Hypothetical Case Study

Slides:



Advertisements
Similar presentations
Davis Wright Tremaine LLP HIT Legal Issues: HIPAA Implications to a Regional Health Information Organization Becky Williams, R.N., J.D. Partner, Co-Chair,
Advertisements

Minimum Data-set for all mental health referrals.
Online Course Module 6 Guidelines for Contacting Patients START Click to begin…
How To Get To The Winners Circle with Your Patient Portal; Our Challenges To Get To The Finish Line. Julie Patterson, Baptist Health Carey Ronan, MHA,
Ex-Offenders and Housing
National Health Information Privacy and Security Week Understanding the HIPAA Privacy and Security Rule.
Who Must Comply? When is a patient authorization NOT required?  As needed for the protection of federal and state elective constitutional officers and.
How to Prepare for a FTCA Site Visit Office Hours
Medical Records Sara Alosaimy, bsc pharm
The Complete Procedure Coding Book By Shelley C. Safian, MAOM/HSM, CCS-P, CPC-H, CHA Chapter 4 Evaluation & Management Codes Part 1 Copyright © 2009 by.
FERPA The Family Educational Rights and Privacy Act (FERPA) also known as the Buckley Amendment, passed by Congress in 1974, grants four specific rights.
Safe Transitions Of Care STOC 2011 MHA Pilot- 4Q 2010 Transition responsibility belongs to the sending clinician/organization, until the receiving practitioners.
The Changing Landscape in Community Corrections and Supervision of High Risk Offenders San Francisco Juvenile Probation Department Juvenile Probation Commission.
Steps for Success in EHR Planning Bill French, VP eHealth Strategies Wisconsin Office of Rural Health HIT Implementation Workshop Stevens Point, WI August.
Facilitating the Subject Visit. Introduction Inpatient and Outpatient visits are conducted on both White 13 and on the 2 nd floor of Building 149 in the.
Medical Care Independent Living Consumer Rights & Responsibilities.
Consumer Rights & Responsibilities in Health Care-Unit 3 Adonis K. Lomibao, R.N.
One Health Information Exchange’s experience in responding to the changing landscape Funding: AHRQ Contract ; State of Tennessee; Vanderbilt.
Prepared by Commission staff for presentation purposes only. These slides should not be considered an official summary of the order or an official Commission.
© 2016 AHIMA Hill Day 2016: Exercising Your Voice Presenter: Lauren Riplinger, JD, Senior Director, Federal Relations.
A Pilot Study of Dexmedetomidine-Propofol in Children Undergoing Magnetic Resonance Imaging
Program Management Office (PMO) Design
NYS Health Home 101.
Peter van den Biggelaar Former CEO Dutch Legal Aid Board
Mental Health Program; CVH and M Site
Program Management Office (PMO) Design
Alaska Air Carrier Association
Admissions, Transfers, and Discharges
Consultant Nurse Learning Disabilities
Evaluation & Management Codes
Electronic Health Records (EHR)
Critical Incidents.
Medication Reconciliation ROP Compliance
Hospital influx scenarios
Evaluation and management (E/M) Services
General Data Protection Regulations: what you really need to know
1.02 Team Communication.
Clinical Engineering Lecture (3).
Program Management Office (PMO)
ArcGIS Web Part: Using Map information in SharePoint
Booz Allen Hamilton Standard Colors
Synchronized Predeployment Operational Tracker (SPOT)
Identifying & Assisting Victims within the Fracture Clinic
1.02 PP3 Team Communication.
HTHS240-Final Exam Zenobia Ursery.
1.02 Team Communication.
1.02 Team Communication.
الرسالة الأسبوعية من الشؤون الدينية المركــز الـرئيسي Central office
مقالات إدارية حبيبات القهوة!!!! مبيعات قطاع الأعمال - الأحساء
中国医疗制度 Medical System.
Program Management Office (PMO)
Program Management Office (PMO)
How we use Your Health Records
New Tool to Help Prevent Readmissions Modified LACE Tool
1.02 Team Communication By: Judylyn Hobson
Practice! First Grade End of year Breakfast
VASN Legislative Update
Colors Computers build colors from Red, Green, and Blue; not Red, Blue, and Yellow. RGB = Red Green Blue Creating Colors Red + Blue = Purple No Red, No.
Wootton Medical Centre High Street, Wootton Northampton NN4 6LW
1 2 3 a a a b b b You are the manager of the nursing unit at a large hospital. A situation recently occurred in which a nurse’s communications regarding.
What Color is it?.
FERPA and HIPAA for School Nurses and School Based Health Center Staff
Identifying & Assisting Victims within the Fracture Clinic
Team Communication.
1.02 Team Communication.
STOCKPORT TOGETHER: CONSULTATION MENTAL HEALTH CARERS GROUP
History Taking A. A full case history covers: Personal details
1.02 PP3 Team Communication.
Let’s Tango: Crisis Intervention Team and Emergency Department Nurses
Presentation transcript:

Hypothetical Case Study Health Care Privacy Exploring Issues Commonly Confronted by Privacy Officers Harvard University August 22, 2007 Dan Steinberg, JD, CIPP Booz Allen Hamilton (703) 377-1261 steinberg_daniel@bah.com Becky Williams, RN, JD Davis Wright Tremaine LLP (206) 757-8171 beckywilliams@dwt.com Booz Allen Hamilton Standard Colors Colors should be used in the color pairs whenever possible. Do not mix and match colors, use pairs together as shown. Black, White and Gray can be used with any of the other colors. Purple Pantone 2765 R 12 G 4 B 79 Green Pantone 357 R 15 G 67 B 24 Blue Pantone 2 88 R 11 G 31 B 101 Pantone Cool Gray 6 R 158 G 158 B 158 Davis Wright Tremaine LLP Black Red Pantone 485 R 252 G 5 B 14 Yellow Pantone 3965 R 232 G 244 B 4 Aqua Pantone 319 R 126 G 204 B 189 White

The Privacy Symposium’s Overall Goals. Identify current challenges in the field of health care privacy Identify and discuss best practices Define the responsibilities of a privacy officer Identify participants’ areas of interest and expertise

The events you are about to discuss take pace at Daviswright Hospital in the State of Boozylvania. A 500 bed teaching hospital Included in the provider network of the three major managed care companies (MCOs) that operate in the state of Boozylvania Affiliated with Boozylvania State University Medical School (Booz U. Med.) In 2006, made a large investment in an information management system that includes a system for maintaining electronic health records (EHRs) Employs a chief of IT operations and in-house counsel, but no privacy officer Divides privacy responsibilities among IT staff and legal staff You are general counsel and the chief compliance officer for Daviswright Hospital You also serve on its Institutional Review Board (IRB)

Case 1: When my CEO smiles at me, I go to a RHIO! Daviswright’s CEO tells you, “We’re joining the Boozylvania Regional Health Information Organization (RHIO)!” “We’re going to need to use the RHIO’s identity management system.” The RHIO won’t have special treatment for: Psychiatric records Substance abuse records AIDS/HIV “We’ll need to reformat all patients’ records. Let’s outsource the data transfer and reformatting responsibilities overseas.” “This should be straightforward, don’t you think?”

Case 2: “Sure I respect patient privacy Case 2: “Sure I respect patient privacy. But these people aren’t patients, they’re human subjects!” A call from a public health researcher from Boozylvania University is referred to you The proposed study concerns the connection between being the victim of violent crime and future ER visits and chronic illnesses Requires access to all patient records to formulate the project Once constructed, will need access to all EHRs, including histories that detail whether treatment was occasioned by a violent crime Will need some information about the subjects (neighborhood, treatment dates) Will not need patients’ names or other contact information Research will be conducted in conjunction with other researchers at institutions in different states The researcher intends to use an external institution's IRB as the IRB of record What concerns do you have? Who needs to be consulted?

Case 3: “If famous people wanted privacy, why did they become famous?” US Senator and former world ping pong champion Luke Beckenforth is admitted to Daviswright Hospital Internet rumors of suicide Actual chief complaint: impacted bowel Beckenforth has been highly medicated and sedated for over a day Over 300 calls have come into the hospital from: Concerned constituents Journalists Beckenforth’s staff Beckenforth’s estranged wife Hilda Senate colleagues concerned that he will be unavailable for upcoming critical floor votes What information, if any, should be released to each of these callers?

Case 4: This information is available on a “really-really-want-to-know” basis only. No exceptions. You request an audit of access to Beckenforth’s EHR Over 80% of staff with access to the EHR have accessed Beckenforth’s record You ask three staffers why they did so: One responds: “Given the high profile of this patient, I need to be ready to meet any of his needs.” The staffer is a nurse in the same department as the Senator but who has not yet been on a shift with the Senator Another person, a lab technician, says she was concerned about the Senator because she “admires and respects him” The last person admits that a reporter paid him to leak information What should you do now?

Case 5: Whether you blame genetics or environment, it’s best not to have stupid parents. Daviswright houses a genetic counseling service Genetic testing is performed under contract at Booz U. facilities Results are transmitted back to Daviswright Hospital All test results to the subject are delivered at a face-to-face appointment One genetic counselor, Sara Toanin, has lost her personal laptop She used to review records at home via open wireless Internet access points Her laptop contained over 300 patient records, including EHRs indicating records of genetic predispositions to cancer, carriers of genetic illnesses, and others What are your concerns? What are your next steps, now and in the future?

Contact Information Rebecca L. Williams, RN, JD Partner; Co-Chair of Health Information Technology/HIPAA Practice Davis Wright Tremaine LLP (206) 757-8171 beckywilliams@dwt.com Daniel Steinberg, JD, CIPP Associate Booz Allen Hamilton (703) 377-1261 steinberg_daniel@bah.com