Confidentiality for Health Centers Toolkit
The Confidentiality for Health Centers Toolkit HIPAA Privacy documents have been updated to meet current rules and regulations. The 42 CFR Part 2 documents are currently being revised. Current subscribers will be notified once revisions are complete and can still access the Toolkit. If you have any questions, please email training@feldesman.com.
First issued nearly two decades ago, the HIPAA Privacy Rule requires covered entities, including health centers, to protect patient health information from unauthorized uses and disclosures and to respond to patient requests to access, amend and account for disclosures of their health information. To ensure compliance with the HIPAA Privacy Rule, covered entities must have a HIPAA Privacy Officer and develop written policies and procedures, training and education, reporting and investigation mechanisms, and strategies to mitigate the harmful effects of impermissible uses or disclosures. In 2013, the Office for Civil Rights issued a “Final Rule” that strengthened the privacy and security protections for health information under HIPAA and finalized the Breach Notification Rule. These changes, and the possibility for additional changes soon, have left many health centers wondering how best to ensure they are HIPAA compliant.
In addition, as health centers add or enhance their substance use disorder services, they may also have to comply with the federal substance use disorder confidentiality regulations at 42 CFR Part 2 (“Part 2”). Part 2 is more strict than the HIPAA Privacy Rule, requiring specific patient consent to disclose Part 2 protected records for purposes of treatment, payment and health care operations, unless one of a very limited number of exceptions applies.
The Office of the National Coordinator for Health IT (ONC)’s Cures Act (Info Blocking) Final Rule requires “actors,” including health center, to respond to requests for access, exchange and use of electronic health information (EHI) without unreasonable delay, unless an exception applies. The ONC’s Cures Act Final Rule defines eight exceptions that offer actors certainty that, when their practices with respect to accessing, exchanging, or using EHI meet the conditions of one or more exceptions, such practices will not be considered information blocking. If an actor’s response does not meet the exception, allegations of information blocking require a fact-based assessment as to whether a delay or denial of a request for access, exchange or use of EHI would be considered an interference under the ONC’s Cures Act Final Rule. That assessment would also determine whether the interference is with the legally permissible access, exchange, or use of EHI; whether the actor engaged in the practice with the requisite intent; and whether the practice satisfied the conditions of an exception.
Feldesman’s Confidentiality for Health Centers Toolkit is designed to help health centers maintain and improve compliance with applicable federal confidentiality and privacy laws and regulations, including the HIPAA Privacy Rule, the HIPAA Breach Notification Rule, Part 2, and the ONC's Cures Act. The Toolkit includes customizable sample policies, procedures, and forms, including:
- Privacy Officer Job Description: Sample
- Authorization for Disclosure of PHI: Sample Form
- Breach Analysis and Notification: Sample Policy and Procedure
- Breach Notification to Affected Individuals: Sample Letter
- Disclosing PHI to Business Associates: Sample Policy and Procedure
- Business Associate Agreement: Sample
With greater attention to enforcement, now is the time to build or assess and improve your health center’s compliance with the applicable federal confidentiality and privacy laws and regulations.
View the Table of Contents on the Agenda tab.
