Before You Listen
Episode Setup
- Topic in one line: the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule (protected health information (PHI), the minimum necessary standard, the 18 safe harbor identifiers for de-identification, permitted disclosures for treatment, payment, and healthcare operations); the four pillars of bioethics (autonomy, beneficence, non-maleficence, justice); the Belmont Report and the Institutional Review Board (IRB); quality improvement methodology (the Plan-Do-Study-Act (PDSA) cycle, structure/process/outcome measures, levels of evidence, the Appraisal of Guidelines for Research and Evaluation (AGREE II) instrument); patient safety concepts (sentinel event, never event, near miss, root cause analysis (RCA), failure mode and effects analysis (FMEA), the just culture model, the Reason Swiss cheese model); the four elements of medical malpractice (duty, breach, causation, damages); risk management (documentation, communication, error disclosure); and the Merit-based Incentive Payment System (MIPS) under the Medicare Access and CHIP Reauthorization Act (MACRA).
- Prerequisites: familiarity with the basic structure of the United States healthcare system, the federal payer landscape (Medicare, Medicaid), and the rehabilitation team and quality reporting framework introduced in ADMIN-01 (IRF-PAI, IRF Quality Reporting Program).
- Runtime: 53 minutes.
Vignette. A nurse on your inpatient rehabilitation unit administers a 10-fold overdose of morphine to a patient because the order was written as “1.0 mg” with a trailing zero and was read as 10 mg, the pharmacy dispensed a 10 mg vial when the intended dose was 1 mg, the bedside scanner had been disabled because of repeated false alarms, and the night shift was staffed at a 1:8 nurse-to-patient ratio (the protocol calls for 1:5). The patient develops respiratory depression requiring naloxone but recovers fully with no permanent harm. The unit medical director is asked to lead the post-event analysis.
Classify this event using the standard patient safety taxonomy, identify which structured analytic method should be used and what its central question is, identify which conceptual model best explains how the harm reached the patient, classify the nurse’s behavior under the just culture framework and state the appropriate organizational response, and identify which of the four malpractice elements would be the strongest defense if the patient sued.
(Answer at the end of this chapter)
Section 1: HIPAA, PHI, and Permitted Disclosures
Bottom line: HIPAA (1996), Privacy Rule (2003) established national standards for protected health information (PHI). PHI = any individually identifiable health information in any form. Covered entities are health plans, clearinghouses, and providers conducting electronic transactions. The minimum necessary standard does NOT apply to treatment between providers, disclosures to the patient, or disclosures required by law. Permitted disclosures without authorization include Treatment, Payment, and Healthcare Operations (TPO), plus public health, law enforcement, judicial/administrative proceedings, workers’ comp, public safety threats, and abuse/neglect reporting. Safe harbor de-identification requires removal of 18 identifier categories plus no actual knowledge of remaining identifiability; de-identified information is no longer PHI. The Security Rule covers electronic PHI only and requires administrative, physical, and technical safeguards. Breach notification: individuals within 60 calendar days; media when more than 500 residents of a state are affected; the Secretary contemporaneously at 500 or more individuals, otherwise annually within 60 days after year end.
The Health Insurance Portability and Accountability Act (HIPAA), enacted in 1996, established national standards for the protection of individually identifiable health information. The Privacy Rule (general compliance date 2003) governs the use and disclosure of protected health information (PHI) by covered entities: health plans, healthcare clearinghouses, and healthcare providers conducting certain electronic transactions.
PHI is individually identifiable information about health, care, or payment held or transmitted by a HIPAA-covered entity or its business associate, in oral, written, or electronic form. HIPAA excludes certain records, including employment records held in an employer capacity and FERPA-covered education records; not every holder of health data is HIPAA-covered.
The minimum necessary standard requires reasonable efforts to limit PHI use, disclosure, and requests to the intended purpose. Common exceptions are provider treatment disclosures/requests, disclosures to the individual, and disclosures required by law. Other exceptions include patient-authorized disclosures, disclosures to HHS for enforcement, and uses/disclosures required for HIPAA administrative simplification compliance.
Permitted disclosures without patient authorization fall into several board-tested categories. The primary category is Treatment, Payment, and Healthcare Operations (TPO):
- Treatment: ordinary clinical records are shared among treating providers without separate authorization. Separately maintained psychotherapy notes require authorization even for another treating clinician; other special protections apply.
