Standard for HIPAA Accounting of Disclosures
Purpose
Upon request, Ohio University will provide an individual with an accounting of disclosures of Protected Health Information (PHI).
Scope
This standard will apply to all Ohio University HIPAA Covered Entities.
Standard
- Ohio University will provide an individual with a written accounting of the disclosures of PHI that occurred during the six (6) years prior to the date of the request for accounting, including disclosures to or by OU’s business associates.
- Ohio University’s accounting will include the following:
- Date of disclosure;
- The name of the entity or person who received the PHI
- A brief description of the PHI disclosed; and
- A brief statement of the purpose of the disclosure.
- Ohio University will respond to an individual’s request for accounting within sixty (60) days of the request unless Ohio University requests a thirty (30)-day extension. Such requests for extensions will be done in writing.
- Ohio University will provide the first accounting requested by any individual in a twelve (12)-month period without charge. Ohio University will charge a reasonable, cost-based fee for any subsequent request(s) within the twelve (12)-month period.
- Ohio University will document the following:
- The information required to be included in an accounting for disclosures of PHI;
- The written accounting that is provided to any individual; and
- The titles of the persons or offices responsible for receiving and processing requests for an accounting.
- The individual’s right to an accounting of disclosures does not apply to the following types of disclosures:
- To carry out treatment, payment, and health care operations;
- To individuals of PHI about them;
- Incident to a use or disclosure otherwise permitted or required;
- Pursuant to an authorization;
- To persons involved in the individual’s care or for notification purposes;
- For national security or intelligence purposes;
- To correctional institutions or law enforcement officials; or
- That occurred prior to 6 years from the date of the request
Governance
This standard will be reviewed and approved by the University HIPAA Steering Committee, and other key stakeholders in the interest of ensuring the privacy and security of individual’s health information, as deemed appropriate based on the current regulatory requirement mandates.
Status: Approved
Effective: September 24, 2019