TABLE OF CONTENTS
HIPAA Privacy Documents
42 CFR Part 2 Documents
ONC's Cures Act (Info Blocking) Documents
HIPAA Privacy Documents
Administrative Requirements
1. Personnel
- Authority and Responsibilities of the Privacy Officer: Sample Policy and Procedure
- Privacy Officer Job Description: Sample
2. Training
- HIPAA Privacy Education and Training: Sample Policy and Procedure
- HIPAA Privacy Education and Training Attendance Certification and Sign In Form: Sample
- HIPAA Privacy Education and Training Log: Sample
- HIPAA Privacy Education and Training Material Distribution Log: Sample
3. Safeguards
- Safeguards to Protect the Privacy of PHI: Sample Policy and Procedure
4. Privacy Complaints
- Reporting and Responding to Privacy Complaints: Sample Policy and Procedure
- Prohibition on Waiver of Rights: Sample Policy and Procedure
- Privacy Complaint Form: Sample
- Privacy Complaint Summary: Sample
- Privacy Complaint Log: Sample
- Investigating Privacy Complaints: Sample Policy and Procedure
- Privacy Investigation Report: Sample
5. Sanctions
- Sanctioning Workforce Members: Sample Policy and Procedure
6. Mitigation of Violations
- Mitigating the Effects of a HIPAA Violation: Sample Policy and Procedure
7. Prohibiting Intimidation and Retaliation
- Prohibiting Intimidation and Retaliation: Sample Policy and Procedure
8. Policies and Procedures
- Developing, Implementing and Revising HIPAA Policies and Procedures: Sample Policy and Procedure
- Documenting HIPAA Privacy Practices: Sample Policy and Procedure
Uses and Disclosures
- Uses and Disclosures for Treatment, Payment and Health Care Operations: Sample Policy and Procedure
- Uses and Disclosures Required by Law: Sample Policy and Procedure
- Uses and Disclosures for Public Health Activities: Sample Policy and Procedure
- Disclosures about Victims of Abuse, Neglect or Domestic Violence: Sample Policy and Procedure* (REVISED)
- Uses and Disclosures for Health Oversight Activities: Sample Policy and Procedure* (REVISED)
- Disclosures for Judicial and Administrative Proceedings: Sample Policy and Procedure* (REVISED)
- Disclosures for Law Enforcement Purposes: Sample Policy and Procedure* (REVISED)
- Uses and Disclosures about Decedents: Sample Policy and Procedure* (REVISED)
- Uses and Disclosures for Cadaveric Organ, Eye, or Tissue Donation Purposes: Sample Policy and Procedure
- Uses and Disclosures to Avert a Serious Threat to Health or Safety: Sample Policy and Procedure
- Uses and Disclosures for Specialized Government Functions: Sample Policy and Procedure
- Disclosures for Workers' Compensation: Sample Policy and Procedure
Authorizations
- Authorization for Use and Disclosure of PHI: Sample Policy and Procedure
- Authorization for Disclosure of PHI: Sample Form
- Revocation of Authorization: Sample Form
- Verifying Identity and Authority Prior to Disclosing PHI: Sample Policy and Procedure
- Identity Verification: Sample Form
Responding to Patient Requests
- Requests for Restrictions: Sample Policy and Procedure
- Requests for Restriction: Sample Form
- Requests for Confidential Communications: Sample Policy and Procedure
- Requests for Confidential Communications: Sample Form
- Requests for Access: Sample Policy and Procedure
- Request for Access: Sample Form
- Requests to Amend: Sample Policy and Procedure
- Requests to Amend: Sample Form
- Requests for an Accounting of Disclosures: Sample Policy and Procedure
- Requests for an Accounting of Disclosures: Sample Form
- Designation and Authority of Personal Representatives: Sample Policy and Procedure* (REVISED)
Notice of Privacy Practices
- Contents of the Notice of Privacy Practices: Sample Policy and Procedure * (REVISED)
- Providing the Notice of Privacy Practices: Sample Policy and Procedure
- Acknowledgement of Receipt of Notice of Privacy Practices: Sample Form
- Acknowledgement of Receipt of Notice of Privacy Practices Not Obtained: Sample Form
Minimum Necessary
- Minimum Necessary for Use of PHI by Workforce Members: Sample Policy and Procedure
- Workforce Access Categories: Sample Form
- Workforce Directory Chart: Sample Form
- Minimum Necessary for Disclosures and Requests of PHI: Sample Policy and Procedure
Breach
- Breach Analysis and Notification: Sample Policy and Procedure
- Breach Notification to Affected Individuals: Sample Letter
- Breach Log: Sample
- Breach Notification Report to HHS: Sample Form
Business Associates
- Disclosing PHI to Business Associates: Sample Policy and Procedure
- Business Associate Agreement: Sample
- Business Associate Agreement Log: Sample Form
