Notice of Privacy Practices

Odyssey Travel Health, PLLC

Health Information Privacy Policies and Procedures

General


Introduction:

It is the policy of Odyssey Travel Health, PLLC (“Practice”) that all personnel must preserve the integrity and confidentiality of protected health information (“PHI”) and other sensitive information pertaining to its patients.  The purpose of these Privacy Policies and Procedures is to ensure Practice’s compliance with applicable standards, implementation specifications, and requirements of the Washington State Uniform Health Care Information Act (the “Act”). Furthermore, the purpose of these Privacy Policies and Procedures is to ensure that Practice and its workforce have the necessary medical and other information to provide the highest quality medical care possible while protecting the confidentiality of that information in accordance with applicable law. 


General Policy:

Practice and its personnel shall not use or disclose PHI, except as permitted or required by the Act. All Practice workforce members are required to comply with all Privacy Policies and Procedures. In addition, workforce members are expected to report known or suspected violations of the Privacy Policies and Procedures by others. Reports of violations should be in writing and directed to Practice’s Privacy Officer, Lisa Garza.


Procedures:

  1. Practice and its personnel are permitted to use or disclose PHI as follows:
  • to the individual patient;
  • for treatment, payment, or health care operations as permitted under the Act;
  • incident to a use or disclosure otherwise permitted or required by the Act, provided that such use or disclosure is limited to the minimum necessary to accomplish the intended purpose of the use, disclosure or request;
  • pursuant to and in compliance with a valid authorization for use and disclosure of PHI from the individual pursuant to the Authorizations for the Use or Disclosure of PHI Policies and Procedures; and
  • as otherwise permitted or required under the Act.

2) Practice and its personnel are required to disclose PHI as follows:

  • to an individual, when requested in accordance with these the Act Privacy Policies, and 
  • when required by the Washington State Department of Health to determine Practice’s compliance with the Act.

3) The Privacy Officer shall investigate whenever there is a credible allegation that a

violation of these the Act Privacy Policies and Procedures has occurred and shall

recommend appropriate sanctions for such violations, if any.

4) When using or disclosing PHI or when requesting PHI from another health care

provider, Practice will make reasonable efforts to limit PHI to the minimum necessary to

accomplish the intended purpose of the use, disclosure, or request. The foregoing minimum necessary requirement does not apply to the following:

  • disclosures to or requests by a health care provider for treatment;
  • uses or disclosures made to the individual, as permitted or required under the Act;
  • uses or disclosures made pursuant to an authorization by an individual where authorization is required under the Act;
  • disclosures made to the Washington State Department of Health as required to investigate or determine Practice’s compliance with the Act;
  • uses or disclosures that are required by law under the Act; and 
  • uses or disclosures that are required for compliance with the applicable requirements of the Act.

Permitted Uses and Disclosures

General Policy:  

Practice is permitted to use and disclose PHI in specific instances as permitted by the Act without a patient authorization.

Procedures:

  1. Treatment, Payment and Health Care Operations. Practice personnel are permitted to use (in some instances) or disclose PHI for treatment, payment and healthcare operations purposes as follows:
    1. Practice may use or disclose PHI for its own treatment, payment, or health care operations.
    2. Practice may disclose PHI for treatment activities of a health care provider.
    3. Practice may disclose PHI to another health care provider for the payment activities of the entity that receives the information.
    4. Practice may disclose PHI to another health care entity for health care operations activities of the entity that receives the information, if each entity either has or had a relationship with the individual who is the subject of the PHI being requested, the PHI pertains to such relationship, and the disclosure is:
      1. Conducting quality assessment and improvement activities, including outcomes evaluation and development of clinical guidelines, provided that the obtaining of generalizable knowledge is not the primary purpose of any studies resulting from such activities; patient safety activities (as defined in 42 CFR 3.20); population-based activities relating to improving health or reducing health care costs, protocol development, case management and care coordination, contacting of health care providers and patients with information about treatment alternatives; and related functions that do not include treatment; 
      2. Reviewing the competence or qualifications of health care professionals, evaluating practitioner and provider performance, health plan performance, conducting training programs in which students, trainees, or practitioners in areas of health care learn under supervision to practice or improve their skills as health care providers, training of non-health care professionals, accreditation, certification, licensing, or credentialing activities.
      3. For the purpose of health care fraud and abuse detection or compliance.
  1. Permissible Disclosures.  Practice personnel are permitted to use or disclose PHI without a patient authorization as follows:
    1. As required by law.
    2. To the appropriate state or federal health authority conducting public health surveillance, public health investigations, public health interventions and the Food and Drug Administration regulatory oversight.
    3. Limited fundraising – as long as the client is able to opt out.
    4. For health oversight activities.
    5. Reporting the suspected abuse or neglect of a child or vulnerable adult as required by federal and state law.
    6. Cooperating with ongoing investigations related to the suspected abuse of a child or vulnerable adult.
    7. Responding to a subpoena or court order from a federal, state or county court, in which case attempts must be made to notify the individual of the disclosure.
    8. Responding to legal action initiated by a client against the agency regarding services provided.
    9. Limited law enforcement purposes when the disclosure of PHI is reasonably believed to be evidence of criminal conduct on the premises of the Practice.
    10. To a law enforcement official who requests such information to identify or locate a suspect, fugitive, material witness, or missing person. In this case only very limited PHI would be disclosed.
    11. About decedents to coroner, medical examiner or funeral director.
    12. For research purposes, if approved by an Institutional Review Board.
    13. In order to avert a serious threat to health or safety including reporting the imminent danger of a client to self or others as required by state law.
    14. For some specialized government functions related to military, veterans, armed forces, national security or intelligence activity, and correctional institutions and custodial situations.
    15. For some government programs providing public benefits.
    16. To assist with workers compensation claims.
    17. To business associates as outlined in the Business Associate Agreements Policy and Procedure.
    18. As otherwise permitted by the Act.

Sanctions Policy

General Policy

Whenever there is a credible allegation that a violation of a patient’s privacy rights has occurred, Practice shall investigate the allegation and shall recommend appropriate sanctions for such violations, if any.

Procedures

Sanctions for workforce members may include, but are not limited to verbal warnings, written warnings, paid and unpaid suspensions, and termination, in accordance with applicable personnel policies.

    1. Definition of a Violation: The level of breach in patient confidentiality or privacy violation is determined according to the severity of the breach or violation, whether the breach or violation was intentional or unintentional, and whether the breach or violation indicates a pattern or practice of improper use or release of confidential patient information or violation of patient privacy. The degree of discipline may range from a verbal warning to immediate termination. 
      1. Class I Violation(s): Carelessness or Inadvertent action. This level of breach or violation occurs when a Practice workforce member unintentionally or carelessly accesses, reviews, or releases confidential patient information without a legitimate business reason. Examples include, but are not limited to: 
        Leaving PHI in an unsecured area where it might be viewed by others;
        1. Leaving a computer unattended while the workforce member is logged on to a system containing PHI;
          Sharing PHI with another workforce member without authorization or unrelated to the performance of the workforce member’s duties;
          Discussing PHI in public areas where you can be overheard (i.e. patient waiting room, restroom, etc.); or
        2. Faxing documents to the wrong location or mailing/giving documents to the wrong person/patient.
          Class II Violation(s): No Personal Gain.  This level of breach or violation occurs when a workforce member intentionally accesses or releases confidential patient information for purposes other than the care of the patient or other authorized purposes but for reasons unrelated to personal gain. Examples include but are not limited to: 
        1. The sharing of computer access codes (username & password); or
          The use of another person’s computer access codes (username & password).
      2. Class III Violation(s): Personal Gain or Malice. This level of breach or violation occurs when a workforce member accesses, reviews, or releases confidential patient information for personal gain or with malicious intent. Examples include, but are not limited to: 
        Accessing or reviewing a health record of a patient, such as reviewing the record of a patient in the news, another workforce member’s information or a public personality.
        Using and/or disclosing PHI for commercial advantage, personal gain or malicious harm; or
        Obtaining PHI under false pretenses.
        Sanctions: Violation of this policy will result in action appropriate to the circumstances, the class of offense, and whether there is a pattern of repeated violations.  The following steps are guidelines for disciplinary action for privacy breaches and violations. Risk to patients or staff and other serious offenses may warrant deviation from these guidelines. Such disciplinary actions may include, but are not limited to, any one or more of the following:
        Class I Violation(s):
        First Offense: A documented warning.
        Multiple Offenses: Each subsequent Class I Violation constitutes a Class II Violation.
        Class II Violation(s):
        First Offense: Depending on the facts, (1) documented warning, and/or (2) final written warning/last chance agreement.
  • Multiple Offenses: Depending on the facts, (1) final written warning/last change agreement, (2) suspension up to five days without pay, documented and maintained in the workforce member’s file, and/or (3) immediate termination with reports to appropriate agencies if applicable.
    Class III Violation(s):
    First or Subsequent Offense: Depending on the facts, (1) suspension up to five days without pay, documented and maintained in the workforce member’s file, and/or (2) immediate termination with reports to appropriate agencies if applicable. 
    Civil and criminal penalties as provided under the Act and other applicable Federal/State/Local laws. 
    Exceptions: No sanctions or retaliatory actions shall apply to:
    Whistleblowers.  Workforce members who believe in good faith that Practice has engaged in conduct that is unlawful or otherwise violates professional or clinical standards, or that the care, services, or conditions provided by Practice potentially endanger patients, workers, or the public shall not be sanctioned for disclosing PHI to the following individuals or entities:
    A health oversight agency or public health authority authorized by law to investigate or oversee the conduct or conditions of Practice so long as the purpose of the disclosure was to report the allegation regarding Practice’s failure to meet the relevant legal or professional standards;
    A health care accreditation organization, so long as the purpose of the disclosure was to report the allegation regarding Practice’s failure to meet the relevant legal or professional standards; or
    An attorney retained by or on behalf of the workforce member for the purpose of determining the legal options that the member has with regard to Practice’s alleged illegal or unprofessional conduct under Section 3.a.
    Individuals who oppose actions that violate the Act.  Sanctions will not be applied to any individual for the following:
    Filing a truthful complaint with the Washington State Department of Health, or other governmental agency, regarding a privacy violation;
      1. Testifying, assisting, or participating in any official investigation, compliance review, proceeding, or hearing under the Act; or
        Opposing any act of Practice that violates the Act, as long as the individual doing so believes in good faith that the act of Practice is unlawful, and the manner of the opposition is reasonable and does not involve making a disclosure of PHI that violates the Act.

Authorizations for the Use or Disclosure of PHI

General Policy:

Except in the circumstances permitted by the Act and/or described in Practice’s Privacy Policies and Procedures, Practice will not use or disclose a patient’s PHI without first obtaining the patient’s written authorization.

Procedures:

  1. Authorization Forms.  Workforce members shall use the authorization forms that have been developed by Practice to comply with all of the requirements for such forms outlined in the Act and shall not alter those forms in any way.  The authorization forms should be in the same or similar format as the form located at Appendix A of this Policy. 
  1. Incomplete Authorizations.  Authorization forms that are not filled in completely, or that are not signed and/or dated will not be accepted.  Incomplete authorizations are not valid, and disclosures made pursuant to them are not “authorized” under our privacy policies.
  1. Treatment Conditioned on Authorization.  Practice will not condition the provision of treatment on a patient’s provision of an authorization, except:
  1. a) The provision of research-related treatment may be conditioned on a patient’s authorization to have the information generated from that treatment released as part of the research.  
  2. b) The provision of treatment, the sole purpose of which is to create information for release to third parties, may be conditioned on a patient’s authorization to have the information released to the relevant third parties.  For instance, if a patient has requested a physical examination for the sole purpose of having the results of that examination released to his or her employer, Practice may refuse to perform the examination if the patient refuses to authorize the release of PHI regarding that exam to the employer.
  1. Revocation of Authorization.  As a general rule, patients may revoke their authorizations, in writing, at any time.  Revocations become effective when the patient has revoked such authorization in writing and submitted it to Practice.  Exceptions to this general rule are:
  1. a) If Practice has already taken action in reliance on an authorization, the revocation is not effective with respect to those actions.  
  2. b) If the patient signed an authorization as a condition of receiving insurance coverage, a revocation of that authorization will not be effective to impede an insurer’s contest of a claim under the policy.
  1. Authorization Required When Patient Seeks Disclosure. If a patient seeks disclosure of his or her PHI for any purpose for which an authorization is required, the patient shall complete an authorization form.  A copy of the completed form shall be given to the patient and the original shall be sent to the Privacy Officer.  The Privacy Officer shall review the form and make the disclosure, if appropriate.  If the form is not complete, the Privacy Officer shall contact the patient to notify him or her that additional information is needed.  The Privacy Officer shall file the authorization form in the patient’s medical record.
  1. Authorization for Disclosure for Marketing Purposes. Practice shall follow the Disclosure of PHI for Marketing Policy prior to disclosing any PHI for marketing purposes.

Appendix A

Odyssey Travel Health, PLLC

Authorization to Disclose or Release Protected Health Information

Patient name: ____________________________________________ Date of birth: _______________

I hereby give my permission to Odyssey Travel Health, PLLC (the “Practice”) to disclose my health care information consistent with this authorization.

Please disclose the following health care information about me (check all that apply):

  • All health care information in my medical record.
  • Health care information in my medical record relating to the following treatment or condition: ____________________________________________________________________________________________
  • Health care information in my medical record for the date(s): _______________________________
  • Other (e.g. bills), specify date(s):_____________________________________________________

Please disclose health care information about me regarding testing, diagnosis, and treatment for the sensitive health information below (check all that apply).  If none of the below boxes are checked, no information related to the testing, diagnosis or treatment of the categories below will be disclosed pursuant to this authorization.  I understand that if I want to authorize Practice’s disclosure of this information later, I will be asked to sign another authorization.  

  • HIV (AIDS virus)
  • Sexually transmitted diseases
  • Psychiatric disorders/mental health 
  • Drug and/or alcohol use

Please disclose this health care information to:

Name (or title) and organization: _______________________________________________________________

Address: ____________________________________________City: _______________ State: _____   Zip:__________ 

Phone:                     Fax: _______________________________  

Reason(s) for this authorization (check all that apply):

  • At my request 
  • Care coordination with other provider(s)
  • To my attorney
  • Insurance
  • Marketing
  • Medical Leave
  • Other (specify)________________________________________________________________________

This authorization ends: 

  • on (date): _______________________
  • when the following event occurs: _____________________________________________________________

I understand that I may change my mind and decide to cancel my authorization to use and disclose my health care information at any time.  I understand that if I choose to revoke my authorization, I need to do it in writing by sending a letter to the person or organization listed above.  I also understand that if I cancel this authorization, the information may have already been used or disclosed before I changed my mind.

I understand that I may refuse to sign this form, and that I do not need to sign it to receive treatment, for payment for health care services to be made, or to enroll or be eligible for benefits.  However, if research-related treatment is going to be provided, or if health care services are going to be provided solely for the purpose of providing health information to someone else and my signature on this authorization is necessary to make such disclosures, I will not receive those health care services if I refuse to sign this authorization. 

I understand that once the health information I have authorized to be disclosed reaches the noted recipient, that person or organization may re-disclose it, at which time it may no longer be protected under privacy laws.

I understand that I have the right to inspect or receive a copy of my protected health information and to receive a copy of this signed form.

________________________________________________________ ________________________________________

Patient or legally authorized individual signature Date Time

____________________________________________       _______________________________

Printed name if signed on behalf of the patient Relationship/ Description of Authority

*** Note: there may be a charge for copying medical records.

Incidental Disclosures of PHI

General Policy:

Incidental disclosures are disclosures of PHI that occur as a by-product of a permissible use or disclosure, are limited in nature, and cannot be prevented through the use of reasonable measures.  Incidental disclosures do not violate Practice’s Privacy Policies and Procedures as long as: (1) reasonable measures were taken to prevent the incidental disclosure; and (2) the disclosure resulted from a use or disclosure that is otherwise permissible under Practice’s Privacy Policies and Procedures, including policies regarding using or disclosing the minimum necessary information.  

Procedures:

  1. The following measures are considered reasonable with respect to the prevention of incidental disclosures and shall be followed when applicable:
  1. a) Compliance with the Policy Regarding Transmission of PHI via Facsimile, Policy Regarding Transmission of PHI via E-mail, and the Policy Regarding Transmission of PHI via Telephone shall constitute reasonable measures for the prevention of incidental disclosures when receiving or disclosing PHI via telephone, e-mail or fax.
  2. c) When discussing PHI in any non-private area (e.g., a waiting room, reception area, or hall), all conversations should be kept as low as reasonably possible.  Private areas should be used for such discussions whenever reasonably possible.  If PHI is communicated via sign language, reasonable efforts should be made to move the discussion out of plain view of passersby.  
  3. d) Computer screens should be set-up out of view of patients.

Notice of Privacy Practices

General Policy:  Practice will make a good faith effort to obtain written acknowledgement of receipt of Practice’s Notice of Privacy Practices from every patient before the date of the first service delivery to the extent practicable. In an emergency treatment situation, Practice will provide the Notice as soon as reasonably practicable after the emergency treatment.

If a written acknowledgement cannot be obtained from the individual, reasons why and efforts to

obtain one will be documented.

Procedures:

  1. Distribution of Notice of Privacy Practices: The Practice maintains a Notice of Privacy Practices, which describes patient rights and Practice’s permitted uses and disclosure of PHI.
  1. Provide the Notice to every patient or patient’s personal representative before or at the first delivery of service. Provide a new copy of the Notice whenever the Notice is updated, even if the patient has previously received a Notice.
  2. Ask the patient to sign the Acknowledgement Form at Appendix A of this Policy when they receive the Notice. If the patient cannot or will not sign the acknowledgement, note the reason on the form and any effort made to obtain the signature. The patient may be treated even if he/she does not sign the Acknowledgement Form.
  3. Provide the patient with a copy of the Acknowledgement Form. Maintain the original Acknowledgement Form in the patient’s record.
  1. Records Retention
  1. The original paper Acknowledgement Form, or an electronic scanned version of this document must be stored in an easily retrievable location for at least six (6) years.
  1. Review and Changes to the Notice

The Notice will be reviewed periodically to ensure compliance with the Act requirements. 

Appendix A

ACKNOWLEDGEMENT OF RECEIPT OF

NOTICE OF PRIVACY PRACTICES

This form will be retained in your medical record.

By my signature below I, ___________________________________, acknowledge that I received a copy of the Notice of Privacy Practices for Odyssey Travel Health, PLLC

___________________________________________ _____________________

Signature of patient (or personal representative) Date

If this acknowledgment is signed by a personal representative on behalf of the patient, complete the following:

Personal Representative’s Name: ___________________________________________

Relationship to Patient: ___________________________________________

For Office Use Only

I attempted to obtain written acknowledgement of receipt of our Notice of Privacy Practices, but acknowledgement could not be obtained because:

□ Individual refused to sign

□ Communications barriers prohibited obtaining the acknowledgement

□ An emergency situation prevented us from obtaining acknowledgement

□ Other (Please Specify)

______________________________________________________________________

______________________________________________________________________

_________________________________________ _____________________

Employee Name Date

Patient Request to Access Medical Records

General Policy:  Except as specifically limited by this Policy, Practice shall allow patients to inspect and obtain a copy of PHI about the patient that is maintained in a designated record set.  Requests for access must be made in writing and should be directed to Practice’s Privacy Officer. 

Procedures:

  1. Inquiries. All patients who inquire about accessing their medical records shall be notified that requests for access must be made in writing.
  1. Non-Reviewable Grounds for Denial of Access.  Access may be denied under the following circumstances.  Denials for these reasons are final and non-reviewable:
  1. Knowledge of the health care information could reasonably be expected to lead to the patient’s identification of an individual who provided the information in confidence and under circumstances in which confidentiality was appropriate;
  1. The health care information was compiled and is used solely for litigation, quality assurance, peer review, or administrative purposes; or
  1. An individual’s access to the health care information that is contained in records that are subject to the Privacy Act, 5 U.S.C. 552a, may be denied, if the denial of access under the Privacy Act would meet the requirements of that law. 
  1. Reviewable Grounds for Denial of Access.  Access may be denied under the following circumstances.  Patients may request to have these denials reviewed by a licensed health care professional who was not involved in the original denial determination:  
  1. Knowledge of the health care information would endanger the life or physical safety of the patient or another person.
  1. Action on Requests.  Upon receiving a written request for access, the Privacy Officer or his or her designee shall review the request in accordance with the policies set forth in Paragraphs 1 through 3 of this policy.  
  1. General Rule.  Within fifteen (15) days, the Privacy Officer shall determine whether access will be granted in full, granted in part, or denied; shall inform the patient of the decision; and shall provide the access that is granted, if any. 
  1. Extensions of Time.  If the subject record is in use, or unusual circumstances have delayed the handling of the access request, the Privacy Officer may inform the patient and specify in writing, the earliest date, not later than twenty-one (21) days after receiving the request, when Practice will respond to the patient’s request.
  1. Providing Access.  Practice will provide access to the records in accordance with this Section 5.
  1. Form or Format.  If access is granted, the patient will be provided the information in the form or format requested if the information is readily available in that format.  If records are not readily available in the format requested, the patient shall be provided a readable hard copy of the information.
  1. Electronic Format.  If a patient requests an electronic copy of his or her PHI, and if the requested PHI is maintained electronically by Practice, Practice must provide the patient with access to the PHI in the electronic form and format requested by the patient (e.g. Adobe PDF), if it is readily producible in such form and format; or, if not, in a readable electronic form and format as agreed to by Practice and the patient.
  1. Summary Alternative.  Practice may provide the patient with a summary of the requested PHI, in lieu of providing access to the PHI or may provide an explanation of the PHI to which access has been provided, if the patient agrees in advance to such a summary or explanation, and the patient agrees in advance to the fees imposed (if any) by Practice for such summary or explanation.
  1. In-Person Access.  If the patient requests in-person access to his or her medical records, the Privacy Officer shall provide the phone number of the appropriate records staff person so that the patient may contact this person to arrange for in-person inspection.  The patient will be informed that Practice personnel must be present at all times during inspection of the medical record.  
  1. Third Party Access.  If a patient’s request for access directs Practice to transmit the copy of PHI directly to another person designated by the patient, Practice must provide the copy to the person designated by the patient. The patient’s request must be in writing, signed by the patient, and clearly identify the designated person and where to send the copy of PHI.
  1. Denying Access.  All patients who have had their request denied will be sent a written denial within the timeframes set forth in Paragraph 3 above.
  1. Access Upon Denial.  If Practice denies access to a patient’s requested PHI, Practice will, to the extent possible, give the patient access to any other PHI requested after excluding the PHI to which Practice has a ground to deny access.
  1. Information Not Maintained.  If Practice does not maintain the requested information, Practice shall provide the patient with the name of the person or entity who maintains the information, if known
  1. Review.  If a patient’s request for access is denied under this policy, Practice shall permit examination and copying of the record by another health care provider, selected by the patient, who is licensed, certified, registered, or otherwise authorized under the laws of Washington State to treat the patient for the same condition as Practice. Practice shall inform the patient of the patient’s right to select another health care provider under this subsection. The patient shall be responsible for arranging for compensation of the other health care provider so selected.
  1. Fees.  If a patient requests a copy of the PHI or agrees to a summary or explanation of such information, Practice may charge a reasonable cost-based fee in accordance with the Act and applicable state laws pertaining to patient access to medical records.
  1. Requests and Responses.  All correspondence regarding requests for access shall be maintained in the patient’s record for a minimum of six (6) years.

