Showing posts with label HIPAA. Show all posts
Showing posts with label HIPAA. Show all posts

Thursday, September 3, 2020

HIPAA - Parents and Their Children’s Medical Records

 Parents and Their Children’s Medical Records

HCSI

Situations when parents can and cannot see their children’s medical records

Does the HIPAA Privacy Rule allow parents the right to see their children’s medical records?

 The answer is YES; the Privacy Rule generally allows a parent to have access to the medical records about his or her child, as his or her minor child’s personal representative when such access is not inconsistent with State or other law.

Exceptions when the parent would not be the minor’s personal representative under the Privacy Rule.


1. When the minor is the one who consents to care, and the consent of the parent is not required under State or other applicable law;

2. When the minor obtains care at the direction of a court or a person appointed by the court and

3. When and to the extent that, the parent agrees that the minor and the health care provider may have a confidential relationship.

Four exceptions to the exceptions

Even in these exceptional situations, there are additional rules to follow:

1. The parent may have access to the medical records of the minor related to this treatment when State or other applicable law requires or permits such parental access.

2. Parental access would be denied when State or other law prohibits such access.

3. If State or other applicable law is silent on a parent’s right of access in these cases, the licensed health care provider may exercise his or her professional judgment to the extent allowed by law to grant or deny parental access to the minor’s medical information.

4. Finally, as is the case with respect to all personal representatives under the Privacy Rule, a provider may choose not to treat a parent as a personal representative when the provider reasonably believes, in his or her professional judgment, that the child has been or may be subjected to domestic violence, abuse, neglect or that treating the parent as the child’s personal representative could endanger the child.

Can a minor child’s doctor talk to the child’s parent about the patient’s mental health status and needs?

Again the answer is generally yes. With respect to general treatment situations, a parent, guardian, or other person acting in loco parentis usually is the personal representative of the minor child and a health care provider is permitted to share patient information with a patient’s personal representative under the Privacy Rule.

Here come the exceptions

However, section 164.502(g) of the Privacy Rule contains several important exceptions to this general rule. A parent is not treated as a minor child’s personal representative when:

1.  State or other law does not require the consent of a parent or other person before a minor can obtain a particular health care service, the minor consents to the health care service and the minor child has not requested the parent be treated as a personal representative;

2. Someone other than the parent is authorized by law to consent to the provision of a particular health service to a minor and provides such consent, or

3. A parent agrees to a confidential relationship between the minor and a health care provider with respect to the health care service. For example, if State law provides an adolescent the right to obtain mental health treatment without parental consent, and the adolescent consents to such treatment, the parent would not be the personal representative of the adolescent with respect to that mental health treatment information.

HIPAA defers to State Laws

Unlike some HIPAA Rules, the Privacy Rule concedes to State or other applicable laws in allowing or not allowing disclosure. Regardless of whether the parent is otherwise considered a personal representative, the Privacy Rule defers to State or other applicable laws that expressly address the ability of the parent to obtain health information about the minor child. In doing so, the Privacy Rule permits a covered entity to disclose to a parent, or provide the parent with access to, a minor child’s protected health information when and to the extent that it is permitted or required by State or other laws (including relevant case law). Likewise, the Privacy Rule prohibits a covered entity from disclosing a minor child’s protected health information to a parent when and to the extent it is prohibited under State or other laws (including relevant case law).

What if the State Laws are silent?

In cases in which State or other applicable law is silent concerning disclosing a minor’s protected health information to a parent, and the parent is not the personal representative of the minor child based on one of the exceptional circumstances described above, a covered entity has the discretion to provide or deny a parent access to the minor’s health information, if doing so is consistent with State or other applicable law, and the decision is made by a licensed health care professional in the exercise of professional judgment.

Mental Health and Substance Abuse laws may be stricter

In situations where a minor patient is being treated for a mental health disorder and a substance abuse disorder, additional laws may be applicable. The Federal confidentiality statute and regulations that apply to federally-funded drug and alcohol abuse treatment programs contain provisions that are more stringent than HIPAA. In these cases, it is wise to know your State laws and HIPAA rules, found here: https://www.hhs.gov/hipaa/for-professionals/special-topics/mental-health/index.html

Reminder: A parent also may not be a personal representative if there are safety concerns. A provider may decide not to treat the parent as the minor’s personal representative if the provider believes that the minor has been or may be subject to violence, abuse, or neglect by the parent or the minor may be endangered by treating the parent as the personal representative; and the provider determines, in the exercise of professional judgment, that it is not in the best interests of the patient to treat the parent as the personal representative.

To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Thursday, July 30, 2020

Medical Records Retention Time-frames

Medical Records Retention Time-frames


If you Google “Medical Records Retention,” it says to keep records 4, 6, 7, up to 10 years or forever. That is why our call center at HCSI receives many questions about how long medical records need to be retained. Medical Records Retention (MRR) is a challenging issue. There are many variables. This entire newsletter is dedicated to helping explain a few of these variables.

The idea that records, either in paper or electronic form, should be saved for around ten years to comply with all requirements is an oft-touted rule of thumb. And it is often a good one. But, of course, there are exceptions. It is confusing!  Unfortunately, there is no single "exact line" that describes federal, state, and other statutory laws that establish how long medical records must be maintained in every case. But we have assembled Ten MRR Rules to help you understand how long to keep your patient records. This list is not exhaustive, but it covers the majority of situations.

Why is it so important to properly maintain medical records?

Beyond the laws and regulations, at its core, your medical records retention policy should be based primarily on two principles: 

1. Medical Considerations 
2. Continuity of Care for your practice and with other providers who care for your patients

Additional reasons for retaining medical records 

1. Providing Patients with Information should they wish to access their records 
2. Protecting the Provider in case a legal claim is made in the future
a. Relying on the practitioner’s testimony of general habit and practice to show that the standard of care was met—without supporting documentation to establish the treatment that was rendered—often fails to convince a jury that the treatment the patient received was consistent with community standards.
3. Complying with Federal and State Laws for such things as billing audits
4. MRR establishes the quality of care rendered in the event of a medical board or peer review inquiry. 
a.  Patient complaints are often based on an individual’s mistaken recollection of events or on a failure to understand the course of treatment or adverse consequences involved in the dispute. With complete charting, frivolous allegations are readily resolved, frequently well before a formal administrative process is even initiate

MMR Rule #1: Is it practical to keep all your records?

