216-RICR-40-10-6

216-RICR-40-10-6. Patient Safety Organizations (version Adoption, 01/27/2009 to 04/30/2018)

SupersededLast amended: 2009Year: 2026Length: 5,638 wordsOfficial source
RULES AND REGULATIONS PERTAINING TO CERTIFICATION OF PATIENT SAFETY ORGANIZATIONS [R23-17.21-PSO] STATE OF RHODE ISLAND AND PROVIDENCE PLANTATIONS DEPARTMENT OF HEALTH January 2009 i INTRODUCTION These Rules and Regulations Pertaining to Certification of Patient Safety Organizations [R23-17.21-PSO] are promulgated pursuant to the authority conferred under §23-17.21 of the General Laws of Rhode Island, as amended, for the purpose of adopting standards for certification of patient safety organizations. Pursuant to the provisions of §42-35-3(c) of the General Laws of Rhode Island, as amended, the following were given consideration in arriving at these regulations: (1) Alternative approaches to the regulations; and (2) Duplication or overlap with other state regulations. Based on the available information, no known alternative approach, duplication or overlap, was identified. ii TABLE OF CONTENTS Page Section 1.0 Definitions 1 Section 2.0 General Provisions 2 2.1 Purpose and Scope 2 2.2 Ineligible Entities 2 Section 3.0 Privilege and Confidentiality Protections 2 3.1 Privilege 2 3.2 Confidentiality of Patient Safety Work Product and Document Log 3 3.3 Exceptions 3 3.4 Continued Protection of Information After Disclosure 4 3.5 Reporter Protection 4 Section 4.0 Reporting Entity Requirements 5 4.1 Effective Date 5 4.2 Document Log 5 4.3 Applicability of Other Reporting Requirements 5 4.4 Nonapplicability of Public Records Law 5 Section 5.0 Patient Safety Organization Requirements 5 5.1 Maintenance of Reports 5 5.2 Dissemination of Information 5 5.3 Safeguards and Security Measures 5 5.4 Required Notifications 7 Section 6.0 Application For Certification 8 6.1 General Requirements 8 6.2 Certification Application 8 6.3 Issuance and Renewal of Certification 10 Section 7.0 Complaints and Enforcement 11 7.1 Complaints and Routine Correspondence. 11 7.2 Penalties 11 Section 8.0 Rules Governing Practices and Procedures 11 Section 9.0 Severability 11 1 SECTION 1.0 DEFINITIONS Whenever used in these rules and regulations, the following terms shall be construed as follows: 1.1 “Act” means Chapter 23-17.21 of the Rhode Island General Laws, as amended, entitled “The Rhode Island Patient Safety Act of 2008.” 1.2 “Bona fide contract” means a written contract between a reporting entity and a PSO that is executed in good faith by officials authorized to execute such contract. 1.3 “Component organization” means an entity that is either: (a) A unit or division of a corporate organization or of a multi-organizational enterprise; or (b) A separate organization, whether incorporated or not, that is owned, managed or controlled by one or more other organization(s), i.e., its parent organization(s). 1.4 “Component PSO” means a patient safety organization certified by the Director that is a component organization. 1.5 “Department” means the Rhode Island Department of Health. 1.6 “Director" means the Director of the Rhode Island Department of Health. 1.7 “Document log” means an inventory or record, required pursuant to RIGL §23-17.21-6(b), which itemizes the types of documents submitted to the PSO without indicating the content of such documents. 1.8 “Entity” means any organization or organizational unit, regardless of whether the organization is public, private, for-profit or not-for-profit. 1.9 “Health care facility” means any corporation, limited liability company, facility, or institution licensed by this state to provide health care or professional services, or an officer, employee or agent thereof acting in the course and scope of his or her employment. 1.10 “Identifiable patient safety work product” means patient safety work product that: (a) Is presented in a form and manner that allows the identification of any provider or reporting entity that is a subject of the work product, or any providers or reporting entities that participate in activities that are a subject of the work product; (b) Constitutes individually identifiable health information as that term is defined in the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (45 CFR Parts 160-164); or (c) Is presented in a form and manner that allows the identification of an individual. 1.11 “Near misses” means circumstances in which a patient safety event is narrowly averted. 1.12 “Nonidentifiable patient safety work product” means patient safety work product that is not identifiable patient safety work product as defined in these regulations. 1.13 “Patient safety activities” means: (a) Efforts to improve patient safety and the quality of health care delivery; (b) The collection and analysis of patient safety work product; (c) The development and dissemination of information with respect to improving patient safety, such as recommendations, protocols, or information regarding best practices; (d) The utilization of patient safety work product for the purposes of encouraging a culture of safety 2 and of providing feedback and assistance to effectively minimize patient risk; (e) The maintenance of procedures to preserve confidentiality with respect to patient safety work product; and (f) The provision of appropriate security measures with respect to patient safety work product. 1.14 “Patient safety event” means those events as defined by the national quality forum, institute of medicine, center for Medicare and Medicaid Services (CMS), and as further defined by the quality of care advisory committee, as established herein, and shall include near misses. 1.15 “Patient safety organization (PSO)” means any entity certified by the Director whose activity is to improve patient safety and the quality of health care delivery for patients receiving care through the collection, aggregation, analysis, investigation, and/or processing of medical or health care related information submitted to it by reporting entities. A PSO shall not mean any agency or public body as defined in RIGL §38-2-2(i). 1.16 “Patient safety work product" means all reports, records, memoranda, analyses, statements, root cause analyses, or written or oral statements, that: (a) A health care facility or provider prepares for the purpose of disclosing a patient safety event, or is disclosed, to a patient safety organization; (b) Is received from a reporting entity, or is created or analyzed by a patient safety organization; or (c) Directly or indirectly contains deliberations, analytical process, recommendations, conclusions, or other communications of a patient safety organization or between a patient safety organization and health care providers or facilities. 1.17 “Quality of Care Advisory Committee” means the committee established by the Director, pursuant to RIGL §23-17.21-5(b), to advise the Department on PSO-related issues. 1.18 “Regulations” [“these Regulations”] means all sections of the Rules and Regulations Pertaining to Certification of Patient Safety Organizations [R23-17.21-PSO]. Unless specifically cited otherwise, all references contained herein shall be interpreted as pertaining to these Regulations. 1.19 “Reporting entity” means any hospital, nursing facility or freestanding ambulatory surgical center licensed pursuant to RIGL §23-17. 1.20 “RIGL” means the General Laws of Rhode Island, as amended. SECTION 2.0 GENERAL PROVISIONS 2.1 Purpose and Scope. These Regulations establish standards for certification of a patient safety organization (PSO), and operational requirements for both a reporting entity and a patient safety organization. 2.2 Ineligible Entities. Entities that may not seek certification as a PSO include: health insurance issuers or components of health insurance issuers. Any other entity, public or private, that conducts regulatory oversight of health care providers, such as accreditation or licensure, may not seek certification, except that a component of such an entity may seek listing as a component PSO. SECTION 3.0 PRIVILEGE AND CONFIDENTIALITY PROTECTIONS 3.1 Privilege. Notwithstanding any other provision of federal, state, or local law to the contrary, and subject to §3.3, patient safety work product and a document log shall be privileged and shall not be: 3 (a) Subject to a federal, state, or local civil, criminal, or administrative subpoena or order, including in a federal, state, or local civil or administrative disciplinary proceeding against a provider; (b) Subject to discovery in connection with a federal, state, or local civil, criminal, or administrative proceeding, including in a federal, state, or local civil or administrative disciplinary proceeding against a provider; (c) Subject to disclosure pursuant to 5 USC 5521, RIGL §38-22, or any other similar federal, state, or local law; (d) Admitted as evidence in any federal, state, or local governmental civil proceeding, criminal proceeding, administrative rulemaking proceeding, or administrative adjudicatory proceeding, including any such proceeding against a provider; or (e) Admitted in a professional disciplinary proceeding of a professional disciplinary body established or specifically authorized under state law. 3.2 Confidentiality of Patient Safety Work Product and Document Log. Notwithstanding any other provision of federal, state or local law to the contrary, and subject to §3.3, the patient safety work product and document log shall be confidential and shall not be disclosed. 3.3 Exceptions. (a) Exceptions From Privilege and Confidentiality. §3.1 and §3.2 shall not apply to, and shall not be construed to prohibit, one or more of the following disclosures: (1) Disclosure of relevant patient safety work product and document log for use in a criminal proceeding, but only after a court makes an in camera3 determination that such patient safety work product and document log contains evidence of a criminal act and that such patient safety work product and document log is material to the proceeding and not reasonably available from any other source; or (2) Disclosure of identifiable patient safety work product and document log if authorized by each provider or reporting entity identified in such work product. (b) Exceptions From Confidentiality. §3.2 shall not apply to, and shall not be construed to prohibit one or more of the following voluntary disclosures: (1) Disclosure of patient safety work product and document log to a reporting entity to carry out patient safety activities; (2) Disclosure of patient safety work product and document log to grantees, contractors, or other entities carrying out research, evaluation, or demonstration projects