Finance & Management Services

Privacy:


The privacy regulation specifies how health care organizations and their business partners transfer, receive, handle, protect and disclose protected health information (PHI). The regulation applies to all forms of PHI, whether paper, oral or electronic.

Health care organizations are required to create privacy-conscious business practices and data systems, which include the requirement that only the minimum amount of health information necessary is used or disclosed to conduct business. Health care organizations must:

  • Ensure the internal protection of individual health information and implement physical and administrative safeguards.
  • Implement procedures that limit the use and disclosure of PHI to meet the "minimum necessary" standards.
  • Develop mechanisms for the accounting and auditing of all disclosures made for purposes other than treatment, payment or operations.
  • Establish policies and procedures to allow individuals to inspect, copy or correct their health information.
  • Establish contracts and agreements with business associates that ensure
    the protection of PHI, which is shared or traded.
  • Provide privacy training to members of its workforce who have access to PHI.
  • Establish policies and procedures to allow individuals to log complaints about the entities information practices.
  • Designate a privacy official.
  • Enforce penalties for misuse or inappropriate use of health information.
  • Create and make available documentation regarding the compliance with all the requirements of the regulation.

The compliance date for the privacy regulation was April, 2003.

Modifications to the final privacy rule were finalized on August 14, 2002. The modifications include key revisions to address public concerns. The regulation text as well as the text of the modifications can be found at the Office of Civil Rights.

The Alaska Department of Health and Social Services has created an annotated version of the combined privacy and security regulations with additional helpful annotations to assist readers in locating and tracking the regulation information.

PDF Icon PDF version of DHSS Combined Annotated Privacy & Security Regulations.

PDF Icon PDF version of the Index to the Combined Privacy & Security Regulations is also available.

The US Department of Health and Human Services website contains additional information and frequently asked questions about the privacy regulations.