[§323C-13] Notice of confidentiality practices; forms of notices.
(a) For the purposes of this section only, "entity" means [a] health care provider, health care data organization, health plan, health oversight agency, public health authority, employer, insurer, health researcher, or educational institution.(b) An entity shall prominently post or provide the current notice of the entity's confidentiality practices. The notice shall be printed in clear type and composed in plain language. This notice shall be given pursuant to the requirements of section 323C-22. For the purpose of informing each individual of the importance of the notice and educating the individual about the individual's rights under this chapter, the notice shall contain the following language, placed prominently at the beginning:
IMPORTANT: THIS NOTICE DEALS WITH THE SHARING OF INFORMATION FROM YOUR MEDICAL RECORDS. PLEASE READ IT CAREFULLY. This notice describes your confidentiality rights as they relate to information from your medical records and explains the circumstances under which information from your medical records may be shared with others. This information in this notice also applies to others covered under your health plan, such as your spouse or children. If you do not understand the terms of this notice, please ask for further explanation.
In addition, as shall be appropriate to the size and nature of the entity, the notice shall include information about:
(1) A description of an individual's rights with respect to protected health information which shall contain at a minimum, the following:
(A) An individual's right to inspect and copy their record;
(B) An individual's right to request that a health care provider append information to their medical record; and
(C) An individual's right to receive this notice by each health plan upon enrollment, annually, and when confidentiality practices are substantially amended.
(2) The uses and disclosures of protected health information authorized under this chapter including information about:
(A) Payment;
(B) Conducting quality assurance activities or outcomes assessments;
(C) Reviewing the competence or qualifications of health care professionals;
(D) Performing accreditation, licensing, or credentialing activities;
(E) Analyzing health plan claims or health care records data;
(F) Evaluating provider clinical performance;
(G) Carrying out utilization management; or
(H) Conducting or arranged for auditing services in accordance with statute, rule or accreditation requirements;
(3) The right of the individual to limit disclosure of protected health information by deciding not to utilize any health insurance or other third party payment as payment for the service, as set forth in section 323C-21(c);
(4) The procedures for giving consent to disclosures of protected health information and for revoking the consent to disclose;
(5) The description of procedures established by the entity for the exercise of the individual's rights required under this chapter; and
(6) The right to obtain a copy of the notice of confidentiality practices required under this chapter.
(c) The actual procedures established by the entities for the exercise of individual rights under this part shall be available in writing upon request. [L 1999, c 87, pt of §2]