I. Purpose and Scope:
- The purpose of this policy is to explain when the HIPAA Privacy Regulation’s minimum necessary standard applies to Tufts University School of Dental Medicine (TUSDM) operations and the procedures TUSDM must follow to limit the amount and kinds of protected health information (“PHI”) that is used, disclosed, or requested from others.
- This policy applies to TUSDM Workforce, including faculty, employees, volunteers, trainees, students, and other persons as defined below.
II. Policy Statement:
- TUSDM must make “reasonable efforts” to limit its use and disclosure of and requests for PHI to the minimum necessary to accomplish the intended purpose of the use, disclosure, or request.
III. Definitions:
IV. General Rules:
- WHEN THE MINIMUM NECESSARY STANDARD APPLIES.
- When using or disclosing PHI or when requesting PHI from another entity, TUSDM must make reasonable efforts to limit the PHI to the minimum amount of PHI necessary to accomplish the intended purpose of the use, disclosure, or request.
- The minimum necessary standard is defined by law and guidance promulgated by the Department of Health and Human Services (“HHS”). The Health Information Technology for Economic and Clinical Health Act (“HITECH”) provisions of the American Recovery and Reinvestment Act of 2009 define the minimum necessary standard as a “limited data set” as that term is defined under HIPAA. A limited data set includes only the following patient identifiers:
- Date of birth.
- Date of death.
- Dates of service.
- Town or city.
- State.
- ZIP code.
NOTE: If additional patient information is needed for a particular task, TUSDM must confirm that the information is necessary to accomplish its intended purpose prior to using, disclosing, or requesting the information. TUSDM will comply with the minimum necessary standard as revised from time to time by HHS.
- Among the uses, disclosures, and requests to which the minimum necessary standard does not apply are:
- Uses or disclosures by a healthcare provider for treatment purposes.
- Disclosures to the individual who is the subject of the information.
- Uses or disclosures made pursuant to a valid authorization.
- Uses or disclosures required for compliance with the HIPAA standard transactions.
- Disclosures to HHS when required for compliance and enforcement purposes.
- Uses or disclosures that are required by other law.
- Business Associates. The minimum necessary standard applies directly to business associates when using and disclosing PHI or requesting PHI from another covered entity. Business Associates must limit uses and disclosures of PHI consistent with the TUSDM’s Minimum Necessary policies and procedures.
- USES OF PROTECTED HEALTH INFORMATION.
- Required Procedures. TUSDM must develop and implement procedures that limit the use of PHI to the minimum PHI necessary to accomplish the intended purpose of the use. The procedures for use of PHI must identify the:
- People or classes of people within TUSDM who need access to PHI to perform their duties.
- Categories of PHI, each person or class of people, needs.
- Any conditions necessary for such access.
- Additional Procedures. TUSDM must have procedures that limit access to only the identified persons, and only to the identified PHI. These procedures should be based on reasonable determinations about the persons or classes of persons who require PHI, and the nature of the PHI they require, for their job responsibilities.
- Use of the Entire Medical Record. TUSDM is required to develop procedures that address when use of the entire medical record is justified. TUSDM’s procedures must make it clear that an entire medical record may not be disclosed other than as allowed by these procedures. The procedures should identify those people or classes of people in the Workforce that need to see the entire medical record and the conditions, if any, that are appropriate for such access.
- Required Procedures. TUSDM must develop and implement procedures that limit the use of PHI to the minimum PHI necessary to accomplish the intended purpose of the use. The procedures for use of PHI must identify the:
- DISCLOSURES OF PROTECTED HEALTH INFORMATION.
- Routine Disclosures. For any type of disclosure that is made on a routine, recurring basis, TUSDM must develop and implement procedures (which may be standard protocols) that permit only the disclosure of the minimum PHI necessary to achieve the purpose of the disclosure. The procedures must identify the:
- Types of PHI to be disclosed.
- Types of people who would receive the PHI.
- Conditions necessary for such access.
- Non-Routine Disclosures. TUSDM must develop reasonable criteria for determining and limiting disclosure to only the minimum amount of PHI necessary to accomplish the purpose of the disclosure.
- Among the factors that may be considered in making such a determination are:
- How much PHI will be disclosed?
- To what extent would the disclosure increase the number of persons with access to the PHI?
- What is the likelihood of further disclosures?
- How important is this disclosure?
- Can the same purpose be achieved using de-identified information?
- Can the same purpose be achieved using a limited data set?
- Is there technology available to limit the amount of PHI disclosed?
- What is the cost, financial or otherwise, of limiting the disclosure?
- TUSDM must also develop and implement procedures for reviewing non-routine requests for disclosures on an individual basis in accordance with established criteria.
