Healthcare Privacy
Beyond the Breach
Access for Treatment, Payment and
Healthcare Operations
Regulations
•
Health Information Portability and Accountability
Act of 1996(HIPAA) regulations at 45 CFR Parts
160-164
–
The Omnibus Rule of 2013 – pulled in the
Health Information Technology for Economic
and Clinical Health Act (HITECH) regulations
•
WA State: Uniform Health Care Information
Definitions
•
Protected Health Information (PHI) – HIPAA
–
Health care Information – UHCIA
•
Treatment – HIPAA
•
Payment – HIPAA
•
Healthcare Operations – HIPAA
•
Covered Entity (CE) – HIPAA
•
Business Associate (BA) – HIPAA
•
Minimum Necessary – HIPAA
•
Need to Know – UHCIA
Defining PHI
•
HIPAA 160.103
•
Protected Health Information(PHI)
– “means individually identifiable health information” that is transmitted
or maintained in any form or medium
•
Individually Identifiable Health Information
– health information, including demographic information collected from
an individual, created or received by a health care provider, health plan, or health care clearinghouse that relates to the past, present, or future physical or mental health of an individual; the provision of
health care to an individual; or the past, present, or future payment for the provision of health care to an individual that identifies the
individual or there is a reasonable basis to believe the information can be used to identify the individual.
Defining PHI – De-Identified rule
•
HIPAA 164.514
• “Health information that does not identify an individual and with respect to which there is no reasonable basis to believe that the information can be used to identify an individual is not individually identifiable health
information.”
•
A covered entity may determine that health information is not
individually identifiable health information only if:
– “A person with appropriate knowledge of and experience with generally
accepted statistical and scientific principles and methods for rendering information not individually identifiable”
or
– “The following identifiers of the individual or of relatives, employers, or household members of the individual, are removed:”
Defining PHI - 18 identifiers
• Names
• Addresses (except State)
• Dates (except year) directly related to an individual, … and all ages over 89 and all elements of dates (including year) indicative of such age
• Phone numbers • Fax numbers
• Email addresses
• Social Security Numbers
• Medical Record Numbers
• Health plan beneficiary numbers
• Account numbers
• Certificate/license numbers
• Vehicle identifiers and serial numbers, including license plates • Device identifiers and serial numbers
• Website addresses
• Internet Protocol (IP) address numbers
• Biometric identifiers, including finger and voice prints • Full face photographic images and any comparable images