Ohio Administrative Code
Title 3364 - University of Toledo
Chapter 3364-15 - HIPAA Organizational Structure; Fraud, Waste and Abuse; Compliance and Confidentiality of Patient Information
Section 3364-15-01 - HIPAA organizational structure and administrative responsibilities
Current through all regulations passed and filed through September 16, 2024
(A) Policy statement
The university of Toledo(UToledo)) and the university of Toledo physicians, LLC, (UTP") have a long-standing commitment to protect the confidentiality, integrity and availability of identifiable patient health information (PHI) by taking reasonable and appropriate steps to address the requirements of the Health Insurance Portability and Accountability Act (HIPAA) of 1996, as amended by the health information technology for Economic and Clinical Health Act (HITECH Act), and the privacy and security regulations.
(B) The purpose of this policy:
(C) Scope
This policy applies to UTP affiliated covered entity (ACE) and all UToledo health care components (hybrid) and their respective workforce members. Health care components are designated routinely by the privacy and security committee. Health care components are on UToledo privacy website and include the health science campus, the university of Toledo medical center (UTMC), the student health center, and designated departments of the main campus that perform HIPAA covered functions. A reference in this policy to the covered entity refers to UTP ACE and the designated components of UToledo hybrid.
(D) Designation as a hybrid entity:
Although UToledo is a single legal entity, the covered entity must treat units not designated as part of the covered entity as an external entity with respect to uses and disclosures of protected health information (PHI).
If a person performs duties for both the covered entity and for another unit of the university such workforce member must not use or disclose PHI created or received in the course of or incident to the member's work for the covered entity.
(E) Designation as ACE
(F) Administrative responsibility:
The committee will operate under a charter approved by the committee. The committee will be chaired by the privacy officer and the information security officer. Other members will be designated from time to time by the privacy officer and approved by existing members.
Develops procedures including certification, incident response and reporting, contingency planning, documented policies and procedures and training;
(G) Standards for electronic transactions
UToledo ACE must electronically bill using the standardized formats, codes, and data elements and comply with the rules governing such transactions.
(H) Workforce members
Workforce members of UToledo ACE means employees, volunteers, trainees, and other persons whose conduct, in the performance of work for a covered entity, is under the direct control of such covered entity, whether or not they are paid by the covered entity.
(I) UToledo ACE workforce members and employees who conduct business on the health science campus who have access or may be exposed to PHI will complete online HIPAA training. Business associates who need to access electronic PHI will follow all business associate agreement terms and conditions.
All UToledo ACE workforce members must complete HIPAAprivacy and security training within thirty days of date from hire and annually thereafter.
(J) Violation of policy or procedures:
The failure of a workforce member to comply with this policy or any UToledo policy or procedure that relates to HIPAA or IT security will be grounds for discipline under the applicable disciplinary policies or collective bargaining agreement. These disciplinary proceedings shall not apply to workforce member "whistleblower" activities, crime victims or complaints, investigations or opposition as set forth in the applicable regulations. The UToledo ACE must document any sanctions applied under the disciplinary policies or collective bargaining agreements.
(K) Monitoring/auditing
Monitoring/auditing of compliance with UToledo policies relating to HIPAA privacy and security will be performed to assure compliance with HIPAA privacy and security regulations.
UT