Showing posts with label PHI Disclosure. Show all posts
Showing posts with label PHI Disclosure. Show all posts

Wednesday, June 28, 2017

Patient Authorization

What is the difference between “consent” and “authorization” under the HIPAA Privacy Rule?
 Healthcare Compliance Solutions Inc.
The Privacy Rule permits, but does not require, a covered entity voluntarily to obtain patient consent for uses and disclosures of protected health information for treatment, payment, and health care operations (TPO). Covered entities that do so have complete discretion to design a process that best suits their needs.

By contrast, an “authorization” is required by the Privacy Rule for uses and disclosures of protected health information not otherwise allowed by the Rule. Where the Privacy Rule requires patient authorization, voluntary consent is not sufficient to permit a use or disclosure of protected health information unless it also satisfies the requirements of a valid authorization. An authorization is a detailed document that gives covered entities permission to use protected health information for specified purposes, which are generally other than TPO (treatment, payment, or health care operations), or to disclose protected health information to a third party specified by the individual.

HIPAA requires that certain elements be present on the authorization that the patient is to sign. Whenever you receive an authorization (or “release”) asking you to disclose PHI and HIPAA requires an authorization for the disclosure, use this checklist to verify that the authorization meets the HIPAA requirements. If any ONE of the following elements is missing, you should NOT release the patient’s PHI until you have a valid authorization signed by the patient. If ALL the elements are present, the authorization is valid.

• A description of the PHI to be used or disclosed that identifies it in a specific and meaningful fashion. They may request the entire medical record, all records between specific dates, or other specific items.

• The name or other specific identification of the person(s), or class of persons, who can make the requested use or disclosure. For example, the signed request should list either your organization or someone in your organization by name.

• The person(s), or class of persons, to whom you may make the requested disclosure. The specific entity(ies) to receive the information should be identified. A cover sheet stating who should receive the information is NOT sufficient.

• A description of each purpose of the requested use or disclosure. The statement “at the request of the individual” is a sufficient description of the purpose when a patient initiates the authorization and does not, or elects not to, provide a statement of the purpose. The above statement or some other description must be present.

• An expiration date or an expiration event that is related to the individual or the purpose of the use and disclosure. The statement “end of research study”, “none”, or similar language is sufficient if the authorization is for a use or disclosure of PHI for research. Again, the statement must be present.

• Signature of the patient and date. If the authorization is signed by a personal representative of the individual, a description of such representative’s authority to act for the individual must also be provided.

• In addition to the core elements, the rule states that a valid authorization must include:
  1. A statement of the individual’s right to revoke the authorization, in writing, and either:
    • A reference to the revocation right and procedures described in the notice, or
    • A statement about the exceptions to the right to revoke, and a description of how the individual may revoke the authorization
    Exceptions to the right to revoke include situations in which the covered entity has already taken action in reliance on the authorization, or the authorization was obtained as a condition of obtaining insurance coverage. (*Note that if an authorization is revoked it must be fully documented in a separate "revocation of authorization" form/document.)


  2. A statement about the ability or inability of the covered entity to condition treatment, payment, enrollment, or eligibility for benefits on the authorization:

    • The covered entity must state that it may not condition treatment, payment, enrollment, or eligibility for benefits on whether the individual signs the authorization, or
    • The covered entity must describe the consequences of a refusal to sign an authorization when the covered entity conditions research-related treatment, enrollment or eligibility for benefits, or the provision of healthcare, solely for the purpose of creating protected health information for a third party on obtaining an authorization.

  3. A statement that information used or disclosed pursuant to the authorization may be subject to redisclosure by the recipient and may no longer be protected by the rule
•    The ability or inability to condition treatment on the authorization by stating either:  
  1. The covered entity may not condition treatment on whether the individual signs the authorization or 
  2. The consequences to the individual for refusal to sign the authorization.  (Remember that there are very limited circumstances in which action can be a condition on a patient signing an authorization.)
•    A statement that informs of the potential for information to be re-disclosed by the person or organization to which it is sent.  The privacy of this information may not be protected under the Federal Privacy Rule depending on whom the information is disclosed to.

*Authorization for marketing purposes: If the requested use or disclosure is for marketing purposes. If the marketing involves direct or indirect remuneration to the covered entity from a third party, the authorization must state such remuneration.

