Privacy, Use, and Disclosure Policy (HIPAA) | Incode
Privacy, Use, and Disclosure Policy (HIPAA)
Incode Technologies, Inc.
Background
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) as amended by the Health Information Technology for Economic and Clinical Health (HITECH) Act and its implementing regulations, provides restrictions on the use and disclosure of protected health information (PHI).
Purpose
This policy specifies the responsibilities, requirements, and procedures for the safeguarding, use, and disclosure of protected health information (PHI) transmitted or maintained in any form or medium (electronic or otherwise) by Incode and its members.
Definitions
Business Associate. An entity, not a member of the Covered Entity’s workforce, who:
- Performs or assists in performing a function or activity regulated by HIPAA, on behalf of a covered entity, involving the creation, receipt, maintenance, or transmission (i.e., use and disclosure) of PHI (including claims processing or administration, data analysis, processing or administration, utilization review, quality assurance, patient safety activities listed at 42 CFR 3.20, billing, benefit management, practice management, and repricing); or
- Provides legal, accounting, actuarial, consulting, data aggregation, management, accreditation, or financial services, where the performance of such services involves giving the service provider access to PHI;
- Business Associates include:
- A health information organization;
- An e-prescribing gateway;
- Any entity that provides data transmission services with respect to PHI to a covered entity and that requires routine access to PHI;
- An entity that maintains PHI for a covered entity, whether or not the entity actually reviews the PHI.
De-identified Information. Health information that does not identify an individual and with respect to which there is no reasonable basis to believe that the information can be used to identify an individual. There are two ways a covered entity can determine that information is de-identified:
- Professional statistical analysis
- Removing 18 specific identifiers.
Designated Record Set. A group of records maintained by or for a company that includes:
- Enrollment, payment, and claims adjudication record of an individual maintained by or for the Plan; or
- Other protected health information used, in whole or in part, by or for the Plan to make coverage decisions about an individual.
Disclosure. For information that is PHI, disclosure means any release, transfer, provision of access to, or divulging in any other manner of individually identifiable health information to persons not employed by or working within the human resources department of the location(s) of the Employer.
Health Care Operations. Health care operations means any of the following activities to the extent that they are related to Plan administration:
- conducting quality assessment and improvement activities;
- reviewing health plan performance;
- underwriting and premium rating;
- conducting or arranging for medical review, legal services and auditing functions;
- business planning and development;
- business management and general administrative activities;
- to de-identify the information in accordance with HIPAA Rules as necessary to perform required services.
Payment. Payment includes activities undertaken to obtain Plan contributions or to determine or fulfill the Plan’s responsibility for provision of benefits under the Plan, or to obtain or provide reimbursement for health care. Payment also includes:
- eligibility and coverage determinations including coordination of benefits and adjudication or subrogation of health benefit claims;
- risk adjusting based on enrollee status and demographic characteristics; and
- billing, claims management, collection activities, obtaining payment under a contract for reinsurance (including stop-loss insurance and excess loss insurance) and related health care data processing.
Use. The sharing, employment, application, utilization, examination, or analysis of individually identifiable health information by any person working for or within the human resources department of the Employer, or by a Business Associate (defined below) of the Plan.
Scope
Incode is a business entity that is considered to be a BUSINESS ASSOCIATE with respect to protected health information (PHI), as provided by the standards, requirements, and implementation specifications of HIPAA Privacy Rule. Therefore, this policy applies to Incode and all the members of its workforce with access to PHI. Additionally, all third parties, subcontractors, or vendors that provide services to Incode that involve the creation, receipt, maintenance, or transmission of private health information on behalf of the Employer to fulfill its contractual duties, must comply fully with HIPAA’s requirements.
Roles and Responsibilities
Privacy personnel designations will be documented and maintained in written or electronic form for six years from time of designation.
