POLICIY 2400 – CONFIFIDENTIALITY and PRIVACY

TABLE OF CONTENTS

2400 CONFIDENTIALITY & PRIVACY POLICIES

2400.01 POLICIES FOR ALL STAFF

2400.01.01 Confidentiality, Privacy and Computer Security Definitions

POLICY

The following definitions shall apply to Policies 2400 and 2500.

AUDIENCE

All Staff

AUTHORITY

The definitions below are adapted from the federal HIPAA regulations, FERPA regulations, the Ohio Revised Code, and Ohio Administrative Code.  In some cases, a definition in a regulation is adjusted to facilitate these policies.  For example, the definition of PHI, in these policies, is adapted to include both the information protected by the HIPAA regulations and the information protected by the FERPA regulations.

NORMS

Throughout Policies 2400 (Confidentiality and Privacy Policies) and 2500 (Computer Security) the terms may, must, shall and should are used.  The following is a guide for interpreting these terms:

  1. May – means a task is suggested, but nor required, or that an individual or entity is empowered, but not required, to perform the specified task.
  2. Must – means the individual or entity is required to perform the specified task. See also “Shall”.
  3. Shall – means the individual or entity is required to perform the specified task. See also “Must”.
  4. Should – means the individual or entity is recommended to perform the specified task, even though the task may not be required. When “should” is used, the item is a best-practice recommendation although not absolutely mandated.

