The university of Toledo ("UToledo") will make reasonable efforts to limit the use and disclosure of individually identifiable protected health information to the minimum necessary to comply with any requests and make reasonable efforts to limit its own request to other organizations to similar minimum necessary request.
To comply with the minimum necessary use and disclosure guidelines for protected health information ("PHI") in accordance with the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), Administrative Simplification Act Privacy Rule 45 C.F.R. 160, 162 and 164 and HITECH Act.
This policy applies to university of Toledo physicians ("UTP") affiliated covered entities ("ACE") and all UToledo covered components (hybrid) and their respective workforce members. Covered components are determined by the privacy and security committee and documented on the hybrid list that can be located on the UToledo healthcare compliance and privacy website located at: https://www.utoledo.edu/offices/compliance/
Complete access to a patient's entire medical record, both paper and computerized, in order to provide appropriate and efficient treatment to a patient during the patient care episode is required for the following:
A detailed matrix of access to PHI will be held by health information management with input from clinical informatics. The minimum necessary PHI access matrix is based on the role of the individual and the "need to know criteria" in the performance of their job and in some cases their job location.
See addendum A (full access), addendum B (limited access), addendum C (outside access).
Replaces: 3364-90-02
Ohio Admin. Code 3364-90-02
Promulgated Under: 111.15
Statutory Authority: 3364
Rule Amplifies: 3364
Prior effective dates: 7/9/2018