print

Resident and Fellow Policy Manual

HIPAA Training for Residents/Fellows:

HIPAA (Health Insurance Portability and Accountability Act) is federal legislation that provides standards for the privacy and security of protected health information (PHI).

The HIPAA regulations require covered entities (providers, health insurance plans) to create safeguards to ensure that those with a real need for protected health information have access and use it responsibly.  These regulations work alongside state law and complimentary standards by JCAHO and Centers for Medicare and Medicaid Services (CMS) that protect patient rights.

HIPAA Privacy and Security regulations were issued by the Department of Health and Human Services with compliance dates of April 2003 and April 2005 respectively.  All covered entities are required to have policies in place and to train all workforce members on these policies.  Compliance is mandatory.

“URMC/Strong Health” is one covered entity under HIPAA and includes:  Strong Memorial Hospital, UR Medical Faculty Group, Highland Hospital, Eastman Dental Center, Primary Care Network, School of Medicine and Dentistry, School of Nursing, Long Term Care, Visiting Nurse Service, University Health Service and Mount Hope Family Center.  There is a Privacy Officer and HIPAA Security Official for each of these sub-entities within URMC/Strong Health.  Contact information can be found at:  http://intranet.urmc.rochester.edu/HIPAA/FAQsResources/Officers.asp#Privacy.

HIPAA Privacy and Security job-specific training modules are available on the Medical Center Intranet at http://intranet.urmc.rochester.edu/Policy/HIPAA/.

Basic HIPAA Training:

  • HIPAA Basic Training is on the GME web site under Information for Trainees/New Hire Checklist.  Every "new-to-the institution" trainee will need to complete an attestation form which can be found on the New Hire Checklist.

Privacy and Security Job Specific Training:

  • Job-specific training will be completed at the departmental level for all trainees within 30 days of hire.  This training is the same as for attending physicians and medical students.  You will also need to complete an attestation form for this on-line training and return it to your department administrator.  Be sure that you speak with your departmental administrator about this required training.