Cargando…

Important Considerations for the Institutional Review Board When Granting Health Insurance Portability and Accountability Act Authorization Waivers

Background: Privacy is recognized as a basic human right in the United States and has been identified as a core principle of ethics in clinical research. However, changes in the regulations, changes in how research is conducted, and the availability of health data stored in electronic health record...

Descripción completa

Detalles Bibliográficos
Autores principales: Williams, Kelsey, Colomb, Paul
Formato: Online Artículo Texto
Lenguaje:English
Publicado: Academic Division of Ochsner Clinic Foundation 2020
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7122251/
https://www.ncbi.nlm.nih.gov/pubmed/32284689
http://dx.doi.org/10.31486/toj.19.0083
_version_ 1783515376719495168
author Williams, Kelsey
Colomb, Paul
author_facet Williams, Kelsey
Colomb, Paul
author_sort Williams, Kelsey
collection PubMed
description Background: Privacy is recognized as a basic human right in the United States and has been identified as a core principle of ethics in clinical research. However, changes in the regulations, changes in how research is conducted, and the availability of health data stored in electronic health record systems all pose risks to individuals’ privacy. Methods: The Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule addresses the use and disclosure of individuals’ health information and sets standards for privacy rights so that individuals can understand and control how their health information is used. However, despite the significant increase in the complexity of the data privacy landscape, the HIPAA Privacy Rule has been largely unchanged since its enactment in 1996. Results: Generally, healthcare entities may not use or disclose protected health information (PHI) for research without written authorization from each subject permitting that use or disclosure. However, the HIPAA Privacy Rule allows an institutional review board (IRB) to waive the need for such authorization if documentation is provided that the use or disclosure of PHI presents “no more than a minimal risk to the privacy” of the subjects. Because IRBs were one of the only bodies allowed to waive the need for authorizations in the research context, they essentially served as the gatekeepers of privacy for human subjects. However, this situation changed with the 2018 revisions to 45 CFR §46—known as the Common Rule—that added new categories of exempt research. Under the new regulations, research administrative staff may review a submitted research study and determine that it is exempt without the IRB ever being involved and with no independent review of privacy considerations. This change lessens privacy protections for research subjects. Therefore, IRBs must be mindful of the relevant HIPAA guidance and carefully consider all facts and circumstances available when granting approvals of HIPAA authorization waiver requirements, especially in the content of exempt research, so that the IRB is confident that reasonable safeguards to protect patient privacy have been maintained. Research institutions should amend their processes to ensure that the appropriate level of privacy review is given to all studies, even those that are exempt. Conclusion: Few concrete rules are applicable in the research context that ensure compliance with the HIPAA Privacy Rule. Ultimately, more definitive regulatory guidance integrating HIPAA and the revised Common Rule should be promulgated.
format Online
Article
Text
id pubmed-7122251
institution National Center for Biotechnology Information
language English
publishDate 2020
publisher Academic Division of Ochsner Clinic Foundation
record_format MEDLINE/PubMed
spelling pubmed-71222512020-04-13 Important Considerations for the Institutional Review Board When Granting Health Insurance Portability and Accountability Act Authorization Waivers Williams, Kelsey Colomb, Paul Ochsner J Reviews and Contemporary Updates Background: Privacy is recognized as a basic human right in the United States and has been identified as a core principle of ethics in clinical research. However, changes in the regulations, changes in how research is conducted, and the availability of health data stored in electronic health record systems all pose risks to individuals’ privacy. Methods: The Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule addresses the use and disclosure of individuals’ health information and sets standards for privacy rights so that individuals can understand and control how their health information is used. However, despite the significant increase in the complexity of the data privacy landscape, the HIPAA Privacy Rule has been largely unchanged since its enactment in 1996. Results: Generally, healthcare entities may not use or disclose protected health information (PHI) for research without written authorization from each subject permitting that use or disclosure. However, the HIPAA Privacy Rule allows an institutional review board (IRB) to waive the need for such authorization if documentation is provided that the use or disclosure of PHI presents “no more than a minimal risk to the privacy” of the subjects. Because IRBs were one of the only bodies allowed to waive the need for authorizations in the research context, they essentially served as the gatekeepers of privacy for human subjects. However, this situation changed with the 2018 revisions to 45 CFR §46—known as the Common Rule—that added new categories of exempt research. Under the new regulations, research administrative staff may review a submitted research study and determine that it is exempt without the IRB ever being involved and with no independent review of privacy considerations. This change lessens privacy protections for research subjects. Therefore, IRBs must be mindful of the relevant HIPAA guidance and carefully consider all facts and circumstances available when granting approvals of HIPAA authorization waiver requirements, especially in the content of exempt research, so that the IRB is confident that reasonable safeguards to protect patient privacy have been maintained. Research institutions should amend their processes to ensure that the appropriate level of privacy review is given to all studies, even those that are exempt. Conclusion: Few concrete rules are applicable in the research context that ensure compliance with the HIPAA Privacy Rule. Ultimately, more definitive regulatory guidance integrating HIPAA and the revised Common Rule should be promulgated. Academic Division of Ochsner Clinic Foundation 2020 2020 /pmc/articles/PMC7122251/ /pubmed/32284689 http://dx.doi.org/10.31486/toj.19.0083 Text en ©2020 by the author(s); Creative Commons Attribution License (CC BY) http://creativecommons.org/licenses/by/4.0/legalcode ©2020 by the author(s); licensee Ochsner Journal, Ochsner Clinic Foundation, New Orleans, LA. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (creativecommons.org/licenses/by/4.0/legalcode) that permits unrestricted use, distribution, and reproduction in any medium, provided the original author(s) and source are credited.
spellingShingle Reviews and Contemporary Updates
Williams, Kelsey
Colomb, Paul
Important Considerations for the Institutional Review Board When Granting Health Insurance Portability and Accountability Act Authorization Waivers
title Important Considerations for the Institutional Review Board When Granting Health Insurance Portability and Accountability Act Authorization Waivers
title_full Important Considerations for the Institutional Review Board When Granting Health Insurance Portability and Accountability Act Authorization Waivers
title_fullStr Important Considerations for the Institutional Review Board When Granting Health Insurance Portability and Accountability Act Authorization Waivers
title_full_unstemmed Important Considerations for the Institutional Review Board When Granting Health Insurance Portability and Accountability Act Authorization Waivers
title_short Important Considerations for the Institutional Review Board When Granting Health Insurance Portability and Accountability Act Authorization Waivers
title_sort important considerations for the institutional review board when granting health insurance portability and accountability act authorization waivers
topic Reviews and Contemporary Updates
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7122251/
https://www.ncbi.nlm.nih.gov/pubmed/32284689
http://dx.doi.org/10.31486/toj.19.0083
work_keys_str_mv AT williamskelsey importantconsiderationsfortheinstitutionalreviewboardwhengrantinghealthinsuranceportabilityandaccountabilityactauthorizationwaivers
AT colombpaul importantconsiderationsfortheinstitutionalreviewboardwhengrantinghealthinsuranceportabilityandaccountabilityactauthorizationwaivers