Accounting of Disclosure Policy
Accounting of Disclosure Policy
Accounting of Disclosure Policy
Revision History
EXT/HIPAA/ADP/01 Page 1 of 7
Accounting of Disclosure Policy
Reference 45 CFR 164.528 Ver. No. 1.0
1. Objective
Individuals and the CE have the right to receive an accounting of disclosures of their
Protected Health Information (PHI) as set forth by the HIPAA Privacy Rule (45 CFR
164.528).The objective of this Policy and Procedure is to support the Exterprise
process for Accounting of disclosure made by the Organization for TPO, subsequent
to the issuance of an disclosure authorization. This process also addresses situations
under which Exterprise is not obligated to track the accounting process.
2. Scope
This policy applies to all Exterprise workforce members including, but not limited to
full-time employees, part-time employees, trainees, volunteers, contractors, and
temporary workers.
3. Process Overview
The accounting of disclosure policy and procedure of Exterprise involves Covered
Components and those working on behalf of the covered components, designated as
such for purposes of complying with the privacy provisions of the Health Insurance
Portability and Accountability Act of 1996. The Covered components may include
Brokers, Service providers and the actual beneficiary.
4. Policy
1. An individual or CE has the right to receive an accounting of disclosures of PHI
made by Exterprise in the six (6) years prior to the date on which the
accounting is requested.
EXT/HIPAA/ADP/01 Page 2 of 7
Accounting of Disclosure Policy
Reference 45 CFR 164.528 Ver. No. 1.0
Paid wrong provider (claims remit containing PHI sent to wrong provider).
6. Exterprise must provide the accounting, in writing, within 30 days of the date
the request for the accounting was received. The contents of the accounting
should include the following:
EXT/HIPAA/ADP/01 Page 3 of 7
Accounting of Disclosure Policy
Reference 45 CFR 164.528 Ver. No. 1.0
Recording Disclosures
Authorized Employee
EXT/HIPAA/ADP/01 Page 4 of 7
Accounting of Disclosure Policy
Reference 45 CFR 164.528 Ver. No. 1.0
Privacy Officer
Authorized Employee
Privacy Officer
EXT/HIPAA/ADP/01 Page 5 of 7
Accounting of Disclosure Policy
Reference 45 CFR 164.528 Ver. No. 1.0
Retention:
Every policy and procedure revision/replacement will be maintained for a
minimum of six years from the date of its creation or when it was last in effect,
whichever is later. Other Exterprise requirements may stipulate a longer
retention. Log-in audit information and logs relevant to security incidents must
be retained for six years.
Compliance:
Failure to comply with this or any other privacy policy will result in disciplinary
actions. Legal actions also may be taken for violations of applicable regulations
and standards such as the HIPAA Privacy Rule and others.
EXT/HIPAA/ADP/01 Page 6 of 7
Accounting of Disclosure Policy
Reference 45 CFR 164.528 Ver. No. 1.0
References.
Omnibus HIPAA Final Rulemaking,
http://www.hhs.gov/ocr/privacy/hipaa/administrative/omnibus/index.html
HIPAA Final Privacy Rule, 45 CFR Part 164.514(h), Department of Health and
Human Services,
http://www.hhs.gov/ocr/privacy/hipaa/administrative/privacyrule/August
14, 2002.
HIPAA Breach Notification Rule:
http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule
/
Health Information Privacy, Security, and EHR
http://www.healthit.gov/providers-professionals/ehr-privacy-security
Achieve Meaningful Use: Protect Electronic Health Information
http://www.healthit.gov/providers-professionals/achieve-meaningful-
use/core-measures/protect-electronic-health-information
http://www.healthit.gov/providers-professionals/achieve-meaningful-
use/core-measures-2/protect-electronic-health-information
EXT/HIPAA/ADP/01 Page 7 of 7