Scope
HIPAA Policy-02
HIPAA Policy-02
Effective: 07/22/2013
Last Updated: 12/13/2021
Responsible University Office:
Office of the Chief Privacy Officer
Responsible University Administrator:
Chief Privacy Officer
mawerlin@iu.edu
Policy Contact:
HIPAA Privacy Officer
HIPAA Security Officer
hipaa@iu.edu
This policy applies to the workforce members in the designated Indiana University (IU) HIPAA Covered Healthcare Components and HIPAA Affected Areas, anyone rendering services as a Business Associate, and anyone who creates, receives, maintains, or transmits Protected Health Information (PHI) in any capacity at IU, including, but not limited to, faculty, staff, students, trainees, volunteers, visiting scholars, and third-party agents. For the purposes of this policy, all of the above will be referred to as workforce members.
Workforce members shall limit the amount of PHI requested, used, or disclosed to others to the minimum amount necessary to achieve the specific purpose of that use, request, or disclosure.
This limitation does not apply when PHI is:
A. Use of Protected Health Information (PHI)
B. Disclosures of Protected Health Information (PHI)
C. Requests for Protected Health Information (PHI)
Note: Uses or disclosures that impermissibly involve more than the minimum necessary information, in violation of §§ 164.502(b) and 164.514(d), may qualify as breaches.
This policy establishes limits regarding the amount of PHI which may be used or disclosed for an intended purpose to the minimum necessary, in accordance with HIPAA and HITECH privacy regulations, in-conjunction with existing state laws, federal laws, and Indiana University Policy covering human subjects, security and privacy.
Individually Identifiable Health Information (IIHI): A subset of health information, including demographic information collected from an individual, and: (1) is created or received by a health care provider, health plan, employer, or health care clearinghouse; and (2) relates to the past, present, or future physical or mental health or condition of an individual; the provision of health care to an individual; or the past, present, or future payment for the provision of health care to an individual; and identifies the individual or there is a reasonable basis to believe the information can be used to identify the individual.
Minimum Necessary: A standard that requires covered entities to take reasonable steps to limit the use or disclosure of, and requests for PHI to the minimum necessary to accomplish the intended purpose. The minimum necessary standard does not apply to certain uses or disclosures such as those requests by a health care provider for treatment purposes, disclosures to the individual who is the subject of the information or pursuant to an individual’s authorization.
Protected Health Information (PHI): Individually identifiable health information held or transmitted by a covered entity or its business associate in any form or medium, whether electronic, on paper or oral.
See Glossary of HIPAA Related Terms for complete list of terms.
7/22/2013 Effective Date
1/13/2016 Updated Definitions Section
08/01/2016 Added link to Glossary, updated bad links
11/10/2016 Added links to IU Policies
06/xx/2017 Published on University Policies site
12/13/2021 Updated policy contacts and links
HIPAA Regulations
45 CFR §164.502
HITECH Regulations
42 CFR: Part 412
42 CFR: Part 413
42 CFR: Part 422
42 CFR: Part 495
45 CFR: Subtitle A Subchapter D
Related IU Policies
HIPAA-P01 – Uses and Disclosures of Protected Health Information
HIPAA-P04 – IU Fundraising
IT-12 – Security of Information Technology Resources
IT-12.1 – Security of Mobile Devices