GRANULAR PATIENT CONTROL OF PERSONAL HEALTH INFORMATION: FEDERAL AND STATE LAW CONSIDERATIONS
- PMID: 31798215
- PMCID: PMC6890413
GRANULAR PATIENT CONTROL OF PERSONAL HEALTH INFORMATION: FEDERAL AND STATE LAW CONSIDERATIONS
Abstract
The advent of electronic medical records and health information exchanges has facilitated the possibility of patients exercising increasingly granular control over sensitive health information. In principle, patients should be able to control which of their health information is made accessible to which of their healthcare providers. To meet this goal, the architects of any system of granular control of patients' health information face a variety of challenges. In addition to technical, ethical, and prudential considerations, the architects of any effective system must also ensure compliance with applicable legal requirements. The extent of a patient's permissible control depends upon whether governing law prohibits providers from disclosing health information to other providers without a patient's authorization, permits providers to disclose to other providers at the provider's discretion, or requires such disclosure. To inform efforts to design a viable system, this article analyzes U.S. federal and state (Arizona) law in regard to the sharing of the following types of sensitive health information: substance abuse, mental health, genetic, communicable diseases, and sexual and reproductive health.
References
-
- See generally Caine Kelly et al., Designing a Patient-Centered User Interface for Access Decisions About EHR Data: Implications from Patient Interviews, 30 J. GEN. INTERNAL MED (SUPP. 1) S7 (2015) - PMC - PubMed
- Caine Kelly & Hanania Rima, Patients Want Granular Privacy Control Over Health Information in Electronic Medical Records, 20 J. AM. MED. INFORMATICS ASS’N 7 (2013) - PMC - PubMed
- Campos-Castillo Celeste & Anthony Denise L., The Double-Edged Sword of Electronic Health Records: Implications for Patient Disclosure, 22 J. AM. MED. INFORMATICS ASS’N e130 (2015) - PMC - PubMed
- Adela Grando M et al., A Study to Elicit Behavioral Health Patients’ and Providers’ Opinions on Health Records Consent, 45 J. L. MED. & ETHICS 238 (2017) - PMC - PubMed
- Schwartz Peter H. et al., Patient Preferences in Controlling Access to Their Electronic Health Records: A Prospective Cohort Study in Primary Care, 30 J. GEN. INTERNAL MED (SUPP. 1) S25 (2015). - PMC - PubMed
-
- Federal healthcare regulations, notably HIPAA, apply only to covered entities and their business associates. See 45 C.F.R. §§ 160.102–.103 (2017). Other laws also regulate certain indi-viduals and institutions but not others. Thus, the analysis depends upon who the sender of infor-mation is, what the information consists of, and who the receiver is.
-
- See infra Section I.C.1. See also HEALTHCURRENT, https://healthcurrent.org [https://perma.cc/8J34-9ATH].
-
- The research doing this work is funded by NIMH Grant R01MH108992 to Principal Investigator Adela Grando.
-
- About Us, SUBSTANCE ABUSE & MENTAL HEALTH ADMIN, https://www.samhsa.gov/about-us [https://perma.cc/AKP7-BMTC].
Grants and funding
LinkOut - more resources
Full Text Sources