The Bernard Health Institute
HIPAA Privacy Policy
HIPAA – Privacy Compliance
Definition:
The HIPAA Privacy ensures that personal medical information shared with physicians, hospitals, and others who provide and pay for healthcare is protected. The Privacy Rule does the following:
- Imposes new restrictions on the use and disclosure of personal health information
- Gives patient/clients greater access to their medical records
- Gives patient/clients greater protections of their medical records
Protected Health Information (PHI)
When a patient/client gives personal health information to a covered entity, that information becomes Protected Health Information or (PHI). It includes:
- Any personal health information that contains information that connects the patient/clients to the information.
- Information that might connect personal health information to the individual patient/client, including the individual’s name, all geographical identifiers smaller than a state, phone numbers, fax numbers, email addresses, social security numbers, account numbers, certificate/license number, full face photographic images, or other comparable images, and other unique identifying number, characteristic, or code, except the unique code assigned, by the investigator, to code the data.
PHI May Be Used or Disclosed:
- For treatment, payment, and healthcare operations
- With authorization, or agreement, from the individual patient/client
- For incidental uses, such as physicians talking to patient/clients, in a semi-private room
PHI Must Be Released for Use and Disclosure:
- When requested, or authorized, by the individual, although some exceptions may apply
- When required, by the Department of Health and Human Services (HHS), for compliance or information
Signed Authorization from The Patient/Client Is Required If His/Her PHI Is Used for Purposes Other Than:
- Treatment
- Payment
- Healthcare Operations
This includes:
- Use, or disclosure, of psychotherapy notes (except for treatment, payment, or healthcare operations).
- For use, and disclosure, to third parties for marketing activities, such as selling lists of patient/clients and enrollees.
- Covered entities can freely communicate with patient/clients, about treatment options, and health-related information.
Authorization Forms Must Contain:
- A description of the PHI to be used/disclosed, in clear language.
- Who will use/disclose PHI and for what purpose.
- Whether, or not, it will result in financial gain, for the covered entity, and the patient/client’s right to revoke the authorization.
- A dated signature of the patient/client whose records are being used/disclosed.
- An expiration date.
Authorization Is NOT Required as Long as There Is Patient/Client Agreement as Follows:
- To maintain a facility’s patient/client directory.
- To inform family members, or surrogates, or notify them on patient/client location, condition, or death.
- To inform appropriate agencies, during disaster relief.
Other permitted uses/disclosures that do not require patient/client agreement include:
- Public health activities related to disease prevention or control.
- Reporting victims of abuse, neglect, or domestic violence.
- Conducting health oversight activities such as audits, legal investigations, licensure, or for certain law enforcement purposes or government functions.
- For coroners/medical examiners, funeral directors, tissue/organ donations, or certain research purposes.
- To avert a serious threat to health and safety.
In General, Use/Disclosure of PHI Is Limited to the Minimum Amount of Health Information Necessary. This Means:
- Covered entities must develop policies to reduce health information sharing, to a minimum.
- Employees must be identified, who regularly access PHI.
- The type of PHI needed, and the conditions presented for access, must be monitored.
- The Minimum Necessary Rule does not apply to use/disclosure of medical records for treatment, since healthcare providers need the entire record to provide quality care.
Privacy Notice:
Patients have the right to give adequate notice, concerning the use/disclosure of their PHI, on the first date of service delivery, or as soon as possible, after an emergency. New notices must be issued when facility’s privacy practices change.
The Privacy Notice must:
- Contain patient’s rights and the covered entities’ legal duties
- Be made available to patients, in print
- Be displayed, at the site of service, or posted on a web site, if possible.
Once a patient has received notice of his/her rights, covered entities must make an effort to get written acknowledgment of receipt of notice from the patient, or document reasons why it was not obtained. Copies must be kept of all notices and acknowledgments.
