HIPAA and Codes of Ethics

The situation. Healthcare providers need access to patient personal health information wherever patients are present for care. Systems that standardize electronic medical records provide such access, but the risk to privacy that accompanies that access is real, and breaches often make the news. At the Federal level, the HIPAA Privacy Rule protects personal health information gathered by healthcare providers, but most agree that information needs more protection than HIPAA currently affords. Some believe added protection may be found in the forming and keeping of codes of ethics.

A scenario. Mary works in a hospital health information management department, and Maureen, her friend, comes one day to pick up the medical records of a patient who is a client of the lawyer Maureen works for. Maureen, however, has forgotten to bring the client's signed authorization form, though she assures Mary the form, which she saw the patient sign, is at her office. Since Maureen's need for the form is urgent and there isn't enough time to return with the form today, Maureen hopes to take the records and return with the form another day.

Read the iHealthCoalition'seHealth Code of Ethics, the Summary of the HIPAA Privacy Rule, and with the above scenario in mind, consider the following questions:

• In light of what the Code and HIPAA say, how might Mary and Maureen best resolve the problem?

• How might a code of ethics provide personal medical information more protection than HIPAA?

• In the above code, only one of the eleven sections is explicitly labeled privacy. Do matters covered in other sections play roles in protecting personal medical information? Explain.

• In what ways, if any, does HIPAA protect personal medical information where codes of ethics do not?
Support your answers with examples, clear reasoning, and by citing the Code of Ethics and HIPAA regulation directly.

Assignment 2: System Selection

In this course, you will progressively work on a system implementation process in six stages:

• Week 1: System planning

• Week 2: System analysis

• Week 3: System selection

• Week 4: System implementation

• Week 5: User training and system maintenance

You can use Internet resources, peer-reviewed journals, and reputable, published articles, and you may interview an executive of a healthcare facility that has implemented an electronic medical record system/electronic health record system or similar system to describe the six implementation steps.

This week, you will conduct system selection, which requires completion of the following steps:

• Reviewing a Request for Proposal (RFP)-this invites selected vendors to submit a proposal to you that outlines details of their proposed information system or systems.

• Evaluation of the proposed system through on-site demonstration, site visits, reference checks, and making a decision.

• Contract negotiation.

Assume that your healthcare organization has conducted an RFI, or a fact finding part of the system implementation and helps to select the potential vendors. It has requested information from vendors about their products and services. With the information gathered, the organization has screened the potential vendors and issues the RFP (request for proposal).

Download this RFP for EHR Implementation: UA_RFP-EHR. This is an actual RFP. Review the document and answer the following:

• Does the RFP expressly state organization and user needs? If so, what are these? If not, why is the RFP failing to do so?

• What are the strengths and weaknesses of this RFP?

• How would you change this document?

