Healthcare IT NewsHealthcare IT News
TwitterFacebookLinkedInHealthcareITNews International
  • Home
  • Topics
    • ARRA/Stimulus
    • Business Intelligence
    • Claims Processing
    • Data Warehousing
    • EDIS
    • Election 2012
    • Electronic Health Records
    • Enterprise Content Management
    • Enterprise Resource Planning
    • ePrescribing
    • Financial/Revenue Cycle Management
    • Health Information Exchange (HIE)
    • ICD-10
    • Mobile/Wireless
    • Network Infrastructure
    • Policy and Legislation
    • Privacy and Security
    • Quality and Safety
    • RIS and PACS
    • RTLS
    • Telehealth
    • Workforce Management
  • Issues
    • January 2012
    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • August 2011
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Blog
  • Events
  • HIMSS JobMine
  • RSS
  • Press Releases
  • Slideshows
  • Videos
  • Podcasts
  • Supplements
  • Survey Analyses
  • Newsletters
  • Advertise
  • Login
  • Register
  • SUBSCRIBE
    • Newspaper
    • Email Newsletter
Home » News » Health Information Exchange (HIE) | Privacy and Security
Receive News By Email

  • del.icio.us
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • Google
  • RSS Icon
  

Tiger team clarifies patient consent rules for HIEs

August 18, 2010 | Mary Mosquera, Contributing Editor

Suggested Content

  • Veterans Affairs CIO Roger Baker on VLER progress
  • Docs tell government panel EHR tales of woe
  • Federal panel wrangles over timing for MU Stage 2
  • Government tiger team calls for privacy notices patients can understand
  • VA launches fourth data exchange pilot on NHIN
  • Health IT policy panel approves HIE consent rules
  • Federal panel endorses patient safety database
  • CMS' Tavenner spotlights innovation
  • States put tech to work on Medicaid enrollment
  • 2011 MU incentives paid: $2.5B

Related Resources

  • Optimizing Quality Management with Your EHR: Getting Paid More for What You Do Best
  • February 10th @ 1PM ET--Solving Urgent Enterprise-wide Integration Challenges while Focusing on the Future
  • Where Information and Care Meet: Secure Mobile Healthcare Solutions that Drive Care Coordination
  • Protect your Patient Data: Learn How to Avoid Costly Privacy & Security Breaches within your Organization
  • Technical Approaches to Securely Transporting Content for the Enterprise

WASHINGTON – Health information exchanges cannot share sensitive patient information beyond a simple point-to-point exchange without first obtaining a patient's consent, concluded the federal privacy and security tiger team.

The panel, which advises the Health Policy Committee, clarified the matter at an Aug. 16 meeting. Its previous guidance on the privacy obligations of health information exchanges (HIEs) had been unclear, according to panel members.

More specific language was required because some HIEs provide both multipoint exchange services among a provider community but also handle direct point-to-point exchange services.

These simpler exchanges do not require patient consent beyond what is covered in existing law, such as the Health Insurance Portability and Accountability Act (HIPAA), state laws, and fair information practices.

However, the panel said HIEs must obtain a patient's consent if they make personal health information collected during a direct exchange available to a third party.

"Providers have to offer the option to the patient whether or not they're going to participate in health information organizations," said Paul Egerman, a software entrepreneur and co-chair of the tiger team.

The tiger team published a 19-page letter with this and several other draft recommendations around privacy and security in simple exchanges and will present it to the Health IT Policy Committee Aug. 19.

Some patients may not want their provider to use a HIE to share their information if the HIE retains some control over their data in a simple exchange, the panelists said.

In such cases a provider can use a different organization to conduct the exchange. Or, it can use the same HIE, "as long as the provider maintains the control over the decision to exchange," according to the panel's draft recommendations.

Panel member Wes Rishel, a vice president with Gartner's healthcare practice, offered a case in point.

In the scenario, a physician orders and receives lab results through an HIE, which captures the results and begins to build a database with it. "If the patient does not consent to using the HIE, the physician has to go through a dual track," said Rishel.

The provider still needs to use the HIE services to obtain the lab results. But if the HIE performs both community and point-to-point exchange services, "it is precluded from using information under directed exchange without consent," he said.

The policy committee will offer its final recommendations to the Office of the National Coordinator in time for healthcare providers to meet upcoming deadlines for meaningful use.

As the tiger team winds down its work, some of its privacy and security work will also feed into a new policy committee work group being set up on NHIN governance, according to Joy Pritts, ONC chief privacy officer.

In creating the new panel, ONC wants to host discussions on what to include in a formal rulemaking that would establish rules of the road - including principles on consent and privacy - for organizations that participate in the nationwide health information network.

Related Topics:
  • Gartner
  • Mary Mosquera
  • Paul Egerman
  • Washington
  • Wes Rishel
  • Health Information Exchange (HIE)
  • Privacy and Security

Reader Comments (0)Login to Post a Comment

Most Popular

Latest Headlines
Most Popular
  • Analytics and the future of healthcare
  • CNIO position on the rise
  • Health data breaches up 97 percent in 2011
  • Docs use iPads, but don't see them as game-changers
  • Greenway set for IPO
  • HIT figures prominently in GOP primary battle for Nevada
  • Mostashari expects big year ahead for data exchange
  • AMA, AHIMA at odds on ICD-10
  • Minnesota: A healthy appreciation for HIT
  • 5 issues affecting cloud service quality and performance

WEBINARS AND WHITE PAPERS

  • WHITE PAPERS
    The Christ Hospital Case Study: Improving Operations and Ensuring the Best Possible Patient Care with ECM
  • WHITE PAPERS
    Business Intelligence for Hospitals: Empowering Healthcare Providers to Make Informed Decisions
  • ON DEMAND WEBINARS
    Case Study: Sentara Healthcare Completes an Award-Winning EHR with Enterprise Content Management
  • WHITE PAPERS
    Mobility Advantage: Health Care Made Easier
  • WHITE PAPERS
    Winning the EHR Battle with Enterprise Content Management
More Resources
Syndicate content

HIMSS JOBMINE

  • Program Analyst - Mathematica Policy Research - Princeton, NJ
  • Oracle Implementation Analyst - Virginia Mason Medical Center - Seattle, WA
  • Web and Custom Development Manager - Virginia Mason Medical Center - Seattle, Washington
  • Epic Analyst/Builder - Vitalize Consulting Solutions - Nationwide
  • Vice President - Tower Strategies - Remote
more jobs

Marketplace

Follow Healthcare IT News on TwitterFan Healthcare IT News on FacebookJoin Healthcare IT News on LinkedInRSS Subscriptions
Digital EditionBlogEvents
JobsMobile SiteMobile App
 
Healthcare Finance News Government Health IT EHRWatch Healthcare Payer News HITECHWatch ICD10Watch mHIMSS PhysBizTech NHINWatch
©2012 MedTech Media Healthcare IT News is a publication of MedTech Media
Subscribe Advertise About Us Privacy Policy