HIPAA and Clinical Information Privacy
HIPAA Overview and History
HIPAA stands for the Health Insurance Portability and Accountability Act. It was passed by federal law in .
The concept of health information privacy is grounded in the Hippocratic oath from , which mandates that what is heard during professional practice should not be divulged.
The legal foundations of health data privacy include Body Privacy (informed consent) and Information Privacy (the right to control personal data).
Informed consent requires that the patient has the capacity to make decisions, understands the information provided, and gives consent voluntarily without fraud or coercion.
Privacy, Confidentiality, and Security
Privacy: The right of an individual patient to control who accesses their personal health information. It is legally and ethically tied to the patient.
Confidentiality: The responsibility of health care providers to protect patient information and prevent inappropriate disclosure or access. It is tied to the provider.
Security: The administrative, technical, and physical systems and mechanisms (e.g., encryption, locked cabinets, access controls) used to protect privacy and confidentiality.
The Framework of Three Rules
Privacy Rule: Sets national standards for protecting Protected Health Information (). It requires providers to give patients a notice of privacy practices.
Security Rule: A narrower rule that specifically applies to electronic Protected Health Information (). It requires covered entities to analyze vulnerabilities in their information technology systems.
Breach Notification Rule: Requires covered entities to notify the federal Department of Health and Human Services and the patient if is disclosed. If a breach affects or more patients, the media must also be notified.
Protected Health Information ()
includes information regarding a patient's physical and mental health, health care provided, or payment for care that can reasonably identify the individual.
There are specific HIPAA identifiers, including names, Social Security numbers, medical records numbers, IP addresses, and full face photographs.
De-identification involves removing specific identifiers (e.g., stripping the month and day from a birth date while keeping the year) to allow data usage for research or quality improvement.
Operational Standards
Covered Entities: Entities that must comply with HIPAA include health care providers (hospitals, clinics, dietitians), health plans (insurance), and health care clearinghouses.
Minimum Necessary Standard: Clinicians must make a reasonable effort to access only the specific portion of necessary to perform a current task. Treatment communications between providers and disclosures to the patient are exempt from this standard.
Right of Access: Patients have a legal right to access their own health information, including nutrition notes and PES statements. Providers must typically respond to access requests within days.
Business Associate Agreements: Third-party vendors or contractors (e.g., electronic health record companies) that handle must comply with HIPAA laws through written agreements.
Penalties for Violations
Category : The organization did not know and could not have reasonably known a violation occurred (e.g., mailing a result to the wrong address).
Category : A violation occurs with reasonable cause but not due to willful neglect (e.g., unencrypted personal laptops used for work).
Category : A violation due to willful neglect that was corrected right away.
Category : A violation due to willful neglect where no corrective action was taken.
Penalties are calculated per individual affected and can reach up to per year.
Questions & Discussion
Question: Who was the tour guide for the campus tour remembered by the listeners?
Response: A blonde student ambassador likely named Shay, who is seen frequently at use at the bear club.
Question: What is the name of the cheering group at Missouri State?
Response: Bearpocalypse.
Instruction: Students are requested to put their phones away during the class session.