The HITECH Omnibus Rule requires a valid authorization be obtained from an individual before the use or disclosure of PHI for marketing purposes involving financial remuneration. The authorization must also include a statement about any direct or indirect remuneration the covered entity has received or will receive from a third party. An authorization for marketing purposes can be included on the organization’s compliant HIPAA authorization form or a separate one may be created.

The following are exceptions to the marketing rule and do not require an authorization:
  • Face-to-face communications from the covered entity to the individual 
  • Gifts of nominal value provided by the covered entity


 HCSI


To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Friday, January 27, 2017

Disclosure VS Breach

What is the difference between an incidental/accidental disclosure and a breach?

With the approaching breach notification deadline (Before March 1st, all breaches must be reported 60 days after the end of the previous calendar year that the breach occurred), I have receive many calls and emails asking, "is this a breach and do I need to report it?". This is an important topic that needs some clarification.

Incidental Disclosure

These disclosures are non-intentional and occur as a by-product of allowed uses and disclosures. They are allowed as long as the minimum necessary standard and reasonable safeguards are applied in the course of your everyday operations. An example would be if a passerby overhears PHI being discussed at a nursing station. These disclosures do not have to be accounted for.

Accidental Disclosure

These types of disclosures are distinctly different from incidental disclosures. Accidental disclosures
happen when a mistake is made in disclosing a patient’s PHI. Examples include faxing or mailing PHI to the wrong destination or disclosing PHI to an unauthorized person. If you are aware of an accidental disclosure, you need to log the disclosure on the disclosure log. If the disclosure is potentially harmful or damaging to the patient, you need to notify the patient of the accidental disclosure.

Identifying a Breach of Unsecured PHI

A breach is defined in the HIPAA HITECH Act as:

The unauthorized acquisition, access, use, or disclosure of unsecured protected
health information which compromises the security or privacy of such
information, except where an unauthorized person to whom such information is
disclosed would not reasonably have been able to retain such information. (Note
that de-identified health information, as defined in HIPAA’s Privacy Rule, is not
PHI; therefore no breach notification is required.)

Exceptions include:

• Any unintentional acquisition, access, or use of protected health information by an
employee or individual acting under the authority of a covered entity if:
• Such acquisition, access, or use was made in good faith and within the course and
scope of the employment or other professional relationship of such employee or
individual, respectively, with the covered entity; and
• Such information is not further acquired, accessed, used, or disclosed by any
person; or
• Any inadvertent disclosure from an individual who is otherwise authorized to
access protected health information at a facility operated by a covered entity to
another similarly situated individual at the same facility; and
• Any such information received as a result of such disclosure is not further
acquired, accessed, used, or disclosed without authorization by any person.

I hope the information listed above helps you have a better understanding of the difference between an incidental/accidental disclosure and a breach. Here is another article that could offer some additional information.

If you would like additional information, please feel free to email support@hcsiinc.com




To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Wednesday, July 20, 2016

Patient Authorization For Disclosure Of PHI

Required Elements Of A Patient Authorization
 HCSI

HIPAA requires that certain elements be present on the authorization that the patient is to sign.  Whenever you receive an authorization (or “release”) asking you to disclose PHI and HIPAA requires an authorization for the disclosure, use this checklist to verify that the authorization meets the HIPAA requirements. If any ONE of the following elements is missing, you should NOT release the patient’s PHI until you have a valid authorization signed by the patient. If ALL the elements are present, the authorization is valid. 


•    A description of the PHI to be used or disclosed that identifies it in a specific and meaningful fashion.  They may request the entire medical record, all records between specific dates, or other specific items. 


•    The name or other specific identification of the person(s), or class of persons, who can make the requested use or disclosure.  For example, the signed request should list either your organization or someone in your organization by name.

•    The person(s), or class of persons, to whom you may make the requested disclosure.  The specific entity(ies) to receive the information should be identified.  A cover sheet stating who should receive the information is NOT sufficient.

•    A description of each purpose of the requested use or disclosure.  The statement “at the request of the individual” is a sufficient description of the purpose when a patient initiates the authorization and does not, or elects not to, provide a statement of the purpose. The above statement or some other description must be present.

•    An expiration date or an expiration event that is related to the individual or the purpose of the use and disclosure.  The statement “end of research study”, “none”, or similar language is sufficient if the authorization is for a use or disclosure of PHI for research.  Again, the statement must be present.

•   Signature of the patient and date.  If the authorization is signed by a personal representative of the individual, a description of such representative’s authority to act for the individual must also be provided.

•    The individual’ s right to revoke the authorization in writing, any exceptions to that right, and a description of how the individual may revoke the authorization.