Incode’s Data Privacy Officer will serve as the Privacy Official, who will be responsible for:
- Developing and implementing privacy policies and procedures
- Developing a program to manage complaints
- Appointing personnel who will serve as contact persons to respond to questions, concerns, or complaints about individual PHI privacy and protection
- Ensuring compliance with the HIPAA Privacy Rule regarding Business Associates, Business Associate Agreements (BAA)
- Monitoring compliance of all Business Associates with the HIPAA Privacy Rule, and this policy
- Developing privacy training schedules and programs
Documentation
This policy and associated procedures are designed to ensure compliance as it applies to Incode, its size, and the type of activities it performs. As documented, this policy will be maintained for at least six years from the date last in effect. Any necessary or appropriate changes to this policy will be:
- In line with the standards set forth in the HIPAA Privacy Rule;
- To comply with changes in the law, standards, requirements and implementation specifications (including changes and modifications in regulations);
- Promptly implemented and documented;
- Reflected in the notice of privacy practices; and
- Communicated, if required, in writing or electronically, and documented. The Plan shall document certain events and actions (including authorizations, requests for information, sanctions, and complaints) relating to an individual’s privacy rights.
General Policy (For Covered Entities – § 164.530)
Training
Incode will ensure that all personnel are trained on the company’s privacy policies and procedures, and the HIPAA Privacy Rule as applicable, annually. The training will be reviewed and updated as needed, but annually at the least.
Administrative, Technical and Physical Safeguards and Firewall
Incode has appropriate administrative, technical and physical safeguards to prevent PHI from intentionally or unintentionally being used or disclosed in violation of HIPAA’s requirements (see company information security policies and procedures, and controls in place).
- Administrative safeguards include implementing procedures for use and disclosure of PHI, as outlined in this policy.
- Technical safeguards include limiting access to information by creating computer firewalls, which will ensure that there is only authorized access to PHI at the minimum level necessary for administrative functions.
- Physical safeguards include locking doors or filing cabinets.
Privacy Notice
Incode’s privacy notice will include:
- Uses and disclosures of PHI that may be made by the Incode;
- Individual’s rights under the HIPAA privacy rules;
- Incode’s legal duties with respect to the PHI
- Notification of access to PHI in connection with administrative functions;
- Complaint procedures; and,
- Other information as required by the HIPAA privacy rules.
Incode will deliver or make available the privacy notice to appropriate individuals:
- Upon request
- Within 60 days after a material change to the notice
- At least once every three years in compliance with the HIPAA Privacy Rule.
Sanctions
Violation of this policy or HIPAA Privacy Rule will be met with sanctions in accordance with Incode’s discipline policy, up to and including termination ( See Information Security Policy).
Mitigation of Inadvertent PHI Disclosures
Incode will, to the extent possible, mitigate any harmful effects that become known to it of a use or disclosure of an individual’s PHI in violation of HIPAA or the policies and procedures set forth in this Policy. As a result, personnel will immediately contact the Privacy Official for the appropriate steps to mitigate the harm to impacted individuals, if the member becomes aware of:
- A disclosure of PHI, either by an employee or a business associate
- An employee or business associate that is not in compliance with this policy or HIPAA.
No Intimidation or Retaliatory Acts
No Incode member may intimidate, threaten, coerce, discriminate against, or take other retaliatory action against any individual for exercising their rights, filing a complaint, participating in an investigation, or opposing any improper practice under HIPAA.
No Waiver of HIPAA Privacy
No individual will be required by Incode or any of its members to waive his or her privacy rights under HIPAA, as a condition of treatment, payment, enrollment or eligibility under a health plan.
Policy and Procedures for Use and Disclosure of PHI
Compliance
All members of Incode with access to PHI must comply with this Policy and included procedures.
Access to PHI Is Limited to Certain Employees
The following employees (“employees with access”) have access to PHI:
- Any employee who performs functions directly on behalf of Incode,
- Any other employee who has access to PHI on behalf of the Employer for its use in “plan administrative functions”.
Employees with access may use and disclose PHI for company administrative functions, and they may disclose PHI to other employees with access for administrative functions (but the PHI disclosed must be limited to the minimum amount necessary to perform the plan administrative function). Employees with access may not disclose PHI to employees (other than employees with access) unless an authorization is in place or the disclosure otherwise is in compliance with this Policy and any associated procedures.
Permitted Uses and Disclosures for Plan Administration Purposes
- Incode may disclose the following for its use:
- (a) de-identified health information;
- (b) Enrollment information;
- (c) summary health information for the purposes of obtaining premium bids for providing health insurance coverage under a plan or for modifying, amending, or terminating the plan; or,
- (d) PHI pursuant to an authorization from the individual whose PHI is disclosed.