- Business Associate Agreement Checklist: Sample Form
Compliance Programs
- Board Resolution Designating the Privacy Officer: Sample Form
- HIPAA Privacy Compliance Monitoring and Auditing: Sample Policy and Procedure
- Cooperating with HHS: Sample Policy and Procedure
Attestations
- Attestation for Use and Disclosure of PHI Potentially Related to Reproductive Health: Sample Policy and Procedure* (NEW)
Other Privacy Concepts
- Uses and Disclosures of Limited Data Sets: Sample Policy and Procedure
- Data Use Agreement for Limited Data Sets: Sample
- Uses and Disclosures for Fundraising: Sample Policy and Procedure
- Workforce Confidentiality Agreement: Sample Form
- Site Visitor Confidentiality Agreement: Sample Form
*New/Updated to reflect the HIPAA Privacy Rule Final Rule to Support Reproductive Health Care Privacy (2024)
42 CFR Part 2 Documents
Applicability
- Determining Applicability of 42 CFR Part 2: Sample Policy and Procedure
- Determining whether the Health Center Operates a Part 2 Program - Sample Form
Program Requirements
- Providing Notice to Patients of 42 CFR Part 2 Confidentiality Requirements: Sample Policy and Procedure
- Notice to Patients of Federal Confidentiality Requirements under 42 CFR Part 2: Sample Form
- Acknowledgment of Receipt of Notice of Federal Confidentiality Requirements under 42 CFR Part 2: Sample Form
- Security for Records Protected by 42 CFR Part 2: Sample Policy and Procedure
- Request for Access to Records Protected by 42 CFR Part 2: Sample Policy and Procedure
- Disposition of Records by Discontinued Programs: Sample Policy and Procedure
Disclosures with Patient Consent
- Obtaining Patient Consent for Disclosure of Patient Information Protected by 42 CFR Part 2: Sample Policy and Procedure
- Initial Consent to Disclose Records from Health Center’s Part 2 Program: Sample Form
- Consent to Disclose Records Protected by 42 CFR Part 2: Sample Form
- Consent to Disclose Records Protected by 42 CFR Part 2 to a Health Information Exchange: Sample Form
- Consent to Disclose Records Protected by 42 CFR Part 2 to the Criminal Justice System for Referred Patients: Sample Form
Disclosures without Patient Consent
- Disclosures for Medical Emergencies: Sample Policy and Procedure
- Disclosures for Research: Sample Policy and Procedure
- Disclosures for Audits and Evaluations: Sample Policy and Procedure
- Audit and Evaluation of Records Not Copied, Removed, Downloaded or Forwarded: Sample Agreement
- Audit and Evaluation of Records Copied, Removed, Downloaded or Forwarded: Sample Agreement
Court Orders Authorizing Disclosure and Use
- Court Orders Authorizing Disclosure and Use: Sample Policy and Procedure
QUALIFIED SERVICE ORGANIZATIONS
- Disclosures to Qualified Service Organizations: Sample Policy and Procedure
- Qualified Service Organizations Agreement: Sample Addendum to Business Associate Agreement
ONC's Cures Act (Info Blocking) Documents
Responding to Requests to Access, Exchange and Use EHI
- Responding to Requests to Access, Exchange and Use EHI in Compliance with the ONC’s Cures Act Final Rule: Sample Policy*
- Educating Patients on Risks Related to Access, Exchange and Use of EHI: Sample Policy and Procedure
Administrative Elements
- Education and Training for Employees, Contractors and Volunteers: Sample Policy and Procedure
- Reporting and Responding to Non-Compliance with the ONC's Cures Act Final Rule: Sample Policy and Procedure
Preventing Harm Exception
- Preventing Harm Exception to Access, Exchange and Use of EHI: Sample Policy and Procedure
Privacy Exception
- Privacy Exception to Access, Exchange and Use of EHI: Sample Policy and Procedure
Security Exception
- Security Exception to Access, Exchange and Use of EHI: Sample Policy and Procedure
Infeasibility Exception
- Infeasibility Exception to Access, Exchange and Use of Electronic Health Information: Sample Policy and Procedure
- Determining Whether the Infeasibility Exception Applies: Sample Form
- Notice to Patient of Request Denial: Sample Notice
Health IT Performance Exception
- Health IT Performance Exception to Access, Exchange and Use of Electronic Health Information: Sample Policy and Procedure
Content and Manner Exception
- Content and Manner Exception to Access, Exchange and Use of Electronic Health Information: Sample Policy and Procedure**
Fees Exception
- Fees Exception to Access, Exchange and Use of Electronic Health Information: Sample Policy and Procedure
Licensing Exception
- Licensing Exception to Access, Exchange and Use of Electronic Health Information: Sample Policy and Procedure
*Updated definition of EHI.
