Honest Broker: Difference between revisions

Jump to navigation Jump to search
no edit summary
No edit summary
No edit summary
(8 intermediate revisions by 2 users not shown)
Line 17: Line 17:
</table>
</table>
<br />
<br />
[[Identification Card]] | [[Secure Area Card Access]] | [[Privacy/Confidentiality]] | [[Computer Use/Electronic Information]] | [[Retention and Destruction/Disposal of Private and Confidential Information]] | [[Use and Disclosure of Protected Health Information]] | [[Notice of Privacy Practices]] | [[Access to Designated Record Set]] | [[Accounting of PHI Disclosures]] | [[Patient/Consumer Complaints]] | [[Vendors]] | [[Fax Transmissions]] | [[Psychotherapy Notes]] | [[Facility Security]] | [[Conditions of Treatment Form]] | [[Informed Consent for UNMC Media]] | [[Transporting Protected Health Information]] | [[Honest Broker]]
[[Identification Card]] | [[Secure Area Card Access]] | [[Privacy/Confidentiality]] | [[Computer Use/Electronic Information]] | [[Retention and Destruction/Disposal of Private and Confidential Information]] | [[Use and Disclosure of Protected Health Information]] | [[Notice of Privacy Practices]] | [[Access to Designated Record Set]] | [[Accounting of PHI Disclosures]] | [[Patient/Consumer Complaints]] | [[Vendors]] | [[Fax Transmissions]] | [[Psychotherapy Notes]] | [[Facility Security]] | [[Conditions of Treatment Form]] | [[Informed Consent for UNMC Media]] | [[Transporting Protected Health Information]] | [[Honest Broker]] | [[Social Security Number]] | [[Third Party Registry]] | [[Information Security Awareness and Training]]
<br/><br/>
<br/><br/>
Policy No.: '''6074'''<br />
Policy No.: '''6074'''<br />
Effective Date: '''DRAFT'''<br />
Effective Date: '''08/26/15'''<br />
Revised Date: ''' '''<br />
Revised Date: ''' '''<br />
Reviewed Date: ''' ''' <br /><br />
Reviewed Date: ''' ''' <br /><br />
Line 41: Line 41:
An Honest Broker is a neutral intermediary (person or system), who is a workforce member and is certified to collect specified health information from the tissue or data bank, remove all patient identifiers, and provide the de-identified health information or tissue to research investigators, clinicians, or other healthcare workforce members, in such a manner that it would not be reasonably possible for any individual to identify the patients directly or indirectly.
An Honest Broker is a neutral intermediary (person or system), who is a workforce member and is certified to collect specified health information from the tissue or data bank, remove all patient identifiers, and provide the de-identified health information or tissue to research investigators, clinicians, or other healthcare workforce members, in such a manner that it would not be reasonably possible for any individual to identify the patients directly or indirectly.
===Information Custodian===
===Information Custodian===
All application systems must have an information custodian ([http://www.unmc.edu/its/security/procedures/access-control.html Access Control to Information Technology Resources]) who performs the functions which specify the security properties associated with the application system. This includes the categories of information that users are allowed to read and update. The information custodian is also responsible for classifying data and participating in ensuring the technical and procedural mechanisms implemented are sufficient to secure the data based upon a risk analysis that considers the probability of compromise and its potential business impact.  
All application systems must have an information custodian ([https://info.unmc.edu/its-security/policies/procedures/access-control.html Access Control to Information Technology Resources]) who performs the functions which specify the security properties associated with the application system. This includes the categories of information that users are allowed to read and update. The information custodian is also responsible for classifying data and participating in ensuring the technical and procedural mechanisms implemented are sufficient to secure the data based upon a risk analysis that considers the probability of compromise and its potential business impact.
 