Patient Privacy Rights:
The Privacy Rule grants patients new rights over their PHI, including the following:
- Receive a Privacy Notice, at the time of first delivery of service
- Restrict use, and disclosure, although the covered entity is not required to agree
- Have PHI communicated to them, by alternate means, and at alternate locations, to protect confidentiality
- Inspect, correct, and amend PHI and obtain copies, with some exceptions
- Request a history of non-routine disclosures, for six years, prior to the request
- Contact designated persons regarding any privacy concerns, or breach of privacy, within the facility, or at HHS.
Privacy Rights of Minors:
In general, parents have the right to access, and control, the PHI of their minor children, except when state law overrides parental control. Examples include:
- HIV testing of minors, without parental permission
- Cases of abuse
- When parents have agreed to give up control, over their minor child.
Agency Compliance with HIPAA: In order to comply with HIPAA regulations, the Agency will:
- Allow patients to see, and copy, their PHI.
- Designate a full or part-time privacy official responsible for implementing the programs.
- Designate a contact person, or office, responsible for receiving complaints.
- Develop a Notice of Privacy Practices document.
- Develop policies and safeguards to protect PHI and limit incidental use or disclosure.
- Institute employee-training programs, so everyone knows about the privacy policies and procedures for safeguarding PHI.
- Institute a complaints process and file and resolve formal complaints.
- Make sure contracts with business associates comply with the Privacy Rule.
Uses and Disclosures of Protected Health Information
Purpose:
To ensure that disclosure of Protected Health Information (PHI) is made consistent with applicable laws, regulations, and health information standards; to ensure that any disclosures of a patient/client’s PHI to family members, other relatives, close friends, or other persons designated, by the patient/client, are appropriate.
Policy:
-
Disclosure of PHI will only be allowed with a properly completed and signed authorization, except:
- When required or allowed by law
-
As defined in the Notice of Privacy Practices:
- For continuing care (treatment)
- To obtain payment for services (payment)
- For the day-to-day operations of the Agency, and the care given to the patient/clients, Disclosure of PHI will be centralized through the Privacy Officer. In some instances, the Privacy Officer will need to track information that is disclosed.
- All disclosures designated, as trackable, must be approved by the Privacy Officer to enable the Agency to provide an accounting of disclosures, when requested.
- Disclosure of PHI will be carried out in accordance with all applicable legal requirements, and in accordance with Agency policy. The Agency will be responsible for researching, and abiding by, applicable state laws and regulations.
- Original Medical Records will not be removed from the premises except when ordered, by subpoena, or by other court order.
Procedure:
Receiving a Request for Medical Records:
- Requests for Medical Records shall be managed by the Privacy Officer.
- Other staff members will not release PHI, without approval of the Privacy Officer.
- Only emergency release of information will be done, after hours, or on weekends.
- After hours, and on weekends, release of information for continuing care (i.e., transfer to a hospital), is allowed.
Responding to Specific Types of Disclosures:
- Media: No PHI shall be released to the news media, or commercial organizations, without the authorization of the patient/client or their legal representative.
- Telephone Requests: Employees receiving requests for PHI, via the telephone, will make reasonable efforts to identify, and verify, that the requesting party is entitled to receive such information.
Disclosures to Persons Involved with a Patient/Client’s Care:
-
The Agency may disclose, to a family member, other relative, close friend, or any other person
identified, by the patient/client, PHI:
- That is directly relevant to that person’s involvement with the patient/client’s care, or payment for care; or
- To notify such person of the patient/client’s location, general condition, or death.
-
If the patient/client is present for, or otherwise available, prior to a permitted disclosure, then
the Agency may use, or disclose, the PHI, only if the Agency:
- Obtains the patient/client’s agreement;
- Provides the patient/client with an opportunity to object to the disclosure, and the patient/client does not express an objection (this opportunity to object and the patient/client response may be done orally); or
- May reasonably infer from the circumstances based on the exercise of professional judgment, that the patient/client does not object to the disclosure.
-
Conditions: If the patient/client is not present or is incapacitated. The Agency may,
in the exercise of professional judgment, determine whether the disclosure is in the best interest
of the patient/client, and, if so, disclose only that PHI which is directly relevant to the person’s
involvement with the patient/client’s care, if:
- The patient/client is not present;
- The opportunity to agree/object to the use, or disclosure, cannot practicably be provided because of the patient/client’s incapacity; or
- In an emergency.
