Sharing a Clinical Abstract: Privacy Considerations in Minnesota Donald P. Connelly, MD, PhD Daniel T. Routhe, BBA University of Minnesota AHRQ 2007 Annual.

Slides:



Advertisements
Similar presentations
Aim: Advance the adoption of proven strategies to improve the reliability, safety and quality of care received by patients in Tennessee hospitals.
Advertisements

Georgia Department of Community Health
Legal Work Group Developing a Uniform EHR/HIE Patient Consent Form.
The Individual Health Plan Essential to achieve educational equality for students with health management needs Ensures access to an education for students.
A Plan for a Sustainable Community Behavioral Health Information Network Western States Health-e Connection Summit & Trade Show September 10, 2013.
How To Get To The Winners Circle with Your Patient Portal; Our Challenges To Get To The Finish Line. Julie Patterson, Baptist Health Carey Ronan, MHA,
+ Leveraging the power of North Carolina’s health information exchange to improve patient outcomes Organization Name Date.
ELTSS Alignment to Nationwide Interoperability Roadmap DRAFT: For Stakeholder Consideration in response to public comment.
And the finer details of patient privacy TCH Confidential Understanding HIPAA.
Copyright Eastern PA EMS Council February 2003 Health Information Portability and Accountability Act It’s the law.
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
The Health Insurance Portability and Accountability Act of 1996– charged the Department of Health and Human Services (DHHS) with creating health information.
1 HIPAA and Research and YOU. 2 INTRODUCTION Rule #1:Don’t Panic Rule #2:Bottom Line for Researchers: HIPAA is Manageable thru Education/Awareness and.
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996 (HIPAA)
2014 HIPAA Refresher Omnibus Rule & HIPAA Security.
Are you ready for HIPPO??? Welcome to HIPAA
Beth DeLair, JD, RN DeLair Consulting, LLC. Discussion Topics Background Existing WI Requirements State Efforts to Change Law Senate Bill 487 Changes.
The MARYLAND HEALTH CARE COMMISSION. Health IT - An Essential Care Delivery Framework State Involvement in Health IT Leading Initiatives Privacy and Security.
National Health Policy Forum William Winkenwerder, Jr., M.D. Assistant Secretary of Defense (Health Affairs) January 28, 2004.
2015 Edition Proposed Rule Modifications to the ONC Health IT Certification Program and 2015 Edition Health IT Certification Criteria.
Patient Consent The Massachusetts Health Information Highway
Management of Communication and Information Chapter -MCI
2 H. Westley Clark, M.D., J.D., M.P.H., CAS, FASAM Director Center for Substance Abuse Treatment Substance Abuse Mental Health Services Administration.
ELECTRONIC MEDICAL RECORDS By Group 5 members: Kinal Patel David A. Ronca Tolulope Oke.
ONC HIT Policy Committee Interoperability and HIE Workgroup Panel 3: State/Federal Perspectives August 22, 2014 Jennifer Fritz, MPH Deputy Director Office.
HIT Policy Committee Accountable Care Workgroup – Kickoff Meeting May 17, :00 – 2:00 PM Eastern.
COMPLYING WITH HIPAA BUSINESS ASSOCIATE REQUIREMENTS Quick, Cost Effective Solutions for HIPAA Compliance: Business Associate Agreements.
HIE Implementation in Michigan for Improved Health As approved by the Michigan Health Information Technology Commission on March 4, 2009.
Sharing Low-Income Customer Information Water & Energy Utilities LIOB Meeting - January 2009 Seaneen M Wilson Division of Water & Audits.
1 Creation of State Legislation to Protect and Facilitate Use and Exchange of Electronic Health Information Shelley Carter, RN, MCRP, MPH 1, Maggie Gunter,
0 Presentation to: Health IT HIPPA Workshop Presented by: Stacey Harris, Director of Health IT Innovation September 26, 2014 Division of Health Information.
Copyright ©2011 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved. Health Information Technology and Management Richard.
Enhancing Communication Among Health Care and Educational Programs How Privacy Regulations Impact Delivery of Effective Services by Karl R. White National.
Update on Federal HIT Legislation Kirsten Beronio Mental Health America.
State Alliance for e-Health Conference Meeting January 26, 2007.
The PRISM Privacy Tool: A User’s Guide PHDSC Home Page  PRISM Web Page 
Established in 1996 to enforce standards for electronic health information & enhance the security and privacy of health information.
H I P A A T R A I N I N G Self Directed Module 7 Research Disclosures For Data Custodians START Click to begin…
Understanding HIPAA (Health Insurandce Portability and Accountability Act)
Health Information Exchange: Myths, Mirages and Reality Donald P. Connelly, MD, PhD University of Minnesota September 8, AHRQ Annual Conference.
PricewaterhouseCoopers 1 Administrative Simplification: Privacy Audioconference April 14, 2003 William R. Braithwaite, MD, PhD “Doctor HIPAA” HIPAA Today.
HIPAA THE PRIVACY RULE. 2 HISTORY In 2000, many patients that were newly diagnosed with depression received free samples of anti- depressant medications.
January 26, 2007 State Alliance for e-Health January 26, 2007 Robert M. Kolodner, MD Interim National Coordinator Office of the National Coordinator for.
Health Information Technologies and Health Care Transformation James Golden, PhD Director, Division of Health Policy Minnesota Department of Health February.
Minnesota e-Health Initiative Regional and Cross-Border Considerations in eHealth Marty LaVenture, MPH, PhD, Director, Center for Health Informatics Minnesota.
Data Governance 101. Agenda  Purpose  Presentation (Elijah J. Bell) Data Governance Data Policy Security Privacy Contracts  FERPA—The Law  Q & A.
Health Delivery Services May 29, Eastern Massachusetts Healthcare Initiative Policy Work Group Session 2 May 29, 2009.
HIT Policy Committee NHIN Workgroup HIE Trust Framework: HIE Trust Framework: Essential Components for Trust April 21, 2010 David Lansky, Chair Farzad.
Jeanene Smith MD, MPH Office for Oregon Health Policy and Research SCI Coverage Institute - July, 2009 Albuquerque, NM Building a Healthy Oregon: Delivery.
This material was developed by Oregon Health & Science University, funded by the Department of Health and Human Services, Office of the National Coordinator.
Copyright © 2015 by Saunders, an imprint of Elsevier Inc. All rights reserved. Chapter 3 Privacy, Confidentiality, and Security.
BENEFITS OF ELECTRONIC HEALTH INFORMATION. Health IT Video from HealthIT.gov (Please wait for the video to load and click on the arrow to play)
Justice Information Network Strategic Plan Development Justice Information Network Board March 18, 2008 Mo West, JIN Program Manager.
Human Subjects Update E. Wethington, Chair, UCHS.
Health IT for Post Acute Care (HITPAC) Stratis Health Special Innovation Project Candy Hanson, BSN, PHN December 5, 2012.
UNITS 4:3-4:4 Patients’ Rights and Legal Directives for Health Care.
© 2014 By Katherine Downing, MA, RHIA, CHPS, PMP.
COMMUNITY-WIDE HEALTH INFORMATION EXCHANGE: HIPAA PRIVACY AND SECURITY ISSUES Ninth National HIPAA Summit September 14, 2004 Prepared by: Robert Belfort,
An Orientation To Community Benefit: What Hospital Staff Need To Know.
Disclaimer This presentation is intended only for use by Tulane University faculty, staff, and students. No copy or use of this presentation should occur.
Juvenile Legislative Update 2013 Confidential Records and Protected Disclosures.
HIPAA Training Workshop #3 Individual Rights Kaye L. Rankin Rankin Healthcare Consultants, Inc.
Our pledge: reliability, integrity and trust
And the finer details of patient privacy
Electronic Health Records (EHR)
HIPAA Administrative Simplification
Health Information Security and Privacy Collaborative (HISPC) Overview
Disability Services Agencies Briefing On HIPAA
The Health Insurance Portability and Accountability Act
HLN Consulting, LLC® November 8, 2006
Presentation transcript:

