Permissible Uses and Disclosures of PHI
TPO: <ul> <li>Treatment</li> <li>Payment</li> <li>Operations</li> </ul> covered entities: for any disclosure outside TPO, must obtain explicit authorization from individual whose information is to be disclosed business associates: only allowed to disclose for specific intended stated purpose in the BA contract. Cannot use/disclose PHI which violates contract (including when provided by CO or BA), or in violation of the law
Sharing or Disclosing PHI with Third Parties
due diligence with questions to confirm HIPAA compliant before signing BA.
Minimum Necessary Standard
BA must perform reasonable efforts to not use/disclose more than minimum PHI for intended purpose
for CE or BA to disclose outside of TPO, …
Individually Identifiable Information
name, address, email, phone number, any other unique identifiers or codes
breach
when PHI is improperly used or disclosed
breach response
investigate, mitigate, document, and notify the CE whose information was affected, and potentially notify the Office of Civil Rights at the Department of Health and Human Services.