•    The ability or inability to condition treatment on the authorization by stating either:  (A) The covered entity may not condition treatment on whether the individual signs the authorization or (B) The consequences to the individual for refusal to sign the authorization.  (Remember that there are very limited circumstances in which action can be a condition on a patient signing an authorization.)

•    A statement that informs of the potential for information to be re-disclosed by the person or organization to which it is sent.  The privacy of this information may not be protected under the Federal Privacy Rule depending on whom the information is disclosed to.

•    If the requested use or disclosure is for marketing purposes.  If the marketing involves direct or indirect remuneration to the covered entity from a third party, the authorization must state such remuneration.


--For more healthcare compliance information and discussion please join the LinkedIn group forum: The Healthcare Compliance Solutions Administrative Alert

To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Tuesday, March 8, 2016

Share Your Opinion - Is This a HIPAA Breach or Merely an Accidental or Incidental Disclosure?

Emails Exposed BJC HealthCare Patients’ Data

What is the difference between an Incidental and an Accidental disclosure of protected health information (PHI) or a HIPAA Data Breach? Can you give examples of each? How do you handle each in your practice for an accounting of disclosures as required in the HIPAA privacy rule regulations?

The difference between an "incidental" and an "accidental" disclosure of PHI is the difference between complying with the privacy rule and violating it.
In a recent story, BJC HealthCare, a not-for-profit health system based in St. Louis, MO., has started notifying 2,393 of its patients that some of their protected health information has been exposed as a result of an email error that occurred on December 30, 2015.

An email containing sensitive data covered by HIPAA was emailed to another medical group. While HIPAA permits the sharing of healthcare data for certain healthcare operations, the Security Rule requires any shared data to be protected in transit.

If ePHI is to be shared electronically with another covered entity or business associate, it must be adequately protected to prevent unauthorized access and to protect the integrity of those data. Controls to protect the integrity of ePHI are addressable issued under 45 CFR § 164.312(e).

In this case, the data were not encrypted to the standards required by the Security Rule, and consequently the data could potentially have been intercepted in transit.

HIPAA requires covered entities to notify individuals when their PHI has been exposed or viewed by a third party to allow them to take precautions to protect their identities and reduce the risk of loss or harm.

Patients have been advised by mail that their name, date of birth, gender, and Medicare Beneficiary information were included in the email, although Social Security numbers were not exposed, and no financial or medical data were contained in the email. Patients affected by the email error were part of the healthcare provider’s accountable care organization.

An investigation into the incident showed that the email was received by the intended recipient and no other individual appeared to have gained access to any patient data, although the possibility cannot be ruled out. Out of an abundance of caution, all affected individuals have been offered complimentary credit monitoring services for a period of one year.

In order to prevent similar errors from occurring in the future, BJO HealthCare will be conducting further staff training to ensure that staff members are aware of the protocols that must be followed when transmitting data covered by HIPAA.

---

So with all information considered, would you say this incident is a Data Breach, an Accidental disclosure or an Incidental disclosure?  Please post a comment with your feedback.

Additional Information:

Certain "incidental" disclosures are a permitted use of PHI and, therefore, are not a violation of the regulations. (See Section 164.502(a)(1)(iii).) On the other hand, an "accidental" disclosure is not permitted under the regulations and would subject the organization to penalties for the violation. (See Section 164.502(a)(1) and (2) of the regulations.) The HIPAA statute would limit the penalties for an accidental disclosure to civil penalties alone. 


An "incidental" use and disclosure occurs as a by-product of another permissible or required use or disclosure under the privacy rule. It is a limited disclosure that cannot reasonably be prevented.   Examples of "incidental" disclosures include a hospital visitor overhearing a provider's confidential conversation with another provider or a patient, or a visitor catching a glimpse of a patient's information on a sign-in sheet or nursing station whiteboard.


An incidental use or disclosure may result from any use or disclosure permitted under the privacy rule. It is not limited to treatment communications or to communications among healthcare providers or other medical staff. An incidental use or disclosure may occur, for example, when a provider talks with an administrative staff member about billing a patient for a particular procedure and is overheard by 1 or more persons in the waiting room. 


An incidental use or disclosure is not a violation of the HIPAA medical privacy regulation provided the covered entity has applied reasonable safeguards (see Section 164.530(c) of the regulation) and implemented the minimum necessary standard (see Sections 164.502(b) and 164.514(d) of the regulation), where applicable, with respect to the underlying use or disclosure. (See Section 164.502(a)(1)(iii) of the regulation). If the underlying use or disclosure violates the privacy rule, however, the incidental use or disclosure would be a violation of the rule. 


Incidental disclosures do not have to be included in the accounting of disclosures provided at the patient's request. (See Section 164.528(a)(1)(iii) of the regulation.) 

Source(s): www.hipaajournal.comwww.medscape.com, www.law.cornell.edu, hhs.gov

To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Tuesday, February 9, 2016

ONC Clarifies TPO and Health IT Interoperability Under HIPAA

Some providers are not sharing PHI due to organizational policies, procedures or protocols, even if the sharing is permitted under HIPAA.


In general, a Covered Entity (CE) may use and disclose protected health information, without authorization, for treatment, payment, and health care operation activities (TPO). Treatment includes the provision, coordination, or management of health care and related services among health care providers; consultation between providers regarding a patient; or patient referrals from one provider to another. A CE may disclose PHI for its own treatment activities and the treatment activities of any another health care provider. Payment includes all health plan activities associated with obtaining premiums, fulfilling coverage responsibilities, providing plan benefits, and obtaining reimbursement for furnished health care and provider activities related to payment and reimbursement. A CE may use PHI for its own payment activities and may disclose PHI to another covered entity or health care provider for the payment activities of the entity receiving the information.

Many providers believe that HIPAA restrictions prevent them from moving protected health information (PHI) in certain patient care situation. However, that’s a common misconception potentially hindering health IT interoperability when, in fact, HIPAA enables PHI to be accessed, used or disclosed when and where it is needed for patient care.

In a blog post published Feb. 4 on Health IT Buzz, Lucia Savage, JD, and Aja Brooks, JD, of the Office of the National Coordinator for Health IT (ONC) introduced two new government fact sheets that give examples of when electronic PHI can be exchanged without requiring written authorization from the patient as long as other protections or conditions have been met.

ONC, which oversees interoperability aspects of handling PHI, developed the materials in conjunction with the Office of Civil Rights (OCR), which administers policy and enforcement of the HIPAA privacy rules.

“Some providers are not sharing PHI due to their health care organization’s policies, procedures, or protocols, even if the sharing is permitted under HIPAA, or because laws in the provider’s state apply in addition to HIPAA. Interestingly, this lack of exchange of PHI runs contrary to consumer perception, with research demonstrating that patients assume their PHI is automatically shared between their treating physicians,” wrote Savage and Brooks.

The new fact sheets describe permitted uses and disclosures of PHI by a HIPAA covered entity (CE) without first having to obtain written authorization from the patient.

In “Permitted Uses and Disclosures: Exchange for Health Care Operations” (available here), the agencies explain that HIPAA allows a CE to disclose PHI to another CE (or that CE’s business associate) for the following operations activities of the recipient CE without needing patient consent or authorization: 
  • Conducting quality assessment and improvement activities. 
  • Developing clinical guidelines. 
  • Conducting patient safety activities as defined in applicable regulations. 
  • Conducting population-based activities relating to improving health or reducing healthcare cost. 
  • Developing protocols. 
  • Conducting case management and care coordination (including care planning). 
  • Contacting healthcare providers and patients with information about treatment alternatives. 
  • Reviewing qualifications of health care professionals. 
  • Evaluating performance of health care providers and/or health plans. 
  • Conducting training programs or credentialing activities. 
  • Supporting fraud and abuse detection and compliance programs. 
The aforementioned activities are, however, subject to three requirements that must also be met: 
  1. Both CEs must have or have had a relationship with the patient (can be a past or present patient). 
  2. The PHI requested must pertain to the relationship. 
  3. The discloser must disclose only the minimum information necessary for the healthcare operation at hand. 

In “Permitted Uses and Disclosures: Exchange for Treatment” (available here), ONC and OCR explain permissible disclosure of PHI by CEs to another provider for treatment activities without needing patient consent or authorization.

The document explains what happens when a hospital discloses PHI in a permissible way to a receiving provider, who subsequently experiences a breach of the information. The receiving physician is “responsible for safeguarding the PHI and otherwise complying with HIPAA, including with respect to subsequent uses or disclosures or any breaches that occur.” At the same time, the disclosing hospital is responsible for transmitting the PHI in a permitted and secure manner, which includes taking reasonable steps to send it to the right address. The fact sheet also includes sample scenarios in the areas of PHI exchange for care planning and downstream treatment.

