Protección de privacidad

New Hope CORPS HIPAA Política de privacidad 

Fecha de revisión: 29 de abril de 2024 

  1. Designation of Privacy and Contact Officials

Definición 

  • Información sobre la salud protegida (PHI): Cualquier información individual identificable relacionada con la salud de una persona o la del proveedor de atención médica de una persona que pueda utilizarse para identificar a la persona. 

De conformidad con 45 CFR 164.530(a)(1)(i), New Hope CORPS ha designado al siguiente miembro del personal como funcionario de privacidad del organismo responsable de la elaboración y aplicación de políticas y procedimientos HIPAA. Además, New Hope CORPS la ha designado como la Persona de Contacto disponible para recibir quejas y proporcionar información sobre nuestro Aviso de Política de Privacidad de acuerdo con 45 CFR 164.530(a)(1)(ii).: 

Maritza Carvajal, MCAP, BHCMS, FM
Director of QA/HR
New Hope CORPS, Inc.
1020 N Krome Avenue
Homestead, Fl 33030 

  1. Capacitación y documentación

New Hope CORPS se asegurará de que todos los miembros de su personal reciban formación sobre la Regla de Privacidad de HIPAA según lo especificado en 45 CFR 164.530(b). Los nuevos miembros recibirán capacitación dentro de un plazo razonable para incorporarse a nuestra fuerza de trabajo. Además, se comunicarán los cambios en las políticas o procedimientos y se impartirá capacitación oportunamente. La documentación de esa capacitación se mantiene de conformidad con las políticas de organización y las normas federales. 

III. Proceso de denuncia 

De conformidad con 45 CFR 164.530(d)(1), New Hope CORPS ha establecido el siguiente proceso para que las personas presenten quejas sobre nuestras prácticas de privacidad o nuestro cumplimiento de estas prácticas. Todas las denuncias y sus disposiciones se documentan según lo dispuesto en 45 CFR 164.530(d)(2). 

Procedimiento para tramitar las denuncias de privacidad en New Hope CORPS 

Objetivo:
Establecer un procedimiento normalizado para tramitar las denuncias relacionadas con las prácticas de privacidad en New Hope CORPS, de conformidad con 45 CFR 164.530(d)(1) y 45 CFR 164.530(d)(2). 

Alcance:
This procedure applies to all complaints received concerning the privacy practices of New Hope CORPS or its compliance with these practices. 

Procedimiento: 

  1. Recibiendo Quejas: 
  • Las quejas pueden ser enviadas por particulares por correo electrónico, correo postal, teléfono o en persona. 
  • Todas las denuncias deben dirigirse al Oficial de Privacidad designado en New Hope CORPS. 
  1. Denuncias de registro: 
  • Una vez recibida, el Oficial de Privacidad registra cada denuncia en el Registro de Denuncias de Privacidad. El registro incluye la fecha recibida, la naturaleza de la denuncia y la información de contacto del autor. 
  • The Privacy Officer assigns a unique identifier to each complaint for tracking purposes. 
  • The privacy officer notifies all the parties involved, including individuals affected, funding sources and licensing body. 
  1. Reconocimiento de Quejas: 
  • The Privacy Officer acknowledges receipt of the complaint to the complainant within five business days, providing the complainant with the assigned complaint number and an overview of the complaint process. 
  1. Investigación: 
  • The Privacy Officer investigates the complaint, gathering relevant information and documentation. Esto puede implicar entrevistar a los funcionarios, revisar las políticas de privacidad y otras medidas pertinentes. 
  • The investigation should be thorough and impartial, aiming to conclude within 30 days of the complaint receipt. 
  1. Resolución y respuesta: 
  • Al completar la investigación, el Oficial de Privacidad determina el curso adecuado de acción y documenta la decisión. 
  • Se informa al autor de los resultados de la investigación y de las medidas adoptadas o que deben adoptarse. Esta comunicación debe presentarse a más tardar cinco días hábiles después de la conclusión de la investigación. 
  1. Documentación: 
  • Las actas detalladas de cada denuncia, el proceso de investigación y la resolución se llevan según lo dispuesto en 45 CFR 164.530(d)(2). 
  • Toda la documentación se mantiene segura y confidencial, accesible únicamente al personal autorizado. 
  1. Examen y mejora: 
  • El Oficial de Privacidad examina periódicamente todas las denuncias presentadas y sus disposiciones para determinar patrones o cuestiones recurrentes que pueden requerir cambios en las prácticas de privacidad o formación adicional del personal. 
  • Las recomendaciones para mejoras se presentan al equipo de gestión para su examen. 

