| Title: |
| Category: HIPAA Compliance |
Authority: 45 CFR §
HIPAA Section: 164.514(e) |
| Standard: Limited Data Sets |
Responsibility: Health Care Components |
| Effective Date: 04/14/2003 |
Page 1 of 1 |
| Approved by: OSU Legal Counsel |
Revised: |
| Purpose |
Identify limited data sets and permitted usage.
|
| Policy |
CHS may use and disclose a limited data set without authorization for the purposes of research, public health, or operations if CHS and the recipient of the data enter into a data use agreement.
|
| Procedure |
- Definition: A limited data set is PHI that does not identify the patient, but does contain certain information that might potentially identify the patient.
- Creation of a limited data set requires the following identifiers be removed from the data:
- Name
- Social Security number
- Medical record/account numbers
- Health plan beneficiary numbers
- Postal information excluding city, state, and zip codes
- Telephone or fax numbers
- Email addresses
- License numbers
- Vehicle identifiers, including license plate numbers
- Device information, including serial numbers
- Technical information, including URL or IP addresses
- Biometrics, including fingerprint and voiceprints
- Photographs and other identifiable images
- All data use agreements must be approved by the Compliance Office prior to execution. A data use agreement must
- Establish permitted uses and disclosures of the limited data set
- Establish who is permitted to use/receive the limited data set
- Establish the recipient will not use or disclose the information other than permitted, safeguard the data, report any unauthorized use or disclosure, and not identify or contact the patients
|
|