Showing posts with label Privacy Rule. Show all posts
Showing posts with label Privacy Rule. Show all posts

Tuesday, January 17, 2017

OCR Updates HIPAA Guidance on Sharing Information with Patients’ Loved Ones, Family and Friends

Clarification For Sharing Patient Information
A January 10, 2017 Issuance from Heath and Human Services' (HHS) Office if Civil Rights (OCR) updating new privacy guidance is aimed at clarifying that the HIPAA Privacy Rule does permit disclosures of health information to a patient's loved ones regardless of whether they are recognized as relatives under applicable law. This guidance for healthcare professionals is to help clear up confusion about allowable disclosures of protected health information to spouses, relatives, and patients’ loved ones.

The majority of healthcare professionals are aware that the HIPAA Privacy Rule permits them, within the exercise of their own professional judgement, to share the protected health information of a patient with a relative or loved one or if it is in the patient's best interest. However, the 2016 Orlando nightclub shooting incident revealed that many healthcare professionals are unsure about how the HIPAA Privacy Rule – 45 CFR164.510(b) – applies to same sex couples.

OCR has confirmed that the Privacy Rule permits a covered entity to “share PHI with an individual’s family member, other relative, close personal friend, or any other person identified by the individual, the information directly relevant to the involvement of that person in the patient’s care or payment for health care.” OCR has also confirmed that covered entities are allowed to disclose relevant information “to notify, or assist in the notification of (including by helping to identify or locate), such a person of the patient’s location, general condition, or death.”
The recipient can be a “patient’s family member, relative, guardian, caregiver, friend, spouse, or partner,” but also any other individual that is a nominated personal representative of the patient. A personal representative of a patient must, as far as the Privacy Rule is concerned, be treated as the individual for purposes such as exercising the patient’s Privacy Rule rights, including providing access to their health information. There are limited exceptions, which are detailed in 45 CFR164.502(g).

OCR has confirmed that covered entities are permitted to share a patient’s PHI with same-sex partners, and explains that the list of potential recipients of PHI is in no way affected by an individual patient’s sex or gender identity, and neither by the sex or gender of the potential recipient.

OCR also sought to confirm who can be classed as a personal representative of the patient, saying “the Privacy Rule generally looks to state laws governing which persons have authority to act on behalf of an individual in making decisions related to health care.”

For example, if a state grants legally married spouses health care decision making authority for each other, a covered entity would be in violation of the Privacy Rule if access to the patient’s information was not granted if requested by a spouse, regardless of the sex of that individual.

While the covered entity should seek permission from the patient concerned prior to sharing information, in cases when the patient is incapacitated or not available, covered entities should use their professional judgement if the sharing of information is in the patient’s best interest. Should a patient be deceased, information can be shared with a person who has been involved in the patient’s care or who has made payment for medical services prior to the patient’s death.

The new OCR privacy rule guidance, issued in a frequently asked questions format, was developed in large part to address confusion following the 2016 Orlando nightclub shooting about whether and when hospitals may share protected health information with patients' loved ones, OCR says in a statement. "In particular, the FAQ makes clear that the potential recipients of information under the relevant permissive disclosure provisions ... are not limited by the sex or gender identity of the person," OCR says.

On that same topic, OCR also issued updated guidance "that makes clear that the terms 'marriage, spouse and family member' include, respectively, all lawful marriages - whether same-sex or opposite-sex) - lawfully married spouses and the dependents of all lawful marriages, and clarifies certain rights of individuals under the Privacy Rule."

Heathcare Compliance Solutions Inc. recommends consulting with your practice or organization's attorney and/or your state medical association/board to verify your state's legislation regarding the definitions and legal ramifications of terms relating to this regulation such as: "Personal Representative", "Lawful Marriage", "Family Member", etc..

 HCSI



To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Wednesday, August 24, 2016

Discussion Point: Patients Making Recordings In Healthcare Settings

Policies Restricting Patient Recordings In Medical Settings

What are your opinions on a medical office or practice creating a policy to prevent/limit patients from making audio/video recordings in exam rooms or other common areas where HIPAA or patient privacy could be violated by improper use of these recordings?


Does the office or practice have free reign to create such a policy?  What if any limitations might apply?

What about the patient?  Do they have any "rights" providing them the freedom to be able to record a procedure or practitioner giving treatment instructions for example? 

What about recordings in a maternity ward/nursery or during child birth?  What about the potential for cell phones to disrupt sensitive medical equipment?  What about patient's using apps like Pokemon Go and inadvertently or covertly overhearing and recording sensitive patient information?
What HIPAA regulations or legal ramifications might be evoked by such a situation?  How does an office notify patients of and enforce such a policy?  Should the office require patients to sign an acknowledgement of said policy or is a posted sign or notice adequate?

I would love to hear all your thoughts on this topic and any addition related issues that might come up that I have not already listed in the situations above. 

 HCSI
To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Wednesday, October 14, 2015

HIPAA Related Record Retention

Many offices have asked this very question, so we are here to clarify this issue.

Q: How long must we retain the list of authorized and unauthorized disclosures pertaining to our nursing home residents? We assume that we must retain these lists while residents remain here, but how long must we retain this information after death or discharge?


A:  The HIPAA Privacy Rule generally requires covered entities to retain documentation for 6 years to demonstrate their compliance with the rule. You may dispose of documentation after that time.


Although each state regulates the record retention period for patient medical records, HIPAA related documentation must be retained for 6 years.


For more information on this and other topics related to HR, HIPAA, OSHA, and Medicare, please emailsupport@hcsiinc.com or visit our website at http://www.hcsiinc.com


Be sure to become a member of our Linkedin group by visiting; http://bit.ly/1FWmtq6

Tuesday, June 23, 2015

Disclosing PHI to Law Enforcement

Disclosures to Law Enforcement
A law enforcement officer may come into your office and request that you give him information on one of your patients.  He may have some legal documents with him to prove his request is valid, or he may just want to know if the patient is on the premises. What do you do?  It can be confusing if you do not know the HIPAA Privacy Rule governing releasing PHI to law enforcement. Following are the basic guidelines your staff should know.
The Privacy Rule established procedures and safeguards to restrict the circumstances under which you may give such information to law enforcement officers.  If the law enforcement officer does not have a warrant and has not made any prior process, you are limited in the information you may disclose.  The Privacy Rule specifically prohibits disclosure of DNA.  Similarly, under most circumstances, the Privacy Rule requires you to obtain permission from persons who have been the victim of domestic violence or abuse before disclosing information about them to law enforcement.  Some other federal or state law may require a disclosure, and the Privacy Rule does not interfere with the operation of these other laws.  However, if the disclosure is required by some other law, HHS has said that you should use your professional judgment to decide whether to disclose information, reflecting your own policies and ethical principles.  In other words, HHS is allowing healthcare providers to continue to follow their own policies to protect privacy in such instances. 
Disclosures Allowed Without an Authorization
The Privacy Rule is balanced to protect an individual’s privacy while allowing important law enforcement functions to continue.  The Rule permits covered entities to disclose protected health information (PHI) to law enforcement officials, without the individual’s written authorization, under specific circumstances summarized below:
  • Court-Ordered Warrant or Subpoena
  • To comply with a court order or court-ordered warrant, a subpoena, or summons issued by a judicial officer or a grand jury subpoena – The Rule recognizes that the legal process in obtaining a court order and the secrecy of the grand jury process provides protections for the individual’s private information.
  • Administrative Request or Subpoena
  • To respond to an administrative request such as an administrative subpoena or investigative demand or other written request from a law enforcement official – Because an administrative request may be made without judicial involvement, the Rule requires all administrative requests to include or be accompanied by a written statement that the information requested is relevant and material, specific and limited in scope, and de-identified information cannot be used.
  • Applicable Law and Ethical Standard
  • To a law enforcement official reasonably able to prevent or lessen a serious and imminent threat to the health or safety of an individual or the public; or to identify or apprehend an individual who appears to have escaped from lawful custody.
  • Averting a Serious Threat to Health and Safety
  • If you believe that your practice, a workforce member, a patient, or the public is in danger of a threat to health and safety, your disclosure of PHI for that purpose is protected under HIPAA.  You may, consistent with law and ethical conduct, use or disclose PHI if you believe in good faith that:
  • It is necessary to prevent or lessen a serious and imminent threat to the health or safety of a person or the public;
And
  • It is reported to a person or persons reasonably able to prevent or lessen the threat, including the target of the threat
Or
  • It is necessary for law enforcement authorities to identify and apprehend an individual:
  •  
  • Because of a statement by an individual admitting participation in a violent crime that you reasonably believe may have caused serious physical harm to the victim;
Or
  • Where it appears from all the circumstances that the individual has escaped from a correctional institution or from lawful custody. 
Identifying an Individual
To respond to a request for PHI for purposes of identifying or locating a suspect, fugitive, material witness or missing person; but you must limit disclosures of PHI to name and address, date and place of birth, social security number, ABO blood type and rh factor, type of injury, date and time of treatment, date and time of death, and a description of distinguishing physical characteristics.  Other information related to the individual’s DNA, dental records, body fluid or tissue typing, samples, or analysis cannot be disclosed under this provision, but may be disclosed in response to a court order, warrant, or written administrative request.
This same limited information may be reported to law enforcement:
  • About a suspected perpetrator of a crime when the report is made by the victim who is a member of your workforce;
  • To identify or apprehend an individual who has admitted participation in a violent crime that you reasonably believe may have caused serious physical harm to a victim, provided that the admission was not made in the course of or based on the individual’s request for therapy, counseling, or treatment related to the propensity to commit this type of violent act. 
Victim of a Crime
To respond to a request for PHI about a victim of a crime, and the victim agrees – If, because of an emergency or the person ‘s incapacity, the individual cannot agree, you may disclose the PHI if law enforcement officials represent that the PHI is not intended to be used against the victim, is needed to determine whether another person broke the law, the investigation would be materially and adversely affected by waiting until the victim could agree, and you believe in your professional judgment that doing so is in the best interests of the individual whose information is requested.