﻿WEBVTT

00:00:08.375 --> 00:00:09.242
Hi, I'm Jonathan

00:00:09.242 --> 00:00:13.246
Carr and I am the compliance officer
at Arup Laboratories.

00:00:13.279 --> 00:00:16.516
Today we'll be talking
about the second part of the chapter,

00:00:16.516 --> 00:00:19.519
compliance issues, the regulations.

00:00:19.686 --> 00:00:22.322
So we'll talk about OSHA,

00:00:22.322 --> 00:00:27.694
then HIPAA and then some general,
discussion about compliance program

00:00:27.694 --> 00:00:30.697
guidance from the Department
of Health and Human Services.

00:00:33.166 --> 00:00:35.735
So first, the Occupational Safety

00:00:35.735 --> 00:00:38.738
and Health Administration or OSHA.

00:00:38.972 --> 00:00:42.042
This was created in 1970 by Congress.

00:00:42.375 --> 00:00:44.744
And OSHA has the following
responsibilities.

00:00:44.744 --> 00:00:49.215
To set and enforce
safety standards, to provide training

00:00:50.016 --> 00:00:53.586
and also provide outreach, education
and compliance

00:00:53.586 --> 00:00:56.589
assistance to companies.

00:00:57.690 --> 00:00:58.591
Many states

00:00:58.591 --> 00:01:02.629
have their own programs,
and these are encouraged

00:01:02.629 --> 00:01:05.632
to be established,
and they're monitored by OSHA.

00:01:05.932 --> 00:01:10.804
They're also partially funded by OSHA,
the federal administration.

00:01:11.404 --> 00:01:14.574
And most states
have implemented OSHA approved programs.

00:01:17.243 --> 00:01:21.147
OSHA has a general duty clause.

00:01:21.181 --> 00:01:25.085
This requires that employers must maintain
a work environment

00:01:25.418 --> 00:01:29.322
free from recognized hazards to employees.

00:01:29.823 --> 00:01:33.293
And so now we'll watch a short video
about one company

00:01:33.593 --> 00:01:37.330
that ran into some problems
with violating the general duty

00:01:37.330 --> 00:01:40.333
clause.

00:01:40.500 --> 00:01:41.501
Just general duty

00:01:41.501 --> 00:01:45.972
clause requires employers to ensure
workplaces are free of recognized hazards

00:01:45.972 --> 00:01:48.975
that may cause death
or serious physical harm.

00:01:49.609 --> 00:01:53.913
OSHA investigators found that the owner
of a medical facilities in Rhode Island

00:01:53.913 --> 00:01:57.584
fell to protect the employees
from the exposure to the coronavirus,

00:01:57.851 --> 00:02:01.521
and implement proper safety measures
after the owner of the facilities

00:02:01.521 --> 00:02:05.058
exhibited symptoms of the virus
and later tested positive,

00:02:05.058 --> 00:02:08.061
but still continue to interact
with employees.

00:02:08.461 --> 00:02:11.431
OSHA stated that the employers
have a responsibility

00:02:11.431 --> 00:02:15.635
to isolate workers and themselves
if they show symptoms of the virus.

00:02:16.402 --> 00:02:20.006
Also, protecting employees and patients
by implementing timely

00:02:20.006 --> 00:02:23.977
and effective safeguards and controls
to minimize exposure is critical.

00:02:25.445 --> 00:02:28.882
OSHA determined that the employer failed
to implement

00:02:28.882 --> 00:02:33.520
engineering controls such as portable,
high efficiency, particular air fan

00:02:33.520 --> 00:02:37.090
filtration systems, and barriers
between adjacent desks.

00:02:37.857 --> 00:02:41.561
Implement administrative controls
such as cleaning and disinfecting,

00:02:41.561 --> 00:02:47.433
and symptom screening of all employees,
and mandate contact tracing or quarantine

00:02:47.433 --> 00:02:51.771
periods after employee exposure
to coronavirus exposed patients.

00:02:52.772 --> 00:02:56.009
The employer received $136,000

00:02:56.009 --> 00:02:59.012
fine from OSHA for these listed failures.

