Quick HIPAA question

A Broker & Reinsurer for one of my fully insured groups that is leaving us in October is asking for the diagnosis codes for large claimants. That is a HIPAA no can do correct?

Google says it is OK so long as there is no IIHI as well. But I am still not convinced.

We have an exhibit giving them the following:
STATUS: Active/Deceased/Terminated
RELATIONSHIP: EE/SPOUSE/CHILD
DIAGNOSIS CATEGORY (1 of 25 possible)
$Medical
$Rx

The combo of STATUS and RELATIONSHIP could point to an individual is where I am concerned

I’m not a HIPPA expert or even someone who works on Health.

However in my company’s annual mandatory privacy training, one of the last slides is the directive “if you have questions or are the least bit uncertain contact [address of a ‘privacy compliance’ mailbox]”. If your company doesn’t have something similar (if they’re of any size, they should), reaching out to an appropriate legal/compliance person would be the best way to go.

1 Like

If there is no personal information to link it back to an individual, I don’t see a problem

Personally, if you are uncomfortable, kick it up the ladder or to legal

2 Likes

Wondering why “relationship” is included.
Your company should not be including that.

And, definitely, this is a higher pay grade decision, as Paysh says.

And, it is “HIPAA.”

1 Like

I’m not a full-on expert but I think this is kosher, though I’d want to clear it with legal to be sure. I know my broker has provided similar information on our plan. We had a high claimant and we were told it was the spouse of a current employee, and they opined about the likelihood of the high cost continuing so we could budget for that if needed.

1 Like

This is pretty typical information used by brokers when obtaining stop-loss coverage for a group.

HIPAA includes a Safe-Harbor provision that lists all the fields that need to be eliminated from a dataset before it is considered properly de-identified. None of those fields are in that list, but if you feel that a list of large claimants from a small group constitutes a possible re-identification risk, then you are under no obligation to provide the data.

As others have mentioned, contact your internal legal dept.

1 Like

Can the data be deidentified? I see such data all the time.

If concerned, the broker should be able to sign an nda or baa.

Reinsurers dont sign BAA (they are not business associates).

1 Like