ONC and OCR plan to publish three additional blogs on PHI exchange as related to: the goal of nationwide health IT interoperability; care coordination, planning and management; and population-based activities.

Source(s):https://www.healthit.gov, http://www.hhs.gov/ocr/, http://www.healthinfolaw.org/,
http://healthitinteroperability.com, Frank Irving


For more information on this and other healthcare compliance topics related to HIPAA, OSHA, Medicare and HR, simply email your questions to support@hcsiinc.com
visit our website at http://www.hcsiinc.com or post a question on our LinkedIn group at: http://bit.ly/1FWmtq6

To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Friday, December 4, 2015

Dr. Jones is a News Star and His Patients Will Never Forget

The most misunderstood, unknown, or ignored of the HIPAA compliance rules is Breach Notification.


Dr. Jones had a lot of work to do over the weekend. He took his laptop from his office and put it in his car to take home. On the way home, Dr. Jones made a quick stop at the store. Upon returning to his car, Dr. Jones noticed that his car had been broken into. The laptop from his office was one of the items that had been stolen. Having the laptop stolen did not constitute a breach. However, the patient's information on that laptop did not have proper security protections, so now this situation is a breach. With more than 650 patients and their protected health information in the hands of unauthorized individuals, according to the HIPAA Breach Notification Rule, Dr. Jones must report this incident to each individual patient, the local media outlets, and to the Secretary of Health and Human Services. In all likelihood, Dr. Jones' reputation and that of his practice will suffer greatly. He will lose the trust of his patients and the financial effects will be felt for a long time.

What is the Breach Notification Rule?
Simply put, the Breach Notification Rule requires all covered entities and business associates to provide notification if there is a breach of unsecured protected health information (PHI).

What is considered unsecured PHI?
PHI is considered unsecured when it has not been rendered unusable, unreadable, or indecipherable to unauthorized persons who access it through various means that have been specified in HIPAA guidance. Covered entities and business associates that secure their patients PHI, using documented policies and procedures, are not required to provide notifications following a breach of such information.

What is considered a breach?
Health and Human Services (HHS) states that a breach is, "an impermissible use or disclosure under the Privacy Rule that compromises the security or privacy of the protected health information."

Are there exceptions to the Breach Notification Rule?
Yes, there are three exceptions to the Breach Notification Rule as defined by HHS:

  1. "Unintentional acquisition, access, or use of protected health information by a workforce member or person acting under the authority of a covered entity or business associate, if such acquisition, access, or use was made in good faith and within the scope of authority."
  2. "Inadvertent disclosure of protected health information by a person authorized to access protected health information at a covered entity or business associate to another person authorized to access protected health information at the covered entity or business associate, or organized health care arrangement in which the covered entity participates. In both cases, the information cannot be further used or disclosed in a manner not permitted by the privacy rule.
  3. If the covered entity or business associate has a good faith belief that the unauthorized person to whom the impermissible disclosure was made, would not have been able to retain the information.
When a Breach Occurs
Following the discovery of a breach, the covered entity must notify each individual whose PHI was, or is reasonably believed to have been, inappropriately accessed, acquired, or disclosed. If the business associate discovers the breach, it must notify the covered entity and identify the affected individuals.

Timeliness
Notification must be made without reasonable delay and no later than 60 days after discovery of the breach.

Required Notifications
  • Individuals - Written notice must be mailed by first-class mail to the individuals last know address or sent via email if the individual has specified a preference for email communication.
  • Media - If the unsecured PHI of 500 or more residents of a state or jurisdiction is, or is reasonably believed to have been, accessed, acquired, or disclosed during a breach, notice must be provided to prominent media outlets serving the state or jurisdiction.
  • Secretary of HHS - All breaches must be reported by March 1st of each year. If the breach involved 500 or more individuals, notice must be provided immediately. Otherwise, the covered entity may keep a log of breaches and submit the information annually. You can find a list of covered entities experiencing breaches of 500 or more individuals here, http://1.usa.gov/1Q58Jgb
It is important for your office to be compliant with the Breach Notification Rule. Not understanding the requirements will not help your office during a HIPAA audit. Privacy Rule, Security Rule, and Breach Notification are all areas that will be scrutinized during an audit of your HIPAA Compliance Program. Being out of compliance with the Breach Notification Rule will put your office at risk and could destroy your reputation that you have worked so hard to build.

