HIPAA Guidance

Implementation of HIPAA and the Privacy Rule by the IRB

What is HIPAA?

HIPAA is the acronym for the Health Insurance Portability and Accountability Act of 1996. The Act requires The Department of Health and Human Services to develop regulations to protect the privacy and security of identifiable health information.  Two sets of regulations, referred to as the Privacy Rule and Security Rule, outline the requirements that must be followed when entities subject to the rules use and share health information.

What types of information are regulated by the Privacy and Security Rules?

The rules apply to protected health information (PHI), which is defined as individually identifiable health information that is transmitted or maintained in any form or medium (electronic, oral, or paper) by a covered entity or its business associates, excluding certain educational and employment records.

In most instances, health information is considered individually identifiable when any of the following identifiers are included with the information:

  • Names
  • Telephone numbers
  • Fax numbers
  • Email addresses
  • Social Security numbers
  • Medical record numbers
  • Health plan beneficiary
  • Vehicle identifiers and serial numbers, including license plate numbers
  • Account numbers
  • Certificate/license numbers
  • Device identifiers and serial numbers
  • Web Universal Resource Locators (URLs)
  • Internet Protocol (IP) addresses
  • Biometric identifiers, including finger and voice prints
  • Full-face photographs and any comparable images
  • Any other unique identifying number, characteristic, or code, unless otherwise permitted by the Privacy Rule for re-identification
  • All geographic subdivisions smaller than a state, including street address, city, county, precinct, ZIP code, and their equivalent geocodes, except for the initial three digits of the ZIP code if, according to the current publicly available data from the Bureau of the Census:
    • The geographic unit formed by combining all ZIP codes with the same three initial digits contains more than 20,000 people; and
    • The initial three digits of a ZIP code for all such geographic units containing 20,000 or fewer people is changed to 000.
  • All elements of dates (except year) for dates that are directly related to an individual, including birth date, admission date, discharge date, death date, and all ages over 89 and all elements of dates (including year) indicative of such age, except that such ages and elements may be aggregated into a single category of age 90 or older.
  • Back to top

    Who must comply with HIPAA?

    One of the main purposes of HIPAA is to require health plans to accept electronic transactions from health care providers. The Privacy and Security Rules are means to the risk to individual privacy when the electronic transactions are processed.  The Rules apply to all PHI held by covered entities, which are health plans (health insurance companies), health care providers and health care clearing houses (companies that facilitate electronic transactions.  UC Davis Medical Center is a health care provider and is a covered entity under HIPAA.

    Back to top

    What Does the Privacy Rule Have To Do With Research?

    When research involves the use or disclosure of PHI by entities subject to the regulations, the rules will apply. Researchers have legitimate needs to use, access, and disclose PHI to carry out a wide range of health research studies. In most instances, the Privacy Rule requires an authorization from the individual or a waiver of authorization from an IRB or Privacy Board before a covered entity can access, use or disclose PHI for research purposes. In general, there are two types of human research that would involve PHI:

    • Studies involving review of medical records as a source of research information.
    • Studies that create new medical information because a health care service is being performed as part of the research.

    Back to top

    What is the IRB’s Role?

    In most instances, researchers at UC Davis use the UC HIPAA Research Authorization (University of California Permission to Use Personal Health Information for Research) to use and share PHI for research purposes. However, in some instances, the Privacy Rule allows an IRB to waive the requirement for a signed authorization from the individual for use of PHI in research.  UC Davis researchers complete the applicable section of the electronic Initial Review Application when they need access to PHI without obtaining an authorization from the individual.

    Back to top

    When can an IRB waive the requirement for an authorization?

    It is always preferred to obtain authorization to use an individual’s PHI.  In order to waive the requirement for an authorization, the IRB must determine that the study meets the following criteria:

    • The use or disclosure of the identifiers involves no more than minimal risk (An adequate plan to protect identifiers from improper use and disclosure must be included in the research proposal)
    • There is an adequate plan to destroy the identifiers at the earliest opportunity.
    • The project could not practicably be conducted without a waiver
    • The project could not practicably be conducted without use of PHI
    • The IRB receives written assurances that PHI will not be re-used or disclosed for other purposes

    Back to top

    What kind of waivers does the UC Davis IRB grant?

    The UC Davis IRB will approve either:

    • A full waiver of authorization to conduct all the research activities described in the research proposal; or
    • A partial waiver of authorization for specific research actives such as recruitment.

    In most instances, a full waiver of authorization is granted only when there is no opportunity for the researcher to obtain authorization from the individual.  Partial waivers of authorization are often granted to allow researchers to access the EMR to identify potential research participants.

    If a full waiver of authorization is granted, the IRB will post a Form W with the approval documents.  If a partial waiver of authorization is granted, the IRB will post a Form R with the approval documents.