Showing posts with label Health. Show all posts
Showing posts with label Health. Show all posts

Sunday, October 28, 2012

Better Policies for De-Identified Health Data

The staggering amount of personal health data now being collected for treatment or billing purposes has a life beyond the doctor's clipboard. That data is collected, stripped of personally identifying information ("de-identified") and re-used in ways that are vital for medical breakthroughs, improving patient care, or predicting public health trends.  And it's just as valuable when used for targeted marketing campaigns or eliminating inefficiencies in the healthcare industry.  

HIPAA restricts uses of identifiable health information for secondary purposes; but information that is de-identified per HIPAA standards is largely not subject to federal regulation.  As a result, de-identified health data is in high demand.

The HIPAA de-identification standards were controversial when introduced in 2000.  The reason: no record of personal information can be truly de-identified to the point where there is no risk of becoming identifiable. The Department of Health and Human Services acknowledged this risk when approving the standard, but at the time said it was comfortable with "a reasonable balance between the risk of identification and the usefulness of the information."

Time has not erased the initial concerns about the de-identification standards. Those concerns appear to be on the rise and fall into three categories:  1) sufficiency of the methods used for de-identification; 2) lack of accountability for unauthorized or inappropriate re-identification; and 3) disapproval of certain uses of de-identified data.  

In 2009, CDT began exploring concerns about HIPAA de-identification. In October 2011, we held a workshop for about 50 academic, industry and consumer stakeholders to discuss some policy ideas for addressing de-identified data concerns.  A paper based on the findings of that workshop will be published by the Journal of the American Medical Informatics Association. (An online version of the paper was published in June 26, 2012.)

The paper includes more details on the following policy options for addressing concerns about de-identified health data:

•    Prohibiting by law or contract the unauthorized re-identification of de-identified data;
•    Ensuring strong, dependable de-identification methods through consistent review of safe harbor methodology and objectively vetting statistical approaches;
•    Requiring reasonable security safeguards for de-identified data (today no such safeguards are required); and
•    Providing greater transparency to the public regarding uses of de-identified data.

CDT believes these policy ideas merit greater discussion.  De-identification should remain an important tool for protecting privacy while preserving the availability of data for uses critical to advancing a more effective and efficient healthcare system. 


View the original article here

Thursday, September 27, 2012

Oversight of Government Privacy, Security Rules for Health Data Questioned

Oversight and accountability for following federal privacy and security rules is critical if the public is going to trust that the next generation of electronic health care providers, insurers, and billing services can protect the privacy of their medical information.  A recent report by the Government Accountability Office questions whether sufficient work is being done to build that public trust.

The GAO report says the Department of Health and Human Services has failed to issue new rules for protecting personal health information and lacks a long-term plan for ensuring that those new rules are being followed.  The HHS Office for Civil Rights (OCR), which is responsible for overseeing these efforts, acknowledged these concerns but noted that rules are winding their way through government channels and that they have "taken the necessary first steps towards establishing a sustainable" oversight program.   

The report's two main concerns are: (1) the urgent need for guidance on de-identification methods, and (2) lack of a long-term plan for auditing covered entities and business associates for compliance with federal privacy and security rules (specifically, HIPAA and HITECH).

De-Identification Guidance

De-identification is a tool that enables health data to be used for a broad range of purposes while minimizing the risks to individual privacy.  Under HIPAA, there are two methods that can be used to de-identify health data. The first is the safe harbor method, which merely requires the removal of 18 specific categories of identifiers, such as name, address, dates of birth or health care services, and other unique identifiers.  The second is the expert determination method that certifies that the data, in the hands of the intended recipient, raises a very small risk of re-identification. The safe harbor method is static and presumes that the removal of the 18 categories of identifiers translates into very low risk of re-identification in all circumstances.

In HITECH, Congress directed HHS to complete a study of the HIPAA de-identification standard by February 2010.  Though covered entities rely more on the safe harbor method because it is easier to understand and more accessible, OCR aimed to produce guidance that would "clarify guidelines for conducting the expert determination method of de-identification to reduce entities reliance on the Safe Harbor method," according to the report.  Two years later and notwithstanding its good intentions, OCR has not released this guidance.  

CDT has met with industry and consumer stakeholders about how to improve federal policy regarding de-identified health data since 2009. CDT also recently published an article in JAMIA proposing a number of policies to strengthen HIPAA de-identification standards and ensure accountability for unauthorized re-identification.  

The OCR should issue the required guidance on de-identification without further delay and continue seeking public feedback on how to build trust in uses of de-identified data.  Foot dragging on this issue risks impeding progress on the ability to monitor the public's health in ways that go far beyond mere notification and routine reporting of symptoms, diagnoses, etc.  With these new capabilities in place, public health officials can move beyond traditional detection and response to outbreaks, enabling earlier disease detection, allowing public health officials to take a more active role monitoring health issues from cancer screening to adult immunizations to HIV.

Ensuring Compliance

Routine audits help ensure that covered entities and business associates comply with HIPAA and HITECH regulations.  Audits also provide OCR with important information about how entities covered by HIPAA and HITECH are implementing critically important privacy and security protections, and potentially surface issues needing further regulatory guidance and helping OCR better determine when penalties for noncompliance are warranted.  

HITECH directed HHS to audit entities covered by HIPAA for compliance with HIPAA and new HITECH requirements; OCR officials began those audits earlier this year. The report states that OCR has no plan to sustain these audits beyond 2012; the report also notes that HHS does not have a defined plan for including HIPAA business associates in its audits. HHS responded that OCR plans to review the pilot audit program at the end of this year and move forward with an audit program after that step is complete.

