{"id":2827,"date":"2020-04-13T11:06:43","date_gmt":"2020-04-13T11:06:43","guid":{"rendered":"https:\/\/www.empowerelearning.com\/blog\/?p=2827"},"modified":"2023-11-08T06:19:29","modified_gmt":"2023-11-08T06:19:29","slug":"how-to-share-phi-without-violating-hipaa-ocr-relaxes-phi-laws-for-business-associates","status":"publish","type":"post","link":"https:\/\/www.empowerelearning.com\/blog\/how-to-share-phi-without-violating-hipaa-ocr-relaxes-phi-laws-for-business-associates\/","title":{"rendered":"Guidelines for Distributing PHI Without Breaching HIPAA \u2013 OCR Eases PHI Regulations for Business Associates"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">Hipaa for Business associates too can help fight against COVID-19 \u2013 No penalties for sharing PHI.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">HHS Office of Civil Rights (OCR) has relaxed the HIPAA laws for business associates too; allowing the business associates of a covered entity to join the fight against the COVID-19 pandemic.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Currently, business associates are allowed to use and share PHI only as per the terms defined in their Business Associate Agreements with covered healthcare providers. As per the HIPAA Privacy rule, business associates can use or disclose PHI only to conduct work on behalf of the covered entity, or provide services to or for the covered entity, or as required by law.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><a href=\"https:\/\/www.hhs.gov\/sites\/default\/files\/notification-enforcement-discretion-hipaa.pdf\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">enforcement directive<\/span><\/a><span style=\"font-weight: 400;\"> issued on April 2<\/span><span style=\"font-weight: 400;\">nd<\/span><span style=\"font-weight: 400;\"> permits business associates to use and disclose patient information for public health and health oversight purposes to support COVID-19 response.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This could help support the ongoing efforts to reduce the loss of lives to the COVID-19 disease. Federal, state, and local health authorities and oversight agencies can now get quick access to COVID-19 related data held by business associates.\u00a0<\/span><\/p>\n<h3><b>Ensure quick access to COVID-19 patient data<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">The HIPAA privacy rule already allows covered healthcare providers to share the COVID-19 related health data with health authorities and oversight agencies. However, the participation of business associates was being constrained because of their business associate contract obligations under HIPAA.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Some business associates were unable to help in the COVID-19 efforts in a timely manner as their business associate contracts didn\u2019t explicitly permit them to do so.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">As per the OCR Director, <\/span><a href=\"https:\/\/www.hhs.gov\/about\/leadership\/roger-severino\/index.html\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">Roger Severino<\/span><\/a><span style=\"font-weight: 400;\">, this new enforcement directive would help the federal, state and local health departments to get quick access to COVID-19 patient data and would increase the cooperation and information exchange between public health and oversight agencies and HIPAA business associates.<\/span><\/p>\n<h3><b>Enforcement discretion\u00a0<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">The enforcement directive promises that the OCR will exercise enforcement discretion, effective immediately, and will not penalize business associates or their covered entities for the violation of HIPAA Privacy rule for the good faith use and disclosure of COVID-19 related data for public health and health oversight activities.\u00a0<\/span><\/p>\n<h3><b>Limitations of the enforcement discretion<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">The OCR enforcement discretion is subjected to the limitations listed below. Business associates must be careful of these parameters and conditions when using or sharing the PHI of a covered entity. All instances otherwise can still attract penalties.\u00a0<\/span><\/p>\n<h3><b>Business associates can make a good faith use or disclosure of the PHI ONLY IF<\/b><\/h3>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">The uses or disclosures are for <\/span><a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/privacy\/guidance\/disclosures-public-health-activities\/index.html\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">public health purposes<\/span><\/a><span style=\"font-weight: 400;\">, such as for preventing or controlling the spread of the COVID-19 disease, or\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">The uses or disclosures are for <\/span><span style=\"font-weight: 400;\">health oversight activities<\/span><span style=\"font-weight: 400;\">, such as for overseeing and assisting the healthcare system as it relates to COVID-19 response, and<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">The business associate informs the covered entity within 10 calendar days after the use of the disclosure. But if it\u2019s an ongoing activity, the covered entity must be informed within 10 days of starting the activity.