Privacy >> TUSDM Policy on Privacy Officer Designation

TUSDM Policy on Privacy Officer Designation

I. Purpose and Scope: 
  1. The Tufts School of Dental Medicine (TUSDM) is required under Title 2 of the Health Insurance Portability and Accountability Act of 1996, Public Law 104-191, of 1996 as amended by the Health Information Technology for Economic and Clinical Health Act and the Privacy and Security Regulations at 45 CFR §§ 160 and 164 (HIPAA) to designate a privacy official who is responsible for the development and implementation of HIPAA policies and procedures and who will act as the primary contact for information requests and complaints regarding privacy practices. 
  2. TUSDM is a HIPAA covered entity within Tufts University, which is a hybrid entity. This policy designates the TUSDM Privacy Officer and defines the role within the organizational context of Tufts University. 
II. Policy Statement: 
  1. To fulfill its commitment to ensuring the privacy and security of its patients’ protected health information, TUSDM has designated an internal HIPAA Security & Privacy Officer charged with (a) the development, implementation, and enforcement of HIPAA policies within the School of Dental Medicine; and (b) receiving complaints and providing individuals with information on TUSDM’s privacy practices. The HIPAA Security & Privacy Officer will have a direct line of communication to the Tufts University designated Privacy Officer within the Office of General Counsel and the Tufts University Director of Information Security. 
III. Definitions: 
IV. General Rules: 
  1. The Privacy Officer will have overall responsibility for ensuring TUSDM adheres to the Administrative Requirements of the HIPAA Privacy Rule and Commonwealth of Massachusetts privacy laws.
    1. Privacy Policy and Procedures: The Privacy Officer will establish, maintain, and communicate official written policies and procedures that are consistent with the HIPAA Privacy Rule. The Privacy Officer will promptly update policies and procedures as necessary to comply with changes in the federal and state regulations governing privacy.
    2. Workforce Training and Management: The Security & Privacy Officer will partner with the TUSDM Division of Clinical Affairs, Faculty Affairs Office, Office of Human Resources, and other Tufts/TUSDM departments as appropriate to develop and deliver Workforce training to all Workforce Members on TUSDM privacy policies and procedures, as necessary and appropriate for them to conduct their functions.
    3. Data Safeguards: The Security & Privacy Officer will ensure TUSDM maintains reasonable and appropriate administrative, technical, and physical safeguards to prevent intentional or unintentional use or disclosure of protected health information in violation of the Privacy Rule and to limit its incidental use and disclosure pursuant to otherwise permitted or required use or disclosure. Specifically, the Security & Privacy Officer will ensure:
      1. proper use and disclosure of PHI at the request of the individual
      2. proper use and disclosure of PHI without the authorization of the individual
      3. appropriate authorization for the use or disclosure of PHI
      4. protecting individual rights regarding PHI
      5. auditing access to PHI
      6. maintenance of records regarding access to PHI and 
      7. secure management of PHI including reasonable efforts to limit incidental uses and disclosures
    4. Mitigation: The Security & Privacy Officer will mitigate, to the extent practicable, any harmful effect that is known to TUSDM of a use or disclosure of PHI in violation of its policies and procedures or the requirements of the HIPAA Privacy Rule by a member of the TUSDM Workforce or any business associate.
    5. Complaints: The Security and Privacy Officer, in cooperation with the TUSDM Associate Director of Patient Relations and the Tufts Office of General Counsel, will maintain a program encouraging TUSDM Workforce Members and patients to report complaints concerning compliance with TUSDM policies and procedures and the HIPAA Privacy Rule. The Program will provide an option for anonymous and confidential complaints. The Security & Privacy Officer or designee will promptly and properly investigate, document, and address reported violations, including taking steps to prevent recurrence.
    6. Retaliation and Waiver: The Security & Privacy Officer will ensure that all persons, including Workforce Members and patients who exercise rights provided by the Privacy Rule; assist in an investigation by the Privacy Officer, the U.S. Department of Health and Human Services or another appropriate authority; or oppose an act that the person believes in good faith violates the Privacy Rule will not be subject to intimidation, threats, coercion, or any other retaliatory action. The Security & Privacy Officer shall also ensure that patients will not be asked to waive any privacy rights as a condition to receive care.
    7. Documentation and Record Retention: The Security & Privacy Officer will ensure all documentation related to and/or required by HIPAA, including but not limited to policies and procedures, compliance enforcement, training activities, complaint investigations, designated record sets, etc. are maintained for six (6) years from the date of creation, or the date it was last in effect, whichever is later. Documentation may be maintained in written or electronic form. 
  2. The Security & Privacy Officer will develop and maintain the Notice of Privacy Practices in accordance with the TUSDM Notice of Privacy Practices Policy.
  3. The Security & Privacy Officer will ensure TUSDM’s HIPAA policies and procedures are consistently enforced and that appropriate sanctions are levied against Workforce Members who violate its privacy policies and procedures or the Privacy Rule. Sanctions will be in accordance with the TUSDM Sanctions for HIPAA Violations Policy.
  4. The Security and Privacy Officer, in conjunction with the Tufts University Purchasing Department will identify entities that meet the definition of “business associate” under HIPAA and ensure that contractual agreements comply with HIPAA requirement to impose specified written safeguards on the individually identifiable health information used or disclosed by TUSDM business associates.
  5. The Security & Privacy Officer will be a designated Information Manager under the Tufts University Information Stewardship and Information Roles and Responsibilities policies and may appoint Information Stewards to assist in developing, implementing, communicating, and/or monitoring compliance with HIPAA policies and procedures.
  6. The Security & Privacy Officer will cooperate with the DHHS Office of Civil Rights, the Massachusetts Office of the Attorney General, Massachusetts Office of Consumer and Business Regulations in compliance reviews, investigations, and mandatory reporting.
  7. TUSDM will ensure the Security & Privacy Officer receives necessary training to develop and implement a suite of HIPAA-compliant policies and an associated Workforce training program.
V. Policy Compliance Monitoring and Enforcement: 
  1. The TUSDM Office of the Dean, in cooperation with the Tufts University Office of Audit and Management Advisory Services, will monitor the activities of the Security & Privacy Officer and advise, as necessary. 
  2. The TUSDM Compliance Committee will serve as internal resource to support the Security & Privacy Officer will review and recommend adoption of all HIPAA-related policies and procedures. 
VI. Potential Disciplinary Actions and Sanctions: 
  1. The designated Security and Privacy Officer will be subject to the disciplinary policies included in the Tufts University Employee Handbook
VIII. Approval and Review Cycle: 
  1. This policy is subject to review, revision, and approval by the TUSDM Compliance Committee, as necessary; and in the event of material changes, official adoption by the TUSDM Dean.