{"id":752,"date":"2018-05-07T06:44:29","date_gmt":"2018-05-07T06:44:29","guid":{"rendered":"https:\/\/az.research.umich.edu\/medschool\/document\/uses-disclosures-protected-health-information-phi\/"},"modified":"2026-04-15T09:07:32","modified_gmt":"2026-04-15T13:07:32","slug":"uses-disclosures-protected-health-information-phi","status":"publish","type":"document","link":"https:\/\/az.research.umich.edu\/medschool\/guidance\/uses-disclosures-protected-health-information-phi\/","title":{"rendered":"Uses &amp; Disclosures of Protected Health Information (PHI)"},"template":"","categories":[24],"tags":[],"content-type":[41],"topic":[45,75],"update-type":[],"class_list":["post-752","document","type-document","status-publish","hentry","category-institutional-review-boards-irbmed","content-type-guidance","topic-hipaa-protected-health-information","topic-regulations-policies-federal-state-local"],"acf":{"use_legacy_editor":true,"updated_date":"2020-08-10 14:30:00","update_notice":false,"author":"IRBMED","summary":"<a class=\"gtip\" href=\"https:\/\/az.research.umich.edu\/medschool\/glossary\/protected-health-information-phi\/\">Protected Health Information (PHI)<\/a>\u00a0is <a class=\"gtip\" href=\"\/medschool\/glossary\/individually-identifiable-health-information\">individually identifiable health information<\/a> held or maintained by\u00a0<a class=\"gtip\" href=\"\/medschool\/glossary\/covered-entity\">covered entities<\/a>, or by business associates acting for the covered entity. PHI is subject to\u00a0<a href=\"https:\/\/privacyruleandresearch.nih.gov\/pr_07.asp\">HIPAA Privacy Rule<\/a>\u00a0protections.\u00a0<strong>HIPAA\u00a0Privacy Rule permits researchers to access and use PHI when necessary to conduct research, with certain restrictions.<\/strong>","button_links":null,"related_content":[744,745,764,725,877],"legacy_path":"uses-disclosures-protected-health-information-phi","legacy_node_id":293,"legacy_related_nids":"284, 285, 306, 248, 1026","legacy_content_section":[{"legacy_section_type":"heading","legacy_heading":"Definitions - Use and Disclosure","legacy_subheading":"","legacy_section_text":"","legacy_media_position":"","legacy_media_file":"","legacy_media_url":"","legacy_glossary_term":"","legacy_glossary_nids":"","legacy_resource":"","legacy_resource_nids":"","legacy_buttons":null},{"legacy_section_type":"text_area","legacy_heading":"","legacy_subheading":"","legacy_section_text":"\"Use\" has a HIPAA-specific technical definition:\r\n\r\n<strong><em>Use<\/em> means,<\/strong> with respect to individually identifiable health information, the sharing, employment, application, utilization, examination, or analysis of such information <strong>within [a <a href=\"\/medschool\/glossary\/covered-entity\"><em>covered] entity<\/em><\/a> that maintains such information<\/strong>. (45CFR160.103)\r\n\r\nFor example:\r\n<ul>\r\n \t<li><u>clinical<\/u>: desk staff at an outpatient clinic prints check-in materials for a patient<\/li>\r\n \t<li><u>research - interventional<\/u>: in an investigator-initiated clinical trial, lab results on the metabolism of the investigational agent are also entered into the medical record<\/li>\r\n \t<li><u>research - chart review<\/u>: medical faculty obtain a dataset for analysis through the <a href=\"https:\/\/medresearch.umich.edu\/office-research\/about-office-research\/our-units\/data-office-clinical-translational-research\/self-serve-data-tools\">DataDirect PHI<\/a> portal<\/li>\r\n<\/ul>\r\n\"Disclosure\"\u00a0 has a HIPAA-specific technical definition:\r\n\r\n<strong><em>Disclosure <\/em>means the release<\/strong>, transfer, provision of access to, or divulging in any manner of information <strong>outside the <a href=\"\/medschool\/glossary\/covered-entity\"><em>[covered] entity<\/em><\/a> holding the information<\/strong>. (45CFR160.103)\r\n\r\nFor example:\r\n<ul>\r\n \t<li><u>clinical<\/u>: patient fills out a <a href=\"https:\/\/www.uofmhealth.org\/patient-visitor-guide\/medical-records\">release of information form<\/a> to request a hard copy of their Michigan Medicine medical record be sent to another location such as a hospital or doctor's office.