<\/span><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\">When using and disclosing the PHI, business associates should be careful to follow the <\/span><a href=\"https:\/\/www.law.cornell.edu\/cfr\/text\/45\/164.512\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">45 Code of Federal regulations<\/span><\/a><span style=\"font-weight: 400;\">. Your activities have to be in compliance with the permitted uses and disclosure clauses of the federal regulations.\u00a0<\/span><\/p>\n<h3><b>HIPAA Requirements that still apply<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">The directive hasn\u2019t waived off the other business associate obligations under the HIPAA law. Other requirements of the privacy, security and breach notification rules still apply. Business associates are liable to comply with them.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If the business associate uses or shares electronic PHI, the disclosure must meet the Security rule requirements of the HIPAA law. The usage and disclosures should not violate the minimum necessary provisions of the Privacy rule. Similarly they must continue to comply with the HIPAA security rule requirements, including:\u00a0<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Ensure the electronic PHI is transmitted securely\u00a0\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Implement safeguard to ensure the confidentiality, integrity, and availability of the information<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Detect and shield against anticipated threats\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Protect against impermissible use or disclosure<\/span><\/li>\n<\/ol>\n[Also Read: <a href=\"https:\/\/www.empowerelearning.com\/blog\/the-three-rules-of-hipaa-the-basics-you-need-to-know\/\">Understanding HIPAA Privacy Rule-The Three Fundamental Rules to Keep in Mind<\/a>]\n<h3><b>HIPAA waivers for Covered entities<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Considering the severity of the COVID-19 pandemic; the HHS OCR has released <\/span><a href=\"https:\/\/www.empowerelearning.com\/blog\/expert-hipaa-advice-to-empower-you-against-the-coronavirus\/\"><span style=\"font-weight: 400;\">guidance material for covered entities<\/span><\/a><span style=\"font-weight: 400;\"> to explain how healthcare providers can share patient health information. The HHS guidance covers:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Disclosure of PHI to first responders, such as law enforcement, and paramedics<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Sharing PHI with public health authorities, such as CDC and CMS<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Sharing of information with the family, friends, and relatives of COVID-19 patients<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Usage of Telehealth communication tools for connecting with patients and treating ailments<\/span><\/li>\n<\/ul>\n<h3><b>In conclusion<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">The OCR directive would definitely increase the flexibility to the COVID-19 response efforts. Even so, the notification does extend the enforcement discretion to other HIPAA Privacy rule requirements or the business associate obligations under the Security rule. Likewise, the directive has not addressed other applicable federal or state laws. Businesses should exercise caution when using or disclosing PHI of a covered entity.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Are you a HIPAA business associate? What are your views regarding the HHS notification? We\u2019d love to know. Please share your views with our readers in the comments\u2019 section below.\u00a0\u00a0\u00a0<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hipaa for Business associates too can help fight against COVID-19 \u2013 No penalties for sharing PHI. HHS Office of Civil Rights (OCR) has relaxed the HIPAA laws for business associates too; allowing the business associates of a covered entity to join the fight against the COVID-19 pandemic.\u00a0 Currently, business associates are allowed to use and [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":2828,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,138,140,9],"tags":[268,46,28],"class_list":["post-2827","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education","category-elearning","category-empower","category-hipaa","tag-covid-19","tag-empower","tag-hipaa-compliance-training"],"_links":{"self":[{"href":"https:\/\/www.empowerelearning.com\/blog\/wp-json\/wp\/v2\/posts\/2827","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.empowerelearning.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.empowerelearning.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.empowerelearning.com\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.empowerelearning.com\/blog\/wp-json\/wp\/v2\/comments?post=2827"}],"version-history":[{"count":0,"href":"https:\/\/www.empowerelearning.com\/blog\/wp-json\/wp\/v2\/posts\/2827\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.empowerelearning.com\/blog\/wp-json\/wp\/v2\/media\/2828"}],"wp:attachment":[{"href":"https:\/\/www.empowerelearning.com\/blog\/wp-json\/wp\/v2\/media?parent=2827"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.empowerelearning.com\/blog\/wp-json\/wp\/v2\/categories?post=2827"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.empowerelearning.com\/blog\/wp-json\/wp\/v2\/tags?post=2827"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}