Medicare General Information, Eligibility and Entitlement Manual (Pub. 100-01), Ch. 6 § 190

The Health Insurance Portability and Accountability Act (HIPAA)

Last amended: 2004Year: 2004Length: 3,378 wordsOfficial source
190 - The Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule (Rev. 7, 06-25-04) A. General Information To improve the efficiency and effectiveness of the health care system, HIPAA included provisions that required national standards for electronic health care transactions. At the same time, Congress recognized that advances in electronic technology could erode the privacy of health information. Consequently, Congress incorporated into HIPAA provisions that mandated the adoption of Federal privacy protections for individually identifiable health information. The Department of Health and Human Services issued the regulation “Standards for Privacy of Individually Identifiable Health Information”, 45 CFR Parts 160 and 164, (the HIPAA Privacy Rule) to implement section 264 of HIPAA. The HIPAA Privacy Rule establishes a set of basic national privacy standards and fair information practices. It sets a floor of ground rules for health care providers, health plans, and health care clearinghouses to follow to protect the privacy of an individual’s personal health information. The HIPAA Privacy Rule is based on the same fair information principles that are found in the Privacy Act of 1974 and are now generally extended to the public and private sectors of the health care delivery system. The HIPAA Privacy Rule applies to protected health information (PHI) held by covered entities, as defined by the Rule, while the Privacy Act protects records with individually identifiable information held by Federal agencies. The Privacy Act continues to apply to Medicare and Medicare fee-for-service (FFS) contractors in their day-to-day operations. The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) is responsible for providing outreach and technical assistance to covered entities (health plans, health care clearinghouses, and health care providers who conduct certain financial and administrative transactions electronically) and for enforcing the HIPAA Privacy Rule. OCR maintains information on the HIPAA Privacy Rule at http://www.hhs.gov/ocr/hipaa/ B. How CMS Applies Laws Affecting the use and Disclosure of Personal Information 1. General rules Since Medicare operates under both the Privacy Act and the HIPAA Privacy Rule, CMS has determined how the provisions interact with each other as it uses personally identifiable information in its day-to-day operations. For example, a use or disclosure that is permitted under the HIPAA Privacy Rule (e.g., to facilitate cadaveric organ donation and transplants), but not published in a Federal Register notice as a routine use in a CMS system of records would not be permitted for Medicare. Similarly, if the disclosure is a “routine use” under the Privacy Act, but the HIPAA Privacy Rule prohibits the disclosure, CMS will not make the disclosure. Exemption 6 of the Freedom of Information Act (FOIA) permits Federal agencies to withhold personnel and medical files the disclosure of which would constitute a clearly unwarranted invasion of personal privacy. When a FOIA request asks for documents that include personal information, CMS must apply Exemption 6 to preclude the release of, or must otherwise redact, identifying details before disclosing the remaining information. 2. Information About Deceased Individuals The application of Exemption 6 of the FOIA to information about deceased individuals requires a different analysis than that applicable to living individuals because under the Privacy Act of 1974, privacy rights are extinguished at death. However, under FOIA, it is entirely appropriate to consider the privacy interest of a decedent’s survivors under Exemption 6. Under the HIPAA Privacy Rule, the personal health information of deceased as well as living persons is protected. 3. Requests for Access to Records The FOIA and Privacy Act requests will continue to be handled according to current procedures and timeliness standards. A FOIA request for access to public records requires CMS, as a Federal agency, to provide the fullest possible disclosure of its records to the public, subject to certain exceptions (e.g., proprietary information, national defense risks). The Privacy Act requires CMS to provide individuals access to their personal information maintained in a System of Records. Note that an individual’s request under the Privacy Act to access his or her records must specify a Privacy Act System of Records and must be addressed to the system manager identified in the Federal Register notice. A HIPAA Privacy Rule request for access is separate from both FOIA and the Privacy Act and has its own timeliness standards associated with it. Requests for access under the HIPAA Privacy Rule will be handled by CMS’ Central Office (see section G below). 