|
|
||||||||
Ethics Feature |
From the Department of Family Medicine, Wayne State University, Detroit, MI
Correspondence: Address correspondence to: Anne Victoria Neale, PhD, MPH, Department of Family Medicine, Wayne State University, 101 E. Alexandrine, Detroit, MI 48201 (e-mail: vneale{at}med.wayne.edu)
Concerns with the privacy of personal health information have grown with increased use of electronic medical records and with the patient-centered philosophy that physician-patient relationships should rest on principles of respect, autonomy, and confidentiality. Practicing clinicians are aware that the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule1, 2 set rigorous standards for the protection of personal information contained in patient medical records. The Privacy Rule also resulted in more restrictive standards on the research use of "protected health information" (PHI), which can reveal the identity of patients.
To protect patient privacy, "covered entities" (all health plans, health care "clearinghouses, " and health care providers) must obtain specific, written authorization from a patient to use or disclose PHI. Patients must also be notified about their right to restrict the use and disclosure of such information. Covered entities must make reasonable efforts to limit the health information disclosed to the minimum necessary to accomplish the intended purposes. Although these restrictions seem to block some common approaches for patient recruitment and data collection, the Privacy Rule does have several provisions for procedures and processes that allow researchers to access personal health information in the absence of individual consent.
Physicians participating in practice-based research should be aware of how the Privacy Rule limits the use and disclosure of PHI, as well as the current standards for the disclosure of PHI for research purposes. Medical office staff, practice partners, or rotating residents and students may have questions about their ability to support practice-based research while upholding HIPAA standards for the protection of patient health information. Physician researchers must keep up with the evolving requirements for the ethical conduct of research and its associated vocabulary.
Local Institutional Review Boards (IRB) have the authority to make determinations about whether the proposed procedures of research under their domain meet Privacy Rule requirements. Investigators knowledgeable of accepted interpretations of how the Privacy Rule applies to research are better able to develop strategies for patient recruitment, data collection, and data sharing that meet Privacy Rule standards. In addition, participating members of practice-based research (PBR) networks3 need to understand the specific nature of the research activities that are covered in IRB approval of PBR studies. To this end, we address some common questions about the research use of PHI, and present definitions and interpretations of selected Privacy Rule terms with particular meaning to the conduct of PBR.
Practice-Based Research and Compliance with the HIPAA Privacy Rule
Has the Privacy Rule Replaced the Federal Common Rule?
No. The Privacy Rule has not modified the well-known federal "Common Rule"4 that requires IRB approval for all research conducted under its purview. The Common Rule defines the boundaries between research and practice and establishes the eminence of 3 ethical principles in research: respect for persons, beneficence, and justice.5 The Common Rule set the ethical standard that all research subjects provide informed consent to participate in a research study. The local IRB has the authority to waive the requirement of informed consent if it decides that the proposed research involves "no more than minimal risk"; that the waiver "will not adversely affect the rights and welfare of subjects"; that "the research could not practicably be conducted without the waiver"; and "whenever appropriate, the subjects will be provided with additional pertinent information after participation" (such as a treatment benefit).4, 6, 7
The Privacy Rule regulates only the content and conditions of documentation that covered entities must obtain before using or disclosing PHI for research purposes.1, 2, 8 The HIPAA regulations also permit IRBs to grant waivers of patient authorization to use and/or disclose PHI in certain circumstances.6, 8 However, local IRBs have the authority to interpret how the Privacy Rule applies to individual research studies, and they are known to vary in their interpretations of, and standards for, responsible conduct of research.7, 9
As a New PBR Network Member, Im Asked to Provide Practice Characterization Data. Does the Privacy Rule Prohibit This?
No. A covered entity may give researchers access to medical records without IRB review or authorization by individual patients to prepare a research proposal.6, 7 Thus, it is permitted to use personal health records to characterize your patient population if this is preliminary to an actual research study (eg, preliminary information about the patient population for a grant proposal). These data can be organized as either a limited or de-identified dataset and compiled in a summary table. However, the researcher must adhere to the following restrictions on "reviews preparatory for research" 7, 10: (1) disclosure is sought solely to prepare a research protocol or for similar purposes; (2) no PHI is to be physically removed from the covered entity; and (3) the PHI is necessary to plan the research (Table 1).
|
The preparatory research provision also permits covered entities to disclose PHI to aid study recruitment.7, 10 In this case, an employee or member of the covered entitys workforce would be allowed to identify prospective research participants for purposes of seeking their authorization to use or disclose PHI for a research study. Clinician researchers and clinical staff are permitted to directly recruit their patients. It is also permitted for outside researchers to develop a "generic" recruitment letter for clinicians to sign and mail or hand to potential study participants. If the generic letter includes PHI (eg, name or address), the clinical staff must generate the letter.
