|Privacy Incidents & Complaints||E-Mail Authorizations|
Patients or legal representatives may file a Privacy
Complaint at any time. Click here for the Privacy Complaint form.
Use E-Mail to Correspond with Patients and Research Participants!
|Email and Restricted Information||Students and Epic Access|
E-mail may be used to transmit Protected Health Information (PHI) and other restricted data (except Social Security Numbers!) but only under specific conditions and for limited purposes.
UF emails that include PHI may not be forwarded to an outside account (Gmail, Yahoo, etc.)!
Do you know what the rest of the conditions and the approved purposes are? See the policy here for more information.
Student access to the Epic electronic medical record (EMR) system, although stringently controlled, is routinely authorized and provided for academic purposes to approved students.
Visit the website here for more information
|Tracking HIPAA Training||SSN Request Form|
Are you the person responsible for tracking HIPAA training completion for your department or division? Reports are available
for this purpose - see the instructions below.*
Do you need to collect, use or store Social Security Numbers?
Do you know when and how to obtain permission to collect or use SSNs?
Need to request special permission to use SSNs for your work? Click here.
ANNUAL PRIVACY TRAINING REQUIREMENTS
All UF Employees and Volunteers in health care components are required to complete annual Privacy Training during January and February each year. All staff, including volunteers, must complete the training through HR Services - click here for instructions to access the training through myUFL. Volunteers must be given a "Person of Interest" status to access the training. See below for instructions.
Students enrolled in Health Science Center colleges and programs should complete annual Privacy Training during May through August each year. Schedules for completing student training are set by the colleges. Click here for more instructions. Students who are also employees should follow the employee schedule and instructions.
Each member of the workforce is responsible for maintaining their individual training requirements.
Colleges, departments, divisions, clinics, and other units are responsible for ensuring that all their workforce members are in compliance with orientation and annual training requirements.
Failure to comply with entry and annual training requirements is a Level II Privacy Violation and repeated violations (i.e., failure to complete the training after multiple reminders) is grounds for disciplinary action, up to and including termination of employment, enrollment, or volunteer status.
*Tracking: Department staff
responsible for tracking the completion of HIPAA training for their department can access reports through
Enterprise Reporting. Reports generally run about 3-4 days behind. Staff must have the UF_EL_TRAINING_REPORTS role to access these reports.
Go to Enterprise Reporting > Access Reporting > Human Resources Information > Training and Organizational Development > then choose from the options for reports: by department, by employee, etc.
Managers may also use Manager Self Service in MyUFL for quick access to the compliance status of individuals under their supervision.
Person of Interest: In order to access the system you must have a UF ID #, Gatorlink account, and be set up in UF's HR system as a "Person of Interest".
- To get the Person of Interest designation:
- (a) if you are working in conjunction with a specific UF department, contact that department's HR administrator; or
- (b) otherwise contact Melissa Beatty at (352) 392-4803.
Training and Organizational Development (HR) now sends out limited training reminders to individuals who have not met annual training requirements. The Privacy Office conducts periodic audits of training compliance and will send the results to College, Department, and/or Division heads, upon request or as needed. Contact Everall Peele by email for more information.
On a lighter note...