1640.040 HIPAA PRIVACY: DISCLOSURES OF DE-IDENTIFIED HEALTH INFORMATION
Florida International University (FIU) may use or disclose De-identified Health Information without restriction under the HIPAA Privacy Rule. Individually identifiable health information may not be used or disclosed except as permitted by law.
If an FIU Covered Entity seeks to provide De-identified Health Information to any FIU unit or to any third party outside of FIU, the FIU Covered Entity must de-identify all individually identifiable health information in accordance with the requirements of the HIPAA Privacy Rule which are described in this policy..
If an FIU Covered Entity seeks to disclose individually identifiable health information to a Business Associate, the FIU Covered Entity must ensure that a a Business Associate agreement has first been executed between FIU and the Business Associate in accordance with FIU’s HIPAA Privacy Business Associate Policy before any individually identifiable health information is provided to the Business Associate.
Published on 2017-12-13
Administrative Oversight & Contact Information
Office of University Compliance & Integrity
University Compliance & Privacy Officer
- Phone: 305--348-2216