HIPAA – How Will the Regulations Impact Research?.

Slides:



Advertisements
Similar presentations
SIMPLIFYING PRIVACY: HIPAA PRIVACY STANDARDS AND RESEARCH Angela M. Vieira General Counsel Childrens Hospital and Health Center June 5, 2004.
Advertisements

HIPAA Privacy Rule “Standards for Privacy of Individually Identifiable Health Information” 45 CFR 160 and 164* *
HIPAA Privacy Rule and Research
1 The HIPAA Privacy Rule and Research This presentation will probably involve audience discussion, which will create action items. Use PowerPoint to keep.
HIPAA and Public Health 2007 Epi Rapid Response Team Conference.
NATIONAL FORUM ON YOUTH VIOLENCE PREVENTION: HIPAA PRIVACY RULE CONSIDERATIONS November 1, 2011 Iliana L. Peters, JD, LLM HHS Office for Civil Rights.
HIPAA, Privacy & Confidentiality Local Accountability for Research Protection in VA Facilities VA Office of Research & Development Baltimore, February.
COBB/DOUGLAS COMMUNITY SERVICES BOARD Confidentiality and Privacy of Consumer Information.
HIPAA – Privacy Rule and Research USCRF Research Educational Series March 19, 2003.
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
The Health Insurance Portability and Accountability Act of 1996– charged the Department of Health and Human Services (DHHS) with creating health information.
1 HIPAA and Research and YOU. 2 INTRODUCTION Rule #1:Don’t Panic Rule #2:Bottom Line for Researchers: HIPAA is Manageable thru Education/Awareness and.
What is HIPAA? This presentation was created by The University of Arizona Privacy Office, The Office for the Responsible Conduct of Research on March 5,
HIPAA Requirements for Patient Oriented Research
TM The HIPAA Privacy Rule: Safeguarding Health Information in Research and Public Health Practice Centers for Disease Control and Prevention Beverly A.
Informed Consent.
Training In HIPAA Privacy Regulations for Researchers and Research Staff Adapted from a presentation prepared by Human Subjects Division, University of.
Health Insurance Portability Accountability Act of 1996 HIPAA for Researchers: IRB Related Issues HSC USC IRB.
Implementation of Privacy Board Reviews at PCMC Mary Thomason, Intermountain Healthcare Privacy Board Chair.
HIPAA Compliance Strategies for Employers, METs, MEWAs and Taft Hartley Union Trust Funds The HIPAA Colloquium at Harvard University Presented by: Melissa.
University of Miami1 HIPAA Survival Skills An Introduction to HIPAA and Research University of Miami Human Subjects Research Office October 31, 2006 Evelyne.
1 HIPAA, Researchers and the IRB: Part Two Alan Homans, IRB Chair and Nancy Stalnaker, IRB Administrator.
HIPAA, Researchers and the IRB Alan Homans, IRB Chair and Nancy Stalnaker, IRB Administrator.
Informed Consent and HIPAA Tim Noe Coordinating Center.
HIPAA Health Insurance Portability & Accountability Act of 1996.
Health Insurance Portability and Accountability Act (HIPAA)
1 VUMC Confidentiality Policy and HIPAA Implications for Clinical Research General Clinical Research Center Skills Workshop March 2, 2007 Gaye Smith Privacy.
Paula Peyrani, MD Medical/Project Director, HIV Program at the 550 Clinic Assistant Director, Research Design and Development Clinical and Translational.
1 Research & Accounting for Disclosures March 12, 2008 Leslie J. Pfeffer, BS, CHP Office of the Vice President for Research Administration Office of Compliance.
Revised February 4, Health Insurance Portability and Accountability Act (HIPAA) HIPAA Privacy Rule: UCSF Education Module for Researchers, Research.
1 HIPAA OVERVIEW ETSU. 2 What is HIPAA? Health Insurance Portability and Accountability Act.
HIPAA Privacy and Research August 21, 2015
Computerized Networking of HIV Providers Workshop Data Security, Privacy and HIPAA: Focus on Privacy Joy L. Pritts, J.D. Assistant Research Professor Health.
1 Defense Health Agency Privacy and Civil Liberties Office Data Sharing Program Overview Ms. Rita DeShields DHA Data Sharing Compliance Manager August.
PwC Tissue Banking and Repositories – Human Subject Protections Privacy Protections Medical Research Summit Tom Puglisi, Ph.D. Friday March 7 – 9:15 am.
HIPAA and Research Basics for IRB Tim Atkinson Director, Research and Sponsored Programs Director, Institutional Review Board Research Privacy Officer.
H I P A A T R A I N I N G Self Directed Module 7 Research Disclosures For Data Custodians START Click to begin…
Medical Law and Ethics, Third Edition Bonnie F. Fremgen Copyright ©2009 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved.
HIPAA SURVIVAL SKILLS: An Update University of Miami1 Marisabel Davalos, M.S.Ed., CIP Associate Director of Educational Initiatives November, 2008.
Health Insurance Portability and Accountability Act (HIPAA) CCAC.
Understanding HIPAA (Health Insurandce Portability and Accountability Act)
FleetBoston Financial HIPAA Privacy Compliance Agnes Bundy Scanlan Managing Director and Chief Privacy Officer FleetBoston Financial.
University of Pennsylvania Health System 1 Session 3.02: Case Studies in Clinical Research Compliance Russell M. Opland, M.P.H., EMT-P Chief Privacy Officer.
Health Insurance portability and Accountability Act (HIPAA)‏
A Road Map to Research at Jefferson: HIPAA Privacy and Security Rules for Researchers Presented By: Privacy Officer/Office of Legal Counsel October 2015.
HIPAA and Human Subjects Research IRB Member CE May 2014 Slideshow by Sean Horkheimer.
06/20/03- revised1 Health Insurance Portability and Accountability Act (HIPAA) HIPAA Privacy Rule: UCSF Education Module for Researchers, Research Administrators,
Configuring Electronic Health Records Privacy and Security in the US Lecture b This material (Comp11_Unit7b) was developed by Oregon Health & Science University.
HIPAA Privacy Rule Positive Changes Affecting Hospitals’ Implementation of the Rule.
PwC Issues in HIPAA Research Compliance William R. Braithwaite, MD, PhD “Dr. HIPAA” HIPAA Summit 6 Washington, DC 27 March 2003.
Human Subjects Update E. Wethington, Chair, UCHS.
Final HIPAA Privacy Rule: The Research Provisions Julie Kaneshiro DHHS Office for Human Research Protections Phone: Fax:
HIPAA and RESEARCH 5 th Thursday May 31, Page 2.
HIPAA Privacy Rule Positive Changes Affecting Hospitals’ Implementation of the Rule Melinda Hatton -- Oct. 31, 2002.
HIPAA 2017 JHSPH IRB Clarifications and Changes
Institutional Review Board and Research Education
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA)
The HIPAA Privacy Rule: Implications for Medical Research
HIPAA Administrative Simplification
Disability Services Agencies Briefing On HIPAA
The HIPAA Privacy Rule and Research
Making Your IRBs and Clinical Investigators HIPAA-Ready
HIPAA Overview.
HIPAA Privacy & Security: Medical Research Context
Issues in HIPAA Research Compliance
Analysis of Final HIPAA Privacy Modification Rule
Research Compliance: The Research/Privacy Nexus
Office of the Vice President for Research Human Subjects Protection Program IRB Submission Process Module 4 - Health Insurance Portability and Accountability.
The Health Insurance Portability and Accountability Act
Presentation transcript:

HIPAA – How Will the Regulations Impact Research?

What is HIPAA? Health Insurance Portability and Accountability Act of 1996 (Privacy Rule) –November 1999 – DHHS proposed regulations –December 2000 – Final Rule published –August 2002 – New Final Rule published –December 2002 – Guidance Document published –Date of Compliance – APRIL 14, 2003

Covered Entities Health Plans (insurers and payors) Health Care Providers (VUMC) Health Care Clearinghouses (billing services)

Privacy Rule Protects: Individually Identifiable Health Information is defined as any information collected from an individual (including demographics) that is: created or received by a health care provider, health plan, employer, and/or health care clearinghouse relates to the past, present or future: –physical or mental health or condition of an individual, –the provision of health care to an individual; or –payment for the provision of health care to an individual; and –identifies the individual and/or there is reasonable basis to believe that the information can be used to identify the individual. (45 CFR )

Identifying Data Elements Names Addresses Dates Phone Numbers Fax Numbers Social Security Numbers Medical Record Number Health Plan Numbers Account Numbers Certificate/License Numbers VIN/License Plate Numbers Device Identifiers Names of Relatives Web URLs IP addresses Biometric Identifiers Photographs and comparable images Any other unique identifying number, characteristic, or code

HIPAA Terms PHI – Protected Health Information Use – data accessed and shared within the covered entity Disclosure – the providing of data outside of the covered entity, not including Business Associates Authorization – permission provided by the patient or legal representative to use or disclose the individual’s PHI Limited Data Set – group of data that is de- identified except for geographic location and dates

Data Use Agreement – document used to create and disclose a Limited Data Set Designated Record Set – The part of the medical record used for patient care/treatment Minimum Necessary Standard – under certain conditions the covered entity must limit the access to PHI Accounting of Disclosures – under certain conditions the covered entity must track disclosures of PHI, such as waiver of authorization HIPAA Terms Continued

How to Fit HIPAA into your Research?

How to Use or Disclose PHI for Research Purposes De-identified data Limited Data Set Authorization Waiver of Authorization

How to use or disclose PHI for research purposes (continued) De-identification –Remove all 18 identifiers; or –Statistical Certification – the information may be considered de-identified, if an independent, qualified statistician: a.Determines that the risk of re-identification of the data, alone or in combination with other data, is very small; and b.Documents the methods and results by which the health information is de-identified, and the expert makes his/her determination of risk. Note: the expert may not be the researcher or anyone directly involved in the research study.

Limit Data Set (LDS) –Allows access to PHI, with limited identifiable data elements, without an authorization or waiver of authorization –Requires a Data Use Agreement –Limited Data Set may include: –Dates –Geographic information (not street address) –Other unique identifying numbers, characteristics, or codes that are not expressly excluded How to use or disclose PHI for research purposes (continued)

What is a Data Use Agreement? The investigator must agree to the following: –Not to use or disclose the LDS for any purpose other than the research project or as required by law. –To use appropriate safeguards to prevent use or disclosure of the LDS other than as provided for by the agreement. –To report to VUMC any use or disclosure of the LDS not provided for by this agreement, of which he/she becomes aware, including without limitation, any disclosure of PHI to an unauthorized subcontractor. –To ensure that any agent, including a subcontractor, to whom he/she provides the LDS, agrees to the same restrictions and conditions that applies through the agreement to the Data Recipient with respect to such information. –Not to identify the information contained in the LDS or contact the individual.

Authorization –Participant provides authorization to use/disclose PHI as part of the informed consent process. MUST include the following elements: Specific description of the information to be used/disclosed Who may use or disclose To whom the PHI will be disclosed Why the use or disclosure is being made (each purpose) Statement of how long the use or disclosure will continue How to use or disclose PHI for research purposes (continued)

Notice that authorization may be revoked Notice that the information may be disclosed to others not subject to the Privacy Rule Notice that the covered entity (VUMC) may or may not condition treatment or payment on the individual’s signature Individual’s signature and date Authorization elements continued:

Waiver of Authorization –To be granted by the IRB and must meet the following criteria: The use or disclosure of PHI involves no more than minimal risk to the privacy of the individual. The PI must provide a plan to protect identifiers, a plan to destroy the identifiers as soon as possible, and a statement that the information will not be disclosed. The PI should provide justification as to why the research cannot be done without the waiver. How to use or disclose PHI for research purposes (continued)

The PI should provide justification as to why the research cannot be done without the PHI. The PI must provide a written assurance to the IRB that the PHI will not be re-used or disclosed except –As required by law, –For authorized oversight of the research, or –For other research that has been reviewed and approved by the IRB with specific approval regarding access to this PHI. How to use or disclose PHI for research purposes (continued)

Minimum Necessary Standard A covered entity (VUMC) must try to limit the use or disclosure of PHI to the minimum necessary to achieve the research purpose. This standard applies to the following: –Research pursuant to a waiver –Use/disclosure of decedent’s PHI –Uses preparatory to research –Limited Data Sets Minimum Necessary Standard does not apply to the following: –Treatment disclosures or requests –Use or disclosure made with an authorization –Disclosures to the individual –Disclosures to DHHS for compliance –Disclosures required by law

Accounting of Disclosures Patients have the right to request an accounting of disclosures of their PHI for past six years. Applies to disclosure of PHI pursuant to a waiver of authorization, disclosures required by law, and for public health purposes. Does not apply to disclosures pursuant to an authorization or to limited data set. The Privacy Office, not the IRB, will maintain a centralized database to track disclosures. This tracking requirement is the responsibility of the PI in conjunction with the Privacy Office.

