SlideShare a Scribd company logo
Health Information Privacy
Carrie Waggoner
Privacy Specialist
Connecting Michigan For Health, June 6, 2013
To identify what requirements must be
met to share information, ask:
• Who is sharing
• What
information
• With whom
• For what purpose
Important Privacy Issues:
• HIPAA & Other Compliance
Initiatives
• Mobile Devices
• Coordination with Security
Important Privacy Issues in the HIE
Context:
• Mental Health & Substance Abuse
• Public Trust & Buy-in

More Related Content

More from mihinpr

Connecting Patients, Providers and Payers John Halamka Keynote
Connecting Patients, Providers and Payers John Halamka KeynoteConnecting Patients, Providers and Payers John Halamka Keynote
Connecting Patients, Providers and Payers John Halamka Keynote
mihinpr
 
A Vision for Creating a Connected State Subra Sripada
A Vision for Creating a Connected State Subra SripadaA Vision for Creating a Connected State Subra Sripada
A Vision for Creating a Connected State Subra Sripada
mihinpr
 
Panel: Understanding Michigan's HIE Landscape
Panel: Understanding Michigan's HIE LandscapePanel: Understanding Michigan's HIE Landscape
Panel: Understanding Michigan's HIE Landscape
mihinpr
 
Panel Interstate and Other State HIE HIT
Panel Interstate and Other State HIE HITPanel Interstate and Other State HIE HIT
Panel Interstate and Other State HIE HIT
mihinpr
 
Panel: Transitions of Care and ADT (without Rachel Sherman)
Panel: Transitions of Care and ADT (without Rachel Sherman)Panel: Transitions of Care and ADT (without Rachel Sherman)
Panel: Transitions of Care and ADT (without Rachel Sherman)
mihinpr
 
State of Michigan HIE Update (without Tina Scott)
State of Michigan HIE Update (without Tina Scott)State of Michigan HIE Update (without Tina Scott)
State of Michigan HIE Update (without Tina Scott)
mihinpr
 
Health IT and Public Policy Issues Dr. Rich Hodge
Health IT and Public Policy Issues Dr. Rich HodgeHealth IT and Public Policy Issues Dr. Rich Hodge
Health IT and Public Policy Issues Dr. Rich Hodge
mihinpr
 
A Consistent Nationwide Data Matching Strategy Donna Roach & Nancy Walker
A Consistent Nationwide Data Matching Strategy Donna Roach & Nancy WalkerA Consistent Nationwide Data Matching Strategy Donna Roach & Nancy Walker
A Consistent Nationwide Data Matching Strategy Donna Roach & Nancy Walker
mihinpr
 
Jennifer Horowitz EHR Adoption in Michigan & Nationwide
Jennifer Horowitz EHR Adoption in Michigan & NationwideJennifer Horowitz EHR Adoption in Michigan & Nationwide
Jennifer Horowitz EHR Adoption in Michigan & Nationwide
mihinpr
 
Panel: Achieving Interoperability Dr. John Loonsk & Janet King
Panel: Achieving Interoperability Dr. John Loonsk & Janet KingPanel: Achieving Interoperability Dr. John Loonsk & Janet King
Panel: Achieving Interoperability Dr. John Loonsk & Janet King
mihinpr
 
Dr. Charles Friedman Transcending HIE
Dr. Charles Friedman Transcending HIEDr. Charles Friedman Transcending HIE
Dr. Charles Friedman Transcending HIE
mihinpr
 
Doug Dietzman National HIE Landscape
Doug Dietzman National HIE LandscapeDoug Dietzman National HIE Landscape
Doug Dietzman National HIE Landscape
mihinpr
 
Brian Balow HIPAA Final Rule
Brian Balow HIPAA Final RuleBrian Balow HIPAA Final Rule
Brian Balow HIPAA Final Rule
mihinpr
 
Panel Cyber Security and Privacy without Carrie Waggoner
Panel Cyber Security and Privacy without Carrie WaggonerPanel Cyber Security and Privacy without Carrie Waggoner
Panel Cyber Security and Privacy without Carrie Waggoner
mihinpr
 
Andrea walrath mu stage 2 and beyond
Andrea walrath mu stage 2 and beyondAndrea walrath mu stage 2 and beyond
Andrea walrath mu stage 2 and beyond
mihinpr
 
MiHIN Brief Overview
MiHIN Brief OverviewMiHIN Brief Overview
MiHIN Brief Overviewmihinpr
 
Michigan HIE Model- Cynthia Edwards
Michigan HIE Model- Cynthia EdwardsMichigan HIE Model- Cynthia Edwards
Michigan HIE Model- Cynthia Edwardsmihinpr
 
MIHIN HIE Presentation UPHIE
MIHIN HIE Presentation UPHIEMIHIN HIE Presentation UPHIE
MIHIN HIE Presentation UPHIEmihinpr
 
HIE Day- JCMR Overview June 2012
HIE Day- JCMR Overview June 2012HIE Day- JCMR Overview June 2012
HIE Day- JCMR Overview June 2012mihinpr
 
GLHIE Presentation June 19 2012
GLHIE Presentation June 19 2012GLHIE Presentation June 19 2012
GLHIE Presentation June 19 2012mihinpr
 

More from mihinpr (20)

Connecting Patients, Providers and Payers John Halamka Keynote
Connecting Patients, Providers and Payers John Halamka KeynoteConnecting Patients, Providers and Payers John Halamka Keynote
Connecting Patients, Providers and Payers John Halamka Keynote
 
A Vision for Creating a Connected State Subra Sripada
A Vision for Creating a Connected State Subra SripadaA Vision for Creating a Connected State Subra Sripada
A Vision for Creating a Connected State Subra Sripada
 
Panel: Understanding Michigan's HIE Landscape
Panel: Understanding Michigan's HIE LandscapePanel: Understanding Michigan's HIE Landscape
Panel: Understanding Michigan's HIE Landscape
 
Panel Interstate and Other State HIE HIT
Panel Interstate and Other State HIE HITPanel Interstate and Other State HIE HIT
Panel Interstate and Other State HIE HIT
 
Panel: Transitions of Care and ADT (without Rachel Sherman)
Panel: Transitions of Care and ADT (without Rachel Sherman)Panel: Transitions of Care and ADT (without Rachel Sherman)
Panel: Transitions of Care and ADT (without Rachel Sherman)
 
State of Michigan HIE Update (without Tina Scott)
State of Michigan HIE Update (without Tina Scott)State of Michigan HIE Update (without Tina Scott)
State of Michigan HIE Update (without Tina Scott)
 
Health IT and Public Policy Issues Dr. Rich Hodge
Health IT and Public Policy Issues Dr. Rich HodgeHealth IT and Public Policy Issues Dr. Rich Hodge
Health IT and Public Policy Issues Dr. Rich Hodge
 
A Consistent Nationwide Data Matching Strategy Donna Roach & Nancy Walker
A Consistent Nationwide Data Matching Strategy Donna Roach & Nancy WalkerA Consistent Nationwide Data Matching Strategy Donna Roach & Nancy Walker
A Consistent Nationwide Data Matching Strategy Donna Roach & Nancy Walker
 
Jennifer Horowitz EHR Adoption in Michigan & Nationwide
Jennifer Horowitz EHR Adoption in Michigan & NationwideJennifer Horowitz EHR Adoption in Michigan & Nationwide
Jennifer Horowitz EHR Adoption in Michigan & Nationwide
 
Panel: Achieving Interoperability Dr. John Loonsk & Janet King
Panel: Achieving Interoperability Dr. John Loonsk & Janet KingPanel: Achieving Interoperability Dr. John Loonsk & Janet King
Panel: Achieving Interoperability Dr. John Loonsk & Janet King
 
Dr. Charles Friedman Transcending HIE
Dr. Charles Friedman Transcending HIEDr. Charles Friedman Transcending HIE
Dr. Charles Friedman Transcending HIE
 
Doug Dietzman National HIE Landscape
Doug Dietzman National HIE LandscapeDoug Dietzman National HIE Landscape
Doug Dietzman National HIE Landscape
 
Brian Balow HIPAA Final Rule
Brian Balow HIPAA Final RuleBrian Balow HIPAA Final Rule
Brian Balow HIPAA Final Rule
 
Panel Cyber Security and Privacy without Carrie Waggoner
Panel Cyber Security and Privacy without Carrie WaggonerPanel Cyber Security and Privacy without Carrie Waggoner
Panel Cyber Security and Privacy without Carrie Waggoner
 
Andrea walrath mu stage 2 and beyond
Andrea walrath mu stage 2 and beyondAndrea walrath mu stage 2 and beyond
Andrea walrath mu stage 2 and beyond
 
MiHIN Brief Overview
MiHIN Brief OverviewMiHIN Brief Overview
MiHIN Brief Overview
 
Michigan HIE Model- Cynthia Edwards
Michigan HIE Model- Cynthia EdwardsMichigan HIE Model- Cynthia Edwards
Michigan HIE Model- Cynthia Edwards
 
MIHIN HIE Presentation UPHIE
MIHIN HIE Presentation UPHIEMIHIN HIE Presentation UPHIE
MIHIN HIE Presentation UPHIE
 
HIE Day- JCMR Overview June 2012
HIE Day- JCMR Overview June 2012HIE Day- JCMR Overview June 2012
HIE Day- JCMR Overview June 2012
 
GLHIE Presentation June 19 2012
GLHIE Presentation June 19 2012GLHIE Presentation June 19 2012
GLHIE Presentation June 19 2012
 

Recently uploaded

HOT NEW PRODUCT! BIG SALES FAST SHIPPING NOW FROM CHINA!! EU KU DB BK substit...
HOT NEW PRODUCT! BIG SALES FAST SHIPPING NOW FROM CHINA!! EU KU DB BK substit...HOT NEW PRODUCT! BIG SALES FAST SHIPPING NOW FROM CHINA!! EU KU DB BK substit...
HOT NEW PRODUCT! BIG SALES FAST SHIPPING NOW FROM CHINA!! EU KU DB BK substit...
GL Anaacs
 
Surgical Site Infections, pathophysiology, and prevention.pptx
Surgical Site Infections, pathophysiology, and prevention.pptxSurgical Site Infections, pathophysiology, and prevention.pptx
Surgical Site Infections, pathophysiology, and prevention.pptx
jval Landero
 
For Better Surat #ℂall #Girl Service ❤85270-49040❤ Surat #ℂall #Girls
For Better Surat #ℂall #Girl Service ❤85270-49040❤ Surat #ℂall #GirlsFor Better Surat #ℂall #Girl Service ❤85270-49040❤ Surat #ℂall #Girls
For Better Surat #ℂall #Girl Service ❤85270-49040❤ Surat #ℂall #Girls
Savita Shen $i11
 
Hemodialysis: Chapter 3, Dialysis Water Unit - Dr.Gawad
Hemodialysis: Chapter 3, Dialysis Water Unit - Dr.GawadHemodialysis: Chapter 3, Dialysis Water Unit - Dr.Gawad
Hemodialysis: Chapter 3, Dialysis Water Unit - Dr.Gawad
NephroTube - Dr.Gawad
 
The Normal Electrocardiogram - Part I of II
The Normal Electrocardiogram - Part I of IIThe Normal Electrocardiogram - Part I of II
The Normal Electrocardiogram - Part I of II
MedicoseAcademics
 
micro teaching on communication m.sc nursing.pdf
micro teaching on communication m.sc nursing.pdfmicro teaching on communication m.sc nursing.pdf
micro teaching on communication m.sc nursing.pdf
Anurag Sharma
 
Evaluation of antidepressant activity of clitoris ternatea in animals
Evaluation of antidepressant activity of clitoris ternatea in animalsEvaluation of antidepressant activity of clitoris ternatea in animals
Evaluation of antidepressant activity of clitoris ternatea in animals
Shweta
 
Ophthalmology Clinical Tests for OSCE exam
Ophthalmology Clinical Tests for OSCE examOphthalmology Clinical Tests for OSCE exam
Ophthalmology Clinical Tests for OSCE exam
KafrELShiekh University
 
Phone Us ❤85270-49040❤ #ℂall #gIRLS In Surat By Surat @ℂall @Girls Hotel With...
Phone Us ❤85270-49040❤ #ℂall #gIRLS In Surat By Surat @ℂall @Girls Hotel With...Phone Us ❤85270-49040❤ #ℂall #gIRLS In Surat By Surat @ℂall @Girls Hotel With...
Phone Us ❤85270-49040❤ #ℂall #gIRLS In Surat By Surat @ℂall @Girls Hotel With...
Savita Shen $i11
 
MANAGEMENT OF ATRIOVENTRICULAR CONDUCTION BLOCK.pdf
MANAGEMENT OF ATRIOVENTRICULAR CONDUCTION BLOCK.pdfMANAGEMENT OF ATRIOVENTRICULAR CONDUCTION BLOCK.pdf
MANAGEMENT OF ATRIOVENTRICULAR CONDUCTION BLOCK.pdf
Jim Jacob Roy
 
POST OPERATIVE OLIGURIA and its management
POST OPERATIVE OLIGURIA and its managementPOST OPERATIVE OLIGURIA and its management
POST OPERATIVE OLIGURIA and its management
touseefaziz1
 
Tom Selleck Health: A Comprehensive Look at the Iconic Actor’s Wellness Journey
Tom Selleck Health: A Comprehensive Look at the Iconic Actor’s Wellness JourneyTom Selleck Health: A Comprehensive Look at the Iconic Actor’s Wellness Journey
Tom Selleck Health: A Comprehensive Look at the Iconic Actor’s Wellness Journey
greendigital
 
ARTIFICIAL INTELLIGENCE IN HEALTHCARE.pdf
ARTIFICIAL INTELLIGENCE IN  HEALTHCARE.pdfARTIFICIAL INTELLIGENCE IN  HEALTHCARE.pdf
ARTIFICIAL INTELLIGENCE IN HEALTHCARE.pdf
Anujkumaranit
 
Ozempic: Preoperative Management of Patients on GLP-1 Receptor Agonists
Ozempic: Preoperative Management of Patients on GLP-1 Receptor Agonists  Ozempic: Preoperative Management of Patients on GLP-1 Receptor Agonists
Ozempic: Preoperative Management of Patients on GLP-1 Receptor Agonists
Saeid Safari
 
THOA 2.ppt Human Organ Transplantation Act
THOA 2.ppt Human Organ Transplantation ActTHOA 2.ppt Human Organ Transplantation Act
THOA 2.ppt Human Organ Transplantation Act
DrSathishMS1
 
BRACHYTHERAPY OVERVIEW AND APPLICATORS
BRACHYTHERAPY OVERVIEW  AND  APPLICATORSBRACHYTHERAPY OVERVIEW  AND  APPLICATORS
BRACHYTHERAPY OVERVIEW AND APPLICATORS
Krishan Murari
 
Non-respiratory Functions of the Lungs.pdf
Non-respiratory Functions of the Lungs.pdfNon-respiratory Functions of the Lungs.pdf
Non-respiratory Functions of the Lungs.pdf
MedicoseAcademics
 
The hemodynamic and autonomic determinants of elevated blood pressure in obes...
The hemodynamic and autonomic determinants of elevated blood pressure in obes...The hemodynamic and autonomic determinants of elevated blood pressure in obes...
The hemodynamic and autonomic determinants of elevated blood pressure in obes...
Catherine Liao
 
New Directions in Targeted Therapeutic Approaches for Older Adults With Mantl...
New Directions in Targeted Therapeutic Approaches for Older Adults With Mantl...New Directions in Targeted Therapeutic Approaches for Older Adults With Mantl...
New Directions in Targeted Therapeutic Approaches for Older Adults With Mantl...
i3 Health
 
Ocular injury ppt Upendra pal optometrist upums saifai etawah
Ocular injury  ppt  Upendra pal  optometrist upums saifai etawahOcular injury  ppt  Upendra pal  optometrist upums saifai etawah
Ocular injury ppt Upendra pal optometrist upums saifai etawah
pal078100
 

Recently uploaded (20)

HOT NEW PRODUCT! BIG SALES FAST SHIPPING NOW FROM CHINA!! EU KU DB BK substit...
HOT NEW PRODUCT! BIG SALES FAST SHIPPING NOW FROM CHINA!! EU KU DB BK substit...HOT NEW PRODUCT! BIG SALES FAST SHIPPING NOW FROM CHINA!! EU KU DB BK substit...
HOT NEW PRODUCT! BIG SALES FAST SHIPPING NOW FROM CHINA!! EU KU DB BK substit...
 
Surgical Site Infections, pathophysiology, and prevention.pptx
Surgical Site Infections, pathophysiology, and prevention.pptxSurgical Site Infections, pathophysiology, and prevention.pptx
Surgical Site Infections, pathophysiology, and prevention.pptx
 
For Better Surat #ℂall #Girl Service ❤85270-49040❤ Surat #ℂall #Girls
For Better Surat #ℂall #Girl Service ❤85270-49040❤ Surat #ℂall #GirlsFor Better Surat #ℂall #Girl Service ❤85270-49040❤ Surat #ℂall #Girls
For Better Surat #ℂall #Girl Service ❤85270-49040❤ Surat #ℂall #Girls
 
Hemodialysis: Chapter 3, Dialysis Water Unit - Dr.Gawad
Hemodialysis: Chapter 3, Dialysis Water Unit - Dr.GawadHemodialysis: Chapter 3, Dialysis Water Unit - Dr.Gawad
Hemodialysis: Chapter 3, Dialysis Water Unit - Dr.Gawad
 
The Normal Electrocardiogram - Part I of II
The Normal Electrocardiogram - Part I of IIThe Normal Electrocardiogram - Part I of II
The Normal Electrocardiogram - Part I of II
 
micro teaching on communication m.sc nursing.pdf
micro teaching on communication m.sc nursing.pdfmicro teaching on communication m.sc nursing.pdf
micro teaching on communication m.sc nursing.pdf
 
Evaluation of antidepressant activity of clitoris ternatea in animals
Evaluation of antidepressant activity of clitoris ternatea in animalsEvaluation of antidepressant activity of clitoris ternatea in animals
Evaluation of antidepressant activity of clitoris ternatea in animals
 
Ophthalmology Clinical Tests for OSCE exam
Ophthalmology Clinical Tests for OSCE examOphthalmology Clinical Tests for OSCE exam
Ophthalmology Clinical Tests for OSCE exam
 
Phone Us ❤85270-49040❤ #ℂall #gIRLS In Surat By Surat @ℂall @Girls Hotel With...
Phone Us ❤85270-49040❤ #ℂall #gIRLS In Surat By Surat @ℂall @Girls Hotel With...Phone Us ❤85270-49040❤ #ℂall #gIRLS In Surat By Surat @ℂall @Girls Hotel With...
Phone Us ❤85270-49040❤ #ℂall #gIRLS In Surat By Surat @ℂall @Girls Hotel With...
 
MANAGEMENT OF ATRIOVENTRICULAR CONDUCTION BLOCK.pdf
MANAGEMENT OF ATRIOVENTRICULAR CONDUCTION BLOCK.pdfMANAGEMENT OF ATRIOVENTRICULAR CONDUCTION BLOCK.pdf
MANAGEMENT OF ATRIOVENTRICULAR CONDUCTION BLOCK.pdf
 
POST OPERATIVE OLIGURIA and its management
POST OPERATIVE OLIGURIA and its managementPOST OPERATIVE OLIGURIA and its management
POST OPERATIVE OLIGURIA and its management
 
Tom Selleck Health: A Comprehensive Look at the Iconic Actor’s Wellness Journey
Tom Selleck Health: A Comprehensive Look at the Iconic Actor’s Wellness JourneyTom Selleck Health: A Comprehensive Look at the Iconic Actor’s Wellness Journey
Tom Selleck Health: A Comprehensive Look at the Iconic Actor’s Wellness Journey
 
ARTIFICIAL INTELLIGENCE IN HEALTHCARE.pdf
ARTIFICIAL INTELLIGENCE IN  HEALTHCARE.pdfARTIFICIAL INTELLIGENCE IN  HEALTHCARE.pdf
ARTIFICIAL INTELLIGENCE IN HEALTHCARE.pdf
 
Ozempic: Preoperative Management of Patients on GLP-1 Receptor Agonists
Ozempic: Preoperative Management of Patients on GLP-1 Receptor Agonists  Ozempic: Preoperative Management of Patients on GLP-1 Receptor Agonists
Ozempic: Preoperative Management of Patients on GLP-1 Receptor Agonists
 
THOA 2.ppt Human Organ Transplantation Act
THOA 2.ppt Human Organ Transplantation ActTHOA 2.ppt Human Organ Transplantation Act
THOA 2.ppt Human Organ Transplantation Act
 
BRACHYTHERAPY OVERVIEW AND APPLICATORS
BRACHYTHERAPY OVERVIEW  AND  APPLICATORSBRACHYTHERAPY OVERVIEW  AND  APPLICATORS
BRACHYTHERAPY OVERVIEW AND APPLICATORS
 
Non-respiratory Functions of the Lungs.pdf
Non-respiratory Functions of the Lungs.pdfNon-respiratory Functions of the Lungs.pdf
Non-respiratory Functions of the Lungs.pdf
 
The hemodynamic and autonomic determinants of elevated blood pressure in obes...
The hemodynamic and autonomic determinants of elevated blood pressure in obes...The hemodynamic and autonomic determinants of elevated blood pressure in obes...
The hemodynamic and autonomic determinants of elevated blood pressure in obes...
 
New Directions in Targeted Therapeutic Approaches for Older Adults With Mantl...
New Directions in Targeted Therapeutic Approaches for Older Adults With Mantl...New Directions in Targeted Therapeutic Approaches for Older Adults With Mantl...
New Directions in Targeted Therapeutic Approaches for Older Adults With Mantl...
 
Ocular injury ppt Upendra pal optometrist upums saifai etawah
Ocular injury  ppt  Upendra pal  optometrist upums saifai etawahOcular injury  ppt  Upendra pal  optometrist upums saifai etawah
Ocular injury ppt Upendra pal optometrist upums saifai etawah
 

Carrie Waggoner Cyber Security Panel

Editor's Notes

  1. Introduction – My role as an attorney at MDCH is to advise staff on privacy issues across all of the Department’s programs, which include the Medicaid program, public health activities and programs, as well as behavioral health, substance abuse, and developmental disabilities programs. MDCH is one of the largest state government agencies, and is responsible for health policy and management of the state's publicly-funded health service systems.About 2 million Michigan residents will receive services this year that are provided with total or partial support from MDCH.MDCH has 2013 total funding of $15 billion and approximately 3,100 employees. Working on HIE issues is one small subset of the work I do for the Department.
  2. A quick disclaimer - I’m an attorney and DCH is my client. I advise DCH on how it might share information through its data hub to MiHIN and on other legal issues. But I can’t advise other individuals or organizations outside of DCH because they are not my clients. But I can share with you my perspective on privacy issues.
  3. Figuring out the relationship between entities that want to share data and the technical infrastructure supporting that data sharing can get really abstract and complicated. I try to simplify things with the following analysis:Asking “who” helps identify the obligations that entity might have. For example, under HIPAA, DCH is a hybrid covered entity. So HIPAA applies to some offices within DCH when sharing protected health information and HIPAA doesn’t apply to other offices within DCH when sharing information.Asking “what information” is the key question because that question leads us to what laws might protect the confidentiality of the information. And those laws also describe how that information might be shared and what authorization might be needed. Asking “with whom” allows us to discover whether we can share the information with that entity given the confidential protections. The information might be used internally and therefore there might be few if any limits how it might be shared. Under HIPAA, we know that info can be shared without patient authorization by a covered entity to another covered entity or a provider if the information is disclosed for treatment, payment, or health care operations. On the other hand, if the protected health information is disclosed to a business associate of a covered entity, then there are other legal obligations on the business associate for protecting the confidentiality of the information.Asking “for what purpose” allows me to determine whether the information can be shared consistent with any applicable confidentiality laws. For example, HIPAA has specific exceptions, like public health, research, and others, that allow for the disclosure of PHI.
  4. HIPAA & Other Compliance:As many of you probably know, the Office for Civil Rights has been ramping up its HIPAA enforcement and audit activities. It’s really important now to properly document your organization’s compliance so that you do not face millions of dollars in penalties from OCR. I was at a conference earlier this year, and one of the speakers from OCR discussed the results of recent HIPAA compliance audits. OCR audited a range of entities – from large hospitals to small providers. Only 11% of the 115 entities audited as of Dec 2012 had no findings. By compliance I mean the proper legal agreements in place, documenting business flows and processes, documenting policies and procedures regarding information privacy and security, and training of staff members. Given the culture of enforcement at OCR, it is extremely important to evaluate internally compliance with HIPAA on a periodic basis. By other compliance, I mean that it is also important to take similar steps to document policies, procedures, training, etc for other confidentiality laws that may apply to your practice or organization – for example, HIV/AIDS data, mental health, substance abuse, and so on.Mobile Devices:The increased use of mobile devices – laptops, smart phones, and even jump drives – allows us to have more flexibility in where and when we work, but it also increases the potential for an unauthorized use or disclosure of PHI or other confidential information. For example, OCR has published a list of the top five compliance issues over the last decade, and from 2004-2010 (last year published) the number one compliance issue was impermissible uses and disclosures. Mobile devices increase the risk of an unauthorized disclosure because they are out and about with us, and they can easily be lost or stolen, creating additional opportunities for unauthorized access to confidential information. Coordination with Security:To me, privacy and security are separate but interrelated concepts and functions. I agree with the errors that Dan identified, especially the one about basing security on systems rather than on the critical data. Privacy laws can help identify the critical data elements that have to be protected from use or disclosure in some way, and security, from a technological standpoint, can provide the solution to accomplish protecting the data (encryption, role-based access, authentication, etc.). Security solutions may go further than what HIPAA or other privacy laws require for compliance. The point is that privacy and security staff within an organization need to work together to accomplish protecting the privacy rights of individual’s information, as well as the security and integrity of the data itself.
  5. Mental Health & Substance Abuse:I participate in MiHIN’s privacy work group, and one of the issues we are working through is how mental health and substance abuse information, both of which have more stringent privacy protections than HIPAA, will be utilized through HIE technology. How is consent managed? Where are documents stored? Who is liable? This is also an issue for any information that is protected by laws that are more stringent than HIPAA.Public Trust & Buy-in:I heard another speaker at the conference I mentioned that I attended earlier this year who spoke about privacy as an “enabler” to the flow of information. What I think she meant by this is that if the public does not trust the HIE system, they might engage in “privacy-protective” behavior. For example, they might opt-out altogether or they might not allow all of their health information to be disclosed to a provider. This could have real consequences in terms of the quality of medical care – just like withholding information from a doctor about drug use or prescriptions can compromise that providers ability to treat you. Public education and knowledge about how the HIE functions, how their information might be shared, the privacy and security protections in place will help to build the public’s trust and minimize “privacy-protective” behavior.