Retención de documentación: 

  • Todos los registros relacionados con las quejas de privacidad y sus resoluciones se conservan durante un mínimo de siete años a partir de la fecha de su creación o la fecha en que fueron vigentes, lo que sea más tarde. 

Formación: 

  • Todos los funcionarios reciben capacitación sobre este procedimiento de tramitación de denuncias como parte de su inscripción inicial y reciben formación anual de actualización para asegurar que comprendan sus funciones y responsabilidades en relación con las prácticas de privacidad. 

Este procedimiento garantiza que New Hope CORPS siga cumpliendo con las normas HIPAA, respetando la privacidad y seguridad de toda la información personal y manejando cualquier preocupación de manera rápida y efectiva. 

 

  1. No intimidación y no represalia

New Hope CORPS se abstiene de cualquier acto de intimidación o represalia contra personas que ejercen sus derechos bajo HIPAA, como se indica en 45 CFR 164.530(g). 

  1. Non-Waiver of Rights

New Hope CORPS no requiere que las personas renuncien a sus derechos bajo HIPAA como condición de tratamiento o beneficio elegibilidad, respetando las estipulaciones de 45 CFR 164.530(h). 

  1. Amendments to PHI

De conformidad con 45 CFR 164.526(a)(1), New Hope CORPS ha creado los siguientes procedimientos para modificar la información de salud protegida solicitada o acordada. 

Procedimiento: 

  1. Solicitud de enmienda: 
  • Las personas que deseen solicitar una enmienda a su PHI deben presentar su solicitud por escrito al Oficial de Privacidad. The request must clearly identify the information to be amended and the basis for the amendment. 
  • Se proporcionará un formulario estándar para solicitar enmiendas a las personas bajo petición y también está disponible en el sitio web de New Hope CORPS. 
  1. Recepción y registro de solicitudes: 
  • El Oficial de Privacidad registra cada solicitud al recibir, registrar la fecha recibida, la naturaleza de la solicitud y la información de contacto del solicitante. 
  • El solicitante recibe un acuse de recibo dentro de cinco días hábiles. 
  1. Examen de la solicitud: 
  • The Privacy Officer reviews the request to determine if the amendment is warranted under the HIPAA guidelines, which usually include reasons such as the information being inaccurate or incomplete. 
  • El Oficial de Privacidad puede consultar con los proveedores de atención médica pertinentes o con la persona que originalmente registró la información, si es necesario, para evaluar la validez de la solicitud. 
  1. Decisión y notificación: 
  • La decisión de modificar o denegar la solicitud debe adoptarse a más tardar 60 días después de la recepción de la solicitud. Si se necesita tiempo adicional, se podrá notificar al solicitante la demora y las razones de ésta, y el período de decisión podrá prorrogarse por no más de 30 días adicionales. 
  • Si se aprueba la enmienda, New Hope CORPS hará la enmienda apropiada al PHI e informará al solicitante de que se hayan introducido los cambios. 
  • If the request is denied, the requester will be informed in writing of the decision and the reasons for the denial, along with their rights to submit a written desacuerdoment and to have the request and denial, along with any statement of desacuerdo, appended to their PHI. 
  1. Aplicación de las enmiendas: 
  • Si se hace una enmienda, New Hope CORPS hará esfuerzos razonables para informar y proporcionar la enmienda dentro de un plazo razonable a las personas identificadas por el individuo como necesidad de la información modificada, y a las personas, incluidos los asociados empresariales, que podrían haber dependido de la información en detrimento de la persona o podrían confiar en ella. 
  • Todas las enmiendas se documentarán en los registros de salud del individuo, incluyendo la fecha de la enmienda y un enlace o referencia a la información original. 
  1. Documentación y grabación: 
  • La documentación de todas las solicitudes, comunicaciones, decisiones y acciones relacionadas con las enmiendas de PHI será mantenida por el Oficial de Privacidad durante al menos siete años a partir de la fecha de su creación o la fecha en que fue última en vigor, lo que sea más tarde. 
  • Estos registros se mantendrán de una manera que preserve su confidencialidad y seguridad. 

