CSTE IRB Workgroup

HIPAA

Good morning Everyone, 
I came from a hospital setting and HIPAA was a huge part of research.  Is there ever a time when a HIPAA waiver is needed when performing research in a public health setting? I would appreciate any and all information on this, as there is no one left in the institution that is able to answer this (COVID has led to many retirements). 

Thank you,
Robin Krause, MS
IRB Administrator II
NYSDOH IRB

Comments & Events

Alysia Kwon, Vice Chair and Administrator
Hi, Robin - Our health department (LA County) runs some community clinics where PHI is an issue, and some of our non-clinical programs (communicable disease, tobacco control) that focus on prevention, interventions, program planning and research/evaluation, often partner with the County hospitals to access patient data.  We also have a public health lab that collects PHI.  In addition, our non-clinical programs do surveillance and outbreak investigations, as well as COVID-19 testing at mass County-run testing sites where PHI is collected and used for surveillance, program planning, research and evaluation.  As an aside, our IRB reviews some non-research as well as research as an expansion due to community involvement and labor issues regarding staff (e.g., staff surveys).
Robin Krause
Hi Alysia, 

We do similar activities related to PHI and I know that DOH is a covered entity. I was basically wondering is there ever a time when a researcher would need to submit a HIPAA waiver to perform research? If so, could you share a specific example.
Alysia Kwon, Vice Chair and Administrator
Hi, Robin - One example is when one of our researchers wanted to expand  on COVID-19 surveillance activities with intentions to publish and requested a HIPAA waiver since samples had already been collected.  Another example is a COVID-19 seroprevalence study at one of our testing sites where documentation of informed consent was obtained but a HIPAA waiver was requested (PHI included names, telephone numbers and addresses). In this case the participants were recruited from a market research firm where only PII was collected, but the PHI came into play during the testing since our department is a covered entity.  Hope this helps!
Alysia Kwon, Vice Chair and Administrator
By the way, I'm curious, at your institution did COVID-19 lead to retirements due to burnout?
Robin Krause
Hi Alysia,

Maybe now people are retiring due to burnout, but in the beginning it was more of if I have to work from home, I might as well retire. They were already eligible for retirement – COVID helped make that decision.
Robin Krause
Thank you, Alysia.  This does help.
Alysia Kwon, Vice Chair and Administrator
Ah got it, thank you :)
Robin Krause
You’re welcome.
Craig Conover, Medical advisor, Chicago DPH, IRB Chair IL DPH
IL DPH is a hybrid entity. The programs  that are "covered"   are subject to HIPAA regs are those involved in billing-- including eg certain lab programs that bill hospitals (eg newborn screening), certain women's health programs  that involve billing/insurance, and the HIV medical assistance program (formerly known as ADAP).

Per federal rules, there are 4 pathways to obtain PHI from a Covered Entity for an IRB-approved research study:
1. Request only de-identified data from the Covered Entity
2. Request a Limited Data Set, under a Data Use Agreement
3. Get Authorization from each study subject
4. Obtain a Waiver of Authorization from the IRB   

Federal rules:
(1) Permitted uses and disclosures. A
covered entity
may use or disclose
protected health information for
research, regardless of the source of
funding of the research, provided
that:
(i) Board approval of a waiver of
authorization.
The covered entity
obtains documentation that an
alteration to or waiver, in whole or in
part, of the individual authorization
required by § 164.508 for use or
disclosure of protected health
information has been approved by
either:
(A) An Institutional Review Board
(IRB)....or;
(B) A privacy board ...
 