<\/li>\r\n \t<li><u>research - interventional<\/u>: U-M research staff on an industry-sponsored clinical trial send medical records relating to a screened subject's eligibility to the sponsor<\/li>\r\n \t<li><u>research - chart review<\/u>: <a href=\"https:\/\/az.research.umich.edu\/medschool\/policies\/statement-practice-hipaa-and-u-m-study-team-members-outside-michigan-medicine\/\">U-M LSA faculty, staff, or students<\/a> (e.g. UROP) access PHI (usually as part of a study team mostly comprising people from Michigan Medicine)<\/li>\r\n \t<li><u>research - chart review<\/u>: A data coordinating center site receives \"<a href=\"\/medschool\/guidance\/limited-data-sets\">limited data sets<\/a>\" from all sites for a multi-institutional retrospective analysis of clinical data.<\/li>\r\n<\/ul>","legacy_media_position":"","legacy_media_file":"","legacy_media_url":"","legacy_glossary_term":"","legacy_glossary_nids":"","legacy_resource":"","legacy_resource_nids":"","legacy_buttons":null},{"legacy_section_type":"heading","legacy_heading":"Michigan Medicine Covered Entity (CE)","legacy_subheading":"","legacy_section_text":"","legacy_media_position":"","legacy_media_file":"","legacy_media_url":"","legacy_glossary_term":"","legacy_glossary_nids":"","legacy_resource":"","legacy_resource_nids":"","legacy_buttons":null},{"legacy_section_type":"text_area","legacy_heading":"","legacy_subheading":"","legacy_section_text":"A <a class=\"gtip\" href=\"\/medschool\/glossary\/covered-entity\">covered entity (CE) <\/a>is a <em>health care provider, health plan, or health care clearinghouse regulated by <a href=\"https:\/\/www.hhs.gov\/hipaa\/index.html\">HIPAA<\/a><\/em>. The University of Michigan is a \"hybrid\" covered entity because <strong>some <\/strong>of its units are regulated by HIPAA. Interdisciplinary study teams at U-M may include members both 'inside' and 'outside' the CE: when protected health information (PHI) is accessed, obtained, analyzed etc. by such study teams, then PHI is <em>disclosed <\/em>during the study. <a href=\"https:\/\/umhealth.sharepoint.com\/sites\/Corporate-Compliance\">Michigan Medicine Corporate Compliance Office<\/a> <em>(requires level-2 login) <\/em>provides information \u00a0on <a href=\"https:\/\/umhealth.sharepoint.com\/sites\/Corporate-Compliance\/SitePages\/The-University-of-Michigan-HIPAA-Hybrid-Covered-Entity.aspx\">Michigan Medicine 'hybrid covered entity'<\/a>. The graphic below in this section (prepared by Compliance Office) shows that PHI crosses a \"PHI Privacy Barrier\" when a covered component discloses the PHI for clinical, research or other purposes.\r\n\r\nU-M hospital, health centers, and medical school are the main components of the Michigan Medicine CE. Additional health care center components are the <a href=\"http:\/\/www.dent.umich.edu\/\">School of Dentistry<\/a> Provider Clinics, Mary A. Rackham (MARI) Institute Provider Clinics, University Health Service, and the U-M Group Health Plan. Generally, faculty and staff (including research staff) in these components handle PHI as part of their jobs, and they are required annually to complete a <a href=\"https:\/\/umhealth.sharepoint.com\/sites\/Corporate-Compliance\/SitePages\/HIPAA-Training.aspx\">HIPAA training module<\/a> from the <a href=\"https:\/\/umhealth.sharepoint.com\/sites\/Corporate-Compliance\">Corporate Compliance Office<\/a>.