Este procedimiento garantiza que New Hope CORPS siga cumpliendo con las normas HIPAA relativas a la enmienda del PHI, respetando los derechos de las personas a corregir su información sanitaria y garantizando la exactitud e integridad de los registros mantenidos por New Hope CORPS. 

 

VII. Contabilidad de las revelaciones 

New Hope CORPS mantiene registros y proporciona información sobre la información de salud protegida según lo requerido por 45 CFR 164.528. 

VIII. Safeguarding PHI 

New Hope CORPS sigue las Salvaguardias Administrativas establecidas en 45 CFR 164.308 para garantizar la confidencialidad, integridad y disponibilidad de información sanitaria electrónica protegida (ePHI). 

  1. Acuerdos asociados para empresas

Se obtienen garantías adecuadas de los asociados empresariales y subcontratistas que manejan el ePHI en nombre de New Hope CORPS, cumpliendo los requisitos de 45 CFR 164.308(b)(1) y b)(2), así como los artículos pertinentes de la Ley HITECH. 

  1. Política de sanciones

De conformidad con 45 CFR 164.308 a)(1)(ii)(C) y 164.530(e)(1), New Hope CORPS tiene una política de sanciones para hacer frente al incumplimiento de las políticas HIPAA por parte de los miembros de la fuerza de trabajo o asociados comerciales. 

Procedimiento para la aplicación de sanciones para la no conformidad de HIPAA en Nueva Esperanza CORPS 

Objetivo:
To outlined a clear and enforceable sanctions policy at New Hope CORPS for addressing non-compliance with HIPAA policies by labour members or business associates, in accordance with 45 CFR 164.308(a)(1)(ii)(C) and 164.530(e)(1). 

Alcance:
Este procedimiento se aplica a todos los miembros de la fuerza de trabajo, incluidos los empleados, voluntarios, aprendices y otras personas cuya conducta, en el desempeño del trabajo para New Hope CORPS, está bajo el control directo de New Hope CORPS, ya sean o no pagados por la organización. También se extiende a los socios comerciales si se estipula en los acuerdos asociados comerciales respectivos. 

Procedimiento: 

