Privacy & HIPAA Flashcards
(12 cards)
Clinician Duty to Warn of Foreseeable Harm (Tarasoff)
(1) Explicit threat of imminent serious physical harm or death
(2) To an identifiable person
(3) Patient has apparent intent & ability to carry out threat
Permitted Disclosures of Protected
Health Information
- To patient
- For treatment, payment, or health care operations
- To investigate HIPAA complaints
- As otherwise required by law (e.g. law
enforcement, public health activities)
Otherwise: Need patient authorization
Confidentiality:
Professional secrecy. Assurance
that information re: subject’s identity, health, behavior, etc. won’t be disclosed
w/o her permission.
Privacy:
Being free from being observed or
disturbed by others. Ability to control access to self or one’s info.
Data security:
Technical mechanisms to prevent
data breaches (e.g. encryption).
Doe v. Medlantic:
Unconsented, unprivileged
disclosure to 3rd party of nonpublic info that D learned w/i confidential relationship.
HIPAA Privacy Rule includes what groups?
- Health Plans
- Health Care Clearinghouses
- Health Care providers
- Business Associations
- Employers
Protected Health Information
Individually identifiable health information that is:
- Transmitted by electronic media
- Maintained in electronic media
- Transmitted or maintained in any other form (e.g. paper)
Permitted disclosures of protected
health information
-To patient
-For treatment, payment, or health care
operations
-To investigate HIPAA complaints
-As otherwise required by law (e.g. law
enforcement, public health activities)
-Otherwise need patient authorization
Reproductive Privacy Rule
-Prohibits the use or disclosure of individually identifiable health information to law enforcement when purpose of investigation is to impose liability
on patients or physicians.
-Applies only when care was legal
-Explicitly protects privacy of people who travel from abortion-restrictive state to state w/ legal abortion
Patient Rights
- Inspect PHI & obtain copies
- Request amendments
Other HIPAA Issues/Requirements
- Notice requirement
- Breach notification
- Civil and criminal penalties but no private cause of action (only HHS can enforce and impose these)
–> if you want to sue, you’d have to sue under a breach of confidentiality theory. - State law can impose more stringent
requirements than HIPAA - HIPAA Security Rule (Technical, administrative & physical
safeguards)