Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Privacy And Compliance topic
No spam. Unsubscribe anytime.
Board receives HIPAA briefing stressing 'minimum necessary' rule and handling of PHI
Summary
The board received a HIPAA training from Ryn Coleridge emphasizing that commissioners may receive protected health information and that 'once you receive it, it's PHI.' The session reviewed de‑identification safe harbor, cybersecurity practices, and potential civil and criminal penalties.
Get email alerts on the Privacy And Compliance topic
No spam. Unsubscribe anytime.
Ryn Coleridge, director of enterprise systems and analytics and the agency's privacy officer, gave a board education session on HIPAA compliance and commissioners' responsibilities.
Coleridge said SFHSS is a component of a hybrid covered entity and reminded commissioners that when they receive protected health information (PHI), "it's governed by HIPAA" and that the legal test of disclosure is the "minimum necessary" standard. He outlined operational practices: avoid storing PHI on personal computers, route member inquiries through board staff (for triage and assignment), use de‑identification safe harbor when releasing aggregate data, and complete required cybersecurity training.
The presentation reviewed the 18 identifiers that must be removed under the safe‑harbor de‑identification method, examples of permissible uses for treatment, payment and operations, and possible civil penalties across four tiers and criminal penalties up to 10 years for willful neglect or intentional violations. Commissioners asked about practical steps for forwarding member emails and were directed to send inquiries to executive staff for triage.
Coleridge encouraged commissioners to contact the privacy officer before releasing any member information and said the department is providing secured laptops for commissioners to reduce risks from using personal devices.