DEFINITIONS

  • Access means the ability or the means necessary to read, write, modify, or communicate data/information or otherwise use any system resource. (Taken from HIPAA regulations.)
  • Administrative safeguards are administrative actions, and policies and procedures, to manage the selection, development, implementation, and maintenance of security measures to protect electronic protected health information and to manage the conduct of the covered entity’s workforce in relation to the protection of that information.
  • Agency – means CCBDD
  • Applicable Requirements Applicable requirements mean applicable federal and Ohio law and the contracts between the CCBDD and other persons or entities which conform to federal and Ohio Law.
  • Authentication means the corroboration that a person is the one claimed.
  • Availability means the property that data or information is accessible and useable upon demand by an authorized person.
  • Breach – the acquisition, access, use, or disclosure of protected health information in a manner not permitted by the HIPAA Privacy rules which compromises the security or privacy of the protected health information.
    • Breach excludes:
      • Any unintentional acquisition, access, or use of protected health information by a workforce member or person acting under the authority of a covered entity or a business associate, if such acquisition, access, or use was made in good faith and within the scope of authority and does not result in further use or disclosure in a manner not permitted by the HIPAA privacy rules.
      • Any inadvertent disclosure by a person who is authorized to access protected health information at a covered entity or business associate to another person authorized to access protected health information at the same covered entity or business associate, or organized health care arrangement in which the covered entity participates, and the information received as a result of the disclosure is not further used or disclosed in a manner not permitted by the HIPAA Privacy rules.
      • A disclosure of protected health information where a covered entity or business associate has a good faith belief that an unauthorized person to whom the disclosure was made would not reasonably have been able to retain such information.
    • Except for the three exclusions above, any unintentional acquisition, access, use or disclosure of PHI that is a violation of the Privacy Rule is PRESUMED TO BE A BREACH, unless a risk assessment demonstrates that there is a low probability that the PHI has been compromised.  The risk assessment must include at least the following factors:
      • The nature and extent of the protected health information involved, including the types of identifiers and the likelihood of re-identification;
      • The unauthorized person who used the PHI or to whom the disclosure was made;
      • Whether the PHI was actually acquired or viewed; and
      • The extent to which the risk to the PHI has been mitigated.
  • Business Associate (BA) A Business Associate, basically, is a person or entity which creates, uses, receives or discloses PHI held by a covered entity to perform functions or activities on behalf of the covered entity. The complete definition is included in Appendix A – Identifying Business Associates.
  • Confidentiality means the property that data or information is not made available or disclosed to unauthorized persons or processes.
  • Covered Entity Covered entity means a health plan, a health care clearinghouse or a health care provider who transmits any health information in electronic form in connection with a transaction covered by HIPAA transaction rules.
  • Designated Record Set Designated record set means:
    • A group of records maintained by or for a covered entity that is:
      • The medical records and billing records about Individuals maintained by or for a covered health care provider;
      • The enrollment, payment, claims adjudication, and case or medical management record systems maintained by or for a health plan; or
      • Used, in whole or in part, by or for the covered entity to make decisions about Individuals.
    • For purposes of this definition, the term record means any item, collection, or grouping of information that includes protected health information and is maintained, collected, used, or disseminated by or for a covered entity.
  • Directory Information — as defined in FERPA, means information contained in an education record of a student that would not generally be considered harmful or an invasion of privacy if disclosed. It includes, but is not limited to, the student’s name, address, telephone listing, electronic mail address, photograph, date and place of birth, major field of study, dates of attendance, grade level, enrollment status (e.g., undergraduate or graduate; full-time or part-time), participation in officially recognized activities and sports, weight and height of members of athletic teams, degrees, honors and awards received, and the most recent educational agency or institution attended.
  • Disclosure Disclosure means the release, transfer, provision of access to, or divulging in any manner (orally, written, electronically, or other) of information outside the entity holding the information.
  • DODD – the Ohio Department of Developmental Disabilities
  • Early Intervention Records.–means all records regarding a child that are required to be collected, maintained, or used under Part C of the Act and the regulations in this part. These are essentially equivalent to FERPA Education Records
  • Education Education means activities associated with operating the school including instruction, IHP/IEP preparation, administration, behavioral intervention, extra-curricular activities and other normal school functions.  Education shall also include activities associated with early intervention programming.
  • Education Records – As defined in the FERPA regulations, means records that are:
    • Directly related to a student; and
    • Maintained by an educational agency or institution or by a party acting for the agency or institution.
    • The term does not include:
      • Records that are kept in the sole possession of the maker, are used only as a personal memory aid, and are not accessible or revealed to any other person except a temporary substitute for the maker of the record.
      • Records of the law enforcement unit of an educational agency or institution, subject to the provisions of § 99.8.
    • Either of the following:
      • Records relating to an Individual who is employed by an educational agency or institution, that:
        • Are made and maintained in the normal course of business;
        • Relate exclusively to the Individual in that Individual’s capacity as an employee; and
        • Are not available for use for any other purpose.
      • Records relating to an Individual in attendance at the agency or institution who is employed as a result of his or her status as a student are education records and not excepted under paragraph (C)(i) of this definition.
    • Records on a student who is 18 years of age or older, or is attending an institution of postsecondary education, that are:
      • Made or maintained by a physician, psychiatrist, psychologist, or other recognized professional or paraprofessional acting in his or her professional capacity or assisting in a paraprofessional capacity;
      • Made, maintained, or used only in connection with treatment of the student; and
      • Disclosed only to persons providing the treatment. For the purpose of this definition, “treatment” does not include remedial educational activities or activities that are part of the program of instruction at the agency or institution.
    • Records created or received by an educational agency or institution after an Individual is no longer a student in attendance and that are not directly related to the Individual’s attendance as a student.
    • Grades on peer-graded papers before they are collected and recorded by a teacher.
  • Employee – Employee means any person employed by the Agency, volunteers, board members and other persons whose conduct, in the performance of work for the Agency, is under the direct control of the Agency, whether or not they are paid by the Agency.
  • Encryption means the use of an algorithmic process to transform data into a form in which there is a low probability of assigning meaning without use of a confidential process or key.
  • Facility means the physical premises and the interior and exterior of a building(s).
  • FERPA FERPA means the Family Educational Rights and Privacy Act, which are federal regulations that govern the privacy of records maintained by schools, as well as the rights of parents and students to access those records.  These regulations are codified in CFR Title 34 Part 99.
  • Guardian of the Person Guardian of the Person means a person appointed by the Probate Court to provide consent for and make decisions for the ward
  • Health care means care, services, or supplies related to the health of an Individual. Health care includes, but is not limited to, the following:
    • Preventive, diagnostic, therapeutic, rehabilitative, maintenance, or palliative care, and counseling, service, assessment, or procedure with respect to the physical or mental condition, or functional status, of an Individual or that affects the structure or function of the body; and
    • Sale or dispensing of a drug, device, equipment, or other item in accordance with a prescription.
  • Health Care Clearinghouse A Health Care Clearinghouse is a public or private entity, including a billing service, community health management information system or community health information system that does either of the following functions:
    • Processes or facilitates the processing of health information received from another entity in a nonstandard format or containing nonstandard data content into standard data elements or a standard transaction.
    • Receives a standard transaction from another entity and processes or facilitates the processing of health information into nonstandard format or nonstandard data content for the receiving entity.
  • Health care operations means any of the following activities of the covered entity to the extent that the activities are related to covered functions:
    • Conducting quality assessment and improvement activities, including outcomes evaluation and development of clinical guidelines, provided that the obtaining of generalizable knowledge is not the primary purpose of any studies resulting from such activities; patient safety activities (as defined in 42 CFR 3.20); population-based activities relating to improving health or reducing health care costs, protocol development, case management and care coordination, contacting of health care providers and patients with information about treatment alternatives; and related functions that do not include treatment;
    • Reviewing the competence or qualifications of health care professionals, evaluating practitioner and provider performance, health plan performance, conducting training programs in which students, trainees, or practitioners in areas of health care learn under supervision to practice or improve their skills as health care providers, training of non-health care professionals, accreditation, certification, licensing, or credentialing activities;
    • Except as prohibited under §45 CFR § 164.502(a)(5)(i), underwriting, enrollment, premium rating, and other activities relating to the creation, renewal or replacement of a contract of health insurance or health benefits, and ceding, securing, or placing a contract for reinsurance of risk relating to claims for health care (including stop-loss insurance and excess of loss insurance), provided that the requirements of §45 CFR § 164.514(g) are met, if applicable;
    • Conducting or arranging for medical review, legal services, and auditing functions, including fraud and abuse detection and compliance programs;
    • Business planning and development, such as conducting cost-management and planning-related analyses related to managing and operating the entity, including formulary development and administration, development or improvement of methods of payment or coverage policies; and
    • Business management and general administrative activities of the entity, including, but not limited to:
      • Management activities relating to implementation of and compliance with the requirements of this subchapter;
      • Resolution of internal grievances;
        • The sale, transfer, merger, or consolidation of all or part of the covered entity with another covered entity, or an entity that following such activity will become a covered entity and due diligence related to such activity; and
        • Consistent with the applicable requirements of §45 C.F.R. Part 164.514, creating de-identified health information or a limited data set, and fundraising for the benefit of the covered entity.
  • Health Oversight Agency Health oversight agency means an agency or authority of the United States, a State, a territory, a political subdivision of a State or territory, or an Indian tribe, or a person or entity acting under a grant of authority from or contract with such public agency, including the employees or agents of such public agency or its contractors or persons or entities to whom it has granted authority, that is authorized by law to oversee the health care system (whether public or private) or government programs in which health information is necessary to determine eligibility or compliance, or to enforce civil rights laws for which health information is relevant.
  • Health Plan Health plan means an individual or group plan that provides, or pays the cost of medical care. A partial list of entities that are health plans (edited based on relevance to DD Boards) includes the following, singly or in combination:
    • The Medicaid program under title XIX of the Act, 42 U.S.C. § 1396, et seq.
    • Any other individual or group plan, or combination of individual or group plans, that provides or pays for the cost of medical care.
    • A group health plan, that is, an employee welfare benefit plan (as defined in section 3(1) of the Employment Retirement Income and Security Act of 1974 (ERISA), 29 U.S.C. 1002(1), including insured and self-insured plans, to the extent that the plan provides medical care, including items and services paid for as medical care, to employees or their dependents, that:
      • Has 50 or more participants; or
      • Is administered by an entity other than the employer that established and maintains the plan.
    • An employee welfare benefit plan or any other arrangement that is established or maintained for the purpose of offering or providing health benefits to the employees of two or more employers
  • HIPAA HIPAA means the Health Insurance Portability and Accountability Act of 1996, codified in 42 USC §§ 13201320d-9  and at 42 CFR Parts 160, 162 and 45 CFR § 164.   In common terms, this includes the HIPAA Enforcement Rule, Transactions Rule, Privacy Rule, Breach Notification Rule and Security Rule.
  • IDEA – Individuals with Disabilities Education Act.  Part C details rights and safeguards for infants aged 0-2 involved with Early Intervention programs, and Part B details rights and safeguards for children aged 3-18.
  • Incidental Disclosure – An unintentional disclosure of PHI, that occurs as a result of a use or disclosure otherwise permitted by the HIPAA Privacy Rule.  An Incidental Disclosure is NOT a violation of the Privacy Rule.  However, in order for incidental disclosures to not be a violation, the covered entity must be in compliance with the requirement for implementation of the minimum necessary principle, and also in compliance with the requirement to implement physical, technical, and administrative safeguards to limit incidental disclosures.
  • Individual, Individual receiving services or Individual served – Means a person who receives services from the Agency.  Note that parents or minors, guardians and other “personal representatives” may exercise any right or privilege available to an Individual served.
  • Individually Identifiable Health Information is information that is a subset of health information, including demographic information collected from an Individual, and:
    • Is created or received by a health care provider, health plan, employer, or health care clearinghouse; and
    • Relates to the past, present, or future physical or mental health or condition of an Individual; the provision of health care to an Individual; or the past, present, or future payment for the provision of health care to an Individual; and
      • That identifies the Individual; or
      • With respect to which there is a reasonable basis to believe the information can be used to identify the Individual.
  • Information system – means an interconnected set of information resources under the same direct management control that shares common functionality. A system normally includes hardware, software, information, data, applications, communications, and people.
  • Integrity means the property that data or information have not been altered or destroyed in an unauthorized manner.
  • Malicious software means software, for example, a virus, designed to damage or disrupt a system.
  • MOU MOU means a Memorandum of Understanding between governmental entities, which incorporates elements of a business associate contract in accordance with HIPAA rules.
  • Parent Parent means either parent.  If the parents are separated or divorced, “parent” means the parent with legal custody of the child.  “Parent” also includes a child’s guardian, custodian, or parent surrogate.  At age eighteen, the participant must act in their own behalf, unless they had a court-appointed guardian
  • Password means confidential authentication information composed of a string of characters.
  • Payment means, in the context of a County Board of DD:
    • Both:
      • Activities by the Agency required to determine if a person is eligible for services, and
      • Activities of the Agency either to reimburse contracted providers for services rendered to Individuals served or seeking reimbursement, for example from Medicaid or DODD, for services rendered to an Individual served.
    • The activities in paragraph (A) of this definition relate to the Individual to whom health care is provided and include, but are not limited to:
      • Determinations of eligibility or coverage (including coordination of benefits or the determination of cost sharing amounts), and adjudication or subrogation of health benefit claims;
      • Billing, claims management, collection activities, obtaining payment under a contract for reinsurance (including stop-loss insurance and excess of loss insurance), and related health care data processing;
      • Review of health care services with respect to medical necessity, coverage under a health plan, appropriateness of care, or justification of charges;
      • Utilization review activities, including precertification and preauthorization of services, concurrent and retrospective review of services.
  • Personal Representative Personal Representative means a person who has authority under applicable law to make decisions related to health care on behalf of an adult or an emancipated minor, or the parent, guardian, or other person acting in loco parentis who is authorized under law to make health care decisions on behalf of an unemancipated minor, except where the minor is authorized by law to consent, on his/her own or via court approval, to a health care service, or where the parent, guardian or person acting in loco parentis has assented to an agreement of confidentiality between the CCBDD and the minor.
  • Physical safeguards are physical measures, policies, and procedures to protect a covered entity’s electronic information systems and related buildings and equipment, from natural and environmental hazards, and unauthorized intrusion.
  • Protected Health Information, or PHI – means individually identifiable information that is: (i) transmitted by electronic media; (ii) Maintained in electronic media; or (iii) transmitted or maintained in any other form or medium.  Records of Individuals deceased for more than 50 years are not PHI.  For the purposes of this manual, and the Agency’s compliance program, PHI shall also include “Education Records” as defined by FERPA. This creates a consistent set of policies for both types of confidential information.
  • Provider Provider means a person or entity, which is licensed or certified to provide services, including but not limited to health care services, to persons with DD, in accordance with applicable requirements. A Covered Provider is a Health Care Provider who transmits any health information in electronic form.
  • Public Health Authority Public health authority means an agency or authority of the United States, a State, a territory, a political subdivision of a State or territory, or an Indian tribe, or a person or entity acting under a grant of authority from or contract with such public agency, including the employees or agents of such public agency or its contractors or persons or entities to whom it has granted authority, that is responsible for public health matters as part of its official mandate.
  • Security or Security measures encompass all of the administrative, physical, and technical safeguards in an information system.
  • Security incident means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system.
  • Social Engineering –  means “an outside hacker’s use of psychological tricks on legitimate users of a computer system, in order to obtain information they needs to gain access to the system” or “getting needed information (for example, a password) from a person rather than breaking into a system” . … social engineering is generally a hacker’s clever manipulation of the natural human tendency to trust. The hacker’s goal is to obtain information that will allow him/her to gain unauthorized access to a valued system and the information that resides on that system.
  • Subcontractor – means a person to whom a business associate delegates a function, activity, or service, other than in the capacity of a member of the workforce of such business associate.
  • Technical safeguards means the technology and the policy and procedures for its use that protect electronic protected health information and control access to it.
  • Treatment means the provision, coordination, or management of health care and related services by one or more health care providers, including the coordination or management of health care by a health care provider with a third party; consultation between health care providers relating to a patient; or the referral of a patient for health care from one health care provider to another.
  • TPO TPO means treatment, payment or health care operations under HIPAA rules.   For the purposes of this policy manual, TPO shall also include “Education” as defined above.
  • Unsecured protected health information – protected health information that is not rendered unusable, unreadable, or indecipherable to unauthorized persons through the use of a technology or methodology in guidance specified by the Secretary of the Department of HHS in guidance issued under section 13402(h)2 of Public Law 111-5.
  • Use – Use means, with respect to individually identifiable health information, the sharing, employment, application, utilization, examination, or analysis of such information within an entity that maintains such information.
  • User means a person or entity with authorized access.
  • Violation, or violate – means, as the context may require, failure to comply with a provision of either the HIPAA Privacy or Security rules, or a provision of state law relating to privacy, confidentiality or computer security.
  • Workforce Member Workforce Member means the same as Employee.  See definition above.
  • Workstation means an electronic computing device, for example, a laptop or desktop computer, or any other device that performs similar functions, and electronic media stored in its immediate environment.

    2400.01.02 Confidentiality – General Rules

    POLICY

    All information in an enrollee’s records, including electronic information, is confidential.  Further, all conversations involving individually identifiable information is confidential.

    The CCBDD shall conform to all requirements for privacy and confidentiality set forth by the State of Ohio, the federal HIPAA, FERPA and IDEA regulations, and any other applicable law.  Safeguards will be implemented for the use, disclosure, collection, storage, retention and destruction of individually identifiable information.  The CCBDD shall not use or disclose individually identifiable information except in accordance with applicable requirements.

