Privacy & HIPAA Flashcards
Clinician Duty to Warn of Foreseeable Harm (Tarasoff)
(1) Explicit threat of imminent serious physical harm or death
(2) To an identifiable person
(3) Patient has apparent intent & ability to carry out threat
Permitted Disclosures of Protected
Health Information
- To patient
- For treatment, payment, or health care operations
- To investigate HIPAA complaints
- As otherwise required by law (e.g. law
enforcement, public health activities)
Otherwise: Need patient authorization
Confidentiality:
Professional secrecy. Assurance
that information re: subject’s identity, health, behavior, etc. won’t be disclosed
w/o her permission.
Privacy:
Being free from being observed or
disturbed by others. Ability to control access to self or one’s info.
Data security:
Technical mechanisms to prevent
data breaches (e.g. encryption).
Doe v. Medlantic:
Unconsented, unprivileged
disclosure to 3rd party of nonpublic info that D learned w/i confidential relationship.
HIPAA Privacy Rule includes what groups?
- Health Plans
- Health Care Clearinghouses
- Health Care providers
- Business Associations
- Employers
Protected Health Information
Individually identifiable health information that is:
- Transmitted by electronic media
- Maintained in electronic media
- Transmitted or maintained in any other form (e.g. paper)
Permitted disclosures of protected
health information
-To patient
-For treatment, payment, or health care
operations
-To investigate HIPAA complaints
-As otherwise required by law (e.g. law
enforcement, public health activities)
-Otherwise need patient authorization
Reproductive Privacy Rule
-Prohibits the use or disclosure of individually identifiable health information to law enforcement when purpose of investigation is to impose liability
on patients or physicians.
-Applies only when care was legal
-Explicitly protects privacy of people who travel from abortion-restrictive state to state w/ legal abortion
Patient Rights
- Inspect PHI & obtain copies
- Request amendments
Other HIPAA Issues/Requirements
- Notice requirement
- Breach notification
- Civil and criminal penalties but no private cause of action (only HHS can enforce and impose these)
–> if you want to sue, you’d have to sue under a breach of confidentiality theory. - State law can impose more stringent
requirements than HIPAA - HIPAA Security Rule (Technical, administrative & physical
safeguards)