4. State Law Preemption Under HIPAA Medicare is a national program that is administered under Federal statute and regulation. CMS administers Medicare through Medicare FFS contractors that are required to operate in accordance with statutory and regulatory requirements and CMS administrative direction. When considering the provisions of HIPAA, Congress expressly intended to defer to more stringent state laws if those laws conflict with provisions in the HIPAA Privacy Rule. The HIPAA Privacy Rule therefore explicitly preempts conflicting state law provisions, unless they are more stringent or more protective of the individual’s rights. Since the Federal law expressly preserves more stringent state laws, and because of the complexity of this issue, contractors should ask CMS for guidance as issues arise. C. CMS Programs that are Covered Entities Under HIPAA The Federal health programs that CMS administers are health plans as defined in HIPAA and are covered entities subject to the HIPAA Privacy Rule. These health plans are: • Part A or Part B of the Medicare program under Title XVIII; • The Medicaid program under Title XIX; • The State Children’s Health Insurance Program (SCHIP); and • The Medicare Advantage (formerly Medicare+Choice (M+C)) program and other Medicare health plans. The CMS is directly responsible for ensuring that the Medicare Fee-For-Service (FFS) program, also known as the Original Medicare Plan, complies with the HIPAA Privacy Rule. For the Medicaid and SCHIP programs, the appropriate State Agency is responsible for ensuring compliance with privacy requirements. Medicare Advantage (formerly M+C) plans are covered entities subject to the HIPAA Privacy Rule in their own right and responsible for their own compliance. D. Business Associates Most health care providers and health plans do not carry out all of their health care activities and functions by themselves; they require assistance from a variety of contractors and other businesses. By definition, a business associate is a person or entity that performs or assists in the performance of a function or activity involving the use or disclosure of individually identifiable health information on behalf of a covered entity. Medicare FFS contractors that perform health care activities involving the use of PHI on behalf of the Medicare FFS health plan (i.e., claims processing functions) are business associates of the Medicare FFS health plan (the covered entity). The HIPAA Privacy Rule allows providers and plans to give PHI to their business associates as long as they have satisfactory assurances and document those assurances, typically by contract, that business associates will safeguard the information. Medicare contracts have been modified to include the business associate provisions. These provisions also address the contractor’s responsibility to ensure that subcontractors or agents to whom they disclose Medicare data agree, by contract, to safeguard any PHI as well. Contracts continue to include language that applies to contractors who maintain or operate a Privacy Act protected systems of records on Medicare’s behalf. Medicare contractors that perform health care activities involving the use of PHI on behalf of the Medicare FFS health plan are not business associates of providers, physicians, suppliers, clearinghouses, or other health plans. Likewise, providers, physicians, suppliers, clearinghouses, or other health plans are not business associates of the Medicare contractor unless the provider, physician, supplier, clearinghouse, or other health plan is doing work on behalf of the Medicare contractor. For these reasons, Medicare FFS contractors should not sign business associate agreements with any provider, physician, supplier, clearinghouse, or other plan unless the provider, physician, supplier, clearinghouse, or other health plan is doing work on the contractor’s behalf. E. Trading Partner Agreements Currently, Medicare contractors execute trading partner agreements (TPAs) with a number of payers, including Medigap insurers, Medicare supplemental/employee retiree health plans, multiple employer welfare trusts, TRICARE for Life, as well as State Medicaid Agencies, for the purpose of exchanging adjudicated Medicare claims for secondary liability determination by those partners. This exchange of data is commonly referred to as the “claims crossover process.” For coordination of benefits (COB) purposes, Medicare contractors and trading partners are not business associates of each other since neither entity is doing work on the other’s behalf; therefore, MACs should not sign business associate agreements with COB trading partners that receive claims crossover data from them. F. Notice of Privacy Practices The HIPAA Privacy Rule requires each covered entity to develop and provide a plain language notice that describes its legal duties, the uses and disclosures of protected health information that it may make, and individual privacy rights and how to exercise them. The individual rights include the right to inspect and copy protected health information, to amend protected health information, to request restrictions, confidential communications, an accounting of disclosures, a paper copy of the privacy notice, and how to file complaints. Medicare’s privacy notice was provided to beneficiaries for the first time in the 2003 Medicare & You handbook and is provided in the handbook every year. New enrollees receive the privacy notice in the handbook that is mailed to them within 30 days of Medicare entitlement. Medicare’s privacy notice is also posted on Medicare’s Web site at www.medicare.gov. Medicare’s Notice of Privacy Practices informs beneficiaries who are interested in exercising individual rights to go to www.medicare.gov or call 1-800-MEDICARE. Customer Service Representatives (CSR) at 1-800-MEDICARE use scripts to answer questions regarding exercising individual rights and filing complaints. Since Medicare’s privacy notice describes the uses and disclosures of PHI in the day-to- day operations of Medicare (including Medicare FFS contractors), FFS contractors are not required to develop a separate privacy notice for Medicare beneficiaries. G. Individual Rights and Complaints NOTE: For Individual Rights Under the Privacy Act of 1974, see §10 above. The HIPAA Privacy Rule gives individuals rights with respect to their PHI. These rights are listed in covered entities’ privacy notices. The Notice of Privacy Practices for the Original Medicare Plan includes the right to: 1. See and get a copy of personal health information held by Medicare. CMS Central Office is responsible for responding to beneficiary requests for access to records under the HIPAA Privacy Rule. Medicare FFS contractors should only respond to those requests for information related to payment of a claim, for which they are already responsible under the contract under existing customer service procedures. Simple telephone inquiries, such as asking about the status of a claim or requesting a duplicate Medicare Summary Notice, are not considered a HIPAA request for access and should be handled under existing customer service procedures. 2. Have personal health information amended if it is wrong or missing, and Medicare agrees. If Medicare disagrees, a statement of disagreement may be added to the personal health information. Central office is responsible for handling beneficiary requests to amend the record under the HIPAA Privacy Rule. Contractors will not be responding to requests to amend records. Requests for changes to claims or payment records, such as an appeal or change of address request, are not considered HIPAA Privacy Rule requests for amendments, and should be handled according to current procedures. Note, however, that if the request for amendment involves medical records, contractors should explain that, except in rare circumstances, only the source of the medical record (i.e., the provider) may make changes to the record. 3. Get a listing of those receiving personal medical information from Medicare. CMS Central Office is responsible for responding to beneficiary requests for an accounting of disclosures under the HIPAA Privacy Rule. Contractors will not be responding to requests for an accounting of disclosures. The listing does not cover personal health information that was given to the individual or his or her personal representative, that was given out to pay for health care or Medicare operations, or that was given out for law enforcement purposes. 4. Ask Medicare to communicate in a different manner or at a different place, for example, by sending materials to a P.O. box instead of the address on file. Current regulations and existing agreements with the Social Security Administration are extremely prescriptive, often governing precisely how CMS can respond to requests for confidential communications. Operationally, CMS can only maintain one address at a time. Because of this, routine change of address requests should be handled according to current change of address procedures. 5. Ask Medicare to limit how personal health information is used and given out to pay claims and run the Medicare program. CMS Central Office is responsible for responding to beneficiary requests to restrict disclosure of PHI. Contractors will not be responding to requests to restrict disclosure of PHI. 6. Get a separate paper copy of the privacy notice. Contractors who receive requests for a paper copy of the Notice of Privacy Practices for the Original Medicare Plan should refer requestors to their Medicare & You handbook. 7. File a complaint. Medicare’s Notice of Privacy Practices informs individuals of the right to file complaints about Medicare’s privacy practices with either Medicare or the Secretary of Health and Human Services. The privacy notice refers individuals to www.medicare.gov or 1-800-MEDICARE for further information on filing a complaint. CMS is required to document in written or electronic form the complaints received and their disposition. There is no requirement to respond in a particular manner or time frame. For the privacy rights listed above where CMS Central Office is responsible for responding to the request, contractors should advise beneficiaries to address their requests to: HIPAA Privacy P.O. Box 8050 U.S. Department of Health and Human Services Centers for Medicare & Medicaid Services 7500 Security Boulevard Baltimore, MD 21244-1850 H. Privacy Authorizations An authorization is a document that an individual uses to give a covered entity permission to disclose his or her PHI for a particular purpose (e.g., for marketing) or to a third party specified by the individual. A covered entity is generally not required to obtain an authorization for the use or disclosure of PHI for treatment, payment, or health care operations, as well as for certain public priority activities under specified conditions (e.g., health care oversight, law enforcement). Contractors should inform providers that contractors are unable to make payment for Medicare claims if the provider fails to provide the information needed to process them. The HIPAA Privacy Rule specifies certain core elements and required statements for a valid authorization. Contractors may add more elements to their authorizations as long as the core elements and required statements remain and no provisions are added that conflict with these core elements and statements. Contractors must also accept an authorization from another entity, provided it includes all of the core elements and required statements, and no provisions are added that conflict with these core elements and statements. I. Core Elements and Required Statements for an Authorization The core elements of a valid authorization are: 1. A description of the information to be used or disclosed that identifies the information in a specific and meaningful fashion; 2. The name or other specific identification of the person(s), or class of persons, authorized to make the requested use or disclosure; 3. The name or other specific