Patient Request for Restrictions
on the Use and Disclosure of PHI

General Policy:  Practice’s Privacy Officer or his or her designee may grant a patient’s request to restrict the use or disclosure of the patient’s PHI, subject to the limitations set forth in this policy.  

Procedures:

  1. Requests for Restrictions.  If a patient asks to restrict the use or disclosure of PHI, the patient shall submit a written request to Practice’s Privacy Officer.  
  1. Practice is not required to agree to a requested restriction, except if a patient’s request is to restrict disclosure of PHI to a health plan for the purpose of carrying out payment or health care operations, the disclosure is not otherwise required by law, and the PHI pertains solely to a health care item or service which has been paid in full by the patient or another person or entity on the patient’s behalf.  
  1. If Practice agrees to a requested restriction, it may not use or disclose the PHI in violation of such restriction, except in the emergency situations and other permitted or required situations described below.
  1. Use of Restricted Information in Emergency Situations.  Practice may use the restricted information in emergency circumstances, where the information is needed to provide treatment to the patient or for the purpose of providing such treatment.  In such emergency cases, the restricted information may also be disclosed to another health care provider to allow that provider to treat the patient.  When making the disclosure, the health care provider will be requested to not further use or disclose the restricted information.
  1. Other Permitted or Required Situations.  A restriction agreed to by Practice is not effective to prevent uses or disclosures by Practice which are permitted or required as follows:
  1. When required by the Washington State Department of Health to investigate or determine Practice’s compliance with Act;

2) When required by law; for public health activities; for disclosures about victims of abuse, neglect, or domestic violence; for health oversight activities; for judicial and administrative proceedings; for law enforcement purposes; about decedents requested by coroners, medical examiners, and funeral directors; for cadaveric organ, eye or tissue donation purposes; for research purposes, subject to the conditions set forth in Act; to avert a serious threat to health or safety; for specialized government functions, such as military activities and national security/intelligence activities; or for worker’s compensation.

  1. Termination of Restriction.  An agreement to a restriction can be terminated at any time by either the patient or Practice.  The patient’s request or agreement to termination of a restriction shall be in writing, or if submitted orally, shall be reduced to writing and filed in the patient’s medical record.  If Practice determines to terminate the restriction it shall so inform the patient and such termination shall be effective only with respect to PHI of the patient created or received after that notification.
  1. Documentation.  The Privacy Officer or his/her designee shall ensure that the restrictions, if any, are documented in the patient’s record.  Documentation of the restrictions shall be maintained for six (6) years from the date the notation was made or six (6) years from the date the restriction was last in effect, whichever is later.

Accounting of Disclosures 

General Policy:

Except for specific restrictions delineated in this Accounting of Disclosures Policy and Procedure, a patient shall, upon request, be given an accounting of all disclosures of PHI contained in his or her medical or billing record made during all or part of the six (6) years immediately preceding the patient’s request. This accounting shall include disclosures by Practice, or on behalf of Practice, by business associates.

Procedures:

  1. Recording of Disclosures:  With the exception of the disclosures listed in this Accounting of Disclosures Policy and Procedure, any employee or other agent who makes a disclosure of the PHI maintained about a patient in a medical or billing record shall record the following information regarding that disclosure:
    1. The date of the disclosure;
    2. The name of the entity or person who received the disclosure, and, if known, the address of that entity or person;
    3. A brief description of the information disclosed;
    4. A brief statement of the purpose of the disclosure that would reasonably inform a reader of the basis for the disclosure.

If multiple disclosures are made to the same person or entity over a period of time, a reference to the documentation of the first disclosure and the date of subsequent disclosures can be recorded in the accounting log. If disclosures will be periodic, that fact can be recorded along with the first disclosure, as well as the expected date of each periodic disclosure. 

  1. Requests for Accounting:  All persons who request an accounting of disclosures shall be directed to make such a request in writing and submit it to the Privacy Officer, which will be provided to the patient on request.  
  1. Action on Requests for Accounting:  Upon receiving a written request for an accounting, the Privacy Officer or his designee will: 
  1. Contact all qualified service organizations and business associates who have received the PHI of the patient in question and request a copy of the business associate’s or qualified service organization’s accounting log and research disclosures log regarding the patient;
  2. Within sixty (60) days of the patient’s request, review all relevant accounting logs including, but not limited to: the advanced directives section of the patient’s chart, the correspondence section, as well as other appropriate areas of the chart. Once completed, either provide the information requested or notify the patient that an extension of time is needed. The reason for the delay shall be explained and a date for availability of the desired information will be provided.  The extension may be no longer than thirty (30) days and can be utilized only once for any given request.
  1. Accounting Information to be Provided:  Each disclosure included in the accounting shall include:
    1. A description of the type of PHI that was disclosed;
    2. The date or period of time during which disclosures may have occurred, including the date of the last such disclosure during the accounting period;
    3. The name, address, and telephone number of the entity that requested the information;
    4. In the event that it appears that the patient’s health information was disclosed to a research protocol or activity, in addition to a, b, and c, a description of the protocol or activity, including the purpose of the research and the criteria for selecting certain records, will be provided. Practice will assist the patient in contacting the entity that sponsored the research, upon the patient’s request.
  1. Exceptions to the Right to an Accounting:  An accounting will not be provided to the patient for the following disclosures:
    1. Disclosures made for the purpose of carrying out treatment, payment, or health care operations;
    2. Disclosures made to the patient;
    3. Disclosures of information maintained in our patient directory, or disclosures made to persons involved in the patient’s care, or for the purpose of notifying the patient’s family or friends about the patient’s whereabouts;
    4. Disclosures for national security or intelligence purposes;
    5. Disclosures to correctional institutions or law enforcement officials who had the patient in custody at the time of the disclosures;
    6. Disclosures that occurred prior to April 14, 2003;
    7. Disclosures made pursuant to an authorization signed by the patient;
    8. Disclosures that are part of a limited data set;
    9. Incidental disclosures that comply with the Incidental Disclosures of PHI Policy and Procedure.
  1. Suspension of Accounting Rights:  A request by a health oversight agency or law enforcement official to suspend a patient’s ability to receive an accounting of the disclosures made to the agency and/or official shall be complied with if:
    1. The agency or official provides a written statement that an accounting of the disclosures that have been or are being made to the agency or official would be reasonably likely to impede the agency or official’s activities, and states a time period for which the suspension will be effective; or
    2. The agency or official provides an oral statement that an accounting of the disclosures that have been made or are being made to the agency or official would be reasonably likely to impede the agency or official’s activities, so long as the oral statement is documented by Practice employee or agent who takes the statement. Oral suspensions of accountings are effective only for 30 days and may not be renewed with another oral request. 
  1. Charges:  If the patient has not received an accounting in the twelve (12) month period preceding his or her request, the accounting will be provided at no cost to the patient. Otherwise, the patient will be charged for each additional accounting. Patients will be informed of this policy and billed for this charge prior to, or at the time of, the second request for an accounting. At that time the patient may withdraw or modify his or her request in order to avoid the charge. 
  1. Documentation:  All correspondence regarding requests for accountings, suspensions of accountings by health oversight agencies and law enforcement officials, as well as accountings themselves, shall be maintained in the patient’s record for a minimum of six (6) years
Requests to Correct or Amend Medical Records

General Policy:

Patients or their legally authorized representative have a right to request to amend or correct PHI maintained by Practice.  Requests must be in writing, shall be reviewed in a timely fashion, and the disposition documented in writing.  When applicable, the disposition of the request will be disclosed to others who need it. 

Procedures:

  1. Requests to correct or amend PHI, in order to be fully considered, must be in writing. 
  1. Timing for Response

Within ten (10) days of receipt of a request, Practice shall either:

  1. Make the requested correction or amendment and inform the patient of the action;
  2. Inform the patient if the record no longer exists or cannot be found;
  3. If Practice does not maintain the record, inform the patient and provide the patient with the name and address, if known, of the person who maintains the record; or
  4. Deny the request in writing as described below

If Practice is unable to act on the amendment within ten (10) days, Practice may extend the time for response by no more than twenty-one (21) days from the Practice’s receipt of the request, provided that the record is in use or unusual circumstances have delayed the handling of the correction or amendment request.

  1.      Approval of a Request: 
  1. The correction or amendment shall be made in the appropriate record.
  2. Mark the record affected by the change as corrected/amended at patient’s request.
  3. Draw a single line through any information to be modified, or create some other notation, and date and sign the entry. The original entry is to remain legible. 
  4. Indicate where in the record the corrected or amended information is located. 
  5. Enter the new information, indicate that it is a corrected or amended chart note, and date and sign the entry. 
  6. Send a copy of the correction or amendment to any third party that previously received the amended information.
  7. Obtain the individual’s identification of any persons the individual wants notified of the correction or amendment, and take reasonable steps to notify such persons of the change. 
  1. Denial of a Request:  An individual’s request to correct or amend a medical record may be denied if Practice determines that the PHI:
    1. Was not created by Practice, unless the individual provides a reasonable basis to believe that the originator of PHI is no longer available to act on the requested amendment;
      1. Is not part of the designated record set;
      2. Would not be available for inspection under the Patient Request to Access Medical Records Policy; or
      3. Is accurate and complete. 
  2. Disposition:
    1. Individuals must be informed of the disposition of the written request. 
    2. If the request is denied:
      1. Send the requestor a denial letter and include the reason the denial and information about the option to file a statement of disagreement.
      2. Document the reason for the denial. 
      3. Add any statement of disagreement with the suggested amendment. 
      4. Add a copy of the denial letter to the medical record. 
      5. Mark the challenged entry to indicate that the patient claims the entry is inaccurate or incomplete and indicate where the request for amendment and any statement of disagreement is located in the record. 
      6. Send any statement of disagreement to any third-party payor or insurer that previously received the disputed PHI.
      7. Document the disclosure.
    3. Future disclosures must include the written request, the denial and any statement of disagreement. However, if no statement of disagreement is filed, the written request and the denial may only be included in future disclosures upon the request by the patient or authorized individual. 
  1. Amendments Originating Elsewhere:  If notified by another health care entity that an amendment or correction has been made to a patient’s PHI then:
    1. The correction or amendment shall be filed in the appropriate record; 
    2. As necessary, mark the record affected by the change as corrected or amended, and 
    3. The affected record should be attached or linked or otherwise indicate where in the record the corrected or amended information is located. 
  1. Documentation:  The Privacy Officer is responsible for receiving and processing requests for amendments by individuals and retaining documentation of the requests and responses for 6 years.

Privacy Practices Training

General Policy:

Each member of Practice’s workforce shall be instructed regarding these Privacy Policies and Procedures and other privacy practices in a manner that is tailored to address the specific functions that the individual receiving that education performs.

Procedures:

  1. Training for existing workforce members shall be completed as soon as practicable after these Privacy Policies and Procedures are adopted by Practice.  Each individual who joins the workforce after this initial training shall be trained as soon as practicable after joining the workforce
  1. “Workforce” includes all employees, work-study students, volunteers, trainees, and other persons whose conduct is under the direct control of Practice, whether or not they are paid employees.
  1. Whenever a material change is made to privacy practices, each member of the workforce affected by the change shall be trained regarding the change within a reasonable period of time, as defined by the Privacy Officer.
  1. The completion of training required by this Privacy Practices Training Policy shall be documented by the individual who offered the training.  This documentation shall be retained for at least six (6) years from the date of its creation.
  1. The Privacy Officer shall implement and oversee all training required by this Privacy Practices Training Policy.  To accomplish this task, the Privacy Officer shall have the authority to consult with and delegate authority, as well as appoint committees to develop and perform training activities.
  1. If the Privacy Officer believes that a workforce member’s failure to attend or participate in the designated training required by this Privacy Practices Training Policy is purposeful and not reasonably justified, he or she shall report the information supporting that belief, in writing, and further action shall be taken as may be warranted.
  1. Workforce members may be subject to disciplinary procedures for failure to attend and participate in the training required by this Privacy Practices Training Policy.

