For the purposes of rules promulgated by this agency in accordance with section 1347.15 of the Revised Code effective April 9, 2009, the following definitions apply:
Personal information systems of the Ohio department of medicaid (ODM) are managed on a "need-to-know" basis whereby the information owner determines the level of access required for an employee of the agency to fulfill his or her job duties. The determination of access to confidential personal information shall be approved by the employee's supervisor, the information's owner, designee operating under guidlines approved by the information's owner before providing the employee with access to confidential personal information within a personal information system. The agency shall establish procedures for determining a revision to an employee's access to confidential personal information upon a change to that employee's job duties including, but not limited to, transfer or termination. Whenever an employee's job duties no longer require access to confidential personal information in a personal information system, the employee's access to confidential personal information shall be removed.
Based upon a request of any individual for a list of confidential personal information about the individual maintained by ODM, or its predecessor ODJFS, ODM shall do the following:
Pursuant to the requirements of division (B)(2) of section 1347.15 of the Revised Code, this rule contains a list of valid reasons, directly related to the ODM exercise of its powers or duties, for which only employees of the agency may access confidential personal information regardless of whether the personal information system is a manual system or computer system.
Except as prohibited by federal and state law, performing the following functions constitute valid reasons for authorized employees of the agency to access confidential personal information:
The federal statutes and regulations and state statutes and administrative rules listed in the appendix to this rule make personal information maintained by the agency confidential and identify the confidential personal information that are subject to rules promulgated by this agency in accordance with section 1347.15 of the Revised Code.
For personal information systems that are computer systems and contain confidential personal information, ODM shall do the following:
Access to confidential personal information that is kept electronically shall require a password or other sufficient authentication measure as determined by the ODM HIPAA privacy official in conjunction with the chief information security official will determine what constitutes sufficient authentitication measures.
When the agency acquires a new computer system that stores, manages, or contains confidential personal information, ODM shall include a mechanism for recording specific access by employees of ODM to confidential personal information in the system.
When ODM modifies an existing computer system that stores, manages, or contains confidential personal information, that results in over half of the lines of code associated with that system being modified, then that system must have an automated mechanism for recording specific access by employees of ODM to any confidential personal information that is accessed via that system.
Each office within ODM shall use the log provided by the agency, currently identified as "CPI Log", or its successor system. Nothing in this rule limits the agency from requiring logging in any circumstance that it deems necessary.
Ohio Admin. Code 5160-1-04
Five Year Review (FYR) Dates: 08/01/2021
Promulgated Under: 119.03
Statutory Authority: 5164.02
Rule Amplifies: 1347.15, 1347.05, 1347.01