I. Purpose and Scope:
- The purpose of this policy is to ensure that the workforce receives effective and timely education on Tufts University School of Dental Medicine (TUSDM) privacy policies and procedures, and that an education curriculum is created and maintained to meet the needs of all TUSDM Workforce Members who handle protected health information (PHI).
II. Policy Statement:
- All Worforce Members will receive training regarding TUSDM’s privacy policies and procedures as necessary and appropriate for each Workforce Member to carry out his/her responsibilities.
III. Definitions:
IV. General Rules:
- Privacy Training.
- Initial Training. Each member of TUSDM’s workforce who is working in a Covered Care Component must complete HIPAA Basic Training and additional training annually.
- Completion of the privacy training requirements is mandatory and will be considered when TUSDM workforce members are evaluated during performance reviews.
- Failure to complete annual privacy training will result in disciplinary action.
- New Workforce Members. As part of their initial orientation, all new Workforce Members will receive the HIPAA Basic training and will be subject to additional training annually.
- Additional Training. When material changes are made to a policy or procedure, all Workforce Members whose functions are affected by the change must receive training on the new policies and procedures within a reasonable time after the material change has been made. Also, additional training sessions may be conducted for specific Workforce Members who have responsibilities involving specific compliance issues. In addition, the TUSDM Security & Privacy Officer may direct specific employees to attend privacy training if he or she believes that such training is warranted.
- HIPAA Refresher Course Training. Each current Workforce Member that has already completed the HIPAA Basics Training, will need to take the HIPAA Refresher Course training at an assigned timeframe on a yearly basis.
- Content of Training. In privacy training, workforce members will review TUSDM’s privacy policies and procedures and will discuss any changes in these policies and procedures. The training program will focus on changes in federal laws and regulations governing the privacy, confidentiality, and security of PHI, as well as any more stringent state laws.
- Documentation of Training. TUSDM must document that the required training has been provided. Accordingly, all workforce members will be asked to sign a statement acknowledging that they have received privacy training and will abide by TUSDM’s privacy policies and procedures.
- Initial Training. Each member of TUSDM’s workforce who is working in a Covered Care Component must complete HIPAA Basic Training and additional training annually.
- Documentation And Records Retention Requirements.
- As discussed above, TUSDM must document that the required training has been provided. TUSDM must retain this documentation for six years from the date of its creation or the date when it was last in effect, whichever is later.
V. Policy Compliance Monitoring and Enforcement:
- The TUSDM Security & Privacy Officer is responsible for the monitoring and enforcement of this policy; however, directors and managers are also responsible for monitoring compliance with procedures specific to their areas.
VI. Potential Disciplinary Actions and Sanctions:
- Failure to follow standard operating procedures may trigger review for potential disciplinary action under the TUSDM HIPAA Sanctions Policy.
VIII. Approval and Review Cycle:
- This policy shall be subject to annual review, revision, and approval by the TUSDM Compliance Committee.