PROTECT YOUR DNA WITH QUANTUM TECHNOLOGY
Orgo-Life the new way to the future Advertising by AdpathwayAs the U.S. Consumer Product Safety Commission (CPSC) seeks expanded access to identifiable emergency department patient records, Melissa Soliz, a partner at Coppersmith Brockelman, explains the legal, privacy, and compliance issues healthcare organizations should consider before responding ID 179343487 © Josepalbert13 | Dreamstime.com CPSC's Push for Patient Data Raises Privacy and Legal Questions The U.S. Consumer Product Safety Commission (CPSC) is asking several of the nation's largest health systems to provide identifiable medical records for every patient treated in their emergency departments (EDs) as part of a major overhaul of its injury surveillance efforts. On July 22, the federal agency announced a significant modernization of the National Electronic Injury Surveillance System (NEISS), the nation's primary system for tracking consumer product-related injuries. The updated initiative expands the data the agency is seeking from participating hospitals, including identifiable patient information. The move raises important legal and privacy questions: Does the CPSC have the authority to collect this information, and what safeguards are in place to protect patients’ sensitive health data? To learn more, Healthcare Innovation spoke with Melissa Soliz, an attorney and partner specializing in Health Data Privacy, Interoperability, and Technology at Phoenix-based Coppersmith Brockelman PLC. Melissa Soliz, an attorney and partner specializing in Health Data Privacy, Interoperability, and Technology at Phoenix-based Coppersmith Brockelman PLC. When you modernize your injury surveillance system, Soliz notes, that doesn't eliminate the need to follow required processes, minimize data collection, and clearly define who can use identifiable data and information for what purpose. “I think that is what's really sparked some of the concerns about the CPSC's recent proposals.” “What it looks like is that they're trying to get a larger set of identifiable emergency department data,” Soliz explains, “and maybe aren't being particularly clear on the legal authority for asking for an increased amount of data.” CPSC is charged with protecting the public from unreasonable risks of injury and death related to consumer products, and there are over 15,000 types of consumer products, Soliz says. “My understanding is that some of the information that's being asked for isn't directly related necessarily to those consumer products.” However, the data could be used for legitimate public health purposes, Soliz adds. “When a public health authority asks a hospital or healthcare provider for data, there are lots of different pathways under HIPAA and state laws that allow for that,” Soliz explains. “You can provide a de-identified data set under HIPAA…and there is a HIPAA data use agreement that strictly limits how that data can be used and redisclosed for that public health purpose….We also have the public health authority pathway, where if it is authorized by law and subject to minimum necessary standard requirements, the data can also be disclosed that way.” Soliz underscores that hospitals and providers need to ask the following: What is the law that authorizes me to disclose the data, and why is this the minimum amount necessary? We want to have a good public health surveillance system, Soliz remarks. “A good public health surveillance system depends on public trust…and that in turn depends on collecting no more patient information than the law and the mission generally requires.” A public health surveillance system has a very legitimate value, and I think the provider community recognizes that, Soliz adds. Furthermore, Soliz says, “I wanted to emphasize that a lot of these hospitals or providers are going to end up at different conclusions, in part because they're subject to different laws at the state level….Even though HIPAA might allow for something, there might be a more restrictive state law that impacts the disclosure of the data that they are asking for.” Additionally, “the technical systems might not be in place to segment the data that is subject to those more restrictive state laws from being released in the technical manner that they're asking for.” This is not an easy analysis, Soliz says. “It does involve getting lawyers and compliance professionals involved because there's a lot of complexity with the legal landscape, and it's going to drive different answers.” You need to evaluate these proposed arrangements carefully and look for not only HIPAA-compliant but also state law-compliant pathways “This is definitely an evolving issue, Soliz says. “The compliance analysis is really going to depend on what's being requested, why it's being requested, the authority under which it's being requested, and the laws that are applicable to each of the data supplying organizations.” For providers, Soliz says, the right approach is not to assume that a request is prohibited or that compliance is automatically required. “You need to evaluate these proposed arrangements carefully and look for not only HIPAA-compliant but also state law-compliant pathways that also comply with interoperability laws.” Pietje Kobus-McAllister has an international background and experience in content management and editing. She studied journalism in the Netherlands and Communications and Creative Nonfiction in the U.S. Pietje joined Healthcare Innovation in January 2024.

About the Author

Pietje Kobus-McAllister

.jpg)











English (US) ·