PHI may be disclosed to employees who have access to use and disclose PHI to perform functions on behalf of Incode or to perform plan administrative functions (“employees with access”):
Permitted Uses and Disclosures: Payment and Health Care Operations
PHI may be disclosed for the purposes of Incode’s own payment purposes, and PHI may be disclosed to another covered entity for the payment purposes of that covered entity. Same stands for disclosure for health care operations. PHI may be disclosed to another covered entity for purposes of the other covered entity’s quality assessment and improvement, case management, or health care fraud and abuse detection programs, if the other covered entity has (or had) a relationship with the participant and the PHI requested pertains to that relationship.
- Uses and Disclosures for Incode’s Own Payment Activities or Health Care Operations. An employee may use and disclose PHI to perform the Incode’s own payment activities or healthcare operations.
- Disclosures must comply with the “Minimum-Necessary” Standard. (Under that procedure, if the disclosure is not recurring, the disclosure must be approved by the Privacy Official.)
- Disclosures must be documented in accordance with the procedure for “Documentation Requirements.”
- Disclosures for Another Entity’s Payment Activities. An employee may disclose PHI to another covered entity or health care provider to perform the other entity’s payment activities. These disclosures will be made according to procedures developed by the Privacy Official.
- Disclosures for Certain Health Care Operations of the Receiving Entity. An employee may disclose PHI for purposes of the other covered entity’s quality assessment and improvement, case management, or health care fraud and abuse detection programs, if the other covered entity has (or had) a relationship with the individual and the PHI requested pertains to that relationship. Such disclosures are made according to procedures developed by the Privacy Official.
- The disclosure must be approved by the Privacy Official.
- Disclosures must comply with the “minimum-Necessary Standard.”
- Disclosures must be documented in accordance with the procedure for “Documentation Requirements.”
- Use or Disclosure for Purposes of Non-Health Benefits. Unless an authorization from the individual (as discussed in “Disclosures Pursuant to an Authorization”) has been received, an employee may not use a participant’s PHI for the payment or operations of the Employer’s “non-health” benefits (e.g., disability, worker’s compensation, and life insurance). If an employee requires a participant’s PHI for the payment or health care operations of non-Plan benefits, follow the steps provided by the Privacy Official.
- Obtain an Authorization. First, contact the Privacy Official to determine whether an authorization for this type of use or disclosure is on file. If no form is on file, request an appropriate form from the Privacy Official. Employees shall not attempt to draft authorization forms. All authorizations for use or disclosure for non-Plan purposes must be on a form provided by (or approved by) the Privacy Official.
- Questions? Any employee who is unsure as to whether a task he or she is asked to perform qualifies as a payment activity or a health care operation of the Plan should contact the Privacy Official or his or her designated representative.
Non Disclosure for Non-Health Plan Purposes
PHI may not be used or disclosed for the payment or operations of the Incode’s “non-health” benefits (e.g., disability, workers’ compensation, life insurance, etc.), unless the participant has provided an authorization for such use or disclosure (as discussed in “Disclosures Pursuant to an Authorization”) or such use or disclosure is required by applicable state law and particular requirements under HIPAA are met.
Mandatory Disclosures: Individual and HHS
A participant’s PHI must be disclosed as required by HIPAA in three situations: (1) The disclosure is to the individual who is the subject of the information (see the policy for “Access to Protected Information and Request for Amendment” that follows); (b) the disclosure is required by law; or, (c) the disclosure is made to HHS for purposes of enforcing HIPAA.
- Request From Individual. Upon receiving a request from an individual (or an individual’s representative) for disclosure of the individual’s own PHI, the employee must follow the procedure for “Disclosures to Individuals Under Right to Access Own PHI.”
- Request From HHS. Upon receiving a request from an HHS official for disclosure of PHI, the employee must take the steps established by the Privacy Official.
- Follow the procedures for verifying the identity of a public official set forth in “Verification of Identity of Those Requesting Protected Health Information.”
- Disclosures must be documented in accordance with the procedure for “Documentation Requirements.”
Permissive Disclosures: Legal and Public Policy Purposes
An employee who receives a request for disclosure of an individual’s PHI that appears to fall within one of the categories described below under “Legal and Public Policy Disclosures Covered” must contact the Privacy Official. Disclosures must: (1) be approved by the Privacy Official; (2) comply with the “Minimum-Necessary Standard”; and, (3) be documented in accordance with the procedure for “Documentation Requirements”. Permitted disclosures include:
- Disclosures about victims of abuse, neglect or domestic violence, if the following conditions are met:
- The individual agrees with the disclosure; or
- The disclosure is expressly authorized by statute or regulation and the disclosure prevents harm to the individual (or other victim) or the individual is incapacitated and unable to agree and information will not be used against the individual and is necessary for imminent enforcement activity. In this case, the individual must be promptly informed of the disclosure unless this would place the individual at risk or if informing would involve a personal representative who is believed to be responsible for the abuse, neglect or violence.
- For Judicial and Administrative Proceedings, in response to:
- An order of a court or administrative tribunal (disclosure must be limited to PHI expressly authorized by the order); and
- A subpoena, discovery request or other lawful process, not accompanied by a court order or administrative tribunal, upon receipt of assurances that the individual has been given notice of the request, or that the party seeking the information has made reasonable efforts to receive a qualified protective order.
- To a Law Enforcement Official for Law Enforcement Purposes, under the following conditions:
- Pursuant to a process and as otherwise required by law, but only if the information sought is relevant and material, the request is specific and limited to amounts reasonably necessary, and it is not possible to use de-identified information.
- Information requested is limited information to identify or locate a suspect, fugitive, material witness or missing person.
- Information about a suspected victim of a crime (1) if the individual agrees to disclosure; or (2) without agreement from the individual, if the information is not to be used against the victim, if need for information is urgent, and if disclosure is in the best interest of the individual.
- Information about a deceased individual upon suspicion that the individual’s death resulted from criminal conduct.
- Information that constitutes evidence of criminal conduct that occurred on the Employer’s premises.
- To Appropriate Public Health Authorities for Public Health Activities.
- To a Health Oversight Agency for Health Oversight Activities, as authorized by law.
- To a Coroner or Medical Examiner About Decedents, for the purpose of identifying a deceased person, determining the cause of death or other duties as authorized by law.
- For Cadaveric Organ, Eye or Tissue Donation Purposes, to organ procurement organizations or other entities engaged in the procurement, banking, or transplantation of organs, eyes or tissue for the purpose of facilitating transplantation.
- For Certain Limited Research Purposes, provided that a waiver of the authorization required by HIPAA has been approved by an appropriate privacy board.
- To Avert a Serious Threat to Health or Safety, upon a belief in good faith that the use or disclosure is necessary to prevent a serious and imminent threat to the health or safety of a person or the public.
- For Specialized Government Functions, including disclosures of an inmate’s PHI to correctional institutions and disclosures of an individual’s PHI to an authorized federal Official for the conduct of national security activities.
- For Workers’ Compensation Programs, to the extent necessary to comply with laws relating to workers’ compensation or other similar programs.
Disclosures Pursuant to an Individual Authorization
PHI may be disclosed for any purpose if an authorization that satisfies all of HIPAA’s requirements for a valid authorization is provided by an individual. All uses and disclosures made pursuant to a signed authorization must be consistent with the terms and conditions of the authorization.
Verification of Identity of Those Requesting Protected Health Information
Employees must take steps to verify the identity of individuals who request access to PHI. They must also verify the authority of any person to have access to PHI, if the identity or authority of such person is not known. Separate procedures are set forth below for verifying the identity and authority, depending on whether the request is made by the individual, a parent seeking access to the PHI of his or her minor child, a personal representative, or a public official seeking access.
Records
Copies of all of the following items will be maintained for a period of at least six years from the date the documents were created or were last in effect, whichever is later:
- “Notices of Privacy Practices” that are issued to participants
- Copies of policies and procedures
- Individual authorizations
- When disclosure of certain PHI is made:
- Date of the disclosure;
- Name of the entity or person who received the PHI and, if known, the address of such entity or person;
- Brief description of the PHI disclosed;
- Brief statement of the purpose of the disclosure; and
- Any other documentation required under these Use and Disclosure Procedures.