Criminal penalty will be imposed on a person who knowingly obtains and reveals identifiable health information and violates HIPAA Rules at a fine of $50,000 and up to 1 year imprisonment. The fine can increase to $100,000 and the imprisonment to 5 years if the violation involves false pretenses. The fine can go up to $250,000 and up to 10 years imprisonment if there is an intent to sell, transfer or use the information for commercial or personal gain or malicious harm. The Department of Justice enforces criminal sanctions (OCR).
Protected Information
Protected health information or PHI refers to all held or transmitted individually identifiable health data by a covered entity or its business association, contained in any form or medium -- whether electronic, paper or in oral form (OCR, 2003). These data are a person's past, present or future physical or mental health or condition; his or her healthcare provision; and his or her past, present or future payment for healthcare. The data must identify the person and other identifiers, such as address, birthday, and social security number (OCR).
Un-protected Health Information
Health information not protected by HIPAA Privacy Rule pertains to employment records kept or used by a covered entity as an employer (OCR, 2003). These are records of an individual's employment information, education or other records coming under the Family Educational Rights and Privacy Act. Neither is de-identified health information covered, and therefore unprotected, by HIPAA. This refers to health information that neither identifies nor provides an identifier of the person with that record or data. De-identification can be made either by a formal determination by a qualified statistician or by the removal of specific identifiers of the individual and his family, relatives, household members and employers. In this second case, the de-identification can be done only if the covered entity has o actual knowledge that the remaining information may be used in identifying the person (OCR).
Uses and Disclosures
A covered entity may not use or disclose protected health information except as the Privacy Rules permits or requires or it is authorized in writing by the individual or his or her representative (OCR, 2003).
Permitted Uses and Disclosures
A disclosure is permitted, but not required, without the individual's authorization, under certain circumstances (OCR, 2003). These are if the disclosure is made to the individual himself or herself; if it is part of the treatment or as basis for payment and healthcare operations; as an opportunity for the patient to agree or object; incidental use and disclosure; for the public interest and benefit; and limited data set. Public interest is involved and justifies the use and disclosure when it is required by law; as part of public health activities; for the benefit of victims of abuse, neglect or domestic violence; for health oversight activities; as inputs to judicial and administrative proceedings; for law enforcement purposes; for the use of funeral parlors or medical examiners in the identification of deceased persons; for the facilitation of donation and transplant of cadaver organs; for research; for serious threats to health and safety; and for essential government functions (OCR).
Authorized Uses and Disclosures
This is allowed when there is written and specific authorization of the individual involved (OCR, 2003). It is also allowed from psychotherapy notes without the person's authorization if the notes will be used for treatment or for use in training and court litigations. Protected health information may also be disclosed without authorization for marketing purposes in exchange for direct or indirect compensation for product endorsement (OCR).
Limiting Uses and Disclosures
The first limiting provision is that of minimum necessary (OCR, 2003). A covered entity must expend all effort and resources to acquire and reveal only the barest minimum information in order to satisfy its allowed purpose. When done, the covered entity may no longer use or disclose the data for another purpose. The second provision covers the access and uses of an allowed disclosure of the protected health data. The covered entity must develop and use policies and procedures, which will restrict...
Our semester plans gives you unlimited, unrestricted access to our entire library of resources —writing tools, guides, example essays, tutorials, class notes, and more.
Get Started Now