Transmission of PHI via Telephone

General Policy:

Practice personnel may release PHI over the telephone in the same manner that such information may be released in person, in accordance with these Privacy Policies and Procedures.  

Procedures:

  1. Voicemail Services.  The voicemail system will be password protected to prevent unauthorized access to voicemail messages containing PHI.  
  1. Telephone Directories. 
  1. a) Patient-contact telephone numbers shall not be programmed into phones.  
  2. b) Written and computerized directories of patient-contact information will be restricted to authorized individuals only.  Employees or any other individual authorized to access patient-contact directories shall not share the information in the directory, in whole or part, with any unauthorized individual.  
  3. c) Computerized directories of patient information shall not remain displayed on a computer screen while not in use.  
  1. Conducting Calls.  Calls shall be conducted in a manner that preserves patient privacy to the greatest extent possible.  Doors, windows, and other partitions should be shut when possible.  Care should be taken to limit the volume of one’s voice when transmitting PHI, especially if unauthorized individuals are nearby or the information is of a sensitive nature.
  1. Transmitting Information via Telephone.  Whenever practical, the individual handling a call that concern PHI shall make efforts to ensure the identity of the caller prior to transmitting PHI.  To help ensure the confidentiality of PHI, each incoming caller purporting to be the patient or the patient’s representative, when there is doubt as to the identity of the caller, may be asked to state the patient’s birth date or address, prior to releasing PHI to the caller.
  1. Calls to Patients.  When asking for a patient, information about the clinical condition of the patient shall not be disclosed.  This includes not identifying who is calling, if doing so would reveal the patient’s condition.  If a person at the dialed number states that he or she is the patient, that representation shall be considered confirmation that the patient is the person speaking.  PHI may then be discussed with that person.
  1. Messages for Patients.  Messages for patients shall be limited to the following:
  1. a) The name of the person for whom the message is being left;
  2. b) A request that the patient return the call;
  3. c) Adequate identification of the person placing the call, but only if doing so will not reveal the clinical condition of the patient;
  4. d) The name of the individual for whom the patient may ask for when returning the call, if applicable;
  5. e) The telephone number where the call may be returned; and
  6. e) Whether or not the appointment requires special instructions, but only if doing so will not reveal the clinical condition of the patient.

Transmission of PHI via E-mail

General Policy:  Unencrypted e-mail messages may be read by someone other than the intended recipient(s) of the e-mail.  As such, Practice’s workforce must take the appropriate steps to communicate the risks associated with sending unencrypted e-mails with PHI to patients, and to confirm the patient’s desire to have their PHI sent via e-mail notwithstanding the risks involved with doing so.  At a minimum, workforce of Practice must comply with the following procedures set forth in this policy when sending PHI to patients via e-mail.

Procedures:

  1. Workforce may only e-mail a patient’s PHI to the patient, or to a person designated by the patient, if the patient has: (1) requested his or her PHI to be e-mailed, and (2) completed the E-mail Consent Form attached to this policy.  A copy of the signed E-mail Consent Form shall be maintained in the patient’s medical records.
  1. Workforce must exercise a greater degree of caution in transmitting PHI electronically than they take with other means of communicating PHI (e.g., written memos, letters, pictures, or phone calls) because of the reduced human effort required to redistribute information electronically.
  1. PHI should never be transmitted or forwarded to outside individuals or companies not authorized to receive such information and should not be sent or forwarded to other employees inside the organization who do not have a need to know such information.  
  1. Workforce must use care in addressing e-mail messages to patients to ensure that messages are not inadvertently sent to unintended recipients.  
  1. All e-mails containing PHI sent from Practice must include the following standard disclaimer: 

This e-mail and its attachments may contain protected health information intended solely for the use of Odyssey Travel Health, PLLC (the “Practice”) and the recipient(s) named above. Due to the unsecured nature of unencrypted e-mail, the recipient(s) named above understand and agree that there may be some level of risk that the information in this e-mail could be read by a third party.  If you are not the intended recipient, you are hereby notified that any review, dissemination, distribution, printing or copying of this email message and/or any attachments is strictly prohibited.  If you have received this transmission in error, please notify the Practice at odysseytravelhealth@outlook.com and permanently delete this e-mail and any attachments.

PATIENT CONSENT FOR E-MAIL COMMUNICATIONS

It is the understanding of Odyssey Travel Health, PLLC (“Practice”) that you would like us to communicate with you via e-mail.  Prior to using e-mail communications that may contain your protected health information (“PHI”), Practice needs to advise you that there may be some level of risk that information in an unencrypted e-mail could be read by a third party.  Practice will not be responsible for any unauthorized access of your PHI in e-mails that we send to you.

If you have any questions about this form or about our communications with you about your PHI, you may contact our Practice’s Privacy Officer, Lisa Garza at odysseytravelhealth@outlook.com

I, the undersigned, consent to e-mail communications with Practice and its providers about my PHI and I understand the risks associated with using e-mail communications.  I will inform Practice in writing if I no longer wish to communicate with Practice via e-mail.  

___________________________________

Patient Name/Patient Guardian (Print)

___________________________________

Signature

___________________________________

Date

Transmission of PHI via Facsimile

General Policy:

Practice has adopted this policy to comply with the Act, as well as our duty to protect the confidentiality and integrity of confidential medical information as required by law, professional ethics, and accreditation requirements.  PHI shall be transmitted by facsimile only when other means of transmission are not feasible.  Minor inconvenience shall not constitute infeasibility.  All personnel must strictly observe the standards and procedures set forth in this Transmission of PHI via Facsimile Policy and Procedure relating to facsimile communications of patient medical records.

Assumptions:

  • Practice and the personnel or organizations with which Practice does business often will have a need to transmit or receive confidential medical information by facsimile rather than by a slower method, such as mail.
  • Personnel may send faxes to unauthorized recipients, faxes may be intercepted or lost in transmission, or Practice may not receive a fax intended for it because of one of these or other reasons.
  • Thus, the potential for breach of patient confidentiality exists every time someone uses such information.

Procedures:

  1. Practice, its contracted officers, agents, and employees will send health information by facsimile only when the original record or mail-delivered copies will not meet the needs of immediate patient care.
  1. Personnel may transmit health records by facsimile only when urgently needed for patient care or required by a third-party payer for ongoing certification of payment for a patient.
  1. Personnel must limit information transmitted to that necessary to meet the requester’s needs.
  1. Except as authorized by law, a properly completed and signed authorization must be obtained before releasing patient information.  Note, that such authorization is not required if disclosing patient information for treatment, payment or healthcare operations as described in the Permitted Uses and Disclosures Policies and Procedures.
  1. Personnel may not send by fax especially sensitive medical information, including, but not limited to, AIDS/HIV information, mental health and developmental disability information, alcohol and drug abuse information, and other sexually transmissible disease information without the express authorization of the Privacy Officer.
  1. The cover page accompanying the facsimile transmission must include the following confidentiality notice:

This facsimile and its enclosures may contain protected health information intended solely for the use of Odyssey Travel Health, PLLC (the “Practice) and the recipient(s) named above. Due to the unsecured nature of facsimiles, the recipient(s) named above understand and agree that there may be some level of risk that the information in this facsimile could be read by a third party.  If you are not the intended recipient, you are hereby notified that any review, dissemination, distribution, printing or copying of this facsimile and/or any enclosures is strictly prohibited.  If you have received this transmission in error, please notify Practice at  odysseytravelhealth@outlook.com and shred the facsimile and its enclosures.

  1. Personnel must make reasonable efforts to ensure that they send the facsimile transmission to the correct destination.  Personnel must preprogram frequently used numbers into the machine to prevent misdialing errors.  For a new recipient, the sender must verify the fax number before sending the facsimile and verify the recipient’s authority to receive confidential information.
  1. Fax machines must be in secure areas, where visitors and patients cannot easily access them.
  1. Office personnel are responsible for ensuring that incoming faxes are properly handled, not left sitting on or near the machine, but rather are distributed to the proper recipient expeditiously while protecting confidentiality during distribution.
  1. Personnel must report any misdirected faxes to the Privacy Officer.
  1. Users must immediately report violations of this policy to their department manager and to the Privacy Officer.

Complaint and Grievance

General Policy:

Practice will continually strive to improve the quality of the services it provides and will provide a process for handling complaints and grievances related to the use or disclosure of PHI.

Definitions:

  1. Complaint: an oral concern about compliance with health-information privacy laws.
  1. Grievance: a written concern about compliance with health-information privacy laws and regulations.
  1. Responsible Party: all physicians, employees, and personnel of Practice.

Procedures:

  1. All grievances regarding privacy policies and practices, and compliance with those policies and practices, will be accepted and considered.  Complaints should be made in writing using the Compliant and Grievance form attached at the end of this Compliant and Grievance Policy and Procedure and directed to the Privacy Officer.
  1. All grievances will be responded to in writing if the complaint seeks a response.
  1. Individuals who file a grievance will not be retaliated against in any way, including through coercion, harassment or refusal of treatment.  Violations of this anti-retaliation policy will be handled in accordance with the Policy Regarding Sanctions for Privacy Violations.
  1. Procedure for Responding to a Complaint:
  1. The Privacy Officer, or his designee, shall review all complaints within a reasonable period but in no event not later than thirty (30) days. 
  2. If the complaint seeks a response, and provides contact information, the Privacy Officer (or his or her designee) shall prepare and deliver a written response to the individual who lodged the complaint.  
  3. If the complaint does not seek a response, or does not provide contact information, the Privacy Officer (or his designee) shall prepare a written statement of any action taken with regard to the complaint. That statement shall be attached to, and filed with, the complaint.

COMPLIANT AND GRIEVANCE FORM

PERSON WITH COMPLAINT

Date of Report: Date of Occurrence:

Person Reporting: Name & Account # of Patient:

Home Address: Do you feel the problem involves:

      Accidental disclosure     ◻

      Deliberate disclosure     ◻

Telephone #:       Other security incident     ◻ 

When did you first become concerned with this issue?

Have you discussed this problem with anyone?   Yes       No     Who?                                 When?

Please state the problem in your own words, giving as much specific information as possible (use back of sheet if you need more space)

Signature:                                                                               Date:

PERSON TAKING REPORT

Name of person taking report: Position/Title:

Date:

Have you personally interviewed the complainant? Action Taken & Date:

Additional Comments: Follow-up Information & Date:

Business Associate Agreements 

General Policy:

Practice, in accordance with the Act, may permit a business associate to create, receive, maintain, or transmit electronic PHI (ePHI) and to use or disclose PHI on Practice’s behalf only if Practice obtains satisfactory assurances, in accordance with this Business Associate Agreements Policy and Procedure, that the business associate will appropriately safeguard the information.  This Business Associate Agreements Policy and Procedure does not apply with respect to the transmission by Practice of ePHI or PHI to a health care provider concerning the treatment of an individual or an insurance company related to payment for the treatment of an individual.

Procedures:

  1. Practice will document the satisfactory assurances required by this Business Associates Agreements Policy and Procedure through a written contract with a business associate (i.e., a Business Associate Agreement).  
  1. If Practice knows of a pattern of an activity of the business associate that constitutes a material breach or violation of the business associate’s obligation under the Business Associate Agreement, Practice will take reasonable steps to cure the breach or end the violation, as applicable. If such steps are not successful, Practice shall terminate the contract or arrangement, if feasible.

