What is my Protected Health Information (PHI)?
“PHI” is any information that identifies you and relates to health care services, the payment of health care services, or your past, present, or future physical or mental health condition. PHI may be spoken, written, or electronically recorded.
How, why, and with whom is my PHI used or shared within and outside of Netcare?
Your PHI may be used and shared both inside and outside of Netcare for treatment, payment, and operations purposes. In some cases, your authorization is needed to do this.
Your PHI may also be used or shared externally for purposes other than treatment, payment, or operations. Unless required or permitted by law, we must obtain your authorization to use or disclose your PHI for these purposes.
Netcare will disclose the minimum information necessary to meet the stated purpose without your authorization.
Netcare participates in one or more Health Information Exchanges. Your healthcare providers can use this electronic network to securely provide access to your health records for a better picture of your health needs. We, and other healthcare providers, may allow access to your health information through the Health Information Exchange for treatment, payment or other healthcare operations. You may opt-out of the Health Information Exchange at any time by notifying Netcare’s Medical Record Department.
Disclosures for Treatment:
We may use and disclose your PHI to coordinate or manage your care within Netcare and with individuals or organizations outside of Netcare that are involved in your care, such as other health care professionals, hospitals, and related organizations. For example, certain service providers including hospitals and ambulance companies may need information about your medical/psychiatric condition in order to deliver services properly when medical treatment or inpatient psychiatric hospitalization is required.
Except for emergency treatment purposes or if you lack the capacity to authorize disclosure, information about alcohol and drug diagnoses, treatment, or referral cannot be disclosed for treatment purposes without your written authorization.
Disclosures for Payment:
Netcare staff will use your PHI for billing and payment purposes. We may also disclose information that is necessary to be paid for mental health services to persons or organizations outside of Netcare even if you do not authorize disclosure. This includes disclosure to third party payers such as the ADAMH Board who need information to determine you are eligible to have your services paid by them and to process payments.
Netcare cannot disclose information necessary to be paid for Substance Use Disorder (“SUD”) services without your authorization.
Disclosures for Health Care Operations:
Within Netcare, staff performing certain administrative functions necessary to operate the organization and support the delivery of services, such as medical records management and quality improvement activities, may use your PHI. This includes review of records to evaluate the quality of services you received and to investigate any problems or concerns identified so that these may be corrected and/or improved.
Staff of other governmental or healthcare oversight agencies may review your PHI to audit and evaluate Netcare to assure our compliance with their requirements. We may also disclose information to these organizations as mandated for planning, evaluation, and other activities in order to better serve all of our clients.
With limited exceptions, information about alcohol and drug diagnoses, treatment, or referral cannot be disclosed for health care operations purposes without your written authorization.
Other Uses and Disclosures of PHI
We may use artificial intelligence (AI) tools to support and enhance the quality and efficiency of your care, such as for scheduling, documentation or data analysis. We have adopted safeguards to protect your PHI used in conjunction with any AI tool, and any such use will comply with applicable privacy and security standards. All decisions regarding your diagnosis and treatment will always be made by a qualified, licensed clinician using their independent clinical judgment. Any use of AI tools supports our licensed healthcare providers but does not replace their expertise and judgment.
When and to whom can my PHI be used or disclosed without my authorization?
- When permitted or required by Federal, State, or local law.
- In event of a medical or psychiatric emergency.
- To prevent or lessen what we believe, in good faith, to be a serious and imminent threat to you, another person, or the public.
- When there are risks to public health, such as to prevent or control disease, injury or disability; to report disease, injury, and vital events such as death; or to notify someone who has been exposed to a communicable disease or who may be at risk of contracting or spreading a disease.
- To protect victims of abuse or neglect.
- For judicial, administrative, and law enforcement purposes as permitted or required by law.
- To report crimes against our staff or premises.
- When ordered by the court to do so.
- To funeral directors, medical examiners, and coroners to carry out their duties consistent with applicable law.
- To Disability Rights Ohio investigating suspected abuse or neglect or complaints by persons receiving mental health services.
- To the ADAMH1 board or other agency if Netcare closes and transfers its caseload.
- To OhioMHAS2 and/or the ADAMH board if you are in a state hospital or facility and receiving Netcare’s services.
- To the ADAMH Board and/or other agencies if you are involuntarily committed to the ADAMH Board.
- To organizations with the legal authority to audit Netcare, or to plan and evaluate services.
- For healthcare oversight activities including audits, inspections, licensure, civil administrative or criminal investigations where you are not the subject of the investigation, or disciplinary action.
- To business associates performing duties for or on behalf of Netcare, e.g., document imaging companies.
- If we inform you in advance and if you don’t object, we may disclose a limited amount of information directly related to your care or payment for care to family, friends, or those involved in your care.
- If you are unavailable, or if you are unable to agree or object due to incapacity or emergency, we may disclose a limited amount of information directly related to your care, location, condition or death to family, friends, or those involved in your care or payment for care if in our professional judgment it is in your best interest to do so.
- Other disclosures as permitted by relevant sections of 45 CFR 164 (HIPAA Privacy Rule).
- All disclosures of information regarding alcohol and drug diagnoses, treatment or referral are subject to 42 CFR Part 2 which may prohibit or limit disclosures of PHI without your authorization. See Confidentiality of Substance Use Disorder (“SUD”) Records below.
1 “ADAMH” means Alcohol, Drug Addiction, and Mental Health Services board.
2 “OhioMHAS” means the Ohio Department of Mental Health and Addiction Services.
Under what circumstances must I authorize the use and disclosure of my PHI?