  1. Identificación de no cumplimiento: 
  • El incumplimiento puede identificarse mediante auditorías periódicas, exámenes de cumplimiento, sistemas de presentación de informes sobre incidentes o durante investigaciones de infracciones denunciadas. 
  • Todos los casos identificados de incumplimiento deben notificarse inmediatamente al Oficial de Privacidad designado. 
  1. Evaluación inicial: 
  • El Oficial de Privacidad realiza una evaluación preliminar para determinar la gravedad del incumplimiento. 
  • Si el incumplimiento implica a un socio comercial, el Oficial de Privacidad revisará los términos del acuerdo comercial asociado para determinar la respuesta adecuada. 
  1. Investigación: 
  • Se inicia una investigación oficial si la evaluación inicial indica un posible incumplimiento grave. 
  • The investigation will gather all relevant facts, including interviewing witnesses, examining relevant documents, and other necessary actions. 
  • The investigation must be impartial and thorough, aiming to conclude within an established timeframe, usually no longer than 30 days from the initiated. 
  1. Decisión sobre las sanciones: 
  • Based on the investigation findings, the Privacy Officer, in consultation with Human Resources and legal counsel if necessary, determines the appropriate sanction(s). 
  • Sanctions may range from written warnings to termination of employment or contract, depending on the severity of the violation. 
  • Factors considered in determining sanctions include the nature and extent of the harm resulting from the violation, the history of previous violations by the individual or entity, and whether the violation was intentional or unintentional. 
  1. Implementation of Sanctions: 
  • Sanctions are promptly implemented according to the decision. 
  • In cases involving business associates, actions may include modification of the contract terms, suspension of services, or termination of the agreement, as stipulated in the business associate agreement. 
  1. Notification and Documentation: 
  • The individual or entity subject to sanctions will be notified in writing of the decision and the reasons for the sanctions. 
  • All decisions and actions related to sanctions will be documented, including the rationale for the level of sanction applied. These documents will be retained for a minimum of six years from the date of the sanction implementation. 
  1. Appeal Process: 
  • The sanctioned party has the right to appeal the decision. The appeal must be submitted in writing to the Privacy Officer within 15 days of receiving the sanction notification. 
  • The appeal will be reviewed by a panel composed of the Privacy Officer, a representative from Human Resources, and another senior management member not involved in the initial decision. 
  • The decision of the appeal panel is final and will be communicated to the appellant within 30 days of the appeal submission. 
  1. Training and Awareness: 
  • All workforce members and relevant business associates are trained on this sanctions policy as part of their initial training and through annual refresher courses. 
  • This training emphasizes the importance of compliance with HIPAA regulations and the consequences of non-compliance. 

This procedure ensures that New Hope CORPS maintains a robust compliance environment that addresses and corrects HIPAA non-compliance effectively, thereby protecting the privacy and security of all protected health information handled by the organization. 

 

  1. Security Management

New Hope CORPS has appointed a Security Official responsible for the development and implementation of policies and procedures required by 45 CFR 164 Subpart C. The appointed security official is: 

James Doughterty, BA
Director of Operations
New Hope CORPS
1020 N Krome Avenue
homestead, Florida 33030
Tel 786-243-1003 Ext 217 

XII. Risk Analysis and Management 

Consistent with 45 CFR 164.308(a)(1)(ii)(A) and (B), New Hope CORPS conducts thorough risk analyses and implements security measures to mitigate identified risks as outlined in its plan. 

XIII. Facility and Technical Safeguards 

New Hope CORPS implements Physical and Technical Safeguards as per 45 CFR 164.310 and 164.312 to protect ePHI. 

XIV. Notice of Privacy Practices 

New Hope CORPS provides a Notice of Privacy Practices that meets the content requirements of 45 CFR 164.520(b) and is made available to individuals per 45 CFR 164.520(c). 

  1. Amendments to the Policy

New Hope CORPS reserves the right to amend this policy and will provide individuals with a revised notice. 

Contact Information for Privacy Concerns: 

Privacy Official: Maritza Carvajal
Tel 786-243-1003 Ext 223
email: mcarvajal@newhopecorp.org 

XVI. Individual Rights 

New Hope CORPS acknowledges and upholds individual rights under HIPAA, including but not limited to: 

  • The right to request restrictions on uses and disclosures of PHI (45 CFR 164.520(b)(1)(iv)(A)). 
  • The right to receive confidential communications (45 CFR 164.520(b)(1)(iv)(B)). 
  • The right to inspect and copy PHI (45 CFR 164.520(b)(1)(iv)(C)). 
  • The right to amend PHI (45 CFR 164.520(b)(1)(iv)(D)). 
  • The right to receive an accounting of disclosures (45 CFR 164.520(b)(1)(iv)(E)). 

