Good Morning. My name is Joan Kiel and I am the designated spokesperson for the American College Health Association regarding the application of the Health Insurance Portability and Accountability Act (HIPAA) and medical records privacy protections to colleges and universities. In addition, I am the Chairman of University HIPAA Compliance for Duquesne University in Pittsburgh, Pennsylvania. Lastly, I am the Chair of the American College Health Association HIPAA Committee.
Since its inception in 1920, the American College Health Association has been dedicated to the health needs of students at colleges and universities where the vast majority of students are over the age of 18 and are considered adults. ACHA is the principal leadership organization for the field of college health and provides services, communications, and advocacy that help its members to advance the health of their campus communities. ACHA's membership has grown from the original 20 institutions of higher education to more than 930. These member institutions represent the diversity of the higher education community -- two and four year, public and private, large and small.
Today, I will discuss with you:
Regarding the first issue: colleges and universities are a community of people. Therefore, the student health service functions as a community-based health care provider practice. The medical records at the student health service may serve a varied population. Medical records are maintained for ongoing treatment and evaluation of students, and in some cases, family members, faculty, and staff.
Regarding the second issue: the potential expansion of protections for medical records could have positive or negative effects for colleges. On the positive side, under HIPAA, people who do not have a need to know will not be able to access the record, nor have a right to the information contained herein. The law also protects the student health service staff as they can simply say, the law says that you cant have the record. The students confidentiality is protected and the potential for discrimination is mitigated. The health service must respect students right to privacy or they wont use the health service even in emergency situations -- which can then cause further harm.
On the negative side, even cases that have gone to court have not resolved the HIPAA FERPA intersection. In Shin v. MIT, the case was settled out of court and thus the court had no occasion to rule on the HIPAA FERPA issue. In Allegheny College v. Mahoney, the college was found not negligent, and the only mention of the HIPAA FERPA intersection was that policies will be looked at, but that is on a voluntary basis not a court order. Thus, it is imperative that if the courts cannot settle the HIPAA FERPA intersection, then the laws need to be rewritten for all to clearly understand. For as of now, under HIPAA, information is shared for treatment, payment, and healthcare operations or if the patient consents. Under FERPA, information can be shared if the students life is in danger. That is a gray area. The questions arises as to at what point does one tell others. If one is right then they may save a life; but if one is incorrect, this can upset the student and break their trust. It is a tough judgment call.
Regarding the management of student health records, many student health services received legal opinions regarding compliance with FERPA and HIPAA that informed them that student health services must ensure compliance for student records under FERPA or state law, and non-student records would be governed by HIPAA. Many student health services are now in the unenviable position of having three different standards with which to adhere: students records maintained and accessed solely by the health care provider are governed by state law; student records released for any reason including patient authorization are governed by FERPA; non-student records (such as university employees, faculty, non-student spouses) are governed by HIPAA. An option then is for a college health service to discontinue providing services to non-students (such as, spouses, summer camps [band, athletic, etc.], visiting scholars, athletic interns, J-1 visa scholars). This option allows them to follow only FERPA or state law. This certainly is not an optimal solution as it decreases healthcare access and services to the campus community not to mention the lost revenue.
Another potential negative aspect concerns accreditation for college health services. There are many college health services that are accredited by the Joint Commission on the Accreditation of Healthcare Organizations, (JCAHO), and the Accreditation Association for Ambulatory Health Care (AAAHC). Both organizations are moving toward HIPAA regulations as part of the general survey requirements. Will college health services not be accredited because they are not able to meet the HIPAA requirements if they do not engage in one of the electronic transactions? Accreditation is important to student health services as it indicates a commitment toward excellence in health care that parents expect for their students attending a college or university.
Regarding the third issue: adopting protections for medical records are not seen as being easy or burdensome, but more so as necessary to ensure quality care and protect patient privacy. It needs to be reconciled that if HIPAA is the national privacy standard in health care -- as it has been deemed --then why are student medical records exempt under HIPAA?
It is the request of the American College Health Association to specifically address the implementation issues of HIPAA, FERPA, and State laws in our college and university health centers. Our changes to the regulations are as follows:
Thank you for the opportunity to present our concerns and requests.