HIPAA CLIN-200 Notice of Privacy Practices

[…] quality assessment and improvement, peer review, legal, auditing and compliance, business management, general administrative functions, and customer service. Operations also include clinical training of students and residents.   HIPAA Privacy Rule   Refers to the Standards for Privacy of Individually Identifiable Health Information, which governs the use and disclosure of PHI.    The Privacy Rule is codified at […]

HIPAA Privacy Rule: Education of Covered Workforce

Policy Purpose The purpose of this policy is to detail requirements for completing the University of Southern California HIPAA Education Program (“Education Program”) for individuals who collect, use, disclose, or access Protected Health Information subject to HIPAA and other personal health information subject to FERPA and CMIA. Please download policy to access additional details. […]

Data Privacy Policy

[…] what circumstances may the information be used and disclosed, as well as describes the rights students have regarding their information.  Health Insurance Portability and Accountability Act ( HIPAA) Policies further describe the privacy and security requirements related to the use and disclosure of protected health information and rights individuals have related to their health information.  […]

HIPAA BUS-701: Policy Regarding Business Associates

[…] of a Business Associate Agreement, procedures for identifying and managing Business Associates, and ensuring compliance with federal and state regulations.  Please download policy to access additional details. HIPAA Privacy Rule Policy Regarding Business AssociatesDownload To access the institutional policies located behind Shibboleth log-in, please utilize your @usc.edu email address. If you attempt to log-in […]

HIPAA PAT-608 Breach Notification

USC shall comply with breach notification requirements under federal and state laws, including the HIPAA privacy and security regulations and the Health Information Technology for Economic and Clinical Health Act (“HITECH”) Regulations.

HIPAA PAT-607 Mitigations and Sanctions

It is USC’s policy to monitor compliance with HIPAA policies and to mitigate, to the extent practicable, any harm resulting from inappropriate access to, acquisition of, use of, or disclosure of protected health information.

HIPAA PAT-606 Resolution of Patient Complaints

Please download policy to access additional details. HIPAA-PAT-606-Resolution-of-Patient-ComplaintsDownload To access the institutional policies located behind Shibboleth log-in, please utilize your @usc.edu email address. If you attempt to log-in utilizing your school or department address such as @keck.usc.edu, @marshall.usc.edu, etc. the policies will not be accessible.

HIPAA PAT-605 Patient Requests to Receive Confidential Communications

Please download policy to access additional details. HIPAA-PAT-605-Patient-Requests-to-Receive-Confidential-CommunicationsDownload To access the institutional policies located behind Shibboleth log-in, please utilize your @usc.edu email address. If you attempt to log-in utilizing your school or department address such as @keck.usc.edu, @marshall.usc.edu, etc. the policies will not be accessible.

HIPAA PAT-604 Patient Requests to Restrict Uses and Disclosures of Protected Health Information

Please download policy to access additional details. HIPAA-PAT-604-Patient-Requests-to-Restrict-Uses-and-Disclosures-of-Protected-Health-InformationDownload To access the institutional policies located behind Shibboleth log-in, please utilize your @usc.edu email address. If you attempt to log-in utilizing your school or department address such as @keck.usc.edu, @marshall.usc.edu, etc. the policies will not be accessible.

HIPAA PAT-603 Accounting of Disclosures of Protected Health Information

Please download policy to access additional details. HIPAA-PAT-603-Accounting-of-Disclosures-of-Protected-Health-InformationDownload To access the institutional policies located behind Shibboleth log-in, please utilize your @usc.edu email address. If you attempt to log-in utilizing your school or department address such as @keck.usc.edu, @marshall.usc.edu, etc. the policies will not be accessible.

HIPAA PAT-602 Patient Requests to Amend Protected Health Information

Please download policy to access additional details. HIPAA-PAT-602-Patient-Requests-to-Amend-Protected-Health-InformationDownload To access the institutional policies located behind Shibboleth log-in, please utilize your @usc.edu email address. If you attempt to log-in utilizing your school or department address such as @keck.usc.edu, @marshall.usc.edu, etc. the policies will not be accessible.

HIPAA PAT-601 Access to Protected Health Information

Please download policy to access additional details. HIPAA-PAT-601-Access-to-Protected-Health-InformationDownload To access the institutional policies located behind Shibboleth log-in, please utilize your @usc.edu email address. If you attempt to log-in utilizing your school or department address such as @keck.usc.edu, @marshall.usc.edu, etc. the policies will not be accessible.

HIPAA RES-301 Uses and Disclosures of Protected Health Information for Research Purposes

Federal and state regulations govern the protection of human subjects in research. While these regulations provide for some patient confidentiality protections, the HIPAA Privacy Rule adds additional privacy protections for human subjects and establishes the conditions under which protected health information (“PHI”) may be used or disclosed by the University of Southern California (USC) […]

HIPAA CLIN-207 Security Risk Analysis and Management

In accordance with the HIPAA Security Rule, USC maintains a HIPAA security risk analysis and management program to assess and prioritize risks to the confidentiality, integrity and availability of Protected Health Information (PHI) and to respond, accept or remediate as appropriate.

HIPAA CLIN-206 Minimum Security Standards for ePHI for Keck

Please download policy to access additional details. HIPAA-CLIN-206-Minimum-Security-Standards-for-ePHI-for-KeckDownload To access the institutional policies located behind Shibboleth log-in, please utilize your @usc.edu email address. If you attempt to log-in utilizing your school or department address such as @keck.usc.edu, @marshall.usc.edu, etc. the policies will not be accessible.

HIPAA CLIN-204 Facility Directory

Purpose is to ensure that the maintenance of the facility directory at University of Southern California is in accordance with the HIPAA privacy regulations.

HIPAA CLIN-203 Special Privacy Considerations

Please download policy to access additional details. HIPAA-CLIN-203-Special-Privacy-ConsiderationsDownload To access the institutional policies located behind Shibboleth log-in, please utilize your @usc.edu email address. If you attempt to log-in utilizing your school or department address such as @keck.usc.edu, @marshall.usc.edu, etc. the policies will not be accessible.

HIPAA CLIN-202 Personal Representatives of Patients

Please download policy to access additional details. HIPAA-CLIN-202-Personal-Representatives-of-PatientsDownload To access the institutional policies located behind Shibboleth log-in, please utilize your @usc.edu email address. If you attempt to log-in utilizing your school or department address such as @keck.usc.edu, @marshall.usc.edu, etc. the policies will not be accessible.

HIPAA CLIN-201 Use of Protected Health Information for Treatment Payment and Health Care Operations

Please download policy to access additional details. HIPAA-CLIN-201-Use-of-Protected-Health-Information-for-Treatment-Payment-and-Health-Care-OperationsDownload To access the institutional policies located behind Shibboleth log-in, please utilize your @usc.edu email address. If you attempt to log-in utilizing your school or department address such as @keck.usc.edu, @marshall.usc.edu, etc. the policies will not be accessible.

HIPAA GEN-105 Disclosures of De-identified Information

Please download policy to access additional details. HIPAA-GEN-105-DISCLOSURES-OF-DEIDENTIFIEDDownload To access the institutional policies located behind Shibboleth log-in, please utilize your @usc.edu email address. If you attempt to log-in utilizing your school or department address such as @keck.usc.edu, @marshall.usc.edu, etc. the policies will not be accessible.

HIPAA GEN-103 Public Policy Disclosures

USC may use or disclose PHI for treatment, payment and health care operations without an individual’s authorization in accordance with USC HIPAA Policy CLIN – 201 and USC’s Notice of Privacy Practices, provided the individual has acknowledged receipt of USC’s Notice of Privacy Practices or USC has made good faith efforts to obtain the […]

HIPAA GEN-102 When to Obtain Authorizations

Please download policy to access additional details. HIPAA-GEN102-WHEN-TO-OBTAIN-AUTHORIZATIONSDownload To access the institutional policies located behind Shibboleth log-in, please utilize your @usc.edu email address. If you attempt to log-in utilizing your school or department address such as @keck.usc.edu, @marshall.usc.edu, etc. the policies will not be accessible.

Mandated Reporters

[…] the same categories of mandated reporting. For example, health care providers also may need to make an accounting of disclosures under this policy as required by the HIPAA Privacy Rule. See the hospital intranet for links to hospital-based Mandated Reporter information, and USC’s HIPAA policies at https://policy.usc.edu/admin/.​  7. Forms Form OES 2-920 Suspicious Injury Report   Form SOC341 […]

Generative AI General Policy

[…] with caution and in compliance with other University policies and department rules) Confidential Data (e.g., student education records protected by FERPA, health or medical information protected by HIPAA, nonpublic personal or financial information) NOT PERMITTED NOT PERMITTED (unless advance written approval provided by Office of Ethics & Compliance) Restricted Confidential Data (e.g., ITAR/EAR export-controlled […]

Data Protection

[…] legal, financial, reputational, or operational harm if disclosed. “Confidential” data includes, but is not limited to: • All information safeguarded by Health Insurance Portability and Accountability Act ( HIPAA), Gramm-Leach-Bliley Act (GLBA), Payment Card Industry Data Security Standard (PCI DSS), the Family Education Rights Privacy Act (FERPA), and California Financial Information Privacy Act (CFIPA) • Nonpublic […]

HIPAA-RES-301-Uses-and-Disclosures-of-Protected-Health-Information-for-Research-Purposes

University of Southern California POLICY Administrative and Business Practices/Compliance/ HIPAA Issued by: Elizabeth Garrett Provost and Senior Vice President, Academic Affairs Todd R. Dickey Senior Vice President, Administration Date issued: July 15 , 2014 University of Southern California Page 1 of 10 HIPAA Privacy Rule RES -301: Uses and Disclosures of Protected Health Information […]

HIPAA-RES-301-Uses-and-Disclosures-of-Protected-Health-Information-for-Research-Purposes

University of Southern California POLICY Administrative and Business Practices/Compliance/ HIPAA Issued by: Elizabeth Garrett Provost and Senior Vice President, Academic Affairs Todd R. Dickey Senior Vice President, Administration Date issued: July 15 , 2014 University of Southern California Page 1 of 10 HIPAA Privacy Rule RES -301: Uses and Disclosures of Protected Health Information […]

HIPAA-PAT-603-Accounting-of-Disclosures-of-Protected-Health-Information

[…] and Senior Vice President, Academic Affairs Todd R. Dickey Senior Vice President, Admin istration Date issued: July 1, 2015 University of Southern California Page 1 of 9 HIPAA PRIVACY RULE: ACCOUNTING OF DISCLOSURES OF PROTECTED HEALTH INFORMATION I. POLICY: A. General Right to Request Accounting This policy describes the process for responding to a […]

HIPAA Privacy Rule-Education of Covered Workforce

[…] March 17, 2023 Last Reviewed: March 17, 2023 2. Policy Purpose The purpose of this policy is to detail requirements for completing the University of Southern California HIPAA Education Program (“Education Program”) for individuals who collect, use, disclose, or access Protected Health Information subject to HIPAA and other personal health information subject to FERPA […]

HIPAA-CLIN-206-Minimum-Security-Standards-for-ePHI-for-Keck

University of Southern California POLICY Administrative and Business Practices/Compliance/ HIPAA Issued by: Elizabeth Garrett Provost and Senior Vice President, Academic Affairs Todd R. Dickey Senior Vice President, Administration Date issued: July 15 , 201 4 University of Southern California Page 1 of 10 HIPAA Privacy Rule CLIN-206: Minimum Security Standards for Electronic Protected Health […]

HIPAA-CLIN-201-Use-of-Protected-Health-Information-for-Treatment-Payment-and-Health-Care-Operations

University of Southern California Administrative and Business Practices HIPAA PRIVACY RULE: USE OF PROTECTED HEALTH INFORMATIQNT’OR TREATMENT, PAYMENT AND HEALTH CARE OPERATIONS I. Policy A. General Rule. University of Southern California (USC) I is permitted to use and disclose an individual’s Protected Health Information 2 for treatment, payment and health care operations, provided: USC […]

HIPAA-PAT-607-Mitigations-and-Sanctions (2)

[…] Vice President, Academic Affairs David W. Wright Interim Senior Vice President, Administration Date issued: February 1, 2019 University of Southern California Page 1 of 6 PAT -607 HIPAA PRIVACY AND SECURITY RULE: MITIGATION AND SANCTIONS I. Policy A. It is USC’s 1 policy to: 1. Monitor compliance with HIPAA policies and to mitigate, to […]