 

General

 

Introduction:

It is the policy of Odyssey Travel Health, PLLC (“Practice”) that all personnel must preserve the integrity and confidentiality of protected health information (“PHI”) and other sensitive information pertaining to its patients.  The purpose of these Privacy Policies and Procedures is to ensure Practice’s compliance with applicable standards, implementation specifications, and requirements of the Washington State Uniform Health Care Information Act (the “Act”). Furthermore, the purpose of these Privacy Policies and Procedures is to ensure that Practice and its workforce have the necessary medical and other information to provide the highest quality medical care possible while protecting the confidentiality of that information in accordance with applicable law. 

General Policy:

Practice and its personnel shall not use or disclose PHI, except as permitted or required by the Act. All Practice workforce members are required to comply with all Privacy Policies and Procedures. In addition, workforce members are expected to report known or suspected violations of the Privacy Policies and Procedures by others. Reports of violations should be in writing and directed to Practice’s Privacy Officer, Lisa Garza.

Procedures:

  1. Practice and its personnel are permitted to use or disclose PHI as follows:
  • to the individual patient;
  • for treatment, payment, or health care operations as permitted under the Act;
  • incident to a use or disclosure otherwise permitted or required by the Act, provided that such use or disclosure is limited to the minimum necessary to accomplish the intended purpose of the use, disclosure or request;
  • pursuant to and in compliance with a valid authorization for use and disclosure of PHI from the individual pursuant to the Authorizations for the Use or Disclosure of PHI Policies and Procedures; and
  • as otherwise permitted or required under the Act.

2) Practice and its personnel are required to disclose PHI as follows:

  • to an individual, when requested in accordance with these the Act Privacy Policies, and 
  • when required by the Washington State Department of Health to determine Practice’s compliance with the Act.

3) The Privacy Officer shall investigate whenever there is a credible allegation that a

violation of these the Act Privacy Policies and Procedures has occurred and shall

recommend appropriate sanctions for such violations, if any.

4) When using or disclosing PHI or when requesting PHI from another health care

provider, Practice will make reasonable efforts to limit PHI to the minimum necessary to

accomplish the intended purpose of the use, disclosure, or request. The foregoing minimum necessary requirement does not apply to the following:

  • disclosures to or requests by a health care provider for treatment;
  • uses or disclosures made to the individual, as permitted or required under the Act;
  • uses or disclosures made pursuant to an authorization by an individual where authorization is required under the Act;
  • disclosures made to the Washington State Department of Health as required to investigate or determine Practice’s compliance with the Act;
  • uses or disclosures that are required by law under the Act; and 
  • uses or disclosures that are required for compliance with the applicable requirements of the Act.

Permitted Uses and Disclosures

General Policy:  

Practice is permitted to use and disclose PHI in specific instances as permitted by the Act without a patient authorization.

Procedures:

  1. Treatment, Payment and Health Care Operations. Practice personnel are permitted to use (in some instances) or disclose PHI for treatment, payment and healthcare operations purposes as follows:
    1. Practice may use or disclose PHI for its own treatment, payment, or health care operations.
    2. Practice may disclose PHI for treatment activities of a health care provider.
    3. Practice may disclose PHI to another health care provider for the payment activities of the entity that receives the information.
    4. Practice may disclose PHI to another health care entity for health care operations activities of the entity that receives the information, if each entity either has or had a relationship with the individual who is the subject of the PHI being requested, the PHI pertains to such relationship, and the disclosure is:
      1. Conducting quality assessment and improvement activities, including outcomes evaluation and development of clinical guidelines, provided that the obtaining of generalizable knowledge is not the primary purpose of any studies resulting from such activities; patient safety activities (as defined in 42 CFR 3.20); population-based activities relating to improving health or reducing health care costs, protocol development, case management and care coordination, contacting of health care providers and patients with information about treatment alternatives; and related functions that do not include treatment; 
      2. Reviewing the competence or qualifications of health care professionals, evaluating practitioner and provider performance, health plan performance, conducting training programs in which students, trainees, or practitioners in areas of health care learn under supervision to practice or improve their skills as health care providers, training of non-health care professionals, accreditation, certification, licensing, or credentialing activities.
      3. For the purpose of health care fraud and abuse detection or compliance.
  1. Permissible Disclosures.  Practice personnel are permitted to use or disclose PHI without a patient authorization as follows: 
    1. As required by law.
    2. To the appropriate state or federal health authority conducting public health surveillance, public health investigations, public health interventions and the Food and Drug Administration regulatory oversight.
    3. Limited fundraising – as long as the client is able to opt out.
    4. For health oversight activities.
    5. Reporting the suspected abuse or neglect of a child or vulnerable adult as required by federal and state law.
    6. Cooperating with ongoing investigations related to the suspected abuse of a child or vulnerable adult.
    7. Responding to a subpoena or court order from a federal, state or county court, in which case attempts must be made to notify the individual of the disclosure.
    8. Responding to legal action initiated by a client against the agency regarding services provided.
    9. Limited law enforcement purposes when the disclosure of PHI is reasonably believed to be evidence of criminal conduct on the premises of the Practice.
    10. To a law enforcement official who requests such information to identify or locate a suspect, fugitive, material witness, or missing person. In this case only very limited PHI would be disclosed.
    11. About decedents to coroner, medical examiner or funeral director.
    12. For research purposes, if approved by an Institutional Review Board.
    13. In order to avert a serious threat to health or safety including reporting the imminent danger of a client to self or others as required by state law.
    14. For some specialized government functions related to military, veterans, armed forces, national security or intelligence activity, and correctional institutions and custodial situations.
    15. For some government programs providing public benefits.
    16. To assist with workers compensation claims.
    17. To business associates as outlined in the Business Associate Agreements Policy and Procedure.
    18. As otherwise permitted by the Act.

Sanctions Policy

General Policy

Whenever there is a credible allegation that a violation of a patient’s privacy rights has occurred, Practice shall investigate the allegation and shall recommend appropriate sanctions for such violations, if any.

Procedures

Sanctions for workforce members may include, but are not limited to verbal warnings, written warnings, paid and unpaid suspensions, and termination, in accordance with applicable personnel policies.

    1. Definition of a Violation: The level of breach in patient confidentiality or privacy violation is determined according to the severity of the breach or violation, whether the breach or violation was intentional or unintentional, and whether the breach or violation indicates a pattern or practice of improper use or release of confidential patient information or violation of patient privacy. The degree of discipline may range from a verbal warning to immediate termination. 
      Class I Violation(s): Carelessness or Inadvertent action. This level of breach or violation occurs when a Practice workforce member unintentionally or carelessly accesses, reviews, or releases confidential patient information without a legitimate business reason. Examples include, but are not limited to: 
        1. Leaving PHI in an unsecured area where it might be viewed by others;
          Leaving a computer unattended while the workforce member is logged on to a system containing PHI;
          Sharing PHI with another workforce member without authorization or unrelated to the performance of the workforce member’s duties;
        2. Discussing PHI in public areas where you can be overheard (i.e. patient waiting room, restroom, etc.); or
          Faxing documents to the wrong location or mailing/giving documents to the wrong person/patient.
      1. Class II Violation(s): No Personal Gain.  This level of breach or violation occurs when a workforce member intentionally accesses or releases confidential patient information for purposes other than the care of the patient or other authorized purposes but for reasons unrelated to personal gain. Examples include but are not limited to: 
        The sharing of computer access codes (username & password); or
        1. The use of another person’s computer access codes (username & password).
          Class III Violation(s): Personal Gain or Malice. This level of breach or violation occurs when a workforce member accesses, reviews, or releases confidential patient information for personal gain or with malicious intent. Examples include, but are not limited to: 
        1. Accessing or reviewing a health record of a patient, such as reviewing the record of a patient in the news, another workforce member’s information or a public personality.
          Using and/or disclosing PHI for commercial advantage, personal gain or malicious harm; or
          Obtaining PHI under false pretenses.
  • Sanctions: Violation of this policy will result in action appropriate to the circumstances, the class of offense, and whether there is a pattern of repeated violations.  The following steps are guidelines for disciplinary action for privacy breaches and violations. Risk to patients or staff and other serious offenses may warrant deviation from these guidelines. Such disciplinary actions may include, but are not limited to, any one or more of the following:
    Class I Violation(s):
    First Offense: A documented warning.
    Multiple Offenses: Each subsequent Class I Violation constitutes a Class II Violation.
  • Class II Violation(s):
  • First Offense: Depending on the facts, (1) documented warning, and/or (2) final written warning/last chance agreement.
    Multiple Offenses: Depending on the facts, (1) final written warning/last change agreement, (2) suspension up to five days without pay, documented and maintained in the workforce member’s file, and/or (3) immediate termination with reports to appropriate agencies if applicable.
  • Class III Violation(s):
    First or Subsequent Offense: Depending on the facts, (1) suspension up to five days without pay, documented and maintained in the workforce member’s file, and/or (2) immediate termination with reports to appropriate agencies if applicable. 
    Civil and criminal penalties as provided under the Act and other applicable Federal/State/Local laws. 

  • Exceptions: No sanctions or retaliatory actions shall apply to:
    1. Whistleblowers.  Workforce members who believe in good faith that Practice has engaged in conduct that is unlawful or otherwise violates professional or clinical standards, or that the care, services, or conditions provided by Practice potentially endanger patients, workers, or the public shall not be sanctioned for disclosing PHI to the following individuals or entities:
      1. A health oversight agency or public health authority authorized by law to investigate or oversee the conduct or conditions of Practice so long as the purpose of the disclosure was to report the allegation regarding Practice’s failure to meet the relevant legal or professional standards;
      2. A health care accreditation organization, so long as the purpose of the disclosure was to report the allegation regarding Practice’s failure to meet the relevant legal or professional standards; or
      3. An attorney retained by or on behalf of the workforce member for the purpose of determining the legal options that the member has with regard to Practice’s alleged illegal or unprofessional conduct under Section 3.a.
    2. Individuals who oppose actions that violate the Act.  Sanctions will not be applied to any individual for the following:
      Filing a truthful complaint with the Washington State Department of Health, or other governmental agency, regarding a privacy violation;
      1. Testifying, assisting, or participating in any official investigation, compliance review, proceeding, or hearing under the Act; or
        Opposing any act of Practice that violates the Act, as long as the individual doing so believes in good faith that the act of Practice is unlawful, and the manner of the opposition is reasonable and does not involve making a disclosure of PHI that violates the Act.
Authorizations for the Use or Disclosure of PHI

General Policy:

Except in the circumstances permitted by the Act and/or described in Practice’s Privacy Policies and Procedures, Practice will not use or disclose a patient’s PHI without first obtaining the patient’s written authorization.

