HIPAA Privacy and Some Research

Slides:



Advertisements
Similar presentations
The Role of the IRB An Institutional Review Board (IRB) is a review committee established to help protect the rights and welfare of human research subjects.
Advertisements

HIPAA: An Overview of Transaction, Privacy and Security Regulations Training for Providers and Staff.
And the finer details of patient privacy TCH Confidential Understanding HIPAA.
Health Insurance Portability and Accountability Act HIPAA Education for Volunteers and Students.
HIPAA Basic Training for Privacy & Information Security Vanderbilt University Medical Center VUMC HIPAA Website:
HIPAA Training for the MDAA Preceptorship Program Health Insurance Portability and Accountability Act.
Copyright Eastern PA EMS Council February 2003 Health Information Portability and Accountability Act It’s the law.
COBB/DOUGLAS COMMUNITY SERVICES BOARD Confidentiality and Privacy of Consumer Information.
National Health Information Privacy and Security Week Understanding the HIPAA Privacy and Security Rule.
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
1 HIPAA Education CCAC Professional Development Training September 2006 CCAC Professional Development Training September 2006.
NAU HIPAA Awareness Training
HIPAA Privacy Rule Compliance Training for YSU April 9, 2014.
 The Health Insurance Portability and Accountability Act of  Federal Law designed to protect sensitive information.  HIPAA violations are enforced.
Health Insurance Portability and Accountability Act (HIPAA)
HIPAA What’s Said Here – Stays Here…. WHAT IS HIPAA  Health Insurance Portability and Accountability Act  Purpose is to protect clients (patients)
Health Insurance Portability and Accountability Act (HIPAA)
HIPAA Basic Training for Privacy and Information Security Vanderbilt University Medical Center VUMC HIPAA Website: HIPAA Basic.
SECURITY: Personal Health Information Protection Act, 2004 this 5 min. course covers: changing landscape of electronic health records security threats.
Cornell Evaluation Network The Use of Human Participants in Research Office of Research Integrity and Assurance ~ May 14, 2007.
Privacy and Security of Protected Health Information NorthPoint Health & Wellness Center 2011.
 Understanding the IRB Process University of Tennessee Health Science Center Institutional Review Board.
HIPAA OBJECTIVES  Define HIPAA  Define PHI  Use of PHI  Your rights  Your responsibilities.
Confidentiality and Drug Courts Carson Fox Esq. Steve Hanson M.S. Ed.
Submitting IRB Applications (or “Do I have to do an IRB?”) Linda A. Detman, Ph.D. Research Associate Lawton & Rhea Chiles Center for Healthy Mothers and.
Medical Law and Ethics, Third Edition Bonnie F. Fremgen Copyright ©2009 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved.
Building a Privacy Foundation. Setting the Standard for Privacy Health Insurance Portability and Accountability Act (HIPAA) Patient Bill of Rights Federal.
Health Insurance Portability and Accountability Act (HIPAA) CCAC.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
Understanding HIPAA (Health Insurandce Portability and Accountability Act)
Mr. Fleming.  Law passed by Congress in  Right to Privacy ◦ Medical information of patient can only be shared with doctor and professionals administering.
© 2013 The McGraw-Hill Companies, Inc. All rights reserved. Ch 8 Privacy Law and HIPAA.
HIPAA THE PRIVACY RULE. 2 HISTORY In 2000, many patients that were newly diagnosed with depression received free samples of anti- depressant medications.
Institutional Review Board Issues for Classroom Research Sharon McWhorter IRB Administrator, The University of Akron (With assistance from Phil Allen,
A Road Map to Research at Jefferson: HIPAA Privacy and Security Rules for Researchers Presented By: Privacy Officer/Office of Legal Counsel October 2015.
HIPAA and Human Subjects Research IRB Member CE May 2014 Slideshow by Sean Horkheimer.
HIPAA Overview Why do we need a federal rule on privacy? Privacy is a fundamental right Privacy can be defined as the ability of the individual to determine.
HIPAA for Students Health Insurance Portability and Accountability Act.
HIPAA Training. What information is considered PHI (Protected Health Information)  Dates- Birthdays, Dates of Admission and Discharge, Date of Death.
The Medical College of Georgia HIPAA Privacy Rule Orientation.
COMMUNITY-WIDE HEALTH INFORMATION EXCHANGE: HIPAA PRIVACY AND SECURITY ISSUES Ninth National HIPAA Summit September 14, 2004 Prepared by: Robert Belfort,
The Health Insurance Portability and Accountability Act (HIPAA) requires Plumas County to train all employees in covered departments about the County’s.
Collaborative Institutional Training Initiative (CITI) citiprogram.org Georgia Institute of Technology.
Health Insurance Portability and Accountability Act (HIPAA) Primer for Observers, Volunteers, Medical Students Dr. Michael Palumbo- Privacy Officer/ EVP.
Health Insurance Portability and Accountability Act
HIPAA Privacy and Security
Protecting PHI & PII 12/30/2017 6:45 AM
HIPAA PRIVACY & SECURITY TRAINING
HIPAA Privacy & Security
And the finer details of patient privacy
Use of BMC Patient Information Privacy & Security
Reid Cushman, UM Ethics Programs
Privacy & Confidentiality
Welcome New IRB Members!
HIPAA Basic Training for Privacy and Information Security
Health Insurance Portability and Accountability Act
HIPAA PRIVACY AWARENESS, COMPLIANCE and ENFORCEMENT
Disability Services Agencies Briefing On HIPAA
The HIPAA Privacy Rule and Research
Streamlining IRB Procedures for Expanded Access
Health Insurance Portability and Accountability Act
HIPAA Privacy & Security
HIPAA Overview.
HIPAA Privacy and Security Update - 5 Years After Implementation
Health Insurance Portability and Accountability Act
HIPAA Do’s and Don'ts: What is Really Behind Protected Health Information (PHI) and Health Care Privacy Rules Paul Sisler, Director, Information Services;
Health Insurance Portability and Accountability Act
Protecting Student Data
The Health Insurance Portability and Accountability Act
School of Medicine Orientation Information Security Training
Presentation transcript:

HIPAA Privacy and Some Research Maria J. Pekar, MBA, JD Associate General Counsel Loyola University Health System March 27, 2019

Objectives Describe how the Health Insurance Portability and Accountability Act (HIPAA) applies to Loyola University Health System and you. List State of Illinois laws that require stricter confidentiality than described in HIPAA. Describe the federal rules on human subject research.

HIPAA

What is the HIPAA law? Allows employees to change jobs without a gap in health insurance coverage Standardizes electronic health care transactions Regulates the privacy and security of health information Speak to intent of the law Remember Arthur Ashe 4

A Physician’s HIPAA Hats Provider Teacher Researcher

Physician as Provider No minimum necessary requirement for treatment “Need to know” still applies Provider to provider contact may continue Need to account for some disclosures Remember state laws may be more stringent Still need patient consent to treat Incidental disclosures are OK

Physician as Teacher Physicians may discuss a patient’s condition during training rounds Physicians and students should consider surroundings during instruction Notes count too (students or otherwise) Use appropriate security for notes w/PHI Keep notes in confidence Those who have access to PHI with no direct patient contact still have to keep PHI confidential.

Physician as Researcher HIPAA regulates the privacy of the patient information related to research There are other laws that regulate the conduct of research DHHS Common Rule FDA Part 21 LUMC may condition study participation on obtaining the study participant’s authorization to use and disclose PHI How can you participate in a study if the Researcher can’t use your information? Disclosures to sponsors must be the same as what study participants have been told sponsors will receive

Electronic Environment Emails Transmitting PHI electronically must be accomplished securely Understand system-wide policy on email communications containing PHI Sending unencrypted email containing PHI over the internet violates LUMC policy (including gmail) Internal communication can take place via internal email systems External patient communication can take place via My Loyola, which is password protected and behind our fire wall

Epic Access Login ID and password Log-off or else you are accountable for inappropriate access Don’t share your passwords Avoid looking up a friend or colleague’s record out of curiosity Refrain from viewing a family member’s record out of concern Don’t look back-post service

Social Media No tweets, Facebook statuses or Instagram posts should contain PHI Don’t blog interesting cases Don’t upload or text pictures of patients

Best Practices in General Password protect phones & lap tops Select “logon” screen savers for computers Avoid saving PHI to CD ROMs , thumb or hard drives (including desktops and laptops) Ensure it’s OK w/the patient to discuss care w/family & friends Verify callers where necessary Avoid faxing when possible Don’t leave Epic print-outs in odd places

State Information Laws

State Laws Generally federal law “trumps” or “pre-empts” State law HIPAA pre-empts State law unless the State law: Provides greater privacy protections to a patient’s information; OR Affords great access to information rights to a patient

State “Information” Laws Mental Health & Developmental Disabilities Confidentiality Act AIDS Confidentiality Act Genetic Information Privacy Act Medical Patient Rights Act Alcohol & Substance Abuse Act Personal Information Privacy Act From your 2011 SEP lecture 15

Human Subject Research

Common Rule (1981) Federal law governing human subject research Many federal agencies follow this research rule Baseline standard of ethics by which any government-funded research is held Regulates oversight board (IRB) Applies to federally funded research activities Contains additional protections for vulnerable populations (e.g., pregnant women, children, prisoners)

FDA & Human Subjects Research FDA Part 21 contains many of the FDA regulations related to human subject research FDA mostly regulates food, drugs, cosmetics and device research FDA regulations parallel many sections of the Common Rule but are not identical IRB responsibilities are mostly consistent There are additional reporting responsibilities too

Institutional Review Board Committee formally designated to approve, monitor and review research involving humans They conduct some form of risk-benefit analysis Number one priority is to protect human subjects from physical or psychological harm Determines whether study requires full board or expedited review or is exempt

Principle Investigator Role May design a protocol or conduct an externally sponsored study Responsible for ensuring: the protocol is followed; informed consent is obtained; subjects are protected; and, investigational product/device is controlled Common Rule unlike FDA rules does not directly address PI responsibilities

Medical Student as Researcher Possible Research Role Collect or coordinate research data Identify and compile lists of potential research subjects in accordance with study objectives Review or edit data for completeness and accuracy Integrity of study results depends on data collection Professional competency may be enhanced by understanding evidence-based medicine

Summary Patients have a Federal right to privacy State laws may afford greater protections Research is regulated; know the rules https://www.youtube.com/watch?v=915YsKGvHec&feature=youtu.be

Questions?