(Baccalaureate).
Student instructions
1. If you have questions about this activity, please contact your instructor for
assistance.
2. You will review the chart of Melissa Baker to complete this activity. Your
instructor has provided you with a link to the Release of Information
(BS) activity. Click on 2: Launch EHR to review the patient chart and begin this
activity.
3. Refer to the patient chart and any suggested resources to complete this activity.
4. Document your answers directly on this activity document as you complete the
activity. When you are finished, you will save this activity document to your
device and upload this activity document with your answers to your Learning
Management System (LMS).
Learning objectives
• Recommend privacy strategies for health information (5)
• Recommend security strategies for health information (5)
• Analyze compliance requirements throughout the health information life cycle (4)
• Comply with legal processes impacting health information (5)
• Evaluate compliance with external forces (5)
Introduction
Release of Information (ROI)
Release of information is the divulgence of an individual's health information by an
entity, such as a hospital or doctor's office, to a person or organization outside of that
entity. Release of information is covered by the Health Insurance Portability and
Accountability Act. ("HIPAA for Professionals", n.d.).
HIPAA
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) was enacted to
improve the efficiency and integrity of health care. With the realization that privacy of
health information could be affected by advancements in technology, Congress added
provisions to HIPAA mandating the adoption of federal protection of privacy for
protected health information (PHI), defined as all "individually identifiable health
information". These provisions include the HIPAA Privacy Rule and the HIPAA Security
Rule. These rules apply to all covered entities, defined as health plans, health care
, providers who conduct transactions electronically and health care clearinghouses.
("HIPAA for Professionals", n.d.).
HIPAA Privacy Rule
The Privacy Rule establishes national standards to strike the balance of ensuring
consumers' health information receives proper protection while still allowing the flow of
health-related information necessary for high quality health care. Recognizing that the
marketplace for healthcare is large and diverse, the Privacy Rule is marked by its
flexibility.
In a nutshell, the Privacy Rule protects all individually identifiable health information, in
any form - verbal, paper or electronic. Such information includes data that could be
used to identify an individual and includes such data as demographics, information on
the individual's past, present or future physical or mental health, provision of health care
or payment for health care. ("Summary of the HIPAA Privacy Rule", n.d.).
HIPAA Security Rule
The Security Rule takes the protections set forth in the Privacy Rule and outlines the
safeguards organizations must put in place to secure consumers' electronic protected
health information (e-PHI). The Security Rule specifically addresses health information
in electronic form. The Security Rule aims to be flexible to allow organizations to adapt
to new technologies regardless of their size and structure while still protecting the
privacy of consumers' health information. ("Summary of the HIPAA Security Rule", n.d.).
Authorized Uses and Disclosures
Authorization: A covered entity may require the patient's written authorization to
release the patient's PHI. The authorization must be in plain language and include
specific information about the information to be disclosed, the person(s) or entity
receiving and disclosing the information, and an expiration date. ("Individuals' Right
under HIPAA", n.d.).
Verification: A covered entity must take reasonable steps to verify the identity of an
individual requesting access to PHI under the Privacy Rule. The Rule does not require
any specific form of verification (e.g. a copy of a driver's license or state identification
card). Rather, the Rule leaves the type and manner of verification to the covered entity's
discretion and judgment. However, the verification must not "create barriers to or
unreasonably delay the individual from obtaining access to his or her PHI". ("Individuals'
Right under HIPAA", n.d.).
Examples of Unreasonable Measures
• Requiring a patient to physically come to the covered entity's facility to provide
proof of her identity and request access in person
• Using only a web portal for requesting access, when not all individuals have
access to a computer or device with Internet access
• Using only mail to receive and deliver access requests, as this would cause
an unreasonable delay
While a covered entity may not require individuals to request access in these
manners, a covered entity may permit an individual to do so. The Rule
encourages covered entities to offer patients multiple options for requesting
access to PHI. ("Individuals' Right under HIPAA", n.d.).