Exceptions to prohibition on disclosure of identifiable health data.
-
Law
-
Utah Code
-
Utah Health Code
-
Utah Health Data Authority Act
- Exceptions to prohibition on disclosure of identifiable health data.
Affected by 63I-1-226 on 7/1/2024
Effective 5/5/202126-33a-109. Exceptions to prohibition on disclosure of identifiable health data. - (1) The committee may not disclose any identifiable health data unless:
- (a) the individual has authorized the disclosure;
- (b) the disclosure is to the department or a public health authority in accordance with Subsection (2); or
- (c) the disclosure complies with the provisions of:
- (ii) insurance enrollment and coordination of benefits under Subsection 26-33a-106.1(1)(d); or
- (iii) risk adjusting under Subsection 26-33a-106.1(1)(b).
- (2) The committee may disclose identifiable health data to the department or a public health authority under Subsection (1)(b) if:
- (a) the department or the public health authority has clear statutory authority to possess the identifiable health data; and
- (b) the disclosure is solely for use:
- (i) in the Utah Statewide Immunization Information System operated by the department;
- (ii) in the Utah Cancer Registry operated by the University of Utah, in collaboration with the department; or
- (iii) by the medical examiner, as defined in Section 26-4-2, or the medical examiner's designee.
- (3) The committee shall consider the following when responding to a request for disclosure of information that may include identifiable health data:
- (a) whether the request comes from a person after that person has received approval to do the specific research or statistical work from an institutional review board; and
- (b) whether the requesting entity complies with the provisions of Subsection (4).
- (4) A request for disclosure of information that may include identifiable health data shall:
- (a) be for a specified period; or
- (b) be solely for bona fide research or statistical purposes as determined in accordance with administrative rules adopted by the department in accordance with Title 63G, Chapter 3, Utah Administrative Rulemaking Act, which shall require:
- (i) the requesting entity to demonstrate to the department that the data is required for the research or statistical purposes proposed by the requesting entity; and
- (ii) the requesting entity to enter into a written agreement satisfactory to the department to protect the data in accordance with this chapter or other applicable law.
- (5) A person accessing identifiable health data pursuant to Subsection (4) may not further disclose the identifiable health data:
- (a) without prior approval of the department; and
- (b) unless the identifiable health data is disclosed or identified by control number only.
- (6) Identifiable health data that has been designated by a data supplier as being subject to regulation under 42 C.F.R. Part 2, Confidentiality of Substance Use Disorder Patient Records, may only be used or disclosed in accordance with applicable federal regulations.
Download our app to see the most-to-date content.