- Confirming Identity: The Agency shall take reasonable steps to confirm the identity of a patient/client’s family member or friend. The Agency is permitted to rely on the circumstances as confirmation of involvement in care. For example, the fact that a person admits a patient/client to the Agency, and the person is present during home visits and interacts with the employee and the patient/client regarding the care/instructions provided, is sufficient confirmation of involvement in the patient/client’s care.
Notice of Privacy Policy
Purpose:
To ensure that a Notice of Privacy Practices is provided to, and acknowledged by, each patient/client, or his/her personal representative, upon admission to the Agency.
Policy:
The Agency’s policy is to provide a Notice of Privacy Practices (Notice) to each patient/client, upon each admission to the Agency and make a good faith effort to obtain a signed Acknowledgement of Receipt of Notice of Privacy Practices (Acknowledgement), from the patient/client or legal representative.
(See sample Notice and Acknowledgement forms located in the Patient/Client Admission/Information booklet.)
The Notice shall include all elements, and statements, that are required by law. The Notice shall inform the patient/clients of:
- Uses, and disclosures, of Protected Health Information (“PHI”) that may be made by the Agency;
- The patient/client’s rights, with respect to his PHI; and
- The Agency’s legal duties, with respect to such PHI.
Procedure:
- The Notice and Acknowledgement forms will be included in the Admission/Information booklet.
- The Agency admission representative will provide the Notice to the patient/client, or legal representative, at the time of admission.
- Note: In the case of an emergency treatment situation, the Agency will provide the Notice to the patient/client, or legal representative, as soon as reasonably practicable, after the emergency treatment situation.
- The admission representative will make a good faith effort to obtain the patient/client’s signature on the Acknowledgement, at the time the Notice is provided.
- The Notice, and signed Acknowledgement, will be kept in the patient/client’s record.
- If the patient/client or legal representative refuses, or is otherwise unable to sign the Acknowledgement, the admission representative will document, on the Acknowledgement form, what actions were taken to obtain the patient/client or legal representative’s signature on the Acknowledgement and the reason(s) why a signed Acknowledgement was not obtained. This document will then be placed in the patient/client’s record.
- The Agency will provide a copy of the written Notice to patient/clients and to other persons, upon request.
- The Agency will post a copy of the Notice, in a clear and prominent location, such as the entrance lobby or similar location.
- A current version of the Notice will be maintained on the Agency’s website if any.
- Whenever the Notice is revised, the Agency’s Privacy Officer will assure that: The revised Notice is made available, upon request, on or after the effective date of the revision; and The revised Notice is posted in a clear and prominent location. Material changes shall not be implemented prior to the effective date of the revised Notice.
- A copy of each Notice issued by the Agency will be maintained for at least six years from the date it was last in effect.
- Any employee of the Agency who has knowledge of a violation, or potential violation of this Policy must make a report, directly, to the Privacy Officer.
- All employees, on hire and every year, will be trained regarding HIPAA, that includes current state and federal laws concerning PHI for privacy/security compliance, and the latest state and federal regulations.
- In addition to the HIPAA guidelines, training will include the maintenance, and protection, of electronic PHI.
- Employees will sign, electronically or in writing, a statement verifying his/her attendance at the training program. The signed statement will be maintained in the personnel record.
- Patient/client/legal representatives will be provided with copies of their health information, within fifteen days of the patient’s written request for the records.
- The Agency will not disclose a patient/client’s PHI, to any other person, in exchange for any direct, or indirect, payment.
- The patient/client’s PHI information may be disclosed to other covered entities for treatment, payment, healthcare operations, insurance or HMO functions, or as authorized, or required, by federal or state law.
- Patient/clients will be informed of any breach of their PHI. Failure to do so will result in financial penalty and potential felony charges.
HIPAA Compliance Officer
Marnie Bernard
The Bernard Health Institute
18030 Barnesville Rd
Barnesville, MD 20838
301-349-2194