    AUDIENCE

    All Staff

    AUTHORITY

    45 CFR Part 160 and 45 CFR § 164 (current as/of 3/27/2013)

    45 CFR § 164.504(g) for entities with multiple functions

    ORC § 5126.044 Ohio law on confidentiality (effective 9/22/2000)

    OAC § 5123:2-1-02(M) General DD Board confidentiality requirements (1/1/2015)

    45 CFR § 164.502(a)(1)(iii) incidental uses and disclosures

    OAC § 3301-51-04 Confidentiality (effective 7/1/2014), for schools

    34 CFR 99 FERPA (current as of 1/2012)

    34 CFR 300 and 301 Part B IDEA (Individuals with Disabilities Education Act, ages 3-21)

    34 CFR 303 Part C IDEA (Individuals with Disabilities Education Act, ages 0-2)

    34 CFR 303.402 – 416 Early Intervention Confidentiality and Family Rights Provisions

    34 CFR 300.610627 Children with Disabilities Confidentiality and Parent Rights Provisions

    PROCEDURES

    2400.01.03 Minimum Necessary Policy

    POLICY

    The use and disclosure of PHI must be limited to the minimum necessary to satisfy the request or to complete the task, except in situations specifically identified by the HIPAA rules.  The Privacy Officer shall implement safeguards and protocols to implement this policy.  All employees shall follow those protocols.

    AUDIENCE

    All Staff

    AUTHORITY

    45 CFR § 164.502(b)(1) minimum necessary standard

    34 CFR 300.623(d) IDEA Part B

    34 CFR 303.415(d) IDEA Part C

    34 CFR 99.31(a)(1)(i)(A) FERPA

    OAC 3301-51-04(N)(4) OAC Confidentiality Safeguards

    PROCEDURES

    FOR THE PRIVACY OFFICER

    • Implementation Approach.  The Privacy Officer will implement the minimum necessary requirement with the steps detailed below.  Measures to limit workforce access, and procedures for both routine disclosures and requests for PHI will be created and documented as detailed below:
      • Limiting Workforce Access to PHI: Access to the PHI will be granted based on the employee’s role and determined by the Director and Privacy Officer of CCBDD. CCBDD will identify:
        • Those persons or classes of persons, who require access to PHI to carry out their duties, in the workforce, including interns and trainees, will be listed according to job classification with the minimal necessary PHI required for successful job performance to serve the Individuals, and
        • For each such person or class of persons, the category or categories of PHI to which access is needed and any conditions appropriate to such access. 
        • Safeguards will be developed and documented to restrict workforce access to the minimum necessary, especially as detailed in Policy 2500.01.04 Facility Security and Access Control.
        • The Privacy Officer will document the results of this analysis in Appendix D – Minimum Necessary – Workforce, Disclosures and Requests.  This report will be available for public inspection.
      • Procedures for Routine Disclosures and Requests.  The HIPAA Privacy Officer will identify all routine disclosures made by Agency employees, for which the minimum necessary requirement applies, and create procedures to implement these.  The same shall be done for routine requests for PHI.  [Note that minimum necessary does not apply for disclosures or requests related to “treatment”; consequently no procedures must be created in these situations.]  These results shall be documented in Appendix D – Minimum Necessary – Workforce, Disclosures and Requests.
    • Implementation.  The Privacy Officer shall take the steps to implement the results of the analysis above, including configuring access control on software, staff training for routine requests and disclosures, and any other measures necessary.

        FOR ALL EMPLOYEES

        • Minimum Necessary Requirement
          • Basic Requirement.  When using or disclosing PHI, or when requesting PHI from another entity, employees must make reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose of the use, disclosure or request.
          • Exceptions.  The minimum necessary requirement does NOT apply to:
            • Disclosures to or requests by a health care provider for treatment
            • Uses or disclosures made to the Individual served, including but not limited to any requests for their records or requests for an accounting of disclosure
            • Uses of disclosures made pursuant to an Authorization
            • When the disclosure is required by law, is to the Secretary of HHS, or for compliance with HIPAA regulations
        • Routine Requests or Disclosures.  Staff shall be familiar with and follow procedures detailed in Appendix D – Minimum Necessary – Workforce, Disclosures and Requests when making requests for PHI or disclosures.
        • Procedures for Non-Routine Disclosures or Requests
          • For non-routine disclosures, when subject to the minimum necessary provision, the person making the disclosure will apply the minimum necessary principle.  He or she may seek the guidance, if necessary, of the Privacy Officer (or his/her designee).
          • For non-routine requests, the requesting party will utilize the minimum necessary principle, seeking the guidance, if necessary, of the Privacy Officer (or his/her designee).
          • Good Faith Reliance – CCBDD staff may rely on the belief that the PHI requested is the minimum amount necessary to accomplish the purpose of the request when:
            • The disclosure is made to a public official, permitted to receive information, and the public official represents that the request is for the minimum necessary information;
            • The request is from another covered entity;
            • The request is from a professional at CCBDD, or a business associate, and the professional or business associate asserts that the request is for the minimum necessary

              2400.01.04 Confidentiality Safeguards (Oral & Written)

              POLICY

              CCBDD shall utilize appropriate physical, technical, and administrative safeguards to safeguard Paper and Oral PHI.

              AUTHORITY

              45 CFR § 164.530(c) – Administrative, Technical, and Physical Safeguards

              34 CFR 99.31(a)(1)(ii) Safeguards

              ORC § 5126.044 Ohio law on confidentiality

              OAC § 5123:2-1-02(M) DD Board Records

              PROCEDURES

              • General Procedures
                • Employees shall be familiar with Appendix D Facility Security and Access Plan in the Policy 2500 Computer Security regarding staff, Individuals receiving services, parent and other visitor access to the facility.
                • Visitors shall be required to sign-in and wear a visitor badge while on the premises.  Employees shall escort visitors throughout the premises. 
              • Oral Privacy
                • Employees shall be aware of safeguarding oral communications.  This includes being aware of surroundings, and using appropriate volume when speaking to prevent others from overhearing conversations.
                • Employees shall refrain from holding conversations in common areas where Individuals receiving services or visitors can overhear PHI
                • Discussions concerning Individuals should be done in a private area and discussions must be limited to “need to know” information for purposes of providing the best services.
                • Overheard conversations are not to be shared or repeated.
                • When in a public place, any cell phone conversations should be conducted in a manner so as not to divulge PHI to bystanders.
              • Safeguards for Written PHI
                • Control of the Original Paper Records
                  • The HIPAA Privacy Officer shall be responsible for administering the security controls for paper record storage.
                  • Case and School records shall be kept locked and secured.  Employees requiring access to these records shall have a key and/or combination for the storage room or cabinet. 
                  • Paper files shall be put away promptly when not being used.
                  • Original paper records shall not be removed from the building without the authorization of the superintendent, Privacy Officer or designee. 
                  • Individual records shall be retained per Policy 803 Records Retention and Destruction.
                • Other use and storage of paper records
                  • Employees should minimize the use of hardcopy PHI.
                  • Personal appointment books with names of Individuals being served should be safeguarded while away from the office.  It is best to avoid putting last names in appointment books if possible.
                  • Hardcopy reports and redundant copies of records personally maintained should be kept in a locked file drawer.
                • Faxing Procedure
                  • When faxing a document with PHI, use a cover sheet which indicates that information is confidential, protected under state and federal laws, and not to be re-disclosed.
                  • Care should be taken to address and transmit fax to the proper recipient.
                  • Faxed documents should not be left at a common fax machine.
                • Printing and Copying PHI
                  • Printers and copiers used for printing of PHI should be in a secure, non-public location. If the equipment is in a public location, the information being printed or copied is required to be strictly monitored.
                  • PHI printed to a shared printer should be promptly removed.
                  • The Security Officer shall monitor all printer and photocopier acquisitions.  In the event that this equipment includes internal storage devices, which retain images of photocopies made, the asset shall be managed by the IT department, especially upon disposal to ensure destruction of any PHI contained in its storage.
                • Transportation/outside use of documents with PHI
                  • Caseworkers and other employees who remove documents from the facility, to conduct fieldwork, for example, are responsible for safeguarding these documents.
                  • When leaving documents unattended in a personal vehicle, the vehicle should be locked.  Preferably, the documents and/or their container should not be visible.
                  • If any documents with PHI are lost or stolen, the incident should be immediately reported to a supervisor.
                • Visibility of records and other PHI. All employees using records for Individuals and other paperwork with PHI shall arrange these items so that PHI is not readily visible to other Individuals receiving services/visitors, especially in high traffic areas such as reception area.
                • Shredding. Unneeded paper documents containing PHI shall be destroyed by shredding.
                • Clean Desk Policy. All employees shall clean their desks of PHI whenever leaving their work area for a time, especially at end-of-day.
              • Compliance Audits/Facility Review.  At least annually, the HIPAA Privacy Officer or designee may audit staff compliance with these guidelines.  The audit shall consist of a walk-through of the facility, with observations recorded, such as placement of desks, location of computer equipment, any papers with PHI that would be visible to a visitor, etc.  The results shall be discussed with the appropriate employee, and any appropriate actions taken.
              • Enforcement. All supervisors are responsible for enforcing this policy. Employees who violate this policy will be subject to the appropriate and applicable disciplinary process, up to and including termination or dismissal.
              • Annual Review.  These safeguards shall be reviewed and updated annually.

                2400.01.05 Speaking with the Family and Friends of an Individual Receiving Services

                POLICY

                CCBDD personnel are permitted to verbally disclose protected health information to family, friends, caregivers and other persons involved with the care of an Individual being served, in specific situations, after giving the Individual receiving services the opportunity to either agree to or object to the disclosure. 

                AUDIENCE

                All Staff

                AUTHORITY

                45 CFR § 164.510(b)

                PROCEDURES

                • If the Individual is present
                  • Permitted disclosure to family or friend present. If a family member, or friend of the Individual is present while services are being rendered, an employee serving the Individual may disclose PHI after one of the following:
                    • verbally seeking permission for the disclosure, and the Individual agrees; or
                    • giving the Individual the opportunity to object to the disclosure, and the Individual does not express an objection; or
                    • the staff member reasonably infers from the circumstances, based on the exercise of professional judgment, that the Individual does not object to the disclosure.
                • If the Individual is not present
                  • Communications about the Individual’s care
                    • In the event of a phone call or other discussion with a family member or one involved with the care of the Individual being served by CCBDD, where the Individual is not present, the employee may use their professional judgment to determine if the disclosure is in the best interests of the Individual and, if so, disclose only the PHI that is directly relevant to the person’s involvement with the Individual’s care.
                • Notifications
                  • An employee may disclose PHI to notify a family member, a personal representative of the Individual, or another person responsible for the care of the Individual of the Individual’s location or general condition.