Unless otherwise stated in this notice, you must authorize use and disclosure of your PHI before we can disclose it. For example, we may not sell your PHI, or disclose your PHI for certain marketing purposes, without your authorization.
Can I revoke my authorization?
Yes. In order to revoke your authorization, you must do so verbally or in writing so that we can stop sharing your PHI. However, we cannot take back anything that has already been shared.
CONFIDENTIALITY OF SUBSTANCE USE DISORDER (SUD) RECORDS
Some of your health information may be protected by federal law under 42 C.F.R. Part 2, which provides additional privacy protections for records related to substance use disorder (SUD) diagnosis, treatment, and referral services (“SUD Information”) These protections apply in addition to HIPAA. We will only use and disclose your SUD Information as described in this section or with your written consent.
Permitted Uses and Disclosures of SUD Information Without Consent
• To communicate among our clinicians and staff who have a need for the information in connection with their duties to provide diagnosis, treatment, or referral for treatment when the communications are (i) within Netcare or (ii) related to the administration of Netcare.
• To qualified service organizations providing services on our behalf, who agree in writing to protect the SUD information in the same way that we are required to protect the SUD Information.
• To law enforcement agencies or officials if you commit, or threaten to commit, a crime in our facilities or against our personnel.
• To report suspected child abuse and neglect consistent with Ohio law.
• To other medical personnel in a medical emergency under certain conditions.
• For research purposes consistent with approval of an Institutional Review Board (“IRB”).
• To qualified personnel for audit or program evaluation purposes who have agreed to protect the SUD Information.
• To a public health authority, if the SUD Information has been de-identified.
Uses and Disclosures of SUD Information that Require Consent
• For treatment, payment, and health care operations purposes. You may provide us with a single consent for all future uses or disclosures for treatment, payment, and healthcare operations purposes in order to ensure you receive the highest level of coordinated care. Once your SUD Information is disclosed to a HIPAA Covered Entity (such as another health care provider or a health insurance company) or a business associate (companies that provide services on behalf of HIPAA Covered Entities), the recipient may use or disclose your information for treatment, payment and healthcare operations purposes to the extent permitted by HIPAA. See examples of treatment, payment and healthcare operations above.
• To a central registry or to any withdrawal management or maintenance treatment program not more than 200 miles away for the purpose of preventing multiple enrollments with certain limitations.
• Certain information regarding medications prescribed or dispensed to the state prescription drug monitoring program if required by applicable state law.
• Certain information to those persons within the criminal justice system who have made participation in a Netcare SUD treatment program as a condition of the disposition of any criminal proceedings against the patient or of the patient’s parole or of other release from custody requirements, with certain limitations.
Additional Provisions Regarding SUD Information
• SUD Information, or testimony that describes the SUD Information, will not be used or disclosed by us in any civil, criminal, administrative, or legislative proceedings against you, unless authorized by your consent or by a court order after notice and an opportunity to be heard is provided and the court order is accompanied by a subpoena or other legal requirement compelling disclosure in compliance with the requirements of 42 C.F.R. Part 2.
• SUD Information will not be used or disclosed for fundraising purposes unless you are provided with a clear and conspicuous notice and opportunity to elect not to receive any fundraising communications.
· Generally, SUD counseling notes may only be used or disclosed with your specific written consent.
• Unless otherwise restricted in this Section or as modified below, all other provisions of this Notice, including, but not limited to the rights described below, apply to SUD Information
You have the following rights regarding your PHI:
To authorize the use and disclosure of your PHI for purposes other than those uses and disclosures permitted or required by law.
To review and receive information from your clinical record unless there are clear treatment reasons or other reasons specified by law for you to not get this. Requests for records must be in writing. Please allow 30 days for Netcare to respond. We may charge a reasonable fee for processing your request. Please contact our medical records department to arrange this.
To request that we amend your PHI, if you believe that your PHI is incorrect or incomplete. Requests for amendments must be in writing and include a reason to support the requested amendment. We do not have to agree to your request for amendment. If approved, we will include your written statement in your record; however, we cannot change, deface or destroy any information already contained in your record.
To request restrictions on how we use and disclose your PHI. You may request a limit on our disclosure of PHI to someone who is involved in your care or the payment of your care. We do not have to agree to your restrictions, except when it involves disclosures to health plans when you have paid for the services yourself. If we do agree, we must follow your restrictions until you tell us otherwise, except for emergency treatment purposes.
To request that we communicate with you in a confidential manner, for example, with no other family members present. You also have the right to request that we send confidential communications of PHI to alternative locations or by alternative means provided it is reasonable and possible for us to do.
To identify persons to us who may serve as your authorized personal representative, such as court-appointed guardian, a properly executed and specific power of attorney granting such authority, a Durable Power of Attorney for Health Care if it allows the person to act even if you are able to communicate on your own, or other method recognized by applicable law. We may, however, reject a representative if, in our professional judgment, we determine that it is not in your best interest.
To receive a list of certain disclosures of your PHI. You can request disclosures going back as far as 6 years. We will respond to your written request within 60 days. We may charge a reasonable fee for the costs of processing your request.
To receive a paper copy of the Netcare Notice of Privacy Practices. We may change the terms of this Privacy Notice at any time. We will also post the current notice in our waiting areas.
What will you do to protect my health information?
Netcare is required by law to protect the privacy of your PHI. We are required to notify you in the event of a breach of unsecured PHI. We are also required to provide this notice to you, and to abide by the terms of the notice currently in effect. Netcare reserves the right to change the terms of this notice. If we do, it will affect all PHI maintained by us. Material changes will not be implemented before the effective date of the new notice unless required by law. We will notify you by posting the notice in our offices either on the day of or after the effective date of the changes.