Anytime you are accessing or using protected health information (PHI) held or transmitted by a covered entity subject to HIPAA protections, HIPAA applies. A covered entity is a (1) health plan, (2) health care clearinghouse, and (3) health care providers who electronically transmit any health information in connection with transactions. For example, doctors, clinics, hospitals, psychologists, dentists, nursing homes, pharmacies. HIPAA applies to MU Health Care records.
If you do not obtain a HIPAA authorization from patients to access or use their PHI in research, you must obtain a HIPAA waiver by the MU IRB.
If you are only accessing PHI of the deceased, then a HIPAA waiver does not apply. You should submit the “HIPAA-Research on Decedent’s Information form” to confirm HIPAA does not apply. Please contact MU Health Corporate Compliance at 573-882-5193 with questions on how to complete the form.