Medical Privacy in a Broader Privacy Context Professor Peter P. Swire George Washington Law School Former Chief Counselor for Privacy, U.S. Govt. HIPAA.

Slides:



Advertisements
Similar presentations
“Maintaining Trust in an Electronic World”
Advertisements

Why the Financial Privacy Law is Better than People Think Professor Peter P. Swire Ohio State University University of Minnesota Symposium February 9,
Telecom, Privacy & Security After September 11 Professor Peter P. Swire Ohio State University Ohio Telecommunications Industry Association October 2, 2001.
The United States, Privacy, and Data Protection Peter P. Swire Dutch Embassy Presentation January 19, 2001.
Privacy and the Internet Professor Peter P. Swire Ohio State University National Press Foundation February 14, 2001.
Privacy & Security After September 11 Professor Peter P. Swire Ohio State University University of Michigan Lecture December 4, 2001.
Privacy and National Security After September 11 Professor Peter P. Swire Ohio State University FLICC 2002 Forum Library of Congress March 19, 2002.
The Chief Privacy Officer for the U.S. Government Professor Peter P. Swire Ohio State University Visiting, George Washington University Privacy Officers.
"Security and Privacy After September 11 Professor Peter P. Swire Ohio State Law School Consultant, Morrison & Foerster Privacy & Data Security Summit.
Reflections on the White House Privacy Office Peter P. Swire U.S. Chief Counselor for Privacy, OSU College of Law, 2001-present CFP, March 8,
Electronic Surveillance, Security, and Privacy Professor Peter P. Swire Ohio State University InSITes -- Carnegie Mellon February 7, 2002.
Why E-Commerce is Like a Bottle of Tylenol Professor Peter P. Swire Ohio State Law School Conference on New Technologies and International Governance February.
"Security and Privacy After September 11: The Healthcare Example Professor Peter P. Swire Ohio State University Consultant, Morrison & Foerster LLP April.
HIPAA In Relation to Other Federal Laws Professor Peter P. Swire Ohio State University Consultant, Morrison & Foerster LLP Glasser LegalWorks/HIPAA Conference.
"Embedding Privacy in Federal Information Systems" Professor Peter P. Swire Ohio State University Consultant, Morrison & Foerster LLP MITRE Corp. Workshop.
Sharing of Medical Records Pursuant to an Authorization Professor Peter P. Swire Moritz College of Law, Ohio St. Univ. Consultant, Morrison & Foerster,
Privacy in America: Your Role as Guardians of the Publics Data Professor Peter P. Swire Moritz College of Law The Ohio State University Ohio Digital Government.
Research and Privacy Under HIPAA Professor Peter P. Swire Moritz College of Law Ohio State University National Academy of Science Panel on Science, Technology.
The Role of the Federal Government in Privacy Policy Professor Peter P. Swire The Ohio State University Center for American Progress The Privacy Symposium,
"Security and Privacy After September 11: Implications for Healthcare" Professor Peter P. Swire George Washington Law School Consultant, Morrison & Foerster.
Mental Health Issues & Information Sharing Professor Peter P. Swire The Ohio State University NAAG Task Force on School Safety July 5, 2007.
Reflections on the White House Privacy Office Peter P. Swire Ohio State University Center for American Progress N.C. State Privacy Day January 29, 2008.
The Need for Government-Wide Privacy Policy Professor Peter P. Swire Ohio State University Consultant, Morrison & Foerster, LLP DHS Privacy Advisory Committee.
Health IT & Privacy: Is there a path to consensus? Anyone today who thinks the privacy issue has peaked is greatly mistaken… we are in the early stages.
HEALTH I.T. and PRIVACY Breaking the gridlock Breaking the gridl ck.
HIPAA AWARENESS TRAINING
IT Security Policy Framework
The Family Educational Rights & Privacy Act (FERPA) & other statutes related to student information.
WRSU Customer Service The Beauty of Change. Privacy and Confidentiality.
HIPAA and Privacy An Overview of the New Federal Requirements of the Health Insurance Portability and Accountability Act (HIPAA) Reid Cushman, UM Ethics.
HIPAA Training for Pharmaceutical Industry Representatives University of Utah Hospitals & Clinics.
Privacy Laws & Higher Education. Agenda 1.Five Privacy Laws a.FERPA b.HIPAA c.GLB d.FACTA Disposal Rule e.CAN-SPAM 2.Overview of the Laws a.What does.
ITEC 6324 Health Insurance Portability and Accountability (HIPAA) Act of 1996 Instructor: Dr. E. Crowley Name: Victor Wong Date: 2 Sept
COMPLYING WITH HIPAA PRIVACY RULES Presented by: Larry Grudzien, Attorney at Law.
HIPAA THE PRIVACY RULE Reviewed December HISTORY In 2000, many patients that were newly diagnosed with depression received free samples of anti-
Implementation of Privacy Board Reviews at PCMC Mary Thomason, Intermountain Healthcare Privacy Board Chair.
Privacy in Ontario Brian Beamish Office of the Information and Privacy Commissioner/Ontario Presentation to Security Canada Central 2002 International.
Disclaimer This Presentation is provided “as is” without any express or implied warranty. This Presentation is for educational purposes only and does not.
FAMILY EDUCATIONAL RIGHTS AND PRIVACY ACT Electronic Signatures This work is the intellectual property of the author. Permission is granted for this material.
The University of Kansas Medical Center Shadow Experience Training.
Banks and the Privacy of Medical Information 8 th National HIPAA Summit March 8, 2004 Joy Pritts, JD Health Policy Institute Georgetown University
Electronic Records Management: What Management Needs to Know May 2009.
“Privacy and the Future of Justice Statistics” Peter P. Swire Chief Counselor for Privacy OMB/OIRA National Conf.on Privacy, Technology & Criminal Justice.
HIPAA The Privacy Rule Health Insurance Portability and Accountability Act of 1996 (HIPAA) The 104 th Congress passed the Act, Public Law ,
Can We Have EHRs and Privacy Too? Dr. Alan F. Westin Professor of Public Law and Government Emeritus, Columbia University; Principal, Privacy Consulting.
HIPAA EFFECTS OF HEALTH CARE LEGISLATION. Evaluation of the influences of HIPAA  How it affected health care system  How it works as a law  Changes.
Computerized Networking of HIV Providers Workshop Data Security, Privacy and HIPAA: Focus on Privacy Joy L. Pritts, J.D. Assistant Research Professor Health.
HIPAA Michigan Cancer Registrars Association 2005 Annual Educational Conference Sandy Routhier.
Copyright © 2009 by The McGraw-Hill Companies, Inc. All Rights Reserved. McGraw-Hill Chapter 6 The Privacy and Security of Electronic Health Information.
Where Did HIPAA Come From? “HIPAA Then and Now” Peter Swire Georgia Tech Scheller College of Business Alston & Bird LLP IAPP-Las Vegas 2015.
HIPAA BASIC TRAINING Presented by Anderson Health Information Systems, Inc.
Robert Guerra Director, CryptoRights Foundation Implementing Privacy Implementing Privacy: Rules of the Game for Developers Mac-Crypto Conference on Macintosh.
Patient Confidentiality and Electronic Medical Records Ann J. Olsen, MBA, MA Information Security Officer and Director, Information Management Planning.
HIPAA THE PRIVACY RULE. 2 HISTORY In 2000, many patients that were newly diagnosed with depression received free samples of anti- depressant medications.
C HAPTER 34 Code Blue Health Sciences Edition 4. Confidentiality of sensitive information is an important issue in healthcare. Breaches of confidentiality.
HIPAA History March 3, HIPAA Ruling Health Insurance Portability Accountability Act Health Insurance Portability Accountability Act Passed by Congress.
Copyright © 2015 by Saunders, an imprint of Elsevier Inc. All rights reserved. Chapter 3 Privacy, Confidentiality, and Security.
Data Security & Privacy: Fundamental Risk Mitigation Tactics 360° of IT Compliance Anthony Perkins, Shareholder Business Law Practice Group Data Security.
Roundtable on Privacy in Transition: Is Privacy Policy Working in the Healthcare Sector?
The Health Insurance Portability and Accountability Act of 1996 “HIPAA” Public Law
The Medical College of Georgia HIPAA Privacy Rule Orientation.
New Hire HIPAA Orientation. HIPAA Overview HIPAA is an acronym that stands for the Health Insurance Portability and Accountability Act of HIPAA.
What is HIPAA? Health Insurance Portability and Accountability Act of HIPAA is a major law primarily concentrating on the prolongation of health.
Reid Cushman, UM Ethics Programs
Disability Services Agencies Briefing On HIPAA
Employee Privacy and Privacy of Employee Information
Health Care: Privacy in a Digital Age
Introduction to Health Privacy
The Health Insurance Portability and Accountability Act
Lesson 1: Introduction to HIPAA
Presentation transcript:

Medical Privacy in a Broader Privacy Context Professor Peter P. Swire George Washington Law School Former Chief Counselor for Privacy, U.S. Govt. HIPAA West Conference June 22, 2001

Overview n Actions as Chief Counselor for Privacy n Are they picking on doctors? n What has changed with medical records n The HIPAA privacy rule

I. Actions as Chief Counselor, 1999 to early 2001 n HIPAA medical privacy: WH coordinator n Genetic Discrimination Executive Order n Gramm-Leach-Bliley: before, after, regs n Internet privacy; encryption; safe harbor; federal websites and databases; computer security; public records; and so on n Presidential Privacy Archives, at

II. Are They Picking on Doctors: Some U.S. Privacy Laws n Fair Credit Reporting Act, 1970 n Privacy Act, 1974 (federal agencies) n Family Educational Rights and Privacy Act, n Right to Financial Privacy Act, 1978 n [medical legislation proposed, 1970s] n Cable Communications Policy Act, 1984 n Electronic Communications Privacy Act, 1984

U.S. Privacy Laws (cont.) n Video Privacy Protection Act, 1988 n Employee Polygraph Protection Act, 1988 n Telephone Consumer Protection Act, 1991 n Drivers Privacy Protection Act, 1994, 1999 n Telecommunications Act, 1996 n HIPAA, 1996 n Childrens On-Line Privacy Protection Act, 1998 n Gramm-Leach-Bliley Act, 1999 (financial)

II. What has changed for medical records? n From paper to electronic records n More actors see the data n How to create patient trust?

Paper to Electronic n History of mostly paper records n Recently enter some records electronically for payment and other purposes n Soon will be mostly electronic records

How is Electronic Different? n Much more permanent storage n Much easier to link databases n Often, much more detailed information – Digital Angel reports vital signs remotely n Thus, more people see more data for longer

More Actors See the Data n History of paper records in the general practitioners office n Medical subspecialties – More doctors and nurses see it n HMOs and insurers – Managed care uses data intensively

More Actors See the Data n Oversight, audit, accreditation n Outsourcing (back office), joint ventures n Research n Many of these activities are across state lines, so limited effect of state confidentiality laws

Do Consumers Trust the Change? n 90 percent of Americans say they have lost all control over their personal information n WSJ poll 9/99: erosion of personal privacy as greatest fear for the new century n 1 in 6 Americans have misreported to a doctor due to privacy concern

IV. HIPAA Medical Privacy n In light of these changes: – Key points from the March comments – The politics of HIPAA and privacy – Re-discovering why the rule makes sense

Key points from March n Overwhelming procedural burden if repeal – 52, ,000 + many more comments – Perhaps 100 to 200 distinct policy issues – Each decision must be made and then justified on the basis of the record – If repeal, likely no medical privacy protection in place until 2004 and likely much later

Key points from March n The link between administrative simplification and privacy – Clear statutory and policy basis for expanding electronic flows and protecting privacy n A strong lawsuit if repeal – Statutory deadline of rule by 2000 – Link with administrative simplification – Legal and political impact if unlawful

Key points from March n Statements by President Bush to guarantee the privacy of medical records n My March recommendation: permit the December rule to go into effect while announcing a speedy process for clarifying a few key issues where changes are lawful and appropriate n Thats what happened (though I differ on which issues to change)

HIPAA and Privacy Politics n Political consensus that need legal protection of medical records n If had repealed the rule, then straight line from arsenic to global warming to guaranteeing the right of companies to market your medical records n Likely result in lawsuit that was unlawful to repeal the rule

HIPAA and Privacy Politics n Reports that President Bush sincerely believes in privacy protection n So, decision to keep the December rule n Significant possibility, after the HIPAA decision, that there will be some additional political activity on privacy by this Administration, beyond medical area n Query: is the HIPAA rule good politics but bad policy?

Rediscovering why the medical privacy rule makes sense n The rule is not radical -- it reinstitutes state medical confidentiality law for an era where records are shared nationally & electronically n Basic structure: – Information flows quite freely for treatment, payment, and health care operations – Patient consent needed for other transfers – Rules for balancing interests for research, public health, law enforcement, etc.

Business Associates n Imagine a hospital that hires a computer firm to handle its entire back office n Without coverage for business associates, then all those hospital records are totally unprotected n So, need business associates rule with contractual understandings

Scope of rule n Proposed rule scope for electronic records and information contained elsewhere in electronic form; asked for comments n Oral: should your statements to psychiatrist be covered? n Written: coverage for a written HIV test? n So, rule only makes with broader scope, and thats lawful

Required new information flows? n None. n 2 exceptions: – Patient access – For specific privacy enforcement actions n So, no reduction in privacy from the rule

Accounting n Industry concern that will be hard to log when patient records are disclosed for other than treatment, payment, & operations n But, says MIS community, this sort of accounting is a standard feature in the patient management systems coming on the market

Preemption n Statute was clear -- HHS had no discretion n For civil & consumer rights, tradition is to allow states to provide greater protections n Can you create a consensus process in your state for which laws apply?

Consent n Proposed rule: no consent for treatment, payment, health care operations n AMA and others argued that patient autonomy and medical ethics require patient consent; final rule takes this view n One issue to fix: prescription records and prior consent

Summary on HIPAA n Substance held up to scrutiny n Many of the criticisms were not valid: see Myths and Realities about HIPAA at n HIPAA will be a major source of practical experience at building confidentiality into computer systems

Concluding Thoughts n As medical care shifts to electronic records, privacy & security need to be built in n The most sensitive data deserves the greatest protection, and people consider medical the most sensitive n After 25 years of debate, is time to institutionalize good medical privacy practices n In closing, a common-sense test:

President Clinton, at Aspen Institute: Do you have privacy policies you can be proud of? Do you have privacy policies you would be glad to have reported in the media? If so, your policies are far more likely to survive, and help your organization prosper, in the information age.

Contact Information n Professor Peter Swire n Phone: (301) n n Web: n Presidential Privacy Archives: