Privacy/Confidentiality: Difference between revisions

From University of Nebraska Medical Center
Jump to navigation Jump to search
No edit summary
No edit summary
(33 intermediate revisions by 3 users not shown)
Line 20: Line 20:
<td style="padding:0.5em; background-color:#e5e5e5; font-size:90%; line-height:0.95em; border:1px solid #A3B1BF; border-bottom:solid 2px #A3B1BF"  
<td style="padding:0.5em; background-color:#e5e5e5; font-size:90%; line-height:0.95em; border:1px solid #A3B1BF; border-bottom:solid 2px #A3B1BF"  
width="20">[[Intellectual Property]]</td>
width="20">[[Intellectual Property]]</td>
<td style="border-bottom:2px solid #A3B1BF" width="3">&#160;</td>
<td style="padding:0.5em; background-color:#e5e5e5; font-size:90%; line-height:0.95em; border:1px solid #A3B1BF; border-bottom:solid 2px #A3B1BF"
width="20">[[Faculty]]</td>
</tr>
</tr>
</table>
</table>
<br />
<br />
[[Identification Card]] | [[Secure Area Card Access]] | [[Privacy/Confidentiality]] | [[Computer Use/Electronic Information]] | [[Retention and Destruction/Disposal of Private and Confidential Information]] | [[Use and Disclosure of Protected Health Information]] | [[Notice of Privacy Practices]] | [[Access to Designated Record Set]] | [[Accounting of PHI Disclosures]] | [[Patient/Consumer Complaints]] | [[Vendors]] | [[Fax Transmissions]] | [[Psychotherapy Notes]] | [[Facility Security]] | [[Conditions of Treatment Form]] | [[Informed Consent for UNMC Media]] | [[Transporting Protected Health Information]] | [[Honest Broker]] | [[Social Security Number]] | [[Third Party Registry]] | [[Information Security Awareness and Training]]
[[Identification Card]] | [[Secure Area Card Access]] | [[Privacy/Confidentiality]] | [[Computer Use/Electronic Information]] | [[Retention and Destruction/Disposal of Private and Confidential Information]] | [[Use and Disclosure of Protected Health Information]] | [[Notice of Privacy Practices]] | [[Access to Designated Record Set]] | [[Accounting of PHI Disclosures]] | [[Patient/Consumer Complaints]] | [[Vendors]] | [[Fax Transmissions]] | [[Psychotherapy Notes]] | [[Facility Security]] | [[Conditions of Treatment Form]] | [[Informed Consent for UNMC Media]] | [[Transporting Protected Health Information]] | [[Honest Broker]] | [[Social Security Number]] | [[Third Party Registry]] | [[Information Security Awareness and Training]] | [[Patient Privacy Investigations and Levels of Violation]] | [[Use and Disclosure of PHI for Training Health Care Professionals]] | [[Disclosures of PHI as Permitted or Required by Law]] | [[Disclosure of PHI for Law Enforcement Purposes]]
<br /><br />
<br /><br />
Policy No.: '''6045'''<br />
Policy No.: '''6045'''<br />
Effective Date: '''11/21/03'''<br />
Effective Date: '''11/21/03'''<br />
Revised Date: '''07/25/17  DRAFT'''<br />
Revised Date: '''11/29/22 draft'''<br />
Reviewed Date: '''07/20/17'''<br />
Reviewed Date: ''' '''<br />
<br />
<br />
<big>'''Privacy, Confidentiality and Security of Patient and Proprietary Information Policy'''</big><br /><br />
<big>'''Privacy, Confidentiality and Security of Patient and Proprietary Information Policy'''</big><br /><br />
== Basis for Policy ==
== Basis for Policy ==
To maintain the privacy, confidentiality and security of patient and proprietary information and comply with the Health Insurance Portability and Accountability Act of 1996 (HIPAA). UNMC workforce and business associates have access to individually identifiable health information (protected health information) and proprietary information. For purposes of this policy, confidential information means protected health information and proprietary information.
Nebraska Medicine/UNMC implements reasonable and appropriate access controls in alignment with National Institute of Standards and Technology (NIST) standards and guidance to maintain the minimum necessary access. [https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final NIST Special Publication 800-53] and the [https://www.cdc.gov/phlp/publications/topic/hipaa.html#security-rule HIPAA Security Rule] outline considerations for the access control family of security controls.
== Policy ==
== Policy ==
It is the policy of UNMC to maintain strict confidentiality and security of protected health information and proprietary information.
It is the policy of Nebraska Medicine/UNMC to maintain strict confidentiality and security of protected health information (PHI) and proprietary information.
== Definitions (as defined by HIPAA 45 CFR 164.501) ==
*'''Affiliated Covered Entity (ACE)''' means University of Nebraska Medical Center, The Nebraska Medical Center, UNMC Physicians, University Dental Associates, Bellevue Medical Center and The Nebraska Pediatric Practice Plan as one covered entity for the purpose of sharing PHI under HIPAA. ACE membership may change from time to time. The Notice of Privacy Practices lists current ACE members.
*'''Business Associate''' means a third party who performs services on behalf of UNMC and has access to protected health information (PHI) when performing services; or provides one of the following services for UNMC involving access to PHI: claims processing, data analysis, data processing, practice management, utilization review, quality assurance, billing, benefit management, and repricing.
*'''Designated Record Set''' is the medical record and billing record.
*'''Individual''' means the person who is the subject of the protected health information (including ACE workforce who are patients).
*'''Information Security''' is the ability to control access and protect information from unauthorized alteration, destruction, loss or accidental or intentional disclosure to unauthorized persons.
*'''Protected Health Information (PHI)''' is individually identifiable health information. Health information means any information, whether oral or recorded in any medium that:
:*is created or received by ACE; and
:*relates to the past, present, or future physical or mental health or condition of an individual; the provision of health care to an individual; or the past, present, or future payment for the provision of health care to an individual.
*'''Proprietary Information''' is information relating to business practices, including but not limited to financial statements, contracts, and business plans; employee records; student records; and meeting minutes.
*'''Workforce''' means employees, the medical staff, volunteers, trainees, and other persons whose conduct, in the performance of work for UNMC is under the direct control of UNMC, whether or not they are paid by UNMC.
*'''Employee Records''' refers to all information, records and documents pertaining to any person who is an applicant or nominee for any University personnel position described in the Board of Regents Bylaws, § 3.1, regardless of whether any such person is ever actually employed by the University, and all information, records and documents pertaining to any person employed by the University.
*'''Student Education Records''' means any information recorded in any way which directly relates to a student and is maintained by or on behalf of UNMC (education agency/institution). Student education record does not include a (i) sole possession record, (ii) law enforcement record, (iii) employee record of a person other than a student who is employed by UNMC by virtue of his or her status as a student at UNMC, (iv) alumni record and (v) medical record that is part of the common medical record shared by the Affiliated Covered Entity. Student education records are covered by the Family Educational Rights and Privacy Act (FERPA).
