160360 Privacy and security issues related to the electronic exchange of health information for public health and other secondary data uses

Wednesday, November 7, 2007

John Loft, PhD , Survey Research Division, RTI, International, Chicago, IL
Linda L. Dimitropoulos, PhD , Survey and Computing Sciences, RTI, International, Chicago, IL
Stephanie C. Rizk, MSc , Survey Research Department, RTI, International, Chicago, IL
Robert Bailey , RTI International, Research Triangle Park, NC
Between May 2006 and March 2007 teams from 33 states and 1 territory collected input from a wide variety of stakeholders under the Privacy and Security Solutions for Interoperable Health Information Exchange project. Many of the “scenarios” used to capture the variation in business practices and policies touched on the electronic exchange of personal health information for public health purposes. Initial reports from the state projects indicate that a number of fundamental privacy and security concerns emerge in the context of electronic exchange of health information for public health purposes. Although there is a high level of awareness within the health care community that HIPAA allows for the transfer of information in a public health emergency, there is little consensus on procedures to determine the appropriate amount of information to be disclosed and what factors indicate disclosure to non-covered entities such as law enforcement. In non-emergent situations, this variability is even more pronounced. Some states also uncovered significant misunderstanding within the general public and sometimes within the health care community concerning the routine collection of public health data, and guidelines around the disclosure of the information. This paper will report on practices described by stakeholders and summarize issues related to private and secure transmission of information contained in health records.

Learning Objectives:
Describe key privacy and security issues related to electronic health information exchange for public health and other secondary uses. Articulate differing policies concerning appropriate information use and disclosure between entities Discuss stakeholder concerns about the circumstances and extent of disclosure

Keywords: Health Information Systems, Health Insurance Portability Act

Presenting author's disclosure statement:

Any relevant financial relationships? No
Any institutionally-contracted trials related to this submission?

I agree to comply with the American Public Health Association Conflict of Interest and Commercial Support Guidelines, and to disclose to the participants any off-label or experimental uses of a commercial product or service discussed in my presentation.