                      2400.01.06 Authorizations

                      POLICY

                      All disclosures of PHI beyond those otherwise permitted or required by law require a signed authorization. CCBDD will use an authorization form that conforms with Ohio Laws, and the federal FERPA, IDEA and HIPAA regulations.

                      AUDIENCE

                      All Staff

                      AUTHORITY

                      45 CFR § 164.508 – HIPAA requirements for authorizations

                      ORC § 5126.044 – Ohio Statute on confidentiality of records

                      OAC § 5123:2-1-02(M) – Ohio Rule on confidentiality of records

                      34 CFR 99.30 FERPA requirements for prior consents to disclose information

                      34 CFR 99.32 FERPA recordkeeping requirements concerning requests and disclosures

                      LEGAL NOTES

                      • FERPA applies for records created for education; HIPAA applies to all other records.  The term used in the FERPA regulations is “consent”.  The HIPAA term “authorization” is used in these policies.

                      PROCEDURES

                      • Valid Authorization. Unless otherwise authorized by CCBDD policy and/or state or federal law, release of an Individual’s records requires specific authorization by the Individual being served or his/her legal representative.   A standard authorization form is included as an Appendix.  If authorizations are received on other forms, note that a valid authorization must include the following:
                        • Full Name of the Individual
                        • A specific description of the information to be released.  For example, a range of dates, or category of record.
                        • The purpose or need for the disclosure.
                        • The name of the person or agency disclosing the information.
                        • Names of the person(s), or agency to whom the disclosure is to be made.
                        • The date, event, or condition upon which the authorization expires (which can be no longer than 180 days from the date of signing).
                        • Statement of the Individual’s right to revoke the authorization, an explanation of how to revoke it, and any exceptions to the right to revoke.
                        • Statement that CCBDD may not condition treatment on whether the Individual signs the authorization. 
                        • A statement informing the Individual of the potential that information disclosed could be redisclosed if the recipient is not subject to federal or state confidentiality restrictions.
                        • Signature and date of the Individual or personal representative.
                        • If the authorization is signed by a guardian or personal representative, a description of that person’s relationship to the Individual and authority to sign the authorization.
                        • Written in plain language.
                      • Invalid Authorization. A PHI authorization is considered invalid if authorization has the following defects:
                        • Authorization is incomplete.
                        • Authorization is not dated or time has elapsed.
                        • Authorization does not contain required elements as explained above
                        • CCBDD is aware authorization has been revoked.
                        • CCBDD is aware information is false.
                        • Authorizations to release PHI is combined with other documents.
                      • For authorizations presented in person for immediate release, the staff member shall verify the identity of the recipient according to Policy 2400.01.07 Verification, after which the information may be released.
                      • Proper Completion of Authorization Form by Staff. The staff person handling the request should complete the following steps, and annotate the bottom of the Authorization Form:
                        • The employee should write their name on the completed authorization form.
                        • The original signed authorization shall be saved in the Individual’s master record, and a copy must be given to the Individual. 
                        • A record of the release shall be maintained in the Individual’s record, using the Disclosure Log included as an Appendix, detailing the following information:
                          • The date of the disclosure.
                          • The name of the entity or person who received the PHI, and, if known, the address of such entity or person.
                          • A brief description of the PHI disclosed.
                          • A brief statement of the purpose of the disclosure.
                          • If the disclosure was due to a health or safety emergency, a description of the significant threat to health or safety.
                          1. Retention Period for Written or Electronic Copy of Authorization. The CCBDD must retain the written or electronic copy of the authorization for a period of six (6) years from the later of the date of execution or the last effective date.
                          2. Revocation of Authorization. Upon instructions of revocation of authorization, CCBDD employees shall locate the original authorization form, annotate it as revoked, and take appropriate steps to prevent any further disclosure.
                          3. Note that information from other service providers contained in the Individual’s record may be released with the Individual’s written authorization.

                          2400.01.07 Verification

                          POLICY

                          CCBDD will take reasonable steps to verify the identity and the authority of the person requesting protected health information (PHI) of an Individual.

                          AUDIENCE

                          All Staff

                          AUTHORITY

                          34 CFR 99.31(c) Verification

                          45 CFR § 164.514(h) Verification

                          PROCEDURES

                          REQUESTS FROM A PUBLIC OFFICIAL OR AUTHORITY

                          • Verifying Identity and Authority. In verifying the identity and legal authority of a public official or a person acting on behalf of the public official requesting disclosure of PHI, CCBDD personnel may rely on the following, if such reliance is reasonable under the circumstances, when disclosing PHI:
                            • Documentation, statements, or representations that, on their face, meet the applicable requirements for a disclosure of PHI.
                            • Presentation of an agency identification badge, other official credentials, or other proof of government status if the request is made in person.
                            • A written statement on appropriate government letterhead that the person is acting under the government’s authority.
                            • Other evidence of documentation from an agency, such as a contract for services, memorandum of understanding, or purchase order, that establishes that the person is acting on behalf of the public official.
                            • A written statement of the legal authority under which the information is requested.If a written statement would be impracticable, an oral statement of such legal authority.
                            • A request that is made pursuant to a court order and subpoena or other legal process issued by a grand jury or a judicial or administrative tribunal that is presumed to constitute legal authority.
                          • The following issues should be addressed before releasing PHI once a request is received:

                              REQUESTS FROM AN INDIVIDUAL RECEIVING SERVICES, PARENT, GUARDIAN OR PERSONAL REPRESENTATIVE

                              • A properly completed, valid Authorization per the specifications in Policy 2400.01.06 Authorizations is sufficient verification of the identity and authority of the person requesting information.
                              • For requests for information other than formal record releases, staff must first verify both the identity and the authority of the person prior to releasing PHI:
                                • If the person is known to the staff person, this is sufficient verification of identity.
                                • Identity can be verified by questioning the person regarding their knowledge of information in the record of the Individual being served, such as birth date, social security number, etc., which only an authorized person would typically know.
                                • For requests from someone other than the Individual or the parent of a minor, the person’s authority to obtain information must also be verified.  For example, a healthcare Power of Attorney and/or statement from the Individual that the requestor is a HIPAA Personal Representative would demonstrate proper authority.  See also Policy 2400.01.05 Speaking with Family and Friends of an Individual Receiving Services for situations where it may be permissible to give information to a family member.

                                  2400.01.08 Minors, Personal Representatives and Deceased Individuals

                                  POLICY

                                  Staff must follow applicable legal requirements to maintain confidentiality and to permit the legal release of protected health information (PHI) to minors and personal representatives, and for the release of PHI of deceased Individuals.

                                  AUTHORITY

                                  ORC 5126.044 Confidentiality

                                  ORC 3319.321(4) Confidentiality and Parental Rights of Access to Student Records

                                  ORC 3109.051(H) Parenting Time – companionship rights

                                  ORC 1337.13 Authority of attorney under durable power of attorney for health care

                                  45 CFR § 164.502(g)(1) Personal representatives

                                  45 CFR § 164.502(g)(2) Adults and emancipated minors

                                  45 CFR § 164.502(g)(3) Unemancipated minors

                                  45 CFR § 164.502(f) Deceased Individuals

                                  45 CFR § 164.510(b)(5) Uses and disclosures when the individual is deceased

                                  NOTES

                                  Federal HIPAA law changes issued 1/25/2013 relax confidentiality requirements upon death of an Individual.  These include 45 CFR § 164.502(f) which eliminates all protections of information 50 years after the death of an Individual, and 45 CFR § 164.510(b)(5) which allow for disclosures to people involved with the care of the Individual prior to death for information that is relevant to the person’s involvement.  While HIPAA rules preempt contrary state law, state laws which offer greater privacy safeguards, more rights of access to information, or less coercion shall prevail.  No changes have been made to these policies to implement the relaxed HIPAA provisions; consult with your prosecutor regarding whether to change these policies.

                                  PROCEDURES

                                  • Rights of legally Consenting Minors. Individuals being served, who are minors, and who are legally allowed to consent to treatment under Ohio Law may exercise all rights regarding access to, requests for amendment to, and release of their PHI pursuant to a written authorization.
                                  • Rights of an Individual’s Personal Representative. CCBDD recognizes an Individual’s personal representative as a person authorized to exercise rights of access and/or inspection of PHI, rights to request amendment of PHI, and the right to sign the CCBDD Authorization Form which permits release of PHI.
                                  • Recognized Personal Representative. CCBDD recognizes the following persons to be personal representatives:
                                    • The parent of a child younger than 18 years old
                                    • The non-custodial parent of a child younger than 18 years old (ORC 3319.321 and ORC 3109.051(H)), unless the custodial parent presents CCBDD a court order restricting the non-custodial parent’s access.  In the event that CCBDD is presented with such a court order, CCBDD shall adhere to the terms of that order.
                                    • A person who is recognized through durable power of attorney to have authority to act on the behalf of the Individual (ORC § 1337.13)
                                    • The legal guardian of the Individual
                                    • Any other person authorized by law except in Abuse, Neglect, and/or Endangerment situations, or where CCBDD has received a court order or other documentation limiting privileges of a non-custodial parent as provided below.
                                      • Abuse, Neglect, and/or Endangerment Situations.  Notwithstanding a state law of any requirement of this paragraph to the contrary, CCBDD may elect not to recognize a person as a personal representative of an Individual.  In order for CCBDD to choose not to recognize a person as a personal representative, CCBDD must decide that it is not in the best interest of the Individual to treat the person as the Individual’s personal representative and must believe that one of the following conditions exist:
                                        • The Individual has been or may be subjected to domestic violence, abuse, or neglect by a parent, guardian, or personal representative. 
                                        • Treating such person as the personal representative could endanger the Individual.
                                        • Receipt of a court order limiting privileges of a non-custodial parent.  In the event that CCBDD receives from the custodial parent a court order limiting the privileges of the non-custodial parent to act in the capacity of the child’s personal representative, CCBDD shall adhere to the restrictions in the court order.
                                  • Deceased Individuals
                                    • Disclosure of PHI After Death. PHI generated during the life of an Individual is protected from disclosure after death unless disclosure is for treatment or payment, quality assurance or other auditing or program review functions.  CCBDD and its employees cannot release PHI regarding a deceased Individual unless a valid personal representative has been established and has requested the PHI through the proper authorization process.
                                    • Disclosure of PHI to Administer Estate. Upon request, PHI shall be disclosed to the executor or administrator of the estate when the information is necessary to administer the estate (ORC § 5126.044).
                                    • Disclosure to Guardian or next-of-kin:. Upon request, the Agency shall release records regarding an Individual served to the guardian at time of death.  Absent a guardian, records may be released to the next of kin: 
                                      • The Individual’s Spouse (if married)
                                      • The Individual’s children
                                      • The Individual’s parents
                                      • The Individual’s brothers or sisters
                                      • The Individual’s uncles or aunts;
                                      • The Individual’s closest relative by blood or adoption
                                      • The Individual’s closest relative by marriage
                                      • An entire category must be exhausted (i.e., no people in the category exist or are still alive) before moving to the next category (ORC § 5126.044).

                                  2400.01.09 Duty to Report Violations and Security Incidents

                                  Effective Date: 7/1/2013

                                  Revised Date:

                                  Approved: 7/1/2013

                                  POLICY

                                  Confidentiality of PHI, and the computer security required to protect information regarding Individuals receiving services is taken very seriously at CCBDD.  Employees are required to follow all rules in these policies.  Any employee who becomes aware of a violation of either confidentiality or computer security rules is obligated to immediately report this violation.  Violations will be investigated and appropriate action will be taken.

                                  AUTHORITY

                                  HIPAA Privacy Rules, 45 CFR § 164

                                  45 CFR § 164.530(e)(1) – Sanctions

                                  PROCEDURES

                                  • Employees Duty to Report Violation. Any employee observing a violation of any of the Confidentiality and Computer Security policies is to report the violation to his/her supervisor.  Failure to report a violation is in itself a disciplinable offense.
                                  • Investigation. The supervisor should refer the incident to the Privacy Officer and/or the Security Officer.  The Privacy and/or Security Officer shall, in conjunction with other management personnel as he/she deems appropriate, investigate the matter through discussing the matter with staff, Individuals receiving services, or others, and/or review of computer or paper audit trails.
                                  • Procedure for Data Breach. For potential data breaches, the Privacy and/or Security Officer will follow any procedures detailed in Policy 2500.01.08 Breach Reporting.
                                  • Procedure for Privacy Violation. For Privacy Violations, the Privacy Officer will follow procedures in Policy 2500.01.12 Mitigation.
                                  • Filing of Written Report by Privacy and/or Security Officer. A written incident report will be written by the Privacy and/or Security Officer.  It will be filed in:
                                    • the Privacy Officer’s Privacy Violations file; and
                                    • the employee’s personnel file.
                                  • Employee Discipline, if appropriate, will be taken and documented in accordance with Policy 308 Discipline.
                                  • Post-Incident Review. A post-incident review will be conducted by the Privacy and/or Security Officer, with any corrective action taken, such as a change in policy, additional training, or other appropriate action.

                                    2400.01.10 Disclosures that do Not Require an Authorization

                                    POLICY

                                    CCBDD employees may use and disclose PHI in specific situations authorized by state and federal statute.  In these cases, the Individual’s authorization is not required.  Staff will carefully follow specific requirements for these unusual and infrequent disclosures.  These disclosures include the following:

                                    • When required by law.
                                    • For public health purposes such as reporting communicable diseases, work-related illnesses, or other diseases and injuries permitted by law; reporting births and deaths, and reporting reactions to drugs and problems with medical devices.
                                    • To protect victims of abuse, neglect, or domestic violence.
                                    • For health oversight activities such as investigations, audits, and inspections.
                                    • To accrediting organizations.
                                    • For judicial and administrative proceedings.
                                    • For law enforcement purposes.
                                    • To coroners, medical examiners, and funeral directors.
                                    • For organ, eye or tissue donation.
                                    • To reduce or prevent a serious threat to public health and safety.
                                    • For Specialized government functions.
                                    • In connection with “whistleblowing”.
                                    • For workers’ compensation or other similar programs if applicable.

                                    AUTHORITY

                                    45 CFR § 45 CFR § 164.512

                                    34 CFR 99.31

                                    34 CFR 99.36

                                    ORC § 2151.421(A) Reports of Child Abuse

                                    ORC § 2305.51 Disclosures to prevent harm to 3rd parties

                                    ORC § 2317.02(B) Privilege for physicians, school guidance counselors, licensed social workers and licensed counselors

                                    ORC § 4732.19 Privilege for psychologists

                                    ORC § 5123.19 Licensure activities of DODD

                                    ORC § 5123.60 OLRS

                                    ORC § 5123.61(C)(1) Duty to report abuse/neglect of persons with DD

                                    ORC § 5126.044 Confidentiality for DD Boards

                                    ORC § 5126.055 LMAA functions of DD Boards

                                    ORC § 5126.31 Case Review and Investigation

                                    OAC § 5123:2-17-02(B) Incidents adversely affecting health/safety

                                    OAC § 5123:2-17-02(D) Reporting MUIs

                                    OAC § 5123:2-3-04 Monitoring of licensed facilities

                                    Ohio Rules of Civil Procedure Rule 45 Procedures for obtaining a subpoena

                                    ORC § 4113.52 Reporting Violations of law by employer or fellow employee

                                    34 CFR Part 99 Subpart D May an Educational Agency Disclose Education Records

                                    20 U.S.C. 7165(b) Section 4155(b) No Child Left Behind Act – Transfer of Disciplinary Records

                                    OAC 3301-51-04(Q) Disciplinary Information

                                    LEGAL NOTES

                                    • ORC § 5126.044 does not authorize any of the excepted disclosures detailed in HIPAA and FERPA. Other Ohio regulations reference disclosures otherwise allowed by federal and state law.  HIPAA preempts contrary state law, except where state law offers greater privacy protections, greater rights of access to an Individual’s records, or is less coercive.  Consult your county prosecutor for review and approval of this policy.
                                    • HIPAA and FERPA/IDEA maintain overlapping but different lists of disclosures permitted without authorization or parental consent.  We use the term “Education Records” below to refer to FERPA/IDEA permitted disclosures, and “PHI” regarding HIPAA permitted disclosures.

                                    PROCEDURES

                                    CCBDD employees will follow the indicated procedures for the various special circumstances detailed below:

                                    • Recordkeeping.  For all of the disclosures authorized below, the employee handling the disclosure will document the details of the disclosure on the Disclosure Log which will be maintained in the adult or school record.  Copies of all paperwork requesting the disclosure and copies of the records sent will be maintained if practical.
                                    • When required by law
                                      • To officials at another school that an Individual served by the Agency intends to enroll in, or is already enrolled in, for the purposes of Individual’s enrollment or transfer.  Any such disclosures must include records of any disciplinary actions.
                                      • The CCBDD may use or disclose PHI or Education Records to the extent that such use or disclosure is required by law and the use or disclosure complies with and is limited to the relevant requirements of such law.
                                      • For compliance with mandatory disclosures related to sex offenders
                                    • For public health purposes PHI may be used or disclosed to:
                                      • A public health authority authorized by law to collect or receive information for the purpose of preventing or controlling disease, injury or disability, reporting vital events, conducting public health surveillance, investigations or interventions.
                                      • A public health or other government authority authorized by law to receive reports of child abuse or neglect.
                                      • A person subject to the jurisdiction of the Food and Drug Administration (FDA) regarding his/her responsibility for quality, safety or effectiveness of an FDA regulated product or activity, to report adverse events, product defects or problems, track products, enable recalls, repairs or replacements, or conduct post-marketing surveillance.
                                      • A person who may have been exposed to a communicable disease or may be at risk of contracting or spreading a disease or condition.
                                      • To the extent that the CCBDD receives PHI disclosed under this section in its role as LMAA, the CCBDD may use the PHI to carry out its duties.
                                    • To protect victims of abuse, neglect, domestic violenceor other crime
                                      • Reports of child abuse
                                        • Reports of child abuse shall be made in accordance with Ohio law.
                                        • The CCBDD may disclose PHI related to the report of abuse to the extent required by applicable law. Such reports shall be made to a public health authority or other appropriate government authority authorized by law to receive reports of child abuse or neglect.
                                      • Reports of abuse and neglect other than reports of child abuse or neglect.
                                        • The CCBDD may disclose PHI about an Individual believed to be a victim of abuse, neglect, or domestic violence to a governmental authority authorized to receive such reports if:
                                          • the Individual agrees; or
                                          • the CCBDD believes, in the exercise of professional judgment, that the disclosure is necessary to prevent serious physical harm.
                                          • If the Individual lacks the capacity to agree, disclosure may be made if not intended for use against the Individual and delaying disclosure would materially hinder law enforcement activity.
                                        • The CCBDD staff member making the disclosure must promptly inform the Individual whose PHI has been released unless:
                                          • doing so would place the Individual at risk of serious harm; orthe CCBDD would be informing a personal representative, and the CCBDD reasonably believes the personal representative is responsible for the abuse, neglect, or other injury, and that informing such person would not be in the best interests of the Individual as determined by the CCBDD, in the exercise of professional judgment.
                                    • For health or education oversight activities such as investigations, audits, and inspections
                                      • PHI may be used or disclosed for activities related to oversight of the health care system, government health benefits programs, and entities subject to government regulation, as authorized by law, including activities such as audits, civil and criminal investigations and proceedings, inspections, and licensure and certification actions.
                                      • Specifically excluded from this category are investigations of an Individual that are not related to receipt of health care, or the qualification for, receipt of, or claim for public benefits.
                                      • To the extent that the CCBDD receives PHI disclosed under this section in its role as LMAA, the CCBDD may use the PHI to carry out its duties.
                                      • Education Records may be disclosed to the Comptroller General of the US, Attorney General of the US, Secretary of Education and/or State of Ohio Education authorities subject to the requirements of 34 CFR 99.35 or to state officials involved with juvenile justice in accordance with 34 CF 99.38.
                                    • To accrediting organizations
                                      • Information in Education Records may be disclosed to accrediting organizations without parental consent.  For any disclosure of PHI, a HIPAA Business Associate agreement should be in place with the accrediting organization.
                                    • For judicial and administrative proceedings
                                      • NOTE:  These policies do not detail all situations such as grand juries and other infrequent legal proceedings.  Consult with legal counsel prior to disclosure for any unusual situations!  Also note that HIPAA and FERPA requirements are similar but different in some situations.
                                      • The CCBDD must always comply with a court order, but only in accordance with the express terms of the order.
                                      • For a subpoena, discovery request or other lawful process: the CCBDD may comply with such legal requests only if:
                                        • The CCBDD makes reasonable effort to notify the parent involved and/or receives satisfactory assurance from the party seeking the information that reasonable efforts have been made by such party to ensure that the Individual who is the subject of the requested PHI has been given notice of the request; or
                                        • The CCBDD receives satisfactory assurance from the party seeking the information that reasonable efforts have been made by such party to secure a qualified protective order.
                                      • The CCBDD will consult with legal counsel, prior to any response to a subpoena to ensure compliance with applicable requirements of HIPAA or FERPA.
                                    • For law enforcement purposes
                                      • Conditions Allowing for Disclosure of PHI to Law Enforcement. PHI may be disclosed for the following law enforcement purposes and under the specified conditions:
                                        • Pursuant to court order or as otherwise required by law, i.e., laws requiring the reporting of certain types of wounds or injuries; or commission of a felony, subject to any exceptions set forth in applicable law.
                                        • Decedent’s PHI may be disclosed to alert law enforcement to the death if entity suspects that death resulted from criminal conduct.
                                        • The CCBDD may disclose to a law enforcement official protected health information that the CCBDD believes in good faith constitutes evidence of criminal conduct that occurred on the premises of the CCBDD.
                                      • Reporting Commission and Nature of Crime. PHI may be disclosed to law enforcement personnel to report the commission and nature of a crime; The location of such crime or of the victim(s) of such crime; and the identity, description, and location of the perpetrator of such crime. When responding to requests about the location of a suspect, fugitive, material witness, or missing person, the following PHI may be released:
                                        • Name and address
                                        • Date and place of birth
                                        • Social security number
                                        • ABO blood type and RH factor
                                        • Type of injury
                                        • Date and time of treatment
                                        • Date and time of death, if applicable,
                                        • A description of distinguishing physical characteristics, including height, weight, gender, race, hair and eye color, presence or absence of facial hair, scars, and tattoos
                                      • Compliance/Enforcement of privacy regulations: PHI must be disclosed as requested, to the Secretary of Health and Human Services related to compliance and enforcement efforts.
                                    • To coroners, medical examiners, and funeral directors
                                      • PHI may be disclosed to coroners, medical examiners and funeral directors, as necessary for carrying out their duties.
                                    • Organ, eye or tissue donation
                                      • PHI of potential organ/tissue donors may be disclosed to the designated organ procurement organization and tissue and eye banks.
                                    • To reduce or prevent a serious threat to public health and safety and/or safety of person(s)
                                      • The CCBDD may disclose PHI or Education Records as follows, to the extent permitted by applicable law and ethical standards:
                                        • Good Faith. PHI may be used or disclosed if the entity believes in good faith:
                                          • that the use or disclosure is necessary to prevent or lessen a serious and imminent threat to a person or the public, and disclosure is to someone reasonably able to prevent or lessen the threat; or
                                          • the disclosure is to law enforcement authorities to identify or apprehend an Individual who has admitted to violent criminal activity that likely caused serious harm to the victim or who appears to have escaped from lawful custody.
                                      • Disclosure of Individual’s Admitted Participation in a Violent Crime. Disclosures of admitted participation in a violent crime are limited to the Individual’s statement of participation and the following PHI: name, address, date and place of birth, social security number, blood type, type of injury, date and time of treatment, date and time of death, if applicable, and a description of distinguishing physical characteristics.
                                      • Disclosure of Individual’s Admitted Participation in a Violent Crime Learned in the Course of Treatment. Disclosures of admitted participation in a violent crime are not permitted when the information is learned in the course of treatment entered into by the Individual to affect his/her propensity to commit the subject crime, or through counseling, or therapy or a request to initiate the same.
                                    • Specialized government functions
                                      • National Security and Intelligence: PHI may be disclosed to authorized federal officials for the conduct of lawful intelligence, Counterintelligence, and other activities authorized by the National Security Act.
                                      • Protective Services: PHI may be disclosed to authorized federal officials for the provision of protective services to the President, foreign heads of state, and others designated by law, and for the conduct of criminal investigations of threats against such persons
                                      • Correctional Institution or Law Enforcement Official. The CCBDD may disclose to a correctional institution or a law enforcement official having lawful custody of an inmate or other Individual protected health information about such inmate or Individual, if the correctional institution or such law enforcement official represents that such protected health information is necessary for:
                                        • The provision of health care to such Individuals;
                                        • The health and safety of such Individual or other inmates;
                                        • The health and safety of the officers or employees of or others at the correctional institution;
                                        • The health and safety of such persons and officers or other persons responsible for the transporting of inmates or their transfer from one institution, facility, or setting to another;
                                        • Law enforcement on the premises of the correctional institution; and
                                        • The administration and maintenance of the safety, security, and good order of the correctional institution.
                                        • The provisions of this section do not apply after the Individual is released from custody.
                                      • Public Benefits: PHI relevant to administration of a government program providing public benefits may be disclosed to another governmental program providing public benefits serving the same or similar populations as necessary to coordinate program functions or improve administration and management of program functions.
                                    • In connection with “whistleblowing”.  In connection with “whistleblowing”, or reporting of a violation of law or ethics, an employee of CCBDD may disclose PHI to his/her attorney, and to other parties specified in Ohio Revised Code § 4113.52, while following the procedures outlined in that statute.   See also Policy 324 Protection of Whistleblowers.
                                    • For workers’ compensation or other similar programs if applicable.
                                      • PHI may be disclosed as authorized and to the extent necessary to comply with laws relating to workers’ compensation and other similar programs.

                                      2400.02 INDIVIDUAL RIGHTS

                                      2400.02.01 Individual’s Right to Access Records

                                      Adopted: 7/1/2013

                                      Revised Date:

                                      Effective:

                                      POLICY

                                      Individuals served by CCBDD, and their personal representatives, have the right to access and/or inspect the PHI and/or Education Records contained in the designated record set, subject to any limitations imposed by law.

                                      AUDIENCE

                                      Privacy Officer, Supervisors

                                      AUTHORITY

                                      45 CFR § 164.524(e) individual’s right to access PHI

                                      45 CFR § 164.524(b) Time limits on response to access

                                      45 CFR § 164.524(c) Form of access

                                      34 CFR 99.4 Rights of Parents

                                      34 CFR 300.613(c) IDEA Rights of parents

                                      ORC § 1347.08(A)(2) individual’s right to access records

                                      OAC § 3301-51-04 Confidentiality, for Education of Students with Special Needs

                                      OAC § 5123:2-1-02(M) County Board Administration – Records

                                      LEGAL NOTES

                                      • State laws, HIPAA, and FERPA all provide that Individuals receiving services have access to their records.
                                      • State law, OAC 5123:2-1-02 was amended 1/1/2015 to harmonize with HIPAA and FERPA

                                      PROCEDURES

                                      • Who May Access Records
                                        • An Individual served by the Agency above the age of 18, the parent/guardian of a child, the guardian of an adult not able to act on their own behalf, or any “personal representative” of an Individual served may access the records.  See Policy 2400.01.08 Minors, Personal Representatives and Deceased Individuals
                                        • 3rd Party Review. An Individual or parent may include any 3rd party of their choosing, including an attorney, to review the records.
                                        • Presumption of Parental Right to Access Records. CCBDD may presume that either parent of a minor may have access unless presented with documentation that the parent does not have authority under applicable state law governing such matters as guardianship, separation, or divorce.
                                      • Procedure, form and method of access
                                        • Requests for Access. Requests for access to records shall be directed to the Privacy Officer or his/her designee.
                                        • Verification Procedure. The Privacy Officer shall follow the Verification Procedure to verify the identity of the requestor.  For any grant of access to someone other than the parent, the authority of the requestor to access the information shall also be verified.  This might include documentation of guardianship or documentation that the person was appointed a “Personal Representative” under HIPAA.Forms of Access Requested by the Individual. The CCBDD shall provide the Individual with access to their records in any of the following ways requested by the Individual:
                                          • By inspection.  CCBDD shall provide a private room for the Individual to review the records under the supervision of a CCBDD staff member who will ensure that the record is not altered.
                                          • Photocopy.  CCBDD shall provide a photocopy of the entire record or portion of the record requested.
                                          • Electronic format.  CCBDD shall provide an electronic copy of the information requested if this is feasible; if not, the Security Officer or his/her designee shall negotiate an electronic format and transmission method acceptable to both parties and fulfill the request.
                                            • If the Individual requests the information via email and only unsecured email is available, the Individual shall be notified that this method is subject to electronic eavesdropping.  If the Individual is willing to accept the risks, the info shall be sent via email.
                                            • The Agency shall honor requests for commonly used media, such as USB Flash drives.
                                        • Record of Parties Accessing Records. The Privacy Officer or his/her designee shall maintain a record of parties accessing records (except the access by the Individual or their parent) including the name of the party, the date access was given, and the purpose of access.  These shall be maintained on the Disclosure Log illustrated in the Appendix.
                                      • Other services/rights of Individuals, parents, and guardians
                                        • Explanation and Interpretation of Records. CCBDD will respond to reasonable requests for explanation and interpretation of the records.
                                        • List of Types and Locations of Records Maintained by CCBDD. Upon request, CCBDD must provide Individuals, parents and guardians a list of the types and locations of records maintained or used by CCBDD.
                                        • Known Records Not Maintained by CCBDD. If the CCBDD does not maintain the PHI that is the subject of the Individual’s request for access, and the CCBDD knows where the requested information is maintained, the CCBDD must inform the Individual where to direct the request for access.
                                      • Transfer of rights at Age of Majority
                                        • Rights of parents under these policies and under FERPA and IDEA transfer to the Individual served once that Individual reaches age 18 years.  Once a child reaches age 17 years, the child must be informed of this transfer, and the IEP must include a statement that the child has been informed regarding the transfer of rights.
                                      • Time for response to request for access
                                        • Access shall be granted without unnecessary delay.  In particular, requests should be honored prior to any scheduled IEP meeting, hearing, or administrative procedure.  Requests in all cases shall be honored within 5 business days.
                                      • Fees for copying/electronic media
                                        • CCBDD at present has no fees for photocopies, postage or electronic media used to provide records.