00:02:59.279 --> 00:03:03.550
Remember, OSHA expects employers
such as clinical laboratories to ensure

00:03:03.550 --> 00:03:07.187
workplaces are free of recognized hazards
like infectious diseases.

00:03:09.088 --> 00:03:13.326
Okay, so that was an example
of a medical facility

00:03:13.326 --> 00:03:16.329
that ran into some problems
with the general duty clause.

00:03:16.663 --> 00:03:20.833
OSHA also has more specific requirements

00:03:21.201 --> 00:03:24.771
for laboratories
and other health care facilities.

00:03:25.538 --> 00:03:28.074
One is the bloodborne pathogens standard.

00:03:28.074 --> 00:03:31.177
This is found in title 29 of the CFR,

00:03:31.211 --> 00:03:35.682
or Code of Federal
Regulations in part 1910.

00:03:36.783 --> 00:03:38.918
This includes universal precautions.

00:03:38.918 --> 00:03:43.122
This requires
that all blood, bodily fluids, tissue,

00:03:43.122 --> 00:03:47.727
and other potentially infectious materials
are treated as equally hazardous.

00:03:48.161 --> 00:03:51.664
It also requires that the laboratory
develop and implement

00:03:51.664 --> 00:03:53.633
an exposure control plan.

00:03:53.633 --> 00:03:57.370
What to do if an employee is exposed to

00:03:57.370 --> 00:04:00.373
a hazardous material?

00:04:01.207 --> 00:04:02.809
The bloodborne pathogens

00:04:02.809 --> 00:04:06.079
standard also requires
that jobs are classified

00:04:06.079 --> 00:04:11.284
based on their potential for exposure
to potentially hazardous materials.

00:04:12.752 --> 00:04:15.989
The standard also requires
that laboratories provide

00:04:15.989 --> 00:04:20.226
personal protective equipment
or PPE, such as goggles, masks,

00:04:20.226 --> 00:04:23.730
gloves, and lab coats,
depending on the roles

00:04:23.730 --> 00:04:26.733
and responsibilities
and work environment of the employee.

00:04:27.967 --> 00:04:31.104
OSHA also has implemented

00:04:31.104 --> 00:04:34.240
a Needle Stick Safety and Prevention Act,

00:04:34.941 --> 00:04:38.845
and this includes a requirement
that a laboratory set up

00:04:38.845 --> 00:04:44.250
engineering and work practice controls
to help prevent needle stick injuries.

00:04:44.817 --> 00:04:46.152
If an injury does occur,

00:04:46.152 --> 00:04:50.223
then the laboratory is required
to maintain a sharps injury log.

00:04:53.159 --> 00:04:56.162
OSHA inspections can happen at any time.

00:04:56.229 --> 00:05:00.099
OSHA inspectors may arrive
unannounced to the laboratory,

00:05:00.600 --> 00:05:04.003
and a laboratory cannot legally refuse

00:05:04.504 --> 00:05:07.507
entry of an OSHA inspector.

00:05:09.776 --> 00:05:11.844
Okay, now we'll move to the Health
Insurance

00:05:11.844 --> 00:05:15.548
Portability and Accountability Act,
or HIPAA.

00:05:17.984 --> 00:05:22.155
HIPAA comes from a 1996
legislation passed by Congress,

00:05:22.155 --> 00:05:25.591
which was essentially focused
on health insurance

00:05:26.159 --> 00:05:29.896
and geared towards preventing employers

00:05:30.229 --> 00:05:34.834
from causing problems with employers
that had preexisting conditions.

00:05:35.201 --> 00:05:40.540
The idea was to maintain privacy of health
insurance records so that workers could,

00:05:41.708 --> 00:05:45.445
not run into issues with future employers

00:05:45.445 --> 00:05:48.448
who had access to their health
insurance records.

00:05:49.949 --> 00:05:52.352
The Department of Health
and Human Services

00:05:52.352 --> 00:05:55.555
established a privacy rule in 2000,

00:05:55.555 --> 00:05:58.558
and a security rule in 2003.

00:05:58.658 --> 00:06:01.661
In accordance with the HIPAA legislation.

00:06:02.061 --> 00:06:04.564
The office for Civil Rights, or OCR,

00:06:04.564 --> 00:06:08.835
is the entity within the Department
of Health and Human Services

00:06:09.102 --> 00:06:12.739
that is responsible
for enforcement of the HIPAA standards.