Common Rule Privacy Rule Where the Common Rule (45 CFR 46) and the Privacy Rule (45 CFR 160 & 164) disagree, the IRB must act in the best interest of protection of human subjects and follow the regulation that is more restrictive.

What does not require IRB review? Preparatory to Research –defined as any action taken, where access to PHI is required, for assessing the research question/hypothesis such as accessing medical records or querying of databases to prepare a research protocol. The use or disclosure of the PHI is sought solely for the purpose of preparing a research protocol. The PHI will not be removed from the covered entity (VUMC). This PHI is necessary for the purpose of a research study.

Research on Decedents –Researchers may use and disclose a decedent’s PHI for research purposes without IRB review. –The following criteria must be met in the form of a statement to the covered entity (VUMC): The use will be solely for research on the PHI of a decedent. The PHI sought is necessary for the purposes of the research. The researcher has documentation of the death of the individual about whom information is being sought. What does not require IRB review? (Continued)

How do we get ready for HIPAA?

Transition Period April 14, 2003 IRB Approval Planned enrollment of subjectsPlanned research assessment period INFORMED CONSENT DOCUMENTS GRANDFATHERED HIPAA AUTHORIZATION RIDER IS NOT NEEDED

Transition Period April 14, 2003 IRB Approval Planned enrollment of subjectsPlanned research assessment period Informed consent documents - GRANDFATHERED Consent form(s) need HIPAA Authorization Language (Rider)

Transition Period April 14, 2003 IRB Approval Planned enrollment of subjects BUT the IRB has granted a WAIVER OF CONSENT Planned research assessment period Waiver of Authorization grandfathered and no action needed.

Transition Period April 14, 2003 IRB Approval Planned enrollment of subjectsPlanned research assessment period NEW Consent form(s) with HIPAA Authorization Language incorporated with Confidentiality Language

Transition Period April 14, 2003 IRB Approval Planned enrollment of subjects AND the study meets the criteria for Exempt under 45 CFR category (b) 4. Planned research assessment period Complete Affirmation/Data Set Agreement to obtain a Limited Data Set – This is included in the Exempt Application.

Transition Period April 14, 2003 IRB Approval Planned enrollment of subjects BUT the IRB has granted a WAIVER OF CONSENT Planned research assessment period Waiver of Authorization criteria must also be met and approved. This is a combined form currently available on the web.

Proposal Does this proposal involve the creating, using, and/or disclosing of PHI? Can the research be completed using a Limited Data Set? yes PI should complete a Data Use Agreement with Affirmation Statements. yes Waiver granted PI must track disclosures and minimum necessary applies. yes HIPAA Does Not Apply no Does the proposal meet HIPAA criteria for Waiver of Authorization? no PI must obtain Authorization from the participant. no Decision Path

What is the IRB currently doing to prepare for HIPAA? The IRB forms and template language are updated and on the website. Currently approved studies that will be enrolling beyond April 14, 2003 must have an authorization rider attached to the consent document. Template language for the HIPAA authorization rider is approved and on the website. New studies should choose the Confidentiality and Privacy of Health Information language in the template and modify to include study specific information.

VU Institutional Review Board is serving as the Privacy Board for Research for the VUMC Covered Entity. We are NOT serving as the Privacy Board for Research for institutions outside the Covered Entity (VUMC). These institutions will need their own authorization language and will be responsible for submission as an amendment, only if VU IRB is serving as the IRB of record or coordinating center. Sponsors are generally NOT covered entities. The IRB will not be incorporating sponsor’s language in the authorization for patients at VUMC. The VU IRB is not serving as the Privacy Board for Research for the VAMC. POINTS to REMEMBER

HIPAA IS COMING! Compliance Date: APRIL 14, 2003

Questions?

Additional Training Opportunities March 24, 2003 Preston Research Building, Room 206 1:30pm - 2:30pm March 31, Medical Center North 11:00am-12:00pm