Appropriate management of access to protected health information is an important aspect of ΒιΆΉΣ°ΚΣ's information security strategy. ΒιΆΉΣ°ΚΣ has adopted this Access Control Policy in order to recognize the requirement to comply with the Health Insurance Portability and Accountability Act (βHIPAAβ). The purpose of this policy is to establish a standard for HIPAA access control activities related to the ΒιΆΉΣ°ΚΣ HIPAA Program. Pacific is committed to take reasonable...
Policies by Category
Most information systems, including electronic health records that contain ePHI have the ability to create log files, which describe the activity occurring to, or within the system. A timely review of system activity can give insight into potential issues that may negatively impact the security of protected health information. The purpose of this policy is to establish ΒιΆΉΣ°ΚΣ's compliance with federal HIPAA regulations including standard practices for reviewing system activity within...
Tuesday, Nov. 25, 2014
The purpose of this standard is to define approved methods for using encryption technology to ensure the integrity and confidentiality of electronic protected health information (ePHI) and other ΒιΆΉΣ°ΚΣ confidential information while at rest and during transmission. This standard applies to all data that is considered ΒιΆΉΣ°ΚΣ confidential information, including ePHI when it is at rest, being processed, or transmitted between information technology resources. Data encryption...
Monday, Dec. 1, 2014
The purpose of this standard is to define approved methods for using box.com to ensure the integrity and confidentiality of protected health information (PHI) and other ΒιΆΉΣ°ΚΣ confidential information while at rest and during transmission. This standard applies to all data that is considered ΒιΆΉΣ°ΚΣ confidential information, including PHI, and is being stored in Box, regardless of its storage duration. Business and instructional needs may require the storage of PHI in the...
Tuesday, Feb. 9, 2016
This standard establishes a consistent set of minimum security measures required for computer workstations used within ΒιΆΉΣ°ΚΣ. This standard also addresses standards for vendor and personally owned workstations when they are connected to ΒιΆΉΣ°ΚΣβs systems and networks.The elements of this standard include requirements for installation and configuration, access control, physical security, document storage, logging and monitoring, and change management. ΒιΆΉΣ°ΚΣ...
Wednesday, Nov. 14, 2018
Required document for providing a Job Shadow opportunity as a learning experience to a minor student. Form must be signed. Updated 3-8-2022 PUNet ID required to review
Wednesday, Nov. 7, 2018
The purpose of this policy is to establish language proficiency requirements for Providers in accordance with OHA 333.002.0250. ΒιΆΉΣ°ΚΣ will allow Providers to interpret from English to the target language, when arranging for or providing services to a person with Limited English Proficiency (LEP), when the Provider meets the proficiency standard, prior to acting as interpreter. Patient requests for a certified or qualified interpreter from the Health Care Interpreters Registry will...
Thursday, Sep. 29, 2022
The purpose of this policy is to establish ΒιΆΉΣ°ΚΣ's compliance with federal HIPAA regulations 45 CFR §§ 164.502(b) and 164.514(d), which require covered entities to make reasonable efforts to limit the use and disclosure of PHI to the minimum necessary. Information systems, including electronic health records contain more protected health information (PHI) than may be needed for a given purpose or disclosure. This policy governs the use and disclosure of PHI so that only the minimum...
Tuesday, Feb. 11, 2020
Workforce members of ΒιΆΉΣ°ΚΣ are generally not issued smart phones or similar mobile devices, which have the ability to connect to the Pacific network and download data. To support mobile access for the workforce, Pacific has adopted a "bring your own device" (BYOD) approach, which permits workforce members to utilize personally owned devices to access Pacific email, calendar, contacts and other resources. This policy applies to both personally owned devices and Pacific-owned devices...
Tuesday, Jan. 29, 2019
ΒιΆΉΣ°ΚΣ promotes the highest standard of ethical and legal conduct. The Code of Conduct, policy and procedures for all workforce members guide this effort. ΒιΆΉΣ°ΚΣ promotes open dialogue between members of the ΒιΆΉΣ°ΚΣ community, and encourages workforce members to report problems, concerns, opinions without fear of retaliation or retribution. The University will use best efforts to protect workforce members against retaliation or retribution from reporting actual...
Tuesday, Feb. 25, 2020
ΒιΆΉΣ°ΚΣ is committed to preserving the privacy of your health information. We are required by law to keep your health information private and provide you with this Notice of Privacy Practices. We are also required to provide you with this Notice describing our legal duties and our practices concerning your health information. We reserve the right to change this Notice and to make the revised or changed Notice effective for health information we already have about you, as well as any...
Monday, Mar. 1, 2021
The purpose of this policy is to establish a standard for creation of strong passwords, the protection of those passwords, and the frequency of change. Passwords are an important aspect of computer security. A poorly chosen password may result in the compromise of ΒιΆΉΣ°ΚΣ's entire university network.
Tuesday, Jan. 29, 2019
In accordance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), ΒιΆΉΣ°ΚΣ patients may complain about how ΒιΆΉΣ°ΚΣ uses and discloses their Protected Health Information (PHI). All patient complaints will be submitted to the HIPAA Privacy Officer for investigation and resolution. (See the policy document for procedures on submitting a complaint.) ΒιΆΉΣ°ΚΣ has established a comprehensive HIPAA privacy and security program to prevent...
Wednesday, Nov. 1, 2017
The purpose of this policy is to ensure credit balances are appropriately returned to the payer, patient, or properly accounted for by each clinic.
Friday, Sep. 6, 2024
This policy establishes the required guidelines for the use of HIPAA/FERPA protected healthcare conferencing and video services (e.g. Healthcare Zoom) by workforce members to discuss Protected Data. Permitted uses are: case conferences, preceptor consultations, HIPAA/FERPA protected conferencing and video services, student performance measures, care coordination, student advising sessions, and administrative meetings. PUNID required to review policy. Updated October 2024.
Tuesday, Mar. 12, 2019
This policy describes and defines the retention and destruction of Protected Health Information (PHI) of patients of the healthcare component of ΒιΆΉΣ°ΚΣ. The entire record must be maintained for the required period. This policy is in accordance with all regulations related to the retention and storage of PHI, including but not limited to the follow healthcare regulations: HIPAA, HITECH, Oregon Administrative Rules, Oregon Revised Statutes and Oregon Medical Board. In cases where...
Tuesday, Dec. 14, 2021
This policy applies universally to all remote access, regardless of ownership of the equipment used to perform the remote access. ΒιΆΉΣ°ΚΣ determines the financial and technical feasibility of implementing technical controls and remote workstation security enhancements. PUNID required to review policy. Revised 2/8/2022
Tuesday, Jan. 29, 2019
The purpose of this policy is to ensure patients the right to request Confidential Communications as required by HIPAA. HIPAA permits a patient to request that the covered entity communicates by alternative means or to alternative locations. The scope of this policy is all workforce members of ΒιΆΉΣ°ΚΣβs health care component. ΒιΆΉΣ°ΚΣ is a hybrid entity. Only the health care component (i.e., the covered functions) of ΒιΆΉΣ°ΚΣ must comply with this policy. All...
Tuesday, Sep. 14, 2021
The purpose of this policy is to describe the patient right to request a restriction of use and disclosure of protected health information (PHI). HIPAA permits a patient to request that the covered entity restrict uses or disclosures of protected health information (PHI) about the patient to carry out treatment, payment, or health care operations. The scope of this policy is all workforce members of ΒιΆΉΣ°ΚΣβs health care component. ΒιΆΉΣ°ΚΣ is a hybrid entity. Only the...
Wednesday, Nov. 1, 2017
The purpose of this policy is to describe a patientβs right to request an amendment of protected health information contained in the designated record set (DRS), and the process and timeline for replying to the request. HIPAA provides patients and their representatives certain rights. This policy describes a patientβs right to request an amendment of protected health information (PHI). The scope of this policy is all workforce members of ΒιΆΉΣ°ΚΣβs health care component. Pacific...
Tuesday, Mar. 10, 2020