HIPAA Compliance Strategies for Pharmaceutical Manufacturers,



Similar documents
HIPAA COMPLIANCE. What is HIPAA?

HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA): FACT SHEET FOR NEUROPSYCHOLOGISTS Division 40, American Psychological Association

HIPAA COMPLIANCE INFORMATION. HIPAA Policy

What is Covered under the Privacy Rule? Protected Health Information (PHI)

Winthrop-University Hospital

HIPAA Medical Billing Requirements For Research

SOP Number: OCR-HIP-001 Effective Date: August 2013 Page 1 of 5

HIPAA PRIVACY AND SECURITY AWARENESS

University of Mississippi Medical Center Office of Integrity and Compliance

What is Covered by HIPAA at VCU?

Section C: Data Use Agreement. Illinois Department of Healthcare and Family Services. And DATA USE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT

Protecting Personal Health Information in Research: Understanding the HIPAA Privacy Rule

HIPAA Privacy Overview

HIPAA-P01 Uses and Disclosures of Protected Health Information Policy

Health Information Privacy Refresher Training. March 2013

HIPAA Privacy Rule Primer for the College or University Administrator

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE ADDENDUM

HIPAA SELF STUDY TRAINING GUIDE

BUSINESS ASSOCIATE AGREEMENT HIPAA Protected Health Information

HIPAA-P06 Use and Disclosure of De-identified Data and Limited Data Sets

Limited Data Set Background Information

HIPAA Privacy Compliance Plan for Research. University of South Alabama IRB Guidance and Procedures

Health Insurance Portability & Accountability Act (HIPAA) Compliance Application

Implementing an HMIS within HIPAA

Welcome to ChiroCare s Fourth Annual Fall Business Summit. October 3, 2013

BREVIUM HIPAA BUSINESS ASSOCIATE TERMS AND CONDITIONS

AVE MARIA UNIVERSITY HIPAA PRIVACY NOTICE

THE HIPAA PRIVACY RULE AND THE NATIONAL HOSPITAL CARE SURVEY

Addendum To Agreement With Business Associate

HIPAA Basics for Clinical Research

The HIPAA privacy rule and long-term care : a quick guide for researchers

PATIENT REGISTRATION FORM

HEALTH INSURANCE PORTABILITY & ACCOUNTABILITY ACT OF 1996 HIPAA

NOTICE OF PRIVACY PRACTICES (NPP)

We are required to provide this Notice to you by the Health Insurance Portability and Accountability Act ("HIPAA")

Memorandum. Factual Background

BUSINESS ASSOCIATE AGREEMENT

Releasing Information

How To Write A Community Based Care Coordination Program Agreement

HIPAA BUSINESS ASSOCIATE ADDENDUM (Privacy & Security) I. Definitions

HIPAA Privacy Board Overview

CATHOLIC SOCIAL SERVICES BUSINESS ASSOCIATE AGREEMENT

HIPAA BUSINESS ASSOCIATE AGREEMENT

Pacific Medical Centers HIPAA Training for Residents, Fellows and Others

HIPAA and Research Ethics

HIPAA 100 Training Manual Table of Contents. V. A Word About Business Associate Agreements 10

Page 1. NAOP HIPAA and Privacy Risks 3/11/2014. Privacy means being able to have control over how your information is collected, used, or shared;

NOTICE OF PRIVACY PRACTICES

Health Insurance Portability and Accountability Policy 1.8.4

DETAILED NOTICE OF PRIVACY AND SECURITY PRACTICES OF THE Trustees of the Stevens Institute of Technology Health & Welfare Plan

what your business needs to do about the new HIPAA rules

BUSINESS ASSOCIATE AGREEMENT ( BAA )

INDIANA UNIVERSITY SCHOOL OF OPTOMETRY HIPAA COMPLIANCE PLAN TABLE OF CONTENTS. I. Introduction 2. II. Definitions 3

Donna S. Sheperis, PhD, LPC, NCC, CCMHC, ACS Sue Sadik, PhD, LPC, NCC, BC-HSP Carl Sheperis, PhD, LPC, NCC, MAC, ACS

HIPAA BUSINESS ASSOCIATE AGREEMENT

The Privacy Rule is designed to minimize conflicts between Federal requirements and those of State law. It establishes a floor of Federal privacy

BUSINESS ASSOCIATE AGREEMENT

The Basics of HIPAA Privacy and Security and HITECH

OCTOBER 2013 PART 1. Keeping Data in Motion: How HIPAA affects electronic transfer of protected health information

HIPAA Business Associate Addendum

HIPAA Overview. Darren Skyles, Partner McGinnis Lochridge. Darren S. Skyles

Data Security and Integrity of e-phi. MLCHC Annual Clinical Conference Worcester, MA Wednesday, November 12, :15pm 3:30pm

How to De-identify Data. Xulei Shirley Liu Department of Biostatistics Vanderbilt University 03/07/2008

RESEARCH INVOLVING DATA AND/OR BIOLOGICAL SPECIMENS

APPENDIX 1: Frequently Asked Questions

Central Maine Healthcare

HIPAA BUSINESS ASSOCIATE AGREEMENT

Health Insurance Portability and Accountability Act HIPAA Privacy Standards

Children's Hospital, Boston (Draft Edition)

NATIONWIDE HIPAA NOTICE OF PRIVACY PRACTICES

OFFICE OF CONTRACT ADMINISTRATION PURCHASING DIVISION. Appendix A HEALTHCARE INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPPA)

HIPAA: Open Research Issues Michael L. Blau, Esq. McDermott, Will & Emery

Personal Information - Protecting And Balancing It At Hulse QM

HIPAA OVERVIEW ETSU 1

Health Insurance Portability and Accountability Act HIPAA. Glossary of Common Terms

Understanding Your Health Record Information

Heather L. Hughes, J.D. HIPAA Privacy Officer U.S. Legal Support, Inc.

Salt Lake Community College Employee Health Care Benefits Plan Notice of Privacy Practices

HIPAA PRIVACY DIRECTIONS. HIPAA Privacy/Security Personal Privacy. What is HIPAA? 6/28/2012

HIPAA (The Health Insurance Portability and Accountability Act)

HIPAA Compliance. Saeed Rajput

HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT BUSINESS ASSOCIATE TERMS AND CONDITIONS

HIPAA Privacy & Security Training for Clinicians

NOTICE OF PRIVACY PRACTICES FOR PURDUE UNIVERSITY HEALTH PLANS

BUSINESS ASSOCIATE AGREEMENT

Accessing Electronic Health Record Data for Human Subjects Research: Challenges and Solutions August 2, 2012

BUSINESS ASSOCIATE AGREEMENT

HIPAA POLICY PROCEDURE GUIDE

HIPAA-Compliant Research Access to PHI

PRIVACY PRACTICES OUR PRIVACY OBLIGATIONS

Advanced Eye Care & Optical 499 E Winchester Blvd., Suite 101 Collierville, TN Phone: Fax:

E-Health and Medical Billing Requirements

Use & Disclosure of Protected Health Information by Business Associates

HIPAA Handbook for Researchers at UAB

Health Insurance Portability and Accountability Act (HIPAA)

The Health and Benefit Trust Fund of the International Union of Operating Engineers Local Union No A-94B, AFL-CIO. Notice of Privacy Practices

NOTICE OF HEALTH INFORMATION PRIVACY PRACTICES (HIPAA)

HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) TERMS AND CONDITIONS FOR BUSINESS ASSOCIATES

Transcription:

HIPAA Compliance Strategies for Pharmaceutical Manufacturers, PBMs and Pharmacies Jean-Paul Hepp,, Ph.D. Director, Global Privacy HIPAA Colloquium Harvard MA; August 22, 2002 1

Agenda Privacy ~ Definitions and Context HIPAA ~ Pharmaceutical Companies HIPAA ~ Online Marketing HIPAA ~ R&D Privacy ~ Current PHA Approach 2

Right of Privacy The claim of individuals to determine for themselves when, how and to what extent information about them is communicated. 1. What kind of Information 2. How we use it 3. Who we are sharing it with 3

PII, PHI Personal identifiable information (PII) means any confidential or sensitive information that can be related back to an individual. Personal identifiable health information (PHI) means information about an individual s health. 4

