HIPPA



WHAT HEALTH INFORMATION IS PROTECTED?

HIPAA created two new phrases to describe information protected by the legislation. The medical record is now referred to as protected health information (PHI). This includes all information that is created by any covered entity. All forms of the information are part of protected health information, i.e., paper, electronic, video tapes, photos, audiotapes, and any information that has been duplicated, discussed, read from a computer screen, or shared over the internet.

The other new HIPAA phrase is individually identifiable health information (IIHI). Included in this category is any information that could reasonably be linked to a specific patient, such as a photo, name, address, date of birth, next of kin or responsible relative, medical record identifier, social security number, driver’s license number, health beneficiary, account number, employer, finger, or voice prints.

The law specifies that some information that is not individually identifiable can remain. Age that is reported as 60+ if the patient is older than 60, zip code if the patient lives within a zip code with greater than 20,000 people in it, race, gender, ethnicity, marital status, and the year only of the health care occurrence are not considered individually identifiable information and these data may be used in the aggregate.

All facilities must limit access to information only to those who have a need to know. A nurse who seeks information about a patient not under her care is violating the HIPAA rules. Similarly, health information can only be used for health purposes. Employers cannot use the information to screen candidates for hire or promotion. Financial institutions may not use it to determine lending practice. Only the patient can explicitly authorize employers, banks, and individuals to have access to his/her medical information.

HIPAA also established the “minimum necessary rule” which stipulates that only the minimum necessary information may be shared, even with the patient authorization. A classic example would involve treatment for a case of child or domestic abuse; the provider would, rather than providing an entire medical record, furnish the pertinent data furnished in the form of an abstract outlining the information that is necessary to provide treatment and protect the victim(s). The abstracted information could be provided to legal and law enforcement entities. Health providers involved in the treatment of patients are not subject to the minimum necessary rule and can have full access to all information that is needed to provide patient care. Health information that has implications for the public health and safety can be shared without consent. There are several situations where medical information can be shared:  In Emergency 911 situations, when communicable diseases are involved, when law enforcement agencies participate, or if national defense or security is a factor.

The public health department is deemed a legitimate recipient of certain personal health information and providers may, in fact in some instances, must report some findings to the proper public health agency. Included are: 

  1. cause of death even when the patient dies at home

  2. reportable communicable diseases

  3. child abuse

  4. reporting an adverse drug reaction to the Federal Drug Administration

  5. occurrence of cancer in a state with a cancer registry

  6. meningitis, and 

  7. immunizations for children. 

These examples are thought to be important to the health of the public (Campos-Outcalt 2004).

PATIENT CONSENT AND AUTHORIZATION

HIPAA makes a distinction between informed consent and patient authorization. Patients are entitled to know exactly how an entity plans to use the information.

Informed consent is signed at the first encounter the patient has with the provider/health care facility; the consent covers treatment, payment, and other health care information. The meaning and use of the patient’s consent must be carefully explained to the patient. Facilities must explicate their disclosure process in a document called Information Practices. The American Hospital Association published a sample consent and explanation document that was 10 pages long. The document explains patient rights, as well as a description of how patient information is collected and used. Facilities must decide how and when the information concerning consent is presented to patients and how patients can use their right to revoke consent. Patients must also be advised about the agency’s policy that covers conditions for admission that are related to consent.

Patients may also sign authorizations. These are required when information is used by the agency for purposes outside of treatment. Agencies must assess their policies and procedures to assure that they are always using an authorization when it is needed; some agencies may not realize that information sharing policies violate the patient’s right to restrict release of data (Cichon, 2002). Patients must be fully informed about the way agencies use a signed authorization and are entitled to receive a free accounting every twelve months describing how their health information has been used.

HIPAA privacy regulations also mandate specific patient rights that include the following:

  1. Right to privacy notice requires disclosure and reasonable effort to assure that the patient understands the agency’s policy concerning privacy of information.

  2. Right to request restrictions means that patients may specify health information that cannot be released and/or, they may restrict to whom information can be released.

  3. Right to access of PHI means that patients must be allowed to inspect and copy information contained in the agency’s record.

  4. Right to know what disclosures have been made means the agency must track all information released and be able to provide documentation to the patient.

  5. Right to amend the PHI means that while patients may request amendments to the PHI and the agency must allow amendments, the agency may deny some requests.

All covered entities are required to comply with certain procedural rules. Most have had to develop new policies and procedures to address the many aspects covered under these rules. The following are some of the rules:

  1. Agencies must appoint a privacy officer who will monitor and audit compliance.

  2. Agencies must develop an internal compliance process that will assure no patient rights are violated, complaints are addressed and investigated, and that a process for remediation is in place.

  3. Training must be provided to employees to assure that they are informed about patient rights and disclosure of information.

  4. HIPAA requires that agencies document any and all violations and that sanctions parallel other disciplinary policies.

  5. Agencies must have a process for mitigating any harmful effect of disclosure.

  6. All forms of communication must be addressed in administrative safeguards.

  7. Agencies must agree and have policies that specify no retaliation for an employee or consumer who files a complaint.

Prev
Next