01Background
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) as amended by the Health Information Technology for Economic and Clinical Health (HITECH) Act and its implementing regulations, provides restrictions on the use and disclosure of protected health information (PHI).
02Purpose
This policy specifies the responsibilities, requirements, and procedures for the safeguarding, use, and disclosure of protected health information (PHI) transmitted or maintained in any form or medium (electronic or otherwise) by Consultex and its members.
03Definitions
An entity, not a member of the Covered Entity’s workforce, that:
- Performs or assists in performing a function or activity regulated by HIPAA, on behalf of a Covered Entity, involving the creation, receipt, maintenance, or transmission (i.e., use and disclosure) of PHI — including, without limitation: claims processing or administration, data analysis, processing or administration, utilization review, quality assurance, patient safety activities listed at 42 CFR 3.20, billing, benefit management, practice management, and repricing; or
- Provides legal, accounting, actuarial, consulting, data aggregation, management, accreditation, or financial services, where the performance of such services involves giving the service provider access to PHI.
Business Associates include: a health information organization; an e-prescribing gateway; any entity that provides data transmission services with respect to PHI to a Covered Entity and that requires routine access to PHI; and any entity that maintains PHI for a Covered Entity, whether or not the entity actually reviews the PHI.
Health information that does not identify an individual and with respect to which there is no reasonable basis to believe that the information can be used to identify an individual. A Covered Entity may determine that information is de-identified by either: (a) professional statistical analysis; or (b) removal of eighteen (18) specific identifiers.
A group of records maintained by or for a company that includes:
- Enrollment, payment, and claims adjudication records of an individual maintained by or for the Plan; or
- Other protected health information used, in whole or in part, by or for the Plan to make coverage decisions about an individual.
For information that is PHI, “Disclosure” means any release, transfer, provision of access to, or divulging in any other manner of individually identifiable health information to persons not employed by or working within the human resources department of the location(s) of the Employer.
Any of the following activities, to the extent related to Plan administration: conducting quality assessment and improvement activities; reviewing health plan performance; underwriting and premium rating; conducting or arranging for medical review, legal services, and auditing functions; business planning and development; business management and general administrative activities; and de-identifying information in accordance with HIPAA Rules as necessary to perform required services.
Activities undertaken to obtain Plan contributions or to determine or fulfill the Plan’s responsibility for provision of benefits under the Plan, or to obtain or provide reimbursement for health care. Payment also includes, without limitation: eligibility and coverage determinations, including coordination of benefits and adjudication or subrogation of health benefit claims; risk adjusting based on enrollee status and demographic characteristics; and billing, claims management, collection activities, obtaining payment under a contract for reinsurance (including stop-loss insurance and excess loss insurance), and related health care data processing.
The sharing, employment, application, utilization, examination, or analysis of individually identifiable health information by any person working for or within the human resources department of the Employer, or by a Business Associate of the Plan.
04Scope
Consultex is a business entity that is considered to be a Business Associate with respect to protected health information (PHI), as provided by the standards, requirements, and implementation specifications of the HIPAA Privacy Rule. Therefore, this policy applies to Consultex and all the members of its workforce with access to PHI.
Additionally, all third parties, subcontractors, or vendors that provide services to Consultex that involve the creation, receipt, maintenance, or transmission of protected health information on behalf of the Employer to fulfill its contractual duties must comply fully with HIPAA’s requirements.
05Roles and Responsibilities
Privacy personnel designations will be documented and maintained in written or electronic form for six (6) years from the time of designation.
Consultex’s Chief People Officer will serve as the Privacy Official, who will be responsible for:
- Developing and implementing privacy policies and procedures
- Developing a program to manage complaints
- Appointing personnel who will serve as contact persons to respond to questions, concerns, or complaints about individual PHI privacy and protection
- Ensuring compliance with the HIPAA Privacy Rule regarding Business Associates and Business Associate Agreements (BAAs)
- Monitoring compliance of all Business Associates with the HIPAA Privacy Rule and this policy
- Developing privacy training schedules and programs
06Documentation
This policy and associated procedures are designed to ensure compliance as it applies to Consultex, its size, and the type of activities it performs. As documented, this policy will be maintained for at least six (6) years from the date last in effect. Any necessary or appropriate changes to this policy will be:
- In line with the standards set forth in the HIPAA Privacy Rule;
- To comply with changes in the law, standards, requirements and implementation specifications (including changes and modifications in regulations);
- Promptly implemented and documented;
- Reflected in the notice of privacy practices; and
- Communicated, if required, in writing or electronically, and documented.