authorized, funded, certified, or otherwise sanctioned by rule or other means by the Director, for the purpose of conducting research to the extent that disclosure of protected health information would be allowed for such purpose under the Health Insurance Portability and Accountability Act of 1996, and its implementing regulations (45 C.F.R. Parts 160-164); (3) Disclosure by a provider to the U.S. Food and Drug Administration with respect to a product or activity regulated by the Food and Drug Administration; (4) Voluntary disclosure of patient safety work product and document log by a provider to an 1 Section of the United States Code commonly known as the Freedom of Information Act. 2 Section of the Rhode Island General Laws commonly known as the Access to Public Records Law. 3 In camera refers to a hearing or discussion with a judge in the privacy of his/her chambers or when spectators and jurors have been excluded from the courtroom. 4 accrediting body that accredits that provider; or (5) Disclosure of patient safety work product and document log to law enforcement authorities relating to the commission of a crime, or to an event reasonably believed to be a crime, if the person making the disclosure believes, reasonably under the circumstances, that the patient safety work product and document log that is disclosed is necessary for criminal law enforcement purposes. 3.4 Continued Protection of Information After Disclosure. (a) General Requirement. Patient safety work product and/or document log that is disclosed under §3.3 shall continue to be privileged and confidential as provided for in §3.1 and §3.1, and such disclosure shall not be treated as a waiver of privilege or confidentiality, and the privileged and confidential nature of such work product and/or document log shall also apply to such work product and/or document log in the possession or control of a person to whom such work product and log was disclosed. (b) Exception. Notwithstanding §3.4(a) and subject to §3.4(c), if patient safety work product and/or document log is admitted into evidence in a criminal proceeding, the confidentiality protections provided for in §3.2 shall no longer apply to the work product and/or log so disclosed; and (c) Construction. §3.4(b) shall not be construed as terminating or limiting the privilege or confidentiality protections provided for in §3.1 or §3.2 with respect to patient safety work product and document log other than the specific patient safety work product and document log disclosed as provided for in §3.3. (d) Limitations On Actions. (1) Patient Safety Organizations (i) General Requirement. A patient safety organization shall not be compelled to disclose information collected or developed under the Act or these Regulations whether or not such information is patient safety work product and/or a document log unless such information is identified, it is not patient safety work product and/or a document log, and it is not reasonably available from another source. (ii) Nonapplication. The limitation contained in §3.4(d)(1)(i) shall not apply in an action against a patient safety organization or with respect to disclosures pursuant to §3.3(a). (2) Providers. An accrediting body shall not take an accrediting action against a provider based on the good faith participation of the provider in the collection, development, reporting, or maintenance of patient safety work product and a document log in accordance with the Act or these Regulations. An accrediting body may not require a provider or reporting entity to reveal its communications with any patient safety organization established in accordance with the Act or these Regulations. 3.5 Reporter Protection. (a) General Requirement. A provider may not take any adverse employment action, as described in §3.5(b), against an individual based upon the fact that the individual, in good faith, reported the information: (1) To the reporting entity with the intention of having the information reported to a patient safety organization; or (2) Directly to a patient safety organization. (b) Adverse Employment Action. For the purposes of this Section, an adverse employment action 5 includes: (1) Loss of employment, the failure to promote an individual, or the failure to provide any other employment related benefit for which the individual would otherwise be eligible; or (2) An adverse evaluation or decision made in relation to accreditation, certification, credentialing, or licensing of the individual. SECTION 4.0 REPORTING ENTITY REQUIREMENTS 4.1 Effective Date: On and after 1 January 2009, a reporting entity may enter into a written contract with a patient safety organization, certified in accordance with these Regulations, to which it sends patient safety work product. 4.2 Document Log. Each contract shall require the reporting entity to maintain a document log itemizing the types of documents submitted to the PSO without indicating the content of such documents. Such document log shall be accessible to the Department for the sole purpose of allowing the Department to verify the type of information submitted to PSOs. The Department shall not have access to patient safety work product. Such document log shall not be subject to a disclosure to, or use by, any person or entity, other than the PSO and the reporting entity with which it has contracted, and by the Department for the sole purpose provided in this Section. 4.3 Applicability of Other Reporting Requirements . A reporting entity shall not be exempt from the requirements of RIGL §23-17-40 or RIGL §5-37-9. 4.4 Nonapplicability of Public Records Law. Patient safety work product (whether identifiable of nonidentifiable) and any document log submitted to the Director under §4.2 shall not be a public record for the purposes of RIGL §38-2. A reporting entity shall not be considered a public body or agency for the purposes of RIGL §38-2. SECTION 5.0 PATIENT SAFETY ORGANIZATION REQUIREMENTS 5.1 Maintenance of Reports. A PSO shall provide guidance to reporting entities on reporting matters, and shall maintain all reports and associated documents as confidential and privileged, including any reports or information with identifiable information. 5.2 Dissemination of Information. A PSO shall, as appropriate, disseminate to health care providers and facilities, the Department, the Quality of Care Advisory Committee, and the public, information or recommendations, including suggested policies, procedures or protocols, on best medical practices or potential system changes designed to improve patient safety and the overall quality of care. Notwithstanding the foregoing, the PSO shall not disclose identifiable patient safety work product to the Department, the quality of care advisory committee, or the public. 5.3 Safeguards and Security Measures. (a) (1) A PSO shall have in place appropriate physical, technical and procedural safeguards and security measures to ensure the technical integrity, physical safety, and confidentiality of any patient safety work product. These safeguards and security measures shall be in place at all times and at any location at which the PSO, its workforce members, or its contractors hold patient safety work product. Such safeguards and security measures shall comply with state and federal confidentiality laws including, without limitation, the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (45 CFR Parts 6 160-164) and RIGL §5-37.3 [Confidentiality of Health Care Communications and Information Act]. (2) As provided for in RIGL §23-17.21-8, patient safety work product shall be confidential, and shall not be subject to any discovery, access or use by any person or entity other than the PSO and the reporting entity with which the PSO has contracted. (3) Nothing in the Act or these Regulations shall be construed to prohibit a PSO from choosing to disclose patient safety work product, or portions of patient safety work product, solely to a reporting entity, in conformity with the PSO's mission and within its contractual obligations to the reporting entity who submitted the information. No patient safety organization shall release protected health information or patient identifying information without meeting the requirements of state RIGL §5-37.3 [Confidentiality of Health Care Communications and Information Act] and the federal Health Insurance Portability and Accountability Act of 1996, as amended from time to time, and its implementing regulations (45 CFR Parts 160- 164). (b) Security Framework. PSOs shall consider the following framework for the security of patient safety work product. The framework includes four elements: security management, separation of systems, security monitoring and control, and system assessment. To address the four elements of this framework, a PSO shall develop appropriate and scalable security standards, policies, and procedures that are suitable for the size and complexity of its organization. (1) Security Management. A PSO shall address: (i) Maintenance and effective implementation of written policies and procedures that conform to the requirements of this Section to protect the confidentiality, integrity, and availability of the patient safety work product that is processed, stored, and transmitted; and to monitor and improve the effectiveness of such policies and procedures, and (ii) Training of the PSO workforce and PSO contractors who access or hold patient safety work product regarding the requirements of the Act, these Regulations and the PSO's policies and procedures regarding the confidentiality and security of patient safety work product. (2) Separation of Systems. A PSO shall address: (i) Maintenance of patient safety work product, whether in electronic or other media, physically and functionally separate from any other system of records; (ii) Protection of the media, whether in electronic, paper, or other format, that contain patient safety work product, limiting access to authorized users and sanitizing and destroying such media before disposal or release for reuse; and (iii) Physical and environmental protection, to control and limit physical and virtual access to places and equipment where patient safety work product is stored or used. (3) Security Control and Monitoring. A PSO shall address: (i) Identification of those authorized to have access to patient safety work product and an audit capacity to detect unlawful, unauthorized or inappropriate access to patient safety work product, and (ii) Measures to prevent unauthorized removal, transmission or disclosure of patient safety work product. (4) Security Assessment. A PSO shall address: (i) Periodic assessments of security risks and controls, as determined appropriate by the 7 PSO, to establish if its controls are effective, to correct any deficiency identified, and to reduce or eliminate any vulnerabilities. (ii) System and communications protection, to monitor, control, and protect PSO uses, communications, and transmissions involving patient safety work product to and from reporting entities and any other responsible persons. 5.4 Required Notifications. A PSO shall meet the following notification requirements: (a) Notification Regarding PSO Compliance With Minimum Contract Requirement. No later than forth five (45) calendar days prior to expiration of the PSO’s certification, as specified in §6.3(a), the PSO shall submit to the Director an attestation as to whether it has met the requirement of §6.2(b)(1)(iii) regarding two (2) bona fide contracts. (b) Notification Regarding a PSO's Relationships With Its Contracting Reporting entities. A PSO shall submit a disclosure statement to the Director regarding its relationships with each reporting entity with which the PSO has a contract pursuant to the Act and these Regulations if the circumstances described in either §5.4(b)(1) or §5.4(b)(2) are applicable. The Director shall receive a disclosure statement within forty five (45) days of the date on which a PSO enters a contract with a reporting entity if the circumstances are met on the date the contract is entered. During the contract period, if a PSO subsequently enters one or more relationships with a contracting reporting entity that create the circumstances described in §5.4(b)(1) or a reporting entity exerts any control over the PSO of the type described in §5.4(b)(2), the Director shall receive a disclosure statement from the PSO within forty five (45) days of the date that the PSO entered each new relationship or of the date on which the reporting entity imposed control of the type described in §5.4(b)(2). (1) Taking into account all relationships that the PSO has with the reporting entity, other than the bona fide contract entered into pursuant to the Act and these Regulations, the PSO shall fully disclose any other contractual, financial, or reporting relationships described below that it has with that reporting entity. (i) Contractual relationships which are not limited to relationships based on formal contracts but also encompass relationships based on any oral or written agreement or any arrangement that imposes responsibilities on the PSO. (ii) Financial relationships including any direct or indirect ownership or investment relationship between the PSO and the contracting reporting entity, shared or common financial interests or direct or indirect compensation arrangement, whether in cash or in-kind. (iii) Reporting relationships including any relationship that gives the reporting entity access to information or control, directly or indirectly, over the work of the PSO that is not available to other contracting reporting entities. (2) Taking into account all relationships that the PSO has with the reporting entity, the PSO shall fully disclose if it is not independently managed or controlled, or if it does not operate independently from, the contracting reporting entity. In particular, the PSO shall further disclose whether the contracting reporting entity has exercised or imposed any type of management control that could limit the PSO's ability to fairly and accurately perform patient safety activities and fully describe such control(s). (3) PSOs may also describe or include in their disclosure statements, as applicable, any agreements, stipulations, or procedural safeguards that have been created to protect the ability of the PSO to operate independently or information that indicates the limited impact or insignificance of its financial, reporting, or contractual relationships with a contracting 8 reporting entity. SECTION 6.0 APPLICATION FOR CERTIFICATION 6.1 General Requirements: (a) Certification Required. A patient safety organization (PSO) shall be certified by the Director pursuant to these Regulations before entering into a contract with a reporting entity. (b) Submission of Application. Any entity, except as specified in §2.2, may request an initial or renewal certification as a PSO by submitting a completed application form to the Director on forms provided by the Department. An individual with authority to make commitments on behalf of the entity seeking certification will be required to acknowledge each of the certification requirements, attest that the entity meets each requirement, provide contact information for the entity, and certify that the PSO will promptly notify the Department during its period of certification if it can no longer comply with any of the criteria in these Regulations. (c) Notification of Changes. Any PSO certified pursuant to this Section shall notify the Department in writing before making any change which would render the information4 contained in their application for certification no longer accurate. (d) Federal Certification Required. Any entity requesting certification as a PSO pursuant to these Regulations shall also obtain and maintain certification/listing as a PSO pursuant to the Patient Safety and Quality Improvement Act of 2005 (Pub. L. 109-41) and any implementing regulations promulgated by the U.S. Agency for Healthcare Quality and Research5. (1) Any PSO certified pursuant to these Regulations prior to the establishment of a federal PSO certification/listing program shall be required to obtain such certification when it becomes available. The PSO shall provide copies of all federal PSO certification/listing documents to the Director pursuant to §6.1(c). (2) Any entity requesting certification as a PSO pursuant to these Regulations after the establishment of a federal PSO certification/listing program shall be required to provide copies of all federal PSO certification/listing documents with their application. (3) Renewal. A PSO seeking renewal of certification after the establishment of a federal PSO certification/listing program shall include documentation that the PSO maintains current certification/listing pursuant to that federal PSO program. 6.2 Certification Application. An application for certification as a PSO shall include, as a minimum, the following information for review by the Department: (a) Certification Regarding Patient Safety Activities. (1) An entity seeking initial certification as a PSO shall attest that it has written policies and procedures in place to perform each of the following eight (8) patient safety activities: (i) Efforts to improve patient safety and the quality of health care delivery; (ii) Collection and analysis of patient safety work product; 4 For example, changes involving name of entity, key staff, organizational structure, mailing address or phone number. 5 Pub. L. 109-41 amended Title IX of the Public Health Service Act (42 U.S.C. 299 et seq.) by adding sections 921 through 926, 42 U.S.C. 299b-21 through 299b-26. Implementing regulations are proposed for promulgation as 42 CFR Part 3. 9 (iii) Development and dissemination of information with respect to improving patient safety, such as recommendations, protocols, or information regarding best practices; (iv) Utilization of patient safety work product for the purposes of encouraging a culture of safety and of providing feedback and assistance to effectively minimize patient risk; (v) Maintenance of procedures to preserve confidentiality with respect to patient safety work product; (vi) Provision of appropriate security measures with respect to patient safety work product; (vii) Utilization of qualified staff; and (viii) Activities related to the operation of a patient safety evaluation system and to the provision of feedback to participants in a patient safety evaluation system. (2) The policies and procedures referenced in §6.2(a)(1) shall provide for compliance with the privilege and confidentiality provisions of §3.0 and the appropriate safeguards and security measures required by §5.3. (3) Renewal. A PSO seeking renewal of certification shall attest that it is performing, and will continue to perform, each of the eight (8) patient safety activities referenced in §6.2(a)(1), and is and will continue to comply with the privilege and confidentiality provisions of §3.0 and the appropriate safeguards and security measures required by §5.3. (b) Certification Regarding PSO Criteria. (1) An entity seeking initial certification as a PSO shall attest that it will comply with each of the following seven (7) criteria: (i) The mission and primary activity of a PSO shall be to conduct activities that are to improve patient safety and the quality of health care delivery. (ii) The PSO shall have appropriately qualified workforce members, including licensed or certified medical professionals. (iii) The PSO, within the initial two (2) year certification period, and within each sequential two (2) year certification renewal period, shall have entered into at least two (2) bona fide contracts, each of a reasonable period of time, each with a different reporting entity for the purpose of receiving and reviewing patient safety work product. (iv) The PSO is not a health insurance issuer, and is not a component of a health insurance issuer. (v) The PSO shall make disclosures to the Director as required under §5.4. (vi) To the extent practical and appropriate, the PSO shall collect patient safety work product from reporting entities in a standardized manner that permits valid comparisons of similar cases among similar reporting entities. (vii) The PSO shall utilize patient safety work product for the purpose of providing direct feedback and assistance to reporting entities to effectively minimize patient risk. (2) Renewal. A PSO seeking renewal of certification shall also attest that it is complying with, and will continue to comply with, each of the seven (7) PSO criteria referenced in §6.2(b)(1). (c) Additional Certifications Required of Component Organizations. An entity seeking initial certification as a PSO, that is a component of another organization or enterprise, shall also attest that it will comply with the following requirements: 10 (1) Separation of Patient Safety Work Product. (i) A component PSO shall: (a) Maintain patient safety work product separately from the rest of the parent organization(s) of which it is a part; and (b) Not have a shared information system that could permit access to its patient safety work product to an individual(s) in, or unit(s) of, the rest of the parent organization(s) of which it is a part. (ii) Notwithstanding the requirements of paragraph §6.2(c)(1)(i), a component PSO may provide access to identifiable patient safety work product to an individual(s) in, or a unit(s) of, the rest of the parent organization(s) of which it is a part if the component PSO enters into a written agreement with such individuals or units that requires that: (a) The component PSO will only provide access to identifiable patient safety work product to enable such individuals or units to assist the component PSO in its conduct of patient safety activities, and (b) Such individuals or units that receive access to identifiable patient safety work product pursuant to such written agreement will only use or disclose such information as specified by the component PSO to assist the component PSO in its conduct of patient safety activities, will take appropriate security measures to prevent unauthorized disclosures and will comply with the other certifications the component has made pursuant to §6.2(c)(2) and §6.2(c)(3) regarding unauthorized disclosures and conflicts with the mission of the component PSO. (2) Nondisclosure of Patient Safety Work Product. A component PSO shall require that members of its workforce and any other contractor staff, or individuals in, or units of, its parent organization(s) that receive access in accordance with §6.2(c)(1)(ii) to its identifiable patient safety work product, not be engaged in work for the parent organization(s) of which it is a part, if the work could be informed or influenced by such individuals' knowledge of identifiable patient safety work product, except for individuals whose other work for the rest of the parent organization(s) is solely the provision of clinical care. (3) Conflict of Interest. The pursuit of the mission of a component PSO shall not create a conflict of interest with the rest of the parent organization(s) of which it is a part. (4) Renewal. A component PSO seeking renewal of certification shall also certify that it is complying with, and will continue to comply with, each of the additional requirements referenced in §6.2(c)(1)-(c)(3). 6.3 Issuance and Renewal of Certification. (a) Issuance of Certification. Pursuant to the provisions of §23-17.21-5(a) of the Act, the Director shall grant certification to a PSO which meets the certification requirements set forth in these Regulations. The certification shall expire on the last day of the month two (2) years from the date of issue, unless sooner suspended or revoked. (b) Renewal of Certification. A PSO may renew a certification every two (2) years upon submission of an application in accordance with the provisions of §6.2(a)(3), §6.2(b)(3) and §6.2(c)(4) [if applicable]. In any case in which the responsible individual of a PSO has filed a renewal application in proper form, including compliance with the notification requirements of §5.4(a), not less than forty five (45) calendar days prior to expiration of its existing certification, the existing certification shall not expire until final action on the renewal application has been taken by the Department. 11 SECTION 7.0 COMPLAINTS AND ENFORCEMENT 7.1 Complaints and Routine Correspondence. (a) Complaints. Any person who desires to register a complaint citing a violation of the Act or these Regulations shall submit a written and signed letter of complaint to the Director. All complaints shall be directed to: Rhode Island Department of Health 3 Capitol Hill Providence, RI 02908-5097 Phone: (401) 222-5960 (b) Routine Correspondence. Routine correspondence, including all required notifications and reports, shall also be directed to the address specified above. 7.2 Penalties. (a) Civil Monetary Penalty. Subject to §3.4(c), a person who discloses identifiable patient safety work product and/or document log in a knowing or reckless violation of §3.2 shall be subject to a civil monetary penalty of not more than ten thousand dollars ($10,000) for each act constituting such violation. (b) Relation to Health Insurance Portability and Accountability Act of 1996. Penalties shall not be imposed both under these Regulations and under the regulations issued pursuant to §264(c)(1) of the Health Insurance Portability and Accountability Act of 1996 (42 U.S.C. 1320d-2 note) for a single act or omission. SECTION 8.0 RULES GOVERNING PRACTICES AND PROCEDURES 8.1 Upon due notice in accordance with RIGL §42-35, all hearings and reviews required under the provisions of the Act and these Regulations shall be held in accordance with requirements of the Rules and Regulations of the Rhode Island Department of Health Regarding Practices and Procedures Before the Department of Health and Access to Public Records of the Department of Health [R42-35-PP]. SECTION 9.0 SEVERABILITY 9.1 If any section, subsection, sentence, clause, phrase or portion of the Act or these Regulations is for any reason held invalid or unconstitutional by any court of competent jurisdiction, that portion shall be deemed a separate, distinct and independent provision and this holding shall not affect the validity of the remaining portions of the Act or these Regulations. 9.2 Nothing contained in the Act or these Regulations shall be construed to affect any other provisions of Title 23 of the Rhode Island General Laws, as amended.
216-RICR-40-10-6: 216-RICR-40-10-6. Patient Safety Organizations (version Adoption, 01/27/2009 to 04/30/2018) | Justis AI