Can someone do my Week 5 discussion IN MHA 616 Health Care Management Information Systems

profileCrowe71
CHAPTER12.docx

CHAPTER 12

Privacy and Security

LEARNING OBJECTIVES

To be able to distinguish among privacy, confidentiality, and security as they relate to health information.

To be able to describe and discuss the impact of the HIPAA Privacy, Security, and Breach Notification rules.

To be able to identify threats to health care information and information systems caused by humans (intentional and unintentional), natural causes, and the environment.

To be able to understand the purpose and key components of the health care organization security program and the need to mitigate security risks.

To be able to discuss the increased need for and identify resources to improve cybersecurity in health care organizations.

Health information privacy and security are key topics for health care administrators. In today's ever-increasing electronic world, where nearly every health care organization employee and visitor have smartphones, and health care equipment and devices are connected to the Internet, new and more virulent security threats are an everyday concern. In spite of the legislated protections discussed in this chapter, between 2009 and 2020 health care entities reported over 3,700 health information breaches of at least five hundred records, resulting in 266 million health or health-related records being exposed or improperly disclosed. The largest breach in 2020 was a ransomware attack on Blackbaud, Inc., a cloud-based service provider; over one hundred health care organizations were impacted by this attack alone (Adler, 2021c).

In this chapter we examine and define the concepts of privacy, confidentiality, and security as they apply to health information. Major legislative efforts to protect health care information are outlined, with a focus on the Health Insurance Portability and Accountability Act (HIPAA) Privacy, Security, and Breach Notification rules. Different types of threats to health information, human, natural and environmental, are discussed, and requirements for a strong health care organization security program are outlined. The chapter also includes a broad discussion of cybersecurity challenges in today's environment.

PRIVACY, CONFIDENTIALITY, AND SECURITY DEFINED

Privacy is an individual's right to be left alone and, in the health care arena, to limit access to their health care information. Individuals control their rights to privacy. Confidentiality is related to privacy but specifically addresses the expectation that information shared with a health care provider during the course of treatment will be used only for its intended purpose and not disclosed otherwise. Confidentiality relies on the trusted relationships among providers and patients; the provider has a professional duty to maintain confidentiality. Security refers to the systems that are in place to protect health information, the systems within which it resides, and the IT assets that support those systems. Health care organizations must protect their health information, health care information systems, and IT assets from a range of potential threats.

LEGAL PROTECTION OF HEALTH INFORMATION

There are ethical and legal reasons health care professionals maintain the confidentiality of patient information and protect patient privacy. Professional ethics and standards address professional conduct and the need to hold patient information in confidence. Accrediting bodies, such as the Joint Commission, state facility licensure rules, and the Centers for Medicare & Medicaid Services (CMS) dictate that health care organizations follow standard practice, along with state and federal laws, to ensure the confidentiality and security of patient information.

Today, legal protection specially addressing the unauthorized disclosure of an individual's health information generally comes from one of three sources (Koch, 2016):

Federal HIPAA Privacy, Security, and Breach Notification rules

State privacy laws. These laws typically apply more stringent protections for information related to specific health conditions (HIV/AIDS, mental or reproductive health, for example).

Federal Trade Commission (FTC) Act consumer protection, which protects against unfair or deceptive practices.

There is a fourth major federal law providing an extra level of protection to substance use disorder patients' privacy, which is also important to understand.

Confidentiality of Substance Abuse Patient Records (42 U.S.C. §290dd-2, 42 C.F.R. Part 2)

HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA)

Enacted in 1996, HIPAA was the first comprehensive federal regulation to offer specific protection to private health information. Prior to the enactment of HIPAA there was no single federal regulation governing the privacy and security of patient-specific information; existing laws were not comprehensive and protected only specific groups of individuals.

HIPAA actually consists of contains five sections, or titles, outlining rules to improve citizens' access and maintenance of health insurance and to ensure health information privacy and security.

Title I protects health insurance coverage for individuals who lose or change jobs. It also prohibits group health plans from denying coverage to individuals with specific diseases and preexisting conditions, and from setting lifetime coverage limits.

Title II directs the U.S. Department of Health and Human Services (HHS) to establish national standards for processing electronic healthcare transactions. It also requires health care organizations to implement secure electronic access to health data and to remain in compliance with privacy regulations set by HHS.

