Privacy >> TUSDM Policy on Sanctions for HIPAA and MGL Violations

TUSDM Policy on Sanctions for HIPAA and MGL Violations

I. Purpose and Scope: 
  1. The Health Insurance Portability and Accountability Act of 1996 (HIPAA) authorized the U.S. Department of Health and Human Services (DHHS) to establish national standards for health information. The HIPAA Privacy Rule sets forth Standards for Privacy of Individually Identifiable Health Information, which protect the privacy and security of patients’ health information and confer certain rights with respect to patients’ health information. The HIPAA Security Rule sets forth Standards for the Protection of Electronic Protected Health Information. As a “covered entity” under HIPAA, TUSDM must establish policies and implement procedures to ensure the HIPAA standards are met and must have and apply appropriate sanctions against Workforce Members who violate policies and procedures of the Privacy and Security rules. 
  2. The activities of TUSDM and its Workforce Members are subject to oversight by the U.S. Department of Health and Human Services Office of Civil Rights. Any individual workforce member who fails to uphold the HIPAA standards may face progressive sanctions ranging from corrective actions (e.g., mandatory retraining) and verbal and written warnings for unintentional, non-malicious violations up to expulsion or termination for repeated or serious violations. Serious violations could result in institutional penalties levied against TUDSM including significant fines, reputational damage, and exclusion from participation in any programs funded by the federal government (e.g., student financial aid, research grants). 
  3. This policy applies to all TUSDM Workforce Members. 
II. Policy Statement: 
  1. TUSDM shall establish and consistently apply appropriate corrective actions and disciplinary sanctions against its Workforce Members who fail to comply with the federal, state, and local, regulations governing privacy of personal information and related Tufts University and TUSDM policies and standard operating procedures. 
  2. Corrective actions and sanctions shall be imposed based on the severity or level of the violation, whether it was intentional or unintentional, and whether the violation indicated a pattern or practice of improper use or disclosure of protected health information (PHI) and protected personal information (PPI) (Appendix B: Guidelines for Sanctions for Violations of Privacy):
    1. Level 1: Failure to demonstrate appropriate care and safeguards in handling PHI/PPI. Violations are usually inadvertent with no improper access, use or disclosure of the information. Requires retraining with the TUSDM Security & Privacy Officer.
    2. Level 2: Inadvertent and careless disclosure of PHI/PPI or inappropriate, unauthorized internal use and access to PHI/PPI, or repeated Level 1 violations. Requires further retraining with TUSDM Security & Privacy Officer as well as potential for added discipline via Dean’s/Chairs, HR or predoctoral or postdoctoral EPC committees. 
    3. Level 3: Intentional disclosure of PHI/PPI outside TUSDM without malicious intentions or repeated Level 2 violations. Requires further retraining with TUSDM Security & Privacy Officer as well as potential for added discipline via Dean’s/Chairs, HR or predoctoral or postdoctoral EPC committees. 
    4. Level 4: Intentional disclosure of PHI/PPI with malicious intent, personal gain and/or loss of reputation or repeated Level 3 violations. Violations may result in termination.
III. Definitions: 
IV. General Rules: 
  1. Upon receipt of any report of a possible privacy violation, the TUSDM HIPAA Security & Privacy Officer (or respective designee[s]) will conduct a confidential investigation of the alleged violation, in coordination with the TUSDM Compliance Officer. If appropriate, the TUSDM HIPAA Security & Privacy Officer or designee(s) may interview any person who may have knowledge of the alleged violation.
  2. The TUSDM HIPAA Security & Privacy Officer (or respective designee[s]) shall determine if a violation has occurred. If a violation has occurred, the TUSDM Security & Privacy Officer shall report the violation to the Compliance Committee, who will refer the case and recommendation for corrective or disciplinary action to the appropriate disciplinary entity final review and disposition (See Appendix A: TUSDM HIPAA Sanctions Flowchart).
  3. If a violation has occurred, the TUSDM HIPAA Security & Privacy Officer shall initiate the Reporting Information Security Incidents process as defined in TUSDM Security Incident Policy.
  4. All sanctions will be consistent with this policy and with other TUSDM policies governing employee misconduct, if any. In addition, sanctions will be administered consistently and without regard to workforce member rank or status.
  5. TUSDM application of corrective actions and level 2–4 sanctions under this policy shall be designated to one four disciplinary entities:
    1. Violations by predoctoral students: Predoctoral Ethics, Professionalism, and Citizenship Committee.
    2. Violations by postgraduate residents: Postgraduate Ethics, Professionalism, and Citizenship Committee.
    3. Violations by paid or volunteer faculty members: Department Chair and/or TUSDM Dean.
    4. Violations by exempt and non-exempt employees: TUSDM Office of Human Resources     
