Introduction
The Public Education Health Trust (the “Trust”) sponsors various health benefits that are subject to privacy rules of the Health Insurance Portability and Accountability Act of 1996 as amended (HIPAA”) and its implementing regulations (Privacy Rules”). This HIPAA Privacy Policy (“Policy”) applies to the following self-funded group health benefits offered by the Trust, and referred to in this Policy as the “Plan”:
Medical Benefits, Dental Benefits, and Vision Benefits.
Members of the Trust’s workforce may have access to the individually identifiable health information of Plan participants (1) on behalf of the Plan itself; or (2) on behalf of the Trust for administrative functions of the Plan. The Trust has designated the Chief Financial Officer to execute the duties of the Plan set forth in this policy.
HIPAA restricts the Plan’s ability to use and disclose protected health information (PHI).
Protected Health Information. Protected health information means information that is created or received by the Plan and relates to the past, present, or future physical or mental health or condition of a participant; the provision of health care to a participant; or the past, present, or future payment for the provision of health care to a participant; and that identifies the participant or for which there is a reasonable basis to believe the information can be used to identify the participant. Protected health information includes information of persons living or deceased.
It is the Trust’s policy to comply fully with HIPAA’s requirements. To that end, all members of the Trust’s workforce who have access to PHI must comply with this Privacy Policy. For purposes of this policy and the Plan’s more detailed Use and Disclosure Procedures, the Trust’s workforce includes individuals who would be considered part of the workforce under HIPAA, including employees, trainees, volunteers and contractors performing services under the supervision, control and direction of the Trust.
No third party rights (including but not limited to rights of Plan participants, beneficiaries, covered dependents, or business associates) are intended to be created by this policy. The Trust reserves the right to amend or change this policy at any time (including retroactively) without notice. To the extent, this Policy establishes requirements and obligations above and beyond those required by HIPAA; the Policy shall be aspirational and shall not be binding upon the Plan, the Plan Administrator or any person with delegated duties under the Plan. This Policy does not address requirements under other federal laws or under state laws.
Plan’s Responsibilities as Covered Entity
I. Privacy Official and Contact Person
The Trust’s Chief Financial Officer will be the Privacy Official for the Plan. The Privacy Official will be responsible for the development and implementation of policies and procedures relating to privacy, including but not limited to this Privacy Policy and the Plan’s more detailed Use and Disclosure Procedures. The Privacy Official will also serve as the contact person for participants who have questions, concerns, or complaints about the privacy of their PHI:
Chief Financial Officer
Public Education Health Trust
2550 Denali St, Ste 1614
Anchorage, AK 99503
(907)274-7526
II. Workforce Training
It is Trust’s policy to train all employees who have access to PHI regarding its privacy policies and procedures. The Privacy Official is charged with developing training schedules and programs so that all workforce members receive the training necessary and appropriate to permit them to carry out their functions within Plan.
III. Technical, Physical and Administrative Safeguards and Firewall
A. Technical, Physical and Administrative Safeguards
Appropriate technical, physical and administrative safeguards to prevent PHI from intentionally or unintentionally being used or disclosed in violation of HIPAA’s requirements, including but not limited to the following:
- Designating a biannual audit day to reevaluate space and document flow,
both hard copy documentation and electronic data to ensure ongoing compliance with HIPAA’s privacy rules.
- Altering positioning of computer screens or providing screen savers operational upon five minutes or less of computer inactivity to prevent inadvertent disclosure of PHI to unauthorized personnel.
- Securing PHI which must be maintained and stored by the Plan in a locked storage room to which only Plan personnel have access.
- Moving the Plan’s facsimile machine to the locked PHI storage room.
- Re-arranging information stored in file cabinets and credenzas to make optimal use of locking file cabinets to prevent loss or disclosure of PHI.
- Designating an “in box” for each employee to formalize the flow of PHI in the workspace. In-boxes are secured through covering during periods of absence of less than one hour, are secured in locked credenza, file cabinet or PHI storage room for periods of absence beyond one hour.
- Instituting procedure requiring employees to cover files or papers on their desktops containing PHI during periods of absence from their immediate work area of 20 minutes or more.
- Setting aside screened area where participants may have confidential discussions with a Plan employee or review files.
- Instituting procedures requiring Plan employees to use low tone when answering participant telephone calls. Instructing Plan employees that notes taken during calls should be secured and destroyed through shredding in accordance with the Plan’s document retention policies.
- Instituting procedures to authenticate identities of individuals seeking PHI over the phone or in person, as: (1) the individual to whom the PHI pertains, (2) the individual’s legal representative, (3) a person for whom the Plan has a current HIPAA authorization. (4) or another individual permitted to have access to the PHI under HIPAA.
- Shredding or securing PHI in accordance with document retention policies.
- De-identifying claims information required to be presented at Trustee meetings. Shredded or secured non-minute notes of Trustee meetings containing PHI once adopted as official minutes of the trustees at the next meeting.
B. Firewalls between Employer and Plan Functions
Firewalls will ensure that only authorized employees will have access to PHI, that they will have access to only the minimum amount of PHI necessary for Plan administrative functions, and that they will not further use or disclose PHI in violation of HIPAA’s privacy rules.
The Trust has instituted the safeguards described above to limit unnecessary to inappropriate access to the protected health information created or maintained by the Plan. In every case, the Trust will ensure that protections applied to the general public to prevent the disclosure of PHI during office visits would be applied to non-Trust personnel.
IV. Privacy Notice
The Privacy Official is responsible for developing and maintaining a Notice of Privacy Practices that describes:
- The uses and disclosures of PHI that may be made by the Plan;
- The individual’s rights; and
- The Plan’s legal duties with respect to the PHI.
The Notice will inform participants that the Plan will have access to PHI in connection with its Plan administrative functions. The Notice will also provide a description of the Plan’s complaint procedures, the name and telephone number of the contact person for further information, and the date of the Notice.
The Notice of Privacy Practices will be individually delivered to all participants:
- No later than April 14, 2003;
- On an ongoing basis, at the time of an individual’s enrollment in the Plan; and
- Within 60 days after a material change to the notice.
The Plan will also provide notice of availability of the Notice at least once every three years.
V. Complaints
The Privacy Official will be the Plan’s contact person for receiving complaints. The Privacy Official is responsible for creating a process for individuals to lodge complaints about the Plan’s privacy procedures and for creating a system for handling such complaints.
VI. Sanctions for Violations of Privacy Policy
All members of the Plan’s workforce with access to PHI must comply with this Policy and with the Plan’s Use and Disclosure Procedures. Sanctions for using or disclosing PHI in violation of this HIPAA Privacy Policy will be imposed in accordance with the Plan’s policies regarding employee discipline. The severity of the sanction will depend on the facts and circumstances of the violation and may include discipline up to and including immediate termination.
VII. Mitigation of Inadvertent Disclosures of Protected Health Information
The Plan shall mitigate, to the extent reasonable and feasible, any harmful effects that become known to it of a use of disclosure of an individual’s PHI in violation of the policies and procedures set forth in this Policy. An employee who becomes aware of a disclosure of protected health information (either by an employee of the Plan or an outside business associate, consultant, or contractor) that is not a compliance with this Policy must immediately report the disclosure to the Privacy Official. The Privacy Official will determine the reasonable and appropriate steps, which may mitigate the harm to the participant can be taken. The method of mitigation will depend on the facts and circumstances of the unauthorized use or disclosure as determined in the discretion of the Privacy Official.
VIII. No Intimidating or Retaliatory Acts; No Waiver of HIPAA Privacy
Neither the Plan nor any of its employees acting within the course and scope of employment shall intimidate, threaten, coerce, discriminate against, or take other retaliatory action against individuals for exercising their rights, filing a complaint, participating in an investigation, or opposing any improper practice under HIPAA.
No individual shall be required to waive his or her privacy rights under HIPAA as a condition of treatment, payment, enrollment or eligibility under the Plan.
IX. Plan Document
The Plan document shall include provisions describing the permitted and required uses and disclosures of PHI by the Plan for Plan administrative purposes.
X. Documentation
The Plan’s privacy policies and procedures shall be documented and maintained for at least six years. Policies and procedures will be amended as necessary or appropriate to comply with changes in the law, standards, requirements and implementation specifications (including changes and modifications in regulations). Any changes to policies or procedures will be documented and become effective only with respect to PHI created or received after the effective date of the amended policies and procedures. The Plan shall document certain events and actions relating to an individual’s PHI in accordance with the Plan’s more detailed Use and Disclosure Procedures.
Policies on Use and Disclosure of PHI
I. In General
The Plan will use and disclose PHI only as permitted under HIPAA. An individual’s decision to voluntarily disclose their own PHI with others, including a Plan trustee (trustees are not responsible for receiving or handling PHI for the Plan), is not governed by this Policy or the Plan’s more detailed Use and Disclosure Procedures. The Plan is not responsible for such voluntary disclosures of PHI by the individual to whom the information pertains.