00:06:13.172 --> 00:06:17.143
The privacy rule
and the security rule in HIPAA are both

00:06:17.143 --> 00:06:21.848
focused on establishing national standards
for protection of health information.

00:06:22.382 --> 00:06:26.619
The security rule is primarily focused
on the electronic form

00:06:26.953 --> 00:06:30.523
of information,
and making sure that it is protected.

00:06:31.491 --> 00:06:33.593
The security rule has technical

00:06:33.593 --> 00:06:36.996
and non-technical safeguards
established in the rule.

00:06:40.400 --> 00:06:42.168
HIPAA uses

00:06:42.168 --> 00:06:46.339
the term protected health information
or Fi,

00:06:46.939 --> 00:06:52.245
and Fi
is individually identifiable information

00:06:52.845 --> 00:06:55.681
relating to the past, present or future

00:06:55.681 --> 00:07:00.052
health status of an individual
and it is created,

00:07:00.052 --> 00:07:04.223
collected or transmitted
or maintained by a HIPAA covered entity

00:07:05.658 --> 00:07:09.662
and relates
to the provision of health care, payment

00:07:09.662 --> 00:07:14.100
for health care services
or use in health care operations.

00:07:15.568 --> 00:07:20.072
So if information meets these criteria,
then it is considered

00:07:20.072 --> 00:07:23.443
protected health information
or by and it's

00:07:23.443 --> 00:07:26.446
subject to the HIPAA rules.

00:07:26.746 --> 00:07:29.582
Now covered entities are

00:07:29.582 --> 00:07:32.985
is another term used in the HIPAA rules.

00:07:33.586 --> 00:07:37.890
And covered entities are entities
like health care providers

00:07:38.891 --> 00:07:42.195
health plans, health care clearinghouses.

00:07:42.695 --> 00:07:45.331
And then also
there are business associates

00:07:45.331 --> 00:07:51.003
which are not necessarily covered entities
by the nature of their business

00:07:51.003 --> 00:07:56.943
themselves, but by the nature of the work
that they do for a covered entity.

00:07:57.176 --> 00:08:01.214
So a company that is perhaps
not a health care provider,

00:08:01.681 --> 00:08:04.584
but a company that handles

00:08:04.584 --> 00:08:07.587
billing information, or other

00:08:07.820 --> 00:08:11.657
AI for a covered entity will be obligated

00:08:11.657 --> 00:08:16.062
to follow the same rules
under HIPAA as a covered entity.

00:08:20.333 --> 00:08:23.336
So some general,

00:08:23.469 --> 00:08:27.507
practices or principles of HIPAA
and the security rule,

00:08:28.107 --> 00:08:31.444
they are geared towards
protecting privacy, but

00:08:31.444 --> 00:08:35.948
being flexible enough so that companies
can adopt new technologies

00:08:37.183 --> 00:08:40.253
to help the health care entity
or other company

00:08:40.520 --> 00:08:43.689
be more efficient
in the provision of health care.

00:08:45.258 --> 00:08:48.794
Minimum necessary is
another term used in HIPAA.

00:08:49.262 --> 00:08:53.766
This means that information
is only provided to employees or others

00:08:54.100 --> 00:08:57.870
who have a need to know
they don't have access to

00:08:58.571 --> 00:09:03.609
Fi that is beyond what's necessary
in their roles and responsibilities.

00:09:04.176 --> 00:09:09.382
Encryption of electronic devices
is another general principle of HIPAA,

00:09:09.782 --> 00:09:14.053
and then shredding physical paperwork
or physical materials,

00:09:14.320 --> 00:09:18.291
making sure that they're destroyed
appropriately is another general principle

00:09:18.357 --> 00:09:23.496
of HIPAA and maintaining protection
of protected health information.

00:09:25.464 --> 00:09:28.367
As I mentioned before, the office
for Civil Rights

00:09:28.367 --> 00:09:31.470
is the entity within the Department
of Health and Human Services

00:09:32.138 --> 00:09:35.775
that is responsible
for enforcement of HIPAA laws.

