I. Purpose and Scope:
- The purpose of this policy is to establish a process for the receipt and resolution of individuals’ privacy-related complaints.
- This policy applies to TUSDM Workforce, including faculty, employees, volunteers, trainees, students, and other persons as defined below.
II. Policy Statement:
- As patient service and privacy of health information are of utmost importance to TUSDM, it is our policy to promptly receive, respond, and resolve patient complaints regarding TUSDM’s (and/or our business associates’) information handling and privacy-related policies and practices.
III. Definitions:
IV. General Rules:
- Who May Make Complaints. The Privacy Regulation allows any person to make a complaint to TUSDM regarding its privacy practices. This means that individuals who are not patients of TUSDM and employees have the same right as patients to make a complaint about TUSDM’s compliance with its policies and procedures and the Privacy Regulation.
- Subject of Complaints. An individual may lodge a formal complaint about TUSDM’s information practices, including, but not limited to, complaints relating to:
- the privacy and security of PHI
- the use and/or disclosure of PHI
- complaints related to an individual’s access to, or amendment of, their PHI
- practices or actions of TUSDM’s business associates
- TUSDM’s marketing practices or
- any other complaint relating to TUSDM’s privacy policies and procedures
- Receipt of Complaints. Any TUSDM employee who receives a complaint from an individual should explain to that individual that TUSDM has established a contact person within TUSDM to receive and respond to privacy-related complaints. If possible, employees should refer the individual to their department manager. Employees and department managers should promptly forward any written complaints or verbal complaints received to the TUSDM Security and Privacy Officer for review and resolution. Only the Security and Privacy Officer has the authority to resolve HIPAA privacy complaints on behalf of TUSDM. Once a complaint is reviewed and resolved, appropriate information will be forwarded to the relevant TUSDM employees for specified corrective action and/or notification of the individual.
- Documentation and Records Retention Requirements. TUSDM must maintain complete documentation of the complaint, the Security and Privacy Officer’s review and disposition of the matter, including a record of any changes to policies or procedures or the imposition of sanctions against members of TUSDM’s workforce, if any. TUSDM must retain all documents relating to the complaint and the investigation for a period of at least six (6) years from the date of their creation.
V. Policy Compliance Monitoring and Enforcement:
- The TUSDM Security & Privacy Officer is responsible for the monitoring and enforcement of this policy; however, directors and managers are also responsible for monitoring compliance with procedures specific to their areas.
VI. Potential Disciplinary Actions and Sanctions:
- Failure to follow standard operating procedures may trigger review for potential disciplinary action under the TUSDM Sanctions for HIPAA Violations Policy.
VIII. Approval and Review Cycle:
- This policy shall be subject to annual review, revision, and approval by the TUSDM Compliance Committee.