- Among the factors that may be considered in making such a determination are:
- Disclosure of the Entire Medical Record. TUSDM is required to develop procedures that address when disclosure of the entire medical record is justified. TUSDM’s procedures must make it clear that an entire medical record may not be disclosed other than as allowed by these procedures. Without such procedures, TUSDM is never permitted to disclose the entire medical record.
- Reasonable Reliance on Requested Disclosures. TUSDM may rely, if reasonable under the circumstances, on statements by public officials or other covered entities that they are requesting the minimum PHI necessary to achieve the stated purpose of the request. TUSDM may also reasonably rely on the statements of its business associates or professionals within its workforce (such as attorneys or accountants) that the information requested to provide professional services to TUSDM is the minimum necessary for such purposes.
- Routine Disclosures. For any type of disclosure that is made on a routine, recurring basis, TUSDM must develop and implement procedures (which may be standard protocols) that permit only the disclosure of the minimum PHI necessary to achieve the purpose of the disclosure. The procedures must identify the:
- REQUESTS FOR PROTECTED HEALTH INFORMATION.
- Routine Requests. The minimum necessary standard applies to situations where TUSDM is requesting an individual’s PHI from another entity. For requests to other entities made on a routine, recurring basis, TUSDM must establish standard protocols describing what information is necessary for the purposes for which it is requested and limit its requests to only that information.
- Non-Routine Disclosures. TUSDM must develop reasonable criteria for determining and limiting requests to only the minimum amount of PHI necessary to accomplish the purpose of the request. TUSDM must also develop and implement procedures for reviewing non-routine requests for disclosures on an individual basis in accordance with established criteria.
- Request for the Entire Medical Record. TUSDM is required to develop procedures that address when a request for the entire medical record is justified. TUSDM’s procedures must make it clear that an entire medical record may not be requested other than as allowed by these procedures. Without such procedures, TUSDM is never permitted to request the entire medical record.
- INCIDENTAL USES AND DISCLOSURES.
- Definition of Incidental Uses and Disclosures. Incidental uses and disclosures are secondary uses or disclosures that cannot be prevented, are limited in nature, and that occur as a by-product of otherwise permitted or required uses and disclosures. For example, an incidental disclosure occurs when a physician is speaking with a nurse about a patient’s treatment and an individual walking by overhears part of the conversation. Erroneous uses or disclosures or those that result from mistake or neglect are not considered incidental uses and disclosures because they do not occur as a by-product of an otherwise permissible use and disclosure.
- General Rule. Incidental uses and disclosures are permitted by the Privacy Regulation, so long as TUSDM has applied reasonable safeguards to protect PHI and implemented the minimum necessary standard as required.
- Incidental Uses and Disclosures Not Permitted. An incidental use or disclosure that occurs due to a failure to apply reasonable safeguards or the minimum necessary standard, as appropriate, is not a permissible use or disclosure and is, therefore, a violation of the Privacy Regulation. For instance, if a TUSDM workforce member were to ask for a patient’s health history on the waiting room sign-in sheet, it would not be abiding by the minimum necessary requirements and, therefore, any incidental disclosure of such information that resulted would be an unlawful disclosure under the Privacy Regulation.
- STORAGE OF PHI.
- The TUSDM Security and Privacy Officer will ensure that TUSDM maintains PHI, both in electronic and hard copy form, in areas that are out of view of third parties. The Security and Privacy Officer will assist employees in taking precautions to prevent PHI from being viewed or accessed by guests or fellow employees who do not have a need to see the PHI.
- The Security and Privacy Officer will assist employees in clearly labeling records and restricting access to outdated physical and electronic records stored on site.
- DISPOSAL OF PHI.
- All papers and documents containing PHI should be disposed of in a manner that protects the patient’s confidentiality and is consistent with HHS guidance issued from time to time. Paper, film, or other hard copy media must be shredded or destroyed such that the PHI cannot be read or otherwise reconstructed. Electronic media must be cleared, purged, or destroyed consistent with NIST Special Publication 800-88, Guidelines for Media Sanitation, such that PHI cannot be retrieved.
V. Policy Compliance Monitoring and Enforcement:
- The TUSDM Security and Privacy Officer is responsible for the monitoring and enforcement of this policy. However, directors and managers are also responsible for monitoring compliance with procedures specific to their areas.
VI. Potential Disciplinary Actions and Sanctions:
- Failure to follow standard operating procedures may trigger review for potential disciplinary action under the TUSDM HIPAA Sanctions Policy.
VIII. Approval and Review Cycle:
- This policy shall be subject to annual review, revision, and approval by the TUSDM Compliance Committee.