Data Sharing Agreements TRICARE Management Activity HEALTH AFFAIRS 2009 Data Protection Seminar TMA Privacy Office.

Slides:



Advertisements
Similar presentations
H = P = A = HIPAA DEFINED HIPAA … A Federal Law Created in 1996 Health
Advertisements

Data Sharing In Accordance with HIPAA
Slide 1 Insert your own content. Slide 2 Insert your own content.
NIXON PEABODY LLP 1 Understanding the Marketing Restrictions of HIPAA Leigh-Ann M. Patterson Nixon Peabody LLP 101 Federal Street Boston, MA (617)
JCAHO –A HIPAA Business Associate National HIPAA Summit
Query Health Operations WG Face-to-Face Meeting 0ctober 18 & 19, 2011.
HIPAA Security Presentation to The American Hospital Association Dianne Faup Office of HIPAA Standards November 5, 2003.
The HIPAA Privacy Rule And Its Impact On Agents And Employers National Association of Health Underwriters Capitol Conference March 23, 2003 Joseph T. Holahan,
Todd Frech Ocius Medical Informatics 6650 Rivers Ave, Suite 137 North Charleston, SC Health Insurance Portability.
HIPAA Privacy Practices. Notice A copy of the current DMH Notice must be posted at each service site where persons seeking DMH services will be able to.
HIPAA AWARENESS TRAINING
0 - 0.
1 1  1 =.
The Legal Foundation TRICARE Management Activity HEALTH AFFAIRS 2009 Data Protection Seminar TMA Privacy Office.
Privacy Impact Assessment Future Directions TRICARE Management Activity HEALTH AFFAIRS 2009 Data Protection Seminar TMA Privacy Office.
A Guide to Compliant Data Management
Office for Human Research Protections 1 Updating the Common Rule Governing Human Subjects Research Protections Jerry Menikoff.
Privacy Act: System of Records Notices and Privacy Act Statements TRICARE Management Activity HEALTH AFFAIRS 2009 Data Protection Seminar TMA Privacy Office.
2009 Data Protection Seminar
Freedom of Information Act TRICARE Management Activity HEALTH AFFAIRS 2009 Data Protection Seminar TMA Privacy Office.
Privacy Trends TRICARE Management Activity HEALTH AFFAIRS 2009 Data Protection Seminar TMA Privacy Office.
Surveillance TRICARE Management Activity HEALTH AFFAIRS 2009 Data Protection Seminar TMA Privacy Office.
Privacy Reporting and Investment Certification TRICARE Management Activity HEALTH AFFAIRS 2009 Data Protection Seminar TMA Privacy Office.
Minimum Necessary Standard Version 1.0
Independent Contractor Orientation HIPAA What Is HIPAA? Health Insurance Portability and Accountability Act of 1996 The Health Insurance Portability.
Fort Bragg Civilian Personnel Advisory Center June 2014 System Access Nomination and Authorization Request (SANAR) HOW TO COMPLETE THE SANAR FORM.
- 1 - Defense Security Service Background: During the Fall of 2012 Defense Security Service will be integrating ISFD with the Identity Management (IdM)
1 Food Safety and Inspection Service Import Permit Policies Guidance for Products Containing Small Amounts of Meat, Poultry or Processed Egg Ingredients.
Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996 (HIPAA)
HIPAA Privacy Rule Compliance Training for YSU April 9, 2014.
Health Insurance Portability Accountability Act of 1996 HIPAA for Researchers: IRB Related Issues HSC USC IRB.
Implementation of Privacy Board Reviews at PCMC Mary Thomason, Intermountain Healthcare Privacy Board Chair.
August 10, 2001 NESNIP PRIVACY WORKGROUP HIPAA’s Minimum Necessary Standard Presented by: Mildred L. Johnson, J.D.
1 Developed by: U-MIC To start the presentation, click on this button in the lower right corner of your screen. The presentation will begin after the.