\r\n\r\nAdditional units at U-M provide \"covered functions\" for components of the covered entity, supporting the covered entity <em>in its primary functions of treatment, payment and operations (TPO)<\/em>. Faculty and staff from these units who also have hospital or health center responsibilities usually have professional appointments at a U-M 'School' and at UMHS \u2014 for instance, School of Pharmacy faculty often also have 'Clinical Pharmacist' appointments.\r\n\r\nAccess or exposure to PHI also arises in educational opportunities and training inside the CE for U-M Medical School students, and students at some other U-M schools (e.g. Schools of Dentistry, Nursing, Pharmacy). However, even within these schools not all roles engage with PHI held by the Michigan Medicine Covered Entity (e.g. administrative staff at <a href=\"\/\/medresearch.umich.edu\/office-research\/about-office-research\/our-units\">Medical School Office of Research<\/a>, and bench scientists).\r\n\r\n<strong>Graphic: Use inside covered components, and Disclosure to other U-M Units (crossing the \"PHI Privacy Barrier\")<\/strong>","legacy_media_position":"","legacy_media_file":"","legacy_media_url":"","legacy_glossary_term":"","legacy_glossary_nids":"","legacy_resource":"","legacy_resource_nids":"","legacy_buttons":null},{"legacy_section_type":"media","legacy_heading":"","legacy_subheading":"","legacy_section_text":"","legacy_media_position":"media-full","legacy_media_file":1448,"legacy_media_url":"https:\/\/az.research.umich.edu\/sites\/default\/files\/media\/embedded\/Hybrid-CE-Graphic-lg.jpg","legacy_glossary_term":"","legacy_glossary_nids":"","legacy_resource":"","legacy_resource_nids":"","legacy_buttons":null},{"legacy_section_type":"heading","legacy_heading":"Research Context For Use and Disclosure","legacy_subheading":"","legacy_section_text":"","legacy_media_position":"","legacy_media_file":"","legacy_media_url":"","legacy_glossary_term":"","legacy_glossary_nids":"","legacy_resource":"","legacy_resource_nids":"","legacy_buttons":null},{"legacy_section_type":"text_area","legacy_heading":"","legacy_subheading":"","legacy_section_text":"<strong>Almost all research under IRBMED oversight involves use and\/or disclosure of PHI.<\/strong> Researchers from other parts of U-M sometimes receive <em>disclosed <\/em>PHI. HIPAA regulations prescribe several provisions under which PHI may be used and\/or disclosed for research. Every use and\/or disclosure must satisfy the criteria under one of these provisions:\r\n<ul>\r\n \t<li><strong>signed authorization from the individual <\/strong>(such as the authorization embedded in <a href=\"\/medschool\/templates\/standard-informed-consent-template\">IRBMED Standard Consent Template<\/a>)<\/li>\r\n \t<li><a href=\"\/medschool\/guidance\/waiver-or-alteration-hipaa-authorization\/\"><strong>waiver of authorization<\/strong><\/a> approved by IRBMED (or, rarely, an external IRB or Privacy Board).<\/li>\r\n \t<li><a href=\"\/medschool\/guidance\/limited-data-sets\"><strong>limited data set<\/strong><\/a> shared under the terms of a <a href=\"https:\/\/medresearch.umich.edu\/office-research\/about-office-research\/our-units\/data-office-clinical-translational-research\/data-biospecimen-sharing\">written data use agreement<\/a><\/li>\r\n \t<li>research on the <a href=\"\/medschool\/guidance\/decedents\/\">protected health information of decedents<\/a> (<strong>deceased individuals<\/strong>)<\/li>\r\n \t<li><a href=\"\/medschool\/guidance\/certification-preparatory-research\"><strong>preparatory to research <\/strong><\/a>activities, such as assessing the feasibility of conducting a study<\/li>\r\n<\/ul>\r\nA research study may utilize several of these HIPAA provisions. For instance, an interventional study may identify eligible subjects under waiver of HIPAA authorization, then obtain signed authorization as part of the enrollment process. A chart review may collect Michigan Medicine MiChart data under waiver of HIPAA authorization, and also receive from external entities \"limited data sets.\"\r\n\r\nImportantly, <strong>some research activities involving PHI must take place inside a covered entity<\/strong> (<em>use<\/em> of PHI, not <em>disclosure<\/em>). Also, researchers are required to keep a record of some <em>disclosures<\/em>, depending on the HIPAA regulatory provision that applies.\r\n<ul>\r\n \t<li><strong>Exemption 4(iii)<\/strong>, <em>aka <\/em>HIPAA Exemption, allows for a streamlined review pathway and oversight for secondary research uses where \"the research involves only information collection and analysis involving the investigator's <strong>use <\/strong>of identifiable health information when that <strong>use <\/strong>is regulated\" under HIPAA (<a href=\"https:\/\/www.ecfr.gov\/current\/title-45\/subtitle-A\/subchapter-A\/part-46#subpart-A\">45CFR46<\/a>.104(d)(4)(iii))<\/li>\r\n \t<li><strong>Preparatory to research<\/strong> activities may <strong>not <\/strong>include removing PHI from a CE, though an external researcher may review PHI within the covered entity.<\/li>\r\n \t<li><strong>Tracking of disclosures<\/strong> is governed by Michigan Medicine Policy <a href=\"https:\/\/michmed-administration.policystat.com\/policy\/6509419\/latest\/\">01-04-335<\/a> <em>(requires level-2 login)<\/em>, and applies to research relying on HIPAA provisions for waiver of authorization, preparatory to research, and\/or research on decedents. Inappropriate disclosures (see heading below) must also be tracked. The Policy linked above includes suggested tracking methods; <a href=\"https:\/\/umhealth.sharepoint.com\/sites\/Corporate-Compliance\/SitePages\/Contact-Us.aspx\">contact Corporate Compliance Office<\/a> for further guidance.<\/li>\r\n<\/ul>","legacy_media_position":"","legacy_media_file":"","legacy_media_url":"","legacy_glossary_term":"","legacy_glossary_nids":"","legacy_resource":"","legacy_resource_nids":"","legacy_buttons":null},{"legacy_section_type":"heading","legacy_heading":"Unauthorized Uses and Disclosures","legacy_subheading":"","legacy_section_text":"","legacy_media_position":"","legacy_media_file":"","legacy_media_url":"","legacy_glossary_term":"","legacy_glossary_nids":"","legacy_resource":"","legacy_resource_nids":"","legacy_buttons":null},{"legacy_section_type":"text_area","legacy_heading":"","legacy_subheading":"","legacy_section_text":"Occasionally, unauthorized disclosures (both incidental and accidental) of PHI will occur within the research setting. Regardless of the type, extent, or volume of PHI that is disclosed, it is important that you take appropriate actions to mitigate any potential harm and that you report the occurrence.\r\n\r\nIf you suspect or know of an unauthorized disclosure of PHI related to research, you should take any practicable steps necessary to limit potential or ongoing harmful effects.\u00a0 Additionally, you should <a href=\"https:\/\/medresearch.umich.edu\/office-research\/about-office-research\/our-units\/institutional-review-boards-irbmed\">notify IRBMED<\/a> as soon as possible. You will also need to promptly report the concern to the <a href=\"https:\/\/umhealth.sharepoint.com\/sites\/Corporate-Compliance\/SitePages\/Contact-Us.aspx\">Corporate Compliance Office<\/a>.