XVII. Notice of Privacy Practices 

New Hope CORPS’s Notice of Privacy Practices: 

  • Is written in plain language (45 CFR 164.520(b)(1)). 
  • Includes all required elements as listed in the CFR and as pertains to New Hope CORPS. 
  • Is available upon request and prominently posted and available at service delivery sites (45 CFR 164.520(c)(2)(iii)(A) and (B)). 

XVIII. Changes to Privacy Practices 

New Hope CORPS reserves the right to change its privacy practices as stated in the notice (45 CFR 164.520(b)(1)(v)©). 

XIX. Filing Complaints 

Individuals may file complaints directly with New Hope CORPS or with the Secretary of the U.S. Department of Health and Human Services if they believe their privacy rights have been violated. New Hope CORPS will not retaliate against anyone for filing a complaint (45 CFR 164.520(b)(1)(vi)). 

  1. Contact Information for Filing Complaints

For further information or to file a complaint, please contact:
Privacy Official: Maritza Carvajal
1020 N Krome Avenue
Homestead, FL 33030
Tel 786-243-1003 Ext 223
email: mcarvajal@newhopecorp.org 

 

XXI. Effective Date and Notice 

New Hope CORPS will alert individuals to any policy changes and provide them with the updated policy as required (45 CFR 164.520(b)(1)(viii)). 

XXII. Documentation and Record Retention 

New Hope CORPS will maintain all records related to its HIPAA compliance efforts, including training documentation, complaint records, and policies and procedures updates. All documentation will be retained for the time period required by law, which is typically six years from the date of its creation or the date when it last was in effect, whichever is later (45 CFR 164.530(j)). 

XXIII. Data Breach Procedures 

In accordance with 45 CFR 164.410 and the Business Associate Agreement Section 3.b.(ii), New Hope CORPS has implemented the following policies and procedures to report any unauthorized use or disclosure of PHI. In case of a breach, New Hope CORPS will notify affected individuals, the Secretary of Health and Human Services, licensing body, funding sources and potentially, the media, in a manner consistent with the law and without unreasonable delay. 

 

These Data Breach Policies and Procedures are established to comply with the Health Insurance Portability and Accountability Act (HIPAA) regulations, particularly 45 CFR 164.410, the Business Associate Agreement with SFBHN, and Standard Contract ME225-XX-37. They outline the steps New Hope will take to identify, report, and mitigate potential or actual breaches of protected health information (PHI). Definitions 

  • Breach: The unauthorized acquisition, access, use, or disclosure of PHI. 
  • Potential Breach: An event that poses a risk of unauthorized access to PHI. 

Identifying a Breach New Hope shall implement these procedures to detect and investigate potential or actual breaches of PHI. This may include: 

  • Regular security risk assessments 
  • Monitoring system activity logs 
  • Employee training to identify and report suspicious activity. 
  • Receiving reports from individuals suspecting a breach 

Reporting a Breach In the event of a suspected or confirmed breach, New Hope will take the following actions: 

  1. Internal Notification: 
  • Immediately notify internal personnel, including the Security Officer, Privacy Officer, and relevant managers. 
  • Initiate an investigation to determine the nature and scope of the breach. 
  1. Reporting to SFBHN: 
  • Notify the SFBHN Security Officer, Privacy Officer, and Contract Manager within four (4) business days of determining a potential or actual breach. 
  • The notification will include details of the breach, including the date, affected individuals (if known), and the steps New Hope is taking to mitigate the breach. 
  1. Notification to Department of Health and Human Services (HHS): 
  • New Hope will follow the Department of Health and Human Services (HHS) guidelines to determine if notification to HHS is required. 
  • If HHS notification is required, New Hope will notify the SFBHN Privacy Officer and Contract Manager within twenty-four (24) hours of receiving notification from HHS. 
  1. Notification to Affected Individuals: 
  • If the breach affects a significant number of individuals (as defined by HHS regulations), New Hope will provide written notification to the affected individuals within thirty (30) days of determining the breach. 
  • The notification will explain the nature of the breach, the affected information, steps individuals can take to protect themselves, and contact information for New Hope. 

Mitigation Procedures New Hope will take steps to mitigate any potential harm caused by a breach. This may include: 

  • Resetting passwords or access codes 
  • Offering credit monitoring or identity theft protection services to affected individuals. 
  • Implementing additional security measures to prevent future breaches. 

Subcontractor Requirements New Hope will require all subcontractors to comply with these Data Breach Policies and Procedures. This will be achieved through contractual agreements that require subcontractors to: 

  • Implement procedures to identify and report breaches. 
  • Notify New Hope of any breaches involving New Hope data. 
  • Cooperate with New Hope’s breach response efforts. 

Training New Hope will provide regular training to all employees on HIPAA regulations and these Data Breach Policies and Procedures. The training will emphasize the importance of protecting PHI and how to identify and report potential breaches. Review and Updates New Hope will periodically review and update these Data Breach Policies and Procedures to ensure they remain compliant with HIPAA regulations and best practices. Recordkeeping New Hope will maintain records of all breaches, including the nature of the breach, the affected individuals, the actions taken to mitigate the breach, and any communications with SFBHN or HHS. 

By implementing these Data Breach Policies and Procedures, New Hope is committed to protecting the privacy and security of PHI. We will take all necessary steps to identify, report, and mitigate any potential or actual breaches of PHI. 

XXIV. Mitigation of Harm 

In the event of a use or disclosure of PHI that is in violation of the policy, New Hope CORPS will mitigate, to the extent practicable, any harmful effect that is known. This includes taking immediate corrective actions to prevent further unauthorized use or disclosure and addressing any harmful consequences that may have occurred as a result of the breach (Business Associate Agreement, Amendment. 3. Section 3.d.). 

 

XXV. Privacy Policy Notice Distribution 

New Hope CORPS shall provide the Notice of Privacy Practices to all individuals at the first service delivery and upon request. The notice will also be posted on the New Hope CORPS website to ensure accessibility (45 CFR 164.520(c)(2)(iii)(A) and (B)). 

XXVI. Updates to Privacy Policy 

New Hope CORPS acknowledges its duty to maintain up-to-date privacy policies. If New Hope CORPS decides to revise its privacy practices, the changes will be effective for all PHI that it maintains. Individuals will be informed of any significant changes to the policies through a revised notice that will be made available upon request and on the New Hope CORPS website (45 CFR 164.520(b)(1)(v)(C)). 

XXVII. Policy Availability and Acknowledgment 

A copy of this policy and any subsequent revisions shall be available to all members of the workforce, individuals receiving services, and other stakeholders as applicable. Acknowledgment of receipt of this policy will be documented for each individual served upon the first service delivery or enrollment. 

XXVIII. Oversight and Enforcement 

New Hope CORPS’s Privacy Officer is responsible for ongoing oversight and enforcement of the HIPAA Privacy Policy. This includes periodic risk assessments, monitoring compliance with the privacy practices, and ensuring that any privacy issues are resolved in accordance with the established procedures. 

XXIX. Relations with Business Associates 

New Hope CORPS ensures that all business associates who handle PHI on behalf of the organization agree to the same restrictions and conditions that apply to the organization regarding such information, as stipulated in 45 CFR 164.504(e) and the HITECH Act. 

XXX. Governing Law 

This HIPAA Privacy Policy shall be governed by and construed in accordance with federal HIPAA standards, state privacy laws, and any other applicable regulations. Should any conflict arise between state and federal laws, the law that provides the greater protection for PHI will be followed. 

New Hope CORPS is committed to upholding the privacy and security of PHI and to adhering to the requirements set forth by HIPAA and the HITECH Act. This policy will be reviewed annually or upon the enactment of significant regulatory changes, and training will be provided to all members of the workforce to ensure continued compliance.