The Plan shall document certain events and actions (including authorizations, requests for information, sanctions, and complaints) relating to an individual’s privacy rights.
07General Policy (§ 164.530)
Training
Consultex will ensure that all personnel are trained on the company’s privacy policies and procedures, and the HIPAA Privacy Rule as applicable, annually. The training will be reviewed and updated as needed, but annually at the least.
Administrative, Technical and Physical Safeguards
Consultex has appropriate administrative, technical and physical safeguards to prevent PHI from intentionally or unintentionally being used or disclosed in violation of HIPAA’s requirements.
- Administrative safeguards — implementing procedures for use and disclosure of PHI, as outlined in this policy.
- Technical safeguards — limiting access to information by creating computer firewalls, ensuring only authorized access to PHI at the minimum level necessary for administrative functions.
- Physical safeguards — locking doors or filing cabinets.
Privacy Notice
Consultex’s privacy notice will include:
- Uses and disclosures of PHI that may be made by Consultex;
- Individual’s rights under the HIPAA Privacy Rule;
- Consultex’s legal duties with respect to PHI;
- Notification of access to PHI in connection with administrative functions;
- Complaint procedures; and
- Other information as required by the HIPAA Privacy Rule.
Consultex will deliver or make available the privacy notice to appropriate individuals: upon request; within 60 days after a material change to the notice; and at least once every three years in compliance with the HIPAA Privacy Rule.
Sanctions
Violation of this policy or the HIPAA Privacy Rule will be met with sanctions in accordance with Consultex’s discipline policy, up to and including termination (see Information Security Policy).
Mitigation of Inadvertent PHI Disclosures
Consultex will, to the extent possible, mitigate any harmful effects that become known to it of a use or disclosure of an individual’s PHI in violation of HIPAA or the policies and procedures set forth in this Policy. Personnel will immediately contact the Privacy Official for appropriate steps to mitigate harm to impacted individuals if the member becomes aware of:
- A disclosure of PHI, either by an employee or a Business Associate
- An employee or Business Associate that is not in compliance with this policy or HIPAA
No Intimidation or Retaliatory Acts
No Consultex member may intimidate, threaten, coerce, discriminate against, or take other retaliatory action against any individual for exercising their rights, filing a complaint, participating in an investigation, or opposing any improper practice under HIPAA.
No Waiver of HIPAA Privacy
No individual will be required by Consultex or any of its members to waive his or her privacy rights under HIPAA, as a condition of treatment, payment, enrollment or eligibility under a health plan.
08Use and Disclosure of PHI
All members of Consultex with access to PHI must comply with this Policy and the included procedures.
Access to PHI Is Limited to Certain Employees
The following employees (“employees with access”) have access to PHI:
- Any employee who performs functions directly on behalf of Consultex (titles to be inserted per role assignment);
- Any other employee who has access to PHI on behalf of the Employer for its use in “plan administrative functions” (titles to be inserted per role assignment).
Employees with access may use and disclose PHI for company administrative functions, and they may disclose PHI to other employees with access for administrative functions — but the PHI disclosed must be limited to the minimum amount necessary to perform the plan administrative function. Employees with access may not disclose PHI to other employees unless an authorization is in place or the disclosure is otherwise in compliance with this Policy and any associated procedures.
Permitted Uses and Disclosures for Plan Administration
Consultex may disclose the following for its use:
- De-identified health information;
- Enrollment information;
- Summary health information for the purposes of obtaining premium bids for providing health insurance coverage under a plan, or for modifying, amending, or terminating the plan; or
- PHI pursuant to an authorization from the individual whose PHI is disclosed.
PHI may be disclosed to employees who have access to use and disclose PHI to perform functions on behalf of Consultex or to perform plan administrative functions.
Permitted Uses and Disclosures: Payment and Health Care Operations
PHI may be disclosed for the purposes of Consultex’s own payment purposes, and PHI may be disclosed to another covered entity for the payment purposes of that covered entity. The same applies for disclosures for health care operations.
Uses and Disclosures for Consultex’s Own Payment Activities or Health Care Operations. An employee may use and disclose PHI to perform Consultex’s own payment activities or health care operations.