For release of identifiable data from a non-covered component of a health dept to/for use by a covered entity, we typically do a HIPAA waiver in this situation.  But I would like to see the opinion of an expert HIPAA lawyer on this issue. 
Robin Krause
Thank you, Craig for your detailed response and federal regulations.  I do appreciate it. Do you have an example of a study (generic info only, of course) where a HIPAA waiver was submitted with the research package?
Ian Horste
Hi Robin,
Similar to the post above, In Michigan our department's IRB reviews research involving public health components of the department/public health data (which generally is not covered by HIPAA) and data from HIPAA covered components of our department including the state public health laboratory, the state's Medicaid agency, state hospitals, etc. and the data associated with those settings. When HIPAA covered data is requested for use in research, our board makes every effort to ask whether it is possible to conduct the research without the use or disclosure of potentially identifying information. In most cases, a limited data set that can be disclosed with an appropriate data use agreement in place (and therefore without a requirement for authorization) is all that is needed.
A recent example where we required the researcher request a waiver of authorization under HIPAA was for research that involved data from a covered component of the department and address specific geography. For the analysis proposed, the research couldn't be conducted without street level address as a variable so the HIPAA covered data could not be used in the form of a limited data set.
For what it is worth, we treat evaluations of informed consent and waivers of informed consent (when the request is for public health data that is not HIPAA covered) in a similar fashion, the documentation is just a little more rigorous when HIPAA applies. Best,
-Ian
Robin Krause
Thank you, Ian for your thorough response.  It is greatly appreciated.  Our IRB always does a thorough review as well in regards to identifying information and will often suggest to the PI to limit their dataset further. 
Ian Horste
I'm not sure the example I provided was specific enough, but I'll add that we typically see requests for waivers of authorization in retrospective research involving a large number of potentially identifiable records (that can't be further de-identified) where neither our department nor the researcher involved have a clear and ongoing relationship with the subjects (that is, a relationship that might offer an opportunity for informed consent/authorization to be obtained).
Robin Krause
Thank you, Ian. Yes, that example is very helpful.

I appreciate you taking the time to respond.
Jessica Robbins
I think others have covered this pretty well.  I will add that we now forward new studies that request waiver of HIPAA authorization to our Law Department HIPAA unit for review.  HIPAA enforcement is substantial enough that Law wants to have an eye on it.  This does not replace the IRB review, since the IRB is the body that is legally required to evaluate waiver requests, but the HIPAA unit's evaluation informs our decision-making.
Robin Krause
Yes, I think have a legal representative review it when it comes to research that involves HIPAA whether it is a waiver or not is important.

Thank you,
Robin
Joni Koenig
Hi Robin - This may be somewhat of a loaded question, but I'll try to keep my response simple.  My state health department is a "public health authority" under HIPAA and not a hybrid entity.  As such, we comply with HIPAA to the extent feasible.

Our state health department does not consider human subjects research to be public health authority work.  Our IRB has oversight of human subjects research in which the state health department is engaged and functions as both an IRB and a Privacy Board.  To use or disclose state health department PHI as part of the research, the IRB requires either HIPAA authorization from research participants or justification for waiver of HIPAA authorization.  

We have a few programs that have state statutes that specifically speak to release of PHI for research.  We also have at least one program that has a federal regulation that speaks to release of PHI.  For the remainder of the programs, our state health department also has a separate Privacy Board that speaks to use and disclosure of PHI for purposes other than research.

Joni
Robin Krause
Hi Joni,

Thank you, Joni. I appreciate your response. When I posted – I knew it was a loaded question. We are in the mist of revising our guidelines, as the IRB Administrative Director recently retired, and I am finding some policies are not clearly written and would like to expand and clarify them. Would you mind sharing any guidance you have regarding HIPAA for IRB and/or researchers with me? Or anyone else. My email is robin.krause@health.ny.gov<mailto:robin.krause@health.ny.gov>

Thank you,
Robin
Craig Conover, Medical advisor, Chicago DPH, IRB Chair IL DPH
Robin: If we release identifiable data to a researcher who works at a covered entity, our IRB requires a waiver of consent and a waiver of authorization.

We are not always clear on whether or not a researcher is a covered health care provider..,  When is a researcher considered to be a covered health care provider under HIPAA?
Robin Krause
Thank you Joni!
Robin Krause
Thank you for the information and the link, Craig that makes sense.