What is Covered under the Privacy Rule? Protected Health Information (PHI)



Similar documents
Winthrop-University Hospital

HIPAA Medical Billing Requirements For Research

HIPAA COMPLIANCE. What is HIPAA?

HIPAA COMPLIANCE INFORMATION. HIPAA Policy

HIPAA Basics for Clinical Research

Health Insurance Portability & Accountability Act (HIPAA) Compliance Application

University of Mississippi Medical Center Office of Integrity and Compliance

IRB Application for Medical Records Review Request

What is Covered by HIPAA at VCU?

HIPAA-Compliant Research Access to PHI

Protecting Personal Health Information in Research: Understanding the HIPAA Privacy Rule

HIPAA Privacy Compliance Plan for Research. University of South Alabama IRB Guidance and Procedures

Health Insurance Portability and Accountability Policy 1.8.4

HIPAA POLICY REGARDING DE-IDENTIFICATION OF PROTECTED HEALTH INFORMATION AND USE OF LIMITED DATA SETS

HIPAA and Research Ethics

Children's Hospital, Boston (Draft Edition)

HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA): FACT SHEET FOR NEUROPSYCHOLOGISTS Division 40, American Psychological Association

4. No accounting of disclosures is required with respect to disclosures of PHI within a Limited Data Set.

SOP Number: OCR-HIP-001 Effective Date: August 2013 Page 1 of 5

HIPAA OVERVIEW ETSU 1

Memorandum. Factual Background

HIPAA Privacy Rule Primer for the College or University Administrator

The HIPAA privacy rule and long-term care : a quick guide for researchers

UPMC POLICY AND PROCEDURE MANUAL

UPMC POLICY AND PROCEDURE MANUAL

HIPAA-P06 Use and Disclosure of De-identified Data and Limited Data Sets

SCHOOL OF PUBLIC HEALTH. HIPAA Privacy Training

HIPAA and Clinical Research

PROTECTED HEALTH INFORMATION AND THE JHSPH

Administrative Services

MCDONOUGH CENTER FOR FAMILY DENTISTRY, LLC

HIPAA Compliance Strategies for Pharmaceutical Manufacturers,

De-Identification of Health Data under HIPAA: Regulations and Recent Guidance" " "

A. HIPAA Privacy Authorizations and Exceptions for Use of Identifiable Protected Health Information

Limited Data Set Background Information

HIPAA: Open Research Issues Michael L. Blau, Esq. McDermott, Will & Emery

Section C: Data Use Agreement. Illinois Department of Healthcare and Family Services. And DATA USE AGREEMENT

Professional Employer Organizations Obligations Under HIPAA A Summary

Implementing an HMIS within HIPAA

IDAHO STATE UNIVERSITY POLICIES AND PROCEDURES (ISUPP) HIPAA Privacy - De-identification of PHI 10030

INDIANA UNIVERSITY SCHOOL OF OPTOMETRY HIPAA COMPLIANCE PLAN TABLE OF CONTENTS. I. Introduction 2. II. Definitions 3

The Health and Benefit Trust Fund of the International Union of Operating Engineers Local Union No A-94B, AFL-CIO. Notice of Privacy Practices

Standard Operating Procedures for Research Involving Human Subjects

HIPAA PRIVACY AND SECURITY STANDARDS CITY COMPLIANCE

How To Get A Health Care License

HIPAA POLICY PROCEDURE GUIDE

HIPAA 100 Training Manual Table of Contents. V. A Word About Business Associate Agreements 10

NOTICE OF HIPAA PRIVACY AND SECURITY PRACTICES

Gaston County HIPAA Manual

How to De-identify Data. Xulei Shirley Liu Department of Biostatistics Vanderbilt University 03/07/2008

NLRG HIPAA PRIVACY SHORTCUT ROUTE: AN EMPLOYER GUIDE PARTNERING WITH YOU ON TRENDS AND BEST PRACTICES TO SUPPORT YOUR HUMAN RESOURCES INITIATIVES

IRB Month Investigator Meeting April 2014

BUSINESS ASSOCIATE AGREEMENT HIPAA Protected Health Information

SDC-League Health Fund

Protected Health Information

RESEARCH INVOLVING DATA AND/OR BIOLOGICAL SPECIMENS

HIPAA Privacy Board Overview

Compliance Program and HIPAA Training For First Tier, Downstream and Related Entities

YALE UNIVERSITY RESEARCHER S GUIDE TO HIPAA. Health Insurance Portability and Accountability Act of 1996 Handbook

HIPAA Policies and Procedures

Everett School Employee Benefit Trust. Reportable Breach Notification Policy HIPAA HITECH Rules and Washington State Law

Principal Investigator Responsibilities for Education and Social/Behavioral Researchers

HIPAA-G04 Limited Data Set and Data Use Agreement Guidance

State of Nevada Public Employees Benefits Program. Master Plan Document for the HIPAA Privacy and Security Requirements for PEBP Health Benefits

Connecticut Carpenters Health Fund Privacy Notice

Instructions for Form: Application for Claim of Exemption

Use or Disclosure of PHI

California State University. HIPAA Privacy Summary Manual

AVE MARIA UNIVERSITY HIPAA PRIVACY NOTICE

State of Connecticut Department of Social Services HIPAA Policies and Procedures Manual

PEPPERDINE UNIVERSITY HIPAA Policies Procedures and Forms Manual

VENDOR / CONTRACTOR. Privacy Basics

BUMC Clinical Research Seminar: What would YOU do? Put your IRB hat on!

Tips for Investigators ~eirb Submissions~ Department of Emergency Medicine Research Division. *Edwin D. Boudreaux, PhD; EM Division Director

HIPAA Policy Use and Disclosure of Protected Health Information November 3, 2015

Attachment B HIPAA-P03 Instructions for Completing IU s Authorization for Research Purposes

Accessing Electronic Health Record Data for Human Subjects Research: Challenges and Solutions August 2, 2012

University of Cincinnati Limited HIPAA Glossary

HIPAA Handbook for Researchers at UAB

Schindler Elevator Corporation

January Employers must be prepared for their obligations under the HIPAA Privacy Rules

Guidelines Relating to Implementation of the Privacy Regulations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA)

THE HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) EMPLOYEE TRAINING MANUAL

HIPAA Privacy Officer Sonya Middleton. HIPAA Security Officer Joan Kellner

HIPAA PRIVACY POLICIES AND PROCEDURES

NOTICE OF HEALTH INFORMATION PRIVACY PRACTICES (HIPAA)

Salt Lake Community College Employee Health Care Benefits Plan Notice of Privacy Practices

Grand Rapids Medical Education Partners Mercy Health Saint Mary s Spectrum Health. Pam Jager, GRMEP Director of Education & Development

Graphic Communications National Health and Welfare Fund. Notice of Privacy Practices

HIPAA. Privacy and Security Frequently Asked Questions for Employers. Gallagher Benefit Services, Inc.

HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT HIPAA DENTAL HYGIENE PRIVACY AND SECURITY POLICIES AND PROCEDURES

A Privacy and Information Security Guide for UCLA Workforce. HIPAA and California Privacy Laws

Statement of Policy. Reason for Policy

VALPARAISO UNIVERSITY NOTICE OF PRIVACY PRACTICES. Health, Dental and Vision Benefits Health Care Reimbursement Account

HIPAA Data Use Agreement Policy R&G Template Updated for Omnibus Rule HIPAA DATE USE AGREEMENT 1

Central Maine Healthcare

HIPAA Privacy Manual

SCHOOL DISTRICT OF BLACK RIVER FALLS HIPAA PRIVACY AND SECURITY POLICY

American Guild of Musical Artists ( AGMA ) Health Fund Privacy Notice. Plan A and Plan B

Transcription:

HIPAA & RESEARCH

What is Covered under the Privacy Rule? Protected Health Information (PHI) Health information + Identifier = PHI Transmitted or maintained in any form (paper, electronic, forms, web-based, etc.) Decedents information included Does not include de-identified health information.

Covered Entity & Researcher Relationship Covered Entities = (1) Health Plans, (2) Health Care Clearing Houses, & (3) Health Care Providers who electronically transmit any health information Researchers are covered entities if they are also Health Care Providers who electronically transmit health information Any entity that meets the definition of a covered entity is generally, in its entirety, subject to the Privacy Rule A single entity may elect hybrid status if it performs both covered & non-covered functions

Exceptions to HIPAA TPO Treatment, Payment, Health Care Operations (TPO) Treatment the provision, coordination, or management of health care and related services by one or more health care provider, (i.e., consultation, referrals) Payment activities of a health care provider to obtain reimbursement for the provision of health care (i.e., eligibility, coverage, billing, claims management, collections) Health Care Operations such activities as quality assessment and improvement, reviewing qualification of employees and students, medical/legal/compliance reviews, cost-management, internal grievances, customer service, education

What Research is Affected? Records research that uses existing PHI, such as: Research databases and repositories Chart reviews Research that includes treatment of research participants, such as: Clinical trials

Research Use and Disclosure of PHI Without Authorization: De-Identified Health Information Completely de-identified information (18 elements removed) and no knowledge that remaining information can identify the individual De-identified is NOT the same as anonymous! Statistically de-identified information where a statistician certifies that there is a very small risk that the information could be used to identify the individual

What is an Identifier under the Privacy Rule? The Privacy Rule defines 18 identifiers Name Geographic information (including city, state and zip) Elements of dates (including admission/discharge dates; service dates; birth date, date of death) Telephone numbers FAX numbers E-mail addresses Social Security number Medical Record number prescription number, etc. Health plan beneficiary number Account Numbers Certification numbers VIN and Serial numbers, license plate numbers Device identifiers and serial numbers Web URLs IP address numbers Biometric identifiers (finger prints, voice prints, retinal scans, etc.) Full face or comparable photo images Unique identifying numbers

Research under HIPAA Situations in which PHI may be used for research purposes: By De-Identification of PHI With individual Authorization With waiver of Authorization by IRB or Privacy Board As a Limited Data Set with Data Use Agreement As an activity preparatory to research For research on decedent s information

Elements of an Authorization Core HIPAA Elements Description of PHI to be used or disclosed Person(s) authorized to make and receive requested use or disclosure Purpose for the use or disclosure Expiration date or event (e.g. end of the research study or none) Subject or legally authorized representative signature and date Required HIPAA Statements Right to revoke Authorization plus exceptions and process Ability/Inability to condition treatment, payment, or enrollment/eligibility for benefits on Authorization PHI may no longer be protected by Privacy Rule once it is disclosed by the covered entity

Common Rule vs. Privacy Rule Research WITH subject permission Common Rule/FDA Regulated Privacy Rule IRB review of research and informed consent Valid authorization

Use and Disclosure of PHI for Research Without Individual Authorization: Four Options: Option 1: Obtain documentation that an IRB or Privacy Board has approved an alteration to or waiver of authorization based on the following 3 waiver criteria: 1. The use or disclosure involves no more than minimal risk because of an adequate plan/assurance To protect PHI from improper use or disclosure To destroy identifiers at earliest opportunity That PHI will not be inappropriately reused or disclosed 2. The research could not practicably be conducted without the waiver 3. The research could not practicably be conducted without access to and use of PHI

Waiver of Authorization HIPAA Waiver of requirement for Authorization to use or disclose PHI No more than minimal risk to privacy based on at least: Plan to protect identifiers Plan to destroy identifiers at earliest opportunity Written assurance that PHI will not be used/disclosed with few exceptions Research cannot be done without waiver Research cannot be done without the PHI OHRP Waiver of requirement for informed consent Research involves no more than minimal risk the probability and magnitude of harm or discomfort anticipated in the research are not greater in and of themselves than those ordinarily encountered in daily life or during the performance of routine physical or psychological examinations or tests Waiver or alteration of informed consent will not adversely affect the rights and welfare of the subject The research could not be practicably carried out without the waiver Whenever appropriate, subjects will be given additional information after participation FDA No comparable waiver of informed consent allowed

