Three HIPAA Security Safeguards {Ans: Administrative, Physical and Technical}Education & training: When designing curriculum for the audit learner {Ans: Understand whether the concepts or ideas will be in concert or in conflict with the learner.}If State law is more/less strict than HIPAA {Ans: The more strict law governs}HIPAA is enforced by {Ans: OCR, CMS & DOJ}HIPAA Covered Entities (160.103) {Ans: Health Plans, Providers (including SNFs, hospitals, clinics, etc.), and Clearlinghouses}Scenario: A neurologist in Tampa has a patient with a confusing presentation and would like to get a second opinion. Recently, the neurologist met a retired neurosurgeon from Michigan who specialized in unusual cases similar to this. The neurologist would like to talk with the retired neurosurgeon from Michigan. Does the Payment, Treatment, or Health Operations exception apply? {Ans: No, no HIPAA application because there is no PHI.}Payment, Treatment and Healthcare Operations examples {Ans: 1) provider can discuss patient case with colleagues to determine the best course of treatment 2) health plan can share information with a nursing home regarding payment for services 3) compliance officer can obtain charts for compliance audits}Scenario: A wealth woman sees a story on the news about a man