Procedures:

  1. Authorization Forms.  Workforce members shall use the authorization forms that have been developed by Practice to comply with all of the requirements for such forms outlined in the Act and shall not alter those forms in any way.  The authorization forms should be in the same or similar format as the form located at Appendix A of this Policy. 
  1. Incomplete Authorizations.  Authorization forms that are not filled in completely, or that are not signed and/or dated will not be accepted.  Incomplete authorizations are not valid, and disclosures made pursuant to them are not “authorized” under our privacy policies.
  1. Treatment Conditioned on Authorization.  Practice will not condition the provision of treatment on a patient’s provision of an authorization, except:
  1. a) The provision of research-related treatment may be conditioned on a patient’s authorization to have the information generated from that treatment released as part of the research.  
  2. b) The provision of treatment, the sole purpose of which is to create information for release to third parties, may be conditioned on a patient’s authorization to have the information released to the relevant third parties.  For instance, if a patient has requested a physical examination for the sole purpose of having the results of that examination released to his or her employer, Practice may refuse to perform the examination if the patient refuses to authorize the release of PHI regarding that exam to the employer.
  1. Revocation of Authorization.  As a general rule, patients may revoke their authorizations, in writing, at any time.  Revocations become effective when the patient has revoked such authorization in writing and submitted it to Practice.  Exceptions to this general rule are:
  1. a) If Practice has already taken action in reliance on an authorization, the revocation is not effective with respect to those actions.  
  2. b) If the patient signed an authorization as a condition of receiving insurance coverage, a revocation of that authorization will not be effective to impede an insurer’s contest of a claim under the policy.
  1. Authorization Required When Patient Seeks Disclosure. If a patient seeks disclosure of his or her PHI for any purpose for which an authorization is required, the patient shall complete an authorization form.  A copy of the completed form shall be given to the patient and the original shall be sent to the Privacy Officer.  The Privacy Officer shall review the form and make the disclosure, if appropriate.  If the form is not complete, the Privacy Officer shall contact the patient to notify him or her that additional information is needed.  The Privacy Officer shall file the authorization form in the patient’s medical record.
  1. Authorization for Disclosure for Marketing Purposes. Practice shall follow the Disclosure of PHI for Marketing Policy prior to disclosing any PHI for marketing purposes.

Appendix A

Odyssey Travel Health, PLLC

Authorization to Disclose or Release Protected Health Information

Patient name: ____________________________________________ Date of birth: _______________

I hereby give my permission to Odyssey Travel Health, PLLC (the “Practice”) to disclose my health care information consistent with this authorization.

Please disclose the following health care information about me (check all that apply):

  • All health care information in my medical record.
  • Health care information in my medical record relating to the following treatment or condition: ____________________________________________________________________________________________
  • Health care information in my medical record for the date(s): _______________________________
  • Other (e.g. bills), specify date(s):_____________________________________________________

Please disclose health care information about me regarding testing, diagnosis, and treatment for the sensitive health information below (check all that apply).  If none of the below boxes are checked, no information related to the testing, diagnosis or treatment of the categories below will be disclosed pursuant to this authorization.  I understand that if I want to authorize Practice’s disclosure of this information later, I will be asked to sign another authorization.  

 

  • HIV (AIDS virus)
  • Sexually transmitted diseases
  • Psychiatric disorders/mental health 
  • Drug and/or alcohol use

Please disclose this health care information to:

Name (or title) and organization: _______________________________________________________________

Address: ____________________________________________City: _______________ State: _____   Zip:__________ 

Phone:                     Fax: _______________________________  

Reason(s) for this authorization (check all that apply):

  • At my request 
  • Care coordination with other provider(s)
  • To my attorney
  • Insurance
  • Marketing
  • Medical Leave
  • Other (specify)________________________________________________________________________

This authorization ends: 

  • on (date): _______________________
  • when the following event occurs: _____________________________________________________________

I understand that I may change my mind and decide to cancel my authorization to use and disclose my health care information at any time.  I understand that if I choose to revoke my authorization, I need to do it in writing by sending a letter to the person or organization listed above.  I also understand that if I cancel this authorization, the information may have already been used or disclosed before I changed my mind.

I understand that I may refuse to sign this form, and that I do not need to sign it to receive treatment, for payment for health care services to be made, or to enroll or be eligible for benefits.  However, if research-related treatment is going to be provided, or if health care services are going to be provided solely for the purpose of providing health information to someone else and my signature on this authorization is necessary to make such disclosures, I will not receive those health care services if I refuse to sign this authorization. 

I understand that once the health information I have authorized to be disclosed reaches the noted recipient, that person or organization may re-disclose it, at which time it may no longer be protected under privacy laws.

I understand that I have the right to inspect or receive a copy of my protected health information and to receive a copy of this signed form.

________________________________________________________ ________________________________________

Patient or legally authorized individual signature Date Time

____________________________________________       _______________________________

Printed name if signed on behalf of the patient Relationship/ Description of Authority

*** Note: there may be a charge for copying medical records.

Incidental Disclosures of PHI

General Policy:

Incidental disclosures are disclosures of PHI that occur as a by-product of a permissible use or disclosure, are limited in nature, and cannot be prevented through the use of reasonable measures.  Incidental disclosures do not violate Practice’s Privacy Policies and Procedures as long as: (1) reasonable measures were taken to prevent the incidental disclosure; and (2) the disclosure resulted from a use or disclosure that is otherwise permissible under Practice’s Privacy Policies and Procedures, including policies regarding using or disclosing the minimum necessary information.  

Procedures:

  1. The following measures are considered reasonable with respect to the prevention of incidental disclosures and shall be followed when applicable:
  1. a) Compliance with the Policy Regarding Transmission of PHI via Facsimile, Policy Regarding Transmission of PHI via E-mail, and the Policy Regarding Transmission of PHI via Telephone shall constitute reasonable measures for the prevention of incidental disclosures when receiving or disclosing PHI via telephone, e-mail or fax.
  2. c) When discussing PHI in any non-private area (e.g., a waiting room, reception area, or hall), all conversations should be kept as low as reasonably possible.  Private areas should be used for such discussions whenever reasonably possible.  If PHI is communicated via sign language, reasonable efforts should be made to move the discussion out of plain view of passersby.  
  3. d) Computer screens should be set-up out of view of patients.

 
Notice of Privacy Practices

General Policy:  Practice will make a good faith effort to obtain written acknowledgement of receipt of Practice’s Notice of Privacy Practices from every patient before the date of the first service delivery to the extent practicable. In an emergency treatment situation, Practice will provide the Notice as soon as reasonably practicable after the emergency treatment.

If a written acknowledgement cannot be obtained from the individual, reasons why and efforts to

obtain one will be documented.

Procedures:

  1. Distribution of Notice of Privacy Practices: The Practice maintains a Notice of Privacy Practices, which describes patient rights and Practice’s permitted uses and disclosure of PHI.
  1. Provide the Notice to every patient or patient’s personal representative before or at the first delivery of service. Provide a new copy of the Notice whenever the Notice is updated, even if the patient has previously received a Notice.
  2. Ask the patient to sign the Acknowledgement Form at Appendix A of this Policy when they receive the Notice. If the patient cannot or will not sign the acknowledgement, note the reason on the form and any effort made to obtain the signature. The patient may be treated even if he/she does not sign the Acknowledgement Form.
  3. Provide the patient with a copy of the Acknowledgement Form. Maintain the original Acknowledgement Form in the patient’s record.
  1. Records Retention
  1. The original paper Acknowledgement Form, or an electronic scanned version of this document must be stored in an easily retrievable location for at least six (6) years.
  1. Review and Changes to the Notice

The Notice will be reviewed periodically to ensure compliance with the Act requirements. 

Appendix A

ACKNOWLEDGEMENT OF RECEIPT OF

NOTICE OF PRIVACY PRACTICES

This form will be retained in your medical record.

By my signature below I, ___________________________________, acknowledge that I received a copy of the Notice of Privacy Practices for Odyssey Travel Health, PLLC

___________________________________________ _____________________

Signature of patient (or personal representative) Date

If this acknowledgment is signed by a personal representative on behalf of the patient, complete the following:

Personal Representative’s Name: ___________________________________________

Relationship to Patient: ___________________________________________

For Office Use Only

I attempted to obtain written acknowledgement of receipt of our Notice of Privacy Practices, but acknowledgement could not be obtained because:

Individual refused to sign

Communications barriers prohibited obtaining the acknowledgement

An emergency situation prevented us from obtaining acknowledgement

Other (Please Specify)

______________________________________________________________________

______________________________________________________________________

_________________________________________ _____________________

Employee Name Date

Patient Request to Access Medical Records

General Policy:  Except as specifically limited by this Policy, Practice shall allow patients to inspect and obtain a copy of PHI about the patient that is maintained in a designated record set.  Requests for access must be made in writing and should be directed to Practice’s Privacy Officer. 

Procedures:

  1. Inquiries. All patients who inquire about accessing their medical records shall be notified that requests for access must be made in writing.
  1. Non-Reviewable Grounds for Denial of Access.  Access may be denied under the following circumstances.  Denials for these reasons are final and non-reviewable:
  1. Knowledge of the health care information could reasonably be expected to lead to the patient’s identification of an individual who provided the information in confidence and under circumstances in which confidentiality was appropriate;
  1. The health care information was compiled and is used solely for litigation, quality assurance, peer review, or administrative purposes; or
  1. An individual’s access to the health care information that is contained in records that are subject to the Privacy Act, 5 U.S.C. 552a, may be denied, if the denial of access under the Privacy Act would meet the requirements of that law. 
  1. Reviewable Grounds for Denial of Access.  Access may be denied under the following circumstances.  Patients may request to have these denials reviewed by a licensed health care professional who was not involved in the original denial determination:  
  1. Knowledge of the health care information would endanger the life or physical safety of the patient or another person.
  1. Action on Requests.  Upon receiving a written request for access, the Privacy Officer or his or her designee shall review the request in accordance with the policies set forth in Paragraphs 1 through 3 of this policy.  
  1. General Rule.  Within fifteen (15) days, the Privacy Officer shall determine whether access will be granted in full, granted in part, or denied; shall inform the patient of the decision; and shall provide the access that is granted, if any. 
  1. Extensions of Time.  If the subject record is in use, or unusual circumstances have delayed the handling of the access request, the Privacy Officer may inform the patient and specify in writing, the earliest date, not later than twenty-one (21) days after receiving the request, when Practice will respond to the patient’s request.
  1. Providing Access.  Practice will provide access to the records in accordance with this Section 5.
  1. Form or Format.  If access is granted, the patient will be provided the information in the form or format requested if the information is readily available in that format.  If records are not readily available in the format requested, the patient shall be provided a readable hard copy of the information.
  1. Electronic Format.  If a patient requests an electronic copy of his or her PHI, and if the requested PHI is maintained electronically by Practice, Practice must provide the patient with access to the PHI in the electronic form and format requested by the patient (e.g. Adobe PDF), if it is readily producible in such form and format; or, if not, in a readable electronic form and format as agreed to by Practice and the patient.
  1. Summary Alternative.  Practice may provide the patient with a summary of the requested PHI, in lieu of providing access to the PHI or may provide an explanation of the PHI to which access has been provided, if the patient agrees in advance to such a summary or explanation, and the patient agrees in advance to the fees imposed (if any) by Practice for such summary or explanation.
  1. In-Person Access.  If the patient requests in-person access to his or her medical records, the Privacy Officer shall provide the phone number of the appropriate records staff person so that the patient may contact this person to arrange for in-person inspection.  The patient will be informed that Practice personnel must be present at all times during inspection of the medical record.  
  1. Third Party Access.  If a patient’s request for access directs Practice to transmit the copy of PHI directly to another person designated by the patient, Practice must provide the copy to the person designated by the patient. The patient’s request must be in writing, signed by the patient, and clearly identify the designated person and where to send the copy of PHI.
  1. Denying Access.  All patients who have had their request denied will be sent a written denial within the timeframes set forth in Paragraph 3 above.
  1. Access Upon Denial.  If Practice denies access to a patient’s requested PHI, Practice will, to the extent possible, give the patient access to any other PHI requested after excluding the PHI to which Practice has a ground to deny access.
  1. Information Not Maintained.  If Practice does not maintain the requested information, Practice shall provide the patient with the name of the person or entity who maintains the information, if known
  1. Review.  If a patient’s request for access is denied under this policy, Practice shall permit examination and copying of the record by another health care provider, selected by the patient, who is licensed, certified, registered, or otherwise authorized under the laws of Washington State to treat the patient for the same condition as Practice. Practice shall inform the patient of the patient’s right to select another health care provider under this subsection. The patient shall be responsible for arranging for compensation of the other health care provider so selected.
  1. Fees.  If a patient requests a copy of the PHI or agrees to a summary or explanation of such information, Practice may charge a reasonable cost-based fee in accordance with the Act and applicable state laws pertaining to patient access to medical records.
  1. Requests and Responses.  All correspondence regarding requests for access shall be maintained in the patient’s record for a minimum of six (6) years.

