Mayo Clinic Privacy Office Communications Division Meeting: Patient Consents April Carlson May 2016
Why is April here today? New York-Presbyterian Hospital to pay $2.2 million for 'egregious disclosure' of PHI in HIPAA violation NYP's actions while filming the TV show 'NY Med' blatantly violated HIPAA rules, said Jocelyn Samuels of the Office for Civil Rights. TV series “NY Med” in July 2012 (Dr. Oz) ABC film crew allowed to film in hospital 2 patients filmed/broadcast without consent NYP Privacy Officer had no knowledge Source (http://www.healthcareitnews.com/news/newyork-presbyterian-hospital-pay-22-million-egregious-disclosure-phi-hipaa-violation)
Mayo Clinic Privacy Office Work unit within Integrity and Compliance Office Located on Plummer 6 Comprised of: Mayo Clinic Privacy Officer 2 Senior Privacy Analysts 4 Privacy Analysts 6 Site/Regional Privacy Officers
Privacy Regulations Health Insurance Portability and Accountability Act of 1996 (HIPAA) Set of standards and processes implemented to protect individuals against the unauthorized use and disclosure of protected health information (PHI) Covered entities may use/disclose a patient’s PHI for treatment, payment, and health care operations For any other reason, the patient must give consent Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH)
HITECH Requirements When a breach occurs where PHI has been comprised, Mayo Clinic must provide notification to: Individual(s) affected by breach Government (HHS) Media Outlets (>500 affected patients) Notification must be provided within 60 days of discovery; 30 days in Florida
Protected Health Information (PHI) Information that: Relates to past, present, or future physical or mental health conditions Relates to a person’s eligibility for health care Relates to payments for healthcare Identifies or could identify an individual patient Is created or received by a healthcare organization
Examples of PHI Personal identifiers Diagnosis Specific dates Social Security Number Medical records (paper & electronic) Medical record number Verbal or written communication about patients Patient information on white boards Photographs/videos (unintentional PHI in employee photos)
Patient Consents at Mayo Clinic Release of Information Authorizations Campus Auth Auth to Disclose Auth to Release Media Support Services Media Release (photograph, video, interview) Photography and Videography Policy
Pop Quiz The ABC film crew contacts you tomorrow and wants to shoot footage for a “hot” new medical documentary. They are requesting to film patients flown in by Mayo One to the St. Marys Emergency Department. What form do you use?
Contact Privacy Mayo Clinic Office for Integrity and Compliance – Privacy Office Internal: (77) 6-6286 External: (507) 266-6286 Email: DL Enterprise Privacy Office To report a suspected violation anonymously, you may contact Mayo’s Integrity and Compliance Hotline: Toll-free: 888-721-5391 Online: www.MayoClinicComplianceReport.com
Report Privacy Incidents Go to Office for Integrity and Compliance web page Select Privacy tab and then Privacy Incident Reporting Form
Questions & Discussion