Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
Next revision Both sides next revision
access_of_health_information [2016/06/14 11:36]
jillian_nadette_de_leon
access_of_health_information [2016/06/21 00:40]
jillian_nadette_de_leon
Line 1: Line 1:
 ##ACCESS OF HEALTH INFORMATION ##ACCESS OF HEALTH INFORMATION
  
-**Access of PHCP, Secondary ​Health Care Provider, Health Facilities**\\ +**Access of Health Care Providers**\\ 
-  *Health facilities shall clearly define access rights and user roles of staff to ensure that only appropriate people have access to the minimum necessary protected health information. The Health Facility shall create policies and procedures to specify the groups and positions that need to access health information to perform their job responsibilities,​ as well as the types of health information to which they need access. The Chief of Health Facility shall issue a memorandum containing the list of names and information stated in the preceding statement and a copy shall be furnished to the DOH Central Office.\\ +  * Upon patient consent, only the health care provider ​shall have access to the patient'​s ​health ​information and read-only access shall be given to secondary health care providers. \\ 
-  *Upon patient consent, only the attending physician ​shall have access to the patient'​s information and read-only access shall be given to secondary health care providers.\\+
   *Accessible information for secondary healthcare providers shall be the following:​\\   *Accessible information for secondary healthcare providers shall be the following:​\\
   ​   ​
Line 24: Line 24:
  
 **Access of Third Party**\\ **Access of Third Party**\\
-  ​* A "third party" ​in relation to personal data, means any person other than-\\ +   * A third party is allowed access to health information that is provided ​in the contract with the health care provider ​or as required by law.
-(a) the data subject, \\ +
-(b) the data controller, ​or\\ +
-(c) any data processor or other person authorized to process data for the data controller or processor.  +
-    * Patient'​s medical record shall not be accessible for case study purposes.\\ +
-    * Provisions regarding access of third party providers which use applications that are hosted in their cloud service shall be provided. Accountability of third party providers shall be made explicit.+
  
 //__Notes re: Third Party Relationships__//​\\ //__Notes re: Third Party Relationships__//​\\