Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Privacy Compliance topic
No spam. Unsubscribe anytime.
Board receives HIPAA and HITECH refresher: privacy officer urges caution on PHI handling
Summary
SFHSS privacy officer delivered HIPAA/HITECH training for commissioners emphasizing PHI definitions, penalties for violations, 'minimum necessary' principles and routing member inquiries to member services; presenter said there have been no reportable incidents in the past 3–4 years.
Get email alerts on the Privacy Compliance topic
No spam. Unsubscribe anytime.
The San Francisco Health Service System provided a HIPAA refresher for commissioners that outlined what counts as protected health information and how commissioners should handle member inquiries.
Ryn Coolidge, the system’s HIPAA privacy and security officer, reviewed the privacy and security rules, explained that PHI includes any health information linked to an identifier, and emphasized the "minimum necessary" standard for disclosures. Coolidge described de-identification methods and said the department generally prefers the safe-harbor approach that removes all 18 identifiers.
The presentation spelled out potential penalties for noncompliance: “These violations can range from a $100 to $1,500,000” in civil fines, Coolidge said, and noted there are also criminal penalties in the most serious cases. Commissioners were urged to avoid sharing PHI on unsecured platforms and to route member issues to member services where city infrastructure provides stronger protections.
When Commissioner Scott asked whether there had been any recent reportable incidents, Coolidge replied there had been none in the past three to four years and that any earlier incidents were over five years old; staff said recent risk assessments found robust protections.
The training closed with practical guidance: use city email systems with encryption, avoid storing PHI on local devices, and contact the privacy officer if members suspect a breach. Commissioners were told they will be enrolled in short online modules covering cybersecurity and privacy.