Patient Request for Restrictions
on the Use and Disclosure of PHI

General Policy:  Practice’s Privacy Officer or his or her designee may grant a patient’s request to restrict the use or disclosure of the patient’s PHI, subject to the limitations set forth in this policy.  

Procedures:

  1. Requests for Restrictions.  If a patient asks to restrict the use or disclosure of PHI, the patient shall submit a written request to Practice’s Privacy Officer.  
  1. Practice is not required to agree to a requested restriction, except if a patient’s request is to restrict disclosure of PHI to a health plan for the purpose of carrying out payment or health care operations, the disclosure is not otherwise required by law, and the PHI pertains solely to a health care item or service which has been paid in full by the patient or another person or entity on the patient’s behalf.  
  1. If Practice agrees to a requested restriction, it may not use or disclose the PHI in violation of such restriction, except in the emergency situations and other permitted or required situations described below.
  1. Use of Restricted Information in Emergency Situations.  Practice may use the restricted information in emergency circumstances, where the information is needed to provide treatment to the patient or for the purpose of providing such treatment.  In such emergency cases, the restricted information may also be disclosed to another health care provider to allow that provider to treat the patient.  When making the disclosure, the health care provider will be requested to not further use or disclose the restricted information.
  1. Other Permitted or Required Situations.  A restriction agreed to by Practice is not effective to prevent uses or disclosures by Practice which are permitted or required as follows:
  1. When required by the Washington State Department of Health to investigate or determine Practice’s compliance with Act;

2) When required by law; for public health activities; for disclosures about victims of abuse, neglect, or domestic violence; for health oversight activities; for judicial and administrative proceedings; for law enforcement purposes; about decedents requested by coroners, medical examiners, and funeral directors; for cadaveric organ, eye or tissue donation purposes; for research purposes, subject to the conditions set forth in Act; to avert a serious threat to health or safety; for specialized government functions, such as military activities and national security/intelligence activities; or for worker’s compensation.

  1. Termination of Restriction.  An agreement to a restriction can be terminated at any time by either the patient or Practice.  The patient’s request or agreement to termination of a restriction shall be in writing, or if submitted orally, shall be reduced to writing and filed in the patient’s medical record.  If Practice determines to terminate the restriction it shall so inform the patient and such termination shall be effective only with respect to PHI of the patient created or received after that notification.
  1. Documentation.  The Privacy Officer or his/her designee shall ensure that the restrictions, if any, are documented in the patient’s record.  Documentation of the restrictions shall be maintained for six (6) years from the date the notation was made or six (6) years from the date the restriction was last in effect, whichever is later.

Accounting of Disclosures 

General Policy:

Except for specific restrictions delineated in this Accounting of Disclosures Policy and Procedure, a patient shall, upon request, be given an accounting of all disclosures of PHI contained in his or her medical or billing record made during all or part of the six (6) years immediately preceding the patient’s request. This accounting shall include disclosures by Practice, or on behalf of Practice, by business associates.

Procedures:

  1. Recording of Disclosures:  With the exception of the disclosures listed in this Accounting of Disclosures Policy and Procedure, any employee or other agent who makes a disclosure of the PHI maintained about a patient in a medical or billing record shall record the following information regarding that disclosure:
    1. The date of the disclosure;
    2. The name of the entity or person who received the disclosure, and, if known, the address of that entity or person;
    3. A brief description of the information disclosed;
    4. A brief statement of the purpose of the disclosure that would reasonably inform a reader of the basis for the disclosure.

 

If multiple disclosures are made to the same person or entity over a period of time, a reference to the documentation of the first disclosure and the date of subsequent disclosures can be recorded in the accounting log. If disclosures will be periodic, that fact can be recorded along with the first disclosure, as well as the expected date of each periodic disclosure. 

  1. Requests for Accounting:  All persons who request an accounting of disclosures shall be directed to make such a request in writing and submit it to the Privacy Officer, which will be provided to the patient on request.  
  1. Action on Requests for Accounting:  Upon receiving a written request for an accounting, the Privacy Officer or his designee will: 
  1. Contact all qualified service organizations and business associates who have received the PHI of the patient in question and request a copy of the business associate’s or qualified service organization’s accounting log and research disclosures log regarding the patient;
  2. Within sixty (60) days of the patient’s request, review all relevant accounting logs including, but not limited to: the advanced directives section of the patient’s chart, the correspondence section, as well as other appropriate areas of the chart. Once completed, either provide the information requested or notify the patient that an extension of time is needed. The reason for the delay shall be explained and a date for availability of the desired information will be provided.  The extension may be no longer than thirty (30) days and can be utilized only once for any given request.
  1. Accounting Information to be Provided:  Each disclosure included in the accounting shall include: 
    1. A description of the type of PHI that was disclosed;
    2. The date or period of time during which disclosures may have occurred, including the date of the last such disclosure during the accounting period;
    3. The name, address, and telephone number of the entity that requested the information;
    4. In the event that it appears that the patient’s health information was disclosed to a research protocol or activity, in addition to a, b, and c, a description of the protocol or activity, including the purpose of the research and the criteria for selecting certain records, will be provided. Practice will assist the patient in contacting the entity that sponsored the research, upon the patient’s request.
  1. Exceptions to the Right to an Accounting:  An accounting will not be provided to the patient for the following disclosures:
    1. Disclosures made for the purpose of carrying out treatment, payment, or health care operations;
    2. Disclosures made to the patient;
    3. Disclosures of information maintained in our patient directory, or disclosures made to persons involved in the patient’s care, or for the purpose of notifying the patient’s family or friends about the patient’s whereabouts;
    4. Disclosures for national security or intelligence purposes;
    5. Disclosures to correctional institutions or law enforcement officials who had the patient in custody at the time of the disclosures;
    6. Disclosures that occurred prior to April 14, 2003;
    7. Disclosures made pursuant to an authorization signed by the patient;
    8. Disclosures that are part of a limited data set;
    9. Incidental disclosures that comply with the Incidental Disclosures of PHI Policy and Procedure.

  

  1. Suspension of Accounting Rights:  A request by a health oversight agency or law enforcement official to suspend a patient’s ability to receive an accounting of the disclosures made to the agency and/or official shall be complied with if: 
    1. The agency or official provides a written statement that an accounting of the disclosures that have been or are being made to the agency or official would be reasonably likely to impede the agency or official’s activities, and states a time period for which the suspension will be effective; or
    2. The agency or official provides an oral statement that an accounting of the disclosures that have been made or are being made to the agency or official would be reasonably likely to impede the agency or official’s activities, so long as the oral statement is documented by Practice employee or agent who takes the statement. Oral suspensions of accountings are effective only for 30 days and may not be renewed with another oral request. 
  1. Charges:  If the patient has not received an accounting in the twelve (12) month period preceding his or her request, the accounting will be provided at no cost to the patient. Otherwise, the patient will be charged for each additional accounting. Patients will be informed of this policy and billed for this charge prior to, or at the time of, the second request for an accounting. At that time the patient may withdraw or modify his or her request in order to avoid the charge. 
  1. Documentation:  All correspondence regarding requests for accountings, suspensions of accountings by health oversight agencies and law enforcement officials, as well as accountings themselves, shall be maintained in the patient’s record for a minimum of six (6) years
Requests to Correct or Amend Medical Records

General Policy:

Patients or their legally authorized representative have a right to request to amend or correct PHI maintained by Practice.  Requests must be in writing, shall be reviewed in a timely fashion, and the disposition documented in writing.  When applicable, the disposition of the request will be disclosed to others who need it. 

Procedures:

  1. Requests to correct or amend PHI, in order to be fully considered, must be in writing. 
  1. Timing for Response

Within ten (10) days of receipt of a request, Practice shall either:

  1. Make the requested correction or amendment and inform the patient of the action;
  2. Inform the patient if the record no longer exists or cannot be found;
  3. If Practice does not maintain the record, inform the patient and provide the patient with the name and address, if known, of the person who maintains the record; or
  4. Deny the request in writing as described below

If Practice is unable to act on the amendment within ten (10) days, Practice may extend the time for response by no more than twenty-one (21) days from the Practice’s receipt of the request, provided that the record is in use or unusual circumstances have delayed the handling of the correction or amendment request.

  1.      Approval of a Request: 
  1. The correction or amendment shall be made in the appropriate record.
  2. Mark the record affected by the change as corrected/amended at patient’s request.
  3. Draw a single line through any information to be modified, or create some other notation, and date and sign the entry. The original entry is to remain legible. 
  4. Indicate where in the record the corrected or amended information is located. 
  5. Enter the new information, indicate that it is a corrected or amended chart note, and date and sign the entry. 
  6. Send a copy of the correction or amendment to any third party that previously received the amended information.
  7. Obtain the individual’s identification of any persons the individual wants notified of the correction or amendment, and take reasonable steps to notify such persons of the change. 
  1. Denial of a Request:  An individual’s request to correct or amend a medical record may be denied if Practice determines that the PHI:
    1. Was not created by Practice, unless the individual provides a reasonable basis to believe that the originator of PHI is no longer available to act on the requested amendment;
      1. Is not part of the designated record set;
      2. Would not be available for inspection under the Patient Request to Access Medical Records Policy; or
      3. Is accurate and complete. 
  2. Disposition: 
    1. Individuals must be informed of the disposition of the written request. 
    2. If the request is denied:
      1. Send the requestor a denial letter and include the reason the denial and information about the option to file a statement of disagreement.
      2. Document the reason for the denial. 
      3. Add any statement of disagreement with the suggested amendment. 
      4. Add a copy of the denial letter to the medical record. 
      5. Mark the challenged entry to indicate that the patient claims the entry is inaccurate or incomplete and indicate where the request for amendment and any statement of disagreement is located in the record. 
      6. Send any statement of disagreement to any third-party payor or insurer that previously received the disputed PHI.
      7. Document the disclosure.
    3. Future disclosures must include the written request, the denial and any statement of disagreement. However, if no statement of disagreement is filed, the written request and the denial may only be included in future disclosures upon the request by the patient or authorized individual. 
  1. Amendments Originating Elsewhere:  If notified by another health care entity that an amendment or correction has been made to a patient’s PHI then:
    1. The correction or amendment shall be filed in the appropriate record; 
    2. As necessary, mark the record affected by the change as corrected or amended, and 
    3. The affected record should be attached or linked or otherwise indicate where in the record the corrected or amended information is located. 
  1. Documentation:  The Privacy Officer is responsible for receiving and processing requests for amendments by individuals and retaining documentation of the requests and responses for 6 years.
Privacy Practices Training

General Policy:

Each member of Practice’s workforce shall be instructed regarding these Privacy Policies and Procedures and other privacy practices in a manner that is tailored to address the specific functions that the individual receiving that education performs.

Procedures:

  1. Training for existing workforce members shall be completed as soon as practicable after these Privacy Policies and Procedures are adopted by Practice.  Each individual who joins the workforce after this initial training shall be trained as soon as practicable after joining the workforce
  1. “Workforce” includes all employees, work-study students, volunteers, trainees, and other persons whose conduct is under the direct control of Practice, whether or not they are paid employees.
  1. Whenever a material change is made to privacy practices, each member of the workforce affected by the change shall be trained regarding the change within a reasonable period of time, as defined by the Privacy Officer.
  1. The completion of training required by this Privacy Practices Training Policy shall be documented by the individual who offered the training.  This documentation shall be retained for at least six (6) years from the date of its creation.
  1. The Privacy Officer shall implement and oversee all training required by this Privacy Practices Training Policy.  To accomplish this task, the Privacy Officer shall have the authority to consult with and delegate authority, as well as appoint committees to develop and perform training activities.
  1. If the Privacy Officer believes that a workforce member’s failure to attend or participate in the designated training required by this Privacy Practices Training Policy is purposeful and not reasonably justified, he or she shall report the information supporting that belief, in writing, and further action shall be taken as may be warranted.
  1. Workforce members may be subject to disciplinary procedures for failure to attend and participate in the training required by this Privacy Practices Training Policy.
Transmission of PHI via Telephone

General Policy:

Practice personnel may release PHI over the telephone in the same manner that such information may be released in person, in accordance with these Privacy Policies and Procedures.  

