HIPAA · Domain 1
HIPAA Privacy Rule
About 25% of the exam
Who the law covers
- Covered entity
- providers, health plans, clearinghouses
- Provider
- bills electronically for covered transactions
- Health plan
- insurers and group health plans
- Clearinghouse
- translates nonstandard transactions into standard
- Business associate
- handles protected information on their behalf
- Subcontractor
- an associate of the associate
- Hybrid entity
- designates its health care components
- Organized arrangement
- clinically integrated care shared between entities
A vendor storing encrypted records is a business associate even if it never looks at them, while a janitor with no access is not
The rules in the family
- Privacy Rule
- uses and disclosures of health information
- Security Rule
- electronic information only
- Breach Notification Rule
- who to tell and when
- Enforcement Rule
- investigations, penalties and hearings
- Transactions and code sets
- standard electronic formats
- Identifiers
- national numbers for providers and plans
- Title one
- insurance portability between jobs
- Title two
- administrative simplification and privacy
Protected health information
- Health information tied to an individual
- Created or received by a covered entity
- Past, present or future condition
- Payment for care also counts
- Any medium, spoken, paper or electronic
- Employment records are excluded
- Protection lasts fifty years after death
The eighteen identifiers
- Names and geography below state level
- All dates except the year
- Telephone, fax and email addresses
- Social security and medical record numbers
- Account, license and vehicle identifiers
- Device serials, network addresses and biometrics
- Full face photographs and anything else identifying
De-identification
- Safe harbor removes eighteen identifier types
- No actual knowledge of residual identity
- Expert determination uses statistical judgment
- Very small risk of renewed identification
- Methods and results must be documented
- A limited data set is not de-identified
Minimum necessary
- Limit to what the purpose needs
- Role based access for the workforce
- Standard protocols for routine disclosures
- Case by case review for others
- Does not apply to treatment requests
- Does not apply to the individual
- Does not apply to required disclosures
Uses and disclosures
No authorization needed
- Treatment, payment and health care operations
- Required by law or public health
- Health oversight, judicial and law enforcement
- Serious and imminent threat to safety
- Research under a waiver or review
Authorization required
- Most psychotherapy notes
- Marketing communications made for payment
- Sale of protected health information
- Anything outside the permitted list
Opportunity to agree or object covers facility directories and telling family, which sits between a permitted use and a full authorization
A valid authorization
- Describes the information to disclose
- Names who may disclose and receive
- States the purpose in plain terms
- Carries an expiration date or event
- Explains the right to revoke
- Signed and dated by the individual
Individual rights
- Access and copies of the record
- Amendment, with grounds for refusal
- Accounting of certain disclosures
- Request restrictions on use
- Confidential communications by other means
- Notice of privacy practices
- Complain to the entity or regulator
Access requests
- Act within thirty days of request
- One thirty day extension with notice
- Reasonable cost based fees only
- Send to a third party if directed
- Format the individual asks for
- Some denials carry a review right
Notice of privacy practices
- Describes uses and disclosures made
- Lists individual rights and legal duties
- Explains how to complain
- Carries an effective date
- Posted at the site and online
- Revised when practices materially change
Privacy failures that draw attention
- Records withheld or priced too high
- Snooping on famous or familiar patients
- Faxes and email to wrong recipients
- Photographs posted in response to reviews
- Paper discarded in open dumpsters
- Discussions overheard in public areas
Answering a disclosure question
- Confirm the information is protected
- Identify who is asking and why
- Look for a permitted purpose
- Check whether authorization is required
- Apply the minimum necessary standard
- Verify the requester's identity
- Log the disclosure where accounting applies
- Stricter state law still applies alongside
- Required by law disclosures need no authorization
- Incidental disclosures are tolerated with safeguards
- Verification is a rule, not a courtesy
Rapid recall: rule locations
- Part 160
- general administrative requirements
- Part 162
- transactions and code sets
- Part 164 subpart C
- the Security Rule
- Part 164 subpart D
- breach notification
- Part 164 subpart E
- the Privacy Rule
- Enforcement
- the Office for Civil Rights
Terms to fix early
- Treatment, payment, operations
- the core permitted purposes
- Designated record set
- records used to make decisions
- Limited data set
- identifiers stripped except dates and geography
- Personal representative
- stands in the individual's shoes
- Incidental disclosure
- unavoidable result of a permitted use
Reference strip: scope, information, uses, rights, notice
Scope
- Three covered entity types
- Associates and subcontractors bound too
- Hybrid entities designate components
Information
- Identifiable health information, any medium
- Eighteen identifiers for safe harbor
- Employment records sit outside
Uses
- Treatment, payment, operations permitted
- Authorization for marketing and sale
- Minimum necessary everywhere else
Rights
- Access within thirty days
- Amendment may be denied
- Accounting of disclosures available
Notice
- Given at first service
- Posted and published online
- Updated when practices change
Quick exam traps
- Trap: Patients must authorize every disclosure of their records
- Trap: The minimum necessary standard applies to treatment requests between providers
- Trap: Removing names alone makes a record de-identified
- Trap: A vendor that only stores encrypted records is not a business associate
- Trap: HIPAA preempts every state privacy law
- Trap: Protected health information stops being protected when the patient dies
- Trap: An overheard conversation is automatically a violation
cybercertprep.com · original revision sheet written from the public body of knowledge