**Updated to remove reference to 45 CFR 171.301(a)(1) which limited EHI to data elements in the USCDI.
ABOUT THE AUTHORS
Attorneys from Feldesman Leifer LLP provide a full range of counseling services for the development, evaluation, implementation, operation, and support of effective HIPAA Privacy programs, informed by decades of experience advising federally qualified health centers, behavioral health providers, primary care associations, and health-center controlled networks.
DIANNE PLEDGIE
As Partner and Compliance Counsel with the firm’s health law practice group, Dianne advises health centers on implementing effective compliance programs and on addressing top compliance risk areas. Dianne counsels health centers and other organizations on developing compliance programs that include the OIG’s seven elements, respond to identified compliance risk areas, and reflect the organization’s culture. Dianne also advises health centers and other organizations on patient privacy and confidentiality, including the HIPAA Privacy Rule and 42 CFR Part 2. She has experience responding to privacy and security incidents, including determining whether there has been a breach, notifying patients and the government, and creating corrective action plans. [Full Bio]
MOLLY EVANS
A partner in the firm’s health law practice group, Molly advises health centers on the management of clinical, employment and workforce related risks, with a particular focus on professional liability, Federal Tort Claims Act, and HIPAA matters. From her experience as both a private attorney and in-house counsel, Molly knows the importance of managing liability and risk issues in mission-driven organizations. [Full Bio]
There are no continuing education credits or other attendance records associated with this product.
Price
ACCESS PERIOD
Purchasing this Toolkit provides access for one calendar year. This access includes any updates or additions Feldesman makes to Toolkit resources throughout the year at no extra charge.
APPROVAL PROCESS
We require approval for all Toolkit purchases. We aim to review all requests as quickly as possible, but there are occasional delays. Please allow up to 3-5 business days for approval.
Toolkit subscriptions are for use within your organization only. If you are interested in purchasing Toolkit subscriptions for more than one organization, please Contact Us for bulk pricing options.
DISCLAIMER
By purchasing this Toolkit, you acknowledge and agree to our Terms of Use and Privacy Policy. This Toolkit has been prepared by attorneys at Feldesman Leifer LLP (Feldesman ) and includes original materials developed by Feldesman . This Toolkit is designed as a resource and the materials are not intended to be adopted word for word; Feldesman recommends that each organization tailor the materials to fit your health center's legal, financial, administrative, and programmatic needs. Failing to modify the original materials to the specific needs of your program may have adverse consequences.
By purchasing this Toolkit, you acknowledge and agree that the materials contained herein do not constitute legal advice and your purchase does not create an attorney-client relationship between you and Feldesman , nor is it intended to do so. If legal advice or other expert assistance is required, your organization should enter into an engagement agreement with Feldesman or seek the services of another competent professional. Each legal problem is different, and past performance does not guarantee future results.
By purchasing this Toolkit, you acknowledge and agree that, unless otherwise indicated, Feldesman owns the copyright to the resources in this Toolkit. All such materials are for personal/non-commercial use only and, any other use or disclosure is a violation of federal copyright law and is punishable by the imposition of substantial fines. Unless otherwise noted, all materials in this Toolkit remain the intellectual property of Feldesman and are protected under the copyright of Feldesman Leifer LLP. Copyright is claimed in all original material, including but not limited to the sample forms, policies and procedures, and similar resources. Any and all such copyrighted materials may not be republished for or distributed to any third party at any time or in any form without written permission from Feldesman.