Should we begin thinking about keeping all records for 30 years or more?

With the advent of inexpensive high-speed storage, HCSI would like to suggest the idea that if all your medical records are electronic, they may be kept permanently. This would be helpful should access to patient information becomes necessary, as has been evidenced by litigation cases involving exposure to chemicals, drugs, or substances such as asbestos. 

We realize that the storage of hard copy records makes permanent retention impractical; however,

Sound too expensive. It used to be. One estimate states that 2000 patient over 30 years could take up 4000 gigabytes of computer storage, or about 30 Terabytes. At today’s prices, a 30 TB hard drive can be purchased for under $1,000.

Another side of the coin

There’s another side of this that is sometimes suggested by law firms. Here’s the argument:

Destroying records, digital or otherwise, once their retention deadlines arrive lessens the volume of Protected Health Information (PHI) theft that is possible. Even if your backroom is locked and your health IT system offers top-notch encryption, security breaches and HIPAA violations can still occur.

There’s no reason to leave any patient information – especially data that’s unnecessary to retain – vulnerable to being compromised. As long as you keep documented records of all destructions, proper disposal of old data is the best way to ensure patient confidentiality is upheld. If you’ve got plenty of space at your practice for stowing old paper records, you may be tempted to hang on to them forever, if only to avoid the hassle of electronic archiving or digging through them to determine what you can pitch.

So comb through your old charts, dig through your electronic data and destroy what no longer needs to be retained.

MRR Rule #2: Coordinate State and Federal laws

Whichever law instructs you to keep medical records the longest prevails

Know your State Laws:
  • Providers must comply with individual state regulations on Medical Record Retention (which often differ from the national standards) and their states’ statutes of limitations on malpractice lawsuits.
  • If Federal laws require individual medical records to be kept 10 years and your state law says 12 years, keep them 12 years – and vice versa. This rule applies to all other retention laws. 
  • You can find the state laws on retention periods for your state and practice type at: (PDF) 

MRR Rule #3: Maintain a policy for retaining your medical records 

Share it with your staff and patients

Share your medical record retention rules with your entire staff and new employees

Even a simple practice such as holding a meeting (and making a record of it) to go through the rules in this newsletter will help your staff understand the importance of medical records. You can customize your policies based on your specialty and needs.

Some practices provide a summary MMR policy to new patients as part of their "introduction to the practice" materials.

When new patients are informed in advance about how their medical records will be handled, there is substantially less likelihood of a complaint to the Medical Board if/when a practice is closed. Be sure current and future patients at some point receive assurance about their medical records. This may be as simple as a paragraph at the top or bottom of an intake form that says something like. “At ABC Medical, we carefully maintain and protect your private medical records according to all federal and state laws. Should you at any time desire access to these records, please consult with your physician or our staff.”

Have your MMR policy reviewed

It is a wise idea to check with your medical liability insurance carrier and legal representative before finalizing your policy. They have experience defending other practice policies. 

MRR Rule #4: MINORS: Typically 3 Years after they reach majority 

Consult State/Federal/Hospital/etc. laws and retaining them for whichever is longest 

  • Typically Age of Majority is 18-20. 
  • A typical exception for minors is hospitals usually require age of majority plus 6 years.
  • Once a minor reaches majority, the adult retention recommendation applies, e.g., 10 years from the last medical service for which a medical entry is required.
  • If a lawsuit is filed, it is essential to note that the statute of limitations may not begin to run until the plaintiff (patient) learns of the causal relationship between an injury and the care received.
  • The American Academy of Pediatrics recommends that, at a minimum, pediatric records should be retained for 10 years or the age of majority plus the applicable state statute of limitations (time to file a lawsuit), whichever is longer.

MRR Rule #5: Adults: 7-10 years

Measured from the date of the last medical service for which a medical entry is required. 
  • In some instances Federal law mandates that a provider keep and retain each record for a minimum of 7-10 years from the date of last service to the patient, we recommend keeping them for a minimum of 10 years.
  • For Medicare Advantage patients, 10 years.
  • Deceased adult patients: 10 years from the time of death. State exceptions may apply.
MRR Rule #6: Legal matters: Keep accruing’ ‘till they’re all done suin’ 

In other words, maintain medical records as long as they might be used to defend against a malpractice allegation.
  • Should you ever discover or suspect that legal action is pending from a patient, be sure to save his relevant records, even if you’ve already kept them past their other retention deadlines.
  • No destruction is allowed once you have knowledge of the litigation. 
MRR Rule #7:  OSHA: 30 years

For workplace injuries, if OSHA was involved, keep them for 30 years after the last date of service.

MRR Rule #8:  Veterans: 70 years - Indefinitely
  • Be prepared to store vet charts for a long time – 75 years.
  • If a patient was not mentally competent at the time of treatment, retain the records indefinitely.
MRR Rule #9: HIPAA: 6 Years

Six years from when the document was created, or – for policies – from when it was last in effect
  • According to the Department of Health and Human Services, the HIPAA Privacy Rule has no requirements for medical record retention at a doctor's office. Only HIPAA Related documents. How long a doctor is required to keep a chart is based on what each state's legislation decides. So, Tennessee's medical record retention rules may completely differ from Georgia's and so forth.
  • Although there are no HIPAA retention requirements for medical records, there is a requirement covering how long HIPAA-related documents should be retained. This is covered in
  • CFR §164.316(b)
  • While the HIPAA Privacy Rule does not determine how long a chart must be kept at a doctor's office, it does; however, require that any covered entities apply all safety guidelines necessary to protect the privacy of all patients,
  • As with all these rules, states requiring less than six years, health organizations must still retain HIPAA information for six years – the longer of the two rules.
The list of documents subject to the HIPAA retention requirements, and depends on the nature of business conducted by the Covered Entity or Business Associate. The following list is an example of the most common types of HIPAA documents beyond patient files.
  • Notices of Privacy Practices.
  • Authorizations for the Disclosure of PHI.
  • Risk Assessments and Risk Analyses.
  • Business Associate Agreements.
  • Employee Sanction Policies.
  • Incident and Breach Notification Documentation.
  • Complaint and Resolution Documentation.
  • IT Security System Reviews (including new procedures or technologies implemented).
MRR Rule #10: Rule of Thumb Rule: 10 years and 28 years

When all else fails
Where no statutory requirement exists, and no legal threat is imminent, HCSI makes the following 
  • Adult patients, 10 years from the date the patient was last seen.
  • Minor patients, 28 years from the date of birth. 


To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Thursday, March 8, 2018

100 in 10 Campaign

Healthcare Compliance Solutions, Inc. (HCSI)
has launched the “100 in 10” campaign.

What is the “100 in 10” Campaign?

The Healthcare Compliance Solutions Inc. “100 in 10” campaign was designed to encourage healthcare organizations to complete 100% of their new employees’ compliance training within their first 10 days.

100% Completion

First 10 Days

Why is it Necessary?

When a new employee is hired, outside of Medicare (within first 45 days), there is not a set time period for training the new hires on compliance regulations. With new hires, healthcare organizations will train their new employees on the different workings of the organization, the daily tasks the employee will perform, and other training's that are vital to the new employee’s ability to perform the job they have been hired to do. However, many organizations will postpone providing compliance training until it is convenient for them do conduct the training.

During this time, the employee continues to do his or her job while being ignorant on compliance regulations, office polices, and potential liabilities for the organization. All the while:
  • They have been exposed to various forms of protected health information (PHI) without being trained on HIPAA regulations. 
  • They have been moving around the office without knowledge of the safety protocols due to not being trained on OSHA regulations.
  • They have been interacting with other co-workers before the new employee understands what is and what is not acceptable behavior within the organization because they have not been properly trained on HR Policies/Procedures.
  • They do billing or other activities involving Medicare without being trained on Fraud, Waste, and Abuse.
All of this activity by the new employee is a major liability and puts the organization at unnecessary risk.

Recommendation

With more than 30 years of experience, it is the professional recommendation of HCSI that all new employees complete 100% of the compliance training within their first 10 days.

100% in 10 days is a goal that all healthcare professionals can achieve.

Make sure all of your new employees are 100 in 10!



To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Tuesday, August 29, 2017

Where Is Your PHI Data Traveling Today?

Understanding "The Cloud" and it's regulatory relationship with HIPAA and PHI.

With most vendors offering and pushing cloud computing solutions and offsite data backup, or guaranteeing offsite backup of data they process for you, many HIPAA covered entities (CEs) and business associates (BAs) are questioning whether and how they can take advantage of cloud computing while complying with regulations protecting the privacy and security of electronic protected health information (ePHI). 

What "Cloud" computing means is that instead of all the computer hardware and software you're using sitting on your desktop, or somewhere inside your company's network, it's provided for you as a service by another company and accessed over the Internet, usually in a completely seamless way. Exactly where the hardware and software is located and how it all works doesn't matter to you, the user -- it's just somewhere up in the nebulous "cloud" that the Internet represents. 

The business decision to "move to the cloud" is often financially motivated. Companies used to have to buy their own hardware equipment, the value of which depreciated over time. But now with the cloud, companies only have to pay for what they use. This model makes it easy to quickly scale use up or down and to have data backed up for you as part of that provided service.

The rise of offshore IT services, including distributed storage, by cloud data providers creates issues that most healthcare providers have not yet realized. Even if some of the issues are realized, many covered entities and their business associates do not know where their data is currently being processed, stored, or backed up. In fact, storage or processing of protected health information (PHI) overseas may or may not be permitted or at least require additional resources, such as additional or more detailed risk assessments.

There are currently no federal regulations or statutes that prevent storing or processing PHI offshore or overseas; however, the Centers for Medicare and Medicaid Services (CMS), the U.S. Department of Health and Human Services (HHS), and the U.S. Office of Civil Rights (OCR) within the HHS, have all issued regulations or provided guidance that restrict storing or processing PHI offshore. In addition, there are four states that ban any Medicaid data from being stored or processed overseas (Arizona, Alaska, Ohio and Wisconsin), two more that only allow offshore contracts under extremely limited circumstances, and nine more that have specific requirements that must be met before any offshore processing or storage of Medicaid data is allowed. 

Even if a healthcare provider is not located in one of the above states, if the provider has treated a patient of those states, state regulators may argue that the healthcare provider must comply with their laws, regulations, and guidance, as applied to the resident of their state. Even more concerning is that even though Delaware does not have any laws or statutes banning offshore processing or data storage, Delaware recently started adding provisions to all of their contracts (similar to Wisconsin) that the State (Delaware) will not permit project work to be done offshore. There may be additional states adding these prohibitions to their contracts in the future.
If extra regulatory burden and potential state law bans were not enough by themselves, any PHI stored offshore likely will be subject to local law of the country in which it is stored. Furthermore, these local laws may allow for actions or even access to the data that directly conflicts with requirements on healthcare providers under HIPAA/HITECH, even if the vendor signed a Business Associate Agreement (BAA). Due to the issues in enforcing HIPAA and HITECH, and even a BAA against an overseas vendor, HHS has basically stated that it is the duty of the healthcare provider or vendor for deciding how to vet data services vendors and comply with expected additional requirements when conducting a risk assessment on overseas providers. 
At this point, most healthcare providers question if any offshore or offsite data storage or processing is worth any potential cost savings, or if OCR has any further guidance. In the fall of 2016, OCR prepared guidance that explained how federal health information privacy and data security rules apply to cloud services. In summary, this guidance helped data service companies, but at the expense of covered entities by primarily placing the burden on the covered entities, specifically hospitals, insurers, doctors, and other healthcare providers.