II. Access to PHI is Limited to Certain Employees
The use and disclosure of protected health information shall be limited to the minimum necessary extent to perform a particular Plan function. To this end, the Plan has analyzed the appropriate level of access to PHI by the Plan’s workforce. Only Trust personnel, have a job-related need for access to protected health information created or maintained by the Plan.
Based on their job descriptions, the size and nature of the Plan’s operations and the need for cooperation amongst a small workforce, each member of the Plan’s workforce shall have co-equal access to protected health information. This protected information may include payment, claims administration, enrollment and eligibility information, which each member of the Plan’s workforce may be called upon to access, interpret, use for Plan operations, and disclose in accordance with the Plan’s privacy policy. The PHI will be secured with reasonable technical, physical and administrative protections to prevent unauthorized use and disclosure.
The Plan’s workforce with the need for co-equal access to protected health information created or maintained by the Plan includes:
- Chief Financial Officer – Assists the Plan Administrator with Plan administrative functions involving PHI on behalf of the Plan, primarily responsible for Plan administrative duties, including claims payment, member enrollment and essential services affecting the delivery of benefits; including and the Plan’s finances keeping records of the Plan’s financial transactions, preparing reports and instruments containing protected health information regarding payments under the Plan.
- Administrative Assistant – Assists the Chief Financial Officer with Plan administrative functions involving PHI on behalf of the Plan, including providing participants with information regarding coverage or pending claims, administering enrollment, eligibility and continuation coverage functions.
- Trust Claims Analyst – Assists the Chief Financial Officer with Plan administrative functions involving PHI on behalf of the Plan, including providing participants with information regarding coverage or pending claims, administering enrollment, eligibility and continuation coverage functions.
These employees with access may use and disclose PHI for Plan administrative functions, and they may disclose PHI to other employees with access for Plan administrative functions (but the PHI disclosed must be limited to the minimum amount necessary to perform the Plan administrative function). Employees with access may not disclose PHI to employees without access unless an authorization is in place or the disclosure otherwise is in compliance with this Policy and the Plan’s more detailed Use and Disclosure Procedures.
III. Permitted Uses and Disclosures: Payment and Plan Operations
PHI may be disclosed for the Plan’s own payment purposes, and PHI may be disclosed to group health plans (i.e. for purposes of coordination of benefits), health care providers or health care clearinghouses for the payment purposes of that covered entity.
Payment. Payment includes activities undertaken to obtain Plan contributions or to determine or fulfill the Plan’s responsibility for provisions of benefits under the Plan, or to obtain or provide reimbursement for health care. Payment also includes:
- Eligibility and coverage determinations including coordination of benefits and adjudication or subrogation of health benefit claims;
- Risk adjusting based on enrollee status and demographic characteristics; and
- Billing, claims, management, collection activities, obtaining payment under a contract for reinsurance (including stop-loss insurance and excess loss insurance) and related health care data processing.
PHI may be disclosed for purposes of the Plan’s own health care operations. PHI may be disclosed to another group health plan, health provider or health clearinghouse for purposes of the other entity’s quality assessment and improvement, case management, or health care fraud and abuse detection programs, if the other covered entity has (or had) a relationship with the participant and the PHI requested pertains to that relationship.
Operations. Plan operations mean any of the following activities to the extent that they are related to Plan administration:
- Conducting quality assessment and improvement activities;
- Reviewing health Plan performance;
- Underwriting and premium rating;
- Conducting or arranging for medical review, legal services and auditing functions;
- Business planning and development; and
- Business management and general administrative activities.
IV. No Disclosure of PHI for Non-Plan Purposes
PHI may not be used or disclosed for the payment or operations of any “non-health” benefits (e.g., sick leave, disability, workers’ compensation, life insurance, etc.), that may be provided by the Trust, or for other non-Plan employment purposes (e.g., administration of the Trust’s duties under the Americans with Disabilities Act, Family Medical Leave Act, etc.), unless the participant has provided an authorization for such use or disclosure (discussed further below) or such use or disclosure is required by applicable state law and particular requirements under HIPAA are met.
V. Mandatory Disclosures of PHI: to Individual and DHHS
A participant’s PHI must be disclosed as required by HIPAA in two situations:
- The disclosure is to the individual who is the subject of the information; and
- The disclosure is made to DHHS for purposes of enforcing of HIPAA.