===Institutional Review Board (IRB)===
===Institutional Review Board (IRB)===
IRB means the Institutional Review Board of record for the ACE.
IRB means the Institutional Review Board of record for the ACE.
Line 63: Line 64:
:*Introduce the research study;
:*Introduce the research study;
:*Ascertain their interest in study participation; and
:*Ascertain their interest in study participation; and
:*Obtain written authorization to share their interest in study participation with the investigators and allow patients to be contacted. The honest broker would not directly contact the patient.
:*Obtain written authorization to share their interest in study participation with the investigators and allow patients to be contacted by researcher. The honest broker would not directly contact the patient.
:*After secondary review by the Associate Vice Chancellor for Clinical Research, an honest broker may provide the research investigator with a list of potentially eligible patients who have agreed to be contacted for research studies they are eligible for based on their election on the Conditions of Treatment form or consistent with the Human Research Protection Program Policy #3.4 “Use of Protected Health Information in Research and Registries” for further information.
:*After secondary review by the Associate Vice Chancellor for Clinical Research, an honest broker may provide the research investigator with a list of potentially eligible patients who have agreed to be contacted for research studies they are eligible for based on their election on the Conditions of Treatment form or consistent with the Human Research Protection Program Policy #3.4 “Use of Protected Health Information in Research and Registries” for further information.
*Honest broker Data Requests: Individuals requesting PHI or de-identified data shall complete:
*Honest broker Data Requests: Individuals requesting PHI or de-identified data shall complete:
:*the [https://unmcredcap.unmc.edu/redcap/surveys/?s=9TsTE2UGsM UNMC/Nebraska Medicine Request for Electronic Health Data Form] (research),  
:*the [https://unmcredcap.unmc.edu/redcap/surveys/?s=94TLJCCAAT UNMC/Nebraska Medicine Request for Electronic Health Data Form] (research),  
:*the Nebraska Medicine [http://newintranet.nebraskamed.com/AnalyticsRequest/Login.aspx?ReturnUrl=%2fanalyticsrequest%2f Analytics Request Form] (performance improvement) or  
:*the Nebraska Medicine [http://newintranet.nebraskamed.com/AnalyticsRequest/Login.aspx?ReturnUrl=%2fanalyticsrequest%2f Analytics Request Form] (performance improvement) or  
:*another similar form.     
:*another similar form.     
Line 90: Line 91:
::*New brokers must first complete the education/certification modules as noted in the honest broker certification section above.
::*New brokers must first complete the education/certification modules as noted in the honest broker certification section above.
::*In accordance with UNMC/Nebraska Medicine policy, applicants who are not UNMC/Nebraska Medicine employees must complete and sign a business associate agreement (BAA).
::*In accordance with UNMC/Nebraska Medicine policy, applicants who are not UNMC/Nebraska Medicine employees must complete and sign a business associate agreement (BAA).
::*A complete revision of the each unit’s application must be submitted to the Privacy Office with any brokers to be added reflected in the revision. A copy of any relevant BAAs must accompany the revision documents.  
::*A complete revision of each unit’s application must be submitted to the Privacy Office with any brokers to be added reflected in the revision. A copy of any relevant BAAs must accompany the revision documents.  
:*Removing Brokers:  A complete revision of the application must be submitted to the Privacy Office with any brokers to be removed and the reason for the removal reflected in the revision.
:*Removing Brokers:  A complete revision of the application must be submitted to the Privacy Office with any brokers to be removed and the reason for the removal reflected in the revision.
*Duties and Other Requirements of the Honest Broker: In order for a certified honest broker to work on behalf of investigators to de-identify PHI that is owned/held by UNMC, the honest broker must perform the following UNMC/Nebraska Medicine-defined duties and adhere to the following -defined requirements:
*Duties and Other Requirements of the Honest Broker: In order for a certified honest broker to work on behalf of investigators to de-identify PHI that is owned/held by UNMC, the honest broker must perform the following UNMC/Nebraska Medicine-defined duties and adhere to the following -defined requirements:
Line 101: Line 102:
::*An individual honest broker for the investigator must obtain (and retain) evidence of an appropriately executed Data Use Agreement in order to be granted access to the UNMC/Nebraska Medicine-held PHI.
::*An individual honest broker for the investigator must obtain (and retain) evidence of an appropriately executed Data Use Agreement in order to be granted access to the UNMC/Nebraska Medicine-held PHI.
==Additional Information==
==Additional Information==
*Contact the [mailto:tscrogin@unmc.edu Privacy Officer]
*Contact the [mailto:debrbishop@nebraskamed.com Privacy Officer]
*[http://www.unmc.edu/hipaa/about/notice-privacy-practices.html Notice of Privacy Practices]
*[http://www.unmc.edu/hipaa/about/notice-privacy-practices.html Notice of Privacy Practices]
*[http://www.unmc.edu/hipaa/_documents/application-for-honest-broker-certification.pdf Application for Honest Broker Certification Form]
*[http://www.unmc.edu/hipaa/_documents/application-for-honest-broker-certification.pdf Application for Honest Broker Certification Form]
*[http://www.unmc.edu/hipaa/_documents/attestation-of-honest-brokers-responsibilites.pdf Attestation of Honest Brokers Responsibilities Form]
*[http://www.unmc.edu/hipaa/_documents/attestation-of-honest-brokers-responsibilites.pdf Attestation of Honest Brokers Responsibilities Form]
*[https://unmcredcap.unmc.edu/redcap/surveys/?s=9TsTE2UGsM UNMC/Nebraska Medicine Request for Electronic Health Data Form]  
*[https://unmcredcap.unmc.edu/redcap/surveys/?s=94TLJCCAAT UNMC/Nebraska Medicine Request for Electronic Health Data Form]  
*Nebraska Medicine [http://newintranet.nebraskamed.com/AnalyticsRequest/Login.aspx?ReturnUrl=%2fanalyticsrequest%2f Analytics Request Form]  
*Nebraska Medicine [http://newintranet.nebraskamed.com/AnalyticsRequest/Login.aspx?ReturnUrl=%2fanalyticsrequest%2f Analytics Request Form]  
*[http://www.unmc.edu/its/security/procedures/access-control.html Access Control to Information Technology Resources]
*[https://info.unmc.edu/its-security/policies/procedures/access-control.html Access Control to Information Technology Resources]


This page maintained by [mailto:dpanowic@unmc.ed dkp]
This page maintained by [mailto:dpanowic@unmc.ed dkp]

Navigation menu