Page 17 - Driving Public Health in the Fast Lane
P. 17

Public Health Authority to Receive and Protect Confidential Data


               Public health’s ability to collect identifiable, patient information is necessary to respond to public health threats
               effectively and is a critical aspect to protect the nation’s health. Below are descriptions of public health’s authority to
               collect and protect patient information:

                  •  Public health has broad authority to collect data to prevent and control disease and protect public health;  1

                  •  State and Local Health and Sanitary Codes authorize receipt and investigation of reportable disease data by public
                    health. The ability to collect identifiable patient information is necessary to respond effectively, codified primarily
                    by state and local laws and regulations;

                  •  The Health Insurance Portability and Accountability Act (HIPAA) of 1996 permits public health information
                    disclosure to public health without patient consent;  2
                  •  Confidentiality is rigorously protected by public health laws at all times; information use is limited to the purpose
                    for which it was collected;  3
                  •  Information that could result in the identification of an individual is not released.


               Today, data privacy concerns have become a pressing issue for many patients as they interact with the health care and
               public health communities. Although public health surveillance activities benefit patients at both the individual and
               population level, patients often find the term “surveillance” threatening. This negative perception persists for several
               reasons. To start, health data includes some of a patient’s most confidential information, such as diagnoses (e.g., HIV
               status, addiction) that may be used to stigmatize or discriminate against vulnerable populations. Because most patients
               do not understand where health data are stored and protected, the functions of public health surveillance and how
               public health authorities use the data, a pervasive “fear of the unknown” breeds distrust of the public health surveillance
               system. While public health data is both a strategic asset and a critical national resource to protect our democracy,
               American patients have historically disfavored government-led surveillance initiatives, so essential public health
               surveillance mechanisms may be incorrectly interpreted as an unreasonable overreach into individual patients’ lives
                                4
               instead of beneficial.  Finally, the increasing threat of sophisticated health data system security breaches exacerbates
               patient concerns about health data misuse. Cyber vulnerabilities such as hacking, malware, ransomware, and phishing
                                                                                       5, 6
               attacks impact millions of patients each year, and cost the industry $6.2 billion annually.  Moreover, these cyberattacks
               also disincentivize patients—who fear becoming victims of health data misuse—from honestly and fully disclosing
               essential health information to providers. 7

               Health data privacy and security issues are addressed by a complex web of federal and state regulations with variable
               standards for health data protection and usage within the public health surveillance system. Traditionally, public
               health data collection and transmission processes have been manual, such as faxing reports from a clinical laboratory
               to a public health department. In addition to being slow and riddled with data errors, these manual processes are also
               especially vulnerable to security threats, lack audit trails, and risk misplacement of paper documents or transmission
               to the wrong place. On the other hand, electronic data systems promote timeliness and improve data quality, but must
                                              8,9
               meet rigorous data security standards. As the public health community shifts to electronic public health surveillance,
               it must have adequate resources and leadership to respond to privacy and cybersecurity challenges facing the public
               health community, and continue to prioritize strong cybersecurity infrastructure to adequately defend against breaches
               or attacks on any public health data system.






               1  Whalen v Roe. law.cornell.edu (Burger Court 1977). https://www.law.cornell.edu/supremecourt/text/429/589.
               2  Permitted Uses and Disclosures: Exchange for Public Health Activities. Healthit.gov. https://www.healthit.gov/sites/default/files/12072016_hipaa_and_public_health_fact_sheet.pdf.
                 Published December 2016.
               3  Section 308(d) of the Public Health Service Act (42 U.S.C. 242m). cdc.gov. https://www.cdc.gov/rdc/Data/b4/section308.pdf.
               4  Geiger AW. How Americans have viewed government surveillance and privacy since Snowden leaks. Pew Research Center. https://www.pewresearch.org/fact-tank/2018/06/04/how-
                 americans-have-viewed-government-surveillance-and-privacy-since-snowden-leaks/. Published June 4, 2018.
               5  The Rampant Growth of Cybercrime in Healthcare. Workgroup for Electronic Data Interchange. https://www.wedi.org/docs/publications/cybercrime-issue-brief.pdf?sfvrsn=0. Published
                 February 8, 2017. Accessed May 9, 2019.
               6  Ronquillo JG, Winterholler JE, Cwikla K, Szymanski R, Levy C. Health IT, hacking, and cybersecurity: national trends in data breaches of protected health information. JAMIA Open.
                 2018;1(1):15-19. https://academic.oup.com/jamiaopen/article/1/1/15/5035928. Published June 11, 2018.
               7  Ibid.
               8  Privacy, Security, and Electronic Health Records. hhs.gov. https://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/understanding/consumers/privacy-security-electronic-records.pdf.
               9  Kruse CS, Smith B, Vanderlinden H, Nealand A. Security Techniques for the Electronic Health Records. J Med Syst. 2017;41(8): 127. https://www.ncbi.nlm.nih.gov/pmc/articles/
                 PMC5522514/. Published July 21, 2017.
   12   13   14   15   16   17   18   19   20   21   22