Sharing a Clinical Abstract: Privacy Considerations in Minnesota Donald P. Connelly, MD, PhD Daniel T. Routhe, BBA University of Minnesota AHRQ 2007 Annual Meeting September 27, 2007 Findings from AHRQ’s State Privacy & Security Projects

Overview What does our project aim to do? HIE and Minnesota’s patient privacy context Minnesota’s HISPC work - MPSP Changes in MN privacy laws that facilitate our work Adopting MPSP’s privacy & security principles Lessons learned

Our Response to AHRQ’s invitation Focus: fill information gaps that occur at care transitions Patients presenting to ED Patients moving from one provider organization to another Partners: Allina, HealthPartners, Fairview Health Services How: deliver a clinical record abstract near the point of care Leverage partners’ use of a common EHR vendor Use a federated model of contributing clinical databases not a centralized one Use evolving national standards

Information Gaps in the ED Gaps are frequent - 32% of visits Gaps are consequential Very important or essential 48% Somewhat important 32% Prolong the ED stay Increase costs Redundant testing & repeated MD assessments Stiell A et al. CMAJ 2003; 169:

Rationale for sharing an abstract instead of the entire record Contents are bounded & defined A better first step for a public wary of confidentiality breaches Patients “get it.” They understand the value of a concise clinical abstract for themselves and their providers Avoiding sensitive content means easier consenting & wider use While not the entire record, clinicians endorse the abstract as having high clinical value The abstract’s succinctness is preferred by some emergency room physicians Interoperability across vendor platforms should be easier

