 What is the Privacy Rule? The Standards for Privacy of Individually Identifiable Health Information (Privacy Rule) governs the use and disclosure of.

Slides:



Advertisements
Similar presentations
Tamtron Users Group April 2001 Preparing Your Laboratory for HIPAA Compliance.
Advertisements

0 Jumping through Two Hoops: the HIPAA Privacy Rule and State Law Compliance Issues Bruce Merlin Fried, Esq. The fifth National HIPAA Summit November 1,
Jumping through Two Hoops HIPAA and State Law Compliance Bruce Merlin Fried, Esq. HIPAA State Law and Preemption Audio Summit July 10, 2002.
HIPAA In Relation to Other Federal Laws Professor Peter P. Swire Ohio State University Consultant, Morrison & Foerster LLP Glasser LegalWorks/HIPAA Conference.
SIMPLIFYING PRIVACY: HIPAA PRIVACY STANDARDS AND RESEARCH Angela M. Vieira General Counsel Childrens Hospital and Health Center June 5, 2004.
Responding to Subpoenas and Law Enforcement Demands for PHI: An Overview Janet A. Newberg Chair, Health Law Section Felhaber Larson Fenlon & Vogt, P.A.
Jumping through Two Hoops HIPAA and State Law Compliance: the Problem of the Failure of Federal Preemption Bruce Merlin Fried, Esq. HIPAA Summit West II.
I.G. Subpoenas and the HIPAA Privacy Rule The views and opinions expressed in the presentation are those of the presenter, and not necessarily official.
How do they effect you everyday?
An Overview for In-Home Service Providers Legal advice must be tailored to specific circumstances. Information provided in this presentation should not.
HIPAA Privacy Rule “Standards for Privacy of Individually Identifiable Health Information” 45 CFR 160 and 164* *
HIPAA Basics Brian Fleetham Dickinson Wright PLLC.
HIPAA: Privacy, Security, and HITECH, Oh My! Presented by Stephanie L. Ganucheau, Special Assistant Attorney General.
P E N N S Y L V A N I A C O A L I T I O N A G A I N S T D O M E S T I C V I O L E N C E P E N N S Y L V A N I A C O A L I T I O N A G A I N S T RAPE HIPAA.
HIPAA PRIVACY REQUIREMENTS Dana L. Thrasher Constangy, Brooks & Smith, LLC (205) ; Victoria Nemerson.
North Carolina State University Health Information Privacy 4/16/03.
 Original Intent: ◦ Act passed in 1996 with two main goals: 1.Ensure individuals would be able to maintain their health insurance between jobs (the “portability”
Copyright 2006 Rubin Law Firm, LLC Drafting HIPAA Compliant Subpoenas & Discovery Presented by:RACHEL B. RUBIN Kansas Bar Association Annual Meeting June.
Health Insurance Portability and Accountability Act (HIPAA)
Objectives  Review federal statutes (HIPAA, FERPA)  Discuss state guidelines  Review local procedures
Consent and Confidentiality for Children in New Mexico Liz McGrath Executive Director Pegasus Legal Services for Children.
August 10, 2001 NESNIP PRIVACY WORKGROUP HIPAA’s Minimum Necessary Standard Presented by: Mildred L. Johnson, J.D.
Access to Mental Health Records and Related Issues Social Services Attorneys’ Conference March 10, 2006 Mark Botts School of Government, UNC.
HIPAA Compliance Strategies for Employers, METs, MEWAs and Taft Hartley Union Trust Funds The HIPAA Colloquium at Harvard University Presented by: Melissa.
Code of Federal Regulations Title 42, Chapter 1, Subchapter A Part 2 – CONFIDENTIALITY OF ALCOHOL AND DRUG ABUSE PATIENTS BRYANT D. MILLER CAC II, MAC,
Medical Records in Court: Life after HIPAA North Carolina Conference of Superior Court Judges, October 2003 Presented by Jill Moore, UNC School of Government.
Confidentiality of MH/DD/SA Records Family Court Conference March 9, 2006 Mark Botts School of Government, UNC.
HIPAA Health Insurance Portability & Accountability Act of 1996.
Banks and the Privacy of Medical Information 8 th National HIPAA Summit March 8, 2004 Joy Pritts, JD Health Policy Institute Georgetown University
1 VUMC Confidentiality Policy and HIPAA Implications for Clinical Research General Clinical Research Center Skills Workshop March 2, 2007 Gaye Smith Privacy.
HIPAA The Privacy Rule Health Insurance Portability and Accountability Act of 1996 (HIPAA) The 104 th Congress passed the Act, Public Law ,
1 Disclosures © HIPAA Pros 2002 All rights reserved.
Confidentiality, Consents and Disclosure Recent Legal Changes and Current Issues Presented by Pam Beach, Attorney at Law.
Confidentiality in Your TEAP Program By Diane A. Tennies, Ph.D., LADC Lead TEAP Health Specialist October 20,
Office of the Secretary Office for Civil Rights (OCR) Indian Health Service HIPAA Training Hosted by the Aberdeen Area Office July 24, 2012.
Computerized Networking of HIV Providers Workshop Data Security, Privacy and HIPAA: Focus on Privacy Joy L. Pritts, J.D. Assistant Research Professor Health.
Michael R. Costa, Esq., M.P.H. Greenberg Traurig, LLP One International Place, 3 rd Floor Boston, MA (fax)
Privacy and the Civil Commitment Process Allyson K. Tysinger Assistant Attorney General June 4-5, 2008.
Privacy and Confidentiality. Definitions n Privacy - having control over the extent, timing, and circumstances of sharing oneself (physically, behaviorally,
Health Insurance Portability and Accountability Act (HIPAA) CCAC.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
© 2013 The McGraw-Hill Companies, Inc. All rights reserved. Ch 8 Privacy Law and HIPAA.
HIPAA and State Law Compliance: the Problem of the Lack of Federal Preemption Clark Stanton HIPAA SUMMIT IV April 26, 2002 Clark Stanton HIPAA SUMMIT IV.
Davis Wright Tremaine LLP The Seventh National HIPAA Summit HIPAA Privacy: Privacy Rule Compliance on Public Health Activities and Research Thomas E. Jeffry,
Federal Preemption, and State Healthcare Privacy and Data Security Law and Regulation Fifth National HIPAA Summit October 30 – November 1, 2002 Mark Barnes.
Configuring Electronic Health Records Privacy and Security in the US Lecture b This material (Comp11_Unit7b) was developed by Oregon Health & Science University.
HIPAA Overview Why do we need a federal rule on privacy? Privacy is a fundamental right Privacy can be defined as the ability of the individual to determine.
HIPAA TRIVIA QUEST December Edition. I’ll ask the questions - and you’ll give the answers.
Health Insurance Portability and Accountability Act (HIPAA) © 2013 Project Lead The Way, Inc.Principles of Biomedical Science.
Disclaimer This presentation is intended only for use by Tulane University faculty, staff, and students. No copy or use of this presentation should occur.
Public Health IT Privacy, Confidentiality and Security of Public Health Information This material (Comp13_Unit2) was developed Columbia University, funded.
Juvenile Legislative Update 2013 Confidential Records and Protected Disclosures.
HIPAA Training Workshop #3 Individual Rights Kaye L. Rankin Rankin Healthcare Consultants, Inc.
Health Insurance Portability and Accountability Act
HIPAA CONFIDENTIALITY
HIPAA Administrative Simplification
HIPAA and 42 C.F.R. Part 2 Confidentiality
Health Insurance Portability and Accountability Act
HIPAA Pros - Disclosures
Confidential Records and Protected Disclosures
Disability Services Agencies Briefing On HIPAA
HIPAA Summit West The Hidden Trap: Compliance with State Law
HIPAA Summit VII The Hidden Trap: Compliance with State Law
CONFIDENTIALITY AND PRIVILEGE
2003 Immunization Registry Conference
National Congress on Health Care Compliance
Health Insurance Portability and Accountability Act
Health Insurance Portability and Accountability Act
HIPAA, The Next Level: HIPAA Preemption of State Laws
South Jordan City Fire Department
Presentation transcript:

 What is the Privacy Rule? The Standards for Privacy of Individually Identifiable Health Information (Privacy Rule) governs the use and disclosure of individuals’ health information (referred to as “protected health information” or “PHI”), by “covered entities.” Reference: 45 C.F.R (a)(1)-(3)(2012).

 HIPAA Provides Guidance The HIPAA Privacy Rule provides guidance on: What information needs to be protected (PHI) Who must protect PHI (covered entities, business associates) Responsibilities in protecting PHI

 Terms & Concepts Used in the HIPAA Privacy Rule Use and Disclosure of PHI Covered entities may only use or disclose PHI as permitted or required by the Privacy Rule. Use is the sharing, employment, application, utilization, examination, or analysis of …information within the entity… Disclosure is the release, transfer, provision of access to, or divulging in any other manner of information outside the entity. References: 45 CFR §§ ,

 Terms & Concepts Used in the HIPAA Privacy Rule Covered Entities A covered entity is: A health plan A health care clearinghouse A health care provider who transmits any health information in electronic form in connection with a covered transaction— one for which the Secretary has adopted standards.

 Requirements for Uses and Disclosures of PHI A covered entity must not use or disclose PHI, except as specifically permitted or required by the HIPAA Privacy Rule. References: 45 CFR § (a)

 Requirements for Uses and Disclosures of PHI The HIPAA Privacy Rule requires disclosure to the individual when the individual exercises the right to access PHI in designated record sets or the right to an accounting of disclosures Reference: 45 CFR § (a)(2)

 Requirements for Uses and Disclosures of PHI Required disclosures to the individual: The individual may be the patient, or in the case of an unemancipated minor, the “personal representative” of the individual. Thus parents, guardians or other people acting in loco parentis can exercise the right of the individual to obtain medical information. Reference: 45 C.F.R (g)(3).

 Recap The HIPAA Privacy Rule: “Federal Floor” of Privacy Protections First set of comprehensive federal health privacy protections Restricts uses and disclosures of PHI Provides rights for individuals who are the subject of PHI

 Preemption of State Law What is Preemption? The judicial principle asserting the supremacy of federal over state law. Two kinds: Field Preemption Conflict Preemption

 Definition of State Law Definition of State Law from 45 CFR § State law for HIPAA preemption purposes means provisions in: State constitution State statutes State regulations State rules State common law Any other state action having the force and effect of law

 Definition of Contrary Definition of “Contrary” Contrary, as it relates to the preemption of state law by HIPAA requirements, means: It would be impossible for a covered entity to comply with both the state and federal requirements (the impossibility test) OR The provision of state law is an obstacle to accomplishing the full purposes and objectives of the Administrative Simplification provisions of HIPAA (the obstacle test) Reference: 45 CFR. §

 Preemption of State Law – General Rule Under 45 CFR § , a HIPAA Rule provision that is contrary to a provision of state law preempts the state law, unless one of the specified exceptions applies.

 Preemption of State Law – Child Abuse and Public Health Important to dependency proceedings is the exemption contained within § (c), which provides: (c) The provision of State law, including State procedures established under such law, as applicable, provides for the reporting of disease or injury, child abuse, birth, or death, or for the conduct of public health surveillance, investigation, or intervention.

 Preemption of State Law – Child Abuse and Public Health …HIPAA expressly carved out state laws on child abuse and neglect from preemption or any other interference…. State laws continue to apply with respect to child abuse, and the final rule does not in any way interfere with a covered entity’s ability to comply with these laws. Reference: Standards for Privacy of Individually Identifiable Health Information, 65 Fed. Reg. 82,462, 82,527 (Dec. 28, 2000.)

 Conflict Minimization and the HIPAA Privacy Rule The HIPAA Privacy Rule is designed to minimize conflicts between its requirements and state law. Generally, state laws are not contrary. HIPAA Privacy Rule provides a federal floor and state laws that provide greater protection for PHI and more expansive privacy rights will not be affected.

 Conflict Minimization and the HIPAA Privacy Rule 45 CFR § provides permission to covered entities to make the uses and disclosures listed in the statute. Other uses/disclosures that do not require an authorization: Required by law Public health activities About victims of abuse, neglect, or domestic violence Health oversight activities Judicial and administrative proceedings Law enforcement purposes

 Conflict Minimization and the HIPAA Privacy Rule To date, OCR has not been presented with any state law that is contrary to a HIPAA provision. In each case, it has been possible to comply with both. If a state law were contrary, it would be preempted by HIPAA unless an exception applied.

 Recap State laws that are contrary to the regulations are preempted by the federal requirements unless a specific exception applies. The Privacy Rule provides a federal floor of privacy protections for individuals’ PHI. State laws that provide greater protections for PHI and greater privacy rights for individuals are generally not contrary to the federal requirements and will not be preempted. Where HIPAA permits disclosures that are required or permitted under state law, there is no conflict and so no preemption.

 Practice Pointers 1.Disclosure to the GAL is required by HIPAA The State of Florida stands in loco parentis with an abused, abandoned or neglected child. Accordingly, the State is a personal representative of the child for HIPAA purposes and should be treated as an individual for purposes of determining whether the disclosure is authorized under § (g)(3). As the court-appointed representative of the State, i.e., the child’s personal representative, the GALP’s access to the information is permitted by § (g).

 Practice Pointers 2.Child abuse and neglect laws are exempt from HIPAA’s provisions. There are exemptions and exclusions from HIPAA. The child abuse exemption provision of the statute should be read broadly to allow record sharing of information concerning children: “Although not generally thought of as public health related functions, investigative and intervention responses to child maltreatment clearly are public health matters, even if government social services or law enforcement agencies play the lead roles.” References: Howard Davidson, The Impact of HIPAA on Child Abuse and Neglect Cases (2003); 45 CFR §

 Practice Pointers 3. Disclosure is excluded from HIPAA under § (a)’s public benefits exception, because it is required by § : (3) Upon presentation by a guardian ad litem of a court order appointing the guardian ad litem: (b) A person or organization, other than an agency under paragraph (a), shall allow the guardian ad litem to inspect and copy any records related to the best interests of the child who is the subject of the appointment, including, but not limited to, confidential records. For the purposes of this subsection, the term “records related to the best interests of the child” includes, but is not limited to, medical, mental health, substance abuse, child care, education, law enforcement, court, social services, and financial records.

No notice for the order… why do they keep talking about drugs and alcohol?

 Practice Pointers CAUTION: Do not get caught in the § (e) trap Do not confuse HIPAA with 42 USC §§290dd - 2