Protection of patient confidentiality.

Checkout our iOS App for a better way to browser and research.

153.50 Protection of patient confidentiality. Subject to s. 153.455:

(1) Definitions. In this section:

(b)

1. “Patient-identifiable data", for information submitted by hospitals and ambulatory surgery centers, means all of the following data elements:

a. Patient medical record or chart number.

b. Patient control number.

c. Patient date of birth.

d. Date of patient admission.

e. Date of patient discharge.

f. Date of patient's principal procedure.

g. Encrypted case identifier.

h. Insured's policy number.

i. Patient's employer's name.

j. Insured's date of birth.

k. Insured's identification number.

L. Medicaid resubmission code.

m. Medicaid prior authorization number.

1m. “Patient-identifiable data" does not include calculated variables that are derived from patient-identifiable data and the dissemination of which does not permit patient identification.

1r. “Patient-identifiable data" does not include data elements that identify a patient's race or ethnicity.

2. “Patient-identifiable data", for information submitted by health care providers who are not hospitals or ambulatory surgery centers and by insurers and administrators, means all of the following data elements:

a. Data elements specified in subd. 1. a. to g., L. and m.

b. Whether the patient's condition is related to employment, and occurrence and place of an auto accident or other accident.

c. Date of first symptom of current illness, of current injury or of current pregnancy.

d. First date of the patient's same or similar illness, if any.

e. Dates that the patient has been unable to work in his or her current occupation.

f. Dates of receipt by the patient of medical service.

g. The patient's city, town or village.

(c) “Small number" means a number that is insufficiently large to be statistically significant, as determined by the department.

(3) Measures to ensure protection of patient identity. To ensure that the identity of patients is protected when information obtained by the department, by the entity under contract under s. 153.05 (2m) (a), or by the data organization under contract under s. 153.05 (2r) is disseminated, the department, the entity, and the data organization shall do all of the following:

(a) Aggregate any data element category containing small numbers. The department, in so doing, shall use procedures that are developed by the department and that follow commonly accepted statistical methodology.

(b) Remove and destroy all of the following data elements on the uniform patient billing forms that are received by the department, the entity, or the data organization under the requirements of this subchapter:

1. The patient's name and street address, except as provided under sub. (6) (am).

2. The insured's name, address and telephone number.

3. Any other insured's name, employer name and date of birth.

4. The signature of the patient or other authorized signature.

5. The signature of the insured or other authorized signature.

6. The signature of the physician.

7. The patient's account number, after use only as verification of data by the department or by the entity.

(c) Develop, for use by purchasers of data under this subchapter, a data use agreement that specifies data use restrictions, appropriate uses of data and penalties for misuse of data, and notify prospective and current purchasers of data of the appropriate uses.

(d) Require that a purchaser of data under this subchapter sign and have notarized the data use agreement of the department, the entity, or the data organization, as applicable.

(3m) Provider, administrator, or insurer measures to ensure patient identity protection. A health care provider that is not a hospital or ambulatory surgery center or an insurer or an administrator shall, before submitting information required by the department, or by the data organization under contract under s. 153.05 (2r), under this subchapter, convert to a payer category code as specified by the department or the data organization, as applicable, any names of an insured's payer or other insured's payer.

(4) Release of patient-identifiable data.

(a) Except as specified in. pars. (b) and (c), under the procedures specified in sub. (5), release of patient-identifiable data may be made only to any of the following:

1.

a. An agent of the department who is responsible for the patient-identifiable data in the department, in order to store the data and ensure the accuracy of the information in the database of the department or to create a calculated variable that is derived from the patient-identifiable data.

b. An agent of the entity under contract under s. 153.05 (2m) (a) who is responsible for the patient-identifiable data of the entity, in order to store the data and ensure the accuracy of the information in the database of the entity or to create a calculated variable that is derived from the patient-identifiable data.

c. An agent of the data organization under contract under s. 153.05 (2r) who is responsible for the patient-identifiable data of the data organization, in order to store the data and ensure the accuracy of the information in the database of the data organization or to create a calculated variable that is derived from the patient-identifiable data.

2. A health care provider that is not a hospital or ambulatory surgery center or the agent of such a health care provider, to ensure the accuracy of the information in the database of the department or the data organization under contract under s. 153.05 (2r), or a health care provider that is a hospital or ambulatory surgery center or the agent of such a health care provider, to ensure the accuracy of the information in the database of the entity under contract under s. 153.05 (2m) (a).

