Minding HIPAA & IRBs Cave Fatuis!. Elements HIPAA definitions of identifiable data Reducing risk of identifying people Research and IRB approval Business.

Slides:



Advertisements
Similar presentations
Fourth National HIPAA Summit April 26, 2002 Implementation of a HIPAA Data Management Strategy Safeguarding privacy interests while making data available.
Advertisements

SIMPLIFYING PRIVACY: HIPAA PRIVACY STANDARDS AND RESEARCH Angela M. Vieira General Counsel Childrens Hospital and Health Center June 5, 2004.
Minimum Necessary Standard Version 1.0
HIPAA Privacy Rule “Standards for Privacy of Individually Identifiable Health Information” 45 CFR 160 and 164* *
1 The HIPAA Privacy Rule and Research This presentation will probably involve audience discussion, which will create action items. Use PowerPoint to keep.
HIPAA and Public Health 2007 Epi Rapid Response Team Conference.
NATIONAL FORUM ON YOUTH VIOLENCE PREVENTION: HIPAA PRIVACY RULE CONSIDERATIONS November 1, 2011 Iliana L. Peters, JD, LLM HHS Office for Civil Rights.
HIPAA – Privacy Rule and Research USCRF Research Educational Series March 19, 2003.
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
National Cancer Institute Cancer Therapy Evaluation Program (CTEP) presents: How to Obtain Protected Health Information (PHI) from an Outside Healthcare.
1 HIPAA and Research and YOU. 2 INTRODUCTION Rule #1:Don’t Panic Rule #2:Bottom Line for Researchers: HIPAA is Manageable thru Education/Awareness and.
HIPAA Health Insurance Portability and Accountability Act.
What is HIPAA? This presentation was created by The University of Arizona Privacy Office, The Office for the Responsible Conduct of Research on March 5,
WHAT IS HIPAA? The Health Insurance Portability and Accountability Act of 1996 (HIPAA) provides certain protections for any of your health information.
TM The HIPAA Privacy Rule: Safeguarding Health Information in Research and Public Health Practice Centers for Disease Control and Prevention Beverly A.
HIPAA Training Presentation for New Employees How did we get here? HIPAA Police 1.
Health Insurance Portability Accountability Act of 1996 HIPAA for Researchers: IRB Related Issues HSC USC IRB.
Implementation of Privacy Board Reviews at PCMC Mary Thomason, Intermountain Healthcare Privacy Board Chair.
Privacy and Information Security Essentials
August 10, 2001 NESNIP PRIVACY WORKGROUP HIPAA’s Minimum Necessary Standard Presented by: Mildred L. Johnson, J.D.
University of Miami1 HIPAA Survival Skills An Introduction to HIPAA and Research University of Miami Human Subjects Research Office October 31, 2006 Evelyne.
CUMC IRB Investigator Meeting November 9, 2004 Research Use of Stored Data and Tissues.
HIPAA COMPLIANCE IN YOUR PRACTICE MARIBEL VALENTIN, ESQUIRE.
Health Insurance Portability and Accountability Act (HIPAA)
HIPAA – Health Insurance Portability & Accountability Act and the Privacy Act MSgt Nechele M. Chambers Senior Enlisted Liaison TRICARE Area Office-Europe.
1 VUMC Confidentiality Policy and HIPAA Implications for Clinical Research General Clinical Research Center Skills Workshop March 2, 2007 Gaye Smith Privacy.
Paula Peyrani, MD Medical/Project Director, HIV Program at the 550 Clinic Assistant Director, Research Design and Development Clinical and Translational.
Confidentiality, Patient Safety Work Product, and PSOs The Proposed Rule Implementing the Patient Safety and Quality Improvement Act of 2005 AHRQ Annual.
1 Research & Accounting for Disclosures March 12, 2008 Leslie J. Pfeffer, BS, CHP Office of the Vice President for Research Administration Office of Compliance.