==Procedures==
==Procedures==
===Patient Information===
#Records containing confidential information, in any form, are the property of Nebraska Medicine/UNMC. The original medical record in any form shall not be released except in response to a valid search warrant, subpoena or court order requiring the release of the original record. A copy of the medical record should be offered first in such circumstances. If the original medical record must be released, a copy should be made prior to release if possible.  
*Records containing confidential information, in any form, are the property of the ACE. The original medical record in any form shall not be released except in response to a valid search warrant, subpoena, or court order requiring the release of the original record. A copy of the medical record should be offered first in such circumstances. If the original medical record must be released, a copy should be made prior to release if possible.
#Individuals have the following rights with respect to their PHI: </b
*Individuals have the following rights with respect to their PHI:
##Right to request access to inspect or to obtain a copy of their PHI in a designated record set and to receive such access (where granted) within a reasonable amount of time and to request amendment (see UNMC Policy No. 6059, [https://wiki.unmc.edu/index.php/Access_to_Designated_Record_Set Access and & Amendment of Designated Record Set]);
:*Right to request access and obtain copies of their designated record set within a reasonable amount of time and to request amendment (see UNMC Policy No. 6059, [https://wiki.unmc.edu/index.php/Access_to_Designated_Record_Set Access and Amendment of Designated Record Set]);
##Right to request restrictions of how their PHI is used and disclosed (see UNMC Policy No. 6057, [https://wiki.unmc.edu/index.php/Use_and_Disclosure_of_Protected_Health_Information Use & Disclosure of Protected Health Information]);
:*Right to request restrictions of how their PHI is used and disclosed (see UNMC Policy No. 6057, [[Use and Disclosure of Protected Health Information]]);
##Right to request an accounting of disclosures (see UNMC Policy No. 6061, [https://wiki.unmc.edu/index.php/Accounting_of_PHI_Disclosures Accounting of Protected Health Information Disclosures]);  
:*Right to request an accounting of disclosures (see UNMC Policy No. 6061, [[Accounting of PHI Disclosures]]);
##Right to receive a Notice of Privacy Practices (see UNMC Policy No. 6058, [https://wiki.unmc.edu/index.php/Notice_of_Privacy_Practices Notice of Privacy Practices]); and
:*Right to receive a Notice of Privacy Practices (see UNMC Policy No. 6058, [[Notice of Privacy Practices]];
##Right to file a complaint internally with the Patient Relations Department or with the U.S. Department of Health and Human Services Office for Civil Rights (see UNMC Policy No. 6058, [https://wiki.unmc.edu/index.php/Notice_of_Privacy_Practices Notice of Privacy Practices], UNMC Policy No. 6062, [[Patient/Consumer Complaints]] and '''Nebraska Medicine Patient Complaint and Grievance Management policy''' ''''' needpolicy #'''''<br /> '''Individuals shall not be asked to waive these rights as a condition of receiving treatment.'''
:*Right to file a complaint internally with the Nebraska Medicine Patient Relations Department, the Office of the Assistant Dean for Patient Services (College of Dentistry), or with the U.S. Department of Health and Human Services Office for Civil Rights. (See UNMC Policy Nos. 6058, [[Notice of Privacy Practices]] and 6062, [[Patient/Consumer Complaints]]).
#Nebraska Medicine/UNMC is responsible for safeguarding and protecting confidential information against loss, tampering and use by or disclosure to unauthorized individuals. The safeguarding of confidential information in any form includes when the information is stored and/or being transferred outside the facility (see UNMC Policy No. 6073, [[Transporting Protected Health Information]]).
*Individuals shall not be asked to waive these rights as a condition of receiving treatment.
#Nebraska Medicine/UNMC workforce has a duty to protect confidential information. Breach of this duty includes but is not limited to the following:
*The ACE is responsible for safeguarding and protecting confidential information against loss, tampering, and disclosure to unauthorized individuals. The safeguarding of confidential information in any form includes when the information is stored and/or being transferred outside the facility (see UNMC Policy No. 6073, [[Transporting Protected Health Information]]).
##Accessing confidential information, in any form, without a current "need to know" to perform assigned duties. Workforce members may not access their own records. Workforce members may not access records of family members (including children), relatives, friends and others, unless access is necessary to perform assigned duties. Workforce members may obtain a copy of their medical records from the Health Information Management Department or via the online patient portal.
*ACE workforce have a duty to protect confidential information. Breach of this duty includes the following:
##Discussing or disclosing patient care events/PHI to individuals who do not have a “need to know” this information to perform assigned duties, even if the patient’s name is not mentioned. The facts surrounding patient care are confidential and can lead to the identity of the patient.
:*Accessing confidential information, in any form, without a "need to know" to perform assigned duties. Workforce members with medical information system access may view their own individual medical records. Workforce members may not print copies of their own records nor access records of family members (including children), relatives, friends and others, unless access is necessary to perform assigned duties. Workforce members may obtain a copy of their medical records from the Health Information Management Department. Workforce may not alter their own medical record.
##Disclosing confidential information without proper authorization (see UNMC Policy No. 6057, [[Use and Disclosure of Protected Health Information]]);
:*Discussing or disclosing patient care events to individuals who do not have a “need to know” to perform assigned duties, even if the patient’s name is not mentioned. The facts surrounding patient care are confidential and can lead to the identity of the patient.
##Accessing patient information via Health Information Exchange in a manner or for a purpose not permitted (see UNMC Policy No. 6057, [[Use and Disclosure of Protected Health Information]]);
:*Disclosing confidential information without proper authorization (see UNMC Policy No. 6057, [[Use and Disclosure of Protected Health Information]]);
##Discussing confidential information in the presence of individuals who do not have the "need to know" to perform assigned duties;  
:*Accessing patient information via Health Information Exchange in a manner or for a purpose not permitted (see UNMC Policy No. 6057, [[Use and Disclosure of Protected Health Information]]);