If the public is to trust that the privacy of their health information is well protected, it must know where that information is going and how it's being used. The report highlights the importance of audits as an effective mechanism for accountability. CDT is encouraged by the progress OCR has made to date in its pilot audit program, and we are pleased to see HHS commit to learning from the pilots to developing and implementing a sustained plan for auditing compliance with federal privacy and security regulations. 


View the original article here

Better Policies for De-Identified Health Data

The staggering amount of personal health data now being collected for treatment or billing purposes has a life beyond the doctor's clipboard. That data is collected, stripped of personally identifying information ("de-identified") and re-used in ways that are vital for medical breakthroughs, improving patient care, or predicting public health trends.  And it's just as valuable when used for targeted marketing campaigns or eliminating inefficiencies in the healthcare industry.  

HIPAA restricts uses of identifiable health information for secondary purposes; but information that is de-identified per HIPAA standards is largely not subject to federal regulation.  As a result, de-identified health data is in high demand.

The HIPAA de-identification standards were controversial when introduced in 2000.  The reason: no record of personal information can be truly de-identified to the point where there is no risk of becoming identifiable. The Department of Health and Human Services acknowledged this risk when approving the standard, but at the time said it was comfortable with "a reasonable balance between the risk of identification and the usefulness of the information."

Time has not erased the initial concerns about the de-identification standards. Those concerns appear to be on the rise and fall into three categories:  1) sufficiency of the methods used for de-identification; 2) lack of accountability for unauthorized or inappropriate re-identification; and 3) disapproval of certain uses of de-identified data.  

In 2009, CDT began exploring concerns about HIPAA de-identification. In October 2011, we held a workshop for about 50 academic, industry and consumer stakeholders to discuss some policy ideas for addressing de-identified data concerns.  A paper based on the findings of that workshop will be published by the Journal of the American Medical Informatics Association. (An online version of the paper was published in June 26, 2012.)

The paper includes more details on the following policy options for addressing concerns about de-identified health data:

•    Prohibiting by law or contract the unauthorized re-identification of de-identified data;
•    Ensuring strong, dependable de-identification methods through consistent review of safe harbor methodology and objectively vetting statistical approaches;
•    Requiring reasonable security safeguards for de-identified data (today no such safeguards are required); and
•    Providing greater transparency to the public regarding uses of de-identified data.

CDT believes these policy ideas merit greater discussion.  De-identification should remain an important tool for protecting privacy while preserving the availability of data for uses critical to advancing a more effective and efficient healthcare system. 


View the original article here

Benefits of Streamlining CA State and Federal Health Privacy Laws Stalled

An initiative aimed at making California's health privacy laws easier to understand and more streamlined with federal standards has stalled.  A year into this harmonization of state and federal standards finds the program needs focus, lacks adequate transparency and isn't providing enough opportunity for public input. CDT believes industry and consumers could benefit from the effort, but changes are needed to make the initiative a success.

The harmonization effort is aimed at eliminating conflicts, confusion and inconsistencies between the primary health privacy laws at the state and federal level. An advisory group, the Privacy and Security Steering Team (PSST), will provide its harmonizing recommendations to the agency that oversees California's health privacy laws.  The agency will give the recommendations to the state legislature as a proposed amendment to the state's primary health law, which, if adopted, could lead to significant changes.

Consumer's Union (CU) and CDT recently issued a joint letter endorsing efforts to make health privacy and security policy in California more protective for consumers and less burdensome to industry. Success here is critical, the letter says, "to securing public trust in the use of [health information technology] to improve individual and population health."

However, both organizations expressed concerns about the lack of focus and transparency of the effort to date. CU and CDT specifically called on the PSST to release work product from the law harmonization deliberation process to include:

detailed explanations of what legal standards each recommendation would specifically change,precisely how the legal standards will be changed;and a justification or the rationale behind each recommendation.

To better focus the project, CU and CDT also call on the PSST to consider addressing areas or issues lacking legal standards or safeguards for personal health information, or areas where current policies are not well understood or insufficiently enforced. Such policy gaps allow for the use and transfer of personal health information in ways that could undermine public trust, creating an environment where individuals do not feel safe or confident utilizing HIT tools.

CDT recently became a member of the PSST and is committed to helping reach the goal of building trust in the use of HIT by making California health privacy law clearer and more comprehensive.


View the original article here

Monday, September 24, 2012

'Safe Data' Strategies for Health Info on Mobile Devices

Consumer use of mobile technologies to stay healthy or manage a chronic health condition is increasing; likewise, an increasing number are using these technologies as a digital link to their doctors.  Yet, unlike health care providers who must follow federal privacy and security rules when using mobile technologies to share a patient's health information, no such rules apply to consumers or their devices.

Building and maintaining consumer and patient trust in the use of mobile devices is key to delivering on the promise that these mobile tools can bring to improving patient care.  And a key to cultivating that trust is building basic security safeguards into those devices.
CDT teamed up with the law firm of Manatt, Phelps & Phillips LLP to develop "Strategies for Safeguarding Patient-Generated Health Information Created or Shared Through Mobile Devices." The paper comes from CDT and Manatt's work with the Robert Wood Johnson Foundation's Project HealthDesign, which is exploring patients' use of personal health applications to promote better health decision-making by both patients and providers.

The paper discusses what factors should be considered when protecting patient-generated health information created on or shared through mobile devices, including:

•    The complexity and cost of the security measure;
•    The ability (or willingness) of the patient or consumer to deploy the security measure;
•    The effect the security measure will have on the health or health care management; and
•    The probability of potential risks to the information, and the potential consequences of a breach of information.

The paper also recommends specific strategies for securing information on patient mobile devices; such strategies include providing patients with clear information on privacy and security risks and providing them with technical tools to help them manage those risks.


View the original article here