PII 1. Name 2. Address 3. E-Mail Address 4. Social Security Number 5. Password (if used to access the site) 6. Bank Account Information 7. Credit Card Information 8. Any combination of Data that could be used to identify a consumer, such as the consumer's birth date, zip code and gender. 5

Right of Privacy The claim of individuals to determine for themselves when, how and to what extent information about them is communicated. 1. What kind of Information 2. How we use it 3. Who we are sharing it with 6

Mapping Identification of Regulations and Legal Pitfalls and Tracking of Information Flow: Regions Customers Channels Technology 7

Right of Privacy The claim of individuals to determine for themselves when, how and to what extent information about them is communicated. 1. What Information 2. How we use it 3. Who we are sharing it with 8

Points of Access Pharmaceutical Company Employees Third Party Developers/Contractors Third Party Hosting Company Subcontractors of Third Party Hosting Company Third Party Transmission Company Third Party Service Provider Other Points of Access or Links 9

Regulatory/Legal Environment Privacy & Security Federal Regulations State laws Attorney General s actions Litigation EU Safe Harbor Canada.. 10

Agenda Privacy ~ Definitions and Context HIPAA ~ Pharmaceutical Companies HIPAA ~ Online Marketing HIPAA ~ R&D Privacy ~ Current PHA Approach 11

HIPAA HIPAA (Health Insurance Portability and Accountability Act) Requires (DHHS) to develop standards and requirements for maintenance and transmission of health information that identifies individual patients. Protect the security and confidentiality of electronic and other health information. 12

Covered Entities Health Plans Healthcare Clearinghouse Healthcare Providers Business Associate Access of Protected Information through or from Covered Entity Either acts on behalf of or acts as part of an Organized Health Care Arrangement 13

For The Pharmaceutical Industry The Rule May Affect: HR (online) Marketing Reimbursement Programs Disease management programs Pharmacy benefits programs 14

For The Pharmaceutical Industry R&D The Rule May Affect: DNA? Clinical trials? Drug safety monitoring Biostatistical analysis Outcomes or economics studies? 15

Agenda Privacy ~ Definitions and Context HIPAA ~ Pharmaceutical Companies HIPAA ~ Online Marketing HIPAA ~ R&D Privacy ~ Current PHA Approach 16

17

Privacy Statement 18

19

Privacy Statement 20

21

Workshop ~ Case Study 22

23

HIPAA April 14, 2003 Uses and disclosures of Protected Information Consent, Authorization and Opportunity to Agree Requirements Organizational Requirements - Privacy Officer - Training - Safeguards - Enforcement Program - Policy and Procedure Standards 24

Agenda Privacy ~ Definitions and Context HIPAA ~ Pharmaceutical Companies HIPAA ~ Online Marketing HIPAA ~ R&D Privacy ~ Current PHA Approach 25

R&D/Clinical 26

Human Genome Project FINDING TARGETS GAAACTGTGC TTCAACTAGT CGTAATTCTG AAAGCGAAAT ATTCTTGTGT GTTTGCAGAT TTCTACTTTC CATGGCTCTT AATTATTATC TTTGGAATAT TTGGGCTAAC AGTGATGCTA TTTGTATTCT TATTTTCTAA GAAACTGTGC TTCAACTAGT CGTAATTCTG AAAGCGAAAT ATTCTTGTGT GTTTGCAGAT TTCTACTTTC CATGGCTCTT AATTATTATC TTTGGAATAT TTGGGCTAAC AGTGATGCTA TTTGTATTCT TATTTTCTAA GAAACTGTGC TTCAACTAGT CGTAATTCTG AAAGCGAAAT ATTCTTGTGT GTTTGCAGAT TTCTACTTTC CATGGCTCTT AATTATTATC TTTGGAATAT TTGGGCTAAC AGTGATGCTA TTTGTATTCT TATTTTCTAA GAAACTGTGC TTCAACTAGT CGTAATTCTG AAAGCGAAAT ATTCTTGTGT GTTTGCAGAT TTCTACTTTC CATGGCTCTT AATTATTATC TTTGGAATAT TTGGGCTAAC AGTGATGCTA TTTGTATTCT TATTTTCTAA GAAACTGTGC TTCAACTAGT CGTAATTCTG AAAGCGAAAT GAAACTGTGC TTCAACTAGT CGTAATTCTG AAAGCGAAAT ATTCTTGTGT GTTTGCAGAT TTCTACTTTC CATGGCTCTT AATTATTATC TTTGGAATAT TTGGGCTAAC AGTGATGCTA TTTGTATTCT TATTTTCTAA GAAACTGTGC TTCAACTAGT CGTAATTCTG AAAGCGAAAT ATTCTTGTGT GTTTGCAGAT TTCTACTTTC CATGGCTCTT AATTATTATC TTTGGAATAT TTGGGCTAAC AGTGATGCTA TTTGTATTCT TATTTTCTAA GAAACTGTGC TTCAACTAGT CGTAATTCTG AAAGCGAAAT ATTCTTGTGT GTTTGCAGAT TTCTACTTTC CATGGCTCTT AATTATTATC TTTGGAATAT TTGGGCTAAC AGTGATGCTA TTTGTATTCT TATTTTCTAA GAAACTGTGC TTCAACTAGT CGTAATTCTG AAAGCGAAAT ATTCTTGTGT GTTTGCAGAT TTCTACTTTC CATGGCTCTT AATTATTATC TTTGGAATAT TTGGGCTAAC AGTGATGCTA TTTGTATTCT TATTTTCTAA GAAACTGTGC TTCAACTAGT CGTAATTCTG AAAGCGAAAT 27

