HIPAA and Clinical Information Privacy

HIPAA Overview and History

  • HIPAA stands for the Health Insurance Portability and Accountability Act. It was passed by federal law in 19961996.

  • The concept of health information privacy is grounded in the Hippocratic oath from 400BC400\,BC, which mandates that what is heard during professional practice should not be divulged.

  • The legal foundations of health data privacy include Body Privacy (informed consent) and Information Privacy (the right to control personal data).

  • Informed consent requires that the patient has the capacity to make decisions, understands the information provided, and gives consent voluntarily without fraud or coercion.

Privacy, Confidentiality, and Security

  • Privacy: The right of an individual patient to control who accesses their personal health information. It is legally and ethically tied to the patient.

  • Confidentiality: The responsibility of health care providers to protect patient information and prevent inappropriate disclosure or access. It is tied to the provider.

  • Security: The administrative, technical, and physical systems and mechanisms (e.g., encryption, locked cabinets, access controls) used to protect privacy and confidentiality.

The Framework of Three Rules

  • Privacy Rule: Sets national standards for protecting Protected Health Information (PHIPHI). It requires providers to give patients a notice of privacy practices.

  • Security Rule: A narrower rule that specifically applies to electronic Protected Health Information (ePHIePHI). It requires covered entities to analyze vulnerabilities in their information technology systems.

  • Breach Notification Rule: Requires covered entities to notify the federal Department of Health and Human Services and the patient if PHIPHI is disclosed. If a breach affects 500500 or more patients, the media must also be notified.

Protected Health Information (PHIPHI)

  • PHIPHI includes information regarding a patient's physical and mental health, health care provided, or payment for care that can reasonably identify the individual.

  • There are 1818 specific HIPAA identifiers, including names, Social Security numbers, medical records numbers, IP addresses, and full face photographs.

  • De-identification involves removing specific identifiers (e.g., stripping the month and day from a birth date while keeping the year) to allow data usage for research or quality improvement.

Operational Standards

  • Covered Entities: Entities that must comply with HIPAA include health care providers (hospitals, clinics, dietitians), health plans (insurance), and health care clearinghouses.

  • Minimum Necessary Standard: Clinicians must make a reasonable effort to access only the specific portion of PHIPHI necessary to perform a current task. Treatment communications between providers and disclosures to the patient are exempt from this standard.

  • Right of Access: Patients have a legal right to access their own health information, including nutrition notes and PES statements. Providers must typically respond to access requests within 3030 days.

  • Business Associate Agreements: Third-party vendors or contractors (e.g., electronic health record companies) that handle PHIPHI must comply with HIPAA laws through written agreements.

Penalties for Violations

  • Category 11: The organization did not know and could not have reasonably known a violation occurred (e.g., mailing a result to the wrong address).

  • Category 22: A violation occurs with reasonable cause but not due to willful neglect (e.g., unencrypted personal laptops used for work).

  • Category 33: A violation due to willful neglect that was corrected right away.

  • Category 44: A violation due to willful neglect where no corrective action was taken.

  • Penalties are calculated per individual affected and can reach up to 1,500,0001,500,000 per year.

Questions & Discussion

  • Question: Who was the tour guide for the campus tour remembered by the listeners?

  • Response: A blonde student ambassador likely named Shay, who is seen frequently at use at the bear club.

  • Question: What is the name of the cheering group at Missouri State?

  • Response: Bearpocalypse.

  • Instruction: Students are requested to put their phones away during the class session.