HIPAA Flashcards
Covered Entities
(1) health plans
(2) health care clearinghouses
(3) health care providers who electronically transmit any health information in connection with transactions for which HHS has adopted standards (i.e. Doctors, Clinics, Psychologists, Dentists, Chiropractors, Nursing Homes, Pharmacies)
Business Associates
A “business associate” is a person or entity that performs certain functions or activities that involve the use or disclosure of protected health information on behalf of, or provides services to, a covered entity.
PHI (protected health information)
Protected health information is information, including demographic information, which relates to:
- the individual’s past, present, or future physical or mental health or condition,
- the provision of health care to the individual, or
- the past, present, or future payment for the provision of health care to the individual, and that identifies the individual or for which there is a reasonable basis to believe can be used to identify the individual. Protected health information includes many common identifiers (e.g., name, address, birth date, Social Security Number) when they can be associated with the health information listed above.
De-identification and its Rationale
The process of removing identifiers from health information.
Lowers privacy risks for individuals and supports the secondary use of data for comparative effectiveness studies, policy assessment, life sciences research, and other endeavors. (see more: https://www.hhs.gov/hipaa/for-professionals/privacy/special-topics/de-identification/index.html)
If a CSP (cloud service provider) stores only encrypted ePHI and does not have a decryption key, is it a HIPAA business associate?
HHS says yes, because the CSP receives and maintains ePHI for a covered entity or another business associate.
What is required for FP to be HIPAA compliant?
- Downstream BAAs with all vendors where customer data touches or might touch
- Locked down cloud infrastructure
- Access logs kept forever
- All employees trained on HIPAA compliance
What makes something PHI vs just health data? Why is health data in Strava not considered PHI, but health data in Modern Health is considered PHI?
There’s no covered entity with Strava, or other consumer health apps. Modern Health is a covered entity. (might need more information on this)
How does de-identification work? How is this different from encrypting PHI?
There are no restrictions on the use or disclosure of de-identified health information. De-identified health information neither identifies nor provides a reasonable basis to identify an individual.
There are two ways to de-identify information; either: (1) a formal determination by a qualified statistician; or (2) the removal of specified identifiers of the individual and of the individual’s relatives, household members, and employers is required, and is adequate only if the covered entity has no actual knowledge that the remaining information could be used to identify the individual.
Encrypted data can still be identified, it just requires a private key to do so
What are the HIPAA Compliant Tools?
- Amplitude
- Mixpanel
- Heap
- Pendo
- Tealium
How much does Amplitude cost to get a BAA signed?
Minimum 60-75k / year
What tools AREN’T HIPAA Compliant?
Segment & Rudderstack
What makes something PHI vs just health data? Why is health data in Strava not considered PHI, but health data in Modern Health is considered PHI?
Health data that is not shared with a covered entity or is personally identifiable doesn’t count as PHI. For example, heart rate readings or blood sugar level readings without PII.
Because Strava isn’t a covered entity & consumers are choosing to collect the information for their own use, it is not PHI
How do you determine if a company needs to be HIPAA compliant?
Does it fall under a covered entity?
- Health plan
- Health care provider
- Health care clearing house
How do you determine if the company is violating HIPAA?
Use Segment Event Tracker (Chrome Extension)
What is considered PHI? What is not considered PHI?
https://mobisoftinfotech.com/resources/blog/what-is-phi-and-what-is-not-phi/