  6. All TUSDM disciplinary entities will adhere to a set of consistent definitions and recommended actions for Level 1–4 violations, which are defined under Appendix B: Guidelines for Sanctions for Violations of Privacy.
  7. Workforce sanctions shall be based on (a) severity of the violation and its impact; (b) whether the violation was intentional and, if so, what the intent was; and (c) whether the violation is part of a pattern of improper behavior regarding privacy and security. Mitigating factors may be considered.
  8. The sanctions imposed may include but are not limited to informal counseling; verbal warning; written warning; suspension; and/or termination. A workforce member may also be placed on probation and/or demoted. Financial restitution may be required, if warranted by the circumstances of the violation. In all cases, the sanction imposed will be at the discretion of the disciplinary entity governing the case.
  9. At minimum, Workforce Members with first-time documented Level 1 or Level 2 violations must participate in mandatory retraining sessions with TUSDM Security & Privacy Officer or Privacy Officer-approved content focused on prevention of further violations.
  10. A manager or supervisor may also be sanctioned to the extent that inadequate supervision or a lack of due diligence contributed to the violation, or if the manager or supervisor’s conduct was culpable or sanctionable in other ways. In addition, managers and supervisors may be sanctioned for failing to detect non-compliance with applicable policies and legal requirements, where reasonable diligence would have led to the discovery of any disclosures or violations.
  11. All Workforce Members are strongly encouraged to report actual or suspected violations of TUSDM’s policies and procedures to their supervisor, the TUSDM Security & Privacy Officer or their Human Resources representative. TUSDM will not impose sanctions on any workforce member who in good faith reports a suspected violation of the law or TUSDM’s policies and procedures.
  12. TUSDM allows for two exceptions to sanctions for external disclosure of PHI/PPI under this policy:
    1. Disclosures by Whistleblowers. TUSDM shall not apply sanctions against a Workforce Member who believes in good faith that TUSDM has engaged in conduct that is unlawful or otherwise violates professional or clinical standards, or that the care, services, or conditions provided by TUSDM potentially endangers one or more patients, workers, or the public; and the disclosure is to (a) a health oversight agency or public health authority authorized by law to investigate or otherwise oversee the relevant conduct or conditions of TUSDM; (b) an appropriate health care accreditation organization for the purpose of reporting the allegation of failure to meet professional standards or misconduct by a component; or (c) an attorney retained by or on behalf of the workforce member for the purpose of determining the legal options of the workforce member with regard to the conduct related to whistleblowing.
    2. Disclosures by Workforce Members Who Are Victims of a Crime. TUSDM shall not apply sanctions to a member of its workforce who is the victim of a criminal act and discloses PHI/PII to a law enforcement official, provided that the PHI disclosed is about the suspected perpetrator of the criminal act and the PHI disclosed is limited to the following types:
      1. Name and address.
      2. Date and place of birth.
      3. Social Security number.
      4. ABO blood type and Rh factor.
      5. Type of injury.
      6. Date and time of treatment.
      7. Date and time of death, if applicable.
      8. A description of distinguishing characteristics, including height, weight, gender, race, hair, and eye color, presence, or absence of facial hair (beard or mustache), scars, and tattoos. 
  13. A record of the event and any discipline imposed shall be maintained in the workforce member’s personnel file with a copy to be filed in a master file maintained by TUSDM’s Security & Privacy Officer.
V. Policy Compliance Monitoring and Enforcement: 
  1. The TUSDM Security & Privacy Officer shall be responsible for overall monitoring and enforcement of HIPAA Security and Privacy Rules and related policies. When potential privacy and security violations, incidents or breaches are reported or discovered, the TUSDM Security & Privacy Officer must be informed and involved throughout the investigation and sanctions process. The potential violator’s direct supervisor or manager, Department Chair, and/or Dean shall also be involved.
  2. Each case shall be documented and filed in the workforce member’s personnel or student record, where it will be retained for a minimum of six years. Documentation shall include (a) name of workforce member; (b) name(s) and role(s) of decision-maker(s) for the case; (c) description of the violation (without inclusion of any protected information except if/as necessary); (d) other circumstances—either mitigating or damaging; (d) date(s) and time(s) of violation; (e) real and potential consequences; (f) sanction(s) applied (including a complete record of any external reporting).
VI. Potential Disciplinary Actions and Sanctions: 

See above.

VIII. Approval and Review Cycle: 
  1. This policy shall be subject to annual review, revision, and approval by the TUSDM Compliance Committee and, in the event of material changes, official adoption by the TUSDM Dean.