Health Insurance Portability and Accountability Act (HIPAA)
HIPAA – Health Insurance Portability & Accountability Act and the Privacy Act MSgt Nechele M. Chambers Senior Enlisted Liaison TRICARE Area Office-Europe.
2012 VA IRB Administrators Meeting Stephania H. Griffin, JD, RHIA, CIPP/G VHA Privacy Officer Director, Information Access and Privacy Privacy Officer.
Notice of Privacy Practices Nebraska SNIP Privacy Subgroup July 18, 2002 Michael J. Brown, MHA, CPA Vice-President, Administrative & Regulatory Affairs,
DEFENSE PRIVACY & CIVIL LIBERTIES OFFICE Privacy Foundations Samuel P. Jenkins Director for Privacy Defense Privacy and Civil Liberties Office Identity.
Navy PAD Symposium Samuel P. Jenkins, CHE TMA Privacy Officer HEALTH AFFAIRS TRICARE Management Activity This document contains proprietary information.
HIPAA PRIVACY AND SECURITY AWARENESS.
DSDS Quality Assurance Unit State of Alaska, Dept. of Health and Social Services Division of Senior and Disabilities Services (DSDS) Quality Assurance.
1 HIPAA OVERVIEW ETSU. 2 What is HIPAA? Health Insurance Portability and Accountability Act.
1 Defense Health Agency Privacy and Civil Liberties Office HIPAA Privacy Board Overview August 6, 2015.
Computerized Networking of HIV Providers Workshop Data Security, Privacy and HIPAA: Focus on Privacy Joy L. Pritts, J.D. Assistant Research Professor Health.
1 Defense Health Agency Privacy and Civil Liberties Office Data Sharing Program Overview Ms. Rita DeShields DHA Data Sharing Compliance Manager August.
1 Personnel Security 2007 Data Protection Seminar TMA Privacy Office HEALTH AFFAIRS TRICARE Management Activity.
HIPAA – How Will the Regulations Impact Research?.
Utilizing the CMS Security Risk Assessment Tool Liz Hansen, PCMH CEC, ICD-10 PMC Special Consultant, GA-HITEC Member Manager, GaHIN
HIPAA Michigan Cancer Registrars Association 2005 Annual Educational Conference Sandy Routhier.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
FleetBoston Financial HIPAA Privacy Compliance Agnes Bundy Scanlan Managing Director and Chief Privacy Officer FleetBoston Financial.
C HAPTER 34 Code Blue Health Sciences Edition 4. Confidentiality of sensitive information is an important issue in healthcare. Breaches of confidentiality.
HIPAA Privacy Rules: What Are Plan Sponsors Required to Do?
HIPAA History March 3, HIPAA Ruling Health Insurance Portability Accountability Act Health Insurance Portability Accountability Act Passed by Congress.
Copyright © 2015 by Saunders, an imprint of Elsevier Inc. All rights reserved. Chapter 3 Privacy, Confidentiality, and Security.
HIPAA Health Insurance Portability and Accountability Act.
©2002 by the National Committee for Quality Assurance NCQA and HIPAA “A match made in ?” The Fifth National HIPAA Summit Sharon King Donohue, JD General.
Final HIPAA Privacy Rule: The Research Provisions Julie Kaneshiro DHHS Office for Human Research Protections Phone: Fax:
HIPAA 2017 JHSPH IRB Clarifications and Changes
To start the presentation, click on this button in the lower right corner of your screen. The presentation will begin after the screen changes and you.
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA)
HIPPA/HITECH Act Requirements Under the Business Associate Agreement Between CNI and Military Health Services.
Privacy Notice - Requirements
HIPAA Pros - Minimum Necessary
HIPAA Security Standards Final Rule
Enforcement and Policy Challenges in Health Information Privacy
Analysis of Final HIPAA Privacy Modification Rule
Presentation transcript:

Data Sharing Agreements TRICARE Management Activity HEALTH AFFAIRS 2009 Data Protection Seminar TMA Privacy Office

TRICARE Management Activity HEALTH AFFAIRS 22 Data Sharing Agreements Purpose The purpose of this presentation is to review the role of the TRICARE Management Activity (TMA) Privacy Office, the current Data Use Agreement (DUA) process, and provide an update on the status of the data sharing restructuring initiative

TRICARE Management Activity HEALTH AFFAIRS 33 Data Sharing Agreements Objectives Upon completion of this presentation, you should be able to: Explain the role of the TMA Privacy Office in authorizing access to Military Health System (MHS) corporate data Understand the current DUA process Recognize the status of the data sharing restructuring initiative

TRICARE Management Activity HEALTH AFFAIRS 44 Data Sharing Agreements Role of the TMA Privacy Office The role of the TMA Privacy Office is to authorize use and disclosure of Military Health System (MHS) data that are owned and/or managed by Health Affairs (HA) and TMA and ensure compliance with applicable privacy regulations, including: DoD R (implementing the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule) DoD R (implementing the Privacy Act of 1974) DoD R (implementing the HIPAA Security Regulations) There is a separate process managed by Defense Health Services Systems (DHSS) that is required in order to obtain access to information system applications

TRICARE Management Activity HEALTH AFFAIRS 55 Data Sharing Agreements Who Must Submit a Request? A person or entity that seeks to obtain MHS data that are owned and/or managed by HA and TMA must submit a request to the TMA Privacy Office A person or entity seeking data from the Army, Navy, or Air Force data must direct their request to the respective service as follows: Army DUA Submissions: Navy DUA Submissions: Air Force Submissions:

TRICARE Management Activity HEALTH AFFAIRS 66 Data Sharing Agreements Current Types of DUAs Two types of frequently used DUAs Protected Health Information (PHI) and Beneficiary Encrypted Files De-Identified Files

TRICARE Management Activity HEALTH AFFAIRS 77 Data Sharing Agreements Overview of Current Process The term DUA is currently used in a broad sense and includes different types of agreements for the sharing of MHS data The purpose of DUAs under the current structure is to: Serve as an agreement between a recipient of MHS data and the TMA Privacy Office Document compliance with DoD regulations and applicable privacy laws Identify the minimally necessary data required to meet a specific data request Outline the permitted uses and disclosures

TRICARE Management Activity HEALTH AFFAIRS 88 Data Sharing Agreements Restructuring Initiative

TRICARE Management Activity HEALTH AFFAIRS 99 Data Sharing Agreements Purpose of the Restructuring Initiative To more closely align the data sharing process with DoD Health Information Privacy Regulation (DoD R) To streamline the process and provide more targeted data sharing agreements, and To enhance regulatory compliance and accountability

TRICARE Management Activity HEALTH AFFAIRS 10 Data Sharing Agreements Focusing on the Different Needs Who is the recipient? DoD, Government (non-DoD), Non-government Why is the request being made? Quality Assurance Research Maintenance of an MHS system Other – to be reviewed by the TMA Privacy Office

TRICARE Management Activity HEALTH AFFAIRS 11 What data is used/disclosed? De-identified data Sensitive information Limited data set Personally Identifiable Information (PII) and/or Protected Health Information (PHI) Data Sharing Agreements Focusing on the Different Needs (continued)

TRICARE Management Activity HEALTH AFFAIRS 12 Data Sharing Agreements Laying a Strong Foundation The TMA Privacy Office is analyzing all different types of data sharing requests in order to ultimately improve clarity, regulatory compliance, and ease-of-use; this has included: Taking a close look at research-related requests and collaborating with others Streamlining collaboration with DHSS to help expedite access Reviewing different needs and requirements for de-identified data, limited data sets, quality assurance purposes, health care operations, managed care support contracts, public health, etc. Clearly identifying contract verification needs for business associates Updating the current System Assurance Questionnaire

TRICARE Management Activity HEALTH AFFAIRS 13 Data Sharing Agreements Next Steps Reformat the current DUA (interim step) Finalize the System Security Verification, which will replace the current System Assurance Questionnaire Continue collaboration and effort to finalize an improved process for research-related requests Complete a data sharing questionnaire which will lead to different agreements and verifications, as required, to meet all needs within the three Ws (slide 10) Explore the use of Health Program Analysis & Evaluation Division (HPA&E) web portal for launching the new restructure

TRICARE Management Activity HEALTH AFFAIRS 14 Data Sharing Agreements Summary You should now be able to: Explain the role of the TMA Privacy Office in authorizing access to MHS corporate data Understand the current DUA process Recognize the status of the data sharing restructuring initiative

TRICARE Management Activity HEALTH AFFAIRS 15 Data Sharing Agreements Resources DoD R, DoD Health Information Privacy Regulation, January 2003 DoD R, DoD Privacy Program, May 14, 2007 DoD R, DoD Health Information Security Regulation, July 12, 2007