Is It Permitted to Combine the Form for Patient Informed Consent (Required by the Common Rule), and the Patient Authorization to Use PHI (Required by the Privacy Rule) into a Single Consent/Authorization?
Yes. Although there are important differences between the Privacy Rules requirement for individual authorization for the research use or disclosure of PHI and the Common Rules requirement to consent to participate in a research study as a whole, "both sets of requirements can be met by use of a single, combined form, which is permitted by the Privacy Rule."1, 2, 7 , 10 However, local IRBs have the authority to require separate forms.
Does the Privacy Rule Permit the Creation of a Research Database That Contains PHI?
Yes. The regulations permit researchers to access and use all PHI with patients authorization.1, 2, 8 If such patient authorization is not possible or "practicable, " researchers can apply to their IRB for a waiver of individual authorization, making sure to document that the specific waiver criteria are satisfied.1, 2, 7, 8, 10 Researchers who apply for a waiver are advised to thoroughly address the following concerns: (1) the use or disclosure of the PHI involves no more than minimal risk to the privacy of the individual; (2) the research could not practicably be conducted without access to and use of the PHI; (3) only the "minimum necessary" information is requested and each data element is justified; (4) the research could not practicably be conducted without the waiver; and (5) there is an adequate plan to protect the identifiers from improper use and disclosure.
What Is the Difference between a "De-Identified" and a "Limited" Dataset?
A "de-identified dataset" excludes 18 specified identifiers (Table 2). A covered entity may de-identify PHI so that such information may be used and disclosed freely, without being subject to the Privacy Rules protections.11 However, a de-identified dataset may contain a nominal linking code that could allow the covered entity to later re-identify that information.
|
Strategies to Professionalize PBR Networks
PBR networks (PBRNs) must be professional research organizations with high-quality research capability, 12 and researchers should be prepared to educate covered entities about the research-related provisions of the Privacy Rule.10 The following are potentially supportive strategies that PBRNs can pursue to position their studies to be favorably reviewed by IRBs.
The HIPAA Privacy Rule was not specifically designed to facilitate or limit medical research, 6 and it does not directly regulate research.10 Compliance with the Privacy Rule can be achieved with the following strategies:
Glossary of Selected HIPAA Privacy Rule Terms of Importance to Practice-Based Researchers
A Business Associate is a person or entity who, on behalf of a covered entity, performs a function involving the use or disclosure of individually identifiable health information, such as data analysis, utilization review, and quality assurance reviews.7, 8
Data Use Agreements describe permitted uses and disclosure of PHI and prohibit re-identifying or using information to contact individuals.7, 8
A De-identified Dataset contains no PHI, although it may have personal health information if it cannot be linked to an individual. There are 2 ways of de-identifying datasets so that the Privacy Rule will not apply1, 2, 7, 10:
Acceptable techniques include removing direct identifiers, reducing the number of variables on which a match might be made, and limiting the distribution of records through a data use agreement, in which the recipient agrees to limit who can use or receive the data.
The IRB will determine whether these criteria have been satisfied.
Written permission ("HIPAA authorization") obtained from the individuals; or
A waiver of the requirement for authorization from the IRB. Research is a systematic investigation, including research development, testing, and evaluation, designed to develop or contribute to generalizable knowledge.1, 2, 8 This includes the development of research repositories and databases for research.7 A covered entity may always use or disclose, for research purposes, health information that has been de-identified without regard to the Privacy Rule.8 Note that research differs from the "health care operations" of covered entities, which are exempt from the Privacy Rule, and may include "quality assurance and quality improvement, including outcomes evaluation and development of clinical guidelines."10 (See Doezema and Hauswald13 for a discussion of the distinction between quality improvement and research.)
Received for publication September 13, 2004. Revision received September 13, 2004.
References
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| HOME | HELP | CONTACT US | SUBSCRIPTIONS | ARCHIVE | SEARCH | SEARCH RESULT |