Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« Privacy Initiatives Sincere Or Marketing Ploy? | Main | Compliance and Information Security: Common Sense Confirmed »

Confusing Folks: PHR, PHI, PII, NPPI, and Dozens of Other Acronyms...It's Still All Personal Information

I really enjoy reading survey results. I can't help myself. Whether the surveys are well-done, sloppy, long, short, statistically accurate or obviously statistically invalid, I still find them interesting. Especially when they cover what the general public and non-IT/non-infosec person thinks or knows about information security and privacy, or some industry-specific issue.

Last week Aetna and the Financial Planning Association released the results of a survey seeking to find out more about what adults know about their healthcare records.

"An estimated 70 million people have access to basic Personal Health Records (PHRs) – password-protected, online records that store essential health information – through their health insurers, with millions more scheduled to receive the service this year. But when Aetna (NYSE:AET) and the Financial Planning Association® (FPA®) surveyed more than 2,100 adults 18 and older, 64 percent said they do not know or are unsure about what a PHR is. Among the group of Americans who are familiar with PHRs, 83 percent acknowledge that the online record personalizes their experience with their health care provider, but only 11 percent currently use one to keep track of their medical and health history."

Okay, why is yet another abbreviation being used to describe what, essentially, is also called Electronic Protected Health Information (E-PHI) by the Health Insurance Portability and Accountability Act (HIPAA)? Yes, I know there are some differences in what is contained within PHRs, but the point is all these acronyms confuse the heck out of people to the point they just don't even try to know or understand them any more.

The HIPAA Privacy Rule describes and covers all types of PHI, and the HIPAA Security Rule describes and covers PHI only in electronic form.

Geesh, talk about confusing to most folks! Not to mention the covered entities (CEs) that must comply with them.

And each of the other laws addressing privacy and data protection have another term to reference personally identifiable information (PII), including "PII" (the term I like the most) in some of them.

Is it no wonder 64% of the public don't know what PHR is? In fact I'm surprised it's not higher.

It would help the understanding of the public to harmonize the definition of PII across all the federal and state laws so that people don't have to keep track of all the different labels. Well, the chances of this happening are less than seeing pigs sprouting wings and flying.

Okay, going beyond the terminology issue and assuming the survey described what a PHR is, what about the other findings?

"Survey Highlights:

-- When asked why they didn't use a PHR, respondents had varying reasons, indicating a need for education:

-- Have their own system for maintaining records (35 percent)

-- Concerned with the security of personal information (26 percent)

-- Don't know how to use and manage a PHR (18 percent)

-- Even those surveyed who are familiar with PHRs may not realize essential
health information is at their fingertips. Surprisingly,
fewer than one in 10 would turn to a PHR to access health
information if displaced during a natural disaster. The majority
of respondents would contact their physician (64 percent) or
insurance company (16 percent) or say they do not know where they
would find vaccination records, recent test results and their
blood type (16 percent).

-- More than half (55 percent) of the women surveyed keep track of
their medical and health history, but not through a PHR. By
comparison, only 39 percent of men keep track of their medical and
health history and 44 percent don't keep track at all."

What this survey does demonstrate is the need for all organizations, no matter in what industry, to provide a way for individuals to be able to access their PII, be able to review it, and give them the ability to request corrections. This is a basic privacy principle of most non-US data protection laws, which are almost all built around the Organization for Economic Cooperation and Development (OECD) privacy principles.

Organizations will find that if they give individuals access to their corresponding PII and allow them the ability to correct mistakes within it, they will have much more accurate records, and as a result can make better business decisions with that data. Currently incorrect PII is perpetuated and shared, causing many problems for not only the individuals but also the businesses.

And, not only will data be more accurate, customers will be happier knowing the organizations with whom they do business are giving them access to their PII. This is a very good way to retain customers and attract new customers.

"In light of these findings, Aetna and FPA have expanded the Plan for Your Health public education campaign by introducing PHR information on www.PlanforYourHealth.com to help Americans use PHRs to manage their personal health data and ultimately play a more active role in their health care. The site features tips on maximizing and personalizing a PHR and top reasons to use the online record."

Have you looked at your PHR? If you're in a healthcare organization, do you know if your organization has a process in place to allow individuals access to their PII/PHR/whatever-acronym-you-use?

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/470

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.