
When you modernize your injury surveillance system, Soliz notes, that doesn’t eliminate the need to follow required processes, minimize data collection, and clearly define who can use identifiable data and information for what purpose. “I think that is what’s really sparked some of the concerns about the CPSC’s recent proposals.”
“What it looks like is that they’re trying to get a larger set of identifiable emergency department data,” Soliz explains, “and maybe aren’t being particularly clear on the legal authority for asking for an increased amount of data.”
CPSC is charged with protecting the public from unreasonable risks of injury and death related to consumer products, and there are over 15,000 types of consumer products, Soliz says. “My understanding is that some of the information that’s being asked for isn’t directly related necessarily to those consumer products.” However, the data could be used for legitimate public health purposes, Soliz adds.
“When a public health authority asks a hospital or healthcare provider for data, there are lots of different pathways under HIPAA and state laws that allow for that,” Soliz explains. “You can provide a de-identified data set under HIPAA…and there is a HIPAA data use agreement that strictly limits how that data can be used and redisclosed for that public health purpose….We also have the public health authority pathway, where if it is authorized by law and subject to minimum necessary standard requirements, the data can also be disclosed that way.”
Soliz underscores that hospitals and providers need to ask the following: What is the law that authorizes me to disclose the data, and why is this the minimum amount necessary?
We want to have a good public health surveillance system, Soliz remarks. “A good public health surveillance system depends on public trust…and that in turn depends on collecting no more patient information than the law and the mission generally requires.” A public health surveillance system has a very legitimate value, and I think the provider community recognizes that, Soliz adds.
Furthermore, Soliz says, “I wanted to emphasize that a lot of these hospitals or providers are going to end up at different conclusions, in part because they’re subject to different laws at the state level….Even though HIPAA might allow for something, there might be a more restrictive state law that impacts the disclosure of the data that they are asking for.” Additionally, “the technical systems might not be in place to segment the data that is subject to those more restrictive state laws from being released in the technical manner that they’re asking for.”
This is not an easy analysis, Soliz says. “It does involve getting lawyers and compliance professionals involved because there’s a lot of complexity with the legal landscape, and it’s going to drive different answers.”