Ch. 8 - Medical Privacy Flashcards
Reasons for medical data privacy
- Inner workings of one’s body, is highly sensitive and personal
- Patients more open about their condition if privacy respected.
- Protect employees from unequal treatment.
- Protect health insurance consumers from discrimination.
Confidentiality of Substance Use Disorder Patient Records Rule: Scope
- Covers disclosure and use of PI by treatment programs for alcohol and substance abuse.
- Covers PI that could identify one diagnosed with or undergone treatment for.
- Also covers any info - written or verbal - that could lead/substantiate criminal charges.
Confidentiality of Substance Use Disorder Patient Records Rule: Applicability
- Any program that receives federal funding.
- Program means:
1. provider of alc/sub abuse diagnosis, treatment, referral
2. unit within med facility doing same.
3. staff whose primary function is provision of same.
4. required by state licensing agency to comply
5. clinician uses contr sub for detox and must be DEA licensed.
-
Confidentiality of Substance Use Disorder Patient Records Rule: Disclosure and Re-disclosure
- Program must obtain written consent before disclosing info subject to Rule.
- Can include general consent to those with provider relationship with patient.
- No redisclosure if would identify one as having been diagnosed, treated, or referred.
Confidentiality of Substance Use Disorder Patient Records Rule: Exceptions to Consent
- Medical emergencies
- Scientific research
- Audits and evaluations
- Communications with a qualified service organization (QSO) related to information needed by the organization to provide services to the program
- Crimes on program premises or against program personnel
- Child abuse reporting
- Court order
Confidentiality of Substance Use Disorder Patient Records Rule: Security and Enforcement
- Program and entity disclose to lawfully must have formal policies/procs to protect security.
Violations of Rule are criminal. first violation a finde not more than 500, each subsequent not more than 5k.
Confidentiality of Substance Use Disorder Patient Records Rule: Convergence and Pre-emption
- Not pre-empt.
- Like HIPAA and is lots of overlap, but not completely.
HIPAA: PHI Definition
Protected health information (PHI) is defined as any individually identifiable health information that: is transmitted or maintained in any form or medium; is held by a covered entity or its business associate; identifies the individual or offers a reasonable basis for identification; is created or received by a covered entity or an employer; and relates to a past, present or future physical or mental condition, provision of health care or payment for health care to that individual.30
HIPAA: Covered entities
- Directly covered by HIPAA.
- Covers 3 types of entities:
- Healthcare providers (e.g., a doctors’ offices, hospitals) that conduct certain transactions in electronic form (if not bill for insurance, not covered)
- Health plans (e.g., health insurers)
- Healthcare clearinghouses (e.g., third-party organizations that host, handle or process medical information)
HIPAA: Business associates covered
- Business associate = any person or organization, other than a member of a covered entity’s workforce, that performs services and activities for, or on behalf of, a covered entity, if such services or activities involve the use or disclosure of PHI.
- Privacy Rule and Security Rule apply directly to BAs, thanks to HITECH
HIPAA Privacy Rule: Authorizations for uses and disclosures
- Authorizes use and disclosure of PHI for essential healthcare purposes. Others require opt-in authorization.
- Authorization must
1. be independent document
2. specific identifies into to be disclosed, purpose, person to which disclosed. - Can’t require consent to provide treatment.
- Rules for opt-in marketing and strict rules for psychotherapy notes.
HIPAA Privacy Rule: Minimum necessary use or disclosure
- other than for treatment, covered entities must make reasonable efforts to limit the use and disclosure of PHI to the min necessary to accomplish intended purpose.
HIPAA Privacy Rule: Access and accounting of disclosures
- Have right to access and copy their PHI from CE or BA kept in a “designated record set” i.e. med and billing records, or other records used (by CE) to make decisions.
- Right to an accounting of certain disclosures by CE.
- Right to amend PHI held by CE.
HIPAA Privacy Rule: Safeguards
- Privacy rule requires implement admin, physical, tech measures.
- Security Rule covers only PHI
HIPAA Privacy Rule: Accountability
- CEs must designate a privacy official.
