Policies Regarding HIPAA Privacy

UMass Memorial Laboratories considers patient confidentiality and privacy of the highest importance. UMass Memorial Medical Center is committed to fully comply with the Health Insurance Portability and Accountability Act (HIPAA) and other regulations regarding patient confidentiality and security of protected health information (PHI).

The UMass Memorial Laboratories comply fully with UMass Memorial Medical Center policies related to these issues. Several important policies are summarized below.

The UMass Memorial Laboratories comply fully with the UMass Memorial Medical Center policy #1127 Patient Rights under the Health Insurance Portability and Accountability Act (HIPAA) that ensures that patients are able to exercise their rights afforded by HIPAA. These rights include, but are not restricted to the following:

  • Right to access (inspect/copy) designated record set
  • Right to amend designated record set
  • Right to accounting of disclosures of protected health information
  • Right to file a complaint regarding alleged privacy violations
  • Right to request restrictions on uses and disclosures of protected health information
  • Right to confidential Communications
  • Right to the notice of privacy practices
  • Right to revoke authorizations for the disclosure of protected health information

Other institution policies (e.g., #1085 Uses and Disclosures of Protected Health Information and #1128 Authorization to Disclose Protected Health Information) ensure that patient information is treated as confidential and used or disclosed, following minimum necessary guidelines, under the following circumstances:

  • With authorization from the patient or authorized representative, or
  • For purposes related to treatment, payment and healthcare operations of UMass Memorial Medical Center, or
  • When required by law, or
  • When permitted under research provisions, or
  • When de-identified (i.e., the information is stripped of all identifying information and unique characteristics or codes

In addition, the electronic transfer of information is performed using secure file transfer applications.

Policies are not meant to interfere with the normal flow of information between healthcare providers and patients. Therefore, when needed, a patient may be provided with a copy of laboratory results, without the requirement of a signed authorization or request, for the purposes in participating in his/her own treatment. As listed above, there are some circumstances where protected health information may be disclosed outside UMass Memorial without authorization. All patients have the right to request an accounting of how UMass Memorial discloses their protected health information for certain of these purposes.

Protocols are in place to ensure that, when required, forms for uthorization of protected health anformation have been accurately and thoroughly completed and this authorization is in effect at the time of release of information. Authorization is documented in the patient's medical record in a timely manner. Requests for access or amendments to patient records are directed to Health Information Management:

  • Outreach Client Patients: (508) 334-2863
  • University Campus: (508) 856-4957
  • Memorial Campus: (508) 334-5700

Contact Information for Laboratory HIPAA Compliance Officers:

Manager of Quality and Decision Support
UMass Memorial Laboratories: (508) 334-2827

or:

Privacy Officer, UMass Memorial Medical Center
UMass Memorial Medical Center Privacy Line: (508) 334-5551

   
   

©UMass Memorial Laboratories | Biotech One, 365 Plantation Street, Worcester MA 01605
Directions  Careers  Contact Us  Disclaimer  UMass Memorial Medical Center