In looking at data service vendors, OCR decided that data service subcontractors of the covered entities’ business associates are actually business associations of the business associates. According to the OCR, covered entities must assess the cloud services providers’ or offshore providers’ data security efforts, but HIPAA does not require the cloud services providers to allow covered entities audit them. As such, covered entities are required to determine how well a cloud services provider handles system reliability, data security, and data backup and recovery, without the ability to perform an audit. While this is problematic when dealing with domestic cloud service providers, it creates additional issues when dealing with overseas cloud service providers. 
While OCR allows use of overseas providers, as of right now the rules of HIPAA and HITECH fail to address any international aspects, leaving no requirements but also no protections for covered entities. If you select a domestic provider, the laws and regulations regarding PHI apply to both parties, but if an overseas provider is selected, HIPAA and HITECH will not apply, unless they contractually agreed to comply with such laws and regulations. If there is a breach and the overseas provider refuses to defend against or pay any fines or fees levied related to the breach, the covered entity may be liable for paying. It is also important to note that while an international provider may agree to sign a BAA, many international providers do not understand the requirements of HIPAA and HITECH, while most domestic providers have a greater understanding.
Even if you know where the company with whom you are contracting is located, do you know where they send the backup data? Do they send data for processing or backup to other agents, subcontractors, vendors, or other data providers overseas? You may not realize your data is regularly taking international trips, and may be better traveled than you are. In addition, if a relationship is terminated with an international provider, how will you ensure that the data is wiped from the system? Healthcare providers generally must require a certificate of destruction when terminating data services, and will you be able to comply with this provision with an offshore provider?
In contracting with cloud service providers, including backup providers, e-mail providers, and other processing entities, covered entities and their business associates must determine where their data is located, and if it is offshore, they must analyze if any of the information is prohibited from being exported by any state or local regulations. If not, next it must be determined if there is an extra compliance burden associated with the data being offshore, and if that extra compliance burden and the associated risk of being offshore are worth any cost savings by using the offshore provider. If an entity knows that some of its data may be banned from being exported overseas, or would raise too much risk or compliance burden, then language banning such exports should be placed in the agreements, including any BAAs. 
 HCSI

Used with permission from: Craig A. Phillips council member of Dickinson Wright
To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Thursday, August 10, 2017

Six Ways to Improve Data Security at Your Practice

A married couple — both doctors who shared a medical practice — almost divorced over a HIPAA breach that blindsided them when a patient called to say that her medical records appeared in a Google search and she was filing a lawsuit.

The orthopedist of a small practice didn’t want to fund the cost of an IT service provider to make sure his network was secure.  Instead the doctor hired his cousin who earned his IT stripes fixing performance problems on his own laptop.  Unfortunately, the family member never updated the practice’s malware software and patient data ended up on a rogue server.  Now it’s being held for ransom. 

The Smaller the Practice the Less the Compliance

For medical practices with 20 or less employees, doctors are often reluctant to spend money on HIPAA security than larger practices.  Importantly, the latter will have a compliance officer who makes sure HIPAA rules are followed, employees are trained, and policies and procedures are up to date. 

Doctors running small practices don’t believe they’re at risk for a data breach so they ignore the same steps taken by the compliance officer.  Meanwhile, it’s ordinary human errors that could take down the practice.  An employee leaves his tablet in a taxi or thieves break into the office and steal two laptops that contain patient records.  Or the doctor loses his laptop and keeps it under wraps since he thinks he hasn’t stored any patient records on it, so no one needs to know.  However, a disgruntled employee who was terminated gets revenge by reporting the practice to the Department of Health and Human Services’ Office of Civil Rights (OCR).  The OCR accuses the practice of having a breach and hiding it, and calls for an investigation. 

These are all real world events that have sent medical practices into a tailspin.  Doctors call a HIPAA compliance expert in a panic because they’re now caught in the web of the OCR and scrambling to prepare for an audit.  Worse yet, these compliance risks were right under their noses.

The Practice Needs As Much Care As the Patients

The risk of a data breach can be as life threatening to the practice that doesn’t protect its data, as the risk of lung cancer is for the patient who chain smokes.  Think of a data breach as a disease and the stolen laptop causing pain and suffering, and eventual death, which could all be prevented.  Doctors should think about data breach prevention and care for their businesses with the same commitment to disease prevention and care for their patients. 

When a practice fails to perform a security risk assessment or ensure that his employees used strong passwords, not long after he is convincing OCR auditors that the breach was an accident.  He has to hire attorneys to complete the audit and there is no budget left to invest in more network security, or cyber insurance. 

HIPAA Compliance Made Easy for Small Practices

There are some simple steps small practices can take that will take far less time than preparing for an OCR audit:

- Perform a security risk analysis — Analyze how patient information is currently protected. How often does the practice perform data backups? Is there a termination procedure when an employee leaves? Do employees have the minimum level of access to patient information? Are all portable devices encrypted?  Are medical records protected in case of fire or flood, or lost or stolen laptops that contain patient information?

- Train employees — Make sure they know how to spot phishing scams and suspicious links in emails, recognize fraudulent “IT experts” who call in to upgrade an operating system.  They should also know to avoid conducting business on public Wifi, and minimize sharing on social networks.

- Inventory patient information — Locate where all patient information is stored. It could be an EHR or a word document in the form of patient letters, or excel spreadsheets as billing reports or scanned images of your insurance carrier’s explanation of benefits (EOB).  This information resides on desktops, laptops and mobile devices, and should be encrypted.

- Employee data theft — Employee theft of information is one of the leading causes of HIPAA breaches in small organizations.  An employee steals patient information and opens a charge account at a local department store.  The patient finds out and sues the practice for not protecting her electronic protected health information (ePHI).  Employees should have minimal access to EHRs — only the information they need to perform their duties.   Also data logs should be checked.

- Breach Response Plan — Is there a response plan in place in case a breach does occur? The plan should include who will be on the response team, what actions the team will take to address the breach, and what steps they’ll take to prevent another similar breach from occurring. Make sure the plan is documented and all employees are trained on what they need to do.

These few actions can make the difference between being sued by patients for a data breach and gaining their confidence that their doctor cares as much about their health as he does for their security.

Source(s): https://www.hcsiinc.com, , http://www.physicianspractice.com

For more information on this and other healthcare compliance topics related to HIPAA, OSHA, Medicare and HR, simply email your questions to support@hcsiinc.com, 
visit our website at http://www.hcsiinc.com or post a question on our LinkedIn group at: http://bit.ly/1FWmtq6

To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Wednesday, June 28, 2017

Patient Authorization

What is the difference between “consent” and “authorization” under the HIPAA Privacy Rule?
 Healthcare Compliance Solutions Inc.
The Privacy Rule permits, but does not require, a covered entity voluntarily to obtain patient consent for uses and disclosures of protected health information for treatment, payment, and health care operations (TPO). Covered entities that do so have complete discretion to design a process that best suits their needs.

By contrast, an “authorization” is required by the Privacy Rule for uses and disclosures of protected health information not otherwise allowed by the Rule. Where the Privacy Rule requires patient authorization, voluntary consent is not sufficient to permit a use or disclosure of protected health information unless it also satisfies the requirements of a valid authorization. An authorization is a detailed document that gives covered entities permission to use protected health information for specified purposes, which are generally other than TPO (treatment, payment, or health care operations), or to disclose protected health information to a third party specified by the individual.

HIPAA requires that certain elements be present on the authorization that the patient is to sign. Whenever you receive an authorization (or “release”) asking you to disclose PHI and HIPAA requires an authorization for the disclosure, use this checklist to verify that the authorization meets the HIPAA requirements. If any ONE of the following elements is missing, you should NOT release the patient’s PHI until you have a valid authorization signed by the patient. If ALL the elements are present, the authorization is valid.

• A description of the PHI to be used or disclosed that identifies it in a specific and meaningful fashion. They may request the entire medical record, all records between specific dates, or other specific items.

• The name or other specific identification of the person(s), or class of persons, who can make the requested use or disclosure. For example, the signed request should list either your organization or someone in your organization by name.

• The person(s), or class of persons, to whom you may make the requested disclosure. The specific entity(ies) to receive the information should be identified. A cover sheet stating who should receive the information is NOT sufficient.

• A description of each purpose of the requested use or disclosure. The statement “at the request of the individual” is a sufficient description of the purpose when a patient initiates the authorization and does not, or elects not to, provide a statement of the purpose. The above statement or some other description must be present.

• An expiration date or an expiration event that is related to the individual or the purpose of the use and disclosure. The statement “end of research study”, “none”, or similar language is sufficient if the authorization is for a use or disclosure of PHI for research. Again, the statement must be present.

• Signature of the patient and date. If the authorization is signed by a personal representative of the individual, a description of such representative’s authority to act for the individual must also be provided.

• In addition to the core elements, the rule states that a valid authorization must include:
  1. A statement of the individual’s right to revoke the authorization, in writing, and either:
    • A reference to the revocation right and procedures described in the notice, or
    • A statement about the exceptions to the right to revoke, and a description of how the individual may revoke the authorization
    Exceptions to the right to revoke include situations in which the covered entity has already taken action in reliance on the authorization, or the authorization was obtained as a condition of obtaining insurance coverage. (*Note that if an authorization is revoked it must be fully documented in a separate "revocation of authorization" form/document.)


  2. A statement about the ability or inability of the covered entity to condition treatment, payment, enrollment, or eligibility for benefits on the authorization:

    • The covered entity must state that it may not condition treatment, payment, enrollment, or eligibility for benefits on whether the individual signs the authorization, or
    • The covered entity must describe the consequences of a refusal to sign an authorization when the covered entity conditions research-related treatment, enrollment or eligibility for benefits, or the provision of healthcare, solely for the purpose of creating protected health information for a third party on obtaining an authorization.

  3. A statement that information used or disclosed pursuant to the authorization may be subject to redisclosure by the recipient and may no longer be protected by the rule
•    The ability or inability to condition treatment on the authorization by stating either:  
  1. The covered entity may not condition treatment on whether the individual signs the authorization or 
  2. The consequences to the individual for refusal to sign the authorization.  (Remember that there are very limited circumstances in which action can be a condition on a patient signing an authorization.)
•    A statement that informs of the potential for information to be re-disclosed by the person or organization to which it is sent.  The privacy of this information may not be protected under the Federal Privacy Rule depending on whom the information is disclosed to.

*Authorization for marketing purposes: If the requested use or disclosure is for marketing purposes. If the marketing involves direct or indirect remuneration to the covered entity from a third party, the authorization must state such remuneration.

The HITECH Omnibus Rule requires a valid authorization be obtained from an individual before the use or disclosure of PHI for marketing purposes involving financial remuneration. The authorization must also include a statement about any direct or indirect remuneration the covered entity has received or will receive from a third party. An authorization for marketing purposes can be included on the organization’s compliant HIPAA authorization form or a separate one may be created.

The following are exceptions to the marketing rule and do not require an authorization:
  • Face-to-face communications from the covered entity to the individual 
  • Gifts of nominal value provided by the covered entity


 HCSI


To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Thursday, June 15, 2017

Hold Your Business Associates Feet To The Fire

Documented HIPAA compliance training is NOT an option for your Business Associates!

With the focus of the Office for Civil Rights (OCR) so squarely on the Business Associates of Covered Entities, it is more important than ever to hold your Business Associates feet to the fire when it comes to providing proof of their HIPAA training.

It is strongly recommended that Covered Entities require {45 CFR 164.502(e), 164.504(e), 164.532(d) and (e)} all of their Business Associates to provide them with documented proof of their HIPAA compliance training. This documentation could come in the form of individual employee training certificates or (if the Business Associate does not have training certifications) a signed addendum along with your Business Associate Agreement (BAA) attesting to the fact that the Business Associate's HIPAA training program was completed and will continue to be on an annual basis to maintain a standard for ongoing compliance training and awareness of evolving standards.

Far too often, I have talked with Covered Entities who's Business Associates verbally claimed that all of their employees were HIPAA trained, but could not provided documented proof. Simply saying, "Yah sure, we do HIPAA training..." is not enough proof for OCR. It is vital that Covered Entities are able to provide documentation of their Business Associates claim that they have completed their HIPAA training. If a Covered Entity is working with a Business Associate who either does not have documented proof of their HIPAA training program or refuses to supply the Covered Entity with such documentation, then that Covered Entity has two options:
  1. Recommend a BA HIPAA Compliance Training Program to their Business Associate;
  2. Begin exploring the option of no longer doing business with that particular Business Associate
Remember a BAA is a binding legal Contract and should be treated accordingly. Having Business Associates provide documented proof of a HIPAA training program will greatly assist in helping to limit additional liabilities for a Covered Entity and their patients.


To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Thursday, June 8, 2017

Informed Consent, Consent to Treat and Informed Refusal

A Compilation of Resources Discussing Informed Consent, Consent to Treat and Informed Refusal

As providers redefine processes to ensure more patient-centered care, you will want to reassess your informed consent approach to ensure that it abides by all regulations and protects the provider, patient and practice. Informed consent is a routine aspect of healthcare yet it is one of the most misunderstood concepts even among experienced physicians. This misunderstanding stems from a failure to understand all of the elements that comprise informed consent and recognize the ramifications of patient allegations that he or she did not understand the benefits versus drawbacks of a provider’s treatment recommendation.

