Accounting of PHI Disclosures: Difference between revisions

→‎Additional Information: updated Health Insurance Portability and Accountability Act of 1996 link and HIPAA Security Rule link 2x
(→‎Additional Information: updated Health Insurance Portability and Accountability Act of 1996 link and HIPAA Security Rule link 2x)
 
(2 intermediate revisions by one other user not shown)
Line 30: Line 30:
Policy No.: '''6061'''<br />
Policy No.: '''6061'''<br />
Effective Date: '''03/17/03'''<br />
Effective Date: '''03/17/03'''<br />
Revised Date: '''draft 10/28/22''' <br />
Revised Date: '''06/06/24'''<br />
Revised Date: ''' ''' <br /><br />
Revised Date: '''06/06/24'''<br />
<big>'''Accounting of Protected Health Information Disclosures Policy'''</big>  
<big>'''Accounting of Protected Health Information Disclosures Policy'''</big>  
== Basis for Policy ==  
== Basis for Policy ==  
Nebraska Medicine/UNMC implements reasonable and appropriate access controls in alignment with National Institute of Standards and Technology (NIST) standards and guidance to maintain the minimum necessary access. [https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final NIST Special Publication 800-53] and the [https://www.cdc.gov/phlp/publications/topic/hipaa.html#security-rule HIPAA Security Rule] outline considerations for the access control family of security controls.
Nebraska Medicine/UNMC implements reasonable and appropriate access controls in alignment with National Institute of Standards and Technology (NIST) standards and guidance to maintain the minimum necessary access. [https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final NIST Special Publication 800-53] and the [https://www.cdc.gov/phlp/php/resources/health-insurance-portability-and-accountability-act-of-1996-hipaa.html HIPAA Security Rule] outline considerations for the access control family of security controls.
== Policy ==  
== Policy ==  
Nebraska Medicine (Nebraska Medical Center, Bellevue Medical Center, and UNMCP)/UNMC shall provide patients, as required by law and upon written request, with a list of applicable individuals/organizations to which their Protected Health Information (PHI) has been disclosed.
Nebraska Medicine (Nebraska Medical Center, Bellevue Medical Center, and UNMCP)/UNMC shall provide patients, as required by law and upon written request, with a list of applicable individuals/organizations to which their Protected Health Information (PHI) has been disclosed.
Line 42: Line 42:
It is the policy of Nebraska Medicine (Nebraska Medical Center, Bellevue Medical Center and UNMCP)/UNMC to comply with the procedures set forth below.
It is the policy of Nebraska Medicine (Nebraska Medical Center, Bellevue Medical Center and UNMCP)/UNMC to comply with the procedures set forth below.
#An individual has a right to receive an accounting of disclosures of PHI made by the ACE during a time period specified up to six (6) years prior to the date of the request, except for disclosures:
#An individual has a right to receive an accounting of disclosures of PHI made by the ACE during a time period specified up to six (6) years prior to the date of the request, except for disclosures:
#*To carry out treatment, payment or health care operations (including permissible disclosures to other providers for their treatment, payment or health care operations);
#*To carry out treatment, payment or health care operations (including permissible disclosures to other providers for their treatment, payment or health care operations).
#*To the individual about his or her own information ;
#*To the individual about his or her own information;
#*Authorized by the individual '''(signed authorization) is this [https://info.unmc.edu/_documents/hippa-docs/_accounting-of-disclosures-form.pdf Request for Accounting of Disclosures of Health Information Form]??''';
#*Authorized by the individual written authorization;
#*For the facility directory or to persons involved in the individual's care, or other notification purposes permitted under law;
#*For the facility directory or to persons involved in the individual's care, or other notification purposes permitted under law;
#*For national security or intelligence purposes;
#*For national security or intelligence purposes;
#*To correctional institutions or other law enforcement officials who have custody of an individual as permitted under law;
#*To correctional institutions or other law enforcement officials who have custody of an individual as permitted under law;
#*As part of a limited data set (see UNMC Policy No. 6057, [[Use and Disclosure of Protected Health Information]]);
#*As part of a limited data set (see UNMC Policy No. 6057, [[Use and Disclosure of Protected Health Information]]);
#Individuals shall make their requests to the Health Information Management Department (HIM), using the '''is this the most recent form and the correct one to use in place of Attachment 1? If not, I will need a link to Attachment 1 [https://info.unmc.edu/_documents/hippa-docs/_accounting-of-disclosures-form.pdf Request for Accounting of Disclosures of Health Information Form]??''';
#Individuals shall make their requests to the Health Information Management Department (HIM), using the '''[https://info.unmc.edu/_documents/hippa-docs/_accounting-of-disclosures-form.pdf Request for Accounting of Disclosures of Health Information Form]''';
#Content Requirements. The accounting for each disclosure must include:
#Content Requirements. The accounting for each disclosure must include:
#*Date of disclosure;
#*Date of disclosure;
Line 129: Line 129:
*UNMC Policy No. 6057, [[Use and Disclosure of Protected Health Information]]
*UNMC Policy No. 6057, [[Use and Disclosure of Protected Health Information]]
*[https://info.unmc.edu/_documents/hippa-docs/_accounting-of-disclosures-form.pdf Request for Accounting of Disclosures of Health Information Form]
*[https://info.unmc.edu/_documents/hippa-docs/_accounting-of-disclosures-form.pdf Request for Accounting of Disclosures of Health Information Form]
*[https://www.cdc.gov/phlp/publications/topic/hipaa.html Health Insurance Portability and Accountability Act of 1996 (HIPAA)]
*[https://www.cdc.gov/phlp/php/resources/health-insurance-portability-and-accountability-act-of-1996-hipaa.html Health Insurance Portability and Accountability Act of 1996 (HIPAA)]
*[https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final NIST Special Publication 800-53]  
*[https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final NIST Special Publication 800-53]  
*[https://www.cdc.gov/phlp/publications/topic/hipaa.html#security-rule HIPAA Security Rule]  
*[https://www.cdc.gov/phlp/php/resources/health-insurance-portability-and-accountability-act-of-1996-hipaa.html HIPAA Security Rule]  


This page maintained by [mailto:dpanowic@unmc.edu dkp]
This page maintained by [mailto:mhurlocker@unmc.edu mh]