1 HIPAA OVERVIEW ETSU. 2 What is HIPAA? Health Insurance Portability and Accountability Act.
HIPAA Privacy and Research August 21, 2015
Health Insurance Portability and Accountability Act (HIPAA)
SACHRP HIPAA Recommendations: September 2004 Mark Barnes Huron Consulting Group March 3, 2009.
DATA SHARING and DATA SHARING AGREEMENTS Teresa Mulford MDCH, Office of Legal Affairs.
Computerized Networking of HIV Providers Workshop Data Security, Privacy and HIPAA: Focus on Privacy Joy L. Pritts, J.D. Assistant Research Professor Health.
HIPAA and Research Basics for IRB Tim Atkinson Director, Research and Sponsored Programs Director, Institutional Review Board Research Privacy Officer.
HIPAA – How Will the Regulations Impact Research?.
HIPAA Michigan Cancer Registrars Association 2005 Annual Educational Conference Sandy Routhier.
HIPAAand Disaster Situations By LYNDA M. JOHNSON Friday, Eldredge & Clark.
H I P A A T R A I N I N G Self Directed Module 7 Research Disclosures For Data Custodians START Click to begin…
Medical Law and Ethics, Third Edition Bonnie F. Fremgen Copyright ©2009 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved.
HIPAA SURVIVAL SKILLS: An Update University of Miami1 Marisabel Davalos, M.S.Ed., CIP Associate Director of Educational Initiatives November, 2008.
Privacy and Confidentiality. Definitions n Privacy - having control over the extent, timing, and circumstances of sharing oneself (physically, behaviorally,
Understanding HIPAA (Health Insurandce Portability and Accountability Act)
1 Developed by: U-MIC To start the presentation, click on this button in the lower right corner of your screen. The presentation will begin after the.
© 2013 The McGraw-Hill Companies, Inc. All rights reserved. Ch 8 Privacy Law and HIPAA.
Integrating a Federated Healthcare Data Query Platform With Electronic IRB Information Systems Shan He IPHIE 2010.
Health Insurance portability and Accountability Act (HIPAA)‏
A Road Map to Research at Jefferson: HIPAA Privacy and Security Rules for Researchers Presented By: Privacy Officer/Office of Legal Counsel October 2015.
HIPAA and Human Subjects Research IRB Member CE May 2014 Slideshow by Sean Horkheimer.
Configuring Electronic Health Records Privacy and Security in the US Lecture b This material (Comp11_Unit7b) was developed by Oregon Health & Science University.
HIPAA Privacy Rule Positive Changes Affecting Hospitals’ Implementation of the Rule.
PwC Issues in HIPAA Research Compliance William R. Braithwaite, MD, PhD “Dr. HIPAA” HIPAA Summit 6 Washington, DC 27 March 2003.
CH 10. Confidentiality A. Confidentiality about sensitive medical information is necessary to preserve the patient’s dignity. B. In order to receive payment.
Human Subjects Update E. Wethington, Chair, UCHS.
Final HIPAA Privacy Rule: The Research Provisions Julie Kaneshiro DHHS Office for Human Research Protections Phone: Fax:
HIPAA and RESEARCH 5 th Thursday May 31, Page 2.
HIPAA Privacy Rule Positive Changes Affecting Hospitals’ Implementation of the Rule Melinda Hatton -- Oct. 31, 2002.
HIPAA 2017 JHSPH IRB Clarifications and Changes
10 Patient Confidentiality and HIPAA
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA)
The HIPAA Privacy Rule: Implications for Medical Research
Confidential Records and Protected Disclosures
HIPAA PRIVACY AWARENESS, COMPLIANCE and ENFORCEMENT
Disability Services Agencies Briefing On HIPAA
The HIPAA Privacy Rule and Research
HIPAA Privacy & Security: Medical Research Context
Issues in HIPAA Research Compliance
Analysis of Final HIPAA Privacy Modification Rule
The Health Insurance Portability and Accountability Act
Presentation transcript:

Minding HIPAA & IRBs Cave Fatuis!

Elements HIPAA definitions of identifiable data Reducing risk of identifying people Research and IRB approval Business Associate Agreements Data protection Example of a GIS-web NO NO

HIPAA Health Insurance Portability and Accountability Act of 1996 (HIPAA) –“Covered Entities” health plans health care clearinghouses health care providers –Protected Health Information –Treatment, Payment and Healthcare Operations Department of Health and Human Services National Standards to Protect the Privacy of Personal Health Information.

HIPAA Research Resources

Research Can use protected Health Information if: –Obtain authorization from each patient –Have IRB or Privacy Board authorization waiver –Receive only a limited data set under a DUA with certain PHI elements removed –Use completely de-identified data –Are doing research preparation and need PHI data for this purpose

Research & IRB Independent researchers are not subject to the HIPAA Privacy Rule even with identifiable protected health information –A critical point of the Privacy Rule is that it applies only to individually identifiable health information held or maintained by a covered entity or its business associate acting for the covered entity. Individually identifiable health information that is held by anyone other than a covered entity, including an independent researcher who is not a covered entity, is not protected by the Privacy Rule and may be used or disclosed without regard to the Privacy Rule. There may, however, be other Federal and State protections covering the information held by these entities that limit its use or disclosure. Your problem may be from IRB and Human Protections enforcement

Identifying data features

Identifying data A covered entity may use statistical methods to establish de-identification without removing all 18 identifiers Can keep unique patient codes so long as they cannot be translated in a way that identifies patients Business Associates can be given role of de-identifying data

Research & IRB Research Use Without Authorization –Waiver of authorization approved by an Institutional Review Board (IRB) or a Privacy Board –Researchers unable to use de-identified information and it is not practicable to obtain research participants' authorization –IRB/privacy board approval requirements and criteria very prescriptive

Research & IRB Q: Does the Privacy Rule permit the creation of a database for research purposes through an IRB or Privacy Board waiver of individual authorization? A: Yes. A covered entity may use or disclose PHI without individuals' authorizations for the creation of a research database, provided the covered entity obtains documentation that an IRB or Privacy Board has determined that the specified waiver criteria were satisfied. PHI maintained in such a research database could be used or disclosed for future research studies as permitted by the Privacy Rule - that is, for future studies in which individual authorization has been obtained or where the rule would permit research without an authorization, such as pursuant to an IRB or Privacy Board waiver.

Research & IRB Certificate of Confidentiality –Protects against forced disclosure of data –For HHS conducted or supported research

Limited Data Sets & DUAs May not need an Authorization Waiver from an IRB or Privacy Board if you can work with PHI data that has the following removed:

Business Associate Agreement Contract Business Associate –will use the information only for the purposes for which they were engaged by the covered entity –safeguard the information from misuse –PHI disclosed to a business associate only to help providers/plans carry out their health care functions - not for independent use by the business associate –Not for research purposes for external consumption

BAA, cont’d Because a Business Associate receives protected health information to do work for a covered entity—the privacy rule still applies Covered entity is not liable for privacy violations of a business associate

Data Protection within GIS HIPAA rules, in an attempt to clarify what constitutes personal "identifiable" information, define data items such as a street address, ZIP Code, or an "equivalent geocode" as identifiable information that is subject to "de-identification." There is no Federal guidance about geographically displaying patient data and risk of identifying individuals

What we did No patient names are attached to data or addresses; Pin-mapping will be used rarely, and to prevent identification of patient homes, address dots will be mapped on street segments within a range of addresses and will be deliberately and randomly offset a distance of 0.1 mile from the actual location; No pin-mapping of disease specific data will be produced, only choropleth (census locations such as tracts or block groups, shaded to indicate statistic) maps of aggregate rates will be used. To prevent discovery in areas of extremely low population density, homes in census tracts or smaller geographical units with fewer than four diagnoses-cases will not be mapped (per Alpert and Haynes, 1994);

What we did All disease diagnoses will be ranked by frequency in a given patient population (highest to lowest) and the lowest 5% will be reassigned dummy variables to prevent the possibility of mapping rare diagnoses which may be more identifiable; We have developed a written data-sharing agreement for clinics and/or clinic systems who share data with us. This basic protocol (attached) may be modified (analyses made less revealing) to accommodate clinic concerns and will govern how data is used and published. Maps of diagnoses-data analyses will require review by relevant CHC advisory board(s) prior to publication. Based on extensive review, we believe this protocol is a higher standard than those used in South Carolina, Maryland (specifically Baltimore), and the District of Columbia as noted above.

What other’s are doing Jefferson County, Kentucky –In conjunction with U of Louisville Math Dept (Jennifer Ferrell) –Geographic Masking Displacement by Translation, Rotation, Change of Scale (common options) Random perturbation—random displacement in random direction (50 feet) was better method –SAS with SAS Bridge to ESRI

#1 vote-getter in priority issues for GIS in cancer control: Develop methods to ensure privacy and confidentiality while allowing access, especially with small data sets. Encourage collaborations among agencies, ethicists, HIPAA specialists, "maskers" to reduce ethical barriers to sharing data.

FIGURE 2 —Distribution of clients of the Men’s Health Center in Baltimore City, Maryland. Source. Map courtesy of Baltimore City Health Department. May 2003, Vol 93, No. 5 | American Journal of Public Health © 2003 American Public Health AssociationAmerican Public Health Association