HIPAA Policy-07
About This Policy
Effective: 07/01/2015
Last Updated: 12/13/2021
Responsible University Office:
Office of the Chief Privacy Officer
Responsible University Administrator:
Chief Privacy Officer
mawerlin@iu.edu
Policy Contact:
HIPAA Privacy Officer
HIPAA Security Officer
hipaa@iu.edu
- Print or view a PDF of this policy
- Many policies are quite lengthy. Please check the page count before deciding whether to print.
Scope
This policy applies to the workforce members in the designated Indiana University (IU) HIPAA Covered Healthcare Components and HIPAA Affected Areas, anyone rendering services as a Business Associate, and anyone who creates, receives, maintains, or transmits Protected Health Information (PHI) in any capacity at IU, including, but not limited to, faculty, staff, students, trainees, volunteers, visiting scholars, and third-party agents. For the purposes of this policy, all of the above will be referred to as workforce members.
Policy Statement
A. Notice of Privacy Practices
- IU HIPAA covered healthcare components that provide health care or are part of the IU health plans shall maintain a Notice of Privacy Practices (Notice) that explains how protected health information may be used and disclosed, as well as an individual’s rights and the provider’s legal duties under HIPAA and HITECH.
Designated covered healthcare components are responsible for complying with this policy and for developing operating procedures that implement it. - The Notice shall be written in plain language and shall contain the elements required by the HIPAA Privacy Rule.
- Covered healthcare components may not use or disclose protected health information in a manner inconsistent with their Notice.
B. Distribution/Publication of the Notice
- The Notice will be provided to individuals with whom the covered healthcare component has a direct treatment relationship:
- No later than the date of the first service delivery, including service delivered electronically to such individual;
- Upon request; and
- On or after the effective date of a revision of the Notice.
- Following an emergency treatment situation, the covered healthcare component will provide the individual with the Notice as soon as reasonably practicable.
- In the case of patients who are minors, Notice should be given to the minor’s parent or legal guardian.
- The Notice must be posted in a prominent location where it is reasonable to expect that patients will see and have an opportunity to read the Notice.
- If the Notice is revised, the covered healthcare component must post the revised Notice and make the Notice available upon request. Former Notices must be retained for six (6) years.
- The covered healthcare component shall prominently post the Notice on any web sites it maintains that provide information about its customer services or benefits, and it shall make the Notice available electronically through its web site.
C. Acknowledgement of the Notice of Privacy Practices
- Except in an emergency treatment situation, reasonable effort shall be made by the covered healthcare component to obtain a written acknowledgement from the patient or the patient’s legally authorized representative that he or she has received the Notice.
- Documentation of reasonable attempts to provide the current Notice shall be maintained in the medical record. Refusals to sign the acknowledgement or refusals to accept the Notice shall also be documented.
Reason for the Policy
The Health Insurance Portability and Accountability Act (HIPAA) requires that health plans and covered health care providers develop and distribute a Notice of Privacy Practices (Notice) which describes the provider’s uses and disclosures of protected health information, an individual’s rights with regard to his/her own protected health information, the provider’s duties with regard to the individual’s protected health information, the complaint process, a contact number, and the effective date of the Notice.
This policy describes IU’s Notice of Privacy Practices, the method for distributing the Notice and documenting its distribution.
Definitions
See Glossary of HIPAA Related Terms for complete list of terms.
History
07/01/2015 Effective Date
08/01/2016 Updated retention requirements for NPPs, added link to Glossary
06/xx/2017 Published on University policy site
12/13/2021 Updated policy contacts
Related Information
HIPAA Privacy Rule
45 CFR 164.520