Chapter 7 Flashcards
Reasons for medical data privacy
- Inner workings of one’s body, is highly sensitive and personal
- Patients more open about their condition if privacy respected.
- Protect employees from unequal treatment.
- Protect health insurance consumers from discrimination.
Confidentiality of Substance Use Disorder Patient Records Rule: Scope
- Covers disclosure and use of PI by treatment programs for alcohol and substance abuse.
- Covers PI that could identify one diagnosed with or undergone treatment for.
- Also covers any info - written or verbal - that could lead/substantiate criminal charges.
Confidentiality of Substance Use Disorder Patient Records Rule: Applicability
- Any program that receives federal funding.
- Program means:
1. provider of alc/sub abuse diagnosis, treatment, referral
2. unit within med facility doing same.
3. staff whose primary function is provision of same.
4. required by state licensing agency to comply
5. clinician uses contr sub for detox and must be DEA licensed.
-
Confidentiality of Substance Use Disorder Patient Records Rule: Disclosure and Re-disclosure
- Program must obtain written consent before disclosing info subject to Rule.
- Can include general consent to those with provider relationship with patient.
- No redisclosure if would identify one as having been diagnosed, treated, or referred.
Confidentiality of Substance Use Disorder Patient Records Rule: Exceptions to Consent
- Medical emergencies
- Scientific research
- Audits and evaluations
- Communications with a qualified service organization (QSO) related to information needed by the organization to provide services to the program
- Crimes on program premises or against program personnel
- Child abuse reporting
- Court order
Confidentiality of Substance Use Disorder Patient Records Rule: Security and Enforcement
- Program and entity disclose to lawfully must have formal policies/procs to protect security.
Violations of Rule are criminal. first violation a finde not more than 500, each subsequent not more than 5k.
Confidentiality of Substance Use Disorder Patient Records Rule: Convergence and Pre-emption
- Not pre-empt.
- Like HIPAA and is lots of overlap, but not completely.
HIPAA: PHI Definition
Protected health information (PHI) is defined as any individually identifiable health information that: is transmitted or maintained in any form or medium; is held by a covered entity or its business associate; identifies the individual or offers a reasonable basis for identification; is created or received by a covered entity or an employer; and relates to a past, present or future physical or mental condition, provision of health care or payment for health care to that individual.30
HIPAA: Covered entities
- Directly covered by HIPAA.
- Covers 3 types of entities:
- Healthcare providers (e.g., a doctors’ offices, hospitals) that conduct certain transactions in electronic form (if not bill for insurance, not covered)
- Health plans (e.g., health insurers)
- Healthcare clearinghouses (e.g., third-party organizations that host, handle or process medical information)
HIPAA: Business associates covered
- Business associate = any person or organization, other than a member of a covered entity’s workforce, that performs services and activities for, or on behalf of, a covered entity, if such services or activities involve the use or disclosure of PHI.
- Privacy Rule and Security Rule apply directly to BAs, thanks to HITECH
HIPAA Privacy Rule: Authorizations for uses and disclosures
- Authorizes use and disclosure of PHI for essential healthcare purposes. Others require opt-in authorization.
- Authorization must
1. be independent document
2. specific identifies into to be disclosed, purpose, person to which disclosed. - Can’t require consent to provide treatment.
- Rules for opt-in marketing and strict rules for psychotherapy notes.
HIPAA Privacy Rule: Minimum necessary use or disclosure
- other than for treatment, covered entities must make reasonable efforts to limit the use and disclosure of PHI to the min necessary to accomplish intended purpose.
HIPAA Privacy Rule: Access and accounting of disclosures
- Have right to access and copy their PHI from CE or BA kept in a “designated record set” i.e. med and billing records, or other records used (by CE) to make decisions.
- Right to an accounting of certain disclosures by CE.
- Right to amend PHI held by CE.
HIPAA Privacy Rule: Safeguards
- Privacy rule requires implement admin, physical, tech measures.
- Security Rule covers only PHI
HIPAA Privacy Rule: Accountability
- CEs must designate a privacy official.
- Personnel must be trained
- procedures must be in place.