SlideShare ist ein Scribd-Unternehmen logo
1 von 5
Health Information Privacy
Carrie Waggoner
Privacy Specialist
Connecting Michigan For Health, June 6, 2013
To identify what requirements must be
met to share information, ask:
• Who is sharing
• What
information
• With whom
• For what purpose
Important Privacy Issues:
• HIPAA & Other Compliance
Initiatives
• Mobile Devices
• Coordination with Security
Important Privacy Issues in the HIE
Context:
• Mental Health & Substance Abuse
• Public Trust & Buy-in

Weitere ähnliche Inhalte

Mehr von mihinpr

Panel Cyber Security and Privacy without Carrie Waggoner
Panel Cyber Security and Privacy without Carrie WaggonerPanel Cyber Security and Privacy without Carrie Waggoner
Panel Cyber Security and Privacy without Carrie Waggoner
mihinpr
 
MiHIN Brief Overview
MiHIN Brief OverviewMiHIN Brief Overview
MiHIN Brief Overview
mihinpr
 
Michigan HIE Model- Cynthia Edwards
Michigan HIE Model- Cynthia EdwardsMichigan HIE Model- Cynthia Edwards
Michigan HIE Model- Cynthia Edwards
mihinpr
 
MIHIN HIE Presentation UPHIE
MIHIN HIE Presentation UPHIEMIHIN HIE Presentation UPHIE
MIHIN HIE Presentation UPHIE
mihinpr
 
HIE Day- JCMR Overview June 2012
HIE Day- JCMR Overview June 2012HIE Day- JCMR Overview June 2012
HIE Day- JCMR Overview June 2012
mihinpr
 
GLHIE Presentation June 19 2012
GLHIE Presentation June 19 2012GLHIE Presentation June 19 2012
GLHIE Presentation June 19 2012
mihinpr
 

Mehr von mihinpr (20)

Connecting Patients, Providers and Payers John Halamka Keynote
Connecting Patients, Providers and Payers John Halamka KeynoteConnecting Patients, Providers and Payers John Halamka Keynote
Connecting Patients, Providers and Payers John Halamka Keynote
 
A Vision for Creating a Connected State Subra Sripada
A Vision for Creating a Connected State Subra SripadaA Vision for Creating a Connected State Subra Sripada
A Vision for Creating a Connected State Subra Sripada
 
Panel: Understanding Michigan's HIE Landscape
Panel: Understanding Michigan's HIE LandscapePanel: Understanding Michigan's HIE Landscape
Panel: Understanding Michigan's HIE Landscape
 
Panel Interstate and Other State HIE HIT
Panel Interstate and Other State HIE HITPanel Interstate and Other State HIE HIT
Panel Interstate and Other State HIE HIT
 
Panel: Transitions of Care and ADT (without Rachel Sherman)
Panel: Transitions of Care and ADT (without Rachel Sherman)Panel: Transitions of Care and ADT (without Rachel Sherman)
Panel: Transitions of Care and ADT (without Rachel Sherman)
 
State of Michigan HIE Update (without Tina Scott)
State of Michigan HIE Update (without Tina Scott)State of Michigan HIE Update (without Tina Scott)
State of Michigan HIE Update (without Tina Scott)
 
Health IT and Public Policy Issues Dr. Rich Hodge
Health IT and Public Policy Issues Dr. Rich HodgeHealth IT and Public Policy Issues Dr. Rich Hodge
Health IT and Public Policy Issues Dr. Rich Hodge
 
A Consistent Nationwide Data Matching Strategy Donna Roach & Nancy Walker
A Consistent Nationwide Data Matching Strategy Donna Roach & Nancy WalkerA Consistent Nationwide Data Matching Strategy Donna Roach & Nancy Walker
A Consistent Nationwide Data Matching Strategy Donna Roach & Nancy Walker
 
Jennifer Horowitz EHR Adoption in Michigan & Nationwide
Jennifer Horowitz EHR Adoption in Michigan & NationwideJennifer Horowitz EHR Adoption in Michigan & Nationwide
Jennifer Horowitz EHR Adoption in Michigan & Nationwide
 
Panel: Achieving Interoperability Dr. John Loonsk & Janet King
Panel: Achieving Interoperability Dr. John Loonsk & Janet KingPanel: Achieving Interoperability Dr. John Loonsk & Janet King
Panel: Achieving Interoperability Dr. John Loonsk & Janet King
 
Dr. Charles Friedman Transcending HIE
Dr. Charles Friedman Transcending HIEDr. Charles Friedman Transcending HIE
Dr. Charles Friedman Transcending HIE
 
Doug Dietzman National HIE Landscape
Doug Dietzman National HIE LandscapeDoug Dietzman National HIE Landscape
Doug Dietzman National HIE Landscape
 
Brian Balow HIPAA Final Rule
Brian Balow HIPAA Final RuleBrian Balow HIPAA Final Rule
Brian Balow HIPAA Final Rule
 
Panel Cyber Security and Privacy without Carrie Waggoner
Panel Cyber Security and Privacy without Carrie WaggonerPanel Cyber Security and Privacy without Carrie Waggoner
Panel Cyber Security and Privacy without Carrie Waggoner
 
Andrea walrath mu stage 2 and beyond
Andrea walrath mu stage 2 and beyondAndrea walrath mu stage 2 and beyond
Andrea walrath mu stage 2 and beyond
 
MiHIN Brief Overview
MiHIN Brief OverviewMiHIN Brief Overview
MiHIN Brief Overview
 
Michigan HIE Model- Cynthia Edwards
Michigan HIE Model- Cynthia EdwardsMichigan HIE Model- Cynthia Edwards
Michigan HIE Model- Cynthia Edwards
 
MIHIN HIE Presentation UPHIE
MIHIN HIE Presentation UPHIEMIHIN HIE Presentation UPHIE
MIHIN HIE Presentation UPHIE
 
HIE Day- JCMR Overview June 2012
HIE Day- JCMR Overview June 2012HIE Day- JCMR Overview June 2012
HIE Day- JCMR Overview June 2012
 
GLHIE Presentation June 19 2012
GLHIE Presentation June 19 2012GLHIE Presentation June 19 2012
GLHIE Presentation June 19 2012
 

Kürzlich hochgeladen

🌹Attapur⬅️ Vip Call Girls Hyderabad 📱9352852248 Book Well Trand Call Girls In...
🌹Attapur⬅️ Vip Call Girls Hyderabad 📱9352852248 Book Well Trand Call Girls In...🌹Attapur⬅️ Vip Call Girls Hyderabad 📱9352852248 Book Well Trand Call Girls In...
🌹Attapur⬅️ Vip Call Girls Hyderabad 📱9352852248 Book Well Trand Call Girls In...
Call Girls In Delhi Whatsup 9873940964 Enjoy Unlimited Pleasure
 
Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...
Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...
Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...
adilkhan87451
 
Call Girl in Indore 8827247818 {LowPrice} ❤️ (ahana) Indore Call Girls * UPA...
Call Girl in Indore 8827247818 {LowPrice} ❤️ (ahana) Indore Call Girls  * UPA...Call Girl in Indore 8827247818 {LowPrice} ❤️ (ahana) Indore Call Girls  * UPA...
Call Girl in Indore 8827247818 {LowPrice} ❤️ (ahana) Indore Call Girls * UPA...
mahaiklolahd
 

Kürzlich hochgeladen (20)

Top Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any Time
Top Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any TimeTop Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any Time
Top Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any Time
 
(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...
(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...
(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...
 
🌹Attapur⬅️ Vip Call Girls Hyderabad 📱9352852248 Book Well Trand Call Girls In...
🌹Attapur⬅️ Vip Call Girls Hyderabad 📱9352852248 Book Well Trand Call Girls In...🌹Attapur⬅️ Vip Call Girls Hyderabad 📱9352852248 Book Well Trand Call Girls In...
🌹Attapur⬅️ Vip Call Girls Hyderabad 📱9352852248 Book Well Trand Call Girls In...
 
Mumbai ] (Call Girls) in Mumbai 10k @ I'm VIP Independent Escorts Girls 98333...
Mumbai ] (Call Girls) in Mumbai 10k @ I'm VIP Independent Escorts Girls 98333...Mumbai ] (Call Girls) in Mumbai 10k @ I'm VIP Independent Escorts Girls 98333...
Mumbai ] (Call Girls) in Mumbai 10k @ I'm VIP Independent Escorts Girls 98333...
 
Pondicherry Call Girls Book Now 9630942363 Top Class Pondicherry Escort Servi...
Pondicherry Call Girls Book Now 9630942363 Top Class Pondicherry Escort Servi...Pondicherry Call Girls Book Now 9630942363 Top Class Pondicherry Escort Servi...
Pondicherry Call Girls Book Now 9630942363 Top Class Pondicherry Escort Servi...
 
Most Beautiful Call Girl in Bangalore Contact on Whatsapp
Most Beautiful Call Girl in Bangalore Contact on WhatsappMost Beautiful Call Girl in Bangalore Contact on Whatsapp
Most Beautiful Call Girl in Bangalore Contact on Whatsapp
 
Top Rated Hyderabad Call Girls Erragadda ⟟ 9332606886 ⟟ Call Me For Genuine ...
Top Rated  Hyderabad Call Girls Erragadda ⟟ 9332606886 ⟟ Call Me For Genuine ...Top Rated  Hyderabad Call Girls Erragadda ⟟ 9332606886 ⟟ Call Me For Genuine ...
Top Rated Hyderabad Call Girls Erragadda ⟟ 9332606886 ⟟ Call Me For Genuine ...
 
Top Rated Bangalore Call Girls Richmond Circle ⟟ 9332606886 ⟟ Call Me For Ge...
Top Rated Bangalore Call Girls Richmond Circle ⟟  9332606886 ⟟ Call Me For Ge...Top Rated Bangalore Call Girls Richmond Circle ⟟  9332606886 ⟟ Call Me For Ge...
Top Rated Bangalore Call Girls Richmond Circle ⟟ 9332606886 ⟟ Call Me For Ge...
 
The Most Attractive Hyderabad Call Girls Kothapet 𖠋 9332606886 𖠋 Will You Mis...
The Most Attractive Hyderabad Call Girls Kothapet 𖠋 9332606886 𖠋 Will You Mis...The Most Attractive Hyderabad Call Girls Kothapet 𖠋 9332606886 𖠋 Will You Mis...
The Most Attractive Hyderabad Call Girls Kothapet 𖠋 9332606886 𖠋 Will You Mis...
 
Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...
Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...
Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...
 
Top Rated Bangalore Call Girls Majestic ⟟ 9332606886 ⟟ Call Me For Genuine S...
Top Rated Bangalore Call Girls Majestic ⟟  9332606886 ⟟ Call Me For Genuine S...Top Rated Bangalore Call Girls Majestic ⟟  9332606886 ⟟ Call Me For Genuine S...
Top Rated Bangalore Call Girls Majestic ⟟ 9332606886 ⟟ Call Me For Genuine S...
 
Call Girls Visakhapatnam Just Call 8250077686 Top Class Call Girl Service Ava...
Call Girls Visakhapatnam Just Call 8250077686 Top Class Call Girl Service Ava...Call Girls Visakhapatnam Just Call 8250077686 Top Class Call Girl Service Ava...
Call Girls Visakhapatnam Just Call 8250077686 Top Class Call Girl Service Ava...
 
Call Girls Shimla Just Call 8617370543 Top Class Call Girl Service Available
Call Girls Shimla Just Call 8617370543 Top Class Call Girl Service AvailableCall Girls Shimla Just Call 8617370543 Top Class Call Girl Service Available
Call Girls Shimla Just Call 8617370543 Top Class Call Girl Service Available
 
💕SONAM KUMAR💕Premium Call Girls Jaipur ↘️9257276172 ↙️One Night Stand With Lo...
💕SONAM KUMAR💕Premium Call Girls Jaipur ↘️9257276172 ↙️One Night Stand With Lo...💕SONAM KUMAR💕Premium Call Girls Jaipur ↘️9257276172 ↙️One Night Stand With Lo...
💕SONAM KUMAR💕Premium Call Girls Jaipur ↘️9257276172 ↙️One Night Stand With Lo...
 
Call Girls Guntur Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Guntur  Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Guntur  Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Guntur Just Call 8250077686 Top Class Call Girl Service Available
 
Call Girls Kakinada Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Kakinada Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Kakinada Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Kakinada Just Call 9907093804 Top Class Call Girl Service Available
 
Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...
Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...
Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...
 
VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋
VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋
VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋
 
Call Girls Tirupati Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Tirupati Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Tirupati Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Tirupati Just Call 8250077686 Top Class Call Girl Service Available
 
Call Girl in Indore 8827247818 {LowPrice} ❤️ (ahana) Indore Call Girls * UPA...
Call Girl in Indore 8827247818 {LowPrice} ❤️ (ahana) Indore Call Girls  * UPA...Call Girl in Indore 8827247818 {LowPrice} ❤️ (ahana) Indore Call Girls  * UPA...
Call Girl in Indore 8827247818 {LowPrice} ❤️ (ahana) Indore Call Girls * UPA...
 

Carrie Waggoner Cyber Security Panel

Hinweis der Redaktion

  1. Introduction – My role as an attorney at MDCH is to advise staff on privacy issues across all of the Department’s programs, which include the Medicaid program, public health activities and programs, as well as behavioral health, substance abuse, and developmental disabilities programs. MDCH is one of the largest state government agencies, and is responsible for health policy and management of the state's publicly-funded health service systems.About 2 million Michigan residents will receive services this year that are provided with total or partial support from MDCH.MDCH has 2013 total funding of $15 billion and approximately 3,100 employees. Working on HIE issues is one small subset of the work I do for the Department.
  2. A quick disclaimer - I’m an attorney and DCH is my client. I advise DCH on how it might share information through its data hub to MiHIN and on other legal issues. But I can’t advise other individuals or organizations outside of DCH because they are not my clients. But I can share with you my perspective on privacy issues.
  3. Figuring out the relationship between entities that want to share data and the technical infrastructure supporting that data sharing can get really abstract and complicated. I try to simplify things with the following analysis:Asking “who” helps identify the obligations that entity might have. For example, under HIPAA, DCH is a hybrid covered entity. So HIPAA applies to some offices within DCH when sharing protected health information and HIPAA doesn’t apply to other offices within DCH when sharing information.Asking “what information” is the key question because that question leads us to what laws might protect the confidentiality of the information. And those laws also describe how that information might be shared and what authorization might be needed. Asking “with whom” allows us to discover whether we can share the information with that entity given the confidential protections. The information might be used internally and therefore there might be few if any limits how it might be shared. Under HIPAA, we know that info can be shared without patient authorization by a covered entity to another covered entity or a provider if the information is disclosed for treatment, payment, or health care operations. On the other hand, if the protected health information is disclosed to a business associate of a covered entity, then there are other legal obligations on the business associate for protecting the confidentiality of the information.Asking “for what purpose” allows me to determine whether the information can be shared consistent with any applicable confidentiality laws. For example, HIPAA has specific exceptions, like public health, research, and others, that allow for the disclosure of PHI.
  4. HIPAA & Other Compliance:As many of you probably know, the Office for Civil Rights has been ramping up its HIPAA enforcement and audit activities. It’s really important now to properly document your organization’s compliance so that you do not face millions of dollars in penalties from OCR. I was at a conference earlier this year, and one of the speakers from OCR discussed the results of recent HIPAA compliance audits. OCR audited a range of entities – from large hospitals to small providers. Only 11% of the 115 entities audited as of Dec 2012 had no findings. By compliance I mean the proper legal agreements in place, documenting business flows and processes, documenting policies and procedures regarding information privacy and security, and training of staff members. Given the culture of enforcement at OCR, it is extremely important to evaluate internally compliance with HIPAA on a periodic basis. By other compliance, I mean that it is also important to take similar steps to document policies, procedures, training, etc for other confidentiality laws that may apply to your practice or organization – for example, HIV/AIDS data, mental health, substance abuse, and so on.Mobile Devices:The increased use of mobile devices – laptops, smart phones, and even jump drives – allows us to have more flexibility in where and when we work, but it also increases the potential for an unauthorized use or disclosure of PHI or other confidential information. For example, OCR has published a list of the top five compliance issues over the last decade, and from 2004-2010 (last year published) the number one compliance issue was impermissible uses and disclosures. Mobile devices increase the risk of an unauthorized disclosure because they are out and about with us, and they can easily be lost or stolen, creating additional opportunities for unauthorized access to confidential information. Coordination with Security:To me, privacy and security are separate but interrelated concepts and functions. I agree with the errors that Dan identified, especially the one about basing security on systems rather than on the critical data. Privacy laws can help identify the critical data elements that have to be protected from use or disclosure in some way, and security, from a technological standpoint, can provide the solution to accomplish protecting the data (encryption, role-based access, authentication, etc.). Security solutions may go further than what HIPAA or other privacy laws require for compliance. The point is that privacy and security staff within an organization need to work together to accomplish protecting the privacy rights of individual’s information, as well as the security and integrity of the data itself.
  5. Mental Health & Substance Abuse:I participate in MiHIN’s privacy work group, and one of the issues we are working through is how mental health and substance abuse information, both of which have more stringent privacy protections than HIPAA, will be utilized through HIE technology. How is consent managed? Where are documents stored? Who is liable? This is also an issue for any information that is protected by laws that are more stringent than HIPAA.Public Trust & Buy-in:I heard another speaker at the conference I mentioned that I attended earlier this year who spoke about privacy as an “enabler” to the flow of information. What I think she meant by this is that if the public does not trust the HIE system, they might engage in “privacy-protective” behavior. For example, they might opt-out altogether or they might not allow all of their health information to be disclosed to a provider. This could have real consequences in terms of the quality of medical care – just like withholding information from a doctor about drug use or prescriptions can compromise that providers ability to treat you. Public education and knowledge about how the HIE functions, how their information might be shared, the privacy and security protections in place will help to build the public’s trust and minimize “privacy-protective” behavior.