The PRISM Privacy Tool: A User’s Guide PHDSC Home Page  PRISM Web Page 

Slides:



Advertisements
Similar presentations
HIPAA In Relation to Other Federal Laws Professor Peter P. Swire Ohio State University Consultant, Morrison & Foerster LLP Glasser LegalWorks/HIPAA Conference.
Advertisements

Legal Work Group Developing a Uniform EHR/HIE Patient Consent Form.
Chapter 3 Health Care Information Systems: A Practical Approach for Health Care Management 2nd Edition Wager ~ Lee ~ Glaser.
HIPAA: Privacy, Security, and HITECH, Oh My! Presented by Stephanie L. Ganucheau, Special Assistant Attorney General.
Issue Brief National Association of School Nurses Privacy Standards for Student Health Records.
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
National Cancer Institute Cancer Therapy Evaluation Program (CTEP) presents: How to Obtain Protected Health Information (PHI) from an Outside Healthcare.
1 HIPAA and Research and YOU. 2 INTRODUCTION Rule #1:Don’t Panic Rule #2:Bottom Line for Researchers: HIPAA is Manageable thru Education/Awareness and.
1 Louisiana Department of Health and Hospitals Basic HIPAA Privacy Training: Policies and Procedures 01/09/
TM The HIPAA Privacy Rule: Safeguarding Health Information in Research and Public Health Practice Centers for Disease Control and Prevention Beverly A.
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996 (HIPAA)
2014 HIPAA Refresher Omnibus Rule & HIPAA Security.
Are you ready for HIPPO??? Welcome to HIPAA
Health Insurance Portability and Accountability Act (HIPAA)
Information Sharing and Cross-System Collaboration John Petrila, J.D., LL.M. Professor, University of South Florida
Implementation of Privacy Board Reviews at PCMC Mary Thomason, Intermountain Healthcare Privacy Board Chair.
Consent and Confidentiality for Children in New Mexico Liz McGrath Executive Director Pegasus Legal Services for Children.
August 10, 2001 NESNIP PRIVACY WORKGROUP HIPAA’s Minimum Necessary Standard Presented by: Mildred L. Johnson, J.D.
Your HIPAA rules Ben Burton, JD, MBA, RHIA, CHP, CHC Notice of Privacy Practices.
© Copyright 2014 Saul Ewing LLP The Coalition for Academic Scientific Computation HIPAA Legal Framework and Breach Analysis Presented by: Bruce D. Armon,
Version 6.0 Approved by HIPAA Implementation Team April 14, HIPAA Learning Module The following is an educational Powerpoint presentation on the.
CUMC IRB Investigator Meeting November 9, 2004 Research Use of Stored Data and Tissues.
2 H. Westley Clark, M.D., J.D., M.P.H., CAS, FASAM Director Center for Substance Abuse Treatment Substance Abuse Mental Health Services Administration.
HIPAA Health Insurance Portability & Accountability Act of 1996.
Notice of Privacy Practices Nebraska SNIP Privacy Subgroup July 18, 2002 Michael J. Brown, MHA, CPA Vice-President, Administrative & Regulatory Affairs,
1 VUMC Confidentiality Policy and HIPAA Implications for Clinical Research General Clinical Research Center Skills Workshop March 2, 2007 Gaye Smith Privacy.
Confidentiality, Consents and Disclosure Recent Legal Changes and Current Issues Presented by Pam Beach, Attorney at Law.
Colorado Children and Youth Information Sharing (CCYIS) Educational Stability Summit April 10, 2015.
Health Insurance Portability and Accountability Act (HIPAA)
Privacy, Confidentiality and Data Sharing Committee March 18, 2004.
Computerized Networking of HIV Providers Workshop Data Security, Privacy and HIPAA: Focus on Privacy Joy L. Pritts, J.D. Assistant Research Professor Health.
Utilizing the CMS Security Risk Assessment Tool Liz Hansen, PCMH CEC, ICD-10 PMC Special Consultant, GA-HITEC Member Manager, GaHIN
HIPAA Michigan Cancer Registrars Association 2005 Annual Educational Conference Sandy Routhier.
H I P A A T R A I N I N G Self Directed Module 7 Research Disclosures For Data Custodians START Click to begin…
© 2009 The McGraw-Hill Companies, Inc. All rights reserved. 1 McGraw-Hill Chapter 2 The HIPAA Privacy Standards HIPAA for Allied Health Careers.
Medical Law and Ethics, Third Edition Bonnie F. Fremgen Copyright ©2009 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved.
Copyright © 2009 by The McGraw-Hill Companies, Inc. All Rights Reserved. McGraw-Hill Chapter 6 The Privacy and Security of Electronic Health Information.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
Understanding HIPAA (Health Insurandce Portability and Accountability Act)
PricewaterhouseCoopers 1 Administrative Simplification: Privacy Audioconference April 14, 2003 William R. Braithwaite, MD, PhD “Doctor HIPAA” HIPAA Today.
HIPAA PRACTICAL APPLICATION WORKSHOP Orientation Module 1B Anderson Health Information Systems, Inc.
Policies for Information Sharing April 10, 2006 Mark Frisse, MD, MBA, MSc Marcy Wilder, JD Janlori Goldman, JD Joseph Heyman, MD.
Rhonda Anderson, RHIA, President  …is a PROCESS, not a PROJECT 2.
Privacy, Confidentiality and Data Sharing Committee May 24, 2005.
1 Public Health Data Standards Consortium Web-Based Resource Center Committee Vivian Auld National Library of Medicine NIH, HHS Michelle Williamson Centers.
Privacy, Security and Data Exchange Committee Annual Report 2009 PHDSC Home Page  PHDSC Annual Meeting November 12, 2009.
Privacy, Security and Data Sharing Committee Annual Report Oct. 2, 2007.
1 Public Health Data Standards Consortium Communication and Outreach Committee Michelle Williamson Health Informatics Specialist Centers for Disease Control.
©2002 by the National Committee for Quality Assurance NCQA: HIPAA Business Associate Presentation to the 6th National HIPAA Summit March 28, 2003 Patricia.
HIPAA Compliance Case Study: Establishing and Implementing a Program to Audit HIPAA Compliance Drew Hunt Network Security Analyst Valley Medical Center.
CH 10. Confidentiality A. Confidentiality about sensitive medical information is necessary to preserve the patient’s dignity. B. In order to receive payment.
Human Subjects Update E. Wethington, Chair, UCHS.
HIPAA TRIVIA Do you know HIPAA?. HIPAA was created by?  The Affordable Care Act  Health Insurance companies  United States Congress  United States.
Health Insurance Portability and Accountability Act (HIPAA) © 2013 Project Lead The Way, Inc.Principles of Biomedical Science.
COMMUNITY-WIDE HEALTH INFORMATION EXCHANGE: HIPAA PRIVACY AND SECURITY ISSUES Ninth National HIPAA Summit September 14, 2004 Prepared by: Robert Belfort,
Juvenile Legislative Update 2013 Confidential Records and Protected Disclosures.
HIPAA Training Workshop #3 Individual Rights Kaye L. Rankin Rankin Healthcare Consultants, Inc.
FERPA Family Educational Rights and Privacy Act
Health Insurance Portability and Accountability Act
Bridging the gap between the Individual Healthcare Plan (IHP) and the Individualized Educational Program (IEP) How Special Education and School Nurses.
The HIPAA Privacy Rule: Implications for Medical Research
HIPAA Administrative Simplification
Health Insurance Portability and Accountability Act
Disability Services Agencies Briefing On HIPAA
HIPAA Pros - Minimum Necessary
Presentation to The Fourth National HIPAA Summit
2003 Immunization Registry Conference
National Congress on Health Care Compliance
Making Your IRBs and Clinical Investigators HIPAA-Ready
The PRISM Privacy Tool: A User’s Guide
Presentation transcript:

The PRISM Privacy Tool: A User’s Guide PHDSC Home Page  PRISM Web Page 

What is PRISM?  A framework for understanding the basic legal privacy requirements for the use and disclosure of health information  Created to help public sector health programs understand and apply state and federal privacy laws to their activities

What is PRISM? (cont’d) An electronic, web-based tool Set up as web tables to easily access and focus information relevant to a specific situation Multiple tables created to inform all the common public sector health functions

Purpose of PRISM  Identifies and defines the baseline conditions and requirements that a government or other health entity must follow when using and disclosing specific types of health information  Organizes key privacy requirements related to uses and disclosures to provide direction to improve privacy policies, procedures, and compliance

What Information is in PRISM? Uses the HIPAA privacy rule to set the basic framework Incorporates other federal privacy laws, such as 42 CFR pt. 2 and FERPA, where relevant References common provisions in state law Focuses on DISCLOSURES of health information done by public programs

Includes other laws or requirements that may have an impact Provides additional information on how the requirement may be interpreted or applied in public programs What Information is in PRISM? (cont’d)

Why was PRISM developed? Address a gap in federal HIPAA privacy guidance HIPAA requirements do not always map to public sector health program activities

Why was PRISM developed? (cont’d) Public sector health programs often combine multiple activities and functions, so rule application can be confusing Useful for most payer and provider entities, whether public or private

Who developed PRISM? Developed through the Public Health Data Standards Consortium (PHDSC) Funded by the National Center for Health Statistics (NCHS) Development oversight provided by the Consortium’s Privacy, Security, and Data Sharing Committee (PSDSC)

