Reasons for medical data privacy
Confidentiality of Substance Use Disorder Patient Records Rule: Scope
Confidentiality of Substance Use Disorder Patient Records Rule: Applicability
-
Confidentiality of Substance Use Disorder Patient Records Rule: Disclosure and Re-disclosure
Confidentiality of Substance Use Disorder Patient Records Rule: Exceptions to Consent
Confidentiality of Substance Use Disorder Patient Records Rule: Security and Enforcement
Violations of Rule are criminal. first violation a finde not more than 500, each subsequent not more than 5k.
Confidentiality of Substance Use Disorder Patient Records Rule: Convergence and Pre-emption
- Like HIPAA and is lots of overlap, but not completely.
HIPAA: PHI Definition
Protected health information (PHI) is defined as any individually identifiable health information that: is transmitted or maintained in any form or medium; is held by a covered entity or its business associate; identifies the individual or offers a reasonable basis for identification; is created or received by a covered entity or an employer; and relates to a past, present or future physical or mental condition, provision of health care or payment for health care to that individual.30
HIPAA: Covered entities
HIPAA: Business associates covered
HIPAA Privacy Rule: Authorizations for uses and disclosures
HIPAA Privacy Rule: Minimum necessary use or disclosure
HIPAA Privacy Rule: Access and accounting of disclosures
HIPAA Privacy Rule: Safeguards
HIPAA Privacy Rule: Accountability
HIPAA Privacy Rule: Enforcement
Limits/Exceptions on Privacy Rule
information used for public health activities;
to report victims of abuse, neglect or domestic violence;
in judicial and administrative proceedings;
for certain law enforcement activities;
for certain specialized governmental functions
HIPAA Security Rule: Basics and Goal
HIPAA Security Rule: Addressable vs. Required, for CEs
HIPAA Security Rule: Requirements for CE and BA
Requirements:
HIPAA Security Rule: Factors must take not consideration
CEs and BAs take factors into consideration:
HIPAA Security Rule: Misc requirements for CEs
GINA: Health insurance restrictions
-
GINA: Employer restrictions
Prohibits employers from