Procedures:

  1. Voicemail Services.  The voicemail system will be password protected to prevent unauthorized access to voicemail messages containing PHI.  
  1. Telephone Directories. 
  1. a) Patient-contact telephone numbers shall not be programmed into phones.  
  2. b) Written and computerized directories of patient-contact information will be restricted to authorized individuals only.  Employees or any other individual authorized to access patient-contact directories shall not share the information in the directory, in whole or part, with any unauthorized individual.  
  3. c) Computerized directories of patient information shall not remain displayed on a computer screen while not in use.  
  1. Conducting Calls.  Calls shall be conducted in a manner that preserves patient privacy to the greatest extent possible.  Doors, windows, and other partitions should be shut when possible.  Care should be taken to limit the volume of one’s voice when transmitting PHI, especially if unauthorized individuals are nearby or the information is of a sensitive nature.
  1. Transmitting Information via Telephone.  Whenever practical, the individual handling a call that concern PHI shall make efforts to ensure the identity of the caller prior to transmitting PHI.  To help ensure the confidentiality of PHI, each incoming caller purporting to be the patient or the patient’s representative, when there is doubt as to the identity of the caller, may be asked to state the patient’s birth date or address, prior to releasing PHI to the caller.
  1. Calls to Patients.  When asking for a patient, information about the clinical condition of the patient shall not be disclosed.  This includes not identifying who is calling, if doing so would reveal the patient’s condition.  If a person at the dialed number states that he or she is the patient, that representation shall be considered confirmation that the patient is the person speaking.  PHI may then be discussed with that person.
  1. Messages for Patients.  Messages for patients shall be limited to the following:
  1. a) The name of the person for whom the message is being left;
  2. b) A request that the patient return the call;
  3. c) Adequate identification of the person placing the call, but only if doing so will not reveal the clinical condition of the patient;
  4. d) The name of the individual for whom the patient may ask for when returning the call, if applicable;
  5. e) The telephone number where the call may be returned; and
  6. e) Whether or not the appointment requires special instructions, but only if doing so will not reveal the clinical condition of the patient.

Transmission of PHI via E-mail

General Policy:  Unencrypted e-mail messages may be read by someone other than the intended recipient(s) of the e-mail.  As such, Practice’s workforce must take the appropriate steps to communicate the risks associated with sending unencrypted e-mails with PHI to patients, and to confirm the patient’s desire to have their PHI sent via e-mail notwithstanding the risks involved with doing so.  At a minimum, workforce of Practice must comply with the following procedures set forth in this policy when sending PHI to patients via e-mail.

Procedures:

  1. Workforce may only e-mail a patient’s PHI to the patient, or to a person designated by the patient, if the patient has: (1) requested his or her PHI to be e-mailed, and (2) completed the E-mail Consent Form attached to this policy.  A copy of the signed E-mail Consent Form shall be maintained in the patient’s medical records.
  1. Workforce must exercise a greater degree of caution in transmitting PHI electronically than they take with other means of communicating PHI (e.g., written memos, letters, pictures, or phone calls) because of the reduced human effort required to redistribute information electronically.
  1. PHI should never be transmitted or forwarded to outside individuals or companies not authorized to receive such information and should not be sent or forwarded to other employees inside the organization who do not have a need to know such information.  
  1. Workforce must use care in addressing e-mail messages to patients to ensure that messages are not inadvertently sent to unintended recipients.  
  1. All e-mails containing PHI sent from Practice must include the following standard disclaimer: 

This e-mail and its attachments may contain protected health information intended solely for the use of Odyssey Travel Health, PLLC (the “Practice”) and the recipient(s) named above. Due to the unsecured nature of unencrypted e-mail, the recipient(s) named above understand and agree that there may be some level of risk that the information in this e-mail could be read by a third party.  If you are not the intended recipient, you are hereby notified that any review, dissemination, distribution, printing or copying of this email message and/or any attachments is strictly prohibited.  If you have received this transmission in error, please notify the Practice at odysseytravelhealth@outlook.com and permanently delete this e-mail and any attachments.

PATIENT CONSENT FOR E-MAIL COMMUNICATIONS

It is the understanding of Odyssey Travel Health, PLLC (“Practice”) that you would like us to communicate with you via e-mail.  Prior to using e-mail communications that may contain your protected health information (“PHI”), Practice needs to advise you that there may be some level of risk that information in an unencrypted e-mail could be read by a third party.  Practice will not be responsible for any unauthorized access of your PHI in e-mails that we send to you.

If you have any questions about this form or about our communications with you about your PHI, you may contact our Practice’s Privacy Officer, Lisa Garza at odysseytravelhealth@outlook.com

I, the undersigned, consent to e-mail communications with Practice and its providers about my PHI and I understand the risks associated with using e-mail communications.  I will inform Practice in writing if I no longer wish to communicate with Practice via e-mail.  

___________________________________

Patient Name/Patient Guardian (Print)

___________________________________

Signature

___________________________________

Date

Transmission of PHI via Facsimile

General Policy:

Practice has adopted this policy to comply with the Act, as well as our duty to protect the confidentiality and integrity of confidential medical information as required by law, professional ethics, and accreditation requirements.  PHI shall be transmitted by facsimile only when other means of transmission are not feasible.  Minor inconvenience shall not constitute infeasibility.  All personnel must strictly observe the standards and procedures set forth in this Transmission of PHI via Facsimile Policy and Procedure relating to facsimile communications of patient medical records.

Assumptions:

  • Practice and the personnel or organizations with which Practice does business often will have a need to transmit or receive confidential medical information by facsimile rather than by a slower method, such as mail.
  • Personnel may send faxes to unauthorized recipients, faxes may be intercepted or lost in transmission, or Practice may not receive a fax intended for it because of one of these or other reasons.
  • Thus, the potential for breach of patient confidentiality exists every time someone uses such information.

Procedures:

  1. Practice, its contracted officers, agents, and employees will send health information by facsimile only when the original record or mail-delivered copies will not meet the needs of immediate patient care.
  1. Personnel may transmit health records by facsimile only when urgently needed for patient care or required by a third-party payer for ongoing certification of payment for a patient.
  1. Personnel must limit information transmitted to that necessary to meet the requester’s needs.
  1. Except as authorized by law, a properly completed and signed authorization must be obtained before releasing patient information.  Note, that such authorization is not required if disclosing patient information for treatment, payment or healthcare operations as described in the Permitted Uses and Disclosures Policies and Procedures.
  1. Personnel may not send by fax especially sensitive medical information, including, but not limited to, AIDS/HIV information, mental health and developmental disability information, alcohol and drug abuse information, and other sexually transmissible disease information without the express authorization of the Privacy Officer.
  1. The cover page accompanying the facsimile transmission must include the following confidentiality notice:

This facsimile and its enclosures may contain protected health information intended solely for the use of Odyssey Travel Health, PLLC (the “Practice) and the recipient(s) named above. Due to the unsecured nature of facsimiles, the recipient(s) named above understand and agree that there may be some level of risk that the information in this facsimile could be read by a third party.  If you are not the intended recipient, you are hereby notified that any review, dissemination, distribution, printing or copying of this facsimile and/or any enclosures is strictly prohibited.  If you have received this transmission in error, please notify Practice at  odysseytravelhealth@outlook.com and shred the facsimile and its enclosures.

  1. Personnel must make reasonable efforts to ensure that they send the facsimile transmission to the correct destination.  Personnel must preprogram frequently used numbers into the machine to prevent misdialing errors.  For a new recipient, the sender must verify the fax number before sending the facsimile and verify the recipient’s authority to receive confidential information.
  1. Fax machines must be in secure areas, where visitors and patients cannot easily access them.
  1. Office personnel are responsible for ensuring that incoming faxes are properly handled, not left sitting on or near the machine, but rather are distributed to the proper recipient expeditiously while protecting confidentiality during distribution.
  1. Personnel must report any misdirected faxes to the Privacy Officer.
  1. Users must immediately report violations of this policy to their department manager and to the Privacy Officer.
Complaint and Grievance

General Policy:

Practice will continually strive to improve the quality of the services it provides and will provide a process for handling complaints and grievances related to the use or disclosure of PHI.

Definitions:

  1. Complaint: an oral concern about compliance with health-information privacy laws.
  1. Grievance: a written concern about compliance with health-information privacy laws and regulations.
  1. Responsible Party: all physicians, employees, and personnel of Practice.

Procedures:

  1. All grievances regarding privacy policies and practices, and compliance with those policies and practices, will be accepted and considered.  Complaints should be made in writing using the Compliant and Grievance form attached at the end of this Compliant and Grievance Policy and Procedure and directed to the Privacy Officer.
  1. All grievances will be responded to in writing if the complaint seeks a response.
  1. Individuals who file a grievance will not be retaliated against in any way, including through coercion, harassment or refusal of treatment.  Violations of this anti-retaliation policy will be handled in accordance with the Policy Regarding Sanctions for Privacy Violations.
  1. Procedure for Responding to a Complaint:
  1. The Privacy Officer, or his designee, shall review all complaints within a reasonable period but in no event not later than thirty (30) days. 
  2. If the complaint seeks a response, and provides contact information, the Privacy Officer (or his or her designee) shall prepare and deliver a written response to the individual who lodged the complaint.  
  3. If the complaint does not seek a response, or does not provide contact information, the Privacy Officer (or his designee) shall prepare a written statement of any action taken with regard to the complaint. That statement shall be attached to, and filed with, the complaint.

COMPLIANT AND GRIEVANCE FORM

PERSON WITH COMPLAINT

Date of Report: Date of Occurrence:

Person Reporting: Name & Account # of Patient:

Home Address: Do you feel the problem involves:

      Accidental disclosure     ◻

      Deliberate disclosure     ◻

Telephone #:       Other security incident     ◻ 

When did you first become concerned with this issue?

Have you discussed this problem with anyone?   Yes       No     Who?                                 When?

Please state the problem in your own words, giving as much specific information as possible (use back of sheet if you need more space)

Signature:                                                                               Date:

PERSON TAKING REPORT

Name of person taking report: Position/Title:

Date:

Have you personally interviewed the complainant? Action Taken & Date:

Additional Comments: Follow-up Information & Date:

Business Associate Agreements 

General Policy:

Practice, in accordance with the Act, may permit a business associate to create, receive, maintain, or transmit electronic PHI (ePHI) and to use or disclose PHI on Practice’s behalf only if Practice obtains satisfactory assurances, in accordance with this Business Associate Agreements Policy and Procedure, that the business associate will appropriately safeguard the information.  This Business Associate Agreements Policy and Procedure does not apply with respect to the transmission by Practice of ePHI or PHI to a health care provider concerning the treatment of an individual or an insurance company related to payment for the treatment of an individual.

Procedures:

  1. Practice will document the satisfactory assurances required by this Business Associates Agreements Policy and Procedure through a written contract with a business associate (i.e., a Business Associate Agreement).  
  1. If Practice knows of a pattern of an activity of the business associate that constitutes a material breach or violation of the business associate’s obligation under the Business Associate Agreement, Practice will take reasonable steps to cure the breach or end the violation, as applicable. If such steps are not successful, Practice shall terminate the contract or arrangement, if feasible.