Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« "Trustworthy" Scammers & Checking Website Before Doing Business With Them | Main | FTC Pretexting Report: All Businesses are Obligated to Protect Consumer Data Under Multiple Federal Regulations »

HIPAA, FERPA and Lawsuits

Yesterday the news report following my commentary was published.

It doesn't say what the sensitive information was, but makes clear that often times the wrong law is used to pursue wrongful disclosure of personal information.  HIPAA (the Privacy Rule and the Security Rule) tends to be foremost in most people's minds when privacy infractions occur because it is written about so often.  However, as the article points out, it only applies to covered entities (CEs). 

Unfortunately the discussion given to the television station is misleading.  The list provided is incomplete in that some organizations not in the list are considered hybrid entities; those whose primary business is not being a healthcare provider or healthcare insurer, but have portions of their business that do those type of activities.  Some educational institutions certainly are hybrid entities; simplistically those who provide health clinic services with the medical staff providing the care on their payroll.

It is good whenever considering privacy issues and regulatory noncompliance related to the protection of personally identifiable information (PII) within educational institutions to keep FERPA in the foremost of your considerations.

However, it *IS* possible that inappropriate sharing of PII can be covered by more than one regulation; and certainly, depending upon the details and involved issues, a situation where student PII is inappropriately shared with others could come under both FERPA and HIPAA.  It is important to discuss any situation with a lawyer well-versed in the data protection laws and regulations to determine which one to use when pursuing legal action.

"A Grove mother who's suing the school district on behalf of her 15 year-old son says an administrator told her sensitive information about another student.

Specific medical information that she says, he had no right to reveal.

Sheila Dawson's lawsuit alleges Grove school faculty and administrators violated the Health Insurance Portability and Accountability Act or HIPAA, when they told others medical facts and lies about her son and other students.

The News on 6 spoke with a HIPAA expert and learned that "the act" only protects healthcare providers, healthcare clearing houses and others who bill electronically for medical services. Elise Brennan says if the information comes from anywhere else, it's not protected under HIPAA. "HIPAA doesn't pertain to idle gossip. If an employer or the school has learned information from gossip, then that's not protected health information, which is what's covered under HIPAA."

The US Department of Education points to the Family Education Right to Privacy Act, which prohibits schools from disclosing a student's records without parental consent.

If a school has medical information about a student, it becomes part of the education record and is protected under FERPA."

Technorati Tags







TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/192

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.