Ohio Administrative Code
Title 3364 - University of Toledo
Chapter 3364-90 - Guidelines for Protected Health Information
Section 3364-90-05 - De-identifiable and re-identifiable health information, limited data set and data use agreements
Current through all regulations passed and filed through September 16, 2024
(A) Policy statement
The health insurance portability and accountability act of 1996 "HIPAA" permits disclosure of protected health information "PHI" that does not identify an individual and with respect to which there is no reasonable basis to believe that the information can be used to identify an individual when removing identifiers from the data. A code may be assigned or other means of record identification to allow information de-identified to be re-identified. Limited data sets may be disclosed in accordance with a data use agreement for the purposes of approved research, education, public health or health care operations.
(B) Purpose of policy
To assure that PHI is properly de-identified when used without patient authorization or re-identified as required in HIPAA, C.F.R. 164.514.
(C) Procedure
Requires that a person with appropriate knowledge and experience of generally accepted statistical methods for rendering information not individually identifiable apply those methods or principles and determine that the risk is very small that the information could be used, alone or in combination with other reasonably available information by an anticipated recipient to identify an individual who is the subject of the information. The expert must document the methods used and the results of the analysis.
Information may be re-identified, by a code or other means of record identification to allow information to be re-identified, provided that the code or other means of record identification is not derived from or related to information about the individual and is not otherwise capable of being translated to identify the individual. The code may not be used or disclosed for any other purpose and must remain with the covered entity. The mechanism for re-identification may not be disclosed.
Limited data requires that all of the following PHI identifiers be removed:
All recipients of limited data sets must enter into a data use agreement unless the recipient has entered into a business associate agreement. Disclosure of limited data must be done in conjunction with a data use agreement. There must be satisfactory assurances, in the form of a data use agreement, that the limited data set recipient will only use or disclose the protected health information for limited purposes. Data use agreements must be approved by the office of legal affairs. The university of Toledo institutional review board "IRB" must approve data use agreements for disclosure of PHI within the designated record set for research purposes. The data use agreement must: