HIPAA SURVIVAL SKILLS: An Update University of Miami1 Marisabel Davalos, M.S.Ed., CIP Associate Director of Educational Initiatives November, 2008.

Slides:



Advertisements
Similar presentations
SIMPLIFYING PRIVACY: HIPAA PRIVACY STANDARDS AND RESEARCH Angela M. Vieira General Counsel Childrens Hospital and Health Center June 5, 2004.
Advertisements

Open Library June 4, 2004 Informed Consent Process and Federal Regulations That Must Be Met to Waive Informed Consent Tracey Craddock Regulatory Compliance.
HIPAA Privacy Rule “Standards for Privacy of Individually Identifiable Health Information” 45 CFR 160 and 164* *
HIPAA Privacy Rule and Research
1 The HIPAA Privacy Rule and Research This presentation will probably involve audience discussion, which will create action items. Use PowerPoint to keep.
NATIONAL FORUM ON YOUTH VIOLENCE PREVENTION: HIPAA PRIVACY RULE CONSIDERATIONS November 1, 2011 Iliana L. Peters, JD, LLM HHS Office for Civil Rights.
HIPAA Privacy Rule Training
Copyright Eastern PA EMS Council February 2003 Health Information Portability and Accountability Act It’s the law.
HIPAA – Privacy Rule and Research USCRF Research Educational Series March 19, 2003.
1 HIPAA and Research and YOU. 2 INTRODUCTION Rule #1:Don’t Panic Rule #2:Bottom Line for Researchers: HIPAA is Manageable thru Education/Awareness and.
What is HIPAA? This presentation was created by The University of Arizona Privacy Office, The Office for the Responsible Conduct of Research on March 5,
HIPAA Requirements for Patient Oriented Research
TM The HIPAA Privacy Rule: Safeguarding Health Information in Research and Public Health Practice Centers for Disease Control and Prevention Beverly A.
Informed Consent.
HIPAA Privacy Rule Compliance Training for YSU April 9, 2014.
Jill Moore April 2013 HIPAA Update: New Rules, New Challenges.
HIPAA HIPAA Health Insurance Portability and Accountability Act of 1996.
Training In HIPAA Privacy Regulations for Researchers and Research Staff Adapted from a presentation prepared by Human Subjects Division, University of.
Health Insurance Portability Accountability Act of 1996 HIPAA for Researchers: IRB Related Issues HSC USC IRB.
Implementation of Privacy Board Reviews at PCMC Mary Thomason, Intermountain Healthcare Privacy Board Chair.
August 10, 2001 NESNIP PRIVACY WORKGROUP HIPAA’s Minimum Necessary Standard Presented by: Mildred L. Johnson, J.D.
University of Miami1 HIPAA Survival Skills An Introduction to HIPAA and Research University of Miami Human Subjects Research Office October 31, 2006 Evelyne.
Informed Consent and HIPAA Tim Noe Coordinating Center.
Health Insurance Portability and Accountability Act (HIPAA)
Notice of Privacy Practices Nebraska SNIP Privacy Subgroup July 18, 2002 Michael J. Brown, MHA, CPA Vice-President, Administrative & Regulatory Affairs,
1 VUMC Confidentiality Policy and HIPAA Implications for Clinical Research General Clinical Research Center Skills Workshop March 2, 2007 Gaye Smith Privacy.
University of Miami1 Privacy, Confidentiality & Security Marisabel Davalos, M.S.Ed., CIP Associate Director of Educational Initiatives November, 2008.
Paula Peyrani, MD Medical/Project Director, HIV Program at the 550 Clinic Assistant Director, Research Design and Development Clinical and Translational.
International Research & Research Involving Children K. Lynn Cates, MD Assistant Chief Research & Development Officer Office of Research & Development.
1 Research & Accounting for Disclosures March 12, 2008 Leslie J. Pfeffer, BS, CHP Office of the Vice President for Research Administration Office of Compliance.
Privacy and Security of Protected Health Information NorthPoint Health & Wellness Center 2011.
1 HIPAA OVERVIEW ETSU. 2 What is HIPAA? Health Insurance Portability and Accountability Act.
HIPAA Privacy and Research August 21, 2015
1 Defense Health Agency Privacy and Civil Liberties Office HIPAA Privacy Board Overview August 6, 2015.
Health Insurance Portability and Accountability Act (HIPAA)
Computerized Networking of HIV Providers Workshop Data Security, Privacy and HIPAA: Focus on Privacy Joy L. Pritts, J.D. Assistant Research Professor Health.
1 Defense Health Agency Privacy and Civil Liberties Office Data Sharing Program Overview Ms. Rita DeShields DHA Data Sharing Compliance Manager August.
HIPAA and Research Basics for IRB Tim Atkinson Director, Research and Sponsored Programs Director, Institutional Review Board Research Privacy Officer.
HIPAA – How Will the Regulations Impact Research?.
HIPAA’s Medical Privacy Standards: The Long and Really Winding Road Michael D. Bell, Esq. Mintz, Levin, Cohn, Ferris, Glovsky and Popeo, P.C. Washington,
H I P A A T R A I N I N G Self Directed Module 7 Research Disclosures For Data Custodians START Click to begin…
Medical Law and Ethics, Third Edition Bonnie F. Fremgen Copyright ©2009 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved.
Privacy and Confidentiality. Definitions n Privacy - having control over the extent, timing, and circumstances of sharing oneself (physically, behaviorally,
Health Insurance Portability and Accountability Act (HIPAA) CCAC.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
Understanding HIPAA (Health Insurandce Portability and Accountability Act)
Health Insurance portability and Accountability Act (HIPAA)‏
A Road Map to Research at Jefferson: HIPAA Privacy and Security Rules for Researchers Presented By: Privacy Officer/Office of Legal Counsel October 2015.
HIPAA and Human Subjects Research IRB Member CE May 2014 Slideshow by Sean Horkheimer.
06/20/03- revised1 Health Insurance Portability and Accountability Act (HIPAA) HIPAA Privacy Rule: UCSF Education Module for Researchers, Research Administrators,
HIPAA Overview Why do we need a federal rule on privacy? Privacy is a fundamental right Privacy can be defined as the ability of the individual to determine.
HIPAA Privacy Rule Positive Changes Affecting Hospitals’ Implementation of the Rule.
PwC Issues in HIPAA Research Compliance William R. Braithwaite, MD, PhD “Dr. HIPAA” HIPAA Summit 6 Washington, DC 27 March 2003.
Human Subjects Update E. Wethington, Chair, UCHS.
Final HIPAA Privacy Rule: The Research Provisions Julie Kaneshiro DHHS Office for Human Research Protections Phone: Fax:
HIPAA and RESEARCH 5 th Thursday May 31, Page 2.
HIPAA 2017 JHSPH IRB Clarifications and Changes
HIPAA Privacy Rule Training
Institutional Review Board and Research Education
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA)
What is HIPAA? HIPAA stands for “Health Insurance Portability & Accountability Act” It was an Act of Congress passed into law in HEALTH INSURANCE.
The HIPAA Privacy Rule: Implications for Medical Research
Disability Services Agencies Briefing On HIPAA
The HIPAA Privacy Rule and Research
HIPAA Privacy & Security: Medical Research Context
Issues in HIPAA Research Compliance
Analysis of Final HIPAA Privacy Modification Rule
Research Compliance: The Research/Privacy Nexus
Office of the Vice President for Research Human Subjects Protection Program IRB Submission Process Module 4 - Health Insurance Portability and Accountability.
Presentation transcript:

HIPAA SURVIVAL SKILLS: An Update University of Miami1 Marisabel Davalos, M.S.Ed., CIP Associate Director of Educational Initiatives November, 2008

Responsible for review, approval and monitoring of human subject research conducted by UM faculty, staff and students  Includes ensuring compliance with University of Miami HIPAA policies  Plan must contain elements required under HIPAA  Documentation of compliance with Covered Entity source of PHI University of Miami2

 Health Insurance Portability and Accountability Act (HIPAA) Effective on April 14, 2003  Federal law that protects the privacy of individually identifiable health information (PHI)  Title 45 of the Code of Federal Regulations Parts 160 and 164 University of Miami3

Covered Entity – Custodians of PHI They must make a good faith effort to comply with the rule Three types of “ Covered Entities”  Health Care Providers Includes organizations, individuals such as researchers when they provide health care, e.g. clinical trials  Health Care Plans Insurers and payors  Health Care Clearinghouses Billing services University of Miami4

 Hybrid Covered Entity  The University is not a covered entity. It is a hybrid entity with certain health care components covered by HIPAA and research components that may not be covered by HIPAA and that fall outside the “covered entity”. University of Miami5

6 UM – Hybrid Entity Covered Components Treatment Payment Health Care Operations Non-Covered Components Research

Investigators who do not access or create health information from/with the “covered entity” because they are acting solely as researchers and not health care providers are not considered part of the UM/JHS “covered entity” and are not subject to HIPAA regulations.  Necessary compliance with State privacy laws and Institutional and IRB policies only. University of Miami7

Obtained and access to PHI from a “covered entity” – those who create, use, or access health information while providing health care services to research subjects - must comply with HIPAA regulations as well as state privacy, institutional and IRB policies. University of Miami8

Clinical trials Chart reviews Epidemiological studies Behavioral and Social Science Studies Some basic science research activities  Studies may include the provision of treatment but others may provide neither treatment or diagnosis. University of Miami9

Section 24.2 of the HSRO Policies & Procedures contains some important terms related to HIPAA: PHI – protected health information derived from the past, present, future physical or mental health care of an individual managed by a covered entity RHI – Research-related health information, personally identifiable information distinct from PHI by not being associated with or derived from health care or payment for care. University of Miami10

Protected Health Information (PHI) is any individually identifiable information that is transmitted or maintained in electronic medium, or in any other form or medium  Medical Records E.g. Medical History, Diagnosis, Treatment  Payment Information E.g. Bills, Receipts  Ancillary Services E.g. X-Rays, Labs  Demographic Information (When Maintained with Health Information) E.g. Date of Birth, Social Security Number University of Miami11

When providing health care to individuals, researchers are considered health care providers When accessing existing protected health information, HIPAA privacy rules applies University of Miami12

1. Keep records of certain disclosures 2. Provide only minimally necessary information, including: a. Use pursuant to waiver b. Use preparatory to research c. Use of decedents’ PHI d. Use of limited data sets 3. Provide an accounting of certain disclosures, including: a. Use pursuant to waiver b. Use preparatory to research c. Use of decedents’ PHI Note: This requires significant resources, e.g. time and labor, as well as strong internal controls on the part of the covered entity. University of Miami13

 Investigators will need to go through the covered entity’s “HIPAA-Hoops” to obtain data  UM IRB will need to consider research subjects’ privacy rights University of Miami14

University of Miami15 How Can PHI be Obtained for Research?  Authorization (Form B)  Limited Data Set / Data Use Agreement (Form C)  Waiver of Authorization (Form F)  Certification for Review Preparatory to Research (Form E)  Decedent Certification (Form D)  De-Identification To Access PHI for Research:

University of Miami16

University of Miami17

 Each study participant permits Use & Disclosure of their PHI for research purposes  Must contain Privacy Notice provisions University of Miami18

University of Miami19 Authorization Core Elements:  Specific and meaningful description of information to be used or disclosed  Identification of the person or class of person releasing the information  Description of the investigator or class of persons receiving the information  Description of each purpose of the requested use or disclosure  Expiration date or event  Signature and date Authorization (Form B)

University of Miami20 Confidentiality Other Authorization Contents:  Individual right to revoke authorization  Covered entities are not permitted to condition treatment on the provision of authorization  Must explain potential for information to be re- disclosed by the recipient and that the recipient may not be required to comply with the Privacy Rule  Must be written in plain language  Copies must be provided to individual permitting the use and disclosure of PHI

 The IRB waives the authorization requirement  PI must justify the request for the waiver Note: Most applicable when obtaining authorization is impracticable E.g. Retrospective Medical Research, Identifiable Database Research University of Miami21

In order to obtain the waiver, researchers must justify the following criteria: The use or disclosure of PHI involves no more than a minimal risk to the privacy of individuals  Describe plan to protect identifiers e.g. Who has access to PHI?  Describe plan to destroy identifiers or return identifying information to the covered entity  Provide assurance that PHI will not be re-used or disclosed to others The research could not practicably be conducted without the waiver or alteration to the authorization; and The research could not practicably be conducted without access to and use of the PHI University of Miami22

Decedent PHI is health information collected from deceased (prior to the study) subject’s records. Investigator’s Certification for Research with Decedents (Form D) must be submitted. University of Miami23

University of Miami24

University of Miami25 HIPAA requires that use and disclosure of, and requests for, protected health information (PHI) must be limited to the “minimum necessary to accomplish the intended purpose.” Example: Only the information pertaining to a specific use should be given to researcher. Minimum Necessary Requirement

University of Miami26 The requirements for de-identifying information are so extensive that often the data is of limited value to researchers. The Privacy Rule permits the use and disclosure of PHI via a “limited data set” with a “data use agreement”. Limited Data Set

 Limited set of identifiers to be used for research, public health, and health care operations purposes  Permits use of some identifiable health information:  Five-Digit Zip Codes  City, State  Dates of Birth  Age Expressed in Years, Months, Days or Hours  Dates of Death  Dates of Admission/Discharge/Service  Excludes direct identifiers  Recipient enters into a “data use agreement” with covered entity in a form mandated by HIPAA (Form C)  Recipient enters into a “Business Associate Agreement” with covered entity University of Miami27

1. Defines who can use or receive data; 2. Defines for what purpose the data may be used; 3. Provides that PI will not re-identify the data or contact the subject; 4. Provides that data will be safeguarded & not used for unauthorized purposes; 5. Provides that researcher will report improper uses & disclosures; 6. Provides that researcher will “push down” privacy protection obligations to subcontractors. University of Miami28

University of Miami29  At UM, investigators will serve dual roles: BAs of the covered entity in order to access the PHI to create the limited data set; and investigator/recipient of the LDS.  Prior to disclosing PHI to the business associate, UM is required to enter into a written agreement with the BA that imposes specified safeguards on the PHI used or disclosed by the BA. HIPAA Business Associate (BA)

 Form mandated by HHS, in which the recipients satisfactorily assures the covered entity (UM/JHS) that they will protect the information from further disclosure.  Before data is released, there needs to be specific descriptions of the methods the recipient will use to assure that the privacy of the information is protected. This is to be documented in a data use agreement or business associate agreement, depending on the situation. University of Miami30

University of Miami31

Physicians in the clinical setting may disclose identifying patient information to a researcher who wishes to recruit the patient for a study provided…  The physician first obtains the patient’s signed authorization to disclose the information to the researcher so the patient can be contacted. University of Miami32

Jackson Health System (JHS)  Physicians who identify patients eligible for a research study must use the JHS form to obtain the patient’s authorization to release information to the researcher  Form Available on HSRO Website, “JMH Research Authorization” UM  A research referral authorization form is still being devised. University of Miami33

HIPAA regulations grant individuals the right to receive an accounting of disclosures of their PHI made by a covered component for the six years prior to the request or since the applicable compliance date. Records must include specific information regarding each disclosure. University of Miami34 WAIVERS

The Privacy Rule allows a simplified accounting by Covered Entities for disclosures of PHI for research purposes without an individual’s authorization. Under simplified accounting provisions, covered entities may provide individuals with a list of all protocols for which PHI has been disclosed, as well as the researcher’s name and contact information. University of Miami35

University of Miami36 General Rules For Use and Disclosure of PHI for Research: Disclosures made pursuant to an IRB waiver of authorization Authorized disclosures (Authorization) Disclosures made pursuant to certifications PHI furnished in limited data sets Accounting Required Accounting NOT Required Accounting for Disclosures (Attachment 45):

University of Miami37 General Rules For Use and Disclosure of PHI for Research: Disclosures made pursuant to an IRB waiver of authorization Disclosures made pursuant to certifications Accounting Required  UM must complete an accounting for disclosures form (G) and submit form to privacy office and disclose PHI to research staff.  Disclosure forms must be completed by the PI for each patient participating in the study.

Covered Entities may use and disclose PHI that was received or created for research before the compliance date (April 14, 2003) if they obtained one or more of the following prior to the compliance date:  An authorization or other express legal permission from an individual to use or disclose PHI for research purposes  The informed consent of the individual to participate in research  A waiver of informed consent granted by the IRB University of Miami38

HSRO has “Written Policies and Procedures for the Protection of Human Research Subjects”. Section, 24 specific to Privacy, Security, Confidentiality, and HIPAA were revised on August 6 th, Policies are available on our website under, “Investigator Resources”. University of Miami39

Evelyne Bital, MS, CIP  Associate Director of Privacy & Regulatory Affairs, (305)  For general HIPAA information or to access standard HIPAA forms for research:  hsro.med.miami.edu University of Miami40

Federal Regulations for HIPAA 45 CFR 160 and 45 CFR 164 University of Miami HIPAA Policies and Procedures University of Miami

University of Miami42