-rights-with-phi</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3541.mp4      </video:content_loc>
      <video:title>
What are Patients' Rights with PHI?      </video:title>
      <video:description>
In this lesson, we'll go over patients' rights under HIPAA, what information requires authorization, when patient authorization is not required, and real-world examples you may encounter in practice. Covered Entities and Patients' Rights All covered entities (health plans, healthcare clearinghouses, and healthcare providers transmitting PHI electronically) are required to provide individuals a Notice of Privacy Practices upon request. This notice describes how medical information may be used and disclosed, as well as the process for filing complaints. Patients have several key rights regarding their Protected Health Information (PHI), including:  Record Inspection: The right to inspect and obtain copies of their medical records within 30 days. Record Corrections: The right to request corrections or additions if they believe information is inaccurate or incomplete. Communication Restrictions: The right to ask for restrictions on how their health information is shared or communicated. Accounting of Disclosures: The right to request an accounting of disclosures made outside of routine treatment, payment, and healthcare operations.   Pro Tip #1: Out-of-Pocket Payment Exception: If a patient pays for a healthcare service in full out of pocket, they have the right to require that the provider not share information about that specific service with their health plan.  Patient Authorization Requirements Patient authorization is necessary to disclose an individual's personal health information outside of routine healthcare operations, but written authorization is not required in order to treat the patient.  Pro Tip #2: Treating Without Written Authorization: Healthcare providers often ask if they can see a patient without obtaining written authorization. The answer is yes. However, it is always best practice to update the patient's medical record and note the circumstance.  Sharing PHI Without Patient Authorization There are specific legal exceptions where covered entities may disclose PHI without prior written authorization from the patient or parent:  Workers' Compensation &amp;amp; Public Health: Information can be disclosed as required for workers' compensation claims or valid public health reporting. Imminent Danger &amp;amp; Abuse Reporting: Providers may alert law enforcement or official agencies if there is an imminent danger to the patient or others, or if abuse is suspected. Reporting suspected abuse can save a child's or adult's life. School Healthcare Disclosures: Covered healthcare providers may disclose PHI about students to school nurses or school physicians for treatment purposes without written authorization from the parent or student (e.g., a primary care doctor discussing medication management directly with a school nurse).       </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6325/what-are-patients-rights-with-phi.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
125      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/leaders/video/welcome-to-prohipaa-for-leaders</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3547.mp4      </video:content_loc>
      <video:title>
Welcome to ProHIPAA for Leaders      </video:title>
      <video:description>
Welcome to the ProHIPAA for Leaders course. If you've just taken the General HIPAA course, you likely have a solid foundation on HIPAA already. In this introductory lesson, we'll be going over what you can expect to learn in this course and what your course objective will be. And at the end of the lesson, we'll provide you with a Word about HIPAA Privacy Officers and HIPAA Security Officers. If your business or organization is in the healthcare industry and works as a covered entity or business associate, you're required to have annual HIPAA compliance training for you and your staff. You're also required to conduct periodic risk assessments and have a Book of Evidence on hand that outlines your practice or organization's policies and procedures. In the course, you'll learn about what it takes to be an effective privacy officer, compliance officer, and trusted business associate. What You Can Expect to Learn In your ProHIPAA for Leaders course, you'll learn the following:  Why risk assessments are required About the HITECH Act of 2009 About the Omnibus Rule of 2013 About the importance of customized policies and procedures to create your Book of Evidence Why business associate agreements are required About the types of violations we often see in the healthcare industry today Why you – as a compliance officer or privacy officer – are key to ensuring your business or organization becomes compliant How to handle complaints and audits from the Office for Civil Rights or attorneys  Your Course Objective The objective of ProHIPAA for Leaders is to train you on how to properly handle PHI, ePHI, and a data breach. Or better yet, how to reduce your chances of a data breach. A Word About HIPAA Privacy Officers and HIPAA Security Officers If you just completed the General HIPAA course at ProHIPAA, you may recall some additional information on the duties of a HIPAA Compliance Officer. You might also remember how those duties can be handled by one person or shared – in smaller organizations and businesses – with the person (or people) responsible for privacy and security duties. In this Word, we're going to look at duties for both HIPAA Privacy Officers and HIPAA Security Officers for larger businesses and organizations that have one or more people in each of those positions. HIPAA Privacy Officer A HIPAA Privacy Officer is responsible for developing a privacy program that is HIPAA compliant if one doesn't already exist. Or, if your business already has a privacy program in place, a privacy officer is in charge of ensuring that all privacy policies to protect the integrity of PHI are enforced. Among the duties of a HIPAA Privacy Officer are:  Overseeing or developing ongoing employee privacy training Conducting risk assessments Developing HIPAA compliant procedures where necessary Monitoring compliance with the privacy program Investigating incidents in which a breach of PHI may have occurred Reporting breaches as necessary Ensuring patients' rights in accordance with state and federal laws  In order to fulfill the duties of a HIPAA Privacy Officer, the appointed person will have to keep up to date with relevant state and federal laws. HIPAA Security Officer The duties of a HIPAA Security Officer are quite similar to those of a privacy officer, but with a security focus rather than privacy. The appointed person will be responsible for:  Developing security policies Implementing procedures, training, and risk assessments Monitoring compliance of the security policies  However, the focus of a HIPAA Security Officer is compliance with the Administrative, Physical, and Technical Safeguards of the Security Rule. In this respect, the duties of a HIPAA Security Officer can include such diverse topics as the development of a Disaster Recovery Plan – the mechanisms in place to prevent unauthorized access to PHI, and how ePHI is transmitted and stored. Due to how similar these duties are, the roles of a HIPAA Privacy Officer and HIPAA Security Officer are often performed by the same person in smaller organizations and businesses. And in even smaller businesses, one person could be in charge of handling the duties of a HIPAA Compliance Officer as well.      </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6337/welcome-to-prohipaa-leadership.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
120      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/leaders/video/hipaa-leadership-conclusion</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3559.mp4      </video:content_loc>
      <video:title>
Conclusion      </video:title>
      <video:description>
In this lesson, we'll simply be recapping what you've learned in your ProHIPAA course and at the end, make you an offer that is perhaps too good to pass up. In this course, you've learned what the HIPAA and HITECH laws are, who manages the laws, and who is required to comply. You've learned about covered entities, business associates, and more about PHI than you probably thought possible, and for very good reasons as you now know.  Pro Tip: It's important to note that both covered entities and business associates share in the responsibility to protect personal health information at all times. If you are a covered entity doing all you can to be HIPAA compliant, but you're working with a business associate who isn't, this still poses a significant problem, as all it takes is one weak link in the chain.  For this reason, it's important for all covered entities to ensure that each of their business associates is a trusted partner, has their best interest in mind at all times, and more importantly, is committed to protecting the health data of all of your customers and/or patients. In this course, you've also learned what the value of PHI is on the black market ($700 when part of a larger identity package) and why cybercriminals want PHI. We've looked a little into areas where PHI can be compromised and even a few recent instances in which PHI was compromised. It's critical to always protect PHI, not only for the safety and security of your customers and patients, but also for the legacy and operational integrity of your own business or organization. A data breach isn't just costly in terms of fines. It's also costly in terms of reputation and possible future revenue losses. Through this leadership course, you've also learned about the responsibilities of a HIPAA Privacy Officer, a HIPAA Security Officer, and business associates. You've learned about the importance of business associate agreements (BAAs), why you are required to have regularly scheduled risk assessments, and why you need a customized Book of Evidence that includes all of your policies and procedures. Knowing that Your Organization is HIPAA Compliant – Priceless! If you don't feel confident in your business or organization's ability to become or remain HIPAA compliant, it pays to engage a trustworthy HIPAA compliance partner who can guide you through your HIPAA compliance journey. Even though you've now learned what it takes to become HIPAA compliant, you may still need help getting there. And you certainly have a better understanding of the damage that could occur if your business or organization isn't compliant and suffers a data breach. If you ever feel like you need further assistance, as in a HIPAA compliance guide who can navigate you through those muddy waters, contact us ProHIPAA.com or call us at 844-722-8898 to schedule your complimentary risk review. Thank you again for choosing ProHIPAA. We are honored to help you become (and stay) HIPAA compliant. We look forward to serving you again in the future, because your legacy matters.      </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6361/hipaa-leadership-conclusion.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
120      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/leaders/video/proper-transportation-of-phi-and-ephi</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3548.mp4      </video:content_loc>
      <video:title>
Proper Transportation of PHI and ePHI      </video:title>
      <video:description>
In this lesson, we're going to show you how NOT to transport PHI (aka: explain a little more about common sense). And at the end of the lesson, we're going to take a look at healthcare data breach statistics, which clearly show why lessons like this are important. You probably recall from the corresponding video for this lesson, that nurse Joy decided to go into a grocery store and leave patient records, along with her computer, in plain sight …. and with her windows down and her doors presumably unlocked. It probably wasn't much of a shock to you when someone came along and took it all easily right through her open window. This is poor security! Nurse Joy didn't properly secure the PHI, ePHI, or even her computer. You could use this example when training your staff about properly securing PHI. And while this all may seem a bit too much like an abuse of common sense, there have no doubt been numerous real-life incidents just like this, only with better acting. Quiz: What should nurse Joy have done differently? a) Rolled up her windowsb) Locked her car doorsc) Placed the PHI and her computer out of sightd) All of the above If you chose D, you are correct! If you need to transport medical records or mobile devices that contain PHI, make sure to do all of the above to keep it secure. However, just taking PHI off-premises could also be a no-no, and therefore must be documented in your policies and procedures, along with secure means of transporting personal health information if it is allowed. A Word About Healthcare Data Breach Statistics Healthcare data breach statistics clearly show that there has been an upward trend in data breaches over the past nine years, with 2018 seeing more data breaches reported than any other year since records first started being published in 2009.  Warning: The prevalence of this problem is a bit shocking.  Between 2009 and 2018 there have been 2546 healthcare data breaches involving more than 500 records. Those breaches have resulted in the theft/exposure of 189,945,874 healthcare records. That equates to more than 59% of the population of the United States. Healthcare data breaches are now being reported at a rate of more than one per day. There has been a general upward trend in the number of records exposed each year, with a massive increase in 2015. This was far and away the worst year in history for breached healthcare records with more than 113.27 million records exposed. The best year was 2012, with just 2,808,042 healthcare records exposed. The good news is that the situation has improved since 2015 with successive decreases in the number of exposed records. Although that trend did not continue in 2018. The number of exposed records more than doubled from 5,138,179 records in 2017 to 13,236,569 records in 2018. However, that is still far lower than those outrageous 2015 statistics. The Largest Healthcare Data Breaches To understand how enormous this problem is, let's look at the three largest healthcare breaches to date, all of which occurred in 2015. All three were caused by a hacking or IT incident. And all three covered entities involved were health plans.    1. Anthem Inc. 78,800,000 individuals affected   2. Premera Blue Cross 11,000,000 individuals affected   3. Excellus Health Plan Inc. 10,000,000 individuals affected    That's three incidents affecting 100 million people, or roughly 30 percent of the U.S. population. And all three occurring in the same year. Hacking is the Leading Cause Data breach statistics show hacking is now the leading cause of healthcare data breaches, although it should be noted that healthcare organizations are now much better at detecting hacking incidents. The low hacking/IT incidents in earlier years could be partially due to the failure to detect hacking incidents and malware infections quickly. Many of the hacking incidents between 2014 and 2018 occurred many months, and in some cases years, before they were detected. Hacking isn't the Only Cause As with hacking, healthcare organizations are getting better at detecting internal breaches and also reporting those breaches to the Office for Civil Rights. While hacking is the main cause of breaches, unauthorized access/disclosure incidents are not far behind. Healthcare data breach statistics show HIPAA covered entities and business associates have got significantly better at protecting healthcare records with administrative, physical, and technical controls such as encryption. Although unencrypted laptops and other electronic devices are still being left unsecured in vehicles and locations accessible by the public. Many of these theft/loss incidents involve paper records, which can equally result in the exposure of large amounts of patient information. Yes, the video example for this lesson seems extraordinarily laughable, and yet, this actually happens. Just because you have more sense than that, it would be unwise to assume all the employees in your business or organization share that uncommon sense. Which is why lessons like this still must exist.      </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6339/proper-transportation-of-phi-and-ephi.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
110      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/leaders/video/the-history-of-hipaa</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3535.mp4      </video:content_loc>
      <video:title>
The History of HIPAA      </video:title>
      <video:description>
In this lesson, we'll go over the history of HIPAA, what it is, what it covers, the evolution of healthcare data privacy, and the key regulatory updates that shape modern patient protections. The Health Insurance Portability and Accountability Act of 1996 (HIPAA) provides landmark data privacy and security provisions for safeguarding medical information across the United States healthcare system. The Evolution of HIPAA Legislation In the 1990s, with the rapid growth of the internet, Congress recognized the need for a system to enforce patient rights and protect the privacy of medical records. Over time, key updates expanded these safeguards as healthcare technology evolved:  HIPAA Act of 1996: Established national standards for the portability of insurance, protection of health data, efficiency in healthcare, and prevention of fraud. HITECH Act of 2009: Introduced the Health Information Technology for Economic and Clinical Health rule as medical records transitioned to digital systems. Omnibus Rule of 2013: Expanded privacy requirements to technology companies and strengthened security policies enforced by the HHS Office for Civil Rights.   Notice of Privacy Practices Requirements Updates aligning 42 CFR Part 2 with HIPAA tightened protections for substance use disorder records, requiring explicit patient consent prior to disclosure. As a result, healthcare organizations must update, post, and distribute their Notice of Privacy Practices to detail these heightened protections.  What HIPAA Covers HIPAA legislation provides comprehensive data privacy and security provisions for safeguarding medical information, including:  Portability of insurance information between covered entities, providers, and insurance companies Protection and privacy of healthcare information transmitted in electronic form Standardization and efficiency across healthcare data systems Prevention of healthcare discrimination and fraud   Pro Tip: The main objective of HIPAA regulations is to protect individual medical privacy while encouraging efficiency and standardization across covered entities and business associates.       </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6313/the-history-of-hipaa.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
102      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/leaders/video/what-is-a-risk-assessment</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3551.mp4      </video:content_loc>
      <video:title>
What is a Risk Assessment?      </video:title>
      <video:description>
In this lesson, we'll be going over what a risk assessment is, the purpose of risk assessments, and the benefits of having one regularly. At the end of the lesson, we'll provide you with a Word about what a HIPAA risk assessment should consist of. A risk assessment is a process that helps your business or organization identify any potential risks and analyze what could happen if a breach or mishandling of PHI or ePHI occurs. Risk assessments are required by the Office for Civil Rights. To become compliant, you must attest to 100 questions that the OCR provides. By conducting a thorough risk assessment, you should have a better idea of the amount of a risk your business or organization has, along with your exposure of all protected health information. Pro Tip #1: The important thing to remember is that all covered entities and business associates are required by law to conduct a risk assessment. The goals of doing a risk assessment are understanding your vulnerabilities if any exist and the potential of a data breach. A risk assessment can help identify areas where you can better secure all types of patient health data, from ePHI to paper charts. Pro Tip #2: All covered entities and business associates must also produce a risk report from the risk assessment. The risk report should detail the level of the risk and a remediation plan to resolve any and all risks to PHI and ePHI. ProHIPAA recommends that all covered entities and business associates conduct an annual risk assessment to comply with all regulations and determine your level of risk from year to year. This yearly approach to risk assessments will help ensure that any changes in your business or organization haven't affected the security of the protected health information of your patients or customers. A Word About What a HIPAA Risk Assessment Should Consist Of The U.S. Department of Health and Human Services (HHS) acknowledges that there is no specific risk analysis methodology. This may be due to covered entities and business associates varying significantly in size, complexity, and capabilities. However, HHS does provide an objective of a HIPAA risk assessment – to identify potential risks and vulnerabilities to the confidentiality, availability, and integrity of all PHI that an organization creates, receives, maintains, or transmits. In order to achieve these objectives, the HHS suggests an organization should:  Identify where PHI is stored, received, maintained, or transmitted Identify and document all potential threats and vulnerabilities Assess current security measures that are currently in place to safeguard PHI Assess whether the current security measures are being used properly Determine the likelihood of a reasonably anticipated threat Determine the potential impact of a data breach involving PHI Assign risk levels for vulnerability and impact combinations Document the risk assessment and take action where necessary  A HIPAA risk assessment is not a one time or singular exercise. Assessments should be reviewed periodically, and as new work practices are implemented, or new technology is introduced. HHS does not provide guidance on the frequency of reviews other than to suggest they may be conducted annually depending on an organization´s circumstances. Do You Need a HIPAA Privacy Risk Assessment? Due to the requirement for business associates to conduct risk assessments being introduced in an amendment to the HIPAA Security Rule, many covered entities and Business Associates overlook the necessity to conduct a HIPAA privacy risk assessment. A HIPAA privacy risk assessment is equally as important as a security risk assessment but can be a much larger undertaking depending on the size of the organization and the nature of its business. In order to complete a HIPAA privacy risk assessment, an organization should appoint a privacy officer who can identify organizational workflows and get a big picture view of how the HIPAA Privacy Rule will impact the organization's operations. Thereafter the privacy officer needs to map the flow of PHI both internally and externally in order to conduct a gap analysis to identify where breaches may occur. The final stage of a HIPAA privacy risk assessment should be the development and implementation of a HIPAA privacy compliance program. The program should include policies to address the risks to PHI identified in the HIPAA privacy risk assessment and should be reviewed as suggested by the HHS as new work practices are implemented or new technology is introduced.      </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6345/what-is-a-risk-assessment.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
82      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/leaders/video/hipaa-social-media-mobile-devices-email-and-faxes</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3544.mp4      </video:content_loc>
      <video:title>
HIPAA and Social Media, Mobile Devices, Email and Faxes      </video:title>
      <video:description>
In this lesson, we'll cover how HIPAA applies to electronic Protected Health Information (ePHI) across modern communication channels, including social media, mobile devices, email platforms, and faxes. HIPAA Law &amp;amp; Social Media HIPAA covers all electronic Protected Health Information across all social media platforms, including Facebook, X, Snapchat, and Instagram. Never disclose a patient's name, treatment, or identifiable health details on any social media network under any circumstance.  Personal Liability &amp;amp; Social Media Disclosures Disclosing PHI on social media platforms carries severe risks. Individuals can be held personally liable both financially and criminally for posting protected health information on social channels.  Mobile Devices &amp;amp; Encryption Requirements Mobile devices include smartphones, tablets, and laptops. While mobile devices can be used to share PHI, strict technical safeguards must be in place first:  Encrypted Messaging Required: You must use a dedicated, encrypted texting or chatting platform to transmit PHI. Standard SMS &amp;amp; Messaging Risks: Standard messaging platforms lack sufficient encryption, store data on unapproved third-party servers, and are not HIPAA-compliant.  Email Platforms &amp;amp; Business Associate Agreements Free consumer email services should never be used to send or store PHI because consumer providers generally refuse to sign a Business Associate Agreement (BAA), which is legally required to handle protected data. Organizations must use paid enterprise email platforms (such as Google Workspace or Microsoft 365) properly configured for HIPAA compliance and supported by a signed BAA.  Pro Tip: The Cost of Insecure Email: Unsecured email communications lead to major regulatory penalties. In 2019, Solara Medical Supplies agreed to a $3 million OCR settlement following an email breach that exposed over 114,000 patient records.  Fax Machine &amp;amp; eFax Compliance Faxes remain an approved and compliant method for transmitting PHI, provided essential security protocols are followed:  Cover Sheets: Always use a HIPAA-compliant cover sheet before sending PHI through a physical fax machine or eFax service. Erroneous Faxes Sent: If PHI is faxed in error, contact the recipient immediately and instruct them to destroy the transmitted information. Erroneous Faxes Received: If you receive PHI in error, notify the sender right away and destroy the document immediately.  Guidelines for Properly Disposing of PHI So what do you do if you do receive PHI in error or no longer need access to it?&amp;nbsp; Disposing of PHI is of the utmost importance, particularly in our modern digital world where deleted files and posts are rarely ever completely gone. Following these PHI disposal guidelines will help ensure you and your organization remain HIPAA compliant. Click each guideline to learn more about proper disposal protocols:  1. Shredding Hard Copies  Shred all hard copies containing Protected Health Information (PHI) when the copies are no longer needed.   2. Recycling Paper Records  Place hard copies designated for recycling into locked recycle bins whenever available.   3. Deleting Digital Files (Soft Copies)  Delete all soft copy files containing PHI from your workstation computer and local server once the information is no longer required within your record retention requirements.   4. Destroying Removable Media  Physically destroy all disks, CDs, and external media drives that contained PHI prior to disposal.   5. Sanitizing Reusable Media  Do not reuse disks, CDs, or storage drives that previously contained PHI without thoroughly sanitizing them first.   6. Equipment Transfer &amp;amp; IT Protocol  Contact your IT department before transporting or transferring hardware. IT must follow proper procedures to move equipment and sanitize hard drives and storage media.   7. Contractual Returns  Return PHI directly to the original sender if this requirement is stipulated in any contractual agreements.        </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6331/hipaa-social-media-mobile-devices-email-and-faxes.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
113      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/leaders/video/what-is-hitech</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3550.mp4      </video:content_loc>
      <video:title>
What is HITECH?      </video:title>
      <video:description>
In this lesson, we're going to cover the HITECH Act, including its goals, its importance, and a few details. At the end of the lesson, we're going to provide you with answers to some common business associate agreement questions. The HITECH Act (Health Information Technology for Economic and Clinical Health Act) was introduced during the Obama administration and signed into law on February 17, 2009. The HITECH Act expanded the responsibilities of business associates under the security and privacy rules. Responsibilities and requirements for covered entities and their business associates include:  Providing notification following a breach of unsecured protected health information Limitations on the sale of PHI, marketing, and fundraising communications Stronger individual rights to access electronic medical records Restriction of the disclosure of certain information Only using PHI for proper purposes Protect PHI at all times  The Goals of the HITECH Act The HITECH Act was established to promote and expand the adoption of health information technology, specifically, the use of electronic health records by healthcare providers. The Act also removed some of the loopholes in the HIPAA Act by tightening up the language of HIPAA. This helped to ensure that all business associates were complying with HIPAA Rules, and when health information was compromised, notifications were sent to the affected individuals in a timely manner. Tougher penalties for HIPAA compliance failures were also introduced to add an extra incentive for healthcare organizations and their business associates to comply with the HIPAA Privacy and Security Rules. The Importance of the HITECH Act Prior to the introduction of the HITECH Act, only 10 percent of hospitals had adopted electronic health records. In order to advance healthcare, improve efficiency and care of patients, and make it easier for health information to be shared between different covered entities, electronic health records needed to be adopted. The HITECH Act introduced incentives to encourage hospitals and other healthcare providers to make the change from paper records to electronic records. Had the Act not been passed, there is a good chance that many healthcare providers would still be using paper records today. The HITECH Act also helped to make certain that healthcare organizations and their business associates were complying with the HIPAA Privacy and Security Rules, were implementing safeguards to keep personal health information private and confidential, were restricting the uses and disclosures of health information, and were honoring obligations to provide patients with copies of their medical records upon request. The Act did not make compliance with HIPAA mandatory. That was already a requirement. However, it did make certain that entities found not to be in compliance could be issued substantial fines. Penalties help increase compliance, and sometimes the only language that businesses understand is one that affects the bottom line. Some Common Business Associate Agreement Questions Who does a business associate agreement apply to? Covered entities can be fined for not having a HIPAA business associate agreement in place or for having an incomplete agreement in place. And even if one wasn't in place, business associates are still obligated to comply with the HIPAA Security Rule. However, the issue for many covered entities is they are often unsure who a HIPAA business associate agreement actually applies to. The Department of Health and Human Services defines a business associate as a person or entity that performs certain functions or activities that involve the use or disclosure of protected health information on behalf of, or provides services to, a covered entity, if that helps. However, exclusions to this definition exist and it may be the case that the scope of a covered entity's relationship with a vendor changes over time. As you can see, it's not exactly black and white, or even finite. Can you insist that every contractor sign a BAA? Some covered entities have taken a better-safe-than-sorry approach to address their definition issues and have executed agreements with all entities they have business relationships with. Even when not required. Recent research funded by the California Healthcare Foundation found that many covered entities were entering into agreements with other covered entities unnecessarily and were also entering into agreements with vendors who had no access to PHI and were never likely to. What does access to ePHI include? Many vendors are not given PHI to perform tasks on behalf of the covered entity, but ePHI passes through their systems. Many software solutions touch ePHI which means the software provider is classed as a business associate. There are exceptions for entities that merely act as conduits through which ePHI simply passes, although most cloud service and software providers are not excepted from compliance with HIPAA and BAAs are required. Can I use a business associate agreement template? There are many HIPAA business associate agreement templates available, but care should be taken before they are used. Before using such a template, it's important to check for whom that template has been designed to make sure it's relevant. It should also be personalized to include all of the requirements stipulated by the covered entity.      </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6343/what-is-hitech.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
91      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/leaders/video/what-is-a-business-associate-agreement</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3553.mp4      </video:content_loc>
      <video:title>
What is a Business Associate Agreement?      </video:title>
      <video:description>
In this lesson, we're going to look briefly at what a business associate agreement (BAA) is and what some of the common elements of a BAA are. At the end of the lesson, we'll take a look at some common HIPAA violations. A business associate agreement is a required contract between a covered entity and a business associate who has direct or incidental access to PHI or ePHI. A business associate agreement will contain details on how each entity will be responsible in handling PHI and can include:  Required compliance training A risk assessment Financial liabilities Responsibilities if and when a data breach occurs   Pro Tip: A business associate agreement is required and holds business associates accountable to handle PHI and ePHI securely and safely.  Business associates are required to have:  A risk assessment HIPAA compliance training Policies and procedures, also known as a Book of Evidence  A Word About 10 Common HIPAA Violations The most common HIPAA violations that have resulted in financial penalties are the failure to perform an organization-wide risk analysis to identify risks to the confidentiality, integrity, and availability of protected health information (PHI); the failure to enter into a HIPAA-compliant business associate agreement; impermissible disclosures of PHI; delayed breach notifications; and the failure to safeguard PHI. But before we get into the top 10 list, let's answer a couple of important questions first. Are Data Breaches HIPAA Violations? Data breaches are now a fact of life. Even with multi-layered cybersecurity defenses, data breaches are still likely to occur from time to time. The Office for Civil Rights (OCR) understands that healthcare organizations are being targeted by cybercriminals and that it is not possible to implement impregnable security defenses. Being HIPAA compliant is not about making sure that data breaches never happen. HIPAA compliance is about reducing risk to an appropriate and acceptable level. Just because an organization experiences a data breach, it does not mean the breach was the result of a HIPAA violation. The OCR breach portal now reflects this more clearly. Many data breaches are investigated by OCR and are found not to involve any violations of HIPAA Rules. Consequently, the investigations are closed without any action being taken. How are HIPAA Violations Discovered? HIPAA violations can continue for many months, or even years, before they are discovered. The longer they are allowed to persist, the greater the penalty will be when they are eventually discovered. It is therefore important for HIPAA covered entities to conduct regular HIPAA compliance reviews to make sure HIPAA violations are discovered and corrected before they are identified by regulators. There are three main ways that HIPAA violations are discovered:  Investigations into a data breach by OCR (or state attorneys general). Investigations into complaints about covered entities and business associates. HIPAA compliance audits.  Even when a data breach does not involve a HIPAA violation, or a complaint proves to be unfounded, OCR may uncover unrelated HIPAA violations that could warrant a financial penalty. 10 Most Common HIPAA violations Listed below are 10 of the most common HIPAA violations, together with examples of HIPAA-covered entities and business associates that have been discovered to be in violation of HIPAA Rules and have had to settle those violations with OCR and state attorneys general. In many cases, investigations have uncovered multiple HIPAA violations. In no particular order, the 10 most common HIPAA violations are:  Snooping on healthcare records Failure to perform an organization-wide risk analysis Failure to manage security risks / lack of a risk management process Failure to enter into a HIPAA-compliant business associate agreement Insufficient ePHI access controls Failure to use encryption or an equivalent measure to safeguard ePHI on portable devices Exceeding the 60-day deadline for issuing breach notifications Impermissible disclosures of protected health information Improper disposal of PHI Denying patients access to health records/exceeding timescale for providing access       </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6349/what-is-a-business-associate-agreement.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
54      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/leaders/video/privacy-and-security-rules</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3540.mp4      </video:content_loc>
      <video:title>
Privacy and Security Rules      </video:title>
      <video:description>
In this lesson, we're going to cover the HIPAA Privacy Rule and the Security Rule. We'll dig into the three safeguards – administrative, physical, and technical – and include rules and examples for each. The HIPAA Privacy Rule establishes standards for protecting patients' medical records and other protected health information (PHI). It specifies two important things:  What rights patients have over their information and requires covered entities to protect that information. What usage and disclosures are authorized or required.  The privacy and security rules allow healthcare providers to share PHI electronically for treatment purposes as long as they apply reasonable safeguards when doing so. A couple of examples of this would be when a physician consults with another physician by secured email regarding a patient's condition, or when a healthcare provider exchanges PHI through electronic medical records for patient care. Covered entities need to engage in safeguards to protect this information. These safeguards include:  Administrative safeguards Physical safeguards Technical safeguards   Pro Tip #1: All covered entities need to perform risk analyses to determine what measures need to be taken to reduce risks and vulnerabilities to an appropriate level.  Administrative Safeguards Administrative safeguards include office rules and procedures that help keep protected health data secure. To accomplish this, covered entities should designate security officials who are responsible for the following:  Developing and implementing that covered entity's security policies and procedures Determining who should be authorized to access PHI Training all staff in these security policies and procedures Applying the appropriate sanctions against workforce members who violate those policies and procedures Performing periodic risk assessments of how well the security policies and procedures are meeting the requirements of HIPAA's Security Rule  Example of Administrative Safeguard An example of an administrative safeguard would be allowing only office managers to send protected health information in electronic form. Physical Safeguards Physical safeguards under the HIPAA Security Rule include the following:  Limiting physical access to all facilities while also ensuring that only authorized access is allowed Implementing that covered entity's policies and procedures specify the proper use of access to computers and/or the position of screens and monitors in all patient areas Putting into place policies and procedures regarding the physical transfer, removal, disposal, and reuse of all electronic media, such as computer hard drives  Example of Physical Safeguard An example of a physical safeguard would be keeping all patient files in a locked room that only specified and authorized personnel have access to. Technical Safeguards Technical safeguards under the HIPAA Security Rule include the following:  Implementing all hardware, software, and/or procedural mechanisms to record and examine access and other activities in all information systems that contain or use protected health information Implementing policies and procedures to ensure that electronic measures are put in place to confirm that all protected health information is not improperly altered or destroyed Implementing technical security measures that guard against unauthorized access to all PHI that is transmitted over an electronic network  Example of Technical Safeguard A couple of examples of technical safeguards would be using data encryption and also strong passwords to better protect files from unauthorized access.  Pro Tip #2: HIPAA's Privacy Rule gives much-needed flexibility to healthcare providers and plans to create their own privacy policies that are tailored to fit their size and needs. However, no matter the size of the covered entity, whether that entity is a small optometrist office or a large hospital with thousands of employees, each covered entity is required to have a written privacy policy.  In general, all covered entities must do everything they can to secure all patient records that contain personally identifiable information so that information isn't readily available to those people who do not need it. You may recall the list of those 18 PHI identifiers that we provided in the last lesson. Also, covered entities must always release only as much protected health information as is necessary to address the specific needs of the entity that is requesting the information, or what the HIPAA regulation refers to as the minimum amount necessary to satisfy the inquiry. You might also recall from the last lesson, that when it comes to transmitting or sharing protected health information, less is always more.      </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6323/privacy-and-security-rules.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
245      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/leaders/video/what-do-i-do-if-i-get-a-hipaa-complaint</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3557.mp4      </video:content_loc>
      <video:title>
What do I do if I get a HIPAA Complaint?      </video:title>
      <video:description>
In this lesson, we'll be covering what you should do if you get a HIPAA complaint, including steps you should take if you both get a complaint and suffer a data breach. At the end of the lesson, we'll stick with our recent looks at HIPAA violations with a Word about HIPAA violation penalty structure. If You Receive a HIPAA Complaint If you receive a compliant from a patient or a business about your handling of protected health information, you should remedy the situation using the following steps:  Make a note of the complaint in your incident log. Provide a complaint form to the patient or business making the complaint to complete. The form is used to help explain the complaint in detail. Your privacy officer should conduct a thorough formal investigation into the complaint to identify if any policies or procedures were not followed and if there was a potential data breach that could have impacted PHI.  If you Suffer a Data Breach Let's say you take a complaint seriously and discover it was not only valid, but PHI was indeed breached. What do you do now? If your privacy officer does identify that PHI has been breached, take the following steps:  Log the data breach into a data breach log. Perform a risk assessment to help identify security gaps and vulnerabilities. Notify all of the impacted individuals of the data breach. Be mindful of time – report the data breach before the standard federal 60-day notification or state notification if it is more restrictive. After a risk report has been created from the risk assessment, you must document your remediation plan and remediate the risks in a timely manner.  A Word About HIPAA Violation Penalty Structure Each category of violation carries a separate HIPAA penalty. It is up to the Office for Civil Rights to determine a financial penalty within the appropriate range. They will consider a number of factors when determining penalties, such as the length of time a violation was allowed to persist, the number of people affected, and the nature of the data exposed. An organization´s willingness to assist with an Office for Civil Rights' investigation is also taken into account. The general factors that can affect the level of financial penalty also include prior history, the organization's financial condition, and the level of harm caused by the violation. You may recall in the last Word section of the last lesson, how there was a tier system when it comes to HIPAA's penalty structure. Well, there's also a tier system when it comes to assessing fines.  Tier 1: Minimum fine of $100 per violation up to $50,000. Tier 2: Minimum fine of $1,000 per violation up to $50,000. Tier 3: Minimum fine of $10,000 per violation up to $50,000. Tier 4: Minimum fine of $50,000 per violation.  The above fines for HIPAA violations are those stipulated by the HITECH Act. It should be noted that these are adjusted annually to take inflation into account. A data breach or security incident that results from any violation could see separate fines issued for different aspects of the data breach under multiple security and privacy standards. For instance, a fine of $50,000 could, in theory, be issued for any violation of HIPAA rules, however minor they turn out to be. A fine can also be applied on a daily basis. For example, if a covered entity has been denying patients the right to obtain copies of their medical records, and had been doing so for a period of one year, the Office for Civil Rights may decide to apply a penalty per day that the covered entity has been in violation of the law. Therefore, the penalty would be multiplied by 365, not by the number of patients that have been refused access to their medical records.      </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6357/what-do-i-do-if-i-get-a-hipaa-complaint.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
75      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/leaders/video/how-to-be-proactive-to-be-hipaa-compliant</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3545.mp4      </video:content_loc>
      <video:title>
How to be Proactive to be HIPAA Compliant      </video:title>
      <video:description>
In this lesson, we're going to look at ways you can reduce the risks to your business as it pertains to data breaches. To this end, we'll show the 3 Pillars of Success that should help eliminate your risks and keep you HIPAA compliant. And at the end of the lesson, we'll provide you with a Word about the duties of a HIPAA compliance officer. There are several common issues we've seen over the years that greatly contribute to you or your organization not being HIPAA compliant, which increases your risk of suffering through a data breach. Those issues include:  Your organization's and staff's understanding of HIPAA and HITECH laws Limited or no training on how to properly handle PHI, including ePHI and oral conversations A lack of risk assessments to help identify your risks to PHI A limited, or no, Book of Evidence that includes your organization's policies and procedures Not using the proper business associate agreements (BAAs) The use of Gmail, Yahoo, MSN, AOL, and other unsecure platforms for the transmission of PHI  So, how can you and your organization be more proactive at reducing your risks and becoming more HIPAA compliant? You can institute what we describe as the 3 Pillars of Success The 3 Pillars of Success The 3 Pillars of Success are:  Risk Assessments A Book of Evidence Compliance Training  Let's look at each of these in more detail. Risk Assessments Your business or organization must perform a regularly scheduled compliance risk assessment. We recommend doing this on at least an annual basis to ensure that all staff understand any changes within your organization and/or business environment that could contribute to it being less secure. A Book of Evidence A Book of Evidence is a basic HIPAA requirement and contains all of your organization's policies and procedures on handling PHI and ePHI, including, among other things, your business continuity plan, data breach plan, and how to handle unauthorized access of protected health information. Compliance Training Compliance training is an essential part of any security plan and ensures that you and your staff understand how to better protect PHI and follow all of your organization's policies and procedures. The human firewall is the best kind of firewall, but it cannot properly function without training and education. The more you and your employees understand the risks involved and how to handle PHI, the better your organization's chances of reducing the risks of data breaches and the subsequent risks to your business. A Word About the Duties of a HIPAA Compliance Officer HIPAA requires that one or more people within a covered entity or business associate is assigned the duties of a HIPAA Compliance Officer. How much work is involved depends on the size of the covered entity or business associate along with the amount of PHI involved. And in smaller organizations, it is often the case that the duties of a HIPAA Compliance Officer are divided between a Privacy Officer and a Security Officer. (Our crystal ball says that we'll be digging into these roles in later lessons.) The typical duties of a HIPAA Compliance Officer include:  Gaining a thorough knowledge of the HIPAA Privacy and Security Rules and the solutions available that will allow him or her to develop a HIPAA compliance program. After developing a HIPAA compliance program, the compliance officer should document progress towards its implementation, which would include creating a system that enables the officer to monitor the status of the organization's HIPAA compliance. That system should allow the officer to prioritize efforts towards compliance and communicate priorities to others in the organization. It should also act as a conduit through which compliance concerns can be raised and organizational changes coordinated. The HIPAA Compliance Officer is responsible for developing training programs and executing training courses. These should be designed to help employees understand HIPAA compliance and how any changes implemented will affect their specific duties. The HIPAA Compliance Officer is also responsible for monitoring the Department of Health &amp;amp; Human Services' and their state's regulatory requirements. When new regulations or guidelines are introduced, the officer must adjust their organization's HIPAA compliance program to reflect those changes.  It's important to understand that HIPAA regulations do not define exactly what the duties of a HIPAA Compliance Officer are. Instead, HIPAA leaves it to each covered entity or business associate to establish their own duties according to their specific requirements. Thus, in order for an organization to effectively establish the duties of a HIPAA Compliance Officer, it is necessary for that organization to first understand what those specific requirements are. And part of that would entail undertaking a risk assessment.      </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6333/how-to-be-proactive-to-be-hipaa-compliant.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
104      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/leaders/video/hipaa-breaches-violations-and-penalties</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3542.mp4      </video:content_loc>
      <video:title>
HIPAA Violations and Penalties      </video:title>
      <video:description>
In this lesson, we'll cover HIPAA violations and penalties, how penalty amounts are calculated, the role of a Book of Evidence, and a practical example of addressing workstation security risks. HIPAA Penalties &amp;amp; Financial Impacts Since HIPAA enforcement began, penalties have become increasingly common. Penalty amounts depend directly on the seriousness of the violation and the organization's level of responsibility, ranging from around ten thousand dollars to millions of dollars. As of mid-2026, the largest HIPAA settlement on record remains the 2018 Anthem case at $16 million, which followed the largest healthcare data breach in history.  Pro Tip #1: The Book of Evidence: It is critical for covered entities to maintain written policies and procedures, known as a Book of Evidence. Not only is this a legal requirement under HIPAA, but it protects your organization in the event of a breach, violation, or audit.  Workstation Security &amp;amp; Password Protection As demonstrated in the office scenario, managing passwords properly is an essential part of complying with HIPAA security policies. Displaying passwords on sticky notes attached to computer monitors or placing them under keyboards creates an immediate security risk.  Password Security Standards You are required by law to use a password to access PHI, and passwords must be secure and complex. Avoid placing password notes around your workstation or under your keyboard, as these are the very first places unauthorized individuals look when attempting to gain system access.   Pro Tip #2: Addressing Compliance Issues: Privacy officers and team leaders should address security violations promptly and constructively, helping staff implement secure alternatives to keep all systems protected.       </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6327/hipaa-breaches-violations-and-penalties.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
100      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/leaders/video/do-i-need-a-privacy-officer-or-security-officer</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3556.mp4      </video:content_loc>
      <video:title>
Do I need a Privacy Officer or Security Officer?      </video:title>
      <video:description>
In this lesson, we'll be going into some detail regarding the duties of both HIPAA Privacy Officers and HIPAA Security Officers and where and how those duties sometimes intersect. At the end of the lesson, we'll provide you with a Word about HIPAA violation classifications. One important thing to remember is that you are required by law to have someone appointed as a privacy officer and a security officer at your business or practice. However, it's equally important to point out that these roles can be combined in certain situations and given to just one individual.  Pro Tip #1: While you can appoint one person as privacy officer and security officer, it's not something that we would recommend. Separating these duties adds a second pair of eyes or ensures a certain amount of checks and balances.  What are the Duties of a HIPAA Privacy Officer? In order to fulfill the duties of a HIPAA Privacy Officer, you would be responsible for the following:  Developing a HIPAA compliant privacy program if one does not already exist Ensuring that all privacy policies are in place and capable of protecting the integrity of all PHI and ePHI Enforcing all the privacy policies that are in place Delivering or overseeing ongoing employee privacy training Conducting regularly scheduled risk assessments Developing HIPAA compliant procedures where necessary Monitoring compliance with the privacy program Investigating any and all incidents in which a breach of PHI or ePHI may have occurred Reporting breaches as they occur Ensuring all patient rights in accordance with all state and federal laws Keeping up to date with all relevant state and federal laws  At this point in your lesson, you may be asking yourself, what is the contrast between a security officer and a privacy officer. (Or you may just be contemplating lunch.) The duties of a HIPAA Security Officer are in fact similar to those of a HIPAA Privacy Officer, in as much as the appointed person will be responsible for the development of all security policies, the implementation of all procedures, training, risk assessments, and monitoring compliance.  Pro Tip #2: Having said all that, the focus of a security officer is to ensure compliance with the administrative, physical, and technical safeguards of the HIPAA Security Rule.  What are the Duties of a HIPAA Security Officer? The duties of a HIPAA Security Officer can include, but aren't limited to, the following:  Developing a disaster recovery plan Putting into place the mechanisms to prevent unauthorized access to PHI and ePHI Deciding how all electronic PHI (ePHI) is transmitted and stored  As previously mentioned, while it isn't ideal or recommended, due to the similarity in duties, the roles of a HIPAA Privacy Officer and a HIPAA Security Officer can be performed by the same person. The one caveat: It works best in smaller businesses, practices, or organizations. Customized for Your Business You can complete all the required actions to be HIPAA and HITECH compliant yourself, since all HIPAA and HITECH laws are applicable and must be customized to your exact needs. If you feel that the technical policies and procedures are too overwhelming, however, we would recommend you use a HIPAA compliance guide (like ourselves at ProHIPAA) who can guide you through your HIPAA journey. A Word About HIPAA Violation Classifications Are you curious about what happens if you violate HIPAA? Well, that depends on the severity of the violation. The Office for Civil Rights prefers to resolve HIPAA violations using non-punitive measures, such as with voluntary compliance or issuing technical guidance to help covered entities address areas of non-compliance. However, if the violations are serious, have been allowed to persist for a long time, or if there are multiple areas of noncompliance, financial penalties may be appropriate. There are four categories that are used for the penalty structure. They are as follows:  Tier 1: A violation that the covered entity was unaware of and could not have realistically avoided, had a reasonable amount of care had been taken to abide by HIPAA Rules. Tier 2: A violation that the covered entity should have been aware of but could not have avoided even with a reasonable amount of care, but still falling short of willful neglect of HIPAA Rules. Tier 3: A violation suffered as a direct result of willful neglect of HIPAA Rules, in cases where an attempt has been made to correct the violation. Tier 4: A violation of HIPAA Rules constituting willful neglect, where no attempt has been made to correct the violation.  In the case of unknown violations, where the covered entity could not have been expected to avoid a data breach, it may seem unreasonable for covered entities to be issued with a fine. The Office for Civil Rights understands this and has the discretion to waive a financial penalty. The penalty cannot be waived, however, if the violation involved willful neglect of Privacy, Security and Breach Notification Rules.      </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6355/do-i-need-a-compliance-partner-or-privacy-officer.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
155      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/leaders/video/what-is-an-audit-and-how-do-i-handle-it</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3558.mp4      </video:content_loc>
      <video:title>
What is an audit and how do I handle it?      </video:title>
      <video:description>
In this lesson, we'll be covering what an audit by the Office for Civil Rights could entail, ways to help prevent an audit or make one go more smoothly, and why having a Book of Evidence is so vital. At the end of the lesson, we'll stick with our recent looks at HIPAA violations with a Word about criminal penalties for HIPAA violations. An audit by the Office for Civil Rights requires you to provide the following:  A copy of your last risk assessment A copy of your last risk report Your HIPAA compliance training logs Your Book of Evidence   Pro Tip #1: When it comes to HIPAA in general, and particularly with audits, it's imperative for all business associates and covered entities to be as proactive (rather than reactive) as possible. What does being proactive look like? Great question!  You can be proactive, first and foremost, by covering all your bases regarding the following:  Conduct annual risk assessments. Conduct annual compliance training. Stay current with all of your policies and procedures.  Rely on Your Book of Evidence As we've stated before, your Book of Evidence is a HIPAA requirement (and not a suggestion). A good Book of Evidence must include, but isn't limited to, the following:  Your policies and procedures for how to handle PHI and ePHI Your business continuity plan Your data breach plan   Pro Tip #2: Having your Book of Evidence ready at all times can help an audit process go much more smoothly and hopefully speed things up a bit as well, especially if your Book of Evidence is up-to-date and all of your training records are current.  A Word About Criminal Penalties for HIPAA Violations Before we dig into a word about criminal penalties for HIPAA violations, let's first look at if HIPAA violations can even be criminal. Can HIPAA Violations be Criminal? When a HIPAA covered entity or business associate violates HIPAA Rules, civil penalties can be imposed. When healthcare professionals violate HIPAA, it's often their employer that receives the penalty, but not always. If healthcare professionals knowingly obtain or use PHI for reasons that are not permitted by the HIPAA Privacy Rule, they may be found to be criminally liable for the HIPAA violation under the criminal enforcement provision of the Administrative Simplification subtitle of HIPAA. Criminal HIPAA violations are prosecuted by the Department of Justice, which is increasingly taking action against individuals that have knowingly violated HIPAA Rules. There have been several cases that have resulted in substantial fines and prison sentences. Criminal HIPAA violations include theft of patient information for financial gain and wrongful disclosures with intent to cause harm. A lack of understanding of HIPAA requirements may not be a valid defense. When an individual knowingly violates HIPAA Rules, knowingly means that they have some knowledge of the facts that constitute the offense, not that they definitely know that they are violating HIPAA Rules. Criminal Penalties for HIPAA Violations As you probably know by now, criminal penalties for HIPAA violations are divided into separate tiers, with the term and an accompanying fine decided by a judge based on the facts of each individual case. As with the Office for Civil Rights, a number of general factors are considered which will affect the penalty issued. If an individual has profited from the theft, access, or disclosure of PHI, it may be necessary for all payments received to be refunded, in addition to the payment of a fine. The three tiers of criminal penalties for HIPAA violations are:  Tier 1: Reasonable cause or no knowledge of violation – Up to 1 year in jail. Tier 2: Obtaining PHI under false pretenses – Up to 5 years in jail. Tier 3: Obtaining PHI for personal gain or with malicious intent – Up to 10 years in jail.  In recent months, the number of employees discovered to be accessing or stealing PHI (for various reasons) has increased. The value of PHI on the black market is considerable, and this can be a big temptation for some individuals. It is therefore essential that controls are put in place to limit the opportunity for individuals to steal patient data, and for systems and policies to be put in place to ensure improper access and theft of PHI is identified promptly. All staff likely to come into contact with PHI as part of their work duties should be informed of the HIPAA criminal penalties and that violations will not only result in loss of employment, but potentially also a lengthy jail term and a heavy fine. State attorneys general are cracking down on data theft and are keen to make examples out of individuals found to have violated HIPAA Privacy Rules. A jail term for the theft of HIPAA data is therefore highly likely.      </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6359/what-is-an-audit-and-how-do-i-handle-it.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
60      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/leaders/video/what-penalties-apply-to-violations-of-privacy-rule-requirements</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3555.mp4      </video:content_loc>
      <video:title>
What Penalties Apply to Violations of Privacy Rule Requirements?      </video:title>
      <video:description>
In this lesson, we're going to cover all things related to HIPAA violation penalties and what the true costs are to your business or practice if this should happen to you. At the end of the lesson, we'll provide you with a Word about what constitutes a HIPAA violation. The United States Department of Health and Human Service's Office for Civil Rights is responsible for administrating and enforcing the HIPAA standards and may conduct investigations and compliance reviews whenever they see fit. Should you be found to be in violation of any privacy rule requirements, your business or practice could be responsible for paying civil penalties. These penalties are for each violation and can be stacked if there are multiple violations with respect to a single individual. Penalties also depend on the type of violation. Civil penalties, for instance:  Can range from $100 to $50,000 per violation Can go up to a maximum of $1.5 million per year  Criminal penalties on the other hand:  Can range up to $250,000 in fines Can result in 10 years imprisonment for those knowingly or improperly disclosing information or obtaining information under false pretenses Can result in even higher penalties for violations designed for financial gain or deemed as malicious harm   Pro Tip: That's just the federal side of the penalty puzzle. State laws can also inflict their own set of fines to your business or practice.  The True Cost of a Data Breach Let's go over the details of the cost of a data breach to your business or practice. Here are a few costs you may be subjected to:  Health and Human Services fines up to $1.5 million per violation or per year. Federal Trade Commission fees up to $16,000 per violation. Class action lawsuits from between $1000 and $500,000 since no one usually sues for less than $500,000. State Attorney General can inflict fines of between $150,000 and $6.8 million. Business or patient loss up to 50 percent. The costs associated with offering ID monitoring and free credit reports to all people impacted, or somewhere around $10 to $30 per person. Lawyer fees of at least $2000+. Breach notifications costs of at least $1000. Business associate changes and technology repairs of around $5000+.  A Word About What Constitutes a HIPAA Violation There is much talk of HIPAA violations in this course, but what actually constitutes a HIPAA violation? A HIPAA violation has occurred when a HIPAA covered entity – or a business associate – fails to comply with one or more of the provisions of the HIPAA Privacy, Security, or Breach Notification Rules. A violation may be deliberate or unintentional. An example of an unintentional HIPAA violation is when too much PHI is disclosed, and the minimum necessary information standard is violated. When PHI is disclosed, it must be limited to the minimum necessary information to achieve the purpose for which it is disclosed. Financial penalties for HIPAA violations can be issued for unintentional HIPAA violations, although, as mentioned above, the penalties will often be at a lower rate than willful violations of HIPAA Rules. An example of a deliberate violation is unnecessarily delaying the issuing of breach notification letters to patients and exceeding the maximum timeframe of 60 days following the discovery of a breach to issue notifications, which is a clear violation of the HIPAA Breach Notification Rule. Many HIPAA violations are the result of negligence, such as the failure to perform an organization-wide risk assessment. Financial penalties for HIPAA violations have frequently been issued for risk assessment failures. Penalties for HIPAA violations can potentially be issued for all HIPAA violations, although the Office for Civil Rights typically resolves most cases through voluntary compliance, issuing technical guidance, or accepting a covered entity or business associate's plan to address the violations and change policies and procedures to prevent future violations from occurring. It should be noted that financial penalties for HIPAA violations are reserved for the most serious violations of HIPAA Rules.      </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6353/what-penalties-apply-to-violations-of-privacy-rule-requirements.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
131      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/leaders/video/hipaa-foundation-conclusion</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3546.mp4      </video:content_loc>
      <video:title>
HIPAA Foundation Conclusion      </video:title>
      <video:description>
In this final lesson, we recap what you have learned throughout your HIPAA course, highlighting key requirements for covered entities and business associates, the value of PHI, and next steps for maintaining organizational compliance. HIPAA &amp;amp; HITECH Foundation Review Both covered entities and business associates share the legal responsibility to safeguard Protected Health Information (PHI) at all times. Because business associates handle critical data, covered entities must ensure that all third-party vendors are trusted partners committed to protecting health information.  Pro Tip #1: Protecting Your Practice's Legacy: Complete medical records can sell for hundreds of dollars on the dark web, making healthcare a top target for cybercriminals. Actively protecting PHI is essential not only for patient security, but also to protect the legacy, reputation, and financial stability of your business.  Navigating Your HIPAA Compliance Journey Achieving and maintaining compliance is an ongoing process. If you do not feel completely confident in your organization's HIPAA compliance status, engaging a trustworthy compliance partner can help you navigate regulatory requirements effectively.  Pro Tip #2: Need Additional Support? If you need further assistance or a compliance guide to navigate your journey, contact our team at ProTrainings.com or call us at 888-406-7487. We are here to serve you!       </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6335/hipaa-foundation-conclusion.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
75      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/leaders/video/what-is-a-business-associate</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3549.mp4      </video:content_loc>
      <video:title>
What is a Business Associate?      </video:title>
      <video:description>
In this lesson, we're going to dig into business associates – who they are, what their requirements are, and also include some examples of common business associates. At the end of the lesson, we'll take a more in-depth look into the business associate agreement. A business associate is any company or individual with access to PHI or ePHI in support of a covered entity's business. Business associates are required to have the same policies and procedures when it comes to accessing and protecting PHI as covered entities. Just like covered entities, business associates are required to protect personal health information at all times. They're also required to notify their covered entity of any potential or active data breaches. And in a bigger picture sort of way, business associates must help protect their covered entities at all times.  Pro Tip: Business associates are required to immediately notify their covered entity when a breach of unsecured PHI is discovered. Waiting will only compound the problem and is a breach of HIPAA law.  Business associates can include the following:  IT service companies Cloud service providers Laboratories Lawyers Consultants Benefits managers Claims processing firms Data transmission service providers Technology companies Suppliers and manufacturers with access to PHI  You may recall the corresponding video for this lesson involving an uncomfortable exchange with Tom the IT guy. Office manager Mary left a medical file laying on the counter and Tom unknowingly wandered over to have a look. This one incident is actually responsible for two violations – 1) not securing PHI and 2) looking at PHI when you do not have permissible access. Unfortunately for Tom, he doesn't know he's not supposed to look … until he already has looked. Moral of the story: Don't leave medical files laying around for others to look at. Business Associate Agreements Business associates must comply with all HIPAA requirements by providing written contractual agreements to their covered entities. Included in these agreements is:  The business associate will only use the covered entities protected health information for proper purposes The business associate will safeguard the covered entity's PHI from misuse The business associate will comply with all of HIPAA's security requirements and will ensure that all administrative, physical, and technical safeguards are followed to keep the covered entity's PHI safe  If a business associate violates any part of the HIPAA rules and regulations or is in violation of the business associate agreement with the covered entity, the business associate will be held accountable for both types of penalties. In instances where a business associate uses a subcontractor, also known as a downstream supplier, that subcontractor is required by HIPAA to have a contractual agreement with their business associate. Subcontractors are essentially held to the same HIPAA requirements when it comes to accessing and using protected health information. And like business associates, they are also accountable for any and all penalties when there is a breach of that contract. A Word About the HIPAA Business Associate Agreement A HIPAA business associate agreement is a contract between a HIPAA covered entity and a vendor used by that covered entity. As you already know, a HIPAA-covered entity is typically a healthcare provider, health plan, or healthcare clearinghouse that conducts transactions electronically. A vendor of a HIPAA covered entity that needs to be provided with protected health information in order to perform duties on behalf of the covered entity is called a business associate (BA) under HIPAA. A vendor is also classed as a business associate if, as part of the services provided, ePHI passes through their systems. A signed HIPAA business associate agreement must be obtained by the covered entity before allowing a business associate to come into contact with PHI or ePHI. Since the passing of the HITECH Act and its incorporation into HIPAA in 2013 via the HIPAA Omnibus Final Rule, subcontractors used by business associates are also required to comply with HIPAA. As you now know, all business associates must likewise obtain a signed HIPAA business associate agreement from its subcontractors before access is given to PHI or ePHI. And if subcontractors use vendors that require access to PHI or ePHI, they too need to enter into business associate agreements with their subcontractors. The business associate agreement should stipulate that the business associate (or subcontractor) must implement appropriate administrative, technical, and physical safeguards to ensure the confidentiality, integrity, and availability of ePHI and meet the requirements of the HIPAA Security Rule. Some of those measures may be stated in the business associate agreement or it may be left to the discretion of the business associate. The business associate agreement should also include the allowable uses and disclosures of PHI to meet the requirements of the HIPAA Privacy Rule. In the event that PHI is accessed by individuals unauthorized to view the information, such as an internal breach or cyberattack, the business associate is required to notify the covered entity of the breach and may be required to send notifications to individuals whose PHI has been compromised. The timescale and responsibilities for notifications should be detailed in the agreement. A business associate should also be made aware of the consequences of failing to comply with the requirements of HIPAA. Business associates can be fined directly by regulators for HIPAA violations. Both the Department of Health and Human Services' Office for Civil Rights and state attorneys general have the authority to issue financial penalties for violations of HIPAA Rules. At the end of the next lesson, we'll cover a few more details about business associate agreements that you may want to be aware of.      </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6341/what-is-a-business-associate.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
226      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/leaders/video/who-is-required-to-comply-with-hipaa-laws</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3536.mp4      </video:content_loc>
      <video:title>
Who is required to comply with HIPAA laws?      </video:title>
      <video:description>
In this lesson, we'll go over who is required to comply with HIPAA laws and the two key groups the law directly applies to: covered entities and business associates. Who Must Comply with HIPAA Laws? HIPAA applies directly to two main groups that handle, transmit, or support operations involving Protected Health Information (PHI):  Covered Entities: Include health plans, healthcare clearinghouses, and healthcare providers that transmit PHI electronically in connection with a covered transaction. Business Associates: Perform services for covered entities and require direct or incidental access to PHI in support of business operations.  What is a Covered Entity? A covered entity is any provider of medical or other health services, or an organization that handles PHI. Key examples include:  Healthcare Providers: Physicians, nurses, hospitals, clinics, and allied health professionals. Health Plans: Any individual or group plan that provides or pays the cost of healthcare, such as an HMO, insurance company, Medicaid, or Medicare. Billing &amp;amp; Payment Entities: Organizations and individuals that provide billing services or receive payment in connection with healthcare services in the normal course of business.   Pro Tip #1: Repetition is a key part of mastering HIPAA standards. While you may notice some overlap with previous lessons on general HIPAA guidelines, reinforcing these core definitions ensures clear compliance across your organization.  What is a Business Associate? A business associate is any company or individual with direct or incidental access to PHI or ePHI while supporting a covered entity. Business associates must maintain strict operational safeguards, often documented in what is known as a book of evidence. Examples of business associates include:  IT vendors Call centers Court reporters Cloud providers Legal services providers Suppliers and manufacturers with access to PHI and ePHI   Business Associate Requirements &amp;amp; Breach Reporting Business associates are held to strict standards under HIPAA law. They are required to maintain risk assessments, employee training, and formal policies and procedures. Furthermore, business associates are legally required to notify covered entities of any potential or active data breaches to ensure PHI is protected at all times.   Pro Tip #2: Business associates must sign a formal Business Associate Agreement (BAA) with covered entities before gaining access to PHI. This contract legally binds them to safeguard patient information under federal law.       </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6315/who-is-required-to-comply-with-hipaa-laws.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
97      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/leaders/video/what-is-protected-health-information</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3539.mp4      </video:content_loc>
      <video:title>
What is PHI?      </video:title>
      <video:description>
In this lesson, we'll be going into some detail on what PHI is. At the end of the lesson, we'll dig into when PHI really isn't PHI, or in other words, exceptions to PHI. In a nutshell, PHI (protected health information) is any information that is individual to a patient – past, present, or future – about the care provided, whether physical or mental, for an individual. This can include documentation of doctor visits, charts and notes made by physicians and other healthcare staff, healthcare payment information, claim status, and the coordination of healthcare benefits.  Pro Tip #1: It's worth noting that HIPAA covers all forms of PHI, including electronic, paper, and even oral/spoken. Many people forget that PHI is also covered under spoken word. Be especially mindful when disclosing healthcare-related information with anyone – other patients, staff, and business associates.  You may recall from the corresponding video for this lesson that one patient overheard two healthcare employees talking about another patient's health information. When in doubt, always assume that someone might be listening. And do everything you can to make sure private conversations take place in private locations. Think of PHI the way you would classified information. You have been given clearance to see it. But it's your responsibility to keep it safe and from falling into the wrong hands at all times. A More In-Depth Look at PHI Under HIPAA rules and regulations, PHI is considered as any identifiable health information that is used, maintained, stored, or transmitted by covered entities and business associates. As mentioned above, PHI is health information in any form, including physical records, electronic records, or spoken information. This means that PHI includes health records, health histories, lab test results, and medical bills.  Pro Tip #2: The key point to remember regarding PHI, is that to be considered PHI, it must include individual identifiers, such as patient names, social security numbers, driver's license numbers, insurance details, and birth dates, when they are linked with health information. Demographic information can also be considered PHI under HIPAA Rules.  There are in total 18 identifiers for PHI and these include the following:  Names Dates, except year Telephone numbers Geographic data Fax numbers Social security numbers Email addresses Medical record numbers Account numbers Health plan beneficiary numbers Certificate/license numbers Vehicle identifiers and serial numbers including license plates Web URLs Device identifiers and serial numbers Internet protocol addresses Full face photos and comparable images Biometric identifiers, such as retinal scans and fingerprints Any unique identifying number or code  Can PHI be Disclosed for Public Health Activities? The short answer is, yes. However, it's limited to the CDC (Center for Disease Control and Prevention), public health authorities – federal or state – and OSHA. OSHA is unique because it can request information without authorization or the need to sign a business association agreement.  Pro Tip #3: One caveat to remember, though, is that covered entities should reasonably limit the amount of PHI given in these circumstances to what is considered a necessary amount and nothing more. Remember, less is more when it comes to sharing personal health information.  So, why would OSHA request PHI? They could do so in the event of a natural disaster or a state of emergency in an attempt to determine the demographics of an affected area. Perhaps they need to mobilize the national guard, first responders, or military personnel to aid such an emergency. It's important to remember, that if contacted by someone in the government about sharing PHI, you must ensure their legitimacy. Request relevant phone numbers and email addresses and ask for a written request. A Word About the Exceptions to PHI You may be tempted to think that all health information is considered PHI under HIPAA, but this isn't true, and there are some exceptions. One determining factor is who records the information. A good example of this would be health trackers, such as physical devices worn on the body or apps on mobile phones. These devices can record health information such as heart rate or blood pressure, which would be considered PHI under HIPAA rules if the information was recorded by a healthcare provider or was used by a health plan. However, under the HIPAA rules, this information only applies to HIPAA covered entities and their business associates. This means that if a device manufacturer or app developer hasn't been contracted by a HIPAA covered entity and also isn't a business associate, the information recorded would not be considered PHI under HIPAA rules. The same rules apply to education or employment records. Let's say a hospital holds data on its employees, which can include some health information like allergies or blood types. However, HIPAA rules do not apply to this type of information. Also, it's important to remember that under HIPAA, PHI ceases to be PHI if it's stripped of all identifiers listed above that can tie the information to an individual. When those identifiers are removed, the health information is technically referred to as de-identified PHI, and thus, HIPAA rules no longer apply.      </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6321/what-is-protected-health-information.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
259      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/leaders/video/why-cybercriminals-want-phi</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3543.mp4      </video:content_loc>
      <video:title>
Why Cybercriminals Want PHI      </video:title>
      <video:description>
In this lesson, we review why cybercriminals target PHI and ePHI, the financial value of medical records on the dark web, common threat vectors like ransomware and phishing, and how to respond if you receive a suspicious email.  Pop Quiz: Handling Suspicious Emails Question: You just received a strange-looking or unfamiliar email in your inbox. What should you do?  A) Do not open the email B) Delete the email or mark it as junk C) Immediately notify your manager, privacy officer, or IT team D) All of the above   Reveal Correct Answer  Correct Answer: D) All of the above You should never open a suspicious email, always remove or report it, and promptly notify your manager or privacy officer to protect your entire organization.   The Value of PHI on the Dark Web Healthcare is consistently one of the most targeted and costly sectors for data breaches, with hundreds of millions of records exposed in major incidents such as the Change Healthcare breach. Medical records are significantly more valuable to cybercriminals than stolen financial data due to their permanence and versatility:  Financial Data (Credit Cards): Stolen credit card numbers have a limited lifespan and are only useful until the victim cancels the card or account. A stolen card might only sell for a few dollars. Medical Records (PHI): Information contained in medical records does not change, even if compromised. Complete medical records can sell for hundreds of dollars on the dark web, allowing cybercriminals to commit long-term identity theft and fraud.   Pro Tip #1: Because healthcare data retains its value indefinitely and faces constant threats, healthcare professionals and business associates must actively protect PHI and ePHI at all times.  Common Platforms for Electronic Attacks Cybercriminals use multiple delivery methods and platforms to launch ransomware and distribute malware into healthcare networks:  Business Applications &amp;amp; Cloud Services USB Drives: Exercise extreme caution with USB drives, as they are frequently used across multiple locations and can easily transmit infections. Social Media &amp;amp; Website Attachments Email Attachments &amp;amp; Phishing: Phishing emails remain a primary vector for network breaches.   Handling Suspicious Emails If you receive a suspicious or unfamiliar email, NEVER click links or open attachments. Clicking an unverified attachment can immediately trigger a malware infection or data breach. Use the "Report Phishing" button in your email client to flag it for IT, and promptly alert your office manager and Privacy Officer.   Pro Tip #2: Prompt Reporting Protects Everyone: In the office scenario, Nurse Joy did the right thing by avoiding the unfamiliar email and notifying her team immediately. Reporting suspicious activity right away helps safeguard your entire organization from potential security incidents.       </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6329/why-cybercriminals-want-phi.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
168      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/leaders/video/important-hipaa-terminology</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3537.mp4      </video:content_loc>
      <video:title>
Important HIPAA Terminology      </video:title>
      <video:description>
In this lesson, we will go through some essential HIPAA definitions and core terms to help you better understand the law, including encryption standards, business associate liabilities, and risk assessment structures. Key HIPAA Terms &amp;amp; Definitions  HIPAA: Health Insurance Portability and Accountability Act of 1996. HITECH: Health Information Technology for Economic and Clinical Health Act of 2009. HITECH promotes the adoption and meaningful use of health IT while significantly expanding HIPAA privacy rules and security standards. PHI (Protected Health Information): Any personal health information that identifies or pertains to a patient. ePHI (Electronic Protected Health Information): Personal health information stored or transmitted electronically, including faxes, emails, cloud providers, data backups, patient portals, removable media, and secure texting.   Encryption &amp;amp; "Reasonable and Appropriate" Standards All ePHI should be encrypted at rest and in transit wherever reasonable and appropriate. "Reasonable and appropriate" is not a matter of opinion; it refers to what a careful organization of your size, resources, and risk level would do to protect data. If encryption is not feasible, the reason must be documented and an equivalent safeguard implemented instead.  Business Associate Requirements A Business Associate is any individual or entity that supports the healthcare industry and performs functions on behalf of a covered entity. Under HITECH regulations, business associates must comply directly with HITECH rules and assume financial liability for data breaches caused by their organization or employees. Business associates are required to maintain:  Formal Risk Assessments Employee Training Programs A customized Book of Evidence (policies and procedures)  Understanding Risk Assessments A Risk Assessment consists of government-mandated questions to identify potential security gaps and risk levels. It requires a corresponding risk report featuring a clear roadmap to resolution. Questionnaires cover three main domains (Administrative, Technical, and Physical) and utilize three implementation levels:  Standard: Measures compliance to ensure confidentiality, integrity, and availability of ePHI. Required: Mandatory implementation for all covered entities and business associates. Addressable: Provides operational flexibility based on risk level. However, addressable does not mean optional; organizations must apply appropriate security measures to manage the risk.   Pro Tip #1: A Book of Evidence is your customized set of written policies and procedures explaining how your organization manages PHI and ePHI, including data breach notification protocols, disaster recovery, and privacy policies.   Pro Tip #2: Covered entities must provide patients with a copy of their Privacy Policy upon request. Business associates must make their privacy policies available to internal employees, downstream suppliers, and government auditors.       </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6317/important-hipaa-terminology.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