- Personnel must be trained
- procedures must be in place.
HIPAA Privacy Rule: Enforcement
- Primary enforcer is OCR at HHS. Process complaints, can assess civil fines up to $1.6M per year per type of violation.
- OCR regularly audits select CEs
- DOJ has criminal enforcement - up to 10 years in prison.
- FTC can bring unfair and deceptive even if covered by HIPAA.
- State AGs for state privacy laws.
Limits/Exceptions on Privacy Rule
- No consent required for treatment, payment and healthcare operations.
- Also, de-id is exempted from PR. 2 methods (expert and removal of specific elements).
- Also exempted is research - no consent necessary if IRB approves as consistent with PR and human subjects rules.
- Other exceptions:
Secy of HHS for compliance
information used for public health activities;
to report victims of abuse, neglect or domestic violence;
in judicial and administrative proceedings;
for certain law enforcement activities;
for certain specialized governmental functions
HIPAA Security Rule: Basics and Goal
- Admin, tech, physical measures for protecting ePHI in a tech neutral manner.
- Goal is for CEs to implement policies/procs to prevent, detect, contain, and correct security violations.
HIPAA Security Rule: Addressable vs. Required, for CEs
- Rule has standards and implementation specifications.
- Some impl. specs are required, others “addressable” meaning have to determine if appropriate. if so, must adopt and if not, must say why not reasonable and if appropriate, adopt an alternative measure.
HIPAA Security Rule: Requirements for CE and BA
Requirements:
- Ensure the confidentiality, integrity and availability of all ePHI the covered entity creates, receives, maintains or transmits
- Protect against any reasonably anticipated threats or hazards to the security or integrity of the ePHI
- Protect against any reasonably anticipated uses or disclosures of such information that are not permitted or required under the Privacy Rule
- Ensure compliance with the Security Rule by its workforce
HIPAA Security Rule: Factors must take not consideration
CEs and BAs take factors into consideration:
- The size, complexity and capabilities of the covered entity
- The covered entity’s technical infrastructure, hardware and software security capabilities
- The costs of security measures
- The probability and criticality of potential risks to electronic protected health information
HIPAA Security Rule: Misc requirements for CEs
- identify responsible official
- conduct ongoing risk assessments.
- implement security awareness and training program, and discipline failure to comply.
GINA: Health insurance restrictions
- prohibits health insurance companies from discriminating on the basis of genetic predispositions in the absence of manifest symptoms,
- prohibits health insurance companies from requesting that applicants receive genetic testing
-
GINA: Employer restrictions
Prohibits employers from
- using genetic information in making employment decisions, in absence of manifestation.
- discrim against individuals who have family members who has manifested a disease
- requiring or requesting or purchasing genetic info about employees or family members unless an express exception applies
GINA: Group Health Plan restrictions
Per ERISA amendments, prohibits group health plan providers from –
- adjusting premiums or other contribs on basis of genetic info, absent manifestation of disease/disorder.
- requesting or requiring genetic testing in connection with offering of group health plans (except voluntary research).
- enforcement - penalty of $100 each day of noncompliance per person - can rise to $15k in some circs.
GINA - Individual health plan market
Per amendments to Public Health Service Act, prohibits insurers in indiv. market from
- adjustment of premiums/contribs on basis of genetic info absent manifestation.
- using genetic predisposition to find excludable pre-existing condition.
Also note amendments to Social Security Act extend these protections to providers of Medicare supplemental insurance policies.
GINA - Exceptions to prohibition on employers from requiring, requesting, purchasing genetic info about employees or their family members
(1) such a request is inadvertent,
(2) the request is part of an employer-offered wellness program that the employee voluntarily participates in with written authorization,
(3) the request is made to comply with the Family and Medical Leave Act of 1993,
(4) an employer purchases commercially and publicly available materials that include the information,
(5) the information is used for legally required genetic monitoring for toxin exposure in the workplace if the employee voluntarily participates with written authorization or
(6) the employer conducts DNA analysis for law enforcement purposes and requests the information for quality-control purposes (i.e., to identify contamination).