Title III includes tax-related provisions and guidelines for medical care.

Title IV further defines health insurance reform, including provisions for individuals with preexisting conditions and those seeking continued coverage.

Title V includes provisions on company-owned life insurance and the treatment of those who lose their U.S. citizenship for income tax purposes.

However, within the health care industry, adhering to HIPAA Title II is what is meant when referring to HIPAA. Also known as the Administrative Simplification provisions, Title II includes the following compliance requirements:

National Provider Identifier Standard. Each health care entity, including individuals, employers, health plans, and health care providers, must have a unique ten-digit national provider identifier number, or NPI.

Transactions and Code Sets Standard. Health care organizations must follow a standardized mechanism for electronic data interchange (EDI) in order to submit and process insurance claims.

HIPAA Privacy Rule. Officially known as the Standards for Privacy of Individually Identifiable Health Information, this rule establishes national standards to protect patient health information.

HIPAA Security Rule. The Security Standards for the Protection of Electronic Protected Health Information sets standards for patient data security.

HIPAA Enforcement Rule. This rule establishes guidelines for investigations into compliance violations.

The Privacy Rule was required beginning April 2003 and the Security Rule beginning April 2005. Both rules were subsequently amended and the Breach Notification Rule was added as a part of the HITECH Act in 2009.

Covered Entities

HIPAA Rules apply to covered entities (CEs), defined as health plans, organizations that pay or provide for the cost of medical care; health care clearinghouses, entities that process health information (for example, billing services); and health care providers who conduct certain financial and administrative transactions electronically. These transactions are defined broadly so that in reality HIPAA Rules govern nearly all health care providers who receive any type of third-party reimbursement.

If a CE routinely shares information with other business associates, it must establish contracts to protect the shared information. The HITECH Act expanded Business Associates as a category of CE, further clarifying that certain entities, such as health information exchange (HIE) organizations, regional health information organizations, e-prescribing gateways, Internet service providers, and vendors that provide a personal health record as a part of its EHR, are business associates when they require access to PHI on a routine basis (Coppersmith, Gordon, Schermer, & Brokelman, PLC, 2012).

Protected Health Information

The information protected under the HIPAA Privacy Rule is defined as protected health information (PHI), which is information that

Relates to a person's physical or mental health, the provision of health care, or the payment for health care.

Identifies the person who is the subject of the information.

Is created or received by a covered entity.

Is transmitted or maintained in any form (paper, electronic, or oral).

The Security Rule addresses PHI transmitted or maintained in electronic form. Within the Security Rule this information is identified as electronic protected health information (ePHI).

Specifics of the HIPAA Rules are discussed in subsequent sections in this chapter.

STATE PRIVACY LAWS

Although HIPAA is a comprehensive set of federal standards, it permits the enforcement of existing state laws that are more protective of individual privacy, and states are also free to pass more stringent laws. Therefore, health care organizations must still be familiar with their own state laws and regulations related to privacy and confidentiality.

FEDERAL TRADE COMMISSION BREACH NOTIFICATION RULE

More and more, personal medical information is online. Technologies that support personal health records and applications that collect information from patients or allow uploading of health-related data from wearable devices are common, as is the use of health-related social media sites. These technologies were not addressed in HIPAA and, therefore, do not meet the criteria as covered entities (DeSalvo & Samuels, 2016).

As a consequence, the Federal Trade Commission (FTC), the nation's consumer protection agency, issued the Health Breach Notification Rule to require these businesses to notify their customers and others if there is a breach of unsecured, individually identifiable electronic health information. The Rule applies to:

Vendors of personal health records (PHRs)

PHR-related entities

Third-party service providers for vendors of PHRs or PHR-related entities

CONFIDENTIALITY OF SUBSTANCE ABUSE PATIENT RECORDS

During the 1970s, people became increasingly aware of the extra-sensitive nature of drug and alcohol treatment records and that failure to provide specific protections might prevent individuals from seeking treatment. 42 C.F.R. (Code of Federal Regulations) Part 2, Confidentiality of Substance Abuse Patient Records was enacted to provide more stringent protection to information that identifies an individual, directly or indirectly, as having a current or past drug or alcohol problem, or as a participant in a covered alcohol or drug program. Again, covered programs are defined broadly and essentially include any programs that receive third-party reimbursement.

With limited exceptions, 42 CFR Part 2 requires patient consent for disclosures of protected health information, even for the purposes of treatment, payment, or health care operations. And, the consent for disclosures must be in writing. These regulations have been amended several times, but their fundamental purpose has remained unchanged. In 2017 42 CFR Part 2 was amended to better align it with HIPAA privacy and security regulations, and in 2020 it was amended to facilitate better care coordination in response to the opioid epidemic (US Department of Health and Human Services, 2020a).

HIPAA PRIVACY RULE

The major components to the HIPAA Privacy Rule in its original form fall into one of five categories:

Boundaries. Only the minimum necessary PHI may be disclosed, and only for treatment, payment, and operations (TPO) purposes, with limited exceptions.

Security. PHI should not be distributed without patient authorization unless there is a clear basis for doing so, and the individuals who receive the information must safeguard it. (This section should not be confused with the separate HIPAA Security Rule.)

Consumer control. Individuals are entitled to access and control their health records and are to be informed of the purposes for which information is being disclosed and used.

Accountability. Entities that improperly handle PHI are subject to civil recourse and can be charged under criminal law.

Public responsibility. Individual interests must not override national priorities in public health, medical research, preventing health care fraud, and law enforcement.

With HITECH, the Privacy Rule not only expanded privacy requirements for covered entities and their business associates, but also strengthened the rights of individuals to request and obtain their PHI and to prevent a health care organization from disclosing PHI to a health plan, if the patient paid in full out of pocket. HITECH also added provisions for accounting of disclosures made through an EHR for treatment, payment, and operations (Coppersmith et al., 2012).

The HIPAA Privacy Rule attempts to sort out the routine and nonroutine use of health information by distinguishing between patient consent to use PHI and patient authorization to release PHI. Health care providers and others must obtain a patient's consent prior to disclosing health information for routine uses of treatment, payment, and health care operations (TPO). This consent is general in nature, does not always need to be written, and is obtained prior to patient treatment. There are some exceptions to this in emergency situations, and the patient has a right to request restrictions on the disclosure. However, health care providers can deny treatment if they feel that limiting the disclosure would be detrimental.

HIPAA REQUIRED AUTHORIZATION FOR RELEASE OF INFORMATION

Under HIPAA the patient's specific written authorization for all nonroutine uses or disclosures of PHI (i.e., uses and disclosures for reasons other than TPO) is required, with limited exceptions.

Exhibit 12.1 is a sample release of information form used by a hospital, showing the following elements needed for a valid release:

Patient identification (name and date of birth)

Name of the person or entity to whom the information is being released

Description of the specific health information authorized for disclosure

Statement of the reason for or purpose of the disclosure

Date, event, or condition on which the authorization will expire, unless it is revoked earlier

Statement that the authorization is subject to revocation by the patient or the patient's legal representative

Patient's or legal representative's signature

Signature date, which must be after the date of the encounter that produced the information to be released

Health care organizations also need clear policies and procedures for releasing PHI. A central point of control should exist through which all nonroutine requests for information pass and all disclosures are documented.

In addition to release of PHI for TPO, HIPAA outlines other situations for which specific authorization for release of PHI is not required, including release to the individuals themselves, incidental disclosures (patient sign-in sheets in a waiting room or custodial staff encountering patient records, for example), release of a limited data set, and release for public interest and benefit purposes.

Specific authorization may not be required for releasing a limited set of data, PHI that has some but not all identifiers removed as defined in the Rule, to researchers or others with which the organization has entered into a data use agreement. Public interest and benefit purposes include situations in which information must be disclosed to authorized recipients, such as the required reporting of a communicable disease (e.g. AIDS and sexually transmitted diseases) to the state or county department of health; reporting suspected child abuse or adult abuse to designated authorities; releasing information in situations where a legal duty exists to warn another person of a clear and imminent danger from a patient; accessing information for bona fide medical emergencies; and releasing information requested through a valid court order. In all cases, the principle of releasing only the minimum necessary information applies. See Table 12.1 for a list of the twelve HIPAA public interest and benefit purpose exceptions.