Qual-IT - January 2007
Growing Focus on Privacy and Security Policies
The privacy and confidentiality of personal health information are currently addressed through a complex legal construct, at both federal and state levels, that has evolved over many years and has been interpreted and applied in numerous ways. Despite the complexity and variety of this regulatory framework, it does not yet address many of the issues facing a health care system in which newer electronic health information technologies (HIT) are increasingly being used. With today's focus on facilitating ready access to health information by consumers, providers, health plans, and other stakeholders, an industry based on health information exchange (HIE) is rapidly emerging to meet these demands.New policies and procedures are needed to adapt to these requirements, and to ensure flexibility as the field evolves. This issue of Qual-IT offers a first look at a new initiative working to address key policy challenges in providing access to—while protecting the privacy and security of—electronic forms of personal health information.
The Health Information Security and Privacy Collaboration
The benefits of HIT and HIE will only be obtained if the systems based on them are accountable, trusted, and efficient, particularly from the perspective of consumers and providers. The current laws and business practices affecting health information privacy and security are inadequate for meeting that challenge. To be successful, HIT strategies will need to utilize a common set of principles, policies, and practices governing access to and use of sensitive personal health information. Developing such solutions and a coordinated implementation plan, in order to accelerate HIT and HIE efforts across the state, is the focus of
A federally funded initiative designed to address these issues, HISPC is working to document state legal and policy environments, as well as business practices common in health care today.
For
Ends and Means
On
· Consumers should be able to easily access their own health information;
· Treating providers should have access to complete and accurate information for their patients;
· Multiple stakeholders should have access to aggregated, anonymous forms of health information for research and quality improvement purposes; and
· Providers and public health officials should report and access information necessary for key public health functions.
Accomplishing these goals, the report notes, will require specific measures to:
· Educate patients about, and engage them in, the various methods of accessing information;
· Secure patients’ informed consent;
· Establish safeguards governing the security, access to, and use of electronic patient health information; and
· Create a reliable and secure method of identifying and linking patients’ information.
The HISPC interim report also outlines an implementation framework for taking these steps. First, it says, a “leadership entity” needs to forge consensus on specific policies and methods for achieving these goals and objectives. The
(Officially launched this past November at the New York Summit on eHealth, co-sponsored by the
The report also calls for a system of accreditation and certification for the entities—commonly referred to as regional health information organizations, or RHIOs—involved in HIE. While certification would not be immediately mandatory, it would be a condition for receipt of state funds and for participation in HIE involving Medicaid data. It is likely that any future activities designed to link disparate HIE efforts would also require participating organizations to obtain this certification.
Finally, the report calls for the state to clarify existing laws and regulations, and to adopt new laws as needed. While the report has not yet been made available online, further information on it can be obtained from New York HISPC Project Manager Ellen Flink, at emf02@health.state.ny.us.
The HISPC process will now focus on development of a detailed and coordinated implementation plan, to be completed by April 2007. The Fund looks forward to playing an active role in this process through its continuing participation in NYeC.
Resources
Information about HHS privacy and security activities can be accessed through http://www.hhs.gov/healthit/privacy/
Information about
