Privacy, Use, and Disclosure Policy (HIPAA) | Incode

Privacy, Use, and Disclosure Policy (HIPAA)

Incode Technologies, Inc.

Background

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) as amended by the Health Information Technology for Economic and Clinical Health (HITECH) Act and its implementing regulations, provides restrictions on the use and disclosure of protected health information (PHI).

Purpose

This policy specifies the responsibilities, requirements, and procedures for the safeguarding, use, and disclosure of protected health information (PHI) transmitted or maintained in any form or medium (electronic or otherwise) by Incode and its members.

Definitions

Business Associate. An entity, not a member of the Covered Entity’s workforce, who:

De-identified Information. Health information that does not identify an individual and with respect to which there is no reasonable basis to believe that the information can be used to identify an individual. There are two ways a covered entity can determine that information is de-identified:

Designated Record Set. A group of records maintained by or for a company that includes:

Disclosure. For information that is PHI, disclosure means any release, transfer, provision of access to, or divulging in any other manner of individually identifiable health information to persons not employed by or working within the human resources department of the location(s) of the Employer.

Health Care Operations. Health care operations means any of the following activities to the extent that they are related to Plan administration:

Payment. Payment includes activities undertaken to obtain Plan contributions or to determine or fulfill the Plan’s responsibility for provision of benefits under the Plan, or to obtain or provide reimbursement for health care. Payment also includes:

Use. The sharing, employment, application, utilization, examination, or analysis of individually identifiable health information by any person working for or within the human resources department of the Employer, or by a Business Associate (defined below) of the Plan.

Scope

Incode is a business entity that is considered to be a BUSINESS ASSOCIATE with respect to protected health information (PHI), as provided by the standards, requirements, and implementation specifications of HIPAA Privacy Rule. Therefore, this policy applies to Incode and all the members of its workforce with access to PHI. Additionally, all third parties, subcontractors, or vendors that provide services to Incode that involve the creation, receipt, maintenance, or transmission of private health information on behalf of the Employer to fulfill its contractual duties, must comply fully with HIPAA’s requirements.

Roles and Responsibilities

Privacy personnel designations will be documented and maintained in written or electronic form for six years from time of designation.

Incode’s Data Privacy Officer will serve as the Privacy Official, who will be responsible for:

Further, the Privacy Officer:

Contact person/ office of record: dataprotection@incode.com

Documentation

This policy and associated procedures are designed to ensure compliance as it applies to Incode, its size, and the type of activities it performs. As documented, this policy will be maintained for at least six years from the date last in effect. Any necessary or appropriate changes to this policy will be:

The Plan shall document certain events and actions (including authorizations, requests for information, sanctions, and complaints) relating to an individual’s privacy rights.

General Policy (For Covered Entities – § 164.530)

Training

Incode will ensure that all personnel are trained on the company’s privacy policies and procedures, and the HIPAA Privacy Rule as applicable, annually. The training will be reviewed and updated as needed, but annually at the least.

Administrative, Technical and Physical Safeguards and Firewall

Incode has appropriate administrative, technical and physical safeguards to prevent PHI from intentionally or unintentionally being used or disclosed in violation of HIPAA’s requirements (see company information security policies and procedures, and controls in place).

Privacy Notice

Incode’s privacy notice will include:

Incode will deliver or make available the privacy notice to appropriate individuals:

Sanctions

Violation of this policy or HIPAA Privacy Rule will be met with sanctions in accordance with Incode’s discipline policy, up to and including termination ( See Information Security Policy).

Mitigation of Inadvertent PHI Disclosures

Incode will, to the extent possible, mitigate any harmful effects that become known to it of a use or disclosure of an individual’s PHI in violation of HIPAA or the policies and procedures set forth in this Policy. As a result, personnel will immediately contact the Privacy Official for the appropriate steps to mitigate the harm to impacted individuals, if the member becomes aware of:

No Intimidation or Retaliatory Acts

No Incode member may intimidate, threaten, coerce, discriminate against, or take other retaliatory action against any individual for exercising their rights, filing a complaint, participating in an investigation, or opposing any improper practice under HIPAA.

No Waiver of HIPAA Privacy

No individual will be required by Incode or any of its members to waive his or her privacy rights under HIPAA, as a condition of treatment, payment, enrollment or eligibility under a health plan.

Policy and Procedures for Use and Disclosure of PHI

Compliance

All members of Incode with access to PHI must comply with this Policy and included procedures.

Access to PHI Is Limited to Certain Employees

The following employees (“employees with access”) have access to PHI:

Employees with access may use and disclose PHI for company administrative functions, and they may disclose PHI to other employees with access for administrative functions (but the PHI disclosed must be limited to the minimum amount necessary to perform the plan administrative function). Employees with access may not disclose PHI to employees (other than employees with access) unless an authorization is in place or the disclosure otherwise is in compliance with this Policy and any associated procedures.

Permitted Uses and Disclosures for Plan Administration Purposes

PHI may be disclosed to employees who have access to use and disclose PHI to perform functions on behalf of Incode or to perform plan administrative functions (“employees with access”):

Permitted Uses and Disclosures: Payment and Health Care Operations

PHI may be disclosed for the purposes of Incode’s own payment purposes, and PHI may be disclosed to another covered entity for the payment purposes of that covered entity. Same stands for disclosure for health care operations. PHI may be disclosed to another covered entity for purposes of the other covered entity’s quality assessment and improvement, case management, or health care fraud and abuse detection programs, if the other covered entity has (or had) a relationship with the participant and the PHI requested pertains to that relationship.

Non Disclosure for Non-Health Plan Purposes

PHI may not be used or disclosed for the payment or operations of the Incode’s “non-health” benefits (e.g., disability, workers’ compensation, life insurance, etc.), unless the participant has provided an authorization for such use or disclosure (as discussed in “Disclosures Pursuant to an Authorization”) or such use or disclosure is required by applicable state law and particular requirements under HIPAA are met.

Mandatory Disclosures: Individual and HHS

A participant’s PHI must be disclosed as required by HIPAA in three situations: (1) The disclosure is to the individual who is the subject of the information (see the policy for “Access to Protected Information and Request for Amendment” that follows); (b) the disclosure is required by law; or, (c) the disclosure is made to HHS for purposes of enforcing HIPAA.

Permissive Disclosures: Legal and Public Policy Purposes

An employee who receives a request for disclosure of an individual’s PHI that appears to fall within one of the categories described below under “Legal and Public Policy Disclosures Covered” must contact the Privacy Official. Disclosures must: (1) be approved by the Privacy Official; (2) comply with the “Minimum-Necessary Standard”; and, (3) be documented in accordance with the procedure for “Documentation Requirements”. Permitted disclosures include:

Disclosures Pursuant to an Individual Authorization

PHI may be disclosed for any purpose if an authorization that satisfies all of HIPAA’s requirements for a valid authorization is provided by an individual. All uses and disclosures made pursuant to a signed authorization must be consistent with the terms and conditions of the authorization.

Any requested disclosure to a third party (i.e., not the individual to whom the PHI pertains) that does not fall within one of the categories for which disclosure is permitted or required in this policy may be made pursuant to an individual authorization. If disclosure pursuant to an authorization is requested, the following procedures should be followed:

Verification of Identity of Those Requesting Protected Health Information

Employees must take steps to verify the identity of individuals who request access to PHI. They must also verify the authority of any person to have access to PHI, if the identity or authority of such person is not known. Separate procedures are set forth below for verifying the identity and authority, depending on whether the request is made by the individual, a parent seeking access to the PHI of his or her minor child, a personal representative, or a public official seeking access.

Disclosures of PHI to Business Associates

Business Associate is an entity that:

Business Associates include:

Employees may disclose PHI to Incode’s business associates and allow the business associates to create or receive PHI on its behalf. However, prior to doing so, Incode will first obtain assurances from the business associate that it will appropriately safeguard the information. All uses and disclosures by a “business associate” will be made in accordance with a valid business associate agreement. Before sharing PHI with outside consultants or contractors who meet the definition of a “business associate,” employees must contact the Privacy Official and verify that a business associate contract is in place.

The following additional procedures must be satisfied:

Complying With the “Minimum-Necessary” Standard

HIPAA requires that when PHI is used or disclosed, the amount disclosed generally must be limited to the “minimum necessary” to accomplish the purpose of the use or disclosure.

Disclosures of De-Identified Information

De-identified information is not PHI; it is health information that does not identify an individual and with respect to which there is no reasonable basis to believe that the information can be used to identify an individual. There are two ways to determine that information is de-identified: either by professional statistical analysis, or by removing specific identifiers.

Upon approval and verification from the Privacy Official that the information in question is de-identified, the de-identified information may be used and disclosed freely in accordance with HIPAA privacy regulations.

Individual’s Request for Access

HIPAA provides individuals the right to access and obtain copies of their PHI (or electronic copies of PHI) that Incode (or its business associates) maintains in designated record sets.

Upon receiving a request from an individual (or from a minor’s parent or an individual’s personal representative) for disclosure of an individual’s PHI, the employees will take the following steps:

Follow the procedures for verifying the identity of the individual (or parent or personal representative) set forth in “Verification of Identity of Those Requesting Protected Health Information.”

Individual’s Requests for Amendment

HIPAA also provides individuals the right to request to have their PHI amended. Incode will consider requests for amendment that are submitted in writing by participants.

Upon receiving a request from an individual (or a minor’s parent or an individual’s personal representative) for amendment of an individual’s PHI held in a designated record set, employees will take the following steps:

Request for an Accounting of Disclosures of PHI

An individual has the right to obtain an accounting of certain disclosures of his or her own PHI.

Upon receiving a request from an individual (or a minor’s parent or an individual’s personal representative) for an accounting of disclosures, the employee must take the following steps:

Requests for Confidential Communications

Individuals may request to receive communications regarding their PHI by alternative means or at alternative locations. For example, participants may ask to be called only at work rather than at home. Such requests may be honored if the requests are reasonable.

However, the Employer shall accommodate such a request if the participant clearly provides information that the disclosure of all or part of that information could endanger the participant. The Privacy Official has responsibility for administering requests for confidential communications.

Upon receiving a request from an individual (or a minor’s parent or an individual’s personal representative) to receive communications of PHI by alternative means or at alternative locations, the employee must take the following steps:

Requests for Restrictions on Uses and Disclosures of PHI

Individuals may request restrictions on the use and disclosure of the participant’s PHI. Upon receiving a request from an individual (or a minor’s parent or an individual’s personal representative) for access to an individual’s PHI, the employee must take the following steps:

Records

Copies of all of the following items will be maintained for a period of at least six years from the date the documents were created or were last in effect, whichever is later: