216-RICR-10-10-6
216-RICR-10-10-6. Regional Health Information Organization and Health Information Exchange (version Amendment, 07/17/2014 to 08/27/2018)
RULES AND REGULATIONS PERTAINING TO
THE REGIONAL HEALTH INFORMATION ORGANIZATION
AND HEALTH INFORMATION EXCHANGE
[R5-37.7-HIE]
STATE OF RHODE ISLAND AND PROVIDENCE PLANTATIONS
DEPARTMENT OF HEALTH
July 2009
As Amended:
January 2012 (re-filing in accordance with the
provisions of section 42-35-4.1 of the Rhode
Island General Laws, as amended)
June 2014
i
INTRODUCTION
These amended Rules and Regulations Pertaining to the Regional Health Information
Organization and Health Information Exchange [R5-37.7-HIE] are promulgated pursuant to the
authority conferred under §5-37.7 of the General Laws of Rhode Island, as amended, for the
purpose of updating safeguards and confidentiality protections for the Health Information
Exchange (HIE) in order to improve the quality, safety and value of health care, keep
confidential health information secure and confidential and use the HIE to progress toward
meeting public health goals.
Pursuant to the provisions of §42-35-3(a)(3) and §42-35.1-4 of the General Laws of Rhode
Island, as amended, the following were given consideration in arriving at these amended
regulations:
(1) Alternative approaches to the regulations;
(2) Duplication or overlap with other state regulations; and
(3) Significant economic impact on small business.
Based on the available information, no known alternative approach, duplication or overlap
was identified.
Upon promulgation of these amendments, these amended regulations shall supersede all
previous Rules and Regulations Pertaining to the Regional Health Information Organization and
Health Information Exchange promulgated by the Rhode Island Department of Health and filed
with the Secretary of State.
ii
TABLE OF CONTENTS
Page
SECTION 1.0
DEFINITIONS
1
SECTION 2.0
GENERAL PROVISIONS
3
2.1
Purpose and Scope
3
2.2
Participation in the Health Information Exchange (HIE)
3
2.3
Rhode Island Regional Health Information Organization (RHIO)
5
2.4
Special Requirements Pertaining To the Health Information Exchange (HIE) and the
Rhode Island Regional Health Information Organization (RHIO)
7
2.5
Reconciliation With Other Authorities
8
2.6
Professional Responsibilities
9
SECTION 3.0
HIE ADVISORY COMMISSION
9
SECTION 4.0
CONFIDENTIALITY PROTECTIONS
10
4.1
Patient's Rights
10
4.2
Confidentiality Protections
13
4.3
Secondary Disclosure
13
4.4
Authorization Form
13
4.5
Release of Confidential Health information In Conjunction With Legal Proceedings
14
SECTION 5.0
SECURITY REQUIREMENTS
15
5.1
Minimum Security Requirements
15
5.2
Safeguards and Security Measures
15
5.3
Security Framework
15
5.4
Security Management
15
5.5
Separation of Systems
16
5.6
Security Control and Monitoring
16
5.7
Security Assessment
16
SECTION 6.0
IMMUNITY AND WAIVERS
16
6.1
Immunity
16
6.2
Waivers Void
16
SECTION 7.0
PENALTIES – ATTORNEYS' FEES FOR VIOLATIONS
16
7.1
Civil Penalties.
16
7.2
Criminal Penalties
16
7.3
Commission of Crime
17
7.4
Attorneys’ Fees
17
iii
Page
SECTION 8.0
SEVERABILITY
17
SECTION 9.0
INCORPORATION BY REFERENCE
17
REFERENCES
18
1
Section 1.0
Definitions
Whenever used in these Regulations, the following terms shall be construed as follows:
1.1 “Act” means Chapter 5-37.7 of the Rhode Island General Laws, as amended, entitled, “The
Rhode Island Health Information Exchange Act of 2008.”
1.2 “Administrative review” means the administrative processes contained in Rules and
Regulations Pertaining to Practices and Procedures Before the Rhode Island Department
of Health (R42-35-PP), and as otherwise permitted by the Administrative Procedures Act.
1.3 "Authorized representative" means:
(1) A person empowered by the patient participant to assert or to waive the confidentiality,
or to disclose or authorize the disclosure of confidential information, as established by
this chapter. That person is not, except by explicit authorization, empowered to waive
confidentiality or to disclose or consent to the disclosure of confidential information; or
(2) A person appointed by the patient participant to make health care decisions on his or her
behalf through a valid durable power of attorney for health care as set forth in RIGL
§23-4.10-2; or
(3) A guardian or conservator, with authority to make health care decisions, if the patient
participant is decisionally impaired; or
(4) Another legally appropriate medical decision maker temporarily if the patient
participant is decisionally impaired and no health care agent, guardian or conservator is
available; or
(5) If the patient participant is deceased, his or her personal representative or, in the
absence of that representative, his or her heirs-at-law; or
(6) A parent with the authority to make health care decisions for the parent's child.
1.4 "Authorization form" means the form described in §4.5 and by which a patient participant
provides authorization for the RHIO to allow access to, review of, and/or disclosure of the
patient participant's confidential health information by electronic, written or other means.
1.5 "Business associate" means: a business associate as defined by HIPAA, and its implementing
regulations (45 CFR Parts 160-164).
1.6 "Confidential health information" means all identifiable information relating to a patient
participant's health care history, diagnosis, condition, treatment, or evaluation.
1.7 "Coordination of care" means the process of coordinating, planning, monitoring, and/or
sharing information relating to and assessing a care plan for treatment of a patient.
1.8 "Data submitting partner" means an individual, organization or entity that has entered
into a business associate agreement with the RHIO and submits patient participants'
confidential health information through the HIE.
1.9 “De-identified information” means health information that is not individually identifiable,
does not contain any elements that could identify an individual, and could not be used to
identify an individual.
1.10 "Department" means the Rhode Island Department of Health.
2
1.11 “Director” means the Director of the Rhode Island Department of Health or his/her
designee.
1.12 "Disclosure report" means a report generated by the HIE relating to the record of access
to, review of and/or disclosure of a patient's confidential health information received,
accessed or held by the HIE.
1.13 "Electronic mobilization" means the capability to move clinical information
electronically between disparate health information systems while maintaining the accuracy
of the information being exchanged.
1.14 "Emergency" means the sudden onset of a medical, mental or substance abuse or other
condition manifesting itself by acute symptoms of severity (e.g. severe pain) where the
absence of medical attention could reasonably be expected, by a prudent lay person, to
result in placing the patient's health in serious jeopardy, serious impairment to bodily or
mental functions, or serious dysfunction of any bodily organ or part.
1.15 "Health care provider" means any person or entity licensed by this state to provide or
lawfully providing health care services, including, but not limited to, a physician, hospital,
intermediate care facility or other health care facility, dentist, nurse, optometrist, podiatrist,
physical therapist, psychiatric social worker, pharmacist or psychologist, and any officer,
employee, or agent of that provider acting in the course and scope of his or her employment
or agency related to or supportive of health care services.
1.16 "Health care services" means acts of diagnosis, treatment, medical evaluation, referral or
counseling or any other acts that may be permissible under the health care licensing statutes
of this state.
1.17 "Health Information Exchange" or "HIE" means the technical system operated, or to be
operated, by the RHIO under state authority allowing for the statewide electronic
mobilization of confidential health information, pursuant to the Act and these Regulations.
1.18 "HIE Advisory Commission" means the advisory body established by the Department in
order to provide community input and policy recommendations regarding the use of the
confidential health information of the HIE.
1.19 "HIPAA" means the Health Insurance Portability and Accountability Act of 1996, as
amended, and its implementing regulations (45 CFR Parts 160-164).
1.20 “HIPAA Final Omnibus Rule” means the HIPAA regulations promulgated and effective
March 25, 2013.
1.21 “HITECH” means the Health Information Technology for Economic and Clinical Health
Act of 2009, Public Law 111-5 and its implementing regulations.
1.22 "Participant" means a patient participant, a patient participant's authorized representative,
a provider participant, a data submitting partner, the regional health information
organization and the Department, that has agreed to authorize, submit, access and/or
disclose confidential health information via the HIE in accordance with the Act and these
Regulations.
1.23 "Participation" means a participant's authorization, submission, access and/or disclosure
of confidential health information in accordance with the Act and these Regulations.
3
1.24 "Patient participant" means a person who receives health care services from a provider
participant and has agreed to participate in the HIE through the mechanisms established in
the Act and these Regulations.
1.25 “Protected Health Information” means individually identifiable health information
including demographic information that is collected from an individual and is created or
received by a health care provider, health plan, employer or health care clearinghouse that
relates to the past, present, or future physical or mental health or condition of an individual;
the provision of health care to an individual; or the past, present, or future payment for the
provision of health care to an individual that identifies the individual or with respect to
which there is a reasonable basis to believe the information can be used to identify the
individual.
1.26 "Provider participant" means a pharmacy, laboratory or health care provider who is
providing health care services to a patient participant and/or is submitting or accessing
health information through the HIE and has executed an electronic and/or written
agreement regarding disclosure, access, receipt, retention or release of confidential health
information to the HIE.
1.27 "Regional health information organization" or "RHIO" means the organization
designated as the RHIO by the State of Rhode Island to provide administrative and
operational support to the HIE.
1.28 “Regulations” [“these Regulations”] means all sections of the Rules and Regulations
Pertaining to the Regional Health Information Organization and Health Information
Exchange [R5-37.7-HIE]. Unless specifically cited otherwise, all references contained
herein shall be interpreted as pertaining to these Regulations.
1.29 “RIGL” means the General Laws of Rhode Island, as amended.
1.30 “Unanticipated event” means instances in which the provider participant is unavailable
and another health care provider is providing coverage to treat the patient participant.
1.31 “Unsecured Protected Health Information” means Protected Health Information that is
not rendered unusable, unreadable, or indecipherable to unauthorized persons through the
use of a technology or methodology specified by the United States Secretary of Health and
Human Services in guidance issued under section 13402(h)(2) of Public Law 111-5.
Section 2.0
General Provisions
2.1 Purpose and Scope. These Regulations establish safeguards and confidentiality
protections for the Health Information Exchange (HIE) in order to improve the quality,
safety and value of health care, keep confidential health information secure and confidential
and use the HIE to progress toward meeting public health goals.
2.2 Participation in the Health Information Exchange (HIE): A statewide Health
Information Exchange (HIE) has been established pursuant to RIGL §5-37.7 to allow for
the electronic mobilization of confidential health information in Rhode Island. Confidential
health information shall only be accessed, released or transferred from the HIE in
accordance with the Act, these Regulations, and any other applicable state or federal law or
4
regulation.
(a) Participation in the HIE is voluntary; and may be terminated at any time. Patients and
health care providers shall have the choice to participate in the HIE, as defined by the
Act and these Regulations. Patients shall agree to participate by signing an authorization
form provided by the HIE. Patients may terminate their participation in the RI HIE
pursuant to §4.1(f).
(b) Regardless of a patient’s participation status, provider participants shall continue to
maintain their own medical records, meeting the documentation and other standards
imposed by otherwise applicable law and the prevailing community standard of care.
(c) Individuals shall be informed about the opportunity to enroll in the HIE through
provider participants and other publicly available means. Individuals will be informed
about the HIE through materials that explain the context and process of HIE enrollment,
including any and all choices available to the individual such as identifying which
provider organizations will be able to view their own health care information through
the HIE.
(d) Individuals will be informed that by enrolling in the HIE, at a minimum, they are
authorizing health care providers that care for them in emergencies or other
unscheduled events, to access their health information through the RI HIE on a
temporary basis. Individuals will also be informed that in addition to the ability to
terminate enrollment in the HIE, they have the ability to revoke authorization of a
provider/provider organization to further access their health information through the
HIE consistent with §4.1 of these Regulations.
(e) The RHIO shall maintain a dedicated telephone number staffed with qualified personnel
who can respond to individuals’ questions related to enrollment choices and processes.
If there are remaining concerns or complaints after contacting the RHIO, individuals
can contact the Department of Health “Health Information Line.”
(f) The RHIO shall maintain a process for reviewing and resolving complaints related to it,
and to assist patient participants in resolving complaints.
(1) The RHIO and all provider participants will accept complaints pertaining to the RI
HIE. Provider participants will forward complaints to the RHIO.
(2) The RHIO will appoint a Privacy Officer who will review all complaints.
Complaints will not be public and will be kept confidential as permitted by law.
Any confidential health information contained in the complaint will be protected in
accordance with applicable state and federal law.
(3) Neither the RHIO nor provider participants will retaliate, discriminate against,
intimidate, coerce or otherwise reprise patient participants or patient advocates
relating to the filing of a complaint or for filing a complaint.
(4) The RHIO will contractually require provider participants to comply with HIPAA,
including establishing and implementing HIPAA compliant policies and procedures.
(5) Patients may lodge a complaint with the HIE provider participant directly, with the
RHIO or with the Department of Health. If a complaint is lodged directly with the
RHIO and the RHIO refers the patient to the provider participant and the provider
5
participant cannot directly resolve the complaint or believes the complaint is in
error, the patient may then submit it to the RHIO Privacy Officer for review and
assistance as requested by the patient participant.
(6) All patient participants lodging complaints directly with the RHIO will be directed
to fill out a patient complaint form and will be given assistance if requested. If the
complaint involves an HIE provider participant, the RHIO will notify the HIE
provider participant if it addresses actions by the provider participant.
(7) Any complaint regarding breach of security, if appropriate, may invoke the response
to breach procedures by the RHIO.
(8) The RHIO shall maintain copies of all written patient complaint forms.
(9) The disposition of the complaint shall be documented by the RHIO Privacy Officer
as part of the complaint process.
(10) For complaints lodged directly to the Department, the Department will follow its
usual process for investigating complaints and the complaint shall remain
confidential to the public until it has been resolved. If applicable, once it is
resolved, the Department will notify the RHIO Privacy Officer and/or provider
participant. Any patient participant wishing to lodge a verbal complaint may do so
by calling the Department of Health “Health Information Line.”
(11) Any complaint lodged by a patient participant with the provider participant, the
RHIO or the Department shall be resolved within thirty (30) days of submission.
(12) The Department reserves the right to access the records of complaints received by
the RHIO and the resolution of such complaints.
(g) Participation in the HIE shall have no impact on the content of or use or disclosure of
confidential health information of patient participants that is held in locations other than
the HIE.
(h) Nothing in the Act or these Regulations shall be construed to limit, change or otherwise
affect entities' rights or obligations to exchange confidential health information in
accordance with other applicable laws.
(i) Nothing in the Act or these Regulations shall interfere with or impact upon any rights or
obligations imposed by the Workers Compensation Act as contained in RIGL Title 28,
Chapters 29 through 38.
(j) The Department is also considered a participant for public health purposes.
2.3 Rhode Island Regional Health Information Organization (RHIO).
(a) The RHIO shall, subject to and consistent with the Act and these Regulations and
contractual obligations it has with the State of Rhode Island, be responsible for all
administrative, operational, and financial functions to support the HIE, including, but
not limited to, implementing and enforcing policies for receiving, retaining,
safeguarding and disclosing confidential health information as required by the Act.
(b) The RHIO is deemed to be the steward of the confidential health information for which
it has administrative responsibility.
6
(c) The RHIO shall develop and implement current policies and procedures including, but
not limited to, the following topics:
(1) Participant enrollment (both health care provider and consumer) that is consistent
with §2.2 (a) of these Regulations;
(2) Participant participant’s termination of enrollment that is consistent with §§ 2.2(a)
and 4.0 of these Regulations;
(3) Termination of patient participant authorization for provider access that is consistent
with §4.1(c) of these Regulations;
(4) Handling patient participant complaints and inquiries that is consistent with §2.2(c )
of these Regulations;
(5) The process through which a patient participant can obtain a copy of his or her
confidential health information from the HIE that is consistent with §4.1(a) of these
Regulations;
(6) The process through which a patient participant can obtain a copy of the disclosure
report pertaining to his or her confidential health information consistent with §4.1(d)
of these Regulations;
(7) Patient participant requests to amend his or her own information through the
provider participant consistent with §2.4(c) of these Regulations;
(8) Tiered access to confidential health information (i.e., criteria and controls to obtain
varying degrees of access to data maintained by the HIE) consistent with §2.4 of
these Regulations;
(9) Privacy, confidentiality and security pertaining to access and maintenance of patient
participant confidential health information consistent with §4.0 and §5.0 of these
Regulations;
(10) Temporary access to HIE data by provider participants that need to treat a person in
emergencies or other unanticipated events consistent with Section §2.2(a) of these
Regulations; and
(11) Patient participant notification, if required by either RIGL §11-49.2 [Rhode Island
Identity Theft Protection Act of 2005] or the HIPAA Final Omnibus Rule, regarding
a detected breach of the security of the system of the HIE that may have resulted in
the unauthorized access, use or disclosure of protected health information, personal
information or Unsecured Protected Health Information consistent with §4.1(e) of
these Regulations.
(d) The RHIO shall utilize a committee structure that encourages community involvement
and transparency in the process of the development and implementation of its policies.
(e) Patient participants have the right to access the RHIO’s notice of privacy practices
which will be posted on the RHIO’s websites, www.riqi.org and www.currentcareri.org.
The Notice of Privacy Practices will be written in plain language and will contain
applicable information such as: the uses and disclosures of PHI through the HIE, patient
participants’ individual rights, the RHIO’s responsibilities regarding the privacy of
patient participants’ information and the complaint process.
7
(f) In the event that the RHIO fails to comply with these Regulations or has policies that do
not comply with federal and state laws, rules and regulations, the Director may notify
the RHIO by certified or registered mail or by personal service setting forth the
failure(s) and the RHIO shall be given the opportunity to cure such failure within the
time designated by the Director. If the RHIO does not cure the failure, the Department
may invoke contractual remedies, require specific monitoring or supervision to occur,
or limit or suspend actions of the RHIO until such time as the corrective action has
cured the failure. The Department may also notify the Secretary of the United State
Department of Health and Human Services and the Rhode Island Department of
Attorney General if the Department of Health believes the failure to comply with these
Regulations amounts to a HIPAA violation. The RHIO, or the Department may request
a prompt and fair hearing in accordance with RIGL §42-35-9. Nothing herein shall
limit the authority of the jurisdiction conferred upon the Department of Attorney
General to bring an action against the RHIO pursuant to Section 7.0 of these
Regulations for a violation of these Regulations and/or HITECH.
(g) In the event of the insolvency or involuntary dissolution of the RHIO, the assets and
operations comprising the HIE, including the protection of the protected health
information of the enrollees of the HIE, shall be transitioned or transferred in
accordance with an Order of a court of proper jurisdiction.
(h) In the event of a voluntary dissolution of the RHIO, the RHIO will give the Department
thirty (30) days’ notice. The Department has a contractual right of first refusal to
purchase only the assets comprising the HIE at the appraised value.
(i) In the event of either of the above, the RHIO shall be responsible to safeguard the
protected health information in its care, custody and control until the PHI has been
transferred to another entity.
2.4 Special Requirements Pertaining To the Health Information Exchange (HIE) and the
Rhode Island Regional Health Information Organization (RHIO). Pursuant to RIGL
§5-37.7-4(e), the HIE and the RHIO have an obligation to maintain, and abide by the terms
of, HIPAA-compliant business associate agreements, as well as:
(a) The obligation to use appropriate safeguards to prevent use or disclosure of confidential
health information in accordance with HIPAA, RIGL §5-37.3 [Confidentiality of Health
Care Communications and Information Act] and the Act;
(b) Not to use or disclose confidential health information other than as permitted by
HIPAA, RIGL 5-37.3 [Confidentiality of Health Care Communications and Information
Act] and the Act. The RHIO will maintain user access permission profiles to determine
which PHI may be accessed by authorized users according to specific role classification
and shall implement policies and procedures regarding user authentication;
(c) In response to a request by a patient participant to make an amendment to his/her PHI
contained in the HIE, the RHIO will provide the patient participant with a “Request to Amend
Health Information” form to submit to the originating provider participant and if so directed by
the provider participant, will amend the record in accordance with HIPAA, the Act and
these Regulations. The “Request to Amend Health Information” form shall be available from
the CurrentCare website (www.currentcareri.org), by calling the RHIO, or by requesting the
8
form in writing.
(1) As soon as possible, but no later than sixty (60) days after receipt of a request from
a patient participant to amend health information, the provider participant shall
either forward the corrected information to the RHIO for processing or notify the
patient participant, in writing, why the request to amend health information has been
denied.
(2) As soon as possible, but no later than thirty (30) days after receipt of a request from
a provider participant to amend a confidential health care record, the RHIO/HIE
shall process the request and notify the provider participant, in writing, that the
requested amendment to health information has been completed.
(d) If the patient requests a change to his or her CurrentCare record, and the RHIO
determines that the change is due to an operational issue, the RHIO will address the
error pursuant to its internal error resolution procedures by making the correction and
notifying the patient participant within thirty (30) days of the correction that the
correction has been made.
(e) The RHIO shall have written data sharing agreements in place with provider
participants who submit data to the HIE. Such agreements shall, at a minimum, contain
all required business associate agreement components.
(f) The RHIO shall have written end user agreements in place with provider participants
who access data in the HIE. Such agreements shall, at a minimum, describe roles and
responsibilities of both the end user and the RHIO regarding appropriate use of the HIE
and assuring patient rights in accordance with applicable federal and state law.
2.5 Reconciliation With Other Authorities:
(a) The Department has exclusive jurisdiction over the HIE, except with respect to the
jurisdiction conferred upon the Attorney General in RIGL §5-37.7-13.
(b) The Act and these Regulations shall only apply to the State-designated RHIO’s HIE
system, and do not apply to any other private and/or public health information systems
utilized in Rhode Island, including other health information systems utilized by a health
care provider or other organization that provides health care services.
(c) As the Act and these Regulations provide extensive protection with regard to access to
and disclosure of confidential health information by the HIE, it supplements, with
respect to the HIE only, any less stringent disclosure requirements, including, but not
limited to, those contained in RIGL §5-37.3 [Confidentiality of Health Care
Communications and Information Act], the Health Insurance Portability and
Accountability Act (HIPAA) and its implementing regulations (45 CFR Parts 160-164),
and any other less stringent federal or state law.
(d) The Act and these Regulations shall not be construed to interfere with any other federal
or state laws or regulations which provide more extensive protection than provided in
the Act and these Regulations for the confidentiality of health information.
Notwithstanding such provision, because of the extensive protections with regard to
access to and disclosure of confidential health information by the HIE provided for in
the Act and these Regulations, patient authorization obtained for access to or disclosure
9
of information to or from the HIE or a provider participant shall be deemed the same
authorization required by other state or federal laws including information regarding
mental health (the Rhode Island mental health law, RIGL §40.1-5-1 et seq.); HIV RIGL
§23-6-17); sexually transmitted disease (RIGL §§23-6-17 and 23-11-9); alcohol and
drug abuse (RIGL §23-1.10-1 et seq., 42 U.S.C. §290dd-2) or genetic information
(RIGL §27-41-53, RIGL §27-20-39 and RIGL §27-19-44).
2.6 Professional Responsibilities. In accordance with applicable state laws and regulations
promulgated thereunder, a provider participant that abandons a patient or denies treatment
to a new or existing patient solely on the basis of the patient’s refusal to participate in the
HIE, when the patient’s health information can be obtained from other sources, may be
subject to administrative review by the Department, including, but not limited to the
Department’s Professional Boards, and the Director. The processes contained in Rules and
Regulations Pertaining to Practices and Procedures Before the Rhode Island Department
of Health (R42-35-PP), and as otherwise permitted by the Administrative Procedures Act,
shall apply.
Section 3.0
HIE Advisory Commission
3.1 Pursuant to RIGL §5-37.7-5(c), the Director shall establish a HIE Advisory Commission of
no more than nine (9) members that shall be responsible for recommendations relating to
the type of and use of, and appropriate confidentiality protection for, the confidential health
information of the HIE, subject to regulatory oversight by the Department. The HIE
Advisory Commission shall be responsible for recommendations to the Department, and in
consultation with the RHIO, regarding the use of the confidential health information.
3.2 Pursuant to RIGL §5-37.7-5(c), the Director shall recommend prospective HIE Advisory
Commission members to the Governor, subject to the advice and consent of the Senate.
The membership of the HIE Advisory Commission shall include one (1) person with
experience in HIPAA and privacy and security of health care information requirements, one
(1) person with experience in operations, maintenance and security of complex electronic
databases, one (1) person who is a health care consumer or consumer advocate, one (1)
person who represents a minority or underserved population, one (1) person who has
experience in epidemiology and the use of data for public health purposes, and no more
than three (3) persons employed by a health care delivery organization, at least two (2) of
whom shall be a physician licensed pursuant to RIGL §5-37. The remaining member(s)
shall be selected from business professionals and health care consumers whose experience
and expertise will facilitate the work of the Commission.
3.3 The Director shall appoint a chairperson for the HIE Advisory Commission.
3.4 HIE Advisory Commission members shall be appointed for a term of two (2) years. A
Commission member may be reappointed for an additional term, but shall not be eligible to
serve more than three (3) consecutive terms. RHIO staff and board members shall not be
eligible for appointment to the Commission.
10
3.5 The HIE Advisory Commission shall meet at least annually and shall not vote on any
recommendations regarding the use of confidential health information unless a quorum is
present.
3.6 The HIE Advisory Commission shall report annually to the Department and the RHIO, and
such report shall be made public.
3.7 The HIE Advisory Commission shall actively obtain and consider public input on all
recommendations prior to submitting them to the Director. All meetings of the HIE
Advisory Commission shall be subject to RIGL §42-46 (Open Meetings).
3.8 The Director may recommend to the Governor that any HIE Advisory Commission member
be removed for cause, including but not limited to, failure to attend Commission meetings
on a regular basis.
Section 4.0
Confidentiality Protections
4.1 Patient's Rights. Pursuant to the Act and these Regulations, a patient participant who has
his or her confidential health information transferred through the HIE shall have the
following rights:
(a) To obtain a copy of his/her confidential health information from the HIE by:
(1) Submitting a valid and authenticated request to access the HIE record via the
methods made available by the RHIO.
(2) The form and methods shall be publicly available through posting on the HIE
website (www.currentcareri.org) including calling the CurrentCare information line to
complete and submit the information on the form over the phone. To do so, the
requestor must successfully complete the requirements of the identity verification
process by supplying identifying information through a series of questions initiated
by a RHIO representative over the phone and for the sole purpose of a single
occurrence of a telephone request to submit the form.
(3) If the requestor prefers, he or she may fill out a form in person at the RHIO offices
after identity verification has occurred. The requestor may either obtain an enrollee
request to access record form via the web or request a form be mailed to them.
(4) If neither is possible, then the requestor may send a letter containing the same
information as is required by the form and have it authenticated in the same manner
as the written form.
(b) To designate which provider participant(s) are authorized to access his/her confidential
health information through the HIE by completing a valid and authenticated enrollment
and authorization form setting forth the provider participants who are authorized to have
access to his/her confidential health information through the HIE. The form shall be
publicly available through posting on the HIE website (www.currentcareri.org); or the
patient participant or their authorized representative may request in writing or over the
telephone that a form be sent to them.
(c) A patient participant at any time after enrollment may change his or her authorization
11
for a provider/provider organization to access his/her information through the RI HIE
by completing a valid and authenticated form requesting an amendment or termination
of authorization. The form, along with information about where to submit the form,
shall be publicly available through posting on the HIE website (www.currentcareri.org).
When a patient participant amends or terminates authorization for a provider participant
to access their information through the RI HIE, that provider participant will no longer
have access to the confidential health information through the HIE except in an
emergency circumstance.
(d) To obtain a copy of the disclosure report pertaining to his or her confidential health
information by submitting a valid and authenticated request for a disclosure report. The
forms along with information about where to submit the form shall be publicly available
through posting on the HIE website (www.currentcareri.org); The RHIO will make
every effort to provide disclosure reports in the most prompt manner while recognizing
that state and federal law allow up to sixty (60) days to respond. If extenuating
circumstances arise, the RHIO may have an additional thirty (30) days to provide the
disclosure report to the enrollee. Each request for disclosure history will be addressed
in accordance with 45 C.F.R. §164.528 (a). A charge for a copy of the disclosure report
may be imposed if consistent with state law.
(e) To be notified, if required by either RIGL §11-49.2 [Rhode Island Identity Theft
Protection Act], or the HIPAA Final Omnibus Rule, of a breach of the security system
of the HIE that resulted in the unauthorized access, use or disclosure of personal
information or unsecured protected health information.
(f) To terminate his or her participation in the HIE at any time in accordance with the Act
and these Regulations by submitting a valid and authenticated Revocation of
Authorization form to the RHIO. The form and methods for termination shall be
publicly available through posting on the HIE website (www.currentcareri.org) or the
patient participant or authorized representative may call the RHIO to request a form be
sent to them. If the patient participant does not complete the form at a provider
participant’s facility, the patient participant must be authenticated by a notary public. A
patient participant may also request termination in the HIE by sending a notarized letter
to the RHIO containing the following information:
(1) enrollee’s name (first, middle and last)
(2) date of birth
(3) gender
(4) full address
(5) telephone number (if applicable)
(6) cell phone number (if applicable)
(7) e-mail address (if applicable)
(8) a statement that the patient participant wishes to cancel authorization to participate
in the HIE
(9) the effective date of the request
(10) a statement that the patient participant understands that the termination does not
affect access, use or disclosure of information prior to the effective date of
12
termination.
The RHIO will not deactivate a patient participant’s enrollment until a valid and
authenticated form or letter has been received and recorded by the RHIO.
(g) To revoke access of provider participants to the patient participant’s health information
at any time in accordance with the Act and these Regulations by submitting a valid and
authenticated Revocation of Authorization Form. The form and methods for revocation
of access of provider participant to the patient participant’s health information shall be
publicly available through posting on the HIE website (www.currentcareri.org) or the
patient participant or authorized representative may call the RHIO to request a form be
sent to them. If the patient participant does not complete the form at a provider
participant’s facility, the patient participant must be authenticated by a notary public.
A patient participant may also request revocation of access of provider participant by
sending a notarized letter to the RHIO containing the following information:
(1) enrollee’s name (first, middle and last)
(2) date of birth
(3) gender
(4) full address
(5) telephone number (if applicable)
(6) cell phone number (if applicable)
(7) e-mail address (if applicable)
(8) a statement that the patient participant wishes to revoke access of a provider
participant to the patient participant’s health information in the HIE
(9) the effective date of the request
(10) a statement that the patient participant understands that the revocation of access of a
provider participant does not affect access, use or disclosure of information prior to
the effective date of termination.
The RHIO will not deactivate a provider participant’s access to a patient participant’s
confidential health information through CurrentCare until a valid and authenticated
form or letter has been received and recorded by the RHIO.
(h) Upon a patient participant’s completed termination of enrollment from the HIE, no
additional confidential health information for that patient will be collected by the HIE
and the patient’s confidential health information in the HIE will no longer be accessible
to a provider participant. Nothing herein shall preclude a provider participant from
accessing the provider participant’s own record. The revocation of a patient’s
authorization will not affect the previous disclosures or access to the patient’s health
information while the patient’s authorization and enrollment was in effect.
(i) Since the HIE does not create patient confidential health information, but receives
confidential health information from provider participants, the patient participant may
request to amend his or her own information through the provider participant by
submitting a valid and authenticated request to amend confidential health information
form consistent with these Regulations. The form and methods shall be publicly
available through posting on the HIE website (www.currentcareri.org) or the patient
13
participant or authorized representative may call the RHIO to request a form be sent to
them. The RHIO will respond directly to a patient participant request and follow its
policies and procedures if there is an administrative error that does not require an
amendment to the record received from the provider participant.
4.2 Confidentiality Protections.
(a) A patient participant's confidential health information may only be accessed, released or
transferred from the HIE if the patient participant has enrolled in the HIE and in
accordance with an enrollment/authorization form signed by the patient participant or
the patient's authorized representative. No additional patient participant authorization is
required in the following instances:
(1) To a health care provider who believes, in good faith, that the information is
necessary for diagnosis or treatment of that individual in an emergency; or
(2) To public health authorities in order to carry out their functions as described in
RIGL Titles 5, 21 and 23, and rules promulgated under those titles. These functions
include, but are not restricted to, investigations into the causes of disease, the
control of public health hazards, enforcement of sanitary laws, investigation of
reportable diseases, certification and licensure of health professionals and facilities,
review of health care such as that required by the federal government and other
governmental agencies, and mandatory reporting laws set forth in Rhode Island
General Laws; and
(3) To the RHIO in order for it to effectuate the operation and administrative oversight
of the HIE.
(b) Except as specifically provided by the Act or these Regulations or use for clinical care
or treatment, a patient participant’s confidential health information shall not be accessed
by, given, sold, transferred, or in any way relayed from the HIE to any other person or
entity not specified in the patient participant authorization form meeting the
requirements of §4.4.
(c) The Department reserves the right to review the policies and procedures applicable to
the HIE bi-annually to help assess successes and areas for improvement.
4.3 Secondary Disclosure. Any confidential health information obtained by a provider
participant pursuant to the Act and these Regulations may be further disclosed by such
provider participant with or without authorization of the patient participant to the same
extent that such information may be disclosed pursuant to existing state and federal law,
without regard to the source of the information.
4.4 Authorization Form:
(a) The authorization form for enrollment into the HIE, access to, or the disclosure, release
or transfer of, confidential health information from the HIE shall, at a minimum, contain
the following information in a clear and conspicuous manner:
(1) A statement that the need for and proposed uses of that information is for treatment;
(2) A statement that the authorization for access to, disclosure of and/or release of
14
information may be withdrawn at any future time and is subject to revocation;
(3) A statement that the patient has the right not to participate in the HIE;
(4) The patient's right to choose to:
(i)
Enroll in and participate fully in the HIE and allow access, use and disclosure
of information to all treating providers; or
(ii) Designate only specific health care providers that may access the patient
participant's confidential health information; or
(iii) Designate that access to and disclosure of information may only be accessed in
an emergency situation.
(5) Other information required by the RHIO, in consultation with the Director.
(b) Except as specifically set forth in §4.2(a), the RHIO shall not allow access to or
disclosure of patient participant’s identifiable confidential health information unless it is
to a treating provider and in accordance with the patient participant’s authorization on
the enrollment form.
(c) Except as set forth in §4.2(a), the RHIO will not allow access to or disclosure of a
patient participant’s identifiable confidential health information to a provider participant
unless the recipient has entered into a Data Use Agreement with the RHIO.
(d) The RHIO shall not accept or respond to any authorization form requesting disclosure
of the patient participant’s identifiable health information for any purpose other than to
a treating provider.
(e) Any request to enroll in the HIE or to withdraw or terminate enrollment from the HIE
pursuant to §4.1 shall be on forms which are provided by the RHIO in accordance with
§4.1. Requests to withdraw or terminate enrollment from the HIE shall be made in
accordance with §4.1(f).
4.5 Release of Confidential Health information In Conjunction With Legal Proceedings.
Confidential health information received, disclosed or held by the HIE shall not be subject
to subpoena directed to the HIE or RHIO unless the following procedures have been
completed:
(a) The person seeking the confidential health information has already requested and
received the confidential health information from the health care provider that was the
original source of the information; and
(b) A determination has been made by the Superior Court upon motion and notice to the
patient participant, the HIE or RHIO and the parties to the litigation in which the
subpoena is served that the confidential health information sought from the HIE is not
available from another source and is either relevant to the subject matter involved in the
pending action or is reasonably calculated to lead to the discovery of admissible
evidence in such pending action. The patient participant and the RHIO shall be notified
of the motion and given an opportunity to object to the motion.
(c) Any person issuing a subpoena to the HIE or RHIO pursuant to §4.6 shall certify that
such measures have been completed prior to the issuance of the subpoena.
15
Section 5.0
Security Requirements
5.1 Minimum Security Requirements. The RHIO and HIE shall implement the following
security procedures:
(a) Authenticate the recipient of any confidential health information disclosed by the HIE
in accordance with prevailing industry standards and safeguards pursuant to the Act,
these Regulations and HIPAA (45 C.F.R. §164.312(a)(i) and (d).
(b) Limit authorized access to confidential health information to persons having a need to
know that information. Additional employees or agents may have access to de-
identified information.
(c) Identify an individual or individuals who have responsibility for maintaining safeguards
and security procedures for the HIE, as required by §5.2.
(d) Provide an electronic or written statement to each employee or agent of the RHIO as to
the necessity of maintaining the security and confidentiality of confidential health
information, and of the penalties provided for in the Act and these Regulations for the
unauthorized access, release, transfer, use, or disclosure of this information.