Who developed PRISM? (Cont’d) Content developed by Consortium members: Walter Suarez, MD, PHDSC President Vicki Hohner, Co-Chair PSDS Committee Legal Reviewer: Joy Pritts, JD, Senior Policy Analyst and HIPAA Privacy expert, Georgetown University

How is PRISM structured? Three separate tables for common public sector health-related functions: Public Health Authority Provider Payer Focus is on disclosures of specific types of identifiable health information

How is PRISM structured? (cont’d) Tables organized by:  Disclosure Purpose  Treatment, Payment, Operations  Required by law (public health, health oversight)  Judicial/administrative proceedings, law enforcement

How is PRISM structured? (cont’d) Tables organized by:  Disclosure Purpose  Type of Information  HIV, immunizations, medical records  Separate section for minors  Separate table addressing who (as the individual) can control uses and disclosures and under what conditions

What information is in the PRISM tables? Tables divided into cells that contain information about specific disclosures HIPAA citation Type of disclosure (required vs. permitted) Information related to the disclosure (conditions, special requirements)

What information is in the PRISM tables (cont’d) ? HIPAA requirements of the disclosure Whether consent/authorization is required Whether minimum necessary applies If an accounting of disclosure is required Additional general state law issues/ requirements that may apply

Where can I find PRISM? PHDSC Home Page: PHDSC Home Page: PRISM Web Page: PRISM Web Page:

Introduction to PRISM Click on “Proceed to PRISM Privacy Tool” at bottom of this web page Click on “Proceed to PRISM Privacy Tool” at bottom of this web page

Understanding and Using PRISM Proceed down the page and click on “Government Entity Acting As….” Proceed down the page and click on “Government Entity Acting As….”

Understanding and Using PRISM

Government Entity Acting As… Proceed down the page and click on one of the Type of Disclosure tables Proceed down the page and click on one of the Type of Disclosure tables

Government Entity Acting As…

How do I use PRISM? (Cont’d) Click on a specific functional table to access the actual table This takes you to the grid of disclosure purposes for that table by specific data type

Click on a folder icon to access the content for a specific disclosure/data type This screen provides you with disclosure guidelines specific to this type of disclosure How do I use PRISM? (Cont’d)

Example #1 My program functions as a provider I want to disclose information on children’s immunizations for public health purposes 1.First click to access the Public Health Healthcare Provider table

Example #1 (Cont’d) 2. Then go to table 4, Disclosures Required by Law; for Public Health; etc., which covers disclosures for public health purposes

3. Look along the top for the Public health purpose column, then for Unemancipated minors information down the side, and click to open Example #1 (Cont’d)

4. Using the information in the cell: If an entity is performing public health activities as a provider, that disclosure is allowed without consent or authorization under HIPAA State laws define and control legal issues related to minors, but public health activities are normally not affected by these laws Example #1 (Cont’d)

Example #2 My program functions as a provider AND a public health authority I need to disclose HIV AIDS information for treatment purposes 1.First click to access the Provider table

Example #2 (Cont’d) 2. Then go to table 2, Disclosures for Treatment, Payment, and Health Care Operations, which contains specific information for TPO purposes

3.Look for the Treatment disclosures column, and the STD/AIDS row, and click on the cell to open Example #2 (Cont’d)

4.Then click on the Public Health Authority table, go to table 2, Disclosures for Treatment, Payment, and Health Care Operations, which contains specific information for TPO purposes Example #2 (Cont’d)

5.Look for the Treatment disclosures column, and the STD/AIDS row, and click on the cell to open Example #2 (Cont’d)

6.Using the information in both cells: If an entity is performing treatment activities as a provider, that disclosure is allowed without consent or authorization under HIPAA However, HIV information is often subject to stricter state protections, so state laws may require consent or authorization for some or all treatment activities If an entity is performing treatment activities as a public health authority, then that disclosure is not subject to the HIPAA requirements However, those treatment activities must be clearly identifiable as public health activities defined by law to qualify Example #2 (Cont’d)

PRISM Privacy Definitions and Resources

How can I provide feedback on PRISM? Feedback/Comment form: Your comments are critical to future revisions and enhancements to this tool

How can I provide feedback on PRISM? Feedback/Comment form: Your comments are critical to future revisions and enhancements to this tool

Other Consortium Products and Activities Products Websites Local health privacy case studies Activities Participate in state and national privacy and security projects (HISPC) Participate in national privacy and security standards harmonization (HITSP)

For more information About the Consortium and other Consortium products: Invite participation in Consortium activities Help produce more useful tools and information Consider joining the Consortium to further these and other efforts

Contact Information Walter G. Suarez, MD President and CEO Institute for HIPAA/HIT Education and Research Phone: Vicki Hohner, MBA Senior Consultant Fox Systems, Inc. Phone: