Page tree

Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.


ROWAN UNIVERSITY POLICY

Title: Accounting of Disclosures of Health Information
Subject: Office of Compliance & Corporate Integrity (OCCI)
Policy No: OCCI:2013:P01
Applies: RowanSOM
Issuing Authority:

...

 President

...


Responsible

...

Officer:

...

 Chief Audit, Compliance and Privacy Officer; Director of Information Security 
Adopted: 07/1/

...

2013
Last Revision:

...

 01/

...

26/

...

2021
Last Reviewed:

...

 01/

...

26/

...

2021

I.    PURPOSE

To establish a policy and procedure to ensure Rowan University's University’s School of Osteopathic Medicine (RowanSOM) compliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009 and the Omnibus Privacy Final Rule of 2013 in providing an individual the right to receive an accounting of disclosures of his/her Protected Health Information (PHI), made by RowanSOM and/or its covered entities.

II.

...

   ACCOUNTABILITY

Under the direction of the President, the Dean, Executive Vice President of Administration and Strategic Planning and Chief Compliance and Senior VP for Medical Initiatives and Affiliated Campuses, Dean, the Chief Audit, Compliance & Privacy Officer, and Vice President for Research shall ensure compliance with this policy.

III.  APPLICABILITY

This policy shall apply to health information that is generated during provisions of health care to patients in any of the University's University’s patient care units, patient care centers or faculty practices as well as Human Subjects research under the auspices of the University or by any of its agents in all RowanSOM Schools, Units, Departments and University owned or operated facilities.

IV.  DEFINITIONS

...

  1. Protected Health Information (PHI)

...

  1. means individually identifiable health information that relates to the past, present or future physical or mental health or condition of an individual, the provision of health care to an individual or the past, present or future payment for the provision of health care to an individual and identifies or could reasonably be used to identify the individual. If a patient has been deceased for more than fifty (50) years, the PHI is no longer considered protected. This

...

  1. is not a record retention requirement and covered entities may destroy medical records according to the State or other applicable laws. When individually identifiable health information is created, received, maintained or transmitted by a Business Associate and tied to a covered entity is considered PHI.

    1. Except as provided in paragraph

  2. two
    1. (

  3. 2
    1. b) of this definition that is:

  4. a)
    1.  

      1. transmitted by electronic media

  5. ; b)
      1. maintained in electronic

  6. media; or c)
      1. media 

      2. transmitted or maintained in any other form or medium

    1. Protected health information excludes individually identifiable health information in:

  7. a)
    1.  

      1. Education records covered by the Family Educational Rights and Privacy Act, as amended, 20 U.S.C. 1232g

  8. ; b)
      1. Records described at 20 U.S.C. 1232g(a)(4)(B)(iv)

  9. ; and c)
      1.  

      2. Employment records held by a covered entity in its role as employer

  10. .

V.

...

   REFERENCES

...

  1. 45 CFR 164.528, Title 45, Code of Federal Regulations, Part 164, Section 528, Security and Privacy, Accounting of Disclosures of Protected Health Information

...

...

  1. 45 CFR 164.512 (i), Title 45, Code of Federal Regulations, Part 164, Section 512, Security and Privacy, Uses and Disclosures for Which Consent, an Authorization or Opportunity to Agree or Object is not Required, Uses and Disclosures for Research Purposes

...

  1. 45 CFR 164.514(e), Title 45, Code of Federal Regulations, Part 164, Section 514, Subpart E, Security and Privacy, Privacy of Individually Identifiable Health Information

...

...

  1. Uses and Disclosures of Health Information With and Without an Authorization

...

  1. Health Information Technology for Economic and Clinical Health Act of 2009 (part of the American Recovery and Reinvestment Act of 2009)

...

...

  1. Omnibus Privacy Final Rule of 2013

...

The following policies provide additional and related information:

  1. Standards for Privacy of Individually Identifiable Health Information
  2. Access of Individuals to Health
  3. Information
  4. Information   

VI. POLICY

A. Requirements:

  1. RowanSOM and/or its units will provide an individual with an accounting of all disclosures of their PHI upon the
  2. individual's
  3. individual’s written request as required by state and federal law. A request for Accounting of Disclosures Form
  4. [i] 
  5. can be accessed on the Rowan
  6. .edu
  7. Compliance website.
  8. RowanSOM units will act on an
  9. individual's
  10. individual’s request for an accounting within thirty (30) days of receipt of the request. If a unit is unable to provide the accounting within thirty (30) days, it may extend the time period to provide the accounting by no more than thirty (30) days; however, within the original thirty (30) days, units must provide the individual with a written statement of the reasons for the delay and the date by which units will provide the accounting. RowanSOM units are only permitted one extension per request.
  11. The first accounting in a twelve-month period to an individual must be provided without charge. However, units may impose a reasonable cost-based fee for each subsequent request for an accounting made by the same individual within the twelve-month period provided the unit informs the individual of the fee prior to complying with the request, thus giving the individual the opportunity to withdraw or modify the request.
  12. As part of the accounting of the disclosures, the unit will coordinate the releases of PHI with
  13. business associates
  14. business associates.
  15. A RowanSOM unit must temporarily suspend an
  16. individual's
  17. individual’s right to receive an accounting of disclosures made to a health oversight agency or law enforcement official, for the time specified by such agency or official, if such agency or official provides the unit with a written statement that such an accounting to the individual would be reasonably likely to impede the
  18. agency's
  19. agency’s activities and it must include the time frame for which such a suspension is required.
  20. A RowanSOM unit must temporarily suspend an
  21. individual's
  22. individual’s right to receive an accounting of disclosures made to a health oversight agency or law enforcement official, for the time specified by such agency or official, if such agency or official provides the unit with an oral statement that such an accounting to the individual would be reasonably likely to impede the
  23. agency's
  24. agency’s activities and it must include the time frame for which such a suspension is required. However, inasmuch as the statement was given orally, units must:
    1. document the statement, including the identity of the agency or official making the statement
  25. ;
    1. limits the temporary suspension to no longer than thirty (30) days from the date of the oral statement, unless a written statement is submitted during that time
  26. .
  27. Requests made for accountings of disclosures of PHI must be made to the employee or department designated by the Dean, President, and
  28. RowanSOM
  29. Chief Audit, Compliance & Privacy Officer.

B. Responsibilities:

  1. Each RowanSOM unit will implement a process to provide an accounting to individuals of all disclosures except:

    1. disclosures to carry out treatment, payment and healthcare operations

  2. ;
    1. disclosures to the individual of PHI about themselves

  3. ;
    1. disclosures for the

  4. facility's
    1. facility’s directory or to persons involved in the

  5. individual's
    1. individual’s care or other notification purposes

  6. ;
    1. disclosures for national security or intelligence purposes

  7. ;
    1. disclosures to correctional institutions or law enforcement officials, as provided

  8. ;
    1. disclosures that occurred prior to April 14, 2003

  9. ;
    1. disclosures pursuant to an authorization

  10. ;
    1. disclosures incident to a use and disclosure otherwise permitted

  11. ;
    1. disclosures that are part of a limited data set in accordance with 45 CFR 164.514(e)

  12. .
  13. An accounting must cover a period of six (6) years, unless the request specifies a shorter period.

  14. Each RowanSOM unit will implement a process to provide an accounting to individuals of all disclosures. The accounting for each disclosure must include:

    1. the date of the disclosure request

    2. reason why entity needs PHI

  15. ;
    1. name(s) of RowanSOM employee processed the request

    2. log of whether or not the entity was eligible to receive PHI

  16. If
    1. if the PHI was transmitted to requesting entity

    2. the name and address of the entity or person who received the PHI

  17. ;\
    1. accurate description of the PHI disclosed

  18. ;
  19. When
    1. when the PHI was sent to requesting entity

  20. How
    1. how the PHI was sent to requesting entity

    2. a copy of a written request for disclosure (i.e. subpoena, etc).

  21. Confirmation
    1. confirmation of entity receiving requested PHI

  22. .
  23. If a RowanSOM unit has made multiple disclosures of PHI to the same person or entity for a single purpose, the accounting with respect to such multiple disclosures should provide:

    1. the information required as described in section VI.

  24. .
    1. A.3. for the first disclosure during the accounting period

  25. ;
    1. the frequency or number of the disclosures made during the accounting period

  26. ;
    1. the date of the last disclosure during the accounting period

  27. .
  28. All RowanSOM units must document and retain for six (6) years the following information:

  29. The
    1. the information required to be included in an accounting as discussed in section VI.B.3

  30. .
  31. The
    1. the written accounting itself that was given to the requesting individual

  32. .
  33. The
    1. the titles of persons or offices responsible for receiving and processing requests for an accounting

  34. .
  35. If, during the period covered by the accounting, a unit has made disclosures of PHI for a particular research purpose in accordance with CFR 164.512(i)

  36.  for
  37. for fifty (50) or more individuals, the accounting may, with respect to such disclosures for which the PHI about the individual may have been included, provide:

    1. The name of the protocol or other research activity

  38. ;
    1. A description, in plain language, of the research protocol or other research activity, including the purpose of the research and the criteria for selecting particular records

  39. ;
    1. A brief description of the type of PHI that was disclosed

  40. ;
    1. The date or period of time during which such disclosures occurred, or may have occurred, including the date of the last such disclosure during the accounting period

  41. ;
    1. The name, address, and telephone number of the entity that sponsored the research and of the researcher to whom the information was disclosed

  42. ; and
    1. A statement that the PHI of the individual may or may not have been disclosed for a particular protocol or other research activity

  43. .
  44. If the unit provides an accounting for research

  45. ,
  46. disclosures in accordance with section VI.B.6. and it is reasonably likely that the PHI of the individual was disclosed for such research protocol or activity, the unit must, at the request of the individual, assist in contacting the entity that sponsored the research and the researcher.

VII. NON-COMPLIANCE AND SANCTIONS

 

VI. ATTACHMENTS

A. Attachment 1, HyperlinkAny individual who violates this policy shall be subject to discipline up to and including dismissal from the University in accordance with their union and University rules.  Civil and criminal penalties may be applied accordingly.  Violations of this policy may require retraining and be reviewed with employee during the annual appraisal process. The Deans of each College, Vice Presidents, and University President, with the assistance of the Department of Human Resources, will enforce the sanctions appropriately and consistently to all violators regardless of job titles or level within the University and in accordance with bargaining agreements for represented employees. Any sanction costs or fines will be borne by the Department and the Department Chair or VP will determine how these funds will be assigned.


By Direction of the President:

Signature on file
RowanSOM Chief Compliance and Privacy Officer

ATTACHMENT 1

                                                                                                               
Chief Audit, Compliance and Privacy OfficerA.  Anchorii [i] Accounting of Disclosures Form: www.rowan.edu/compliance/documents/ROWANRequestforAccountingofDisclosuresForm.pdf