1 HIPAA Challenges Ahead in Mining Patient-Centric Data Kristen B. Rosati Coppersmith Schermer & Brockelman, PLC PRISM Forum SIG on Clinical Informatics.

Slides:



Advertisements
Similar presentations
Fourth National HIPAA Summit April 26, 2002 Implementation of a HIPAA Data Management Strategy Safeguarding privacy interests while making data available.
Advertisements

HIPAA Privacy Rule “Standards for Privacy of Individually Identifiable Health Information” 45 CFR 160 and 164* *
1 The HIPAA Privacy Rule and Research This presentation will probably involve audience discussion, which will create action items. Use PowerPoint to keep.
HIPAA Basics Brian Fleetham Dickinson Wright PLLC.
HIPAA and Public Health 2007 Epi Rapid Response Team Conference.
COBB/DOUGLAS COMMUNITY SERVICES BOARD Confidentiality and Privacy of Consumer Information.
HIPAA – Privacy Rule and Research USCRF Research Educational Series March 19, 2003.
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
HIPAA What’s New? What Is HIPAA Health Insurance Portability and Accountability Act of 1996 Health Insurance Portability and Accountability Act.
HIPAA Health Insurance Portability and Accountability Act.
1 Navigating the Privacy and Security Issues: HITECH Overview Rebecca L. Williams, RN, JD Partner Co-chair of HIT/HIPAA Practice Davis Wright Tremaine.
HIPAA Requirements for Patient Oriented Research
Informed Consent.
COMPLYING WITH HIPAA PRIVACY RULES Presented by: Larry Grudzien, Attorney at Law.
Professional Nursing Services.  Privacy and Security Training explains:  The requirements of the federal HIPAA/HITEC regulations, state privacy laws.
Protecting Client Data HIPAA, HITECH and PIPA Part 1A
HIPAA Training Presentation for New Employees How did we get here? HIPAA Police 1.
Health information security & compliance
Health Insurance Portability Accountability Act of 1996 HIPAA for Researchers: IRB Related Issues HSC USC IRB.
March 19, 2009 Changes to HIPAA Privacy and Security Requirements Joel T. Kopperud Scott A. Sinder Rhonda M. Bolton.
University of Miami1 HIPAA Survival Skills An Introduction to HIPAA and Research University of Miami Human Subjects Research Office October 31, 2006 Evelyne.
HIPAA Health Insurance Portability & Accountability Act of 1996.
Health Insurance Portability and Accountability Act (HIPAA)
Notice of Privacy Practices Nebraska SNIP Privacy Subgroup July 18, 2002 Michael J. Brown, MHA, CPA Vice-President, Administrative & Regulatory Affairs,
Protected Health Information (PHI). Privileged Communication An exchange of information between two individuals in a confidential relationship. (Examples:
Paula Peyrani, MD Medical/Project Director, HIV Program at the 550 Clinic Assistant Director, Research Design and Development Clinical and Translational.
California :: Delaware :: Florida :: New Jersey :: New York :: Pennsylvania :: Virginia :: Washington, D.C. :: 1 NEW OBLIGATIONS.
HIPAA Business Associates Leadership Group Meeting June 28, 2001.
1 Research & Accounting for Disclosures March 12, 2008 Leslie J. Pfeffer, BS, CHP Office of the Vice President for Research Administration Office of Compliance.
HIPAA and HITECH The Latest Developments Presented By: Michele Madison Partner, Healthcare Practice Morris, Manning & Martin, LLP
1 HIPAA OVERVIEW ETSU. 2 What is HIPAA? Health Insurance Portability and Accountability Act.
14 May Privacy Requirements Phoenix Ambulatory Blood Pressure Monitoring System © 2006 Christopher J. Adams Copying and distribution of this document.
HIPAA Privacy and Research August 21, 2015
August 8, 2011 Leslie J. Pfeffer, BS, CHP. Health Insurance Portability and Accountability Act HIPAA Privacy Rule April 14, 2003 HIPAA Security Rule April.
Health information that does not identify an individual and with respect to which there is no reasonable basis to believe that the information can be.
Update on Federal HIT Legislation Kirsten Beronio Mental Health America.
Computerized Networking of HIV Providers Workshop Data Security, Privacy and HIPAA: Focus on Privacy Joy L. Pritts, J.D. Assistant Research Professor Health.
PwC Tissue Banking and Repositories – Human Subject Protections Privacy Protections Medical Research Summit Tom Puglisi, Ph.D. Friday March 7 – 9:15 am.
HIPAA – How Will the Regulations Impact Research?.
Office of the Secretary Office for Civil Rights (OCR) The HITECH NPRM: Overview of Research Comments October 19, 2010 Christina Heide, JD HHS Office for.
© 2009 The McGraw-Hill Companies, Inc. All rights reserved. 1 McGraw-Hill Chapter 2 The HIPAA Privacy Standards HIPAA for Allied Health Careers.
Medical Law and Ethics, Third Edition Bonnie F. Fremgen Copyright ©2009 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved.
Health Insurance Portability and Accountability Act (HIPAA) CCAC.
The American Recovery and Reinvestment Act of 2009: Changes to HIPAA Privacy and Security Requirements And its Impact on Hospitals Presented By: Michele.
HealthBridge is one of the nation’s largest and most successful health information exchange organizations. Tri-State REC: Privacy and Security Issues for.
Copyright ©2014 by Saunders, an imprint of Elsevier Inc. All rights reserved 1 Chapter 02 Compliance, Privacy, Fraud, and Abuse in Insurance Billing Insurance.
EHR & BIG DATA – RISKS AND ADVANTAGES OF AMASSING MEDICAL DATABASES Sandra Gardiner Technology Law Section October 24, 2014.
1 Changes to Privacy Regulations under ARRA May 4, 2009 Melissa Goldstein, J.D. The George Washington University School of Public Health and Health Services.
Top 10 Series Changes to HIPAA Devon Bernard AOPA Reimbursement Services Coordinator.
Finally, the Final HIPAA/HITECH Regulations are Here! By LYNDA M. JOHNSON Friday, Eldredge & Clark.
Configuring Electronic Health Records Privacy and Security in the US Lecture b This material (Comp11_Unit7b) was developed by Oregon Health & Science University.
HIPAA Privacy Rule Positive Changes Affecting Hospitals’ Implementation of the Rule.
PwC Issues in HIPAA Research Compliance William R. Braithwaite, MD, PhD “Dr. HIPAA” HIPAA Summit 6 Washington, DC 27 March 2003.
Final PRIVACY RULE Presentation by Richard Campanelli, Director OCR/HHS at 5 th National HIPAA Summit Washington, D.C. October 31, 2002.
AND CE-Prof, Inc. January 28, 2011 The Greater Chicago Dental Academy 1 Copyright CE-Prof, Inc
HIPAA TRIVIA Do you know HIPAA?. HIPAA was created by?  The Affordable Care Act  Health Insurance companies  United States Congress  United States.
Final HIPAA Privacy Rule: The Research Provisions Julie Kaneshiro DHHS Office for Human Research Protections Phone: Fax:
HIPAA and RESEARCH 5 th Thursday May 31, Page 2.
HIPAA Privacy Rule Positive Changes Affecting Hospitals’ Implementation of the Rule Melinda Hatton -- Oct. 31, 2002.
Reviewed by: Gunther Kohn Chief Information Officer, UB School of Dental Medicine Date: October 20, 2015 Approved by: Sarah L. Augustynek Compliance Officer,
HIPAA PRIVACY & SECURITY TRAINING
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA)
The HIPAA Privacy Rule: Implications for Medical Research
The HIPAA Privacy Rule and Research
New School Violence Law; HIPAA Privacy Training
Issues in HIPAA Research Compliance
Analysis of Final HIPAA Privacy Modification Rule
If it's Subsidized, Get it Authorized: New Restrictions on the Sale and Use of PHI for Marketing Purposes Under HIPAA's Omnibus Rule Angela M. Rust This.
Office of the Vice President for Research Human Subjects Protection Program IRB Submission Process Module 4 - Health Insurance Portability and Accountability.
The Health Insurance Portability and Accountability Act
Presentation transcript:

1 HIPAA Challenges Ahead in Mining Patient-Centric Data Kristen B. Rosati Coppersmith Schermer & Brockelman, PLC PRISM Forum SIG on Clinical Informatics October 19, 2010

Agenda A bit of background Upcoming prohibition on “sale” of protected health information (PHI) New restrictions on using or disclosing PHI for marketing Changes in research authorizations Upcoming guidance on de-identification

An Overview of the HITECH Act American Recovery and Reinvestment Act of 2009 (ARRA) -- Division A, Title XIII and Division B, Title IV: Health Information Technology for Economic and Clinical Health Act (HITECH Act)  Medicare and Medicaid payment incentives for adoption of electronic health records by hospitals and physicians  Grant funding and loans to support health information technology (HIT) and health information exchange (HIE)  Changes to the HIPAA Privacy and Security Rules

Privacy and Security in a HITECH World Key privacy and security elements in the HITECH Act  Created new HIPAA privacy requirements  Applied most HIPAA Privacy and Security Rules directly to business associates  Established mandatory breach reporting for covered entities and their business associates  Established new civil and criminal penalties for noncompliance and expands enforcement authority to the states Proposed amendments to the HIPAA Privacy Rule to implement the HITECH Act: 75 Fed. Reg. at (July 14, 2010)

Enforcement in a HITECH World Establishes new civil and criminal penalties for noncompliance  Applies criminal penalties to individuals who without authorization obtain or disclose individually identifiable health information that is maintained by a covered entity (enforceable on 2/18/10)  Increases amount of civil penalties from $100 per violation and a total of $25,000 per year, to a tiered penalty system that can go to $50,000 per violation and total penalties of up to $1,500,000 per year  Gives State Attorneys General authority to bring civil action to enjoin a violation, seek statutory damages for individuals and obtain attorneys fees

6 Current rule: CE may receive payment for a disclosure of PHI where that disclosure is permitted by the regulations (such as for health care operations or research) HITECH Act prohibits indirect or direct receipt of remuneration in exchange for a disclosure of PHI without the individual’s authorization (with exceptions) Proposed rule would prohibit indirect or direct remuneration in exchange for a disclosure of PHI without authorization (with exceptions on the next slide) [HITECH Act § 13405(d); Proposed 45 CFR § ] No Sale of PHI

7  For public health purposes  For research, “where the only remuneration received by the covered entity is a reasonable cost-based fee to cover the cost to prepare and transmit” the PHI  For treatment and payment  For the sale, transfer, merger or consolidation of the covered entity and related due diligence  To or by a business associate to perform activities for the covered entity, where “the only remuneration provided is by the covered entity to the business associate for the performance of such activities”  To an individual for access or accounting  Where required by law to disclose PHI  Where the only remuneration received is a reasonable cost-based fee to cover the cost to prepare and transmit the PHI, or a fee is otherwise expressly permitted by another law [Proposed 45 CFR § ] No Sale of PHI-- Exceptions

8 Current rule: “marketing” is “a communication about a product or service that encourages recipients of the communication to purchase or use the product or service” except: “To describe a health-related product or service (or payment for such product or service) that is provided by, or included in a plan of benefits of, the covered entity making the communication, including communications about: the entities participating in a health care provider network or health plan network; replacement of or enhancements to a health plan; and health- related products or services available only to a health plan enrollee that add value to, but are not part of, a plan of benefits; For treatment of the individual; or For case management or care coordination for the individual, or to direct or recommend alternative treatments, therapies, health care providers, or settings of care to the individual” Marketing