- Disclosures must comply with the “Minimum-Necessary” Standard. (If the disclosure is not recurring, the disclosure must be approved by the Privacy Official.)
- Disclosures must be documented in accordance with the procedure for “Documentation Requirements.”
Disclosures for Another Entity’s Payment Activities. An employee may disclose PHI to another covered entity or health care provider to perform the other entity’s payment activities. These disclosures will be made according to procedures developed by the Privacy Official.
Disclosures for Certain Health Care Operations of the Receiving Entity. An employee may disclose PHI for purposes of the other covered entity’s quality assessment and improvement, case management, or health care fraud and abuse detection programs, if the other covered entity has (or had) a relationship with the individual and the PHI requested pertains to that relationship.
- The disclosure must be approved by the Privacy Official.
- Disclosures must comply with the “Minimum-Necessary” Standard.
- Disclosures must be documented in accordance with the procedure for “Documentation Requirements.”
Use or Disclosure for Purposes of Non-Health Benefits. Unless an authorization from the individual has been received, an employee may not use a participant’s PHI for the payment or operations of the Employer’s “non-health” benefits (e.g., disability, worker’s compensation, and life insurance). If an employee requires a participant’s PHI for the payment or health care operations of non-Plan benefits, follow the steps provided by the Privacy Official.
No Disclosure for Non-Health Plan Purposes
PHI may not be used or disclosed for the payment or operations of Consultex’s “non-health” benefits (e.g., disability, workers’ compensation, life insurance, etc.), unless the participant has provided an authorization for such use or disclosure, or such use or disclosure is required by applicable state law and particular requirements under HIPAA are met.
Mandatory Disclosures: Individual and HHS
A participant’s PHI must be disclosed as required by HIPAA in three situations: (1) the disclosure is to the individual who is the subject of the information; (2) the disclosure is required by law; or (3) the disclosure is made to HHS for purposes of enforcing HIPAA.
Request From Individual. Upon receiving a request from an individual (or an individual’s representative) for disclosure of the individual’s own PHI, the employee must follow the procedure for “Disclosures to Individuals Under Right to Access Own PHI.”
Request From HHS. Upon receiving a request from an HHS official, the employee must take the steps established by the Privacy Official and follow the procedures for verifying the identity of a public official set forth in “Verification of Identity of Those Requesting Protected Health Information.” Disclosures must be documented in accordance with the procedure for “Documentation Requirements.”
Permissive Disclosures: Legal and Public Policy
An employee who receives a request for disclosure of an individual’s PHI that appears to fall within one of the categories below must contact the Privacy Official. Disclosures must (1) be approved by the Privacy Official; (2) comply with the “Minimum-Necessary Standard”; and (3) be documented in accordance with the procedure for “Documentation Requirements.”
Permitted disclosures include:
- Victims of abuse, neglect or domestic violence — if the individual agrees, or if expressly authorized by statute or regulation to prevent harm to the individual or other victim;
- Judicial and administrative proceedings — in response to a court order or administrative tribunal; or a subpoena, discovery request, or other lawful process, upon receipt of assurances of notice to the individual or reasonable efforts to receive a qualified protective order;
- Law enforcement officials — pursuant to process and as required by law; to identify or locate a suspect, fugitive, material witness, or missing person; about a suspected victim of a crime; about a deceased individual upon suspicion of criminal conduct; or evidence of criminal conduct on the Employer’s premises;
- Public health authorities for public health activities;
- Health oversight agencies as authorized by law;
- Coroners, medical examiners about decedents;
- Cadaveric organ, eye or tissue donation;
- Certain limited research purposes, provided a waiver of authorization has been approved by an appropriate privacy board;
- To avert a serious threat to health or safety, upon a good-faith belief that disclosure is necessary;
- Specialized government functions — including disclosures of an inmate’s PHI to correctional institutions and disclosures to an authorized federal official for national security activities; and
- Workers’ compensation programs, to the extent necessary to comply with applicable laws.
Disclosures Pursuant to an Individual Authorization
PHI may be disclosed for any purpose if an authorization satisfying all of HIPAA’s requirements is provided by an individual. All uses and disclosures made pursuant to a signed authorization must be consistent with the terms and conditions of the authorization. Any requested disclosure to a third party that does not fall within one of the categories for which disclosure is permitted or required in this policy may be made pursuant to an individual authorization.
Verify that the authorization form is valid. Valid authorization forms are those that:
- Are properly signed and dated by the individual or the individual’s representative;
- Are not expired or revoked (expiration must be a specific date, time period, or event directly relevant to the individual or purpose);
- Contain a description of the information to be used or disclosed;
- Contain the name of the entity or person authorized to use or disclose the PHI;
- Contain the name of the recipient of the use or disclosure;
- Contain a statement regarding the individual’s right to revoke the authorization and the procedures for revoking; and
- Contain a statement regarding the possibility for a subsequent re-disclosure of the information.
All authorizations for use or disclosure for non-Plan purposes must be on a form provided by (or approved by) the Privacy Official. Follow the procedures for verifying the identity of the individual (or the individual’s representative).
Verification of Identity
Employees must take steps to verify the identity of individuals who request access to PHI, and the authority of any person to have access to PHI if their identity or authority is not known.
Request Made by Individual. Request a form of identification (valid driver’s license, passport, or other government photo ID). Verify that the identification matches the requesting individual. Make a copy of the identification and file it with the individual’s designated record set. If the individual requests PHI over the telephone, ask for the Social Security number. Document the disclosure.
Request Made by Parent Seeking PHI of Minor Child. Seek verification of the person’s relationship with the child (e.g., confirming enrollment as a dependent). Document the disclosure.
Request Made by Personal Representative. Require a copy of a valid power of attorney or other documentation (requirements may vary state-by-state). Make a copy of the documentation and file it with the designated record set. Document the disclosure.
Request Made by Public Official. If in person, request agency identification, credentials, or proof of government status. If in writing, verify the request is on the appropriate government letterhead. If by a person purporting to act on behalf of a public official, request a written statement on letterhead or other evidence of agency. Request a written statement of legal authority (or oral, if a written statement would be impracticable). For legal process, contact the Legal Department. Obtain Privacy Official approval.
Requests From Spouses, Family Members, and Friends. PHI will not be disclosed to family or friends of an individual except as required or permitted by HIPAA. Generally, an authorization is required.
Disclosures of PHI to Business Associates
Employees may disclose PHI to Consultex’s Business Associates and allow the Business Associates to create or receive PHI on its behalf. However, prior to doing so, Consultex will first obtain assurances from the Business Associate that it will appropriately safeguard the information. All uses and disclosures by a Business Associate will be made in accordance with a valid Business Associate Agreement (BAA).
Before sharing PHI with outside consultants or contractors who meet the definition of a Business Associate, employees must contact the Privacy Official and verify that a Business Associate Agreement is in place. Disclosures must:
- Be consistent with the terms of the Business Associate contract;
- Comply with the “Minimum-Necessary” Standard;
- Be documented in accordance with the procedure for “Documentation Requirements.”
Complying with the Minimum-Necessary Standard
HIPAA requires that when PHI is used or disclosed, the amount disclosed generally must be limited to the “minimum necessary” to accomplish the purpose of the use or disclosure.
Procedures for Disclosures. Identify recurring disclosures and create a policy for each that limits the amount disclosed. For all other requests, contact the Privacy Official to ensure the amount of information disclosed is the minimum necessary.
Procedures for Requests. Identify recurring requests and create a policy that limits each request to the minimum amount necessary. For all other requests, contact the Privacy Official.
Exceptions. The Minimum-Necessary standard does not apply to: uses or disclosures made to the individual; uses or disclosures made pursuant to an individual authorization; disclosures made to HHS; uses or disclosures required by law; and uses or disclosures required to comply with HIPAA.
Disclosures of De-Identified Information
De-identified information is not PHI; it is health information that does not identify an individual and with respect to which there is no reasonable basis to believe that the information can be used to identify an individual. There are two ways to determine that information is de-identified: professional statistical analysis, or removing specific identifiers. Upon approval and verification from the Privacy Official that the information in question is de-identified, the de-identified information may be used and disclosed freely in accordance with HIPAA privacy regulations.
09Individual Rights
Request for Access
HIPAA provides individuals the right to access and obtain copies of their PHI (or electronic copies) that Consultex (or its Business Associates) maintains in designated record sets. Upon receiving a request from an individual (or a minor’s parent or a personal representative):
- Follow the procedures for verifying the identity of the individual.
- Review the request to determine whether the PHI requested is held in the individual’s designated record set. No request for access may be denied without approval from the Privacy Official.
- Review the request to determine whether an exception to the disclosure requirement might exist (e.g., psychotherapy notes, documents compiled for a legal proceeding, etc.).
- Respond within 30 days. If the requested PHI cannot be accessed within the 30-day period, the deadline may be extended for 30 days by providing written notice within the original 30-day period.
- A Denial Notice must contain (1) the basis for the denial; (2) a statement of the individual’s right to request a review of the denial, if applicable; and (3) a statement of how the individual may file a complaint.
- Provide the information in the form or format requested, if readily producible. Individuals have the right to receive a copy by mail, by e-mail, or to come in and pick up a copy or inspect the information.
- If a summary and explanation is requested in lieu of, or in addition to, the full information, prepare such summary in the form requested.
- Charge a reasonable cost-based fee for copying, postage, and preparing a summary (the fee for a summary must be agreed to in advance by the individual).
Request for Amendment
HIPAA provides individuals the right to request that their PHI be amended. Consultex will consider requests for amendment that are submitted in writing by participants. Upon receiving a request:
- Follow the procedures for verifying the identity of the individual.
- Review the request to determine whether the PHI at issue is held in the designated record set.
- Review the request to determine whether the information would be accessible under HIPAA’s right to access.
- Review the request to determine whether the amendment is appropriate — that is, whether the information in the designated record set is accurate and complete without the amendment.
- Respond within 60 days. The deadline may be extended for 30 days by providing written notice within the original 60-day period.
- When an amendment is accepted, make the change in the designated record set and provide appropriate notice to the individual and listed persons or entities.
When an amendment request is denied, the Denial Notice (prepared or approved by the Privacy Official) must contain: (1) the basis for the denial; (2) information about the individual’s right to submit a written statement disagreeing with the denial; (3) an explanation that the individual may request that the request for amendment and its denial be included in future disclosures; and (4) a statement of how the individual may file a complaint.
Request for an Accounting of Disclosures
Upon receiving a request for an accounting of disclosures of PHI:
- Follow the procedures for verifying the identity of the individual.
- If the individual has already received one accounting within the preceding 12 months, prepare a notice that a fee for processing will be charged, with an option to withdraw the request.
- Respond within 60 days by providing the accounting (or notice that no reportable disclosures occurred). The deadline may be extended for 30 days with written notice.
The accounting must include disclosures (but not uses) of the requesting individual’s PHI made by the Plan and any of its Business Associates during the requested period up to six years prior to the request. The accounting does not have to include disclosures made: to carry out treatment, payment, and health care operations; to the individual about his or her own PHI; incident to an otherwise permitted use or disclosure; pursuant to an individual authorization; for specific national security or intelligence purposes; to correctional institutions or law enforcement when the disclosure was permitted without authorization; and as part of a limited data set.
The accounting must include, for each reportable disclosure: the date of disclosure; the name (and if known, the address) of the entity or person to whom the information was disclosed; a brief description of the PHI disclosed; and a brief statement explaining the purpose for the disclosure.
Requests for Confidential Communications
Individuals may request to receive communications regarding their PHI by alternative means or at alternative locations (e.g., calls only at work rather than at home). Such requests may be honored if reasonable. The Employer shall accommodate such a request if the participant clearly provides information that disclosure could endanger the participant. The Privacy Official has responsibility for administering these requests.
- Verify the identity of the individual.
- Determine whether the request contains a statement that disclosure could endanger the individual.
- Take steps to honor reasonable requests.
- If a request will not be accommodated, contact the individual in person, in writing, or by telephone to explain why.
- All approved confidential communication requests must be tracked and documented.
Requests for Restrictions on Uses and Disclosures
Individuals may request restrictions on the use and disclosure of the participant’s PHI. Upon receiving a request:
- Verify the identity of the individual.
- Take steps to honor reasonable requests.
- If a request will not be accommodated, explain why in person, in writing, or by telephone.
- All approved restrictions must be tracked.
- All Business Associates that may have access to the individual’s PHI must be notified of any agreed-to restrictions.
10Records and Retention
Copies of all of the following items will be maintained for a period of at least six (6) years from the date the documents were created or were last in effect, whichever is later:
- “Notices of Privacy Practices” that are issued to participants;
- Copies of policies and procedures;
- Individual authorizations;
- When disclosure of certain PHI is made: date of the disclosure; name (and if known, address) of the entity or person who received the PHI; brief description of the PHI disclosed; brief statement of the purpose of the disclosure; and any other documentation required under these Use and Disclosure Procedures.