The HIPAA privacy rule: practical advice for academic and research institutions.
Kim P Gunter
Abstract
Kim P Gunter
Abstract
The Final Standards for Privacy of Individually Identifiable Health Information (privacy rule) of the Health Insurance Portability and Accountability Act (HIPAA) of 1996 holds particular importance for academic and research organizations because they use patient information in the provision of experimental healthcare services. In developing a strategy to comply with the final privacy rule, these organizations require an understanding of certain standards that hold significance for them. Specifically, organizations should establish patient privacy guidelines for non-employee researchers the organization should consider partners in business with whom the organization should share its researcher guidelines. These organizations also should understand the difference between consent and authorization, how requirements of the final privacy rule build upon those of the Federal Policy for the Protection of Human Subjects, and the differing roles of privacy boards and institutional review boards.
OpenAlex reports 7 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
The Final Standards for Privacy of Individually Identifiable Health Information (privacy rule) of the Health Insurance Portability and Accountability Act (HIPAA) of 1996 holds particular importance for academic and research organizations because they use patient information in the provision of experimental healthcare services. In developing a strategy to comply with the final privacy rule, these organizations require an understanding of certain standards that hold significance for them. Specifically, organizations should establish patient privacy guidelines for non-employee researchers the organization should consider partners in business with whom the organization should share its researcher guidelines. These organizations also should understand the difference between consent and authorization, how requirements of the final privacy rule build upon those of the Federal Policy for the Protection of Human Subjects, and the differing roles of privacy boards and institutional review boards.
Key concepts: Health Insurance Portability and Accountability Act, Business, Privacy policy, Information privacy, Privacy by Design, Confidentiality, Internet privacy, Privacy law