A history of informed consent

Hippocrates, who gave us the first set of western writings on conduct for medical professionals, suggested patients are best served when physicians conceal most information. It was not until the 18th century writings of physician Benjamin Rush that we began to see recommendations that physicians share information with their patients. The publication of Medical Ethics in 1803 by Thomas Percival advocated the notion that while patients have a right to the truth, a physician might lie or withhold information if it results in better treatment. Informed consent gained more ground as a result of the atrocities committed by the Nazis who routinely experimented on human subjects.

The American Medical Association via Opinion 8.08, Informed Consent, says, “The physician has an ethical obligation to help the patient make choices from among the therapeutic alternatives consistent with good medical practice.” Adopted in 1981 and updated in 2006, the opinion reads, “Physicians should sensitively and respectfully disclose all relevant medical information to patients.

The main purpose of the informed consent process is to protect the patient. A capable adult cannot be forced to have any type of medical treatment. In general, anything other than a life-threatening emergency in which the patient is unconscious requires consent before treatment. Even in that situation, consent may be required if the patient is known to have an advance directive.

The Advance Healthcare Directive
An advance health care directive or advance directive is a kind of legal document that tells the doctor your wishes about your health care.
Advance directives can be general, with very few directions about your care. The directive may just name a substitute person (proxy) to make these decisions for you if you are unable to do so. Or it may include instructions for the chosen proxy.
Advance directives can also be very detailed and clearly outline the different types of life-sustaining treatments you would accept or refuse in certain situations. Some types of advance directives are limited to certain situations, like the living will, organ or tissue donation, or your wishes not to be revived (resuscitated) if your heart or breathing stops.
Who besides the patient is allowed to consent?
For children or others who are unable to make the decision for themselves, the parent or legal guardian is legally responsible for getting the information, making the decision, and signing the consent form. But that doesn’t mean that the child or patient who is not considered mentally competent is always left out of the process. Some facilities require the assent of older children before they go into a research study, even after the parents have agreed on the child’s behalf. Assent means that, even though the parents sign the form, the child must also be OK with the plan before the facility will do the treatment.
Along the same lines, people who are unable to manage their daily affairs because of impaired thinking or emotional problems might still be able to understand the medical situation and make their wishes known. They should be given information in a way they can understand, and asked what they want to do.
In the event that you become unable to take in information and make your wishes known, another person may be asked to take part in the process of informed consent. There are several ways that person can be chosen.
  • Durable power of attorney for health care -- The only way you can choose the person to make these decisions for you is to set up a durable power of attorney for health care (also called a health care power of attorney). In this case, if you are unable to speak for yourself, the person you chose becomes legally responsible for making medical decisions on your behalf. This person is sometimes called your proxy, agent, or surrogate.
  • Court-appointed proxy -- Another option is a court-appointed surrogate or proxy. This is someone a judge chooses to make medical decisions for you. If you become unable to make decisions for yourself, someone else – such as the doctor, facility, a friend, or a family member – may ask (petition) the court to appoint someone to do it for you. The process varies from state to state.
  • State family agency acts -- Many states have passed family agency acts that choose which family members (in a listed order of priority) may act on behalf of a person who cannot speak for her- or himself. This option may be used if you don’t have an advance directive or court-appointed proxy. Depending on your family situation and which state you are in, that person may be your legal guardian, spouse, parent, child, sibling, or other relative.
A consent form is not needed for simple diagnostic tests and situations in which your actions imply consent. For example, if you see your doctor and allow a blood sample to be taken for lab tests, your consent is assumed because you went to the doctor seeking care and allowed blood to be drawn. At any point, you could change your mind and decide to refuse testing, leave the doctor’s office, or seek care elsewhere. This is different from a treatment that puts you in a vulnerable position or can possibly cause serious harm. You need more information about more risky treatments so that you can weigh your options and consider your risks before making a decision.

Even when there are no other accepted medical treatment options, it’s still your right as a competent adult to refuse a treatment that you don’t want or refuse to be in a study that you didn’t choose. But once you sign the consent form, it’s taken to be a formal, legal agreement that you are OK with the plan or procedure that’s listed on the form unless you revoke (take back) your consent before treatment is given. The doctor or facility will usually give you a copy of the consent form, but they keep the original as a legal record that you agreed to the treatment.
For example, a physician makes a recommendation to a patient for surgery and leaves the exam room. A nurse enters, puts a form in front of the patient and asks if there are any questions. The patient, still absorbing the news that he needs surgery, has no questions and signs the form. The surgery proceeds but does not go as planned. Soon thereafter, the physician is served with a claim for malpractice and medical battery citing, among other issues, a lack of informed consent.

Who wins? The answer is that no one wins.

Whether there is an adverse event that permanently affects the patient’s health or a patient believes he or she was not given all the necessary information, the patient walks away feeling shortchanged and the trust established with the physician is lost. Worst-case scenario, the patient’s health is adversely affected by a decision that would not have been made with better information, and the physician faces years of litigation that will affect the practice and his or her personal well-being.

Informed consent has been referred to in terms of medical ethics and treatment variation, but the task of obtaining informed consent is a practical issue that can be included in process review and regular staff meetings to ensure that providers are protected from malpractice allegations.

Informed consent

Far too often, physicians provide a treatment recommendation and the implications for not following it stop there. And while informed consent is a routine expectation, especially for high-risk procedures and drugs, it generally is not a legal requirement though informed consent requirements vary by state.

These requirements might be enacted by law or could be included in the policy documents of a state governing medical board. They might also be found in case law for malpractice claims. Because of failure to fully appreciate what constitutes effective informed consent and the inconsistency of requirements across the country, it is often not given its due diligence and can become a pretense for doing the right thing in name only with no meaning. Even when a physician believes they have imparted enough information for a patient to make an informed decision, a patient and a jury might disagree.

Informed consent can take two forms: implied or express.

Implied consent is generally associated with lower risk treatments and procedures, such as immunizations. While disclosure must be made regarding benefits and risks of an injection, generally via a Vaccine Information Sheet (VIS), we generally do not obtain signatures before an immunization unless it carries significant side effects or unknown risks. Instead, we rely on the patient rolling up their sleeve and presenting an arm as evidence of consent. In comparison, express consent is more formal. It is evidenced by a patient or guardian/power of attorney’s signature on a form.

