CINXE.COM

Compliance Information | Health Insurance Portability and Accountability Act

<!DOCTYPE html> <!--[if lte IE 8]> <html lang="en" dir="ltr" class="ie8"> <![endif]--> <!--[if gt IE 8]><!--> <html lang="en" dir="ltr" prefix="content: http://purl.org/rss/1.0/modules/content/ dc: http://purl.org/dc/terms/ foaf: http://xmlns.com/foaf/0.1/ og: http://ogp.me/ns# rdfs: http://www.w3.org/2000/01/rdf-schema# sioc: http://rdfs.org/sioc/ns# sioct: http://rdfs.org/sioc/types# skos: http://www.w3.org/2004/02/skos/core# xsd: http://www.w3.org/2001/XMLSchema#"> <!--<![endif]--> <head> <meta http-equiv="X-UA-Compatible" content="IE=edge"> <!-- GGGGGGGGGGGG GGGGGGGGGGG fGGGGGG ;GGGGG. GGGi GGGG CGGGG: GGG GGGG lGGGGt GGL GGGG .GGGGC GG: GGGG GGGGG .GG. ;CGGGGGGL GGGG .LGGGGGGGL GGGGG iGG GGG: ,GGGG GGGG tGGf ;GGGC LGGGGfGG GGGG CGGG; GGGG GGGL GGGGt lGGGGL CGGG; GGGG CGGGCCCCCCCCCCCCC GGGG GGGG, GGGG GGGG GGGG tCGG; CGGG, GGGG GGGG GGGG GGGG CGGG. GGGG GGGGL GGGG GGGGC CGGG. GGGG :GGGGC : ,GGGGG. GGGGG: .LGGGGG,.tG GGGG GGGGGGt,..,fGC ,GGGGGGGGGGGGGGf iGGGGGG CGGGGC GGGGGGGGGG LGGGGGGGC --> <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> <meta name="Generator" content="Drupal 7 (http://drupal.org)" /> <link rel="canonical" href="/security/breach-prevention/compliance-information" /> <link rel="shortlink" href="/node/99" /> <link rel="shortcut icon" href="https://hipaa.yale.edu/misc/favicon.ico" type="image/vnd.microsoft.icon" /> <meta name="viewport" content="width=device-width, initial-scale=1, maximum-scale=10, minimum-scale=1, user-scalable=yes" /> <title>Compliance Information | Health Insurance Portability and Accountability Act</title> <!--[if IEMobile]><meta http-equiv="cleartype" content="on" /><![endif]--> <link rel="shortcut icon" sizes="16x16 24x24 32x32 48x48 64x64" href="/sites/all/themes/yalenew_base/images/favicon.ico" type="image/vnd.microsoft.icon"> <link rel="icon" sizes="228x228" href="/sites/all/themes/yalenew_base/images/touch-icon-228.png"> <link rel="apple-touch-icon-precomposed" sizes="228x228" href="/sites/all/themes/yalenew_base/images/touch-icon-228.png"> <link type="text/css" rel="stylesheet" href="https://hipaa.yale.edu/sites/default/files/css/css_xE-rWrJf-fncB6ztZfd2huxqgxu4WO-qwma6Xer30m4.css" media="all" /> <link type="text/css" rel="stylesheet" href="https://hipaa.yale.edu/sites/default/files/css/css_tmLW2XUIUfo7avAdmlR9Y5csxfSrCZwNNfiVQCd0_Q0.css" media="all" /> <link type="text/css" rel="stylesheet" href="https://hipaa.yale.edu/sites/default/files/css/css_Ok1DDBVnqQ9-KgI-AMFE7nF2PlBEvlT_SeSUVL08ZBw.css" media="all" /> <link type="text/css" rel="stylesheet" href="//maxcdn.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.css" media="all" /> <link type="text/css" rel="stylesheet" href="https://hipaa.yale.edu/sites/default/files/css/css_SbupwLY96NaCH1HAe9Sy9EfHqQ1Kyj0Oq1Ed_4OscR4.css" media="all" /> <link type="text/css" rel="stylesheet" href="https://hipaa.yale.edu/sites/default/files/css_injector/css_injector_1.css?s9hdlu" media="all" /> <link type="text/css" rel="stylesheet" href="https://hipaa.yale.edu/sites/default/files/css_injector/css_injector_2.css?s9hdlu" media="all" /> <link type="text/css" rel="stylesheet" href="https://hipaa.yale.edu/sites/default/files/css_injector/css_injector_3.css?s9hdlu" media="all" /> <link type="text/css" rel="stylesheet" href="https://hipaa.yale.edu/sites/default/files/css_injector/css_injector_6.css?s9hdlu" media="all" /> <!--[if (lt IE 9)&(!IEMobile)]> <link type="text/css" rel="stylesheet" href="https://hipaa.yale.edu/sites/default/files/css/css_nBvgsRGFO8eRuGybs3zqi1R0F_76QazEf5KpSL9kQhA.css" media="all" /> <![endif]--> <!--[if gte IE 9]><!--> <link type="text/css" rel="stylesheet" href="https://hipaa.yale.edu/sites/default/files/css/css_059BxwQdO3W6gC_prw0ohrQj1fWv8MiFJkqt4YP0qJk.css" media="all" /> <!--<![endif]--> <script type="text/javascript" src="https://hipaa.yale.edu/sites/all/libraries/respondjs/respond.min.js?s9hdlu"></script> <script type="text/javascript"> <!--//--><![CDATA[//><!-- document.cookie = 'adaptive_image=' + Math.max(screen.width, screen.height) + '; path=/'; //--><!]]> </script> <script type="text/javascript" src="//ajax.googleapis.com/ajax/libs/jquery/1.8.3/jquery.min.js"></script> <script type="text/javascript"> <!--//--><![CDATA[//><!-- window.jQuery || document.write("<script src='/sites/all/modules/contrib/jquery_update/replace/jquery/1.8/jquery.min.js'>\x3C/script>") //--><!]]> </script> <script type="text/javascript" src="https://hipaa.yale.edu/sites/default/files/js/js_Hfha9RCTNm8mqMDLXriIsKGMaghzs4ZaqJPLj2esi7s.js"></script> <script type="text/javascript" src="https://hipaa.yale.edu/sites/default/files/js/js_WwwX68M9x5gJGdauMeCoSQxOzb1Ebju-30k5FFWQeH0.js"></script> <script type="text/javascript" src="https://hipaa.yale.edu/sites/default/files/js/js_oAfqXa2DIpUo7OsSlNsm_nI5oFs7NL4fMl1iZhnW5K8.js"></script> <script type="text/javascript" src="https://hipaa.yale.edu/sites/default/files/js/js_DTAfYFrWdyPCGwWtVg2VmSbP1KqFAlfZyeAcFZTbiNY.js"></script> <script type="text/javascript" src="https://www.googletagmanager.com/gtag/js?id=UA-9112073-12"></script> <script type="text/javascript"> <!--//--><![CDATA[//><!-- window.dataLayer = window.dataLayer || [];function gtag(){dataLayer.push(arguments)};gtag("js", new Date());gtag("set", "developer_id.dMDhkMT", true);gtag("config", "UA-9112073-12", {"groups":"default","cookie_domain":"hipaa.yale.edu","anonymize_ip":true}); //--><!]]> </script> <script type="text/javascript" src="https://hipaa.yale.edu/sites/default/files/js/js_UNPtX_ZGxcpSkJyp8ls50mHCG5a_tcqRFqN4KjkfLso.js"></script> <script type="text/javascript"> <!--//--><![CDATA[//><!-- jQuery.extend(Drupal.settings, {"basePath":"\/","pathPrefix":"","setHasJsCookie":0,"ajaxPageState":{"theme":"yalenew_standard","theme_token":"nhQiH_ZuVJ_V-6GklQwaa_UTFPbqkZCmaaNL-zWPXqY","js":{"0":1,"sites\/all\/themes\/yalenew_base\/js\/jcaption.min.js":1,"sites\/all\/libraries\/respondjs\/respond.min.js":1,"1":1,"\/\/ajax.googleapis.com\/ajax\/libs\/jquery\/1.8.3\/jquery.min.js":1,"2":1,"misc\/jquery-extend-3.4.0.js":1,"misc\/jquery-html-prefilter-3.5.0-backport.js":1,"misc\/jquery.once.js":1,"misc\/drupal.js":1,"sites\/all\/modules\/contrib\/jquery_update\/replace\/ui\/external\/jquery.cookie.js":1,"misc\/form-single-submit.js":1,"sites\/all\/modules\/contrib\/collapsiblock\/collapsiblock.js":1,"sites\/all\/libraries\/superfish\/sfsmallscreen.js":1,"sites\/all\/libraries\/colorbox\/jquery.colorbox-min.js":1,"sites\/all\/modules\/contrib\/colorbox\/js\/colorbox.js":1,"sites\/all\/modules\/contrib\/jscrollpane\/js\/jquery.jscrollpane.min.js":1,"sites\/all\/modules\/contrib\/jscrollpane\/js\/jquery.mousewheel.js":1,"sites\/all\/modules\/contrib\/jscrollpane\/js\/script.js":1,"sites\/all\/modules\/contrib\/custom_search\/js\/custom_search.js":1,"sites\/all\/modules\/contrib\/google_analytics\/googleanalytics.js":1,"https:\/\/www.googletagmanager.com\/gtag\/js?id=UA-9112073-12":1,"3":1,"sites\/all\/themes\/omega\/omega\/js\/jquery.formalize.js":1,"sites\/all\/themes\/omega\/omega\/js\/omega-mediaqueries.js":1,"sites\/all\/themes\/yalenew_base\/js\/modernizr.min.js":1,"sites\/all\/themes\/yalenew_base\/js\/jquery.fitted.js":1,"sites\/all\/themes\/yalenew_base\/js\/appendAround.min.js":1,"sites\/all\/themes\/yalenew_base\/js\/scripts.js":1},"css":{"modules\/system\/system.base.css":1,"modules\/system\/system.menus.css":1,"modules\/system\/system.messages.css":1,"modules\/system\/system.theme.css":1,"sites\/all\/modules\/contrib\/adaptive_image\/css\/adaptive-image.css":1,"modules\/book\/book.css":1,"sites\/all\/modules\/contrib\/calendar\/css\/calendar_multiday.css":1,"sites\/all\/modules\/contrib\/collapsiblock\/collapsiblock.css":1,"modules\/comment\/comment.css":1,"modules\/field\/theme\/field.css":1,"modules\/node\/node.css":1,"modules\/search\/search.css":1,"modules\/user\/user.css":1,"sites\/all\/modules\/contrib\/views\/css\/views.css":1,"sites\/all\/modules\/contrib\/ckeditor\/css\/ckeditor.css":1,"sites\/all\/libraries\/colorbox\/example4\/colorbox.css":1,"sites\/all\/modules\/contrib\/ctools\/css\/ctools.css":1,"sites\/all\/modules\/contrib\/jscrollpane\/css\/jquery.jscrollpane.css":1,"sites\/all\/modules\/contrib\/panels\/css\/panels.css":1,"sites\/all\/modules\/contrib\/typogrify\/typogrify.css":1,"sites\/all\/modules\/contrib\/custom_search\/custom_search.css":1,"\/\/maxcdn.bootstrapcdn.com\/font-awesome\/4.7.0\/css\/font-awesome.min.css":1,"sites\/all\/themes\/omega\/omega\/css\/formalize.css":1,"sites\/default\/files\/fontyourface\/font.css":1,"\/sites\/all\/libraries\/fontyourface\/YaleDesign-italic-bold\/stylesheet.css":1,"\/sites\/all\/libraries\/fontyourface\/YaleDesign-italic-normal\/stylesheet.css":1,"\/sites\/all\/libraries\/fontyourface\/YaleDesign-normal-bold\/stylesheet.css":1,"\/sites\/all\/libraries\/fontyourface\/YaleDesign-normal-normal\/stylesheet.css":1,"sites\/all\/themes\/yalenew_base\/css\/globalnew.css":1,"public:\/\/css_injector\/css_injector_1.css":1,"public:\/\/css_injector\/css_injector_2.css":1,"public:\/\/css_injector\/css_injector_3.css":1,"public:\/\/css_injector\/css_injector_6.css":1,"ie::wide::sites\/all\/themes\/yalenew_base\/css\/grid\/yalenew_default\/wide\/yalenew-default-wide-12.css":1,"sites\/all\/themes\/yalenew_base\/css\/grid\/yalenew_default\/fluid\/yalenew-default-fluid-12.css":1,"sites\/all\/themes\/yalenew_base\/css\/grid\/yalenew_default\/narrow\/yalenew-default-narrow-12.css":1,"sites\/all\/themes\/yalenew_base\/css\/grid\/yalenew_default\/wide\/yalenew-default-wide-12.css":1}},"collapsiblock":{"blocks":{"block-block-5":"1","block-block-4":"1","block-block-6":"1","block-block-1":"1","block-menu-menu-banner-menu":"1","block-block-9":"1","block-menu-block-10":"1","block-views-59a6af7bce39080c77fa404ccf10ac34":"1","block-block-7":"1","block-block-8":"1","block-block-10":"3","block-block-11":"3","block-block-12":"3","block-block-13":"3","block-block-14":"3","block-block-15":"3","block-block-16":"1","block-block-19":"1","block-block-20":"3","block-block-21":"3","block-block-22":"3","block-block-23":"3","block-block-24":"3","block-block-25":"3","block-block-26":"1","block-block-27":"3","block-block-28":"3","block-block-29":"3","block-block-30":"3","block-block-31":"1","block-block-17":"1","block-block-32":"1","block-block-33":"1","block-block-34":"1","block-block-35":"1","block-block-36":"3","block-block-40":"1","block-block-37":"1","block-menu-block-9":"1","block-block-46":"3","block-block-41":"1","block-block-44":"2","block-block-45":"3","block-block-47":"3","block-block-48":"3","block-block-50":"3","block-block-51":"3","block-block-52":"3","block-block-53":"3","block-block-54":"3","block-block-55":"3","block-block-56":"3","block-block-57":"3","block-block-58":"3","block-block-59":"3","block-block-60":"3","block-block-61":"3","block-block-62":"3","block-block-63":"3","block-block-64":"3","block-block-65":"3","block-block-66":"3","block-block-67":"3","block-block-68":"3","block-block-69":"3","block-block-70":"3","block-block-71":"3","block-block-72":"3","block-block-73":"3","block-block-74":"3","block-block-76":"3","block-block-77":"3","block-block-78":"3","block-block-79":"3","block-block-80":"3","block-block-81":"3","block-block-82":"3","block-block-83":"3","block-block-84":"3","block-block-85":"3","block-block-86":"1","block-block-87":"1","block-block-91":"3","block-block-96":"3","block-system-user-menu":"1","block-menu-menu-secondary-menu":"1","block-block-97":"1"},"default_state":1,"slide_type":1,"slide_speed":200,"block_title":":header:first","block":"div.block","block_content":"div.content"},"colorbox":{"opacity":"0.85","current":"{current} of {total}","previous":"\u00ab Prev","next":"Next \u00bb","close":"Close","maxWidth":"98%","maxHeight":"98%","fixed":true,"mobiledetect":true,"mobiledevicewidth":"480px","specificPagesDefaultValue":"admin*\nimagebrowser*\nimg_assist*\nimce*\nnode\/add\/*\nnode\/*\/edit\nprint\/*\nprintpdf\/*\nsystem\/ajax\nsystem\/ajax\/*"},"jScrollPane":{"class":".scroll-pane"},"custom_search":{"form_target":"_self","solr":0},"googleanalytics":{"account":["UA-9112073-12"],"trackOutbound":1,"trackMailto":1,"trackDownload":1,"trackDownloadExtensions":"7z|aac|arc|arj|asf|asx|avi|bin|csv|doc(x|m)?|dot(x|m)?|exe|flv|gif|gz|gzip|hqx|jar|jpe?g|js|mp(2|3|4|e?g)|mov(ie)?|msi|msp|pdf|phps|png|ppt(x|m)?|pot(x|m)?|pps(x|m)?|ppam|sld(x|m)?|thmx|qtm?|ra(m|r)?|sea|sit|tar|tgz|torrent|txt|wav|wma|wmv|wpd|xls(x|m|b)?|xlt(x|m)|xlam|xml|z|zip","trackColorbox":1,"trackDomainMode":1},"urlIsAjaxTrusted":{"\/security\/breach-prevention\/compliance-information":true},"omega":{"layouts":{"primary":"wide","order":["fluid","narrow","wide"],"queries":{"fluid":"all and (max-width: 739px)","narrow":"all and (min-width: 740px) and (max-width: 1024px)","wide":"all and (min-width: 1025px)"}}}}); //--><!]]> </script> </head> <body class="html not-front not-logged-in page-node page-node- page-node-99 node-type-page yalenew-standard context-security two-sidebars nav-carbon block-carbon nav-serif block-font-serif block-outline"> <aside role='complementary' id="skip-link" aria-label="Skip to main content"> <a href="#main-content" class="element-invisible element-focusable">Skip to main content</a> </aside> <div class="region region-page-top" id="region-page-top"> <div class="region-inner region-page-top-inner"> </div> </div> <div class="page clearfix" id="page"> <header id="section-header" class="section section-header" role="banner"> <div id="zone-topper-wrapper" class="zone-wrapper zone-topper-wrapper clearfix yalenew-standard-topper"> <div id="zone-topper" class="zone zone-topper clearfix container-12"> <div class="grid-3 region region-topper-first" id="region-topper-first"> <div class="region-inner region-topper-first-inner"> <div class="topper-logo"><a href="http://www.yale.edu" class="y-icons y-yale y-univ"><span class="element-invisible">Yale University</span></a> </div> <div id="moved-main-nav-wrapper"> <button aria-expanded="false" id="nav-ready" class="nav-ready"><span class="element-invisible">Open Main Navigation</span></button> <div id="moved-main-nav" class="moved-main-nav" data-set="append-main-nav"></div> <button aria-expanded="true" id="nav-close" class="nav-close nav-hidden"><span class="element-invisible">Close Main Navigation</span></button> </div> </div> </div> <div class="grid-9 region region-topper-second" id="region-topper-second"> <div class="region-inner region-topper-second-inner"> <div class="block block-search block-form block-search-form odd block-without-title" id="block-search-form"> <div class="block-inner clearfix"> <div class="content clearfix"> <form class="search-form" role="search" aria-label="Site Search" action="/security/breach-prevention/compliance-information" method="post" id="search-block-form" accept-charset="UTF-8"><div><div class="container-inline"> <div class="form-item form-type-textfield form-item-search-block-form"> <label for="edit-search-block-form--2"><i class="fa fa-search"></i><span class="element-invisible">Search this site<span> </label> <input title="Enter the terms you wish to search for." class="custom-search-box form-text" placeholder="Search this site" type="text" id="edit-search-block-form--2" name="search_block_form" value="" size="15" maxlength="128" /> </div> <div class="form-actions form-wrapper" id="edit-actions"><input style="display:none;" type="submit" id="edit-submit" name="op" value="" class="form-submit" /></div><input type="hidden" name="form_build_id" value="form-lLAVx6TNSnDbsCOWJNtolFzVIbKykkHZt_2sHXTQ0J4" /> <input type="hidden" name="form_id" value="search_block_form" /> </div> </div></form> </div> </div> </div> <div class="block block-menu block-menu-secondary-menu block-menu-menu-secondary-menu even block-without-title" id="block-menu-menu-secondary-menu"> <div class="block-inner clearfix"> <div class="content clearfix"> <ul class="menu"><li class="first last leaf menu-contact-us"><a href="/contact-us"><span>Contact Us</span></a></li> </ul> </div> </div> </div> </div> </div> </div> </div><div id="zone-branding-wrapper" class="zone-wrapper zone-branding-wrapper clearfix"> <div id="zone-branding" class="zone zone-branding clearfix container-12"> <div class="grid-10 region region-branding" id="region-branding"> <div class="region-inner region-branding-inner"> <div class="branding-data clearfix"> <h2 class="site-name"><a href="/" title="Home">Health Insurance Portability and Accountability Act </a></h2> </div> </div> </div> </div> </div></header> <main id="section-content" class="section section-content" role="main"> <div id="section-content-inner"> <div id="zone-menu-wrapper" class="zone-wrapper zone-menu-wrapper clearfix"> <div id="zone-menu" class="zone zone-menu clearfix yale-standard-menu container-12"> <div id="original-main-nav-wrapper"> <div id="original-main-nav" data-set="append-main-nav"> <div id="main-nav"> <div class="grid-12 region region-menu" id="region-menu"> <div class="region-inner region-menu-inner"> <nav id="main-menu-navigation" role="navigation" aria-label="Main Menu" class="navigation"> <div class="block block-system block-menu block-main-menu block-system-main-menu odd block-without-title" id="block-system-main-menu"> <div class="block-inner clearfix"> <div class="content clearfix"> <ul class="menu"><li class="first leaf menu-patient-rights"><a href="/patient-rights">Patient Rights</a></li> <li class="collapsed menu-policies-&amp;-procedures"><a href="/policies-procedures-forms">Policies &amp; Procedures</a></li> <li class="collapsed menu-security"><a href="/protecting-hipaa-data">Security</a></li> <li class="expanded active-trail menu-breach-prevention"><a href="/security/breach-prevention" class="active-trail">Breach Prevention</a></li> <li class="collapsed menu-resources"><a href="/resources">Resources</a></li> <li class="last collapsed menu-training"><a href="/training">Training</a></li> </ul> </div> </div> </div> </nav> </div> </div> </div> </div> </div> </div> </div> <div id="zone-content-wrapper" class="zone-wrapper zone-content-wrapper clearfix"> <div id="zone-content" class="zone zone-content clearfix container-12"> <div id="breadcrumb" class="grid-12"><nav class="breadcrumb" role="navigation" aria-label="You are here"><a href="/">Home</a><span class="tic"> > </span><a href="/security/breach-prevention">Breach Prevention</a><span class="tic"> > </span>Compliance Information</nav></div> <div id="moved-sidenav-wrapper" class="moved-sidenav-wrapper grid-12"> <div id="moved-sidenav" class="moved-sidenav" data-set="append-sidenav"></div> </div> <div class="grid-5 push-3 region region-content" id="region-content"> <div class="region-inner region-content-inner"> <a id="main-content" tabindex="-1"></a> <h1 class="title" id="page-title">Compliance Information </h1> <div class="block block-block block-97 block-block-97 odd block-without-title" id="block-block-97"> <div class="block-inner clearfix"> <div class="content clearfix"> <hr /> </div> </div> </div> <div class="block block-system block-main block-system-main even block-without-title" id="block-system-main"> <div class="block-inner clearfix"> <div class="content clearfix"> <article about="/security/breach-prevention/compliance-information" typeof="foaf:Document" class="node node-page node-published node-not-promoted node-not-sticky author-14 odd clearfix" id="node-page-99"> <!-- --> <span property="dc:title" content="Compliance Information" class="rdf-meta element-hidden"></span><span property="sioc:num_replies" content="0" datatype="xsd:integer" class="rdf-meta element-hidden"></span> <div class="content clearfix"> <div class="field field-name-body field-type-text-with-summary field-label-hidden"><div class="field-items"><div class="field-item even" property="content:encoded"><h2>Effective date: April 30, 2012</h2> <h4>Violations and Penalties</h4> <p>In 2011, the US Department of Health and Human Services Office for Civil Rights increased HIPAA enforcement activities in accordance with HITECH mandates including issuing large penalties and settlements for noncompliance:</p> <ul> <li>Cignet Health of Prince George’s County, MD  was fined $4.3 million for denying patients access to their records and related HIPAA violations.</li> <li>Massachusetts General Hospital agreed to a $1 million settlement arising from paper records pertaining to 192 patients having been left behind on the Boston subway.</li> <li>University of California at Los Angeles agreed to a $865,000 settlement arising from inappropriate access to celebrity records by staff members.</li> <li>In the fall the US Department of Health and Human Services announced plans to audit 150 HIPAA Covered Entities over the next year for HIPAA compliance.</li> </ul> <h4>Reminders for Avoiding Violations at Yale</h4> <ul> <li>Everyone is required to report any potential breach of PHI. Some examples include: <ul> <li>Loss or theft of a laptop, external hard drive, thumb drive, or paper chart containing PHI</li> <li>Access to PHI outside of an individual’s job responsibilities</li> <li>Improper disposal of PHI such as failure to shred paper documents or securely delete electronic records prior to device disposal or re-purposing</li> <li>Misdirected mailings, emails, or faxes</li> <li>Malware infection on ePHI containing devices</li> </ul> </li> </ul> <p><strong>Potential breaches should be reported to the Security Office hotline at 203.627.4665</strong></p> <ul> <li>Health information included in any presentations or seminars other than for the purpose of patient care, must be redacted of all identifiers including names, dates, medical record numbers etc.</li> <li>PHI collected in the course of a research study is still PHI and must be handled with the same regard to privacy and security as clinical information.</li> <li>VPN should be used for any remote access to Yale PHI. <a href="https://yale.service-now.com/it?id=support_article&amp;sys_id=0a16c0a92b93e840fcb01abf59da15d6">View more information on how to use VPN.</a></li> <li>Non-Yale email services such as Gmail and Yahoo may not be used to send messages or attachments containing PHI.</li> <li>Access to systems containing PHI is subject to electronic audit and monitoring by the University to ensure compliance with University policies on appropriate use and disclosure of protected health information.</li> <li>Please keep in mind that the reminders from 2011 are still applicable and may be found below. Everyone is still required to ensure their devices are appropriately secured and to update your information as you add or discard devices.</li> </ul> <h2>Effective date: August 26, 2011</h2> <p>Yale University is committed to providing the highest quality health care, which includes respecting the right of patients and clinical research subjects to maintain the privacy and security of their health information. The standards for protecting health information are described in the federal law known as the Health Insurance Portability and Accountability Act (HIPAA). HIPAA and Yale&#8217;s HIPAA policies apply to individually identifiable information on past, present or future health care or payment for health care, which HIPAA calls “Protected Health Information” or “PHI.” PHI stored electronically is called “ePHI.”</p> <p><a href="http://https://hipaa.yale.edu/">Yale&#8217;s policies</a> are designed to ensure the appropriate privacy and security of all PHI across the University, in compliance with the law. Yale&#8217;s HIPAA policies apply to all faculty, staff, trainees, students and others in Yale&#8217;s HIPAA Covered Components: the Schools of Medicine (excluding the School of  Public Health, the Animal Resources Center, and the basic science departments: Cell Biology, Cellular and Molecular Physiology, Comparative Medicine, History of Medicine, Immunobiology, Microbial Pathogenesis, Molecular Biophysics &amp; Biochemistry, Neurobiology, Neuroscience, Pharmacology and WM Keck Biotechnology Resources Laboratory), Yale School of Nursing, Yale Health, Department of Psychology clinics and the Group Health Plan Component.</p> <p>All faculty, staff, trainees, students and others in Yale&#8217;s HIPAA Covered Components must comply with Yale University&#8217;s <a href="/security/breach-prevention/compliance-requirements">Compliance Requirements</a>.</p> </div></div></div> </div> <div class="clearfix"> <nav class="links node-links clearfix"></nav> </div> </article> </div> </div> </div> <div class="block block-block block-17 block-block-17 odd block-without-title" id="block-block-17"> <div class="block-inner clearfix"> <div class="content clearfix"> <p><strong>Please review and familiarize yourself with the <a href="/security/breach-prevention/compliance-information">Compliance Information</a> and <a href="/security/breach-prevention/compliance-requirements">Compliance Requirements</a>. You are responsible for complying with these requirements.</strong></p> <hr /> </div> </div> </div> </div> </div> <div class="grid-3 pull-5 region region-sidebar-first sidebar yale-standard-sidebar" id="region-sidebar-first"> <div class="region-inner region-sidebar-first-inner"> <div class="original-sidenav" data-set="append-sidenav"> <div id="additional-nav" class="addnav-ready"> <span class="additional-nav-button"><a id="additional-nav-button" role="button" aria-expanded="false" tabindex="0"><span class="ready">Additional Navigation</span><span class="close">Close</span></a></span> <nav class="block block-menu-block block-9 block-menu-block-9 odd has-subject" id="block-menu-block-9" role="navigation" aria-label="Breach Prevention"> <div class="block-inner clearfix"> <h2 class="block-title">Breach Prevention</h2> <div class="content clearfix"> <div class="menu-block-wrapper menu-block-9 menu-name-main-menu parent-mlid-0 menu-level-2"> <ul class="menu"><li class="first leaf active-trail active menu-mlid-714 menu-compliance-information"><a href="/security/breach-prevention/compliance-information" class="active-trail active-trail active">Compliance Information</a></li> <li class="leaf menu-mlid-1131 menu-compliance-requirements"><a href="/security/breach-prevention/compliance-requirements">Compliance Requirements</a></li> <li class="leaf menu-mlid-716 menu-advice-for-applications"><a href="/security/breach-prevention/advice-applications">Advice for Applications</a></li> <li class="leaf menu-mlid-684 menu-for-everyone"><a href="/security/breach-prevention/breach-prevention-everyone">For Everyone</a></li> <li class="leaf menu-mlid-715 menu-for-servers"><a href="/security/breach-prevention/breach-prevention-servers">For Servers</a></li> <li class="leaf menu-mlid-723 menu-safe-harbor-encryption"><a href="/security/breach-prevention/safe-harbor-encryption">Safe Harbor Encryption</a></li> <li class="leaf menu-mlid-853 menu-smartphones"><a href="https://cybersecurity.yale.edu/minimumsecuritystandards">Smartphones</a></li> <li class="last leaf menu-mlid-734 menu-workstations"><a href="https://your.yale.edu/policies-procedures/procedures/1610-pr03-network-configuration-security">Workstations</a></li> </ul></div> </div> </div> </nav> </div> </div> </div> </div> <div class="grid-4 region region-sidebar-second sidebar yale-standard-sidebar-second" id="region-sidebar-second"> <div class="region-inner region-sidebar-second-inner"> <aside class="block block-block block-4 block-block-4 odd has-subject" id="block-block-4" role="complementary" aria-label="Reporting an Incident, Lost or Stolen Data, or Device"> <div class="block-inner clearfix"> <h2 class="block-title">Reporting an Incident, Lost or Stolen Data, or Device</h2> <div class="content clearfix"> <p><a href="/sites/default/files/files/HIPAA%20Incident%20Reporting%20Form.doc">Report a Privacy Concern (paper form)</a></p> <p><a href="https://yalesurvey.qualtrics.com/SE/?SID=SV_8CCh5idmc4FFia9">Report a Privacy Concern (on-line)</a></p> <p><a href="https://cybersecurity.yale.edu/get-help/report/report-incident">Security Incident Reporting </a></p> </div> </div> </aside> </div> </div> </div> </div> </div> </main> <footer id="section-footer" class="section section-footer" role="contentinfo"> <div id="zone-footer-wrapper" class="zone-wrapper zone-footer-wrapper clearfix"> <div id="zone-footer" class="zone zone-footer clearfix container-12"> <div class="grid-2 region region-footer-first" id="region-footer-first"> <div class="region-inner region-footer-first-inner"> <div class="footer-logo"><a href="http://www.yale.edu" class="y-icons y-yale y-mark"><span class="element-invisible">Yale</span></a></div> </div> </div> <div class="grid-6 region region-footer-second" id="region-footer-second"> <div class="region-inner region-footer-second-inner"> <p class="copyright"> <a href="https://usability.yale.edu/web-accessibility/accessibility-yale">Accessibility at Yale</a> &middot; <a href="http://www.yale.edu/privacy-policy">Privacy policy</a> <br> Copyright &copy; 2025 Yale University &middot; All rights reserved </p> <div class="block block-footer-message block-footer-message block-footer-message-footer-message odd block-without-title" id="block-footer-message-footer-message"> <div class="block-inner clearfix"> <div class="content clearfix"> <p>HIPAA | PO Box 208255 | New Haven, CT 06520-8255 | <a href="&#109;&#97;&#105;&#108;&#116;&#111;&#58;&#104;&#105;&#112;&#97;&#97;&#64;&#121;&#97;&#108;&#101;&#46;&#101;&#100;&#117;">&#104;&#105;&#112;&#97;&#97;&#64;&#121;&#97;&#108;&#101;&#46;&#101;&#100;&#117;</a></p> </div> </div> </div> </div> </div> <div class="grid-4 region region-footer-third" id="region-footer-third"> <div class="region-inner region-footer-third-inner"> <div class="block block-menu sharing block-menu-social-buttons block-menu-menu-social-buttons odd block-without-title" id="block-menu-menu-social-buttons"> <div class="block-inner clearfix"> <div class="content clearfix"> <ul class="menu"><li class="first leaf menu-facebook"><a href="https://www.facebook.com/YaleUniversity" title=""><span>Facebook</span></a></li> <li class="leaf menu-twitter"><a href="http://www.twitter.com/yale" title=""><span>Twitter</span></a></li> <li class="leaf menu-flickr"><a href="http://www.flickr.com/photos/yaleuniversity" title=""><span>Flickr</span></a></li> <li class="leaf menu-itunes"><a href="http://itunes.yale.edu" title=""><span>iTunes</span></a></li> <li class="last leaf menu-youtube"><a href="http://www.youtube.com/yale" title=""><span>YouTube</span></a></li> </ul> </div> </div> </div> </div> </div> </div> </div></footer> </div> <div class="region region-page-bottom" id="region-page-bottom"> <div class="region-inner region-page-bottom-inner"> </div> </div> <script type="text/javascript"> <!--//--><![CDATA[//><!-- (function() { var sz = document.createElement('script'); sz.type = 'text/javascript'; sz.async = true; sz.src = '//siteimproveanalytics.com/js/siteanalyze_66356571.js'; var s = document.getElementsByTagName('script')[0]; s.parentNode.insertBefore(sz, s); })(); //--><!]]> </script> <script type="text/javascript" src="https://hipaa.yale.edu/sites/default/files/js/js_JMVekk522eOkII71K9F5yD4Su-iRqPdTR_-LxjPAtMk.js"></script> </body> </html>

Pages: 1 2 3 4 5 6 7 8 9 10