HIPAA Core Policy: Use & Disclosure of Health Information for Fundraising   

 

 

Abstract: 
This policy establishes guidelines for the use and disclosure of health information for purposes of fundraising by UAB/UABHS Covered Entities in compliance with the Health Insurance Portability and Accountability Act (HIPAA) and Alabama state law.

Effective Date: 01/09/04

 

Review/Revised Date: 5/26/2022

 

Category: Ethics and Integrity

 

Policy Owner: Provost

Policy Contact: Chief Privacy Officer

 

   
 
 
1. PURPOSE: To ensure that UAB covered entities implement and maintain policies for the use and disclosure of health information for purposes of fundraising in compliance with the Health Insurance Portability and Accountability Act (“HIPAA”) and Alabama state law.

2. PHILOSOPHY: UAB values and promotes business practices respecting the confidentiality of health information.

3. APPLICABILITY: This policy applies to all UAB Covered Entities (School of Dentistry, School of Health Professions, School of Medicine, School of Nursing, School of Optometry, Joint Health Sciences Departments, School of Education Community Clinic, UAB Health Plans, and other UAB entities that may be added from time-to-time) and to the following UAB Medicine Enterprise Covered Entities: UAB Hospital, The Kirklin Clinic of UAB Hospital, The Kirklin Clinic of UAB Hospital at Acton Road, The Whitaker Clinic of UAB Hospital, UAB Callahan Eye Hospital Authority and Callahan Eye Hospital Clinics, UAB Health Centers, Medical West Hospital Authority, an Affiliate of UAB Health System, Triton Health Systems, LLC, VIVA Health, Inc., the University of Alabama Health Services Foundation, P.C., Ophthalmology Services Foundation, P.C., and Valley Foundation. For purposes of this policy, UAB and UAB Medicine Enterprise Covered Entities shall be collectively referred to as “UAB.”
 
4. DEFINITIONS: UAB adopts the definitions set forth in the HIPAA regulations at 45 CFR Parts 160, 162, and 164.  The following definitions are relevant to this policy:

Disclosure: The release, transfer, provision of, access to, or divulging in any other manner of information outside the UAB Covered Entity holding the information.

Protected Health Information (PHI): Health information, including demographic information collected from an individual and created or received by a health provider, health plan, employer or health care clearinghouse that relates to the past, present, or future physical or mental health or condition of any individual; the provision of health care to an individual; or the past, present, or future payment for the provision of health care to an individual, and that identifies an individual or there is a reasonable basis to believe the information can be used to identify the individual and that is transmitted or maintained by electronic media or any other form or medium. PHI does not include individually identifiable health information in education records covered and excepted by the Family Educational Right and Privacy Act and employment records held by a covered entity in its role as an employer.

Use: The sharing, employment, application, utilization, examination, or analysis of PHI within the UAB Covered Entity that maintains the PHI. 

5. POLICY STATEMENTS: 

A. Use and Disclosure of PHI for Fundraising

  1. Unless a signed authorization for fundraising purposes has been obtained from the individual, UAB will limit PHI used by UAB or disclosed to a business associate or institutionally related foundation to the following:
    1. Demographic information of an individual, including name, address, other contact information, age, gender, and date of birth
    2. Dates of health care provided to an individual
    3. Department of service information
    4. Treating physician
    5. Outcome information
    6. Health insurance status
  2. The above information can be used or disclosed for fundraising purposes if the Notice of Health Information Practices of the appropriate UAB covered entity informs individuals that they may be contacted for purposes of fundraising and that they have the right to opt out of such communications.
  3. Use of any other PHI requires a signed Authorization from the individual.
  4. The PHI used or disclosed for fundraising purposes must be limited to the minimum necessary information needed to complete the fundraising project.
  5. UAB Covered Entities may use PHI for fundraising only with respect to the patients they treat.
  6. All fundraising involving PHI must be coordinated and communicated by the UAB Office of Advancement or the individual Director of Development/Major Gift Officer assigned to the UAB Covered Entity.

B. Patient Right to Opt Out

  1. Individuals have the right to request not to receive fundraising requests or materials.
  2. All UAB fundraising materials sent to individuals must include a description of how the individual may opt out of receiving any further fundraising communications.
    1. UAB will allow individuals to opt out by furnishing an address, email address, or phone number they can use to opt out of fundraising.
    2. The UAB Office of Advancement will maintain a procedure for managing this opt out requirement and a current list of individuals opting out of receiving fundraising communications. UAB Covered Entities must check with this office prior to sending fundraising communications.
    3. Patients who have opted out of the opportunity to receive fundraising communications may opt back in by methods designated by the UAB Office of Advancement.
  3. UAB will not condition treatment to a patient or payment for care of an individual on whether or not the individual has exercised his/her right to opt out of receiving fundraising communications.

C. Each UAB Covered Entity shall develop procedures to implement this policy.
 
6. REFERENCES: None

7. SCOPE: This policy applies to all UAB Covered Entities and to UAB Medicine Enterprise Covered Entities identified in Section 3.

8. ATTACHMENT: Note: HIPAA forms may be found at the UAB/UAB Medicine Enterprise HIPAA website at www.HIPAA.uab.edu.  


To view HIPAA Core Policies and for more information, please visit the HIPAA Website