HIPAA Research, Public Health, and Law Enforcement Exceptions — Questions and Answers
Question 1: Under the HIPAA Privacy Rule, a covered entity may use or disclose PHI for research without individual authorization when:
- The research will be published in a peer-reviewed journal within 12 months
- The researcher is employed full-time by the covered entity
- An Institutional Review Board (IRB) or Privacy Board has approved a waiver of authorization (Correct answer)
- The research is funded entirely by a federal agency such as the NIH
Correct answer: An Institutional Review Board (IRB) or Privacy Board has approved a waiver of authorization
HIPAA permits use or disclosure of PHI for research without individual authorization if an IRB or Privacy Board has approved a waiver, finding that the research meets specific criteria (e.g., minimal privacy risk, impracticable to conduct otherwise). Employment status and funding source are not the determining factors.
Question 2: A 'limited data set' under HIPAA differs from fully de-identified data in that a limited data set:
- Contains no PHI and may be shared freely without any restrictions
- May still include certain dates and geographic subdivisions but requires a signed Data Use Agreement (Correct answer)
- Can only be used for direct treatment purposes and not research
- Must receive prior approval from the Office for Civil Rights before any sharing
Correct answer: May still include certain dates and geographic subdivisions but requires a signed Data Use Agreement
A limited data set retains certain data elements that would otherwise constitute PHI — such as dates (admission, discharge, birth) and geographic subdivisions larger than a street address — making it useful for research and public health. However, it requires a Data Use Agreement (DUA) with the recipient, unlike fully de-identified data which has no restrictions.
Question 3: Which of the following is a permitted disclosure of PHI to a public health authority under the HIPAA Privacy Rule without patient authorization?
- Sharing PHI with a public relations firm hired by the state health department
- Releasing aggregate patient data to a competing hospital for benchmarking
- Disclosing marketing analytics about patients' prescription habits to a state health plan
- Reporting a communicable disease to the state department of health as required by law (Correct answer)
Correct answer: Reporting a communicable disease to the state department of health as required by law
HIPAA explicitly permits covered entities to disclose PHI to public health authorities authorized by law to receive such reports for purposes of preventing or controlling disease, injury, or disability — including mandatory disease reporting to state health departments. The other options describe commercial or competitive uses that are not public health purposes.
Question 4: Law enforcement may obtain PHI from a covered entity without patient authorization in which of the following circumstances?
- For any federal crime investigation, regardless of whether legal process has been initiated
- Whenever a law enforcement officer verbally asserts an urgent public safety need
- Pursuant to a court order, warrant, subpoena, or grand jury subpoena (Correct answer)
- Only when the patient is a named suspect in a violent felony
Correct answer: Pursuant to a court order, warrant, subpoena, or grand jury subpoena
HIPAA permits disclosure to law enforcement in response to a court order, court-ordered warrant, subpoena, or grand jury subpoena — formal legal process that provides judicial or grand jury oversight. Mere verbal assertion by an officer, without formal process, does not satisfy HIPAA's requirements in most circumstances.
Question 5: Under HIPAA, a covered entity may disclose PHI about a deceased individual to a medical examiner or coroner to:
- Support a civil lawsuit filed by the deceased's surviving family members
- Help the covered entity reduce liability exposure related to the death
- Identify a deceased individual or determine the cause of death (Correct answer)
- Comply with insurance claims processing requirements from the deceased's health plan
Correct answer: Identify a deceased individual or determine the cause of death
The HIPAA Privacy Rule explicitly permits disclosure of PHI to medical examiners and coroners for purposes of identifying a deceased person or determining the cause of death. This exception recognizes the public interest in proper death investigation. It does not extend to litigation support or liability management.
Question 6: When an IRB considers whether to waive HIPAA authorization for a research study, which of the following is NOT a required criterion for granting that waiver?
- The research involves no more than minimal risk to the privacy of individuals
- The researcher must be a full-time employee of the covered entity holding the records (Correct answer)
- The research could not practicably be conducted without access to the PHI
- The research could not practicably be conducted without the waiver of authorization
Correct answer: The researcher must be a full-time employee of the covered entity holding the records
HIPAA's criteria for an IRB or Privacy Board to waive authorization focus on privacy risk, practicability, and adequacy of protections — not on the employment relationship between the researcher and the covered entity. Researchers from academic institutions, government agencies, or other organizations may qualify for waivers.
Under the HIPAA Privacy Rule, a covered entity may use or disclose PHI for research without individual authorization when: