How to Handle PHI with Care
Course Video Preview
Penalties for Violating HIPAA RulesCourse Description
The HIPAA training for healthcare helps in understanding and correctly applying requirements related to the Health Insurance Portability and Accountability Act (HIPAA). This online HIPAA training is critical for any organization collecting, using, handling, and storing Personal Health Information.Key Concepts
- What is HIPAA and what does it attempt to do?
- What are covered entities, business associates, and sub-business associates?
- What is PHI and ePHI?
- What is the Privacy Rule and what does it require?
- Patient access to health records
- What is the Security Rule and what does it require?
- Security incidents and HIPAA violations
- Reporting requirements
- The role of state laws
- Common violations and precautions
Course Features
- Access to our Anonymous Ask the Expert tool
- Rich video scenarios based on real-world events
- Built-in employee sentiment surveys
- 50+ Machine Translation Options
- Optional program timer
- Policy acknowledgement tool
- Extensive customization options
Lessons
Introduction
What Is HIPAA?
PHI or Not?
Who Is Subject to HIPAA?
The Privacy Rule
Understanding the Privacy Rule
Patient Records
The Security Rule
The Role of State Laws in HIPAA
Security Incidents and Breaches
Reporting Requirements Under HIPAA
Common Violations and Precautions
Penalties
Our Policy and Reporting
Post-Program Survey
Relevant Courses
Complementary Microlessons
Recommended Resources
From ‘Ask the Expert’
Emtrain’s Ask the Expert feature enables users to ask questions about compliance, bias, harassment, and diversity & inclusion as they come up. It’s all confidential, and answers are sent straight to their inbox. View some of the example questions below and see the Experts answers.
Q
What is the HIPAA Omnibus Rule and why is it important?
Thanks for asking. The HIPAA Omnibus Rule updated the original law to strengthen privacy and security protections for health information. It expanded responsibilities for business associates, increased patients’ rights to access their data, and raised penalties for non-compliance.
Q
How often do covered entities and business associates need to update compliance programs?
Good question. HIPAA doesn’t set an exact schedule, but compliance programs should be reviewed regularly — at least annually, and any time there are major regulatory changes or new risks. Continuous updates help keep policies and safeguards effective.
Q
What should I do if I suspect a HIPAA violation at work?
If you see or suspect a violation, report it immediately to your compliance officer, HR, or through your company’s reporting process. Don’t try to fix it yourself. Quick reporting helps the organization investigate and address the issue properly.
Q
How should employees handle personal health information (PHI) on mobile devices?
PHI should only be accessed on devices with proper security — like encryption, passwords, and company-approved apps. Don’t save PHI in text messages or personal email. If your device is lost or stolen, report it right away.
Q
What are examples of improper disposal of PHI?
Throwing medical records in regular trash, recycling PHI documents without shredding, or discarding unencrypted devices with patient data are all improper. HIPAA requires that PHI be destroyed or wiped in a way that it can’t be reconstructed.