Research Use and Disclosure of PHI Without Individual Authorization: OPTION 2: Obtain representation that the use or disclosure is necessary to prepare a research protocol or for similar purposes preparatory to research: 1. Researcher must provide representation that: The PHI is to be used solely to prepare a protocol or for a similar purpose The PHI will not be removed from the covered entity The PHI is necessary for research 2. May be used to develop hypothesis, protocol or characteristics of research cohort 3. May not be summarized, used or presented as a research study without prior IRB approval 4. May allow access to PHI to identify subjects for recruitment

Privacy Rule and Research: Subject Recruitment A patient s direct treatment provider may discuss possible research participation with a patient A patient s direct treatment provider may NOT discuss the patient with research colleagues for potential enrollment purposes without the patient s Authorization or Waiver of Authorization by IRB or Privacy Board Can a researcher search through medical records to identify potential research subjects? Only if: They are the subject s direct treatment provider Individual Authorization has been provided A Waiver of Authorization has been granted by the IRB or Privacy Board As Preparatory to Research All subject recruitment strategies and material MUST be approved by the IRB (Common Rule requirement)

Research Use and Disclosure of PHI Without Individual Authorization: OPTION 3: Obtain representation that the use or disclosure is solely for research on decedents protected health information: 1. The researcher must provide representation that: The use and disclosure is solely for research The PHI is necessary for research The individual is deceased, and provide documentation upon request

Research Use and Disclosure of PHI Without Individual Authorization OPTION 4: Only use or disclose limited data set/ Indirect Identifiers (e.g. zip code, age, elements of date) Limited Use Data Set Excludes the following direct identifiers: Name Geographic information (other than city, state and zip) Telephone numbers FAX numbers E-mail addresses Social Security number Medical Record number, prescription number, etc. Health plan beneficiary number Account Numbers Certification numbers VIN and Serial numbers license plate numbers Device identifiers and serial numbers Web URLs IP address numbers Biometric identifiers (finger prints, voice prints, retinal scans, etc.) Full face or comparable photo images Unique identifying numbers

Data Use Agreement REQUIRED for Limited Use Data Sets The Date Use Agreement must: Describe the permitted uses and disclosures (recipient cannot use or disclose PHI in a way that the covered entity cannot) Identify who can use and disclose the PHI Require the recipient to: Not re-identify the information or contact the individuals Use or disclose information for specified purposes only Apply safeguards to protect the information Report known violations to the covered entity Hold subcontractors to the same standards as in the agreement

Disclosure to a Public Health Authority or Required by Law Disclosure without Authorization permitted if required by law or for public health activities Adverse event reporting to a sponsor, FDA, NIH Public health reporting of communicable diseases Tracking of FDA regulated products (e.g. devices) Reporting abuse, neglect or domestic violence A covered entity may disclose PHI related to an adverse event if required to do so by regulation. Even if not required to do so, the researcher may disclose adverse events to a public health authority.

State Law The Federal Regulations defer to State and Local regulations for definition of the following terms: Legally Authorized Representative (LAR) surrogate decision maker for subject who lacks capacity. Child person who has not attained the legal age of consent to research treatments or procedures under applicable state law Guardian individual authorized to consent to a child s general medical care under applicable state or local law. State law may impose additional obligations that impact research, e.g.: Mandatory reporting (child abuse, communicable disease testing) Additional subject protections (ESBOR)

IRB Member Conflict of Interest OHRP and FDA Regulations provide that no IRB member may participate in the review of any project in which the member has a conflicting interest, except to provide information requested by the IRB. An IRB may lose its quorum if the number of members falls below a majority when a member with a conflict of interest leaves the room for deliberation and voting on a study.