foundations of professional nursing discussion 2

profileVRT004
SUO_NSG3007_W2_LegalAspects.pdf

Legal Aspects of Nursing

© 2017 South University

HIPAA and Patient Confidentiality

HIPAA mainly encompasses two rules—The Privacy Rule and the Security Standard Rule. The Privacy Rule (Standards for Privacy of Individually Identifiable Health Information) regulates the use and disclosure of PHI. Medical records of patient with a mental illness may require additional safety measures under the law. According to Gates, Moore & Company (2002), the Privacy Rule has three essential purposes:

• To protect the rights of patients by providing access to their PHI and the ability to control the use and disclosure of it

• To restore public trust in the healthcare delivery system

• To improve the efficiency and effectiveness of healthcare delivery in the US by creating a national framework of healthcare privacy

The Privacy Rule states that PHI can only be used and disclosed for treatment, payment, or healthcare operations without a patient authorization. Any other uses require patient autho- rization before the PHI is released. The rule also generally limits the release of information to the minimum necessary for the purpose of the disclosure so that irrelevant information is not released. The limitation of only releasing the minimum necessary information does not apply when the PHI is disclosed to another practitioner for direct treatment. The rules make allow- ances for public health responsibilities to allow the collection of information to prevent or control disease, injury, and disability, including public health surveillance, investigation, and intervention. The HIPAA limitations do not apply to information that is de-identified so that the patients cannot be connected with their PHI.

Privacy Rules

Beyond limiting the practitioner’s ability to use or disclose PHI without a patient’s authori- zation, the Privacy Rule gives patients more control over their health information. The first step in providing the patient with more control is the mandatory requirement of healthcare providers to provide the patient with a copy of their “Notice of Privacy Practices.” The Notice of Privacy Practices outlines for the patient their rights to privacy and how their personal health information will be routinely used for treatment, payment, and healthcare operations within the healthcare setting. The provider must also obtain a written acknowledgment from the patient that he or she received a copy of the notice (Conklin, 2001).

If the PHI must be released for purposes other than treatment, payment, or healthcare oper- ations, it requires a signed authorization from the patient. This enables patients to make informed choices about how their individual health information may be used or disclosed. The HIPAA privacy rules go beyond mandating an authorization for release of information—it requires tracking the disclosures of PHI. As a result, patients can find out how their health information has been used or released. Patients also have the right to obtain a copy of their medical record and can review, correct, or amend the PHI. There are policies and procedures in place for patient review, correction, or amend- ment of PHI. Patients can make corrections or amendments to the health record only with their physician’s approval.

Reference: US Department of Health and Human Services. (n.d.). Summary of HIPAA privacy rule. Retrieved from http://

www.hhs.gov/hipaa/for- professionals/privacy/laws-regulations/index.html