VI. Permissive Disclosures of PHI: for Legal and Public Policy Purposes
PHI may be disclosed in the following situations without a participant’s authorization, when specific requirements are satisfied. The Plan’s more detailed Use and Disclosure Procedures describe specific requirements that must be met before these types of disclosures may be made. The permitted disclosures include:
- About victims of abuse, neglect or domestic violence;
- For judicial and administrative proceedings;
- For law enforcement purposes;
- For public health activities;
- For health oversight activities;
- About decedents;
- For cadaveric organ, eye or tissue donation purposes;
- To avert a serious threat to health or safety;
- For specialized government functions; and
- Related to workers’ compensation programs.
VII. Disclosures of PHI Pursuant to an Authorization
PHI may be disclosed for any purpose if an authorization that satisfies all of HIPAA’s requirements for a valid authorization is provided by the participant. All uses and disclosures made pursuant to a signed authorization must be consistent with the terms and conditions of the authorization.
VIII. The Minimum-Necessary Standard
When PHI is used or disclosed by the Plan, the amount disclosed or used generally must be limited to the “minimum necessary” to accomplish the purpose of the use or disclosure.
The “minimum-necessary” standard does not apply to any of the following:
- uses or disclosures made to the individual;
- uses or disclosures made pursuant to a valid authorization;
- disclosures made to DHHS;
- uses or disclosures required by law; and
- uses or disclosures required to comply with HIPAA.
All disclosures must be reviewed on an individual basis with the Privacy Official to ensure that the amount of information disclosed or requested is the minimum necessary to accomplish the purpose of the disclosure.
IX. Disclosures of PHI to Business Associates
Plan employees may disclose PHI to the Plan’s business associates and allow the Plan’s business associates to create or receive PHI on its behalf. However, prior to doing so, the Plan will obtain written assurances from the business associate that it will appropriately safeguard the information. Before sharing PHI with outside consultants or contractors who meet the definition of a “business associate” employees must contact the Privacy Official and verify that a business associate contract is in place and that such agreement includes appropriate language regarding HIPAA compliance.
Business Associate is an entity that:
- Performs or assists in performing a Plan function or activity involving the use and disclosure of protected health information (including claims processing or administration, data analysis, underwriting, etc.); or
- Provides legal, accounting, actuarial, consulting, data aggregation, management, accreditation, or financial services, where the performance of such services involves giving the service provider access to PHI.
The Plan in its sole discretion may, but is not required to, seek assurances from non-business associates regarding their implementation of safeguards to prevent impermissible disclosures of PHI.
X. Disclosures of De-Identified Information
The Plan may freely use and disclose de-identified information. De-identified information is health information that does not identify an individual and with respect to which there is no reasonable basis to believe that the information can be used to identify an individual.
Policies on Individual Rights
I. Access to Protected Health Information and Requests for Amendment
HIPAA gives participants the right to access and obtain copies of their PHI that the Plan (or its business associates) maintains in designated record sets. HIPAA also provides that participants may request to have their PHI amended if it is inaccurate or incomplete. The Plan will provide access to PHI and it will consider requests for amendment that are submitted in writing by Participants.
Designated Record Set is a group of records maintained by or for the Plan that includes:
- the eligibility, enrollment, payment, and claims adjudication record of an individual maintained by or for the Plan; or
- other PHI used, in whole or in part, by or for the Plan to make coverage decisions about an individual.
II. Accounting
An individual has the right to obtain an accounting of certain disclosures of his or her own PHI, as described in the Plan’s more detailed Use and Disclosure Procedures. This right to an accounting extends to disclosures made in the last six years. The accounting must include the date of the disclosure, the name of the receiving party, a brief description of the information disclosed, and a brief statement of the purpose of the disclosure (or a copy of the written request for disclosure, if any). The first accounting in any 12-month period shall be provided free of charge. The Privacy Official may impose reasonable production and mailing costs for subsequent accountings.
III. Requests for Alternative Communication Means or Locations
Participants may request to receive communications regarding their PHI by alternative means or at alternative locations. For example, participants may ask to be called only at work rather than at home. Such requests may be honored if, in the sole discretion of the Plan, the requests are reasonable. However, the Plan shall accommodate such a request if the participant clearly provides information that the disclosure of all or part of that information could endanger the participant. The Privacy Official has responsibility for administering requests for alternative means or locations for Plan communications.
IV. Requests for Restrictions on Uses and Disclosures of Protected Health Information
Participants may request restrictions on the use and disclosure of the Participant’s PHI. It is the Plan’s policy to attempt to honor such requests if, in the sole discretion of the Privacy Official, the requests are reasonable.