244      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/leaders/video/policies-procedures-and-the-book-of-evidence</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3552.mp4      </video:content_loc>
      <video:title>
Policies, Procedures and the Book of Evidence      </video:title>
      <video:description>
In this lesson, we'll be covering HIPAA policies and procedures (aka: The Book of Evidence), including what the Book of Evidence should consist of and one very important key point to remember when putting together your own Book of Evidence. At the end of the lesson, we'll provide you with a Word about how to become HIPAA compliant. Every business or practice that has access to PHI and ePHI is required to have a set of policies and procedures in place on how to handle all protected health information. This set of policies and procedures is what we refer to as the Book of Evidence.  Pro Tip #1: One important thing to remember about your Book of Evidence is that it must be customized to your own unique snowflake that is your business or practice. Yes, downloadable online templates are available. And yes, using them is a very bad idea. Your own Book of Evidence must be relevant to your own exact business.  What Should a Book of Evidence Include? Without spoiling the ending, any thorough Book of Evidence should include:  The responsibilities of the covered entity or business associate The use and disclosure of the PHI they have access to The individual rights of patients (if pertinent) How to handle a breach of protected health information   Pro Tip #2: Your Book of Evidence must be present – in the office of the business or practice – and must be provided to the Office for Civil Rights should they ever request to see it. Your Book of Evidence also must reflect the dates of the latest changes to the law. We also recommend storing a copy online or through a local network for disaster recovery and business continuity purposes.  There is a common misconception that a Book of Evidence is one size fits all. Again, it's not! It must be customized to fit your own unique business or practice. Also, don't forget to store a printed copy on site and a copy at an offsite location or cloud-based location. A Word About How to Become HIPAA Compliant Before getting into how to become compliant, it may be best to answer the question, what is HIPAA compliance? HIPAA compliance involves fulfilling the requirements of the Health Insurance Portability and Accountability Act of 1996, its subsequent amendments, and any related legislation such as the Health Information Technology for Economic and Clinical Health (HITECH) Act. Typically, the next question is, what are the HIPAA compliance requirements? That question is not so easy to answer as some of the requirements of HIPAA are intentionally vague. This is so HIPAA can be applied equally to every different type of covered entity or business associate that comes into contact with PHI. While it is possible to use a HIPAA compliance checklist to make sure all aspects of HIPAA are covered, it can be a difficult process for organizations unfamiliar with the intricacies of HIPAA Rules to develop a HIPAA compliance checklist and implement all appropriate privacy and security controls. However, you will certainly need to use a HIPAA compliance checklist to make sure your organization, product, or service incorporates all of the technical, administrative, and physical safeguards of the HIPAA Security Rule. You must also adhere to the requirements of the HIPAA Privacy and Breach Notification Rules. If you get anything wrong and fail to safeguard ePHI, as a HIPAA business associate, you can be fined directly for HIPAA violations by the HHS' Office for Civil Rights, state attorneys general, and other regulators. Criminal charges may also be applicable for some violations. HIPAA compliance can, therefore, be daunting. To ensure you cover all elements on your HIPAA compliance checklist and leave no stone unturned, it is worthwhile seeking expert guidance from HIPAA compliance experts. Many firms offer HIPAA compliance software to guide you through your HIPAA compliance checklist, ensure ongoing compliance with HIPAA Rules, and provide you with HIPAA certification.      </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6347/policies-procedures-and-the-book-of-evidence.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
94      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/leaders/video/hipaa-breach-notification-requirements</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/7666.mp4      </video:content_loc>
      <video:title>
HIPAA Breach Notification Requirements      </video:title>
      <video:description>
In this lesson, we'll go over what happens when PHI is lost, inappropriately shared, or stolen, and review the key requirements outlined in the Breach Notification Rule. What is the Breach Notification Rule? The Breach Notification Rule sets clear standards for how organizations must handle potential compromises of Protected Health Information (PHI). If PHI was used or disclosed in a manner not permitted under HIPAA, it is presumed to be a breach unless a thorough risk assessment demonstrates a low probability that the data was actually compromised.  Pro Tip: Your Primary Role as an Employee: Your job is simple: if you know of or suspect a possible breach, report it immediately to your supervisor and privacy officer within the timeframe and guidelines established by your organization's policies.  Breach Notification Requirements &amp;amp; Timelines Once an incident is determined to be a breach, your organization must follow specific reporting protocols based on the scope and size of the breach:  Affected Individuals: Must be notified without unreasonable delay, and no later than 60 days after the breach is discovered. Large Breaches (500+ Individuals): Must be reported to the Department of Health and Human Services (HHS) at the same time affected individuals are notified, as well as to prominent local media outlets in the affected area. Smaller Breaches (Fewer than 500 Individuals): Must be logged and reported to HHS no later than 60 days after the end of the calendar year in which the breach was discovered.   State Laws and Faster Deadlines The federal 60-day notification window is an absolute outer limit. Many state laws mandate much faster reporting deadlines for security incidents, so organizations must always verify and adhere to the specific privacy rules in the states where affected individuals reside.       </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/13932/hipaa-breach-notification-requirements.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
80      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/leaders/video/what-is-a-covered-entity</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3538.mp4      </video:content_loc>
      <video:title>
What is a Covered Entity?      </video:title>
      <video:description>
In this lesson, we'll go over the basics of covered entities, including what covered entities are, common examples across the healthcare industry, and the core requirements all covered entities share. What is a Covered Entity? As a reminder, a covered entity is one of three things: a health plan, a healthcare clearinghouse, or a healthcare provider that transmits Protected Health Information (PHI) electronically in connection with a covered transaction. Common examples of covered entities include:  Doctors, dentists, and nurses Social workers Laboratories and pharmacies Durable medical equipment providers Hospitals and ambulance companies   Call Centers: Covered Entity vs. Business Associate Call centers present a unique caveat under HIPAA regulations based on ownership and operations:  Owned &amp;amp; Operated by a Covered Entity: Must follow HIPAA regulations as a covered entity. Third-Party Call Center: If handling PHI on behalf of a covered entity, they must follow HIPAA regulations as a business associate.   Compliance Requirements for Covered Entities All covered entities are legally required to comply with HIPAA regulations to ensure patient data remains protected. Every covered entity must maintain:  Risk Assessment: A comprehensive evaluation to identify potential vulnerabilities and risk gaps. Staff Compliance Training: Ongoing education to ensure employees properly handle and protect PHI. Book of Evidence: A customized set of written policies and procedures explaining how the organization handles and safeguards PHI.   Pro Tip #1: The defining characteristic of all covered entities is that they directly handle or transmit PHI electronically in connection with healthcare transactions. When evaluating an organization, always look at how data is transmitted to determine regulatory status.  A Word About the Differences Between Covered Entities &amp;amp; Business Associates First, let's define what a business associate is. What is a Business Associate? A business associate is any business or person that provides a service for a covered entity, or a certain function or activity, when that service, function or activity involves the access to PHI that is maintained by the covered entity. Examples of business associates include, but aren't limited to:  Lawyers Accountants IT contractors Billing companies Cloud storage services Email encryption services  The key phrase from above that really defines a business associate is this: the access to PHI that is maintained by the covered entity.  Pro Tip #2: So, what is the Difference? Covered entities have PHI (protected health information) while business associates merely have access to PHI. It's a bit of an ambiguous distinction, but an important distinction, nonetheless.       </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6319/what-is-a-covered-entity.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
62      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/leaders/video/how-to-handle-a-data-breach-and-violations</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3554.mp4      </video:content_loc>
      <video:title>
How to Handle a Data Breach and Violations      </video:title>
      <video:description>
In this lesson, we're going to tackle your worst nightmare – there's been a data breach or HIPAA violation and you need to take action. We'll provide you with the necessary steps to handle such an event, and at the end of the lesson, we'll provide you with a few more details about the HIPAA Breach Notification Rule. Let's assume your business or organization has had a breach. These are the steps you need to take now that the breach has occurred.  Notify your privacy or compliance officer and let him or her know about the breach. Initiate a data breach risk assessment. Notify all impacted individuals within the required time frame. Provide a formal report to the HHS within 60 days unless your state requires it sooner. Notify your local media if the breach impacted more than 500 individuals.   Pro Tip #1: HIPAA regulations require you to notify impacted individuals within 60 days. However, multiple states like Texas, Wisconsin, North Carolina, Alabama, and others have more stringent laws that require notification to take place more quickly. Other states appear to be following suit. So, the moral of the story: Time is of the essence.  Once your privacy officer has been alerted of the breach, he or she must initiate a data breach risk assessment to determine what PHI was breached and how many individuals have been affected. A formal report must be compiled and reported to the HHS within 60 days. You also must notify all impacted individuals within the same amount of time. However, if your state law is more stringent, you must abide by the state law. Media Notice Rule The media notice rule requires covered entities to report breaches that involved more than 500 individuals to local news outlets. If dealing with this size of breach, your privacy officer would need to contact local television and newspaper outlets and provide a notification of the breach. Here is just some of the information that a breach notification should include:  A brief description of the breach The types of information involved in the breach The steps affected individuals should take to protect themselves from potential harm A brief description of what the covered entity is doing to investigate the breach, mitigate the harm, and prevent further breaches   Pro Tip #2: If a covered entity has insufficient or out of date contact information for 10 or more individuals, the covered entity must substitute an individual notice by either posting a notice on their website for at least 90 days or by providing the breach notification to all major media outlets in the areas affected.  A Word About the HIPAA Breach Notification Rule The HIPAA Breach Notification Rule requires covered entities to notify patients when there is a breach of their ePHI. The Breach Notification Rule also requires entities to promptly notify the Department of Health and Human Services of such a breach of ePHI and issue a notice to the media if the breach affects more than 500 patients. There is also a requirement to report smaller breaches – those affecting fewer than 500 individuals – via the OCR web portal. These smaller breach reports should ideally be made once the initial investigation has been conducted. The OCR only requires these reports to be made annually. Breach notifications should include the following information:  The nature of the ePHI involved, including the types of personal identifiers exposed The unauthorized person who used the ePHI or to whom the disclosure was made (if known) Whether the ePHI was actually acquired or viewed (if known) The extent to which the risk of damage has been mitigated  Breach notifications must be made without unreasonable delay and in no case later than 60 days following the discovery of a breach. When notifying a patient of a breach, the covered entity must inform the individual of the steps they should take to protect themselves from potential harm, include a brief description of what the covered entity is doing to investigate the breach and the actions taken so far to prevent further breaches and security incidents.      </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/6351/how-to-handle-a-data-breach-and-violations.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
141      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/leaders/video/what-is-hipaa</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3933.mp4      </video:content_loc>
      <video:title>
What is HIPAA?      </video:title>
      <video:description>