For more information on the Breach Notification Rule, visit:

If you have any questions, feel free to email support@hcsiinc.com

To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Friday, October 2, 2015

HIPAA and Patient Authorizations

When can a patient authorize or restrict the use of their PHI?


Peggy is working in Dr. Smith’s office when she receives a request for the disclosure of a patient’s PHI (protected health information). The request is being made by Worker’s Compensation, but she does not have a prior written authorization from the patient authorizing the disclosure of their PHI to Worker’s Compensation. In this situation, Peggy would not need prior authorization from the patient to disclose PHI to Worker’s Compensation. The Privacy Rule permits covered entities to disclose PHI to workers’ compensation insurers, state administrators, employers, and other persons or entities involved in workers’ compensation systems, without the individual’s authorization. A covered entity must still follow the minimum necessary standard in these situations.



So how do you know when to disclose PHI without prior written authorization and when do you need prior written authorization?

The HIPAA Privacy Rule requires patient authorization for non-TPO (treatment, payment, and healthcare operations) uses and disclosures of PHI. An authorization is a customized document that gives covered entities permission to use specified PHI for specified purposes, which are generally other than TPO, or to disclose PHI to a third party specified by the individual.

There are occasions when a covered entity may disclose patient PHI without their prior approval:

  • Any disclosure made for TPO reasons
  • Domestic violence, abuse, or neglect, as well as cases of child abuse or neglect
  • Court order or subpoena
  • Use or disclosure for public health reasons to the proper authorities
  • Use or disclosure required by law to law enforcement for criminal investigation
  • Use or disclosure required by law to report cases of suspicious deaths or suspected crime victims

It is also written into the HIPAA Privacy Rule that a patient may restrict the use and disclosure of their PHI. Healthcare providers must permit this request but do not have to agree with the requested restriction. If the healthcare provider does agree to a restriction, it may cause some obvious undesirable outcomes. Such problems include, but are not limited to, problems with treating a patient, billing the patient’s insurance, and other challenges. All written PHI restriction requests should be documented and kept on file.

When it comes to disclosing a patients PHI, there are variables that factor into that decision. It is important that all employees in your office have an understanding of this vital HIPAA Privacy Rule policy.


For more information on this and other related topics, including HIPAA, HR, OSHA, and Medicare, please email support@hcsiinc.com or visit our web site at http://www.hcsiinc.com

Tuesday, September 15, 2015

HIPAA Violations and Social Networking

Social Networking Is Putting Your Practice at Risk

Many healthcare organizations are using social networks (Facebook, Twitter, Instagram, etc.) as a means of connected with their client base, or as a means of advertising their services. Whether your practice is using these social networks or not, you
can reasonably assume that your employees are using these sites to expand their own personal social network. This can present a huge problem! 

Employees who frequently use these sites as a way of sharing the events of their personal lives are very likely to discuss work on-line as well. Social network sites create a huge risk for HIPAA violations, and also for employee relation problems.

HIPAA violations occurring on these popular social media sites demand employers establish guidelines for social network use. Because healthcare workers normally access them on personal time away from work, employers should discuss the importance of these guidelines.

Employers should generally prohibit employees from including any information about patients on their social network pages, even if patients have given them permission to do so. It is also recommended that you prohibit your employees from linking to a patient’s social network page. We encourage you to prohibit your employees from accessing these social networking pages while at work using your office computer.

Individuals are free to disclose any information they choose on their social network pages, including their own personal PHI. However, you should be sensitive about your employees linking to these pages at work because of the appearance of impropriety and the distinct possibility of a HIPAA violation. Employers cannot control their employee’s lives and social media activity, EXCEPT as it relates to work.

Tuesday, July 28, 2015

Oral Communication Privacy Reminder

A HIPAA Reminder – Privacy and Oral Communications


Oral communications at your practice are extremely important but are often overlooked and forgotten.  They can be a confusing issue but need serious attention.

The Privacy Rule applies to individually identifiable health information in all forms. Coverage of oral or spoken information ensures that information retains protections when discussed. If oral communications were not covered, any health information could be disclosed to any person, so long as the disclosure was spoken.

Providers and health plans understand the sensitivity of oral information. For example, many hospitals already have confidentiality policies and concrete procedures for addressing privacy, such as posting signs in elevators that remind employees to protect patient confidentiality.