##Disclosing that a patient is receiving care (except for authorized directory purposes);
:*Discussing confidential information in the presence of individuals who do not have the "need to know" to perform assigned duties;
##Leaving confidential information unattended in a non-secure area;
:*Disclosing that a patient is receiving care (except for authorized directory purposes);
##Improper disposal of confidential information (see policy, “Destruction of Confidential Information”);
:*Leaving confidential information unattended in a non-secure area;
##Using another person's user ID, password or other security codes;
:*Improper disposal of confidential information;
##Assisting an unauthorized user to gain access to a secured information system;  
:*Using another person's user ID, password, or other security codes;
##Transferring confidential information in any form without both parties having a need to know such confidential information.  
:*Assisting an unauthorized user to gain access to a secured information system;
#Nebraska Medicine/UNMC shall mitigate or reduce, to the extent practicable, any harmful effects of a use or disclosure of PHI in violation of its policies and procedures that is known to Nebraska Medicine/UNMC.  
:*Transferring confidential information in any form without both parties having a need to know.
#All employees, the medical staff, allied health practitioners and members of the Workforce with access to confidential information shall sign Nebraska Medicine/UNMC Information Privacy, Confidentiality and Security Agreement upon initial employment/work/appointment/credentialing '''(need URL for attachment to link to the policy)'''.  
*The ACE shall reasonably mitigate or reduce any harmful effects that may result from privacy breaches.
#Workforce members who suspect a privacy or information security violation must report it immediately. Such reports may be made to their respective manager and the Privacy and/or Information Security Office. Alternatively, staff who wish to remain anonymous may report the suspected violation to the Compliance Hotline at 800-822-8310. A full investigation of the suspected violation shall be conducted. Sanctions shall be imposed for substantiated breaches or failure to report suspected violations. The Medical Staff and allied health practitioners shall report suspected violations to the System Chief Medical Officer '''(how to contact that person??)'''.
*All employees, medical staff, allied health practitioners and members of the workforce with access to confidential information shall sign a[https://www.unmc.edu/hipaa/policies/6045-exhibit-a-statement-of-understanding.pdf Statement of Understanding, Exhibit A] upon initial employment/work/appointment/credentialing.
#Sanctions for violations of privacy or information security may include revocation of medical staff privileges or allied health credentials, or employee corrective action up to and including termination of employment (see UNMC Policy No. 6302, [[Patient Privacy Investigations and Levels of Violation]]). Civil and criminal fines and penalties can also be levied under HIPAA.
*Workforce members who suspect a privacy or information security violation must report it immediately to their respective manager and the Privacy and/or Information Security Office. A full investigation of the suspected violation shall be conducted. Staff who wish to remain anonymous may report the suspected violation to the Compliance Hotline at 866-568-5430. Sanctions shall be imposed for substantiated breaches or failure to report suspected violations. The Medical Staff and allied health practitioners shall report suspected violations to the System Chief Medical Officer.
#Workforce members may not intimidate, threaten, coerce, discriminate against, or take other retaliatory action against any individual for reporting a suspected privacy or information security violation, or for filing of a complaint within Nebraska Medicine/UNMC or to the Office for Civil Rights (see [https://wiki.unmc.edu/index.php?title=Privacy/Confidentiality&action=edit#Procedures Procedures, Section 2.2]).
*Sanctions for violations of privacy or information security may include revocation of medical staff privileges, allied health credentials, or employee corrective action up to and including termination of employment (see UNMC Policy No. 1098, [https://wiki.unmc.edu/index.php/Corrective/Disciplinary_Action Corrective and Disciplinary Action]). Civil and criminal fines and penalties can also be levied under HIPAA.
#Access to patient information via Health Information Exchange shall be conducted in accordance with UNMC Policy No. 6057, [[Use and Disclosure of Protected Health Information]].  
*Workforce members may not intimidate, threaten, coerce, discriminate against, or take other retaliatory action against any individual for reporting a suspected privacy or information security violation, or for filing of a complaint within the organization or to the Office for Civil Rights.
#Paper medical records shall be maintained in the Health Information Management Department.  
*Access to patient information via Health Information Exchange shall be conducted in accordance with “Uses and Disclosure of Protected Health Information” policy.
##Records sent to clinic areas shall be returned to the Health Information Management Department within one working day.
*Paper medical records shall be maintained in the Health Information Management Department.
##Records of discharged patients will remain on the units until the Health Information Management Department picks them up. Medical records of deceased patients scheduled for an autopsy may be sent to the morgue.  
:*Records sent to clinic areas shall be returned to the Health Information Management Department within one working day.
##Records signed out to the attending physician's office or other authorized areas shall be returned to the Health Information Management Department as soon as possible (preferably by 5:00 pm each working day).
:*Records of discharged patients will remain on the units until Health Information Management picks them up. Medical records of deceased patients scheduled for an autopsy may be sent to the morgue.
#Editing, authenticating and correcting the medical record.
:*Records signed out to the attending physician's office or other authorized areas shall be returned to the Health Information Management Department as soon as possible (preferably by 5:00 pm each working day).
##See Nebraska Medicine Policy, “Contents of Medical Record”, for editing and authenticating the medical record.'''(Nebraska Medicine Policy number??)'''
*Editing, authenticating and correcting the medical record.
#[https://wiki.unmc.edu/index.php/Business_Associate_Agreements_and_Addendums_Procedures A Business Associate Agreement or Addenda] shall be executed with each Business Associate
:*Please reference, Nebraska Medicine Contents of the Medical Record policy for editing and authenticating the medical record.
#Human Subjects Research shall be conducted in accordance with UNMC’s [https://guides.unmc.edu/books/hrpp-policies-and-procedures Human Research Protection Program (HRPP) Policies and Procedures], including HRPP Policy 3.4, “Use of Protected Health Information in Research" and UNMC Policy No. 6057, [[Use and Disclosure of Protected Health Information]].
*Business Associate agreements/addenda shall be established with any individual or corporation who performs a function on behalf of UNMC involving the use or disclosure of PHI, other than as a member of the workforce or a healthcare provider providing treatment (see UNMC Policy No. 8009, [[Contracts]]).
#Retention of the designated record set and other protected health information shall be in accordance with federal, state and local laws and regulatory association guidelines. Documents required to demonstrate HIPAA compliance shall be retained for a period of six years.  
*Human Subjects Research shall be conducted in accordance with Human Research Protection Program (HRPP) Policies and Procedures, including HRPP Policy 3.4, Use of Protected Health Information in Research and Registries and Use and Disclosure of Protected Health Information policy.
== Definitions  ==
*Retention of the designated record set and other protected health information shall be in accordance with federal, state, and local laws, and regulatory association guidelines. Documents required to demonstrate HIPAA compliance shall be retained for a period of six years.
===Affiliated Covered Entity (ACE)===
*The Privacy Officer shall be designated in writing and shall be responsible for developing and implementing written policies and procedures necessary to comply with the Health Insurance Portability and Accountability Act of 1996 (HIPAA).
Legally separate covered entities that are affiliated and designate themselves as a single covered entity for the purpose of HIPAA Compliance. Current ACE members are: The Nebraska Medical Center, UNMC Physicians, UNMC, University Dental Associates, Bellevue Medical Center and Nebraska Pediatric Practice, Inc. d/b/a Children’s Specialty Physicians. ACE membership may change from time to time. The Notice of Privacy Practices lists current ACE members. Access and amendment rights apply to designated record sets throughout the ACE.
*All members of the workforce shall receive training on privacy and security of confidential information upon hire, and when policies and procedures relevant to their position change.
===Business Associate===
===Business Information===
A third party who performs services on behalf of Nebraska Medicine/UNMC that involve the creation, receipt, maintenance or transmission of PHI. Some examples of such services include claims processing, data analysis, data processing, practice management, utilization review, quality assurance, patient safety activities, billing, benefit management and repricing.
*Members of the workforce have a duty to protect proprietary business information. Breach of this duty includes, but may not be limited to, the following:
===Designated Record Set (DRS)===
:*Disclosure of confidential financial information
Includes medical records and billing records about Individuals maintained by or for UNMC/ACE and any other record used by an ACE entity to make decisions about Individuals. Exact duplicates of records maintained by business associates are not considered part of the DRS. 
:*Disclosure of confidential contract/agreement information
===Individual===
:*Disclosure of confidential business plans
The person who is the subject of the PHI. Personal representatives of the patient have the same rights as the Individual under HIPAA (i.e., they “step into the shoes” of the Individual). Personal representatives include the legal guardian and anyone else authorized by law to act on behalf of the Individual. (See Nebraska Medicine Consents and Permits policy, MS14).
:*Disclosure of fundraising information
===Protected Health Information (PHI)===
:*Disclosure of credit card information received in the course of business, whether or not such credit card information is covered by the Gramm-Leach-Bliley Act (GLBA).
Individually identifiable health information including demographic information, collected from an Individual, whether oral or recorded in any medium, that:
*Workforce members who suspect a breach of confidentiality regarding proprietary business information shall report the breach to the Human Resources Employee Relations Department.  
*is created or received by UNMC/ACE; and
*A full investigation of the breach shall be conducted by the Human Resources Employee Relations Department, as appropriate.  
*relates to the past, present or future physical or mental health or condition of an Individual; the provision of health care to an Individual; or the past, present or future payment for the provision of health care to an Individual and identifies the Individual or with respect to which there is a reasonable basis to believe the information can be used to identify the Individual.
===Student Education Record Information===
PHI includes genetic information, which includes information about the following items (and excludes information about an Individual’s sex or age):
*Members of the workforce have a duty to maintain the confidentiality of student education records. Breach of this duty includes, but is not limited to, release of student information that is not considered “directory information” under the guidelines of the Family Educational Rights and Privacy (FERPA) listed in the Student Handbook. It also includes, but is not limited to, protection of confidential student financial information protected under the Gramm-Leach-Bliley Act (GLBA).  
*an Individual’s genetic tests; 
*Employees shall verify FERPA restrictions placed on student records prior to release of student information.
*the genetic tests of an Individual’s family members; or
*The social security number of a student is considered confidential information and must not be used to identify a student.
*the manifestation of a disease or disorder in such Individual’s family members (i.e., family medical history); or
*Information Technology Services (ITS) shall be available to assist in identifying alternatives to use of social security number. Alternatives which should be considered, include but are not limited to Student Number.
*any request for, or receipt of, genetic services (e.g., genetic test, genetic counseling, genetic education), or participation in clinical research which includes genetic services by the Individual or any family member of the Individual.
*Use of a student’s social security number in databases is prohibited. In the event that the social security number of a student must be maintained, an Exception Form [https://www.unmc.edu/hipaa/_documents/6045-Exhibit-B-SSN-Student.docx Use of Student Social Security Number Exception, Exhibit B] must be completed and submitted to Academic Affairs for approval. If it must be used, the use of the student’s social security number must comply with ITS Database Security Procedures.
PHI excludes:
*Workforce members who suspect a breach of confidentiality regarding Student Education Records shall report the breach to the Compliance Office or the Student Affairs Office.  
*individually identifiable health information of a person who has been deceased for more than fifty (50) years.
*The student may file a complaint with the Family Policy Compliance Office, U.S. Department of Education, 400 Maryland Ave SW, Washington, DC 20202-4605.  
*education records covered by the Family Educational Rights and Privacy Act (FERPA); and
===Employee Information===
*employment records held by UNMC in its role as employer.
*Employment records are confidential and will not be made publicly available, except upon written authorization signed by the individual to whom the records pertain or in response to a legal mandate. In this context, employment records are those of persons who are employees of UNMC, and persons who are or have been either applicants or nominees for employment. Such records include the entire employment process beginning with application or nomination for appointment, search committee evaluation, and appointing authority evaluation, through appointment and employment, and ending with separation from employment.  
===Workforce===
*The social security number of an employee is considered confidential information and should not be used to identify an employee unless legally mandated, see UNMC Policy No. 6085, [[Social Security Number]].
Employees, medical staff, volunteers, trainees and other persons whose conduct, in the performance of work for Nebraska Medicine/UNMC, is under the direct control of Nebraska Medicine/UNMC, whether or not they are paid by Nebraska Medicine/UNMC.<br />
*ITS shall be available to assist in identifying alternatives to use of social security number. Alternatives which should be considered, include but are not limited to:
<br />
:*Personnel (SAP) Number
'''''In addition for purposes of this policy.'''''
:*Last four digits of social security number
===Information Security===
*In the event that the social security number of an employee must be maintained, an Exception Form, [https://www.unmc.edu/hipaa/_documents/6045-Exhibit-C-SSN-Employee.docx Use of Employee Social Security Number Exception, Exhibit C], must be completed and submitted to Human Resources for approval. In cases where the employee social security number must be stored in a database, the database use must comply with ITS Database Security Procedures.
The set of policies and practices designed to protect PHI from any unauthorized access, use, disclosure, modification, destruction or loss.
*The following are not confidential and are considered by UNMC as directory information:
===Proprietary Information===
:*Employee Name
Information relating to Nebraska Medicine/UNMC business practices, including but not limited to financial statements, contracts, and business plans, employee records and meeting minutes.
:*Gross salary
:*Dates of hire and separation
:*Type of appointment(s) held and term of each appointment
:*Title or academic rank
:*UNMC employment address
:*Post-secondary education degrees earned
:*Awards or honors
*Employee information other than directory information is accessible only to the employee, the department administrative personnel, UNMC Human Resources, and other University offices with a need to know. Non-directory information should be released to others only with signed authorization from the employee or in response to a legal mandate.
*Departments have three options for responding to requests for reference checks:
:*Refer to Human Resources – Records
:*Provide directory information only
:*With a signed release, respond to questions and provide information based only on what is documented in the employment file
:*For more information about responding to reference checks, inquire at UNMC Human Resources – Records at 402/559-8962.
*Members of the workforce have a duty to protect employee information. Breach of this duty includes but is not limited to the following:
:*Disclosure of social security number
:*Disclosure of Family Medical Leave information
:*Disclosure of employee corrective action
*Workforce members who suspect a breach of confidentiality regarding Employment Records shall report the breach to the Human Resources Employee Relations Department.
===Research Information===
*Members of the workforce have a duty to protect confidential information produced while performing research. Breach of this duty includes the following:
:*Disclosure of PHI to unauthorized persons or entities not included in the Authorization for Release of Information
:*Disclosure of research results linked to human subjects to persons or entities not authorized in the Institutional Review Board (IRB) approved protocol
*Workforce members who suspect a breach of confidentiality regarding human subjects research information shall report the breach to the IRB office and/or the Privacy Office.
==Additional Information==
==Additional Information==
*Contact the [mailto:debrbishop@nebraskamed.com Privacy] or [mailto:swelna@unmc.edu Information Security] Officers  
*Note: Corresponds to Nebraska Medicine Policy IM06
*Contact Human Resources – Records at 402/559-8962
*Contact the [mailto:sarah.glodencarlson@unmc.edu Chief Compliance Officer], 402-559-9576 or the UNMC Compliance Office at 402-559-6767
*Exhibit A - [https://www.unmc.edu/hipaa/policies/6045-exhibit-a-statement-of-understanding.pdf Statement of Understanding]
*Compliance Hotline - 800-822-8310
*Contact the [mailto:debrbishop@nebraskamed.com Privacy] or [mailto:libazis@nebraskamed.com Information Security] Officers  
*Contact Human Resources – Records at 402-559-8962 or Human Resources - Employee Relations
*'''[https://www.unmc.edu/academicaffairs/_documents/compliance/Statement_of_Understanding.pdf Statement of Understanding] are these the same thing? if so, what is the correct name and URL?  Nebraska Medicine/UNMC Information Privacy, Confidentiality and Security Agreement'''
*Exhibit B - [https://www.unmc.edu/hipaa/_documents/6045-Exhibit-B-SSN-Student.docx Use of Student Social Security Number Exception]
*Exhibit B - [https://www.unmc.edu/hipaa/_documents/6045-Exhibit-B-SSN-Student.docx Use of Student Social Security Number Exception]
*Exhibit C - [https://www.unmc.edu/hipaa/_documents/6045-Exhibit-C-SSN-Employee.docx Use of Employee Social Security Number Exception]
*Exhibit C - [https://www.unmc.edu/hipaa/_documents/6045-Exhibit-C-SSN-Employee.docx Use of Employee Social Security Number Exception]
*UNMC Policy No. 1098, [https://wiki.unmc.edu/index.php/Corrective/Disciplinary_Action Corrective and Disciplinary Action
*UNMC Policy No. 1098, [https://wiki.unmc.edu/index.php/Corrective/Disciplinary_Action Corrective and Disciplinary Action]
*UNMC Policy No. 6036, [http://wiki.unmc.edu/index.php?title=Reproducing_Copyrighted_Materials Reproduction of Copyrighted Materials Policy]
*UNMC Policy No. 6036, [http://wiki.unmc.edu/index.php?title=Reproducing_Copyrighted_Materials Reproduction of Copyrighted Materials Policy]
*UNMC Policy No. 6052, [http://wiki.unmc.edu/index.php?title=Student_Training_Agreement Contract or Agreement for Student Training Policy]
*UNMC Policy No. 6052, [http://wiki.unmc.edu/index.php?title=Student_Training_Agreement Contract or Agreement for Student Training Policy]
Line 153: Line 123:
*UNMC Policy No. 6073, [[Transporting Protected Health Information]]
*UNMC Policy No. 6073, [[Transporting Protected Health Information]]
*UNMC Policy No. 6085, [[Social Security Number]]
*UNMC Policy No. 6085, [[Social Security Number]]
*UNMC Policy No. 6302, [[Patient Privacy Investigations and Levels of Violation]]
*UNMC Policy No. 8000, [[Compliance Program]]
*UNMC Policy No. 8000, [[Compliance Program]]
*UNMC Policy No. 8009, [[Contracts]]
*UNMC Policy No. 8009, [[Contracts]]
*[https://wiki.unmc.edu/index.php/Business_Associate_Agreements_and_Addendums_Procedures Business Associate Agreements and Addendums Procedures]
*UNMC’s [https://guides.unmc.edu/books/hrpp-policies-and-procedures Human Research Protection Program (HRPP) Policies and Procedures], including HRPP Policy 3.4, “Use of Protected Health Information in Research
*Nebraska Medicine Consents and Permits policy, MS14
*UNMC [https://info.unmc.edu/its-security/policies/procedures/data-classification.html Data Classification Procedure]
*[http://wiki.unmc.edu/index.php?title=Privacy/Information_Security UNMC Privacy and Information Security Policies]
*[http://wiki.unmc.edu/index.php?title=Privacy/Information_Security UNMC Privacy and Information Security Policies]
*[http://wiki.unmc.edu/index.php?title=Human_Resources_-_Procedures UNMC Human Resources Procedures]
*[http://wiki.unmc.edu/index.php?title=Human_Resources_-_Procedures UNMC Human Resources Procedures]
Line 160: Line 135:
*[https://info.unmc.edu/its-security/policies/plan.html Information Security Plan]
*[https://info.unmc.edu/its-security/policies/plan.html Information Security Plan]
*[http://www.unmc.edu/hipaa/_documents/telehealth-final.pdf Telehealth Procedures]
*[http://www.unmc.edu/hipaa/_documents/telehealth-final.pdf Telehealth Procedures]
*[http://www.unmc.edu/media/compliance/privacy_incident_response_and_breach_notification_procedures.pdf Privacy Incident Response and Breach Notification Procedures]
*[https://www.unmc.edu/hipaa/_documents/privacy-incident-response-and-breach-notification-procedures.pdf Privacy Incident Response and Breach Notification Procedures]
*[https://nebraska.edu/site-information.html?redirect=true Copyright and Disclaimer]
*[https://nebraska.edu/offices-policies/general-counsel/practice-areas/intellectual-property Copyright and Disclaimer]
*[https://info.unmc.edu/its-security/policies/procedures/destruction-confinfo.html Destruction of Private and Confidential Information Procedures]
*[https://info.unmc.edu/its-security/policies/procedures/destruction-confinfo.html Destruction of Private and Confidential Information Procedures]
*[http://wiki.unmc.edu/index.php?title=Informed_Consent_for_UNMC_Media_Production_and_Distribution_Procedures Procedures for Obtaining Informed Consent for UNMC Audio-Visual Media Production and Distribution]
*[http://wiki.unmc.edu/index.php?title=Informed_Consent_for_UNMC_Media_Production_and_Distribution_Procedures Procedures for Obtaining Informed Consent for UNMC Audio-Visual Media Production and Distribution]
*[http://www.unmc.edu/hr/Proc/Procedures1097.pdf Human Resources Performance Management Procedures]
*[http://www.unmc.edu/hr/Proc/Procedures1097.pdf Human Resources Performance Management Procedures]
*[http://info.unmc.edu/wiki/index.php/Faculty_Handbook UNMC Faculty Handbook: Operating Procedures]
*[http://info.unmc.edu/wiki/index.php/Faculty_Handbook UNMC Faculty Handbook: Operating Procedures]
*[http://www.unmc.edu/studentservices/_documents/handbook.pdf UNMC Student Handbook: Academic Policies]
*[http://catalog.unmc.edu/general-information/ Student Handbook]
*[https://aspe.hhs.gov/report/health-insurance-portability-and-accountability-act-1996 Health Insurance Portability and Accountability Act of 1996] (HIPAA)
*[https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final NIST Special Publication 800-53]
*[https://www.cdc.gov/phlp/publications/topic/hipaa.html Health Insurance Portability and Accountability Act of 1996] (HIPAA)
*[https://www.cdc.gov/phlp/publications/topic/hipaa.html#security-rule HIPAA Security Rule]
*[http://www.ftc.gov/privacy/privacyinitiatives/glbact.html Gramm-Leach-Bliley Act] (GLBA)
*[http://www.ftc.gov/privacy/privacyinitiatives/glbact.html Gramm-Leach-Bliley Act] (GLBA)
*[http://www.ed.gov/offices/OM/fpco/ferpa/index.html Family Educational Rights and Privacy Act] (FERPA)
*[http://www.ed.gov/offices/OM/fpco/ferpa/index.html Family Educational Rights and Privacy Act] (FERPA)
*Nebraska Free Flow of Information Act (§ 20-144, 20-145, 20-146, 20-1470)
*University of Nebraska [https://nebraska.edu/-/media/unca/docs/offices-and-policies/policies/board-governing-documents/board-of-regents-bylaws.pdf?la=en Board of Regents Bylaws]
*[http://nebraskalegislature.gov/laws/laws.php Nebraska Rev. Statutes] § 84-712, 84-712.01, 84-712.02, 84-712.03, 84-712.04, 84-712.05, 84-712.06, 84-712.07, 84-712.08, 84-712.09
*University of Nebraska [https://nebraska.edu/-/media/unca/docs/offices-and-policies/policies/board-governing-documents/board-of-regents-policies.pdf?la=en Board of Regents Policies]
*[http://www.nebraska.edu/bylaws-and-policies.html Board of Regents Bylaws and Policies]
*[https://nebraska.edu/-/media/unca/docs/offices-and-policies/policies/executive-memorandum/policy-for-responsible-use-of-university-computers-and-information-systems.pdf Executive Memorandum No. 16, Policy for Responsible Use of University Computers and Information Systems]
*[http://www.nebraska.edu/docs/president/16%20Responsible%20Use%20of%20Computers%20and%20Info%20Systems.pdf Executive Memorandum No. 16, Responsible Use of Information Resources, Technology and Networks]
*[https://nebraska.edu/-/media/unca/docs/offices-and-policies/policies/executive-memorandum/public-records-request.pdf Executive Memorandum No. 22, Public Record Requests]
*[https://nebraska.edu/docs/president/22%20Public%20Record%20Requests.pdf Executive Memorandum No. 22, Public Record Requests]
*[https://nebraska.edu/-/media/unca/docs/offices-and-policies/policies/executive-memorandum/university-of-nebraska-information-security-plan.pdf Executive Memorandum No. 26, Information Security Plan - Gramm Leach Bliley Compliance]
*[https://nebraska.edu/docs/president/26%20Information%20Security%20Plan%20%28GLB%20Compliance%29.pdf Executive Memorandum No. 26, Information Security Plan]
*[https://nebraska.edu/-/media/unca/docs/offices-and-policies/policies/executive-memorandum/hipaa-compliance-policy.pdf Executive Memorandum No. 27, HIPAA Compliance Policy]
*[https://nebraska.edu/docs/president/27%20HIPAA%20Compliance.pdf Executive Memorandum No. 27, HIPAA Compliance Policy]
*Executive Memorandum No. 41, [https://nebraska.edu/-/media/unca/docs/offices-and-policies/policies/executive-memorandum/policy-on-research-and-data-security.pdf Policy on Research Data and Security]
*[http://www.unmc.edu/com/about/gme/gme-housestaff.pdf University of Nebraska Residency Program Policies and Procedures]
*Executive Memorandum No. 42, [https://nebraska.edu/-/media/unca/docs/offices-and-policies/policies/executive-memorandum/policy-on-risk-classification-and-minimum-security-standards.pdf Policy on Risk Classification and Minimum Security Standards]
*[https://www.unmc.edu/com/about/gme/housestaffmanual.pdf University of Nebraska Affiliated Hospital House Staff Manual 2022 – 2023]
*[https://www.unmc.edu/vcr/about/research-handbook-web.pdf Research Handbook]
*[https://www.unmc.edu/vcr/about/research-handbook-web.pdf Research Handbook]
*[http://www.unmc.edu/irb/ Institutional Review Board Guidelines]
*[http://www.unmc.edu/irb/ Institutional Review Board Guidelines]
*[https://csrc.nist.gov/Projects/protecting-controlled-unclassified-information/sp-800-171 Protecting Controlled Unclassified Information] (CUI)
*[https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final Security and Privacy Controls for Information Systems and Organizations]


