Correct
Fair Debt Collection Practices Act (FDCPA) mandates that Debt collectors are required to
identify themselves and notify the customer that they are attempting to collect a debt in every
conversation, advise that any information disclosed will be used to aid in collecting debt, and
notifying the consumer of their right to dispute the debt in full or in part, with the creditor
TCPA (Telephone Consumer Protection Act) Rule prohibiting telephone solicitation calls
to a residence before 8:00 am or after 9:00 pm,
regulates telemarketing calls. It also is the authority to create the National Do-Not-Call List
DNC National Do-Not-Call List
Advanced Directive (living will) document specifying the type of care wanted by the
maker in the event of an incapacitating or terminal illness
Power of Attorney (POA) legal document in which one person appoints another person to
act as an agent on his or her behalf
,CMS (Centers for Medicare and Medicaid Services) Federal agency in the Department of
Health and Human Services that runs Medicare, Medicaid, clinical laboratories, and other
government health programs; responsible for enforcing all HIPAA standards other than the
privacy and security standards.
HIPPA Health Insurance Portability and Accountability Act of 1996
OCR (Office of Civil Rights) Federal government division that enforces the privacy
standards
PHI (Protected Health Information) Any information concerning a patient's health,
medical condition, diagnosis, or treatment; it can include financial information
Minimum Necessary Standard Must only disclose the bare minimum PHI necessary to do
a particular job or task
PII (Personally Identifiable Information) Information that can be used to identify an
individual. PII should be protected as sensitive data
, Types of PII Patient Name, Address, SSN, DL #, MRN, DOB, Phone #, Insurance ID,
Computer IP, Names of Relatives, Email Address, Biometric Identifiers (including Finger and
Voice Prints) Full Face Photographic Images
ePHI (ele Electronic Protected Health Info, requires strong data security safeguards
NIST (National Institute of Standards and Technology) Provided detailed security
guidance to help protect ePHI
HITECH (Health Information Technology for Economic and Clinical Health Act) Privacy
laws related to electronic transmission of health information
Restricted Disclosure Defined in the HITECH Omnibus of 2013, a patient's right to
restrict PHI disclosure to insurance companies
PCI DSS (Payment Card Industry Data Security Standard) Protect Credit card PII,
Cardholder data is any info that could identify your patient or their bank