- Payment: information for billing, claims processing, insurance functions.
- Healthcare operations: quality improvement, training, compliance, business management.
Additional permitted disclosures without authorization:
- Public health activities: reporting communicable diseases, vital statistics, public health surveillance.
- Law enforcement under specific conditions.
- Judicial and administrative proceedings: a court order permits the specified disclosure. A subpoena without a court order requires applicable safeguards, such as satisfactory notice to the individual or a qualified protective order; route it through the proper legal process.
- Workers’ compensation to the extent required by state law.
- Public safety: serious and imminent threat to health or safety.
- Abuse, neglect, or domestic violence reporting.
De-identification removes information from the protections of the Privacy Rule. Two methods exist:
The safe harbor method requires removal of 18 identifier categories plus no actual knowledge that remaining information can identify the person. Remove date elements other than year at every age; also remove ages over 89 and date elements indicating those ages, allowing an aggregate 90 or older category. The first three ZIP digits may remain only if their combined geographic area contains more than 20,000 people; otherwise use 000. The expert determination method documents a very small identification risk using accepted statistical and scientific methods.
A physician releasing records for treatment by another provider does not require authorization. An employer request for non-workers’-comp purposes does require authorization. Law enforcement requests depend on the specific legal circumstances.
The Security Rule (45 CFR part 164 subpart C) is the Privacy Rule’s companion and applies only to electronic protected health information (ePHI). It requires three categories of safeguards: administrative (45 CFR 164.308: risk analysis, workforce training, sanctions, contingency planning), physical (164.310: facility access, workstation and device controls, media disposal), and technical (164.312: access control, audit controls, integrity, transmission security). A stolen unencrypted laptop triggers Privacy, Security, and breach-notification obligations; the electronic medium does not exclude the Privacy Rule.
Breach notification (45 CFR part 164 subpart D, added by the 2009 HITECH Act and amended by the 2013 omnibus rule) applies to breaches of unsecured PHI, subject to defined exceptions and the documented low-probability-of-compromise risk assessment. The two population thresholds are worded differently:
- Affected individuals must be notified without unreasonable delay and no later than 60 calendar days after discovery of the breach (45 CFR 164.404(b)).
- Prominent media outlets serving the area must also be notified when a breach involves more than 500 residents of a state or jurisdiction, on the same 60-calendar-day clock (45 CFR 164.406).
- The Secretary of Health and Human Services is notified contemporaneously with the individual notice when the breach involves 500 or more individuals; breaches involving fewer than 500 are logged and reported not later than 60 days after the end of the calendar year in which they were discovered (45 CFR 164.408(b) and (c)).
Read those two numbers carefully: the media trigger is more than 500 residents of one state, while the Secretary trigger is 500 or more individuals in total. A breach of exactly 500 individuals in a single state requires HHS notice without unreasonable delay, no later than 60 days after discovery, but does not trigger media notice.
High Yield — HIPAA
- HIPAA (1996), Privacy Rule (2003); covered entities = health plans, clearinghouses, providers conducting electronic transactions.
- PHI = individually identifiable health information in any form (oral, written, electronic).
- Minimum necessary standard does NOT apply to treatment between providers, to the patient, or as required by law.
- TPO disclosures (Treatment, Payment, Healthcare Operations) do not require authorization.
- Other permitted disclosures: public health, law enforcement (specific conditions), judicial/administrative, workers’ comp, public safety threats, abuse/neglect/IPV.
- Safe harbor de-identification requires removal of 18 identifier categories plus no actual knowledge of remaining identifiability.
- De-identified information is no longer PHI.
- Security Rule = ePHI only; administrative, physical, and technical safeguards.
- Breach notification: individuals within 60 calendar days; media when more than 500 residents of a state; HHS without unreasonable delay, within 60 days, at 500 or more individuals, otherwise annually within 60 days after year end.
Mnemonic — “TPO first, then check other permissions”
Treatment, Payment, and Healthcare Operations are permitted without signed authorization, subject to applicable limits and special protections. If a request falls outside TPO, check the other legal permissions before deciding authorization is needed. Routine employer verification, marketing, and life-insurance requests need authorization when no exception applies. Patient agreement can also permit relevant sharing with family involved in care; being a relative alone does not entitle someone to the full record.