Reasonable safeguards for orally exchanging PHI include:
  • Keeping a distance between the public and the people you’re speaking to
  • Stepping into a room with a door
  • Lowering your voice
  • Using the handset instead of the speakerphone

The Privacy Rule is not intended to prohibit providers from talking to each other and to their patients. It is understood that overheard communications are unavoidable. These are considered to be incidental disclosures.

For example, in a busy emergency room, it might be necessary for providers to speak loudly in order to ensure appropriate treatment. The Privacy Rule is not intended to prevent this appropriate behavior. The following practices are permissible, if reasonable precautions are taken to minimize the chance of inadvertent disclosures to others who might be nearby such as using lowered voices:
  • Healthcare staff may orally coordinate services at hospital nursing stations
  • Nurses and other healthcare professionals may discuss a patient’s condition over the phone with the patient or a provider
  • Staff may call out patient names in waiting areas

Healthcare professionals may discuss a patient’s condition during training rounds in an academic or training institution

Tuesday, June 23, 2015

Disclosing PHI to Law Enforcement

Disclosures to Law Enforcement
A law enforcement officer may come into your office and request that you give him information on one of your patients.  He may have some legal documents with him to prove his request is valid, or he may just want to know if the patient is on the premises. What do you do?  It can be confusing if you do not know the HIPAA Privacy Rule governing releasing PHI to law enforcement. Following are the basic guidelines your staff should know.
The Privacy Rule established procedures and safeguards to restrict the circumstances under which you may give such information to law enforcement officers.  If the law enforcement officer does not have a warrant and has not made any prior process, you are limited in the information you may disclose.  The Privacy Rule specifically prohibits disclosure of DNA.  Similarly, under most circumstances, the Privacy Rule requires you to obtain permission from persons who have been the victim of domestic violence or abuse before disclosing information about them to law enforcement.  Some other federal or state law may require a disclosure, and the Privacy Rule does not interfere with the operation of these other laws.  However, if the disclosure is required by some other law, HHS has said that you should use your professional judgment to decide whether to disclose information, reflecting your own policies and ethical principles.  In other words, HHS is allowing healthcare providers to continue to follow their own policies to protect privacy in such instances. 
Disclosures Allowed Without an Authorization
The Privacy Rule is balanced to protect an individual’s privacy while allowing important law enforcement functions to continue.  The Rule permits covered entities to disclose protected health information (PHI) to law enforcement officials, without the individual’s written authorization, under specific circumstances summarized below:
  • Court-Ordered Warrant or Subpoena
  • To comply with a court order or court-ordered warrant, a subpoena, or summons issued by a judicial officer or a grand jury subpoena – The Rule recognizes that the legal process in obtaining a court order and the secrecy of the grand jury process provides protections for the individual’s private information.
  • Administrative Request or Subpoena
  • To respond to an administrative request such as an administrative subpoena or investigative demand or other written request from a law enforcement official – Because an administrative request may be made without judicial involvement, the Rule requires all administrative requests to include or be accompanied by a written statement that the information requested is relevant and material, specific and limited in scope, and de-identified information cannot be used.
  • Applicable Law and Ethical Standard
  • To a law enforcement official reasonably able to prevent or lessen a serious and imminent threat to the health or safety of an individual or the public; or to identify or apprehend an individual who appears to have escaped from lawful custody.
  • Averting a Serious Threat to Health and Safety
  • If you believe that your practice, a workforce member, a patient, or the public is in danger of a threat to health and safety, your disclosure of PHI for that purpose is protected under HIPAA.  You may, consistent with law and ethical conduct, use or disclose PHI if you believe in good faith that:
  • It is necessary to prevent or lessen a serious and imminent threat to the health or safety of a person or the public;
And
  • It is reported to a person or persons reasonably able to prevent or lessen the threat, including the target of the threat
Or
  • It is necessary for law enforcement authorities to identify and apprehend an individual:
  •  
  • Because of a statement by an individual admitting participation in a violent crime that you reasonably believe may have caused serious physical harm to the victim;
Or
  • Where it appears from all the circumstances that the individual has escaped from a correctional institution or from lawful custody. 
Identifying an Individual
To respond to a request for PHI for purposes of identifying or locating a suspect, fugitive, material witness or missing person; but you must limit disclosures of PHI to name and address, date and place of birth, social security number, ABO blood type and rh factor, type of injury, date and time of treatment, date and time of death, and a description of distinguishing physical characteristics.  Other information related to the individual’s DNA, dental records, body fluid or tissue typing, samples, or analysis cannot be disclosed under this provision, but may be disclosed in response to a court order, warrant, or written administrative request.
This same limited information may be reported to law enforcement:
  • About a suspected perpetrator of a crime when the report is made by the victim who is a member of your workforce;
  • To identify or apprehend an individual who has admitted participation in a violent crime that you reasonably believe may have caused serious physical harm to a victim, provided that the admission was not made in the course of or based on the individual’s request for therapy, counseling, or treatment related to the propensity to commit this type of violent act. 
Victim of a Crime
To respond to a request for PHI about a victim of a crime, and the victim agrees – If, because of an emergency or the person ‘s incapacity, the individual cannot agree, you may disclose the PHI if law enforcement officials represent that the PHI is not intended to be used against the victim, is needed to determine whether another person broke the law, the investigation would be materially and adversely affected by waiting until the victim could agree, and you believe in your professional judgment that doing so is in the best interests of the individual whose information is requested.