                                          2400.02.02 Individual’s Right to Request Amendment of Records

                                          Adopted: 7/1/2013

                                          Revised Date:

                                          Effective:

                                          POLICY

                                          Individuals receiving services have the right to request that CCBDD amend PHI in the designated record set, or Education Records, that they believe are erroneous.  CCBDD will use procedures compliant with HIPAA, FERPA and/or IDEA in processing any requests for correction.

                                          AUDIENCE

                                          Privacy Officer, Supervisors

                                          AUTHORITY

                                          45 CFR § 164.526(f) Individual’s right to request amendment

                                          OAC § 3301-51-04 Confidentiality, for Education of Students with Special Needs

                                          ORC § 1347.09 Disputing of Records

                                          34 CFR 99.20 FERPA Requesting amendment of records

                                          34 CFR 99.21 FERPA Rights to a Record Hearing

                                          34 CFR 99.22 FERPA Requirements for a Records Hearing

                                          LEGAL NOTES

                                          These policies are designed to simultaneously comply with Federal HIPAA and FERPA regulations as well as Ohio regulations.  All these regulations are similar; where they differ, policies are written to follow the regulations that provide the greatest degree of privilege and right of appeal to the Individual.

                                          PROCEDURES

                                          REQUESTS FOR AMENDMENTS

                                          • Amending Statements Believed to be Inaccurate, Misleading or in Violation of Individual’s Rights. An Individual, parent, guardian, or other person acting as a HIPAA personal representative may request amendment of PHI about the Individual (and exercise rights for hearing and statements of disagreement), which they believe is inaccurate, misleading, or violates the rights of the Individual, and is held by the CCBDD or any Business Associate.  Such request shall be in writing and shall be subject to the requirements set forth in these procedures.
                                          • Responsibility of Privacy Officer. The Privacy Officer of the CCBDD is responsible for receiving requests for amendment, processing the requests, arranging for any hearings, and completing required documentation.
                                          • Time to Act on a Request for Amendment. The CCBDD will act on a request for amendment without unnecessary delay and no later than 60 days after the date of the request.
                                          • Accepted Request for Amendments. If the CCBDD accepts the requested amendment, in whole or in part, CCBDD must make the appropriate amendment, and inform the Individual and other persons or entities who have had access to the information.
                                          • Denied Request for Amendments. Otherwise, if the CCBDD believes the existing record is correct as is, it may deny the amendment:
                                            • Written Notice. If an amendment is denied, the CCBDD will give written notice in plain language which includes the following:
                                              • The basis for the denial;
                                              • The Individual’s right to submit a written statement disagreeing with the denial and how the Individual may file such a statement;
                                              • A statement that, if the Individual does not submit a statement of disagreement, the Individual may request that the CCBDD provide the Individual’s request for amendment and the denial with any future disclosures of the protected health information that is the subject of the amendment; and
                                              • The Individual’s right for a hearing to challenge the information.
                                            • Statement of Disagreement. If the Individual submits a statement of disagreement, the Privacy Officer will insert this statement into the appropriate portion of the record.  Otherwise, the Privacy officer will insert into the record that the Individual requested an amendment and the CCBDD’s denial.
                                            • Written Rebuttal. The CCBDD may prepare a written rebuttal to the Individual’s statement of disagreement. Whenever such a rebuttal is prepared, the CCBDD must provide a copy to the Individual who submitted the statement of disagreement.
                                            • Permanent Record. The inserted statement of disagreement and any rebuttal become a part of the permanent record and must be included with all future disclosures of the covered records.
                                          • Individual’s Request for Copy of Changed Record. At the Individual’s request, CCBDD will send a copy of the changed record to any party requested by the Individual (per ORC 1347.09).
                                          • Separate Transmission of Information in EDI Format. If the disclosure which was the subject of amendment was transmitted using a standard EDI format, and the format does not permit including the amendment or notice of denial, the CCBDD may separately transmit the information to the recipient of the transaction in a standard EDI format.

                                            RECORDS HEARINGS

                                            CCBDD must offer a Records Hearing to any Individual who is denied a requested amendment of their records. 

                                            • Hearing Procedure
                                              • The HIPAA Privacy Officer will arrange the Records Hearing.
                                              • The Privacy Officer must schedule the hearing within a reasonable time upon receiving a request.
                                              • CCBDD shall give the Individual notice of date, time and place reasonably in advance of the hearing.
                                              • To conduct the hearing, the Privacy Officer may appoint any person, including an official of CCBDD, who does not have a direct interest in its outcome.
                                              • During the hearing, the parent shall have a full and fair opportunity to present evidence relevant to their objection.  The Individual or parent may obtain assistance of any person(s), including an attorney hired at their own expense, to assist them.
                                              • The decision shall be based solely on the evidence presented.
                                              • The decision shall be documented in writing, within a reasonable time of the hearing, and shall include a summary of the evidence presented and the reasons for the decision.
                                            • Results of Hearing
                                              • If, as a result of the hearing, CCBDD decides that the information in its records is inaccurate, misleading, or otherwise in violation of the privacy or other rights of the Individual, it must amend the information accordingly and inform the Individual in writing.
                                              • If, as a result of the hearing, CCBDD decides that the information is not inaccurate, misleading, or otherwise in violation of the privacy or other rights of the Individual, it must inform the Individual of their right to place in the record a statement commenting on the information or setting forth any reasons for disagreeing with the decision of CCBDD.
                                              • Any information placed in the record as a result of this hearing, CCBDD must maintain this statement as part of its permanent record, and include it with any subsequent disclosure.

                                                2400.02.03 Individual’s Right to Receive an Accounting of Disclosures

                                                Effective Date: 7/1/2013

                                                Revised Date:

                                                Approved: 7/1/2013

                                                POLICY

                                                CCBDD will provide, upon request, an “Accounting of Disclosures,” in accordance with HIPAA Regulations, to Individuals who receive services from the Agency. 

                                                AUDIENCE

                                                Privacy Officer, Supervisors

                                                AUTHORITY

                                                45 CFR § 164.528

                                                45 CFR § 164.528(d) Individual’s right to an accounting of disclosures of PHI

                                                34 CFR 99.32  FERPA Recordkeeping requirements concerning requests and disclosures

                                                PROCEDURES

                                                1. Proper Records. The Privacy Officer shall be responsible for insuring that proper records are kept to allow for proper and complete responses to any requests for accountings of disclosures.  See also procedures listed in Policy 2400.01.10 Disclosures that do Not Require an Authorization and Policy 2400.01.06 Authorizations which detail the use of the Disclosure Log.
                                                2. Individual’s Right to Request Accounting of Disclosures of PHI. Generally, an Individual has the right to request an accounting of disclosures of their PHI by CCBDD and its business associates during a time period of up to six years prior to the date of the Individual’s request.   Most disclosures are not requiredto be included in the accounting.  The types of disclosures which are not required to be accounted for are:
                                                  1. For the purposes of treatment, payment and health care operations (45 CFR § 164.502);
                                                  1. To the Individual receiving services, or to a parent, guardian or personal representative, of the Individual’s own PHI (45 CFR § 164.502);
                                                  1. Incidental disclosures, as detailed in (45 CFR § 164.502);
                                                  1. Pursuant to an authorization (45 CFR § 164.508);
                                                  1. To persons involved in the Individual’s care or other notification purposes (45 CFR § 164.510);
                                                  1. For national security and intelligence purposes, as detailed in (45 CFR § 164.512(k)(2);
                                                  1. Disclosures to prisons and other law enforcement agencies regarding an Individual who is in custody, as detailed in (45 CFR § 164.512(k)(5).
                                                3. Employee Documentation of Disclosures. Any employee who makes a disclosure other than listed above shall document the disclosure in the Individual File, with all information described in step 6B below.  More specifically, the following types of disclosures must be documented: 
                                                  1. To public health authorities
                                                  1. Birth and death reporting
                                                  1. To law enforcement regarding crime on premises
                                                  1. To law enforcement in emergencies where crime is suspected
                                                  1. For cadaveric organ, eye, tissue donation purposes
                                                  1. For judicial and administrative proceedings
                                                  1. For research with an IRB waiver
                                                  1. To military command authorities
                                                  1. For Workers Comp purposes
                                                  1. To correctional institutions except as detailed in 2G above
                                                  1. About decedents to medical examiners, funeral directors, coroners
                                                  1. For public health activities
                                                  1. About victims of abuse
                                                  1. Regarding child abuse or neglect
                                                  1. To the FDA
                                                  1. To a person who may have been exposed to a communicable disease
                                                  1. To health oversight agencies for audits, civil or criminal investigations, inspections, licensure or disciplinary actions
                                                  1. In response to a court order
                                                  1. In response to a subpoena or discovery request
                                                  1. As required by law for wound or injury reporting
                                                  1. For identification & locating suspect or fugitive
                                                  1. Unlawful and unauthorized disclosures we have knowledge of
                                                4. Requests to Suspend Individual’s Right to Disclosure. Health oversight agencies and law enforcement officials may request a suspension of an Individual’s rights to disclosure.  If such a request is received, follow procedures in 45 CFR §164.528.
                                                5. Compliance with Request for Accounting Within 45 Days. The HIPAA Privacy Officer shall comply with an Individual’s request for an accounting within 45 days of the request.  The CCBDD does not charge a fee for accountings.
                                                6. The written accounting must meet the following requirements:
                                                  1. All disclosures of the Individual’s PHI during the 6 years prior to the request (or such shorter period as is specified in the request) as stated above.
                                                  1. As to each disclosure, the accounting must include:
                                                    1. The date of the disclosure.
                                                    1. The name of the entity or person who received the PHI, and, if known, the address of such entity or person.
                                                    1. A brief description of the PHI disclosed.
                                                    1. A brief statement of the purpose of the disclosure that reasonably informs the Individual of the basis of the disclosure, or as an alternative, a copy of the request for the disclosure.
                                                    1. If during the time period for the accounting, multiple disclosures have been made to the same entity or person for a single purpose, the accounting may provide the information as set forth above for the first disclosure, and then summarize the frequency, periodicity, or number of disclosures made during the accounting period, and the date of the last such disclosure during the accounting period.
                                                    1. If the accounting request includes school records, consult legal counsel regarding the need to obtain records of redisclosures by state or local school officials (see 34 CFR 99.32).
                                                  1. CCBDD will retain documentation (in written or electronic format) for a period of 6 years:
                                                    1. All information required to be included in an accounting of disclosures of PHI.
                                                    1. All written accountings provided to Individual.