In this lesson, you'll learn what HIPAA is, the role it plays in healthcare, and who is mandated to follow its requirements, along with relevant real-world examples. What is HIPAA? The federal law known as HIPAA stands for the Health Insurance Portability and Accountability Act of 1996. Congress passed this landmark law to provide the following:  Portability of insurance Protection and privacy of healthcare information Standardization and efficiency in healthcare data Prevention of discrimination and fraud  What is HIPAA's Role in Healthcare? HIPAA gives the U.S. Department of Health and Human Services the responsibility of adopting rules to help individuals and companies keep important personal health information private. HIPAA protects against unauthorized disclosure of any protected health information (PHI) that pertains to healthcare patients. It establishes a national set of security standards for protecting health information held or transferred in electronic form (ePHI). In addition to privacy and security, administrative provisions were included to improve system efficiency, including:  Specific transaction standards and code sets National standard unique identifiers Data security and electronic signatures   Pro Tip #1: HIPAA compliance is highly dependent on the size, function, administration, and type of entity or business associate. Therefore, this training module is not intended to be a complete or comprehensive guide to HIPAA compliance.   Legal Compliance Disclaimer Entities and business associates regulated by the Privacy and Security Rules are obligated to comply with all federal and state requirements and should not rely on this training alone as a source of legal information or advice. To ensure compliance, covered entities and business associates should regularly perform risk assessments to track access to PHI, periodically evaluate security effectiveness, and re-evaluate potential risks.  Who is Mandated to Follow HIPAA's Requirements? HIPAA law applies directly to two particular groups: Covered Entities and Business Associates. What is a Covered Entity? Covered Entities are health plans, healthcare clearinghouses, and healthcare providers that transmit PHI electronically in connection with a covered transaction. (Note: Simply holding PHI does not by itself make an entity a covered entity.)  Healthcare Providers: Any provider of medical or health services, or any organization or person who transmits health information electronically in the normal course of business (e.g., physicians, nurses, dentists, hospitals, pharmacies, ambulance companies, social workers). Health Plans: Any individual or group plan that provides or pays the cost of healthcare, such as an insurance company, Medicare, or Medicaid. Healthcare Clearinghouses: A public or private entity that transforms healthcare transactions from one format into a required format (e.g., an outside billing service).   Pro Tip #2: HIPAA applies to employers only to the extent that they operate in one or more of these three groups. If a company offers healthcare services on-site (such as an on-site clinic), the employer would be considered a covered entity and required to follow HIPAA rules.  What is a Business Associate? A business associate is any company or individual with access to Protected Health Information (PHI) or ePHI. Examples include IT vendors, laboratories, call centers, court reporters, cloud providers, and legal services. Business associates are required to maintain a risk assessment, training, policies, and procedures. They must also safeguard PHI at all times, notify covered entities of any data breaches, and execute a Business Associate Agreement (BAA).  Contractual &amp;amp; Regulatory Violations If a business associate violates HIPAA, they are not only in violation of their contract with the covered entity, but also in violation of federal HIPAA law itself and will be held accountable for penalties under both. Furthermore, if a business associate uses subcontractors, contractual agreements (BAAs) are required to hold those subcontractors to the exact same standards.       </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/7075/what-is-hipaa-new.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
320      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/texas-hb300/video/what-training-is-required-under-hb300</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3945.mp4      </video:content_loc>
      <video:title>
What Training is Required under HB300?      </video:title>
      <video:description>
Under HB300, mandatory customized employee training regarding state and federal patient privacy and security laws is required. Training must cover federal and state regulatory requirements as well as include the covered entity’s course of business and employees’ scope of employment as it relates to PHI use and disclosure. Employees of covered entities must complete training at least once every two years and not later than 60 days after their hire date. A covered entity shall require an employee of the entity who attends a training program described above to sign, electronically or in writing, a statement verifying the employee's attendance at the training program. The covered entity shall maintain the signed or electronic training record.      </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/7097/what-training-is-required-under-hb300.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
53      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/texas-hb300/video/duties-of-covered-entities-to-provide-notice</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3947.mp4      </video:content_loc>
      <video:title>
Duties of Covered Entities to Provide Notice      </video:title>
      <video:description>
Now let’s discuss the covered entities duty to provide Notice: The law also broadens the scope of covered entities’ Notice of Privacy Practices or other general notices to inform patients about how their e-PHI is used and disclosed. Note that for some entities, this will mean the need to issue a notice if the PHI is subject to electronic disclosure, e.g., for entities such as business associates that would not be required to issue a Notice of Privacy Practices under the HIPAA Privacy Rule. A covered entity shall provide notice to an individual for whom the covered entity creates or receives protected health information if the individual's protected health information is subject to electronic disclosure. A covered entity may provide general notice by:&amp;nbsp;  posting a written notice in the covered entity's place of business; posting a notice on the covered entity's Internet website; or posting a notice in any other place where individuals whose protected health information is subject to electronic disclosure are likely to see the notice.       </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/7101/duties-of-covered-entities-to-provide-notice.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
68      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/texas-hb300/video/medical-records-and-enforcement-authority</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3946.mp4      </video:content_loc>
      <video:title>
Medical Records and Enforcement Authority      </video:title>
      <video:description>
Medical Records: Under the new law, Texas covered entities must provide patients with their EHRs in electronic format within 15 business days after receipt of a written request. The Texas Health and Human Services Commission will soon recommend a standard format for the release of EHRs that is consistent with federal law. Now let’s talk about Enforcement Authority: Following the Office of Civil Rights’ recent lead, the website of the Office of the Attorney General of Texas will contain consumer access to public health information to educate members of the public, including the steps to take to file a complaint with applicable state agencies and their contact information. These state agencies will file annual complaint reports to the Attorney General of Texas. Then, the Attorney General will provide an annual report to the Texas Legislature that includes an overview and statistical analysis of the complaints received.      </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/7099/medical-records-and-enforcement-authority.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
63      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/texas-hb300/video/breach-notifications-under-hb300</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3948.mp4      </video:content_loc>
      <video:title>
Breach Notifications under HB300      </video:title>
      <video:description>
Covered entities must also notify an individual if a breach of that individual’s sensitive personal information, including that individual’s protected health information, has occurred, meaning if that information was acquired or reasonably believed to have been acquired by an unauthorized person. Although HB300 does not specifically define “sensitive personal information”, it incorporates the definition set forth in the Texas Business and Commerce Code and thus includes:  an individual’s first name or first initial and last name in combination with any one or more of the following items, if the name and the items are not encrypted:  Social Security number; Driver’s license number or government issued identification number; or Account number or credit or debit card number in combination with any required security code,access code, or password that would permit access to an individual’s financial account; or   information that identifies an individual and relates to:  the physical or mental health or condition of the individual; the provision of health care to the individual; or payment for the provision of health care to the individual.    This means that documents that you handle on a daily basis, such as initial client information sheets, tax returns, bank statements, etc. may fall under the umbrella of sensitive information that must be safeguarded pursuant to HB300.      </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/7103/breach-notifications-under-hb300.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
97      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/texas-hb300/video/introduction-to-texas-hb300-training</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3942.mp4      </video:content_loc>
      <video:title>
Introduction to Texas HB300 Training      </video:title>
      <video:description>
Hi, this is Dawn from ProHIPAA, I will be your compliance guide. Today, we will be learning about the Texas Law HB300. You are taking this course because you either live in the great state of Texas like me or you do business in the great state of Texas.      </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/7091/introduction-to-texas-hb300-training.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
28      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/texas-hb300/video/conclusion-to-hb300-training-course</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3950.mp4      </video:content_loc>
      <video:title>
Conclusion to HB300 Training Course      </video:title>
      <video:description>
In conclusion, Texas HB300 dramatically expanded the HIPAA and HITECH Regulations already in place. The most significant change is the definition of a Covered Entity and required training. If you handle or come in contact with PHI or ePHI you are considered a Covered Entity and must take appropriate measures to protect PHI at all times. If you still have questions or need a guide to help you navigate this law please call us at 844-722-8898.      </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/7107/conclusion-to-hb300-training-course.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
48      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/texas-hb300/video/hb300-penalties</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3949.mp4      </video:content_loc>
      <video:title>
HB300 Penalties      </video:title>
      <video:description>
In addition, HB300 authorizes civil penalties ranging from $5,000 to $1.5 million for data breaches, depending on the severity, the covered entity’s compliance program, if entity was certified, and its efforts to correct the violation. Besides these increased civil monetary penalties, a data breach may also be classified as a felony. Audits: The Attorney General is also authorized by HB300 to work in tandem with The OCR and the Texas Department of Insurance in conducting audits of a covered entity. This includes monitoring the results of that audit. While certainly the focus seems to be on covered entities within the health care industry, anyone or any business with access to PHI should already be taking appropriate measures to ensure they are compliant with Texas HB300.      </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/7105/hb300-penalties.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
60      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/texas-hb300/video/what-is-texas-house-bill-300</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3943.mp4      </video:content_loc>
      <video:title>
What is Texas House Bill 300?      </video:title>
      <video:description>
Texas House Bill300 also known as Texas HB300 was effective on September 1, 2012. This bill significantly expands patient privacy protections for Texas covered entities beyond those federal requirements known as "HIPAA" and "HITECH." Texas HB 300 expanded legal requirements by:&amp;nbsp;  revising the definition of a "covered entity"; increasing mandates on covered entities, including requiring customized employee training; establishing standards for the use of electronic health records ("EHRs"); granting enforcement authority to several state agencies; and increasing civil and criminal penalties for the wrongful electronic disclosure of PHI.       </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/7093/what-is-texas-house-bill-300.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
51      </video:duration>
    </video:video>
  </url>
  <url>
    <loc>https://www.prohipaa.com/training/texas-hb300/video/what-is-a-covered-entity-under-hb300</loc>
    <video:video>
      <video:content_loc>
https://d3imrogdy81qei.cloudfront.net/videos/course_videos/en/3944.mp4      </video:content_loc>
      <video:title>
What is a Covered Entity under HB300?      </video:title>
      <video:description>
HB300 significantly expands the definition of a Texas "covered entity." A "covered entity" is now defined as any person/entity who:&amp;nbsp; For commercial, financial, or professional gain, monetary fees, or dues, or on a cooperative, nonprofit, or pro bono basis, engages, in whole or in part, and with real or constructive knowledge, in the practice of assembling, collecting, analyzing, using, evaluating, storing, or transmitting protected healthinformation;&amp;nbsp;  comes into possession of protected health information; obtains or stores protected health information under this chapter; or is an employee, agent, or contractor of a person insofar as the employee, agent, or contractor creates, receives, obtains, maintains, uses, or transmits protected health information.  This revised definition is broad and includes not only health care providers but those entities and individuals who under the “HIPAA Privacy Rule,” a federal regulation that protects the privacy of individually identifiable health information, would be classified as business associates and health care payers. In addition, the Texas Act’s “covered entity” definition includes governmental units, information or computer management entities, schools, health researchers, health care facility, clinics, and persons who maintain an Internet site. As a result, this revision impacts any entity that conducts business in Texas and collects, uses, and/or stores PHI. While HITECH only covers law firms representing covered entities, HB300 has expounded upon those regulations to cover any law firm handling medical records, health insurance records, or healthcare billing records.      </video:description>
      <video:thumbnail_loc>
https://d3imrogdy81qei.cloudfront.net/video_images/7095/what-is-a-covered-entity-under-hb300.jpg      </video:thumbnail_loc>
      <video:family_friendly>
Yes      </video:family_friendly>
      <video:duration>
129      </video:duration>
    </video:video>
  </url>
</urlset>
