Qual-IT - July-August 2006
Privacy and Security Issues Move to the Forefront
Preserving the confidentiality of sensitive personal health information is of paramount concern to both the public and the health care system. Federal and state laws, as well as countless policies and procedures within health care organizations, currently address a number of crucial, related questions:
- Who has access to personal health information, and under what circumstances?
- How can consumers review the information on them to ensure that it is complete and correct?
- What remedies and sanctions exist for violation of privacy protections?
Federal laws—particularly the privacy provisions of the Health Insurance Portability and Accountability Act (HIPAA)—cover important aspects of health information privacy and security relating to electronic claims transactions. HIPAA also allows states to enact additional protections, so health care organizations face different requirements depending on their location.
As electronic health information systems proliferate, data-sharing across different health care settings is increasingly being promoted, to better inform clinicians and consumers, advance quality measurement and improvement, improve public health, and facilitate clinical research. Identifying key issues, developing and forging consensus on solutions, and educating health professionals, the public, and the health care industry on policies and procedures needed to safeguard the appropriate uses of electronic health information are thus becoming ever more critical. This issue of Qual-IT describes recent policy developments on health information privacy and security at the national and state levels.
In this issue
Federal Developments
"Informational privacy is a core value of American society," the Committee stated, noting that people expect their personal health information to be handled securely. Today's fragmented, paper-based health care system makes it difficult to access this information, which may protect privacy but also hinders the application of that information to improve health care. Health information technology and health information exchange can surmount these gaps, the report notes, but public support for a national network depends on trust that personal health information is protected––even though, as its availability and utility increase, "so does the risk to privacy and confidentiality."
While recognizing that the specific architecture for the Network has yet to be determined, the Committee addressed some of the key policy issues that will affect relationships between individuals and these new information systems. It could not agree on many of the essential details, however. Although, for example, the Committee supports individuals' right to decide whether their information will be accessible through the Network, members could not reach consensus on whether that decision would be exercised by opting in––each person providing an explicit affirmation that his or her information can be part of the system––or opting out, requiring an explicit request to withhold information. The Committee also couldn't agree on whether individuals should be able to control access to specific types of information made available through the Network. Whatever choices people make, public information and education is essential to ensure that decisions are truly informed.
The Committee's report further addresses controls on the disclosure of personal health information, suggesting that access be "role-based," or limited to those with specific authorization, consistent with regulations and policies that have already proved feasible in large organizations with advanced HIT systems. In other areas, the report recommends:
- Expanding existing rules covering organizations involved in claims processing to protect health information exchange among other types of organizations in the Nationwide Health Information Network;
- Bolstering public support by requiring all organizations participating in the Network to comply strictly with rules governing privacy, confidentiality, and security, and ensuring strong enforcement efforts in that regard;
- Making the process for designing and implementing the Network, and its privacy and confidentiality policies, open and transparent, and including meaningful consumer representation at the national, regional, and local levels.
...and Congressional Considerations
Consumer-Based Principles Guide State Strategy
- Individuals should be able to access their personal health information conveniently and affordably;
- Individuals should know how their personal health information may be used and who has access to it;
- Individuals should have control over whether and how their personal health information is shared;
- Electronic health information systems must protect the integrity, security, privacy, and confidentiality of personal health information;
- The governance and administration of electronic health information networks should be transparent and publicly accountable.
New York Participates in National Study
The Department of Health has already convened steering and legal committees to provide direction and input throughout the study. Initially, a series of ad hoc work groups––drawn from health care interests across the state––will analyze a variety of scenarios prescribed by RTI. The work groups will elicit a wide range of stakeholder views regarding potential and actual barriers to health information exchange, based on current state laws and on health care operational practices common in New York. Health care leaders from across the state will review the issues identified through this process, and attempt to develop consensus on solutions and implementation strategies to accelerate HIT adoption and use while safeguarding individuals' right to privacy.
Resources
Ferris N. 2006. NHIN forum reveals many unanswered questions. Government Health IT June 30. Available online at http://www.govhealthit.com/article95108-06-30-06-Web
Health Care for All. Information on the eHealth Summit and other policy-related materials is available online at http://www.hcfama.org/index.cfm?fuseaction=Page.viewPage&pageId=555
National Committee on Vital and Health Statistics. 2006. Privacy and confidentiality in the National Health Information Network. Letter to the Secretary, Department of Health and Human Services, June 22. Available online at http://www.ncvhs.hhs.gov/060622lt.htm
National Partnership for Women and Families. 2006. Health Information Technology––Consumer Principles. Available online at http://www.nationalpartnership.org/portals/p3/library/HealthCareQualityPatientsRights/HIT.pdf
RTI International. 2006. Health information security and privacy collaboration request for proposals. Available online at http://www.rti.org/hispc