00:09:37.276 --> 00:09:39.579
Here's a short video of

00:09:39.579 --> 00:09:42.882
an entity
that ran into some problems with HIPAA.

00:09:47.753 --> 00:09:51.090
Why is it so important
to have HIPAA security measures in place?

00:09:51.857 --> 00:09:55.227
In 2015, Anthem Inc., a health benefits

00:09:55.227 --> 00:09:58.230
company,
was the victim of multiple cyber attacks.

00:09:58.364 --> 00:10:01.067
Anthem had discovered
that the cyber attackers had gained

00:10:01.067 --> 00:10:04.470
access to its IT system
after an anthem employee

00:10:04.470 --> 00:10:08.808
responded to a spear phishing email
and opened the door to further attacks.

00:10:09.609 --> 00:10:11.611
And what is spear phishing?

00:10:11.611 --> 00:10:15.948
A spear phishing email is a scam
targeted towards a specific individual,

00:10:15.948 --> 00:10:17.583
and is challenging to detect

00:10:17.583 --> 00:10:20.586
because it appears to come from a known
and trusted source.

00:10:21.087 --> 00:10:26.225
Well, the spear phishing attack resulted
in the largest health data breach in U.S.

00:10:26.225 --> 00:10:28.127
history to that date.

00:10:28.127 --> 00:10:31.564
Within the span of two months,
the attackers stole the electronic health

00:10:31.564 --> 00:10:35.868
information of nearly 79 million
individuals, including names,

00:10:36.102 --> 00:10:40.373
Social security numbers,
medical identification numbers, addresses,

00:10:40.373 --> 00:10:44.043
dates of birth, email
addresses, and employment information.

00:10:44.944 --> 00:10:48.047
Anthem notified
the United States Office for Civil Rights,

00:10:48.047 --> 00:10:49.081
which is part of the U.S.

00:10:49.081 --> 00:10:51.450
Department of Health and Human Services,

00:10:51.450 --> 00:10:54.420
which investigates
health information, data breaches.

00:10:54.720 --> 00:10:58.491
The office determined that anthem failed
to conduct an enterprise wide risk

00:10:58.491 --> 00:11:03.429
analysis, had insufficient procedures
to regularly review information system

00:11:03.429 --> 00:11:08.501
activity, failed to identify and respond
to suspected or known security incidents,

00:11:08.834 --> 00:11:12.638
and failed to implement adequate minimum
access controls to prevent

00:11:12.638 --> 00:11:16.175
the cyber attackers from accessing
sensitive health information.

00:11:17.043 --> 00:11:21.647
As a consequence of these failures,
anthem was fined 16 million and required

00:11:21.647 --> 00:11:26.152
to undertake a robust corrective action
plan to comply with the HIPAA rules.

00:11:26.519 --> 00:11:28.921
In addition to the $16 million fine.

00:11:28.921 --> 00:11:33.092
Anthem paid 115 million
to settle a class action lawsuit,

00:11:33.292 --> 00:11:37.530
which included payment for two years
of credit monitoring for nearly 20 million

00:11:37.530 --> 00:11:40.933
patients, who proved that
their personal information was stolen.

00:11:41.434 --> 00:11:44.837
Learn from Anthem's mistakes
and make sure you implement proper HIPAA

00:11:44.837 --> 00:11:46.972
security measures in your laboratory.

00:11:50.543 --> 00:11:53.646
So there you saw an example of an entity

00:11:53.646 --> 00:11:56.749
that was found to have violated
the HIPAA laws

00:11:58.584 --> 00:12:01.821
and had a very significant large scale
breach

00:12:01.821 --> 00:12:05.191
and suffered significant
financial penalties.

00:12:06.459 --> 00:12:08.461
HIPAA requires

00:12:08.461 --> 00:12:13.499
that entities establish a program
which typically involves

00:12:13.532 --> 00:12:16.669
having a privacy officer
and an information

00:12:16.669 --> 00:12:21.173
security officer to help prevent
having some of these problems.

00:12:21.774 --> 00:12:24.610
These individuals
are typically responsible

00:12:24.610 --> 00:12:28.681
for establishing policies
and procedures under HIPAA,

00:12:29.281 --> 00:12:32.818
providing HIPAA training to employees
throughout the company,

00:12:33.452 --> 00:12:36.388
and also conducting audits to ensure

00:12:36.388 --> 00:12:39.391
that the HIPAA standards are being met.

00:12:40.092 --> 00:12:41.994
Now, I'll mention a few things

00:12:41.994 --> 00:12:44.997
generally about compliance program
guidance.

00:12:45.231 --> 00:12:49.502
In 1998, the Department of Health
and Human Services

00:12:50.703 --> 00:12:55.508
published a guidance document
for Clinical Laboratories

00:12:55.775 --> 00:13:00.212
which outlines
the best practices and expectations

00:13:00.412 --> 00:13:03.983
from the federal government
of what a compliance program at a

00:13:03.983 --> 00:13:05.217
laboratory should look like.

00:13:06.519 --> 00:13:08.854
There are seven fundamental

00:13:08.854 --> 00:13:12.758
elements to a clinical laboratory
compliance program.

00:13:13.125 --> 00:13:16.262
And here on this slide,
I've listed the first four.

00:13:17.630 --> 00:13:19.465
The first is development

00:13:19.465 --> 00:13:22.468
and distribution
of written standards of conduct.

00:13:23.402 --> 00:13:27.706
Then designation of a chief compliance
officer and other appropriate bodies

00:13:27.706 --> 00:13:30.943
such as, for example,
a corporate compliance committee,

00:13:31.977 --> 00:13:34.213
development and implementation

00:13:34.213 --> 00:13:38.317
of regular effective education
and training programs, maintenance

00:13:38.317 --> 00:13:43.022
of a hotline to receive complaints
and protect the anonymity of complainants.

00:13:44.790 --> 00:13:47.693
Enforcement
of appropriate disciplinary action

00:13:47.693 --> 00:13:50.696
against employees
who have violated compliance policies.

00:13:51.497 --> 00:13:56.168
Use of audits and or other evaluation
techniques to monitor compliance.

00:13:56.936 --> 00:13:59.572
And then finally,
the seventh fundamental element

00:13:59.572 --> 00:14:03.242
is investigation
and remediation of identified problems.

00:14:03.876 --> 00:14:07.279
And also a second part
to that ensuring that

00:14:07.980 --> 00:14:12.551
the laboratory does not employ
sanctioned individuals.

00:14:13.085 --> 00:14:16.622
These are individuals
who have been found to have violated,

00:14:18.057 --> 00:14:19.592
health care laws,

00:14:19.592 --> 00:14:22.962
such as laws against fraud,
waste or abuse,

00:14:23.395 --> 00:14:26.398
and have been listed as,

00:14:26.498 --> 00:14:29.535
sanctioned on the federal website,

00:14:30.469 --> 00:14:34.173
with the office of Inspector
General in Health and Human Services.

00:14:34.640 --> 00:14:37.843
And they are not allowed to be employed
by a health care entity

00:14:37.843 --> 00:14:40.846
such as a laboratory.

00:14:43.816 --> 00:14:44.416
Oversight

00:14:44.416 --> 00:14:47.820
of the clinical laboratory
industry is complicated.

00:14:48.220 --> 00:14:51.991
And on this slide,
I've just shown a few of the entities

00:14:51.991 --> 00:14:56.195
that we've already discussed,
but others as well, that oversee

00:14:56.729 --> 00:15:00.332
operations
and the business of a clinical lab.

00:15:00.833 --> 00:15:05.437
As you can see, there's many,
many state and federal agencies

00:15:05.437 --> 00:15:09.541
and various entities that are involved
in what we do in a clinical laboratory.

00:15:09.875 --> 00:15:13.946
And it's important to establish
a compliance program at your lab

00:15:14.146 --> 00:15:19.518
that incorporates all of the applicable
regulations and standards,

00:15:20.252 --> 00:15:23.789
in, in your laboratory
to ensure compliance.

00:15:25.324 --> 00:15:25.791
Okay.

00:15:25.791 --> 00:15:27.293
And that covers the second part

00:15:27.293 --> 00:15:30.296
of the chapter, compliance
issues, the regulations.

00:15:30.663 --> 00:15:31.063
Thank you.