Wednesday, May 27, 2015

10 Steps to Protect PHI

10 Steps for Protecting Patient Data

With increasing numbers of access points to protected health information under attack, the healthcare industry continues to be plagued with damaging breaches. Just last week, CareFirst BlueCross BlueShield announced a hacking that compromised the information of more than a million of its members.

A Ponemon Institute report released in May found that over 90 percent of healthcare organizations have been breached in the last two years and the breaches are a growing $6 billion annual epidemic that is putting millions of patients and their information at risk.

Although employee negligence and lost/stolen devices continue to be primary causes of data breaches, one of the major findings of the recent report is that criminal attacks are now the leading cause of breaches in healthcare. While criminal attacks are often referred to as cyber-attacks, they can also include malicious insider threats.

The study also reveals that most healthcare organizations are still woefully unprepared to address the rapidly changing cyber threat environment and lack the resources and processes to protect patient data. However, Rick Kam, the chair of the PHI Protection Network, a cross-industry collaboration of vendors formed to help expedite the adoption of PHI best practices, believes there are some critical strategies healthcare organizations can employ for protecting patient information.

“Probably the best place to start is really to do a risk assessment,” says Kam. “It needs to be front and center as the starting place to help decide and prioritize where—for the most part—a very limited IT security budget might be allocated. What the risk assessment will do is identify those assets and systems where PHI lives.” He sees this as an inventory of where an organization’s patient information exists, not only internally in a hospital or clinic, but also with external business associates and partners that are involved in managing that data.  

Specifically, the PHI Protection Network recommends 10 steps necessary to protect patient data:
        Demand organizational leadership engagement. Workforce training and safeguards alone will not be effective. Organizational leadership must embrace and champion compliance as it would any other component of the organization’s value chain. Leadership must visibly and actively foster a culture of compliance throughout the organization by setting expectations and holding all workforce members accountable to the same standards.
        Find and identify your data. Organizations need to know where their data lives, where it travels, and in what form (encrypted, identified, de-identified, etc.).
        Control PHI workflow and minimize necessary workforce access. Organizations must find ways to better control PHI workflow within the organization, and movement outside the organization. This not only includes safeguarding it from impermissible uses and disclosures, but also will require integration of HIPAA with other health information protection activities to ensure a single point of control within the organization.
        Assess risks. Organizations must have solid processes in place for assessing risk with new systems, devices, services and partners, and determine how best to use their power as purchasers to weed out those that don’t meet best security practices.
        Prioritize third-party vendor management. Organizations will need help with third-party vendor management to strengthen oversight and review processes. Smaller business associates are particularly vulnerable since they may not have as many resources to devote to security and compliance, and may be more likely to experience a data breach.
        Get proactive. The healthcare industry needs to take a proactive stance when it comes to regulations to protect patient health information. Companies that go above and beyond baseline protection requirements will be seen as industry leaders, and patients will choose to use their services over others.
        Make privacy an integral part of new technology adoption. The pace at which new technology is being introduced into the healthcare industry is increasing with thousands of new health-related mobile applications available this year. But there is little evidence that patient privacy or security features are being considered.
        Measure to improve. You can’t manage what you can’t measure. The healthcare industry needs to get better at determining key metrics to continuously measure and improve security postures.
        Look for “non-standard” systems as potential PHI data stores. In particular, voicemail systems, customer service call recording systems, and closed-circuit television systems could all potentially be storing PHI, but may not be as carefully safeguarded as traditional IT systems such as EHRs and patient billing.
        Instill a culture of security. Remember every employee is a guardian of the patient’s data.


(SourceMedia website)