zlacker

[parent] [thread] 1 comments
1. halduj+(OP)[view] [source] 2023-08-07 02:36:25
One note is that the act of deidentification itself requires accessing PHI when done retroactively, this may be institutional policy or specific to covered entities but per the privacy office lawyers such access (apart from a small dataset) requires a permitted use to be accessible in order to then deidentify and use freely.

As with all things HIPAA, this only becomes a problem when HHS starts looking and I’m sure in practice many people ignore this tidbit (if in fact this is the law and not Stanford policy).

replies(1): >>johndh+HO1
2. johndh+HO1[view] [source] 2023-08-07 16:10:54
>>halduj+(OP)
This is correct -- the covered entity can de-identify data, or ask the BA to de-identify data. If the BAA says the BA can, then they can.
[go to top]