While often referred to in varying terms, the elements that make up an informed consent discussion can be broken down into four categories, which should be included on your informed consent form:

Risks: What is the danger from a recommended treatment? Not every potential adverse outcome has to be mentioned but physicians know which outcomes are most likely to affect patients and those should be addressed. For example, a hand surgeon would probably have a more in-depth conversation with a world-renowned concert pianist than the average patient because an adverse outcome would alter the pianist’s career and life in different ways. Groups might want to consider what procedures or routine activities require express versus implied consent and establish a policy to avoid staff and provider confusion. When in doubt, go for the express consent to protect yourself. In theory, if a patient is properly educated, the execution of a signature on paperwork reflecting this should add very little time on the front end but could save years of wasted time in litigation on the back end.

Benefits: What can be gained from the treatment? Or what can a patient realistically expect to achieve from adhering to the prescribed treatment? For example, will a patient’s pain be minimized or disappear? Will life expectancy increase? Are there limitations? A discussion about the likelihood of potential benefits is prudent, and you should also talk about factors that would prevent this patient from falling within the general expectations.

Alternatives: Are there other treatment choices that should be considered? For example, should a patient consider a nonsurgical approach, such as glasses or contacts in lieu of Lasik surgery? Keep in mind that alternatives include pursuing no treatment, which should be included as an option no matter how wrong you might think it is. The issue of cost for various options might be worth mentioning if there is a significant difference, especially for patients with no insurance. There will be varying opinions among physicians about how to handle alternatives, which they might not advise but it is important for physicians in groups to operate uniformly. Conflicts should be resolved within the governance structure of the organization. Physicians should be encouraged to consider their ethical obligations and reach consensus. Physicians can certainly offer options without endorsing them and be as candid as possible with patients.

Consequences: What are the potential implications of a patient’s decision, whether it is to follow a recommended treatment, pursue an alternative or do nothing? This is when most physicians typically are asked, “What would you do?” There is no harm in answering this question, but remind a patient that he or she has to make the decision based on his or her unique situation.

Informed refusal

While some states require signed consent for certain procedures, such as sterilization, the vast majority have few or no rules. Even when not required, an informed consent form is invaluable in defending a malpractice claim. However, an informed refusal form is equally valuable.

An informed refusal form is really just a twist on an informed consent form and while it is not commonly used, it is worth its weight in gold from a defense perspective with a noncompliant patient. The real difference is that instead of acknowledging and accepting the risks of treatment with an informed consent form, a patient acknowledges the risks of not following a physician’s recommendations. The form acknowledges that a patient is choosing an alternative treatment or no treatment at all and any accompanying consequences. These are particularly important with noncompliant patients to demonstrate that they have made educated decisions to not follow provider advice and knowingly accept the consequences.

As frustrating as it can be, competent adults get to make their own healthcare decisions. That word “competent” is key here. Informed consent discussions should occur while a patient is coherent and able to have the discussion. Ideally, the conversation should occur when the patient is best able to understand the information, which might require a follow-up appointment if the patient has just received difficult news or needs a family member present.

Do not initiate this type of discussion after drugs have been administered or when a patient is distraught over a serious diagnosis. That could result in a signed form being declared void for lack of competency at that moment. (It has happened.) Obtaining a signed form at this point opens a physician up to a “he said/she said” argument that can easily be avoided. And while most physicians understand this, it is important to ensure that the team members who assist a physician also understand these guidelines so they do not pressure a patient for a signature after medications have been administered.

If a situation goes to court, a patient might allege that he or she did not understand the conversation or did not have the opportunity to ask questions. While a patient can still make this assertion, a signed form goes a long way with a jury to show that processes were followed. And a jury ultimately decides the issue in a trial situation. If you choose to not use a form and obtain a signature, it is still wise to document the conversation in the medical record. A note made at the time of the discussion bolsters a physician’s account of what transpired. Lawsuits can take years to reach the deposition or trial phase, and if a physician acts as a witness in his or her own defense, citing a written note is more reliable than relying on his or her memory.

Any number of resources can be used in the informed consent process, such as printed patient education materials, websites and videos. Physicians might also use experienced staff to talk with patients and address questions. That team would include a nonphysician provider, nurse, medical assistant or anyone else who a physician believes has the skill and knowledge to discuss treatment options. However, the physician is ultimately responsible for ensuring that the process was properly conducted and that he or she was available to answer any questions. Failure to do so can result in dissatisfied patients, which carries its own ramifications, and it can prompt needless litigation.

See: Weinmeyer R. “Lack of standardized informed consentpractices and medical malpractice.” AMA Journal of Ethics. February 2014;16(2):120-123.

Requirements for Informed Consent

Informed consent is an ethical concept—that all patients should understand and agree to the potential consequences of their care—that has become codified in the law and in daily practice at every medical institution. One of the earliest legal precedents in this area was established in 1914 when a physician removed a tumor from the abdomen of a patient who had consented to only a diagnostic procedure (Schloendorff vs. Society of New YorkHospital). The judge in this case ruled that the physician was liable for battery because he violated an “individual’s fundamental right to decide what is being done with his or her body.” The first case actually defining the elements of informed consent occurred in the late 1950's and involved a question of potential negligence and whether a patient was given sufficient information to make a decision.

The case law and rules pertaining to informed consent have changed over the years and all 50 states now have legislation that requires some level of informed consent. Although the details of these laws vary from state to state, the bottom line is that failure to obtain informed consent renders any U.S. physician liable for negligence or battery and constitutes medical malpractice.

