Top Banner
HIPAA Issues @ Bellevue
18

HIPAA Issues @ Bellevue 1997 Bellevue Orthopaedic Registry Established on hospital network to enable: 1) Access 2) Security 3) Backup 4) Support 5)

Jan 12, 2016

Download

Documents

Adela Morrison
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: HIPAA Issues @ Bellevue 1997 Bellevue Orthopaedic Registry Established on hospital network to enable: 1) Access 2) Security 3) Backup 4) Support 5)

HIPAA Issues @ Bellevue

Page 2: HIPAA Issues @ Bellevue 1997 Bellevue Orthopaedic Registry Established on hospital network to enable: 1) Access 2) Security 3) Backup 4) Support 5)
Page 3: HIPAA Issues @ Bellevue 1997 Bellevue Orthopaedic Registry Established on hospital network to enable: 1) Access 2) Security 3) Backup 4) Support 5)

1997 Bellevue Orthopaedic Registry

Established on hospital network to enable:

1) Access2) Security3) Backup4) Support5) HIS Integration6) Input load sharing

Page 4: HIPAA Issues @ Bellevue 1997 Bellevue Orthopaedic Registry Established on hospital network to enable: 1) Access 2) Security 3) Backup 4) Support 5)

1997Bellevue Orthopaedic Registry

Point & click, direct physician data entry to:1) improve data specificity & consistency for research 2) codify data for practice management & certification3) provide “just-in-time” alerts and CME

Page 5: HIPAA Issues @ Bellevue 1997 Bellevue Orthopaedic Registry Established on hospital network to enable: 1) Access 2) Security 3) Backup 4) Support 5)

3/27/2007 HIPAA Calls

Concerns about security

No computer system is secure.

Page 6: HIPAA Issues @ Bellevue 1997 Bellevue Orthopaedic Registry Established on hospital network to enable: 1) Access 2) Security 3) Backup 4) Support 5)

Business Associate Agreement (BAA)

Bellevue HIPAA requires a BAA

until then

DATABASE ACCESS DENIED

Page 7: HIPAA Issues @ Bellevue 1997 Bellevue Orthopaedic Registry Established on hospital network to enable: 1) Access 2) Security 3) Backup 4) Support 5)

Business Associate AgreementIndemnification Clause

”The Business Associate must agree to indemnify, defend, and hold harmless Bellevue Hospital and all of its … workforce against all losses suffered and all liability to third parties arising from or in connection with any material breach of this Agreement by the Business Associate.”

Liability insurance - unaffordable

DATABASE ACCESS DENIED

Business Associate AgreementIndemnification Claws

Page 8: HIPAA Issues @ Bellevue 1997 Bellevue Orthopaedic Registry Established on hospital network to enable: 1) Access 2) Security 3) Backup 4) Support 5)

6/1/2007 - Bellevue Ortho Dept “We’ve got you covered.”

“I used to be a doctor,

then I was a provider,

now, I'm a

COVERED ENTITY”

William De Alva, M.D. Tucson, AZ

Page 9: HIPAA Issues @ Bellevue 1997 Bellevue Orthopaedic Registry Established on hospital network to enable: 1) Access 2) Security 3) Backup 4) Support 5)

What’ll HIPAA Do?Move Goalposts - Play for Time

Research DataBase Clearances Required:

1) NYC HHC Legal 2) NYC HHC Research3) NYU SOM IRB4) MSSM IRB

until then

DATABASE ACCESS DENIED

Page 10: HIPAA Issues @ Bellevue 1997 Bellevue Orthopaedic Registry Established on hospital network to enable: 1) Access 2) Security 3) Backup 4) Support 5)

One Year Later

• I am a covered entity within a covered entity.• Database has HHC Legal Office Review• Database has NYU IRB Clearance• Database has NYC HHC Research Office

Clearance• Database has DHHS OHRP Clearance

ADMINISTRATIVE DATABASE ACCESS DENIED

Page 11: HIPAA Issues @ Bellevue 1997 Bellevue Orthopaedic Registry Established on hospital network to enable: 1) Access 2) Security 3) Backup 4) Support 5)

HIPAA Says:You may have a Virus

Administrative Access Denied

It’s OK if you sign a BAA

Liability Insurance - unaffordable

“You don’t have the funds to be on the playing field.”

DATABASE ACCESS DENIED

Page 12: HIPAA Issues @ Bellevue 1997 Bellevue Orthopaedic Registry Established on hospital network to enable: 1) Access 2) Security 3) Backup 4) Support 5)
Page 13: HIPAA Issues @ Bellevue 1997 Bellevue Orthopaedic Registry Established on hospital network to enable: 1) Access 2) Security 3) Backup 4) Support 5)

Senator Edward M. Kennedy HIPAA Sponsor

“In this electronic era it is essential to safeguard the privacy of medical records while insuring our privacy laws do not stifle the flow of information fundamental to effective health care.”

New York Times 7/3/2007

Page 14: HIPAA Issues @ Bellevue 1997 Bellevue Orthopaedic Registry Established on hospital network to enable: 1) Access 2) Security 3) Backup 4) Support 5)

The Bottom Line

HIPAA appears to be much more concerned about the protection of itself - rather than patient privacy and access to evidence-based medical care.

Page 15: HIPAA Issues @ Bellevue 1997 Bellevue Orthopaedic Registry Established on hospital network to enable: 1) Access 2) Security 3) Backup 4) Support 5)

Eugene H. Spafford

“Data is not necessarily information.

Information does not necessarily lead to knowledge.

And knowledge is not always sufficient to discover truth and breed wisdom.”

Page 16: HIPAA Issues @ Bellevue 1997 Bellevue Orthopaedic Registry Established on hospital network to enable: 1) Access 2) Security 3) Backup 4) Support 5)

NYU SoM IRB Findings 12/19/2007

• The Bellevue orthopaedic database is not research involving human subjects.

• The information does not require IRB review for human subjects research purposes or HIPAA purposes.

• The NYU SoM IRB does not consider Clinical Databases to be research data repositories.

Page 17: HIPAA Issues @ Bellevue 1997 Bellevue Orthopaedic Registry Established on hospital network to enable: 1) Access 2) Security 3) Backup 4) Support 5)

NYC HHC Research Findings1/16/2008

• The NYU SoM IRB statement is accepted from an HHC Research Approval standpoint

• The OHRP DHHS regulations do not apply to the existing Bellevue Orthopaedic Department database

Page 18: HIPAA Issues @ Bellevue 1997 Bellevue Orthopaedic Registry Established on hospital network to enable: 1) Access 2) Security 3) Backup 4) Support 5)