HIPPA
PRACTICAL IMPLICATIONS

Questions about the implications HIPAA rules have been numerous. Can an office or laboratory have a patient sign in sheet? Can you use a patient’s name to call him into a treatment room? Can the patient’s name be posted outside the hospital door? At this point, there is some agreement about some of these. As long as personal information regarding the patient’s care or procedures to be done remain confidential, names can be outside hospital room doors, patients can be verbally called to treatment rooms, etc. New questions will undoubtedly arise in the future. Staying informed about the rules and regulations concerning HIPAA will be every health care worker’s obligation.

Sign-in sheets, once disallowed, can now be used along with bedside charts as long as reasonable precautions are taken to safeguard patient information. Sign in sheets can only have the name and time; no information about the nature of the appointment can be included. The patient can give consent or may decline to have information given to family members; facility staff is not obligated to verify the identity of relatives.

HIPAA retains the rights of parents as the personal representative for minor children. There are exceptions, however. Parents may decide that the child and provider have a confidential relationship that excludes the parent from receiving information. A provider may choose to exclude the parent when abuse is suspected or when including the parent would endanger the child.

Patients have the right to restrict clergy visits and religious information. If the patient does want the clergy to visit, health care individuals should provide only the name and location of the patient. They should not provide any information about the patient’s medical condition. Further, patients have the right to restrict informing callers or visitors that they are in the hospital. Most patients are asked on admission to the facility if they want such restrictions and, if they do, hospital workers may not acknowledge that a patient is in the hospital even including visitors, florists delivering flowers, etc.

Some information can be provided to law enforcement without patient consent. Emergency technicians can contact the police at a crime scene and convey nature and location of the crime. Information about a suspicious death may also be reported to the police. HIPAA has a one call rule that permits contacting an organ procurement agency following a death.

Repositories that store human tissue and fluids for future scientific analysis, i.e., genotyping, cell lines, other biotechnologies, express concern that HIPAA will fundamentally change how these commercial repositories function. At question is whether property rights continue to apply to human tissue after removal from the body. Prior to HIPAA, the Supreme Court in California ruled on the side of future research and determined that property rights end when tissue is removed from the body (Allen 2004). However, depending on how HIPAA rules are interpreted, informed consent may be required in order for research to be conducted on removed tissue.

HIPAA AND RESEARCH

Patients must sign an authorization to allow their information to be included in research projects. Information can only be disclosed in accordance with a research protocol approved by an institutional review board. All identifying individual information must be removed. One difficulty researchers may experience is the lack of specific guidance from HIPAA regarding construction of compliant, de-identified data sets, at this point researchers are developing strategies that they believe comply with the intent of privacy under HIPAA. Ongoing analysis of medical information is critical for developing strategies to improve patient outcomes and reduce medical errors (Clause, S.L.; Triller, D.M.; Bornhorst, C.P.; Hamilton, R.A.; Cosler, L.E. 2004). Information that can be used in compliance with HIPAA includes: gender, race, ethnicity marital status, dates of treatment if reported in years, age (for individuals older than 60, one must use 60+), and zip code if more than 20,000 reside in that zip code (Erlen, J.A. 2004)

CONCLUSION

HIPAA regulations require new behavior from health care professional and health care facilities. Close coordination with other partners in health care delivery and reimbursement is mandatory to assure a continuous process of patient privacy.

Restrictions and the ability to amend IIHI give patients new control over their health information. Health care professionals may be challenged. Involving patients as active participants in their care will dispel and avoid potential problems.

Administrators are advised to be sure staff is well-trained and knowledgeable about the requirements of HIPAA. Similarly, they many want to scrutinize day- to-day practices to evaluate whether violations of patient rights are occurring.

PATIENT CONSENT AND AUTHORIZATION

HIPAA makes a distinction between informed consent and patient authorization. Patients are entitled to know exactly how an entity plans to use the information.

Informed consent is signed at the first encounter the patient has with the provider/health care facility; the consent covers treatment, payment, and other health care information. The meaning and use of the patient’s consent must be carefully explained to the patient. Facilities must explicate their disclosure process in a document called Information Practices. The American Hospital Association published a sample consent and explanation document that was 10 pages long. The document explains patient rights, as well as a description of how patient information is collected and used. Facilities must decide how and when the information concerning consent is presented to patients and how patients can use their right to revoke consent. Patients must also be advised about the agency’s policy that covers conditions for admission that are related to consent.

Patients may also sign authorizations. These are required when information is used by the agency for purposes outside of treatment. Agencies must assess their policies and procedures to assure that they are always using an authorization when it is needed; some agencies may not realize that information sharing policies violate the patient’s right to restrict release of data (Cichon, 2002). Patients must be fully informed about the way agencies use a signed authorization and are entitled to receive a free accounting every twelve months describing how their health information has been used.

HIPAA privacy regulations also mandate specific patient rights that include the following:

  1. Right to privacy notice requires disclosure and reasonable effort to assure that the patient understands the agency’s policy concerning privacy of information.

  2. Right to request restrictions means that patients may specify health information that cannot be released and/or, they may restrict to whom information can be released.

  3. Right to access of PHI means that patients must be allowed to inspect and copy information contained in the agency’s record.

  4. Right to know what disclosures have been made means the agency must track all information released and be able to provide documentation to the patient.

  5. Right to amend the PHI means that while patients may request amendments to the PHI and the agency must allow amendments, the agency may deny some requests.

All covered entities are required to comply with certain procedural rules. Most have had to develop new policies and procedures to address the many aspects covered under these rules. The following are some of the rules:

  1. Agencies must appoint a privacy officer who will monitor and audit compliance.

  2. Agencies must develop an internal compliance process that will assure no patient rights are violated, complaints are addressed and investigated, and that a process for remediation is in place.

  3. Training must be provided to employees to assure that they are informed about patient rights and disclosure of information.

  4. HIPAA requires that agencies document any and all violations and that sanctions parallel other disciplinary policies.

  5. Agencies must have a process for mitigating any harmful effect of disclosure.

  6. All forms of communication must be addressed in administrative safeguards.

  7. Agencies must agree and have policies that specify no retaliation for an employee or consumer who files a complaint.

Prev
Next