3. The department or its agent, for purposes of epidemiological investigation, or, with respect to information from health care providers that are not hospitals or ambulatory surgery centers, the department or the data organization under contract under s. 153.05 (2r), to eliminate the need for duplicative databases.

4. An agency or organization that is required by federal or state statute to obtain patient-identifiable data for purposes of epidemiological investigation or to eliminate the need for duplicative databases.

(b) Of information submitted by health care providers that are not hospitals or ambulatory surgery centers, patient-identifiable data that contain a patient's date of birth may be released under par. (a) only under circumstances as specified by rule by the department.

(c) The data organization under contract under s. 153.05 (2r) may not share health care claims data collected by the data organization unless the sharing is in compliance with 42 USC 1320d-2 and 1320d-4 and 45 CFR 164.

(5) Procedures for release of patient-identifiable data.

(a) The department, an entity that is under contract under s. 153.05 (2m) (a), or a data organization that is under contract under s. 153.05 (2r) may not release or provide access to patient-identifiable data to a person authorized under sub. (4) (a) unless the authorized person requests the department, entity, or data organization, in writing, to release the patient-identifiable data. The request shall include all of the following:

1. The requester's name and address.

2. The reason for the request.

3. For a person who is authorized under sub. (4) (a) to receive or have access to patient-identifiable data, evidence, in writing, that indicates that authorization.

4. For an agency or organization that is authorized under sub. (4) (a) 4. to receive or have access to patient-identifiable data, evidence, in writing, of all of the following:

a. The federal or state statutory requirement to obtain the patient-identifiable data.

b. Any federal or state statutory requirement to uphold the patient confidentiality provisions of this subchapter or patient confidentiality provisions that are more restrictive than those of this subchapter; or, if the latter evidence is inapplicable, an agreement, in writing, to uphold the patient confidentiality provisions of this subchapter.

(b) Upon receipt of a request under par. (a), the department, entity, or data organization, whichever is applicable, shall, as soon as practicable, comply with the request or notify the requester, in writing, of all of the following:

1. That the department, entity, or data organization, as applicable, is denying the request in whole or in part.

2. The reason for the denial.

3. For a person who believes that he or she is authorized under sub. (4) (a), the action provided under s. 19.37.

(5m) Employers not to request patient-identifiable data. Notwithstanding subs. (4) and (5) no employer may request the release of or access to patient-identifiable data of an employee of the employer.

(6) Information submitted.

(a) The department or entity under contract under s. 153.05 (2m) (a) may not require a health care provider submitting health care information under this subchapter to include the patient's name or social security number, and the department may not require a health care provider submitting health care information under this subchapter to include the patient's street address.

(am) Hospitals or ambulatory surgery centers shall submit the patient's street address to the entity under contract under s. 153.05 (2m) (a) as directed by the entity. The entity may only use the street address to create a calculated variable that does not identify a patient's address or to convert the data element to the corresponding U.S. bureau of the census census tract and block group. The entity shall destroy the street address information upon the creation of the variable or upon the conversion to the census tract and block group.

(b) The department may not require under this subchapter a health care provider that is not a hospital or ambulatory surgery center to submit uniform patient billing forms.

(c) A health care provider that is not a hospital or ambulatory surgery center may not submit any of the following to the department under the requirements of this subchapter:

1. The data elements specified under sub. (3) (b).

2. The patient's telephone number.

3. The insured's employer's name or school name.

4. Data regarding insureds other than the patient, other than the payer category code under sub. (3m).

5. The patient's employer's name or school name.

6. The patient's relationship to the insured.

7. The insured's identification number.

8. The insured's policy or group number.

9. The insured's date of birth or sex.

10. The patient's marital, employment or student status.

(d) If a health care provider that is not a hospital or ambulatory surgery center submits a data element that is specified in par. (c) 1. to 10., the department shall immediately return this information to the health care provider or, if discovered later, shall remove and destroy the information.

(e) A health care provider may not submit information that uses any of the following as a patient account number:

1. The patient's social security number or any substantial portion of the patient's social security number.

2. A number that is related to another patient identifying number.

History: 1987 a. 399; 1989 a. 18; 1993 a. 16; 1995 a. 27 s. 9126 (19); 1997 a. 27, 231; 1999 a. 9, 185; 2003 a. 33; 2005 a. 228; 2009 a. 274; 2015 a. 287.


Download our app to see the most-to-date content.