                                                2400.02.04 Individual’s Right to Request Additional Restrictions

                                                Effective Date: 7/1/2013

                                                Revised Date:

                                                Approved: 7/1/2013

                                                POLICY

                                                CCBDD supports Individual’s right to request restrictions on the use or disclosure of protected health information which are more stringent than the restrictions defined in organizational policy.  CCBDD maintains procedures compliant with HIPAA regulations to process any requests it receives and to ensure that any requests it agrees to will be properly implemented.

                                                AUDIENCE

                                                Privacy Officer, Supervisors

                                                AUTHORITY

                                                45 CFR § 45 CFR § 164.522(a)

                                                PROCEDURES

                                                1. Refer the Request to CCBDD’ Privacy Officer or Designee:  All requests for additional restrictions on the use or disclosure of PHI will be referred to the HIPAA Privacy Officer, or his/her designee.   Upon receiving a request, the Privacy Officer shall consider the following factors, in the decision to grant or deny the request:
                                                  1. Whether the restriction might cause the organization to violate applicable federal or state law;
                                                  1. Whether the restriction might cause the organization to violate professional standards, including medical ethical standards;
                                                  1. Whether CCBDD’ systems and organization make it very difficult or impossible to accommodate the restriction;
                                                  1. Whether the restriction might unreasonably impede the organization’s ability to serve the Individual;
                                                  1. Whether the restriction appears to be in the best interests of the Individual.
                                                2. Decision Whether CCBDD will agree:  The CCBDD is not obligated to agree to any requests for restriction, except in the unlikely event that the request is not to bill the Medicaid program or other 3rd party payer and that the Individual receiving services agrees to pay for the service themselves.
                                                3. Notify the Individual: CCBDD will notify the Individual of its final decision (whether approving or denying the request) in writing. The notice will be maintained in the Individual’s record.
                                                  1. Granting the Request: If CCBDD agrees to the restriction, the notice to the Individual will clearly state what restriction CCBDD is agreeing to in language the Individual will understand. This notice will state that the restriction will not apply if the information is needed for emergency treatment.
                                                  1. Denying the Request: If the request is denied, the notice will clearly state why the request cannot be complied with, in language the Individual will understand.
                                                4. Take Appropriate Action to Implement Restrictions: If CCBDD agrees to the requested restriction, the Privacy Officer/designee will be responsible for taking appropriate action to implement the restriction. 
                                                5. Modifying or Terminating a Restriction:  An Individual may request a restriction to be eliminated at any time.  If CCBDD desires a modification, consult legal counsel regarding appropriate procedures.
                                                6. Documentation: The Privacy Officer is responsible for maintaining the following documents, to assure that additional privacy protections are handled properly, and assure they are maintained for six years from the date of their creation:
                                                  1. Copies of Individual requests for restrictions.
                                                  1. Copies of any notice informing the Individual about CCBDD’ decision to grant or deny a restriction.
                                                  1. Copies of any written Individual request to terminate a restriction, or alternatively, copies of any documentation in the Individual’s record that the Individual made such request orally.


                                                2400.02.05 Individual’s Right to Request Confidential Communications

                                                Effective Date: 7/1/2013

                                                Revised Date:

                                                Approved: 7/1/2013

                                                POLICY

                                                Individuals (or their parents) are entitled to request confidential communications, including for example, to not receive communications at their home address.  These requests will be honored to the extent that they can be reasonably accommodated with CCBDD administrative systems.

                                                AUTHORITY

                                                45 CFR § 164.502(h) Confidential communications

                                                45 CFR § 164.522(b) Confidential communications requirements

                                                AUDIENCE

                                                Privacy Officer

                                                PROCEDURES

                                                1. Individual’s Right to Request Confidential Communications. Individuals, or their personal representative, may make a request for confidential communications in writing to the Privacy Officer. 
                                                2. Receiving a Request. When the Privacy Officer receives a request, the Privacy Officer may not ask the reason for the request.  The Privacy Officer shall contact the Individual making the request to obtain an alternate means of contacting them (e.g. cell phone, PO Box, etc.).  The Individual will be informed at that time of steps CCBDD will take to implement the request.
                                                3. Implementing the Request. If existing systems are capable of administering the request, the Privacy Officer shall take necessary steps to implement the request, such as adjusted phone numbers or addresses in computer files or mailing lists.
                                                4. Documenting the Request. The Privacy Officer shall document the request, and disposition, in the Individual’s Record.
                                                5. Recommending Necessary Improvements in Computer Systems or Administrative Procedures. When needed, the Privacy Officer will make recommendations to the Superintendent of improvements necessary in computer systems or administrative procedures in order to implement reasonable requests for confidential communications.

                                                2400.02.06 Individual’s Right to Notice of Privacy Practices

                                                Effective Date: 7/1/2013

                                                Revised Date:

                                                Approved: 7/1/2013

                                                POLICY

                                                Individuals (or their parents) are entitled to a Notice detailing the privacy practices of the Agency.  CCBDD will provide such Notice to each Individual (or their parents), in a manner compliant with both the HIPAA and FERPA regulations

                                                AUTHORITY

                                                45 CFR § 164.520 Notice of privacy practices for protected health information

                                                45 CFR § 164.502(i) Uses and disclosures consistent with Notice

                                                34 CFR 99.7 Notice (FERPA)

                                                34 CFR 300.612 Notice (IDEA Part B)

                                                34 CFR 303.404 Notice (IDEA Part C)

                                                ORC § 1347.08(A)(3) (Personal Information Systems)

                                                OAC 3301-51-05

                                                OAC § 5123:2-1-02(M) County Board Administration – Records

                                                34 CFR 99.7 FERPA Annual Notification

                                                LEGAL NOTES

                                                FERPA and IDEA require an annual Notice.  HIPAA requires a one-time Notice, with redistribution upon change.  HIPAA requires signed acknowledgement of receipt.

                                                AUDIENCE

                                                Privacy Officer

                                                PROCEDURES

                                                1. Drafting of Notice. The Privacy Officer shall draft a Notice which is compliant with the requirements of the HIPAA, FERPA and IDEA regulations as well as OAC 3301-51-04(C).  This shall include translations as necessary based on the language needs of the Individuals served. Further, the Notice shall be consistent with the Agency’s privacy practices as detailed in these policies. Notice is detailed in Appendix, Notice of Privacy Practices.
                                                2. Updating Notice.  The Privacy Officer shall update the Notice as necessary based on changes in the Agency’s privacy policies and/or the legal requirements as necessary.  Upon update, the website and Notices posted at each facility (see below) shall be updated. Additionally, an updated copy will be provided to all Individuals receiving services and/or parents.
                                                3. Distribution of Notice. The Privacy Officer shall ensure that Agency policies and procedures, namely Policy 2400.02.06 Individual’s Right to Notice of Privacy Practices are maintained to ensure appropriate distribution of Notice:
                                                  1. All adults at intake, and children attaining age 18 as part of the Transfer of Parental Rights at Age of Majority, will be given a copy of the Notice of Privacy Practices.  At the time that the Notice is provided, the Individual or guardian, shall sign an acknowledgement of his or her receipt of this Notice as part of the intake/transition of rights paperwork.  This acknowledgement will be retained as part of the permanent record, for compliance with HIPAA requirements.
                                                  1. While the Individual is under age 18, the IDEA/FERPA Notice is included in the document Whose IDEA is This? and is distributed annually to all parents annually.
                                                  1. An additional copy of the Notice shall further be provided upon request by an Individual or parent.
                                                4. Posting of Notice. The Privacy Officer shall ensure that the Notice is posted:
                                                  1. Website.  On the Agency’s website.
                                                  1. At Each Facility.  At each facility, in a place where Individuals served can be reasonably expected to see the Notice, such as the reception areas of all Agency facilities.
                                                  1. Copies of the Notice will be maintained for 6 years, as detailed in Policy 803 Records Retention and Destruction.

                                                  IN PROCESS