Orange County NC Website
Policy 20: HIPAA Compliance Officer Action Plan for Administrative Requests for PHI from Government Agencies <br /> North State Medical Transport HIPAA Compliance Officer Action Plan: <br /> Administrative Requests for PHI from Government Agencies <br /> Step 1: Does the federal,state,or local government agency have the authority to YES NO <br /> make the administrative request(an administrative request can include an administrative <br /> subpoena,summons,civil or other authorized investigative demand or similar process)? Go to Step 2 The HIPAA Compliance Officer should deny the request in <br /> The HIPAA Compliance Officer should look to any statutory or regulatory authority cited in writing stating that proper legal authority,demonstrating that <br /> the request and consult with legal counsel when making this determination. the agency has the right to request and receive the PHI, must <br /> be provided to North State Medical Transport by the <br /> administrative agency before the request will be considered. <br /> Step 2: Is it clear from the request that all 3 conditions below are satisfied? YES NO <br /> 1. The PHI sought by the request is relevant and material to a legitimate law Go to Step 3 The HIPAA Compliance Officer should send the requestor a <br /> enforcement inquiry; letter stating that North State Medical Transport will not <br /> 2. The request is specific and limited in scope to the extent reasonable practicable in disclose any PHI until the administrative agency certifies in <br /> light of the purpose for which the PHI is sought;and writing that the three conditions have been met. <br /> 3. De-identified information could not reasonably be used? <br /> Step 3: <br /> The HIPAA Compliance Officer shall ONLY disclose the PHI that has been requested in the administrative request. The HIPAA Compliance Officer shall also contact the issuer of <br /> the request whenever it is unclear what PHI North State Medical Transport is required to disclose. If necessary,the HIPAA Compliance Officer shall ask the requesting agency to <br /> re-issue a more specific request. The HIPAA Compliance Officer shall retain a copy of the administrative request as well as any written assurances in the patient file. The HIPAA <br /> Compliance Officer shall also track the disclosure in an accounting log and document:the name of requesting agency;the date of the request;the date of disclosure and the PHI <br /> that was disclosed. <br />