Girish Mahajan (Editor)

Protected health information

Updated on
Edit
Like
Comment
Share on FacebookTweet on TwitterShare on LinkedInShare on Reddit

Protected health information (PHI) under US law is any information about health status, provision of health care, or payment for health care that is created or collected by a "Covered Entity" (or a Business Associate of a Covered Entity), and can be linked to a specific individual. This is interpreted rather broadly and includes any part of a patient's medical record or payment history.

Contents

PHI is often sought out in datasets for de-identification before researchers share the dataset publicly. When researchers remove PHI from a dataset they do so in an attempt to preserve privacy for research participants.

United States

Under the US Health Insurance Portability and Accountability Act (HIPAA), PHI that is linked based on the following list of 18 identifiers must be treated with special care:

De-identification versus anonymization

Anonymization is a process in which PHI elements are eliminated or manipulated with the purpose of hindering the possibility of going back to the original data set. This involves removing all identifying data to create unlinkable data. De-identification under the Health Insurance Portability and Accountability Act Privacy rule occurs when data has been stripped of common identifiers by two methods:

  1. The removal of 18 specific identifiers (Safe Harbor Method):
2. Obtain the expertise of an experienced statistical expert to validate and document the statistical risk of re-identification is very small (Statistical Method).

De-identified data is coded, with a link to the original, fully identified data set kept by an honest broker. Links exist in coded de-identified data making the data considered indirectly identifiable and not anonymized. Coded de-identified data is not protected by the HIPAA Privacy Rule, but is protected under the Common Rule. The purpose of de-identification and anonymization is to use health care data in larger increments, for research purposes. Universities, government agencies, and private health care entities use such data for research, development and marketing purposes.

Covered Entities

In general, US law governing PHI applies to data collected in the course of providing and paying for healthcare. Privacy and Security regulations govern how doctors, hospitals, health insurers and other Covered Entities use and protect the data they collect. It is important to understand that the source of the data is as relevant as the data itself when determining if something is PHI under US law. For example, you may observe someone on the street with an obvious medical condition such as an amputation. US law does NOT restrict you from using or sharing that information. However, if you had obtained information about the amputation exclusively from a protected source, such as from an electronic medical record, the data would be protected.

Business Associates

Covered Entities often use third parties to provide certain health and business services. If they need to share PHI with those third parties it is the responsibility of the Covered Entity to put in place a Business Associate Agreement that holds the third party to the same standards of Privacy and Confidentiality as the Covered Entity.

Magnitude

The consumers are required to get all the details regarding the importance of the protected health information and how to adapt that in their healthy routine. There are so many products which have their own importance and no any other product could replace it.

The quality, it holds the major importance as the product of poor quality will give the poor results. So, to get the desired outcomes always go for a good quality to buy any healthcare product as no any person can compromise with the health.

Protected Health Information : Consumer Information for Health Care==References==

References

Protected health information Wikipedia