identification of the person(s) or class of persons, to whom the covered entity may make the requested use or disclosure; 4. A description of each purpose of the requested use or disclosure. The statement, “at the request of the individual” is a sufficient description of the purpose when the beneficiary initiates the authorization and does not, or elects not to, provide a statement of the purpose; 5. An expiration date or an expiration event that relates to the individual or the purpose of the use or disclosure; and 6. The signature of the individual and date. If a personal representative of the individual signs the authorization, a description of such representative’s authority to act for the individual must also be provided. Although the HIPAA Privacy Rule requires only a description of the representative’s authority to act for the individual, CMS is requiring that documentation showing the representative’s authority be attached to the authorization (e.g., a Power of Attorney). In addition to the core elements, the authorization must contain statements adequate to place the individual on notice of all of the following: 1. The individual’s right to revoke the authorization in writing, how the individual may revoke the authorization, and the exceptions to the right to revoke, e.g., “You have the right to take back (“revoke”) your authorization at any time in writing, except to the extent that Medicare has already acted based on your permission. To revoke your authorization, send a written request to: [Each Medicare contractor or CMS: Please insert Name, Address, and Telephone number of your organization here]”; 2. The inability to condition treatment, payment, enrollment or eligibility for benefits on the authorization, e.g., “I understand refusal to authorize disclosure of my personal medical information will have no effect on my enrollment, eligibility for benefits, or the amount Medicare pays for the health services I receive”; 3. The potential for information disclosed pursuant to the authorization to be subject to redisclosure by the recipient and no longer protected, e.g.: “Your personal medical information that you authorize Medicare to disclose may be subject to redisclosure and no longer protected by law.” In addition, the authorization must be written in plain language and a signed copy must be provided to the individual (or the individual should be advised to retain a copy). The CMS is developing a standard authorization for beneficiaries or their personal representatives to request disclosure of PHI to third parties. The standard will contain the elements for compliance with both the HIPAA Privacy Rule and Privacy Act requirements. Contractors will be notified when the standard authorization is available. J. Personal Representatives and Third Party Authorizations The HIPAA Privacy Rule requires covered entities to treat an individual’s personal representative as the individual with respect to uses and disclosures of the individual’s PHI, as well as exercising the individual’s privacy rights listed in the covered entity’s Notice of Privacy Practices. A personal representative may also authorize disclosures of an individual’s PHI (see §190H above). In addition to these formal designations of a personal representative, the HIPAA Privacy Rule permits a covered entity to disclose to any person identified by the individual the protected health information directly relevant to such person’s involvement with the individual’s care or payment related to the individual’s care. Therefore, a verbal authorization is allowed under the HIPAA Privacy Rule for those individuals involved in the care of an individual. Contractors should continue to handle routine inquiries, such as telephone requests for the status of claims, under existing customer service procedures that include verification of the individual’s identity. Therefore, with the beneficiary’s verbal or written permission, contractors may continue to speak to third parties on behalf of the individual. See Exhibit D - Disclosure Desk Reference Guide for Call Centers for detailed instructions on disclosing PHI over the telephone. Contractors may also continue to handle Congressional inquiries under existing customer service procedures (see §10J above). K. Administrative Requirements As Medicare’s business associate, contractors are not subject to the administrative requirements of the HIPAA Privacy Rule. However, under the Privacy Act, contractors must comply with the privacy provisions specified in their contracts. Contractors are not required to designate a privacy official. However, contractors are required to have in place a senior official or other responsible party to address the privacy concerns of the organization and to establish an internal control system to monitor compliance with privacy requirements. Similarly, as Medicare’s business associate, contractors are not subject to the HIPAA Privacy Rule’s requirement to train staff specifically on the HIPAA Privacy Rule. However, under the Privacy Act, contractors are required to ensure that employees understand their responsibility to protect the privacy and confidentiality of CMS’s records. It is CMS policy that any data collected on behalf of CMS in the administration of a Medicare contract belongs to CMS. Any disclosure of individually identifiable information without prior consent from the individual to whom the information pertains, or without statutory or contract authorization, requires prior approval by CMS.
Medicare General Information, Eligibility and Entitlement Manual (Pub. 100-01), Ch. 6 § 190: The Health Insurance Portability and Accountability Act (HIPAA) | Justis AI