9 HITECH Act prohibits covered entity’s receipt of direct or indirect payment for any communication permitted on the previous slide, except where: The communication is regarding a drug currently prescribed for the recipient and such payment is “reasonable”; The communication is made by a business associate on behalf of the covered entity, and is consistent with business associate agreement; or The covered entity obtains a valid authorization [HITECH Act § 13406] Marketing

10 Proposed rule: Marketing does not include communications “[f]or treatment of an individual by a health care provider, including case management or care coordination for the individual, or to direct or recommend alternative treatments, therapies, health care providers, or settings of care to the individual, provided, however, that if the communication is in writing and the health care provider receives financial remuneration in exchange for making the communication, the requirements of § (f)(2) are met.”  Financial remuneration: “direct or indirect payment from or on behalf of a third party whose product or service is being described,” not including payment for treatment [Proposed 45 CFR § ] Marketing

11  § (f)(2): If a health care provider will receive payment for making treatment communications, the health care provider must: Amend its Notice of Privacy Practices to explain that the provider receives financial remuneration in exchange for making such communications, and that the individual has the right to opt-out of receiving such communications Must disclose in the communication itself the fact that the provider is receiving financial remuneration in exchange for making the communication, and must provide the individual with a “clear and conspicuous opportunity to elect not to receive further such communications” Opt-out cannot impose undue burden Marketing

12 Proposed rule continued:  Permits refill reminders paid for by third parties, if drug is currently prescribed, if the payment is reasonable related to the costs  Permits the following communication unless the CE receives “financial remuneration” in exchange for making the communications:  “(A) To describe a health-related product or service (or payment for such product or service) that is provided by, or included in a plan of benefits of, the covered entity making the communication, including communications about: the entities participating in a health care provider network or health plan network; replacement of, or enhancements to, a health plan; and health-related products or services available only to a health plan enrollee that add value to, but are not part of, a plan of benefits; or  (B) For case management or care coordination, contacting of individuals with information about treatment alternatives, and related functions to the extent these activities do not fall within the definition of treatment.” Marketing

13 Proposed rule: Would permit “compound authorizations” in research, that combine authorization for a clinical trial and authorization to contribute PHI to a research repository, as long as the form provides the individual with an opportunity opt-in to the research repository [Proposed 45 CFR § (b)] Solicits comments on changing the present OCR interpretation that an authorization may not seek permission for use of PHI in future, unspecified research Research Authorizations

14 HIPAA does not regulate de-identified information Current rule on de-identification:  Remove or code all HIPAA identifiers; or  Have a qualified statistician document that there is a statistically “very small” risk that information could be used to identify a participant (despite the presence of identifiers) Current HIPAA De-Identification Rule

HIPAA “Identifiers” Name; Street address, city, county, precinct, or zip code (unless only the first three digits of the zip code are used and the area has more than 20,000 residents); The month and day of dates directly related to an individual, such as birth date, admission date, discharge date, dates of service, or date of death; Age if over 89 (unless aggregated into a single category of age 90 and older); Telephone numbers; Fax numbers; addresses; Social security numbers; Medical record numbers; Health plan beneficiary numbers; Account numbers; Certificate/license numbers; Vehicle identifiers, serial numbers, and license plate numbers; Device identifiers and serial numbers; Web Universal Resource Locators (URLs) and Internet Protocol (IP) addresses; Biometric identifiers, such as fingerprints Full-face photographs and any comparable images; or Any other unique identifying number, characteristic, or code. 15

16 HITECH Act requires HHS to issue guidance on methods for de- identification of PHI OCR solicited stakeholder input from experts with practical technical and policy experience to inform the creation of guidance materials, and collected views regarding de- identification approaches, best practices for implementation and management of the current de-identification standard and potential changes to address policy concerns March day conference on de-identification – see entities/De-identification/deidentificationworkshop2010.html entities/De-identification/deidentificationworkshop2010.html Treatment of De-Identified Information

17 Questions? Kristen B. Rosati Coppersmith Schermer & Brockelman PLC 2800 North Central Avenue, Suite 1200 Phoenix, Arizona tel (602) /fax (602)