EMRs, Data Mining and HIPAA

June 24, 2011
The current Healthcare Informatics online poll asks whether you would contract with an electronic medical record vendor that had an arrangement with

The current Healthcare Informatics online poll asks whether you would contract with an electronic medical record vendor that had an arrangement with a third party to mine EMR data for research or other purposes. It's important to remember in these situations that an EMR vendor will typically be a business associate of a healthcare provider within the meaning of HIPAA. A compliant business associate agreement must "establish the permitted and required uses and disclosures" of protected health information (PHI) by the business associate. In short, an EMR vendor can share information only to the extent that it has been permitted to do so under the terms of its business associate (BA) agreement.

BA agreements may contain optional provisions permitting "data aggregation" services, "de-identification" of PHI and use for the "proper management and administration" of the business associate. "Data aggregation" and "de-identification" have defined meanings under the HIPAA Privacy Rule. It's a little more unclear how far a vendor may go in using PHI for its own "proper management and administration" purposes. HIPAA covered entities should never sign a BA agreement with an EMR vendor (or any other vendor, for that matter) without watching for these key phrases and understanding fully how the vendor intends to use and disclose their PHI.

Sponsored Recommendations

How Digital Co-Pilots for patients help navigate care journeys to lower costs, increase profits, and improve patient outcomes

Discover how digital care journey platforms act as 'co-pilots' for patients, improving outcomes and reducing costs, while boosting profitability and patient satisfaction in this...

5 Strategies to Enhance Population Health with the ACG System

Explore five key ACG System features designed to amplify your population health program. Learn how to apply insights for targeted, effective care, improve overall health outcomes...

A 4-step plan for denial prevention

Denial prevention is a top priority in today’s revenue cycle. It’s also one area where most organizations fall behind. The good news? The technology and tactics to prevent denials...

Healthcare Industry Predictions 2024 and Beyond

The next five years are all about mastering generative AI — is the healthcare industry ready?