1. A health
information exchange shall:
(a) Ensure that
only covered entities with which the health information exchange has entered
into a business associate agreement as described in NAC 439.588 and members of
the workforces, contractors and agents of such covered entities who have a
legitimate need to use the health information exchange are allowed to use the
health information exchange.
(b)
Establish policies and procedures to verify the identity of all persons who
wish to retrieve or disclose the health information of patients using the
health information exchange. The policies and procedures must include, without
limitation:
(1) A process for verifying the
identity and credentials of each person seeking authorization to retrieve or
disclose health information and a registry of authorized users.
(2) Standards and procedures for determining
whether a person is authorized to retrieve or disclose health information using
the health information exchange. These standards and procedures must be based
on the role of the user and must apply to each user of the health information
exchange.
(3) Systems and
procedures for determining whether an authorized user is allowed to retrieve
the health information of a patient and providing a person with health
information that the person is authorized to retrieve.
(c) Adopt and comply with a policy that has
been established by a nationally recognized organization or approved by the
Director for authenticating the identity of all persons retrieving or
disclosing health information using the health information exchange.
(d) Establish procedures to verify that
access to health information on the health information exchange is consistent
with the requirements of NAC 439.576.
(e) Create a record each time health
information is retrieved using the health information exchange and maintain
such records for at least 6 years after the date on which the record is
created.
(f) Ensure that all data
is encrypted and use integrity controls to ensure that data is not altered or
tampered with during storage or transmission.
2. Any person who retrieves or discloses
health information using a health information exchange shall comply with the
policies and procedures adopted by the health information exchange pursuant to
subsection 1.
3. A prescription may
be created, maintained or transmitted using a health information exchange in
accordance with
NRS
639.2353 and any applicable regulations
adopted by the State Board of Pharmacy.
4. As used in this section, "workforce" has
the meaning ascribed to it in 45 C.F.R. § 160.103.
Added to NAC by Dep't of
Health & Human Services by R056-16, eff.
9-21-2017