 
This page maintained by [mailto:dpanowic@unmc.edu dkp].
 
Technology Services Procedures]This page maintained by [mailto:dpanowic@unmc.edu dkp].

Revision as of 14:54, November 29, 2022

Human Resources   Safety/Security   Research Compliance   Compliance   Privacy/Information Security   Business Operations   Intellectual Property   Faculty


Identification Card | Secure Area Card Access | Privacy/Confidentiality | Computer Use/Electronic Information | Retention and Destruction/Disposal of Private and Confidential Information | Use and Disclosure of Protected Health Information | Notice of Privacy Practices | Access to Designated Record Set | Accounting of PHI Disclosures | Patient/Consumer Complaints | Vendors | Fax Transmissions | Psychotherapy Notes | Facility Security | Conditions of Treatment Form | Informed Consent for UNMC Media | Transporting Protected Health Information | Honest Broker | Social Security Number | Third Party Registry | Information Security Awareness and Training | Patient Privacy Investigations and Levels of Violation | Use and Disclosure of PHI for Training Health Care Professionals | Disclosures of PHI as Permitted or Required by Law | Disclosure of PHI for Law Enforcement Purposes

Policy No.: 6045
Effective Date: 11/21/03
Revised Date: 11/29/22 draft
Reviewed Date:

Privacy, Confidentiality and Security of Patient and Proprietary Information Policy

Basis for Policy

Nebraska Medicine/UNMC implements reasonable and appropriate access controls in alignment with National Institute of Standards and Technology (NIST) standards and guidance to maintain the minimum necessary access. NIST Special Publication 800-53 and the HIPAA Security Rule outline considerations for the access control family of security controls.

Policy

It is the policy of Nebraska Medicine/UNMC to maintain strict confidentiality and security of protected health information (PHI) and proprietary information.

Procedures

  1. Records containing confidential information, in any form, are the property of Nebraska Medicine/UNMC. The original medical record in any form shall not be released except in response to a valid search warrant, subpoena or court order requiring the release of the original record. A copy of the medical record should be offered first in such circumstances. If the original medical record must be released, a copy should be made prior to release if possible.
  2. Individuals have the following rights with respect to their PHI: </b
    1. Right to request access to inspect or to obtain a copy of their PHI in a designated record set and to receive such access (where granted) within a reasonable amount of time and to request amendment (see UNMC Policy No. 6059, Access and & Amendment of Designated Record Set);
    2. Right to request restrictions of how their PHI is used and disclosed (see UNMC Policy No. 6057, Use & Disclosure of Protected Health Information);
    3. Right to request an accounting of disclosures (see UNMC Policy No. 6061, Accounting of Protected Health Information Disclosures);
    4. Right to receive a Notice of Privacy Practices (see UNMC Policy No. 6058, Notice of Privacy Practices); and
    5. Right to file a complaint internally with the Patient Relations Department or with the U.S. Department of Health and Human Services Office for Civil Rights (see UNMC Policy No. 6058, Notice of Privacy Practices, UNMC Policy No. 6062, Patient/Consumer Complaints and Nebraska Medicine Patient Complaint and Grievance Management policy needpolicy #
      Individuals shall not be asked to waive these rights as a condition of receiving treatment.
  3. Nebraska Medicine/UNMC is responsible for safeguarding and protecting confidential information against loss, tampering and use by or disclosure to unauthorized individuals. The safeguarding of confidential information in any form includes when the information is stored and/or being transferred outside the facility (see UNMC Policy No. 6073, Transporting Protected Health Information).
  4. Nebraska Medicine/UNMC workforce has a duty to protect confidential information. Breach of this duty includes but is not limited to the following:
    1. Accessing confidential information, in any form, without a current "need to know" to perform assigned duties. Workforce members may not access their own records. Workforce members may not access records of family members (including children), relatives, friends and others, unless access is necessary to perform assigned duties. Workforce members may obtain a copy of their medical records from the Health Information Management Department or via the online patient portal.
    2. Discussing or disclosing patient care events/PHI to individuals who do not have a “need to know” this information to perform assigned duties, even if the patient’s name is not mentioned. The facts surrounding patient care are confidential and can lead to the identity of the patient.
    3. Disclosing confidential information without proper authorization (see UNMC Policy No. 6057, Use and Disclosure of Protected Health Information);
    4. Accessing patient information via Health Information Exchange in a manner or for a purpose not permitted (see UNMC Policy No. 6057, Use and Disclosure of Protected Health Information);
    5. Discussing confidential information in the presence of individuals who do not have the "need to know" to perform assigned duties;
    6. Disclosing that a patient is receiving care (except for authorized directory purposes);
    7. Leaving confidential information unattended in a non-secure area;
    8. Improper disposal of confidential information (see policy, “Destruction of Confidential Information”);
    9. Using another person's user ID, password or other security codes;
    10. Assisting an unauthorized user to gain access to a secured information system;
    11. Transferring confidential information in any form without both parties having a need to know such confidential information.
  5. Nebraska Medicine/UNMC shall mitigate or reduce, to the extent practicable, any harmful effects of a use or disclosure of PHI in violation of its policies and procedures that is known to Nebraska Medicine/UNMC.
  6. All employees, the medical staff, allied health practitioners and members of the Workforce with access to confidential information shall sign Nebraska Medicine/UNMC Information Privacy, Confidentiality and Security Agreement upon initial employment/work/appointment/credentialing (need URL for attachment to link to the policy).
  7. Workforce members who suspect a privacy or information security violation must report it immediately. Such reports may be made to their respective manager and the Privacy and/or Information Security Office. Alternatively, staff who wish to remain anonymous may report the suspected violation to the Compliance Hotline at 800-822-8310. A full investigation of the suspected violation shall be conducted. Sanctions shall be imposed for substantiated breaches or failure to report suspected violations. The Medical Staff and allied health practitioners shall report suspected violations to the System Chief Medical Officer (how to contact that person??).
  8. Sanctions for violations of privacy or information security may include revocation of medical staff privileges or allied health credentials, or employee corrective action up to and including termination of employment (see UNMC Policy No. 6302, Patient Privacy Investigations and Levels of Violation). Civil and criminal fines and penalties can also be levied under HIPAA.
  9. Workforce members may not intimidate, threaten, coerce, discriminate against, or take other retaliatory action against any individual for reporting a suspected privacy or information security violation, or for filing of a complaint within Nebraska Medicine/UNMC or to the Office for Civil Rights (see Procedures, Section 2.2).
  10. Access to patient information via Health Information Exchange shall be conducted in accordance with UNMC Policy No. 6057, Use and Disclosure of Protected Health Information.
  11. Paper medical records shall be maintained in the Health Information Management Department.
    1. Records sent to clinic areas shall be returned to the Health Information Management Department within one working day.
    2. Records of discharged patients will remain on the units until the Health Information Management Department picks them up. Medical records of deceased patients scheduled for an autopsy may be sent to the morgue.
    3. Records signed out to the attending physician's office or other authorized areas shall be returned to the Health Information Management Department as soon as possible (preferably by 5:00 pm each working day).
  12. Editing, authenticating and correcting the medical record.
    1. See Nebraska Medicine Policy, “Contents of Medical Record”, for editing and authenticating the medical record.(Nebraska Medicine Policy number??)
  13. A Business Associate Agreement or Addenda shall be executed with each Business Associate
  14. Human Subjects Research shall be conducted in accordance with UNMC’s Human Research Protection Program (HRPP) Policies and Procedures, including HRPP Policy 3.4, “Use of Protected Health Information in Research" and UNMC Policy No. 6057, Use and Disclosure of Protected Health Information.
  15. Retention of the designated record set and other protected health information shall be in accordance with federal, state and local laws and regulatory association guidelines. Documents required to demonstrate HIPAA compliance shall be retained for a period of six years.

Definitions

Affiliated Covered Entity (ACE)

Legally separate covered entities that are affiliated and designate themselves as a single covered entity for the purpose of HIPAA Compliance. Current ACE members are: The Nebraska Medical Center, UNMC Physicians, UNMC, University Dental Associates, Bellevue Medical Center and Nebraska Pediatric Practice, Inc. d/b/a Children’s Specialty Physicians. ACE membership may change from time to time. The Notice of Privacy Practices lists current ACE members. Access and amendment rights apply to designated record sets throughout the ACE.

Business Associate

A third party who performs services on behalf of Nebraska Medicine/UNMC that involve the creation, receipt, maintenance or transmission of PHI. Some examples of such services include claims processing, data analysis, data processing, practice management, utilization review, quality assurance, patient safety activities, billing, benefit management and repricing.

Designated Record Set (DRS)

Includes medical records and billing records about Individuals maintained by or for UNMC/ACE and any other record used by an ACE entity to make decisions about Individuals. Exact duplicates of records maintained by business associates are not considered part of the DRS.

Individual

The person who is the subject of the PHI. Personal representatives of the patient have the same rights as the Individual under HIPAA (i.e., they “step into the shoes” of the Individual). Personal representatives include the legal guardian and anyone else authorized by law to act on behalf of the Individual. (See Nebraska Medicine Consents and Permits policy, MS14).

Protected Health Information (PHI)

Individually identifiable health information including demographic information, collected from an Individual, whether oral or recorded in any medium, that:

  • is created or received by UNMC/ACE; and
  • relates to the past, present or future physical or mental health or condition of an Individual; the provision of health care to an Individual; or the past, present or future payment for the provision of health care to an Individual and identifies the Individual or with respect to which there is a reasonable basis to believe the information can be used to identify the Individual.

PHI includes genetic information, which includes information about the following items (and excludes information about an Individual’s sex or age):

  • an Individual’s genetic tests;
  • the genetic tests of an Individual’s family members; or
  • the manifestation of a disease or disorder in such Individual’s family members (i.e., family medical history); or
  • any request for, or receipt of, genetic services (e.g., genetic test, genetic counseling, genetic education), or participation in clinical research which includes genetic services by the Individual or any family member of the Individual.

PHI excludes:

  • individually identifiable health information of a person who has been deceased for more than fifty (50) years.
  • education records covered by the Family Educational Rights and Privacy Act (FERPA); and
  • employment records held by UNMC in its role as employer.

Workforce

Employees, medical staff, volunteers, trainees and other persons whose conduct, in the performance of work for Nebraska Medicine/UNMC, is under the direct control of Nebraska Medicine/UNMC, whether or not they are paid by Nebraska Medicine/UNMC.

In addition for purposes of this policy.

Information Security

The set of policies and practices designed to protect PHI from any unauthorized access, use, disclosure, modification, destruction or loss.

Proprietary Information

Information relating to Nebraska Medicine/UNMC business practices, including but not limited to financial statements, contracts, and business plans, employee records and meeting minutes.

Additional Information

This page maintained by dkp.