(e) Take no disciplinary or punitive action against any employee or agent of the RHIO for
bringing evidence of violation of the Act and these Regulations to the attention of any
person.
5.2 Safeguards and Security Measures. The RHIO shall have in place appropriate physical,
technical and procedural safeguards and security measures to ensure the technical integrity,
physical safety, and confidentiality of any confidential health information in the HIE. These
safeguards and security measures shall be in place at all times and at any location at which the
RHIO, its workforce members, or its contractors hold or access confidential health information.
Such safeguards and security measures shall comply with state and federal confidentiality laws
including, without limitation, the Health Insurance Portability and Accountability Act of 1996
and its implementing regulations (45 CFR §§160-164), HITECH and the HIPAA Final Omnibus
Rule.
5.3 Security Framework. The RHIO shall develop appropriate and scalable security
standards, policies, and procedures that are suitable for the size and complexity of its
organization.
5.4 Security Management. The RHIO shall address:
(a) Maintenance and effective implementation of written policies and procedures that
conform to the requirements of this Section to protect the confidentiality, integrity, and
availability of the confidential health information that is processed, stored, and
transmitted; to protect against any reasonably anticipated threats or hazards to the
security or integrity of the confidential health information and to monitor, modify and
improve the effectiveness of such policies and procedures, and
(b) Training of the RHIO workforce who access or hold confidential health information
regarding the requirements of the Act, these Regulations and the RHIO's policies and
procedures regarding the confidentiality and security of confidential health information.
16
The RHIO will secure written acknowledgement of training of its employees.
5.5 Separation of Systems. The RHIO shall address:
(a) Maintenance of confidential health information, whether in electronic or other media,
physically and functionally separate from any other system of records;
(b) Protection of the media, whether in electronic, paper, or other format, that contain
confidential health information, limiting access to authorized users and sanitizing and
destroying such media before disposal or release for reuse; and
(c) Physical and environmental protection, to control and limit physical and virtual access
to places and equipment where confidential health information is stored or used.
5.6 Security Control and Monitoring. The RHIO shall address:
(a) Identification of those authorized to have access to confidential health information and
an audit capacity to detect unlawful, unauthorized or inappropriate access to
confidential health information, and
(b) Measures to prevent unauthorized removal, transmission or disclosure of confidential
health information in the HIE.
5.7 Security Assessment. The RHIO shall address:
(a) Periodic assessments of security risks and controls, as determined appropriate by the
RHIO, to establish if its controls are effective, to correct any deficiency identified, and
to reduce or eliminate any vulnerabilities.
(b) System and communications protection, to monitor, control, and protect RHIO uses,
communications, and transmissions involving confidential health information to and
from entities authorized to access the HIE.
Section 6.0
Immunity and Waivers
6.1 Immunity. Any health care provider who relies in good faith upon any information
provided through the HIE in his, her or its treatment of a patient, shall be immune from any
criminal or civil liability arising from any damages caused by such good faith reliance.
This immunity does not apply to acts or omissions constituting negligence or reckless,
wanton or intentional misconduct.
6.2 Waivers Void. Any agreement purporting to waive the provisions of the Act or these
Regulations is declared to be against public policy and void.
Section 7.0
Penalties – Attorneys' Fees for Violations
7.1 Civil Penalties. Anyone who violates the provisions of the Act and these Regulations may
be held liable for actual and exemplary damages.
7.2 Criminal Penalties. Anyone who intentionally and knowingly violates the provisions of
the Act and these Regulations shall, upon conviction, be fined not more than ten thousand
17
dollars ($10,000) per patient, per violation, or imprisoned for not more than one (1) year, or
both.
7.3 Commission of Crime. The civil and criminal penalties in these Regulations shall also be
applicable to anyone who obtains confidential health information maintained under the
provisions of the Act and these Regulations through the commission of a crime.
7.4 Attorneys' Fees. Attorneys' fees may be awarded at the discretion of the Court, to the
successful party in any action under the Act and these Regulations.
Section 8.0
Severability
8.1 If any provision of the Act or these Regulations is held by a court of competent jurisdiction
to be invalid, that invalidity shall not affect the remaining provisions of the Act and these
Regulations, and to this end the provisions of the Act and these Regulations are declared
severable.
Section 9.0
Incorporation by Reference
9.1 Pursuant to RIGL §42-35-3.2, all state and federal laws and regulations specifically cited in
these Regulations are hereby incorporated by reference and are deemed to be part of these
Regulations.
18
REFERENCES:
“Confidentiality of Health Care Communications and Information Act," RIGL §5-37.3
Available online: http://www.rilin.state.ri.us/Statutes/TITLE5/5-37.3/INDEX.HTM
Health Insurance Portability and Accountability Act of 1996, Public Law 104-191 enacted on
August 21, 1996. Available online: http://aspe.hhs.gov/admnsimp/pl104191.htm
U.S. Department of Health and Human Services - Subchapter C - Administrative Data Standards
and Related Requirements [HIPAA implementation regulations] 45 CFR §§160-164
Available online: http://ecfr.gpoaccess.gov/cgi/t/text/text-
idx?sid=9ee668e16073c0e4b9ed42cce6db1baf&c=ecfr&tpl=/ecfrbrowse/Title45/45cfrv1_02.tpl
HIE_Final_June2014.doc
Friday, 20 June 2014