Exceptions are made for emergencies or legally adjudicated mental incompetency or physical incapacity. Several of the common elements required for full disclosure have been summarized by the American Medical Association (Table 1 - below) and other groups representing specialists or quality assurance organizations. For example, federal regulations spell out the minimum requirements for a properly executed informed consent form (Table 2 - below) and state that this form must be in the patient’s chart before surgery. [CFR Title 42] These regulations also stipulate that the information must be given in a language or means of communication that the patient understands. The U.S. government requires interpretation and translation services for individuals with limited English proficiency at institutions that receive federal funding; these regulations also state that informed consent forms must be translated into languages spoken by 5% or 1,000 of a provider’s patients—whichever is less. [Executive Order13166]

The Basic Features of Everyday Informed Consent - [Table 1]
               
The physician (not a delegated representative) should disclose and discuss:
  • The diagnosis, if known
  • The nature and purpose of a proposed treatment or procedure
  • The risks and benefits of proposed treatment or procedures
  • Alternatives (regardless of costs or extent covered by insurance)
  • The risks and benefits of alternatives
  • The risks and benefits of not receiving treatments or undergoing procedures
Source: AMA 1998

What’s Needed on the Informed Consent Form - [Table 2]
  • Name and signature of the patient, or if appropriate, legal representative
  • Name of the hospital
  • Name of procedure(s)
  • Name of all practitioners performing the procedure and individual significant tasks if more than one practitioner
  • Risks
  • Benefits
  • Alternative procedures and treatments and their risks
  • Date and time consent is obtained
  • Statement that procedure was explained to patient or guardian
  • Signature of person witnessing the consent
  • Name and signature of person who explained the procedure to the patient or guardian
Source: Federal Code (Title 42 C.F.R. § 482.51 (b) (2)) Interpretive Guideline A-0392

Which procedures require informed consent? Unfortunately there is no continually updated national list describing exactly when informed consent is required. Again, it varies from state to state and is also influenced by clinician or hospital interpretation of recommendations from professional and specialty groups.

For example:
  • Pennsylvania state law specifically requires that consent be obtained for blood transfusions, chemotherapy, and methadone use as part of a narcotics treatment program. [PA Law Code]
  • Many states have developed specific laws governing breast cancer diagnosis and treatment. [ACS 2007]
  • The American College of Obstetrics and Gynecology has developed detailed guidelines for informed consent issues related to sterilization and carrier testing for cystic fibrosis. [ACOG 2004]
  • Increased levels of institutional quality (e.g., compliance with accreditation standards)
  • Potential time and money savings (or offsets) related to reduced litigation
Thus, based on guidance from staff and counsel, each institution generally develops its own list of surgeries, procedures, or situations where full informed consent is needed. In fact, the Joint Commission (formerly known as the Joint Commission on Accreditation of Healthcare Organizations or JCAHO) has set a standard that hospitals must establish and follow policies that describe which procedures or care, treatment, or services require informed consent. [Joint Commission 2005] One of the first steps recommended is to clarify your institution's policies about when informed consent is required.

Another area subject to local interpretation is exactly how much to disclose. How many potential risks must be described, for example, and how many alternatives must be mentioned? While many states rely on a standard of what a “reasonable physician” would provide or what a “reasonable patient” would need, this still leaves room for interpretation. Most laws describe the need to cover all “material” (i.e., significant) risks. But common sense suggests that not every potential risk can be described in detail and that only the most prevalent and/or serious risks and side effects would be covered. The number and type of complications also may vary widely depending on the severity of the patient’s underlying conditions or comorbidities (e.g., pneumothorax following central vein catheterization may not be life-threatening in a patient admitted for a soft-tissue abscess but could be extremely risky in a patient receiving mechanical ventilation for severe acute respiratory distress syndrome). How can a single form cover both situations? Further complicating the issue, of course, is the fact that there are limitations and variations in the capacity of individual patients to comprehend many of these details—and therefore the information needs to be tailored for each individual.

It is precisely these gray areas in the requirements for informed consent - When is it needed? How much is needed? And how can I make sure the patient understands? - that have opened the door for many of the documented failures of informed consent in everyday practice. (See below: “Informed Consent in Practice”).

One common defensive response to the uncertainties about how much to disclose, for example, is use of “blanket” informed consent forms that contain only boiler-plate generalities that “all potential risks and side effects and alternatives have been explained and understood by the patient.” If such a generic consent form is accompanied by genuine documented education involving appropriate explanation and printed material, this may work. (Attorneys also usually advise clinicians to document the details of this interchange in the patient’s record.)

But on its own, an overly generic consent form without any significant accompanying education, interchange and documentation - that is, a quick request for a signature while the patient is on the gurney - is not adequate. On the other hand, an exhaustive list of all the potential risks may be difficult for patients to understand. (Attorneys reviewing such a list would also likely point out that any omission from such a long and seemingly comprehensive list might be a red flag, and that such a form would therefore need to state that the list is not inclusive. [AMA 1998])

Informed Consent in Practice
  • How often does informed consent work as intended?
  • How do your practices match up to the national norms for informed consent?
  • How does one even begin to measure the “success” of informed consent?
These are complex questions that have been tackled by clinicians and researchers from different settings and perspectives. Many studies have focused on one therapeutic area of interest. Others have analyzed the consent process only in the research setting. And some have evaluated the process in targeted patient groups such as those with low literacy.
Reviewing the results from such studies provides a sense of the problems that must still be overcome in planning for and delivering informed consent in everyday clinical practice. While much of this data comes out of the clinical research setting, many of the broader “lessons learned” in these studies are highly applicable to the setting of everyday informed consent.

Best Practices



Developing an Informed Consent Form

Download this Style Guide template for improving you Informed Consent Form(s).

In summary and based on all of this information, two points stand out:
  1. Patients have a fundamental right and need to receive information, both orally and written, about their care in a manner they can fully comprehend and that will lead to truly shared decision-making, and 
  2. current practices of informed consent are often inadequate and are especially hampered by growing rates of health illiteracy in the U.S. 
A number of studies indicate that improving consent forms and the overall consent process can lead to better patient comprehension and recall. Although the research on improved consent forms has been mixed, some studies have found that when consent forms are improved, patients are more likely to read and understand them before signing. Using a consistent informed consent template as a starting point for the creation of forms for various procedures also appears to improve consistency and quality in the forms. Providing clear and simple information about procedures may also lower patient anxiety levels and increase understanding and recall in a way that produces a more deliberative decision-making process.

However, a clearly written consent form does not guarantee that patients will read and understand them. A properly constructed and clearly formatted consent form is a necessary but not sufficient condition for ensuring that patients read, understand, and remember the information presented. Thus, a variety of other methods are needed to increase patient involvement in the consent process and improve patient comprehension of the information presented. For example, several recent studies show that repeating information to patients in various formats and modes and at different times can strengthen comprehension and recall.





To subscribe to this blog, enter your email address:


Delivered by FeedBurner