HIPAA and Public Health 2007 Epi Rapid Response Team Conference.

Slides:



Advertisements
Similar presentations
HIPAA Privacy Rule “Standards for Privacy of Individually Identifiable Health Information” 45 CFR 160 and 164* *
Advertisements

NATIONAL FORUM ON YOUTH VIOLENCE PREVENTION: HIPAA PRIVACY RULE CONSIDERATIONS November 1, 2011 Iliana L. Peters, JD, LLM HHS Office for Civil Rights.
HIPAA and Privacy An Overview of the New Federal Requirements of the Health Insurance Portability and Accountability Act (HIPAA) Reid Cushman, UM Ethics.
HIPAA Privacy Training. 2 HIPAA Background Health Insurance Portability and Accountability Act of 1996 Copyright 2010 MHM Resources LLC.
COBB/DOUGLAS COMMUNITY SERVICES BOARD Confidentiality and Privacy of Consumer Information.
HIPAA – Privacy Rule and Research USCRF Research Educational Series March 19, 2003.
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
HIPAA PRIVACY REQUIREMENTS Dana L. Thrasher Constangy, Brooks & Smith, LLC (205) ; Victoria Nemerson.
HIPAA Health Insurance Portability and Accountability Act.
What is HIPAA? This presentation was created by The University of Arizona Privacy Office, The Office for the Responsible Conduct of Research on March 5,
1 HIPAA Education CCAC Professional Development Training September 2006 CCAC Professional Development Training September 2006.
WHAT IS HIPAA? The Health Insurance Portability and Accountability Act of 1996 (HIPAA) provides certain protections for any of your health information.
TM The HIPAA Privacy Rule: Safeguarding Health Information in Research and Public Health Practice Centers for Disease Control and Prevention Beverly A.
Informed Consent.
HIPAA Privacy Rule Compliance Training for YSU April 9, 2014.
 The Health Insurance Portability and Accountability Act of  Federal Law designed to protect sensitive information.  HIPAA violations are enforced.
COMPLYING WITH HIPAA PRIVACY RULES Presented by: Larry Grudzien, Attorney at Law.
HIPAA THE PRIVACY RULE Reviewed December HISTORY In 2000, many patients that were newly diagnosed with depression received free samples of anti-
Professional Nursing Services.  Privacy and Security Training explains:  The requirements of the federal HIPAA/HITEC regulations, state privacy laws.
University of Miami1 HIPAA Survival Skills An Introduction to HIPAA and Research University of Miami Human Subjects Research Office October 31, 2006 Evelyne.
HIPAA COMPLIANCE IN YOUR PRACTICE MARIBEL VALENTIN, ESQUIRE.
HIPAA Health Insurance Portability & Accountability Act of 1996.
Health Insurance Portability and Accountability Act (HIPAA)
Protected Health Information (PHI). Privileged Communication An exchange of information between two individuals in a confidential relationship. (Examples:
Proprietary and confidential and may not be reproduced or distributed without the express consent of Cap Gemini Ernst & Young U.S. LLC and Ernst & Young.
Paula Peyrani, MD Medical/Project Director, HIV Program at the 550 Clinic Assistant Director, Research Design and Development Clinical and Translational.
HIPAA PRIVACY AND SECURITY AWARENESS.
1 Research & Accounting for Disclosures March 12, 2008 Leslie J. Pfeffer, BS, CHP Office of the Vice President for Research Administration Office of Compliance.
1 HIPAA OVERVIEW ETSU. 2 What is HIPAA? Health Insurance Portability and Accountability Act.
14 May Privacy Requirements Phoenix Ambulatory Blood Pressure Monitoring System © 2006 Christopher J. Adams Copying and distribution of this document.
Health Insurance Portability and Accountability Act (HIPAA)
Health information that does not identify an individual and with respect to which there is no reasonable basis to believe that the information can be.
Computerized Networking of HIV Providers Workshop Data Security, Privacy and HIPAA: Focus on Privacy Joy L. Pritts, J.D. Assistant Research Professor Health.
HIPAA – How Will the Regulations Impact Research?.
HIPAA Michigan Cancer Registrars Association 2005 Annual Educational Conference Sandy Routhier.
© 2009 The McGraw-Hill Companies, Inc. All rights reserved. 1 McGraw-Hill Chapter 2 The HIPAA Privacy Standards HIPAA for Allied Health Careers.
Medical Law and Ethics, Third Edition Bonnie F. Fremgen Copyright ©2009 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved.
Health Insurance Portability and Accountability Act (HIPAA) CCAC.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
Understanding HIPAA (Health Insurandce Portability and Accountability Act)
FleetBoston Financial HIPAA Privacy Compliance Agnes Bundy Scanlan Managing Director and Chief Privacy Officer FleetBoston Financial.
HIPAA THE PRIVACY RULE. 2 HISTORY In 2000, many patients that were newly diagnosed with depression received free samples of anti- depressant medications.
HIPAA Health Insurance Portability and Accountability Act of 1996.
Health Insurance portability and Accountability Act (HIPAA)‏
A Road Map to Research at Jefferson: HIPAA Privacy and Security Rules for Researchers Presented By: Privacy Officer/Office of Legal Counsel October 2015.
Configuring Electronic Health Records Privacy and Security in the US Lecture b This material (Comp11_Unit7b) was developed by Oregon Health & Science University.
HIPAA Overview Why do we need a federal rule on privacy? Privacy is a fundamental right Privacy can be defined as the ability of the individual to determine.
PwC Issues in HIPAA Research Compliance William R. Braithwaite, MD, PhD “Dr. HIPAA” HIPAA Summit 6 Washington, DC 27 March 2003.
CH 10. Confidentiality A. Confidentiality about sensitive medical information is necessary to preserve the patient’s dignity. B. In order to receive payment.
Human Subjects Update E. Wethington, Chair, UCHS.
Table of Contents. Lessons 1. Introduction to HIPAA Go Go 2. The Privacy Rule Go Go.
The Health Insurance Portability and Accountability Act of 1996 “HIPAA” Public Law
Final HIPAA Privacy Rule: The Research Provisions Julie Kaneshiro DHHS Office for Human Research Protections Phone: Fax:
Privacy: HIPAA Emerson Murphy-Hill. Rosie Callender, RHIA, web.msm.edu/hipaa/An%20Introduction%20to%20HIPAA.ppt What is HIPAA? A Federal Law Created in.
HIPAA and RESEARCH 5 th Thursday May 31, Page 2.
HIPAA Training Workshop #3 Individual Rights Kaye L. Rankin Rankin Healthcare Consultants, Inc.
HIPAA PRIVACY & SECURITY TRAINING
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA)
What is HIPAA? HIPAA stands for “Health Insurance Portability & Accountability Act” It was an Act of Congress passed into law in HEALTH INSURANCE.
HIPAA Administrative Simplification
HIPAA PRIVACY AWARENESS, COMPLIANCE and ENFORCEMENT
Disability Services Agencies Briefing On HIPAA
National Congress on Health Care Compliance
New School Violence Law; HIPAA Privacy Training
Issues in HIPAA Research Compliance
The Health Insurance Portability and Accountability Act
Office of the Vice President for Research Human Subjects Protection Program IRB Submission Process Module 4 - Health Insurance Portability and Accountability.
The Health Insurance Portability and Accountability Act
Presentation transcript:

HIPAA and Public Health 2007 Epi Rapid Response Team Conference

HIPAA Standard The HIPAA Privacy Rule provides the first national standards for protecting the privacy of health information. (Standard) The HIPAA Privacy Rule provides the first national standards for protecting the privacy of health information. (Standard) The Privacy Rule regulates how certain entities, called covered entities, use and disclose certain individually identifiable health information, called protected health information (PHI). The Privacy Rule regulates how certain entities, called covered entities, use and disclose certain individually identifiable health information, called protected health information (PHI). PHI is individually identifiable health information PHI is individually identifiable health information

Legislative History Health Insurance Portability and Accountability Act of 1996 (HIPAA) Health Insurance Portability and Accountability Act of 1996 (HIPAA) Subtitle F--Administrative Simplification Subtitle F--Administrative Simplification Encourage development of (electronic) health information technologies (transactions) Encourage development of (electronic) health information technologies (transactions) Easier information sharing—security and privacy Easier information sharing—security and privacy

HIPAA … gives patients more control over their health information gives patients more control over their health information sets boundaries on the use and release of health records sets boundaries on the use and release of health records establishes appropriate safeguards that the majority of health- care providers and others must achieve to protect the privacy of health information establishes appropriate safeguards that the majority of health- care providers and others must achieve to protect the privacy of health information holds violators accountable with civil and criminal penalties that can be imposed if they violate patients' privacy rights holds violators accountable with civil and criminal penalties that can be imposed if they violate patients' privacy rights strikes a balance when public health responsibilities support disclosure of certain forms of data strikes a balance when public health responsibilities support disclosure of certain forms of data

HIPAA … enables patients to make informed choices based on how individual health information may be used enables patients to make informed choices based on how individual health information may be used enables patients to find out how their information may be used and what disclosures of their information have been made enables patients to find out how their information may be used and what disclosures of their information have been made generally limits release of information to the minimum reasonably needed for the purpose of the disclosure generally limits release of information to the minimum reasonably needed for the purpose of the disclosure generally gives patients the right to obtain a copy of their own health records and request corrections generally gives patients the right to obtain a copy of their own health records and request corrections empowers individuals to control certain uses and disclosures of their health information empowers individuals to control certain uses and disclosures of their health information

Scope: Who is Covered? Limited by HIPAA to: Limited by HIPAA to: Health care providers who transmit health information in electronic transactions Health care providers who transmit health information in electronic transactions Health plans Health plans Health care clearinghouses Health care clearinghouses Business associate relationships Business associate relationships

Scope: What is Covered? Protected health information (PHI) is: Protected health information (PHI) is: Individually identifiable health information Individually identifiable health information Transmitted or maintained in any form or medium Transmitted or maintained in any form or medium Held by covered entities or their business associates Held by covered entities or their business associates De-identified information is not covered De-identified information is not covered

Individual’s Rights Individuals have the right to: Individuals have the right to: A written notice of information practices from health plans and providers A written notice of information practices from health plans and providers Inspect and obtain a copy of their PHI Inspect and obtain a copy of their PHI Obtain an accounting of disclosures Obtain an accounting of disclosures Amend their records Amend their records Request restrictions on uses and disclosures Request restrictions on uses and disclosures Accommodation of reasonable communication requests Accommodation of reasonable communication requests Complain to the covered entity and to HHS Complain to the covered entity and to HHS

Day-to-day Data Sharing with Public Health Disclosures permitted if required by law Disclosures permitted if required by law Disclosures also permitted for “public health activities and purposes” Disclosures also permitted for “public health activities and purposes” Consent or authorization not required for above disclosures Consent or authorization not required for above disclosures Rule does not require public health disclosures Rule does not require public health disclosures

Information Types De-Identified Information - require no individual privacy protections and are not covered by the Privacy Rule. De-Identified Information - require no individual privacy protections and are not covered by the Privacy Rule. statistical de-identification --- a properly qualified statistician using accepted analytic techniques concludes the risk is substantially limited that the information might be used, alone or in combination with other reasonably available information, to identify the subject of the information; or the statistical de-identification --- a properly qualified statistician using accepted analytic techniques concludes the risk is substantially limited that the information might be used, alone or in combination with other reasonably available information, to identify the subject of the information; or the safe-harbor method --- a covered entity or its business associate de- identifies information by removing 18 identifiers and the covered entity does not have actual knowledge that the remaining information can be used alone or in combination with other data to identify the subject. safe-harbor method --- a covered entity or its business associate de- identifies information by removing 18 identifiers and the covered entity does not have actual knowledge that the remaining information can be used alone or in combination with other data to identify the subject.

Information Types Limited Data Set - Health information in a limited data set is not directly identifiable, but may contain more identifiers than de-identified data that has been stripped of the 18 identifiers. Limited Data Set - Health information in a limited data set is not directly identifiable, but may contain more identifiers than de-identified data that has been stripped of the 18 identifiers.

Limited Data Set A data-use agreement must establish who is permitted to use or receive the limited data set, and provide that the recipient will A data-use agreement must establish who is permitted to use or receive the limited data set, and provide that the recipient will not use or disclose the information other than as permitted by the agreement or as otherwise required by law; not use or disclose the information other than as permitted by the agreement or as otherwise required by law; use appropriate safeguards to prevent uses or disclosures of the information that are inconsistent with the data-use agreement; use appropriate safeguards to prevent uses or disclosures of the information that are inconsistent with the data-use agreement; report to the covered entity any use or disclosure of the information, in violation of the agreement, of which it becomes aware; report to the covered entity any use or disclosure of the information, in violation of the agreement, of which it becomes aware; ensure that any agents to whom it provides the limited data set agree to the same restrictions and conditions that apply to the limited data set recipient with respect to such information; and ensure that any agents to whom it provides the limited data set agree to the same restrictions and conditions that apply to the limited data set recipient with respect to such information; and not attempt to re-identify the information or contact the individual. not attempt to re-identify the information or contact the individual.

Identifiers 1. Names 2. Geographic subunits smaller than state 3. Age 4. Telephone # 5. Fax # SSN 8. IP addresses 9. Biometric IDs 10. Medical Record Number 11. Health plan beneficiary # 12. Account # 13. Certificate and License # 14. Vehicle ID 15. Medical Device ID 16. URLs 17. Full face photographs 18. Any other unique identifying number, characteristic, or code

Data Shared with Whom? Includes: “Public health authority” for public health activities “Public health authority” for public health activities Official of foreign government acting in collaboration with public health authority Official of foreign government acting in collaboration with public health authority Person exposed to or at risk of contracting or spreading disease Person exposed to or at risk of contracting or spreading disease

Definition of Public Health Authority “an agency or authority of the U.S., a State, a territory, a political subdivision of a State or territory, or an Indian tribe, or a person or entity acting under a grant of authority from or contract with such public agency or its contractors or persons or entities to whom it has granted authority, that is responsible for public health matters as part of its official mandate.”

“Minimum Necessary” Data Information use/disclosed/requested should be “minimum necessary” needed Information use/disclosed/requested should be “minimum necessary” needed Covered entities may rely on public officials to determine Covered entities may rely on public officials to determine

Not Required by Privacy Rule Sharing of data with public health authorities Sharing of data with public health authorities Specification of particular activity in law—general authority under law suffices (e.g., to receive data for surveillance activities) Specification of particular activity in law—general authority under law suffices (e.g., to receive data for surveillance activities) Specification of data requested by public health in law Specification of data requested by public health in law Protection of data received by public health authority unless it is also a covered entity (e.g., a health care provider) Protection of data received by public health authority unless it is also a covered entity (e.g., a health care provider)

Useful sites

Source Health and Human Services, Office of Civil Rights Health and Human Services, Office of Civil Rights Centers for Disease Control and Prevention Centers for Disease Control and Prevention