“My Emergency Data” Abstract Patient Information Contact Information Primary Care MD & Clinic Advance Directives Current Problem List Current Medications Allergies Immunizations Surgical History Family Medical History Alcohol and Tobacco use

Level 1 – MyChart Access (Enrolled in a HealthPartners Clinic) Buffalo Hospital ER (Allina) Username 1 Password 1 MyChart HealthPartners MyChart Fairview My Em. Data ……

What we’ve learned so far: Level 1 MyChart enrollment rate is too low to yield enough heart failure patients for our analysis An opt-in strategy greatly limits impact An opt-in strategy tends to exclude the elderly with multiple chronic illnesses – the very group which may benefit the most MyChart hasn’t integrated well into ED workflow Too few hits in ED to ensure good workflow integration or reliable use Login names and passwords are not uppermost in patients’ minds in urgent situations ED not equipped to provide keyboard access to patients

Level 2 – Direct Health Information Exchange Buffalo Hospital ER Allina Pt Identifier Standards compliant Clinical message Pt Identifier Standards compliant Clinical message (Enrolled in a HealthPartners Clinic) Epic EHR HealthPartners Epic EHR Fairview Review & Incorporate Epic EHR Allina Hosp & Clinics

Minnesota Privacy and Security Project (MPSP) Minnesota’s component of the Health Information Security and Privacy Collaboration (HISPC) We participated in the oversight committee in the Privacy & 4A work groups MPSP  Minnesota law changes effective July 1 We’re adopting key principles put forth in the MPSP report

MPSP Privacy Workgroup activities A systematic review of the state’s privacy laws & practices to determine their impact on the electronic exchange of health data Electronic exchange barriers identified: Undefined and ambiguous terms in our law Current laws are set up for paper exchange Need to update Minnesota consent requirements to facilitate electronic exchange while retaining patient empowerment

2007 Revisions to Minnesota Health Records Act Major revisions in the Health and Human Services Omnibus bill: Improve readability Refine or add definitions for: Health record Medical emergency Related health care entity Identifying health data Record locator service Representation of consent Liability and responsibility around disclosure clarified Information requirements for auditing exchanges

Record Locator Service (RLS) An electronic index of patient identifying information that directs providers in a health information exchange to the location of patient health records held by providers and group purchasers. Providers may construct an RLS without patient consent Providers must obtain patient consent to access a patient’s health record

RLS Privacy Protections Allows multiple groups of providers to create a RLS Only providers may access information in a RLS The Minnesota Department of Health cannot access/receive information from a RLS Providers must enable patients to completely opt- out of the RLS during the consent process An exchange that uses a RLS must maintain audit logs tracking access to patient health records

Minnesota’s patient consent requirements Patient consent is required for nearly all disclosures, including treatment Limited exception to consent requirement Medical emergency Record movement within “related” health care entities Written consent (signed & dated) is required Consent generally expires in one year Or … a representation from a provider that holds a signed and dated consent from the patient authorizing the release

Representation of consent protections Only a provider may request a patient’s health record using a representation of consent. The requesting provider must have, in possession, a signed and dated consent from the patient. The releasing entity must document: identity of the requesting provider identity of the patient records requested/provided date of the request

Liability and responsibilities for disclosure now addressed Prior MN law placed all liability for inappropriate disclosure on disclosing provider Responsibilities are now defined for the patient, the requestor, and the discloser Each party warrants no information known to the person to be false Requestor accurately states the patient's desire to have health records disclosed or that there is specific authorization in law Requestor & discloser do not exceed any limits imposed by the patient in the consent Discloser has complied with the legal requirements regarding disclosure of health records

Applying MPSP’s security & privacy principles is ongoing Concentrating on 4A’s principles Data to be captured in audit logs Limit access requests to patients being treated and information relevant to that treatment Develop & accept written policies and procedures for participating in the exchange security credentialing guidelines for authorizing individuals to access health information through the exchange minimum standards for routine auditing of individuals’ access through the exchange

Lessons learned Attention to privacy concerns pays off Law evolves too – get involved Continuing opportunities Conforming our exchange’s “rules of the road” to Minnesota law Contributing to Minnesota’s universal consent form due in January 2008 Avoiding burden to providers in neighboring states while conforming to our state’s laws

Acknowledgements The many dedicated and committed participants from Allina Hospitals and Clinics Fairview Health Services HealthPartners University of Minnesota Our project’s Board members Jim Golden, MDH AHRQ This project was funded in part under Grant Number UC1 HS from the Agency of Healthcare Research and quality, US Department of Health and Human Services.