As a matter of good practice, every Pregnancy Help Organization (PHO) should have a policy on confidentiality.
Federal Law
United States federal law has established national standards for protecting certain health information through the Health Insurance Portability and Accountability Act of 1996 (HIPAA). HIPAA grants patients certain rights, including the ability to file complaints with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). See 45 CFR 160.306.
Certain entities are required to comply with HIPAA. Federal law outlines three categories of entities that the law applies to:
- A health plan;
- A health care clearing house; and
- A health care provider who transmits any health information in electronic form in connection with a transaction as defined by this law.
HIPAA also applies to business associates. See 45 CFR 160.103.
A health plan is an individual or group that provides or pays the cost of medical care. Health plans include a group health plan, health insurance issuer, and/or a health maintenance organization (HMO). See 45 CFR 160.103.
A health care clearing house is a public or private entity, that either processes or facilitates the processing of nonstandard health information into standard, or vice versa. Examples of health care clearing houses include a repricing company, community health management information system or community health information system, and “value-added” networks and switches. See 45 CFR 160.103.
A health care provider is a provider or organization who provides medical or health services when they furnish, bill, or are paid for health care in the normal course of business. This includes both doctors and clinics. See 45 CFR 160.103.
However, health care providers are only considered to be covered entities when they transmit health information in connection with a transaction as defined by this law. While the term “transaction” has many meanings, under this law, a transaction is defined as the transmission of information between two parties to carry out financial or administrative activities related to healthcare. Examples include health care claim information, health care payments, coordination of benefits, enrollment in health plans, and premium payments. See 45 CFR 160.03.
A business associate is an organization who creates, receives, maintains, or transmits protected health information (PHI) for the purposes of a function or activity regulated by this law, including claims processing or administration, data analysis, processing or administration, utilization review, quality assurance, patient safety activities, billing, benefit management, practice management, and repricing on behalf of a covered entity. A business associate can also be an organization that provides legal, actuarial, accounting, consulting, data aggregation, management, administrative, accreditation, or financial services, which involves the disclosure PHI, to or for a covered entity. See 45 CFR § 160.103.
A business associate does not mean a health care provider who discloses PHI concerning treatment of the individual.
State Law
Most states have a form of HIPAA enacted into law. Some adopt HIPAA entirely, and others take only a few components. It is important you check with a local attorney to determine what the laws in your state are, and how they apply to your center.
Grants and State Funding Agreements
Oftentimes, grants and agreements for state funding will have requirements that mimic HIPAA requirements. Before signing on the dotted line, it may be best to check with local counsel to review these agreements.
Practical Application
If you are not considered a covered entity, you are not required, by federal law, to comply with HIPAA. If you do not bill for services, you most likely are not considered a covered entity. This means that the rights given to patients under HIPAA may not extend to your clients. It is important to consider how you advertise yourself out to the public.
Confidentiality Policy
Every PHO should have standards for confidentiality: a policy for your employees, and a statement for your clients. Both should include your state law’s requirements. You may also include the requirements from grant or state funding agreements.
Your Employee Confidentiality Policy should indicate that confidential information is shared on a need-to-know basis only. The Confidentiality Policy should state that any location that stores personal health data is secure. For example, computers should have automatic lock screens and paper records should be stored in locked cabinets in a locked room, separate from the waiting room or consulting rooms.
Your Confidentiality Statement should apply and be given out to all clients, regardless of the services they receive. The Confidentiality Statement should outline the safeguards your PHO agrees to follow, and any exceptions to confidentiality that are required by your state’s laws or your center’s policies. It is recommended that the client acknowledge receipt of the Confidentiality Statement.
Not only do you need to have a policy on confidentiality, but you also need to follow that policy. External authorities will judge your organization based on how well you follow your own policies.