Clinical Trials Who is covered? - Healthcare providers who transmit health information in electronic transactions: including researchers who provide treatment to research participants - Health Plans - Healthcare Clearinghouse 28

Clinical Trials What is covered? - Protected Health Information - Decedents Health Information - Transmitted or maintained in any form or medium - For Research that involves treatment - For Records research - History of Patient Data 29

Clinical Trials The Privacy Rule permits covered entities to use and disclose PHI for research conducted: - With individual authorization,, or - Without individual authorization under limited circumstances 30

Clinical Trials Patient authorization elements under NPRM (public comments, expected Final Aug 02): The information Who may use or disclose the information Who may receive the information Purpose of the use or disclosure Expiration date or event Right to revoke authorization 31

Clinical Trials Use and disclosure of PHI Without Individual Authorization * (current Final Rule): 1. Obtain documentation that an IRB or privacy board has determined specified criteria were satisfied 2. Obtain representation that the use or disclosure is necessary to prepare a research protocol or for similar purposes preparatory to research * DHHS Office for Human Research Protections, May 2002 32

Clinical Trials Use and disclosure of PHI Without Individual Authorization * (current Final Rule): 3. Obtain representation that the use or disclosure is solely for research on decedents PHI 4. Only use or disclose indirect identifiers for research, public health, or health care operations AND Require a data use agreement from recipient agreeing to use only for purpose provided and not to re-identify or contact individual DHHS Office for Human Research Protections, May 2002 33

Clinical Trials The Privacy Rule does not override the Common Rule of FDA s human subjects regulations 34

Agenda Privacy ~ Definitions and Context HIPAA ~ Pharmaceutical Companies HIPAA ~ Online Marketing HIPAA ~ R&D Privacy ~ Current PHA Approach 35

Pharmacia Approach 1/ Mapping 2/ Data Privacy Agreement 3/ Implementation 4/ Certifications 5/ Privacy Officer 36

1. Mapping Identify Regulations and Legal Pitfalls for Regions Customers Channels Technology 37

2. Data Privacy Agreement for each Business Trust Partner Permitted uses and disclosures of Protected Information Appropriate safeguards of records Report any unauthorized disclosures to entity PHI available for inspection, amendment, accounting Books and records available for inspection by DHHS Destroy/Return PHI at termination of contract 38

3. Implementation Implement Privacy/Security rules: - Front-end: informed Consent, Statement, Terms and conditions - Back-end: Security, Business Partners... 39

4. Certification Internet Healthcare Coalition "e-health Code of Ethics" Health Internet Ethics Alliance "HI-Ethics Health on the Net Foundation Code of Conduct "HON code Other (TRUSTe( TRUSTe,, BBB, PWC, URAC...) 40

5. Privacy Officer The PO has the responsibility for the creation, implementation and maintenance of the company s privacy compliance related activities 41

Thank you! JeanPaul.Hepp Hepp@Pharmacia.com 42