\r\n\r\nYou will be asked to submit an\u00a0<a href=\"\/medschool\/guidance\/other-reportable-information-or-occurrence-orio\">Other Reportable Information and Occurrences (ORIO)<\/a>\u00a0to IRBMED. Please include HIPAA-<a class=\"gtip\" href=\"\/medschool\/glossary\/de-identified\">de-identified<\/a> details of the event, how the event will be addressed, and what procedure(s) will be put in place so that this type of event does not happen again.\r\n\r\nYou will also need to include the date that the study team reported the event to the Compliance Office, to whom they reported it, the response from the Compliance Office, and verification that the study team has complied or will comply with any Compliance Office request.","legacy_media_position":"","legacy_media_file":"","legacy_media_url":"","legacy_glossary_term":"","legacy_glossary_nids":"","legacy_resource":"","legacy_resource_nids":"","legacy_buttons":null}],"update_notice_type":[],"update_notice_start":"","update_notice_end":"","update_notice_text_blocks":null,"global_contact_block":false,"contact_name":"","contact_email":"","contact_additional_info":"Contact us at\u00a0<a href=\"mailto:irbmed@umich.edu\">irbmed@umich.edu<\/a>\u00a0or 734-763-4768 \/ (Fax 734-763-1234)\r\n\r\n2800 Plymouth Road, Ann Arbor, MI 48109-2800\r\n\r\nA <a href=\"https:\/\/medresearch.umich.edu\/office-research\/about-office-research\/our-units\/institutional-review-boards-irbmed\/irbmed-contacts-roster#irbmed-staff\">list of IRBMED staff<\/a> is available at our website.\r\n\r\nEdited By: <a href=\"mailto:larkspur@umich.edu\">larkspur@umich.edu<\/a>\r\nLast Updated: April 15, 9:00AM","global_contact_block_select":null},"_links":{"self":[{"href":"https:\/\/az.research.umich.edu\/medschool\/wp-json\/wp\/v2\/document\/752","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/az.research.umich.edu\/medschool\/wp-json\/wp\/v2\/document"}],"about":[{"href":"https:\/\/az.research.umich.edu\/medschool\/wp-json\/wp\/v2\/types\/document"}],"version-history":[{"count":2,"href":"https:\/\/az.research.umich.edu\/medschool\/wp-json\/wp\/v2\/document\/752\/revisions"}],"predecessor-version":[{"id":1977,"href":"https:\/\/az.research.umich.edu\/medschool\/wp-json\/wp\/v2\/document\/752\/revisions\/1977"}],"acf:post":[{"embeddable":true,"href":"https:\/\/az.research.umich.edu\/medschool\/wp-json\/wp\/v2\/document\/877"},{"embeddable":true,"href":"https:\/\/az.research.umich.edu\/medschool\/wp-json\/wp\/v2\/document\/725"},{"embeddable":true,"href":"https:\/\/az.research.umich.edu\/medschool\/wp-json\/wp\/v2\/document\/764"},{"embeddable":true,"href":"https:\/\/az.research.umich.edu\/medschool\/wp-json\/wp\/v2\/document\/745"},{"embeddable":true,"href":"https:\/\/az.research.umich.edu\/medschool\/wp-json\/wp\/v2\/document\/744"}],"wp:attachment":[{"href":"https:\/\/az.research.umich.edu\/medschool\/wp-json\/wp\/v2\/media?parent=752"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/az.research.umich.edu\/medschool\/wp-json\/wp\/v2\/categories?post=752"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/az.research.umich.edu\/medschool\/wp-json\/wp\/v2\/tags?post=752"},{"taxonomy":"content-type","embeddable":true,"href":"https:\/\/az.research.umich.edu\/medschool\/wp-json\/wp\/v2\/content-type?post=752"},{"taxonomy":"topic","embeddable":true,"href":"https:\/\/az.research.umich.edu\/medschool\/wp-json\/wp\/v2\/topic?post=752"},{"taxonomy":"update-type","embeddable":true,"href":"https:\/\/az.research.umich.edu\/medschool\/wp-json\/wp\/v2\/update-type?post=752"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}