Minnesota Minnesota

Manual

Manual


Title III Administrative and Financial Requirements Policy #14: Confidentiality and Disclosure of Information

This content is part of a public comment period. For more information, refer to Minnesota Board on Aging – State Plan on Aging.

Authority Reference

45 CFR 1321.75

Minnesota Statutes 13.04 (MN Government Data Practices Act, Chapter 13, Rights of Subjects of Data)

Minnesota Statutes, section 13.055

Operating Category

Title III Administrative and Financial Requirements

Policy

1. MBA, AAAs, Senior LinkAge Line, and Title III service providers shall have procedures to protect the confidentiality of information about older individuals and family caregivers collected in the conduct of their responsibilities. The procedures shall ensure that no information about an older person or family, friends, and neighbors caregiving, or obtained from an older person or family, friends and neighbors caregiving by a service provider, MBA, or AAA, is disclosed by the provider or agency in a form that identifies the person without the informed consent of the person or of their legal representative, unless the disclosure is required by law or court order, or for program monitoring and evaluation by authorized Federal, State, or local monitoring agencies.

2. For purposes of this policy, “confidential information about individuals” includes both of the following:

A. Personal Identifiable Information (PII), which means “information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual”. (Office of Management and Budget (OMB) Memoranda M-17-12, January 3, 2017). Examples of PII include name, Social Security number, address, email address, and date of birth.

B. Personal Health Information (PHI), which includes individuals' medical records and other individually identifiable health information.

3. For purposes of administering Title III services, Title III service providers, AAAs, and MBA must not collect social security numbers for older individuals or individuals caregiving interested in or receiving Title III services.

4. Entities providing Title III services must promote the rights of individuals receiving services, including the right to confidentiality of their records. Information gathered by service providers about Title III clients may not be used for other purposes without the consent of the client.

5. The MBA has a multi-faceted approach to protecting confidential information collected, maintained, used, and exchanged by service providers, AAAs, and MBA in the course of their duties. This approach includes training, use of clear language to explain under what circumstances information may be disclosed, limitations on access to data about individuals, and security protocols.

6. The MBA, AAAs, and service providers must use practices consistent with the Minnesota Government Data Practices Act when collecting information about individuals.

A. Prospective clients are asked to provide information about themselves as part of a screening and registration process with NAPIS forms. As required by Minnesota Statutes, section 13.04, subdivision 2, service providers must either read the “Tennessen warning notice” to clients or ensure clients have reviewed it as they work with a client to complete a NAPIS form.

  • · i. The Tennessen warning notice requires that an individual asked to supply private or confidential data concerning the individual shall be informed of: (a) the purpose and intended use of the requested data within the collecting government entity; (b) whether the individual may refuse or is legally required to supply the requested data; (c) any known consequence arising from supplying or refusing to supply private or confidential data; and (d) the identity of other persons or entities authorized by state or federal law to receive the data.
  • · ii. Service providers must inform clients that individual information and records may be shared with other State and local agencies, community-based organizations, and health care providers and payers to facilitate the provision of services.
  • 7. The MBA requires MBA employees, AAAs and service providers to participate in training courses described in the “Procedures” section below to ensure employees and volunteers are aware of federal and state requirements related to certain types of personal data and information.

    8. AAAs and service providers must have measures in place to prevent not public data from being shared with or accessed by those who do not have a work assignment requiring access to not public data. These measures may include, but are not limited to:

    A. securing not public data within locked work spaces and in locked file cabinets; 

    B. limiting access to shared folders or databases containing not public information; 

    C. locking computers and/or office spaces when leaving them unattended; 

    D. using secure print functions (e.g., “hold badge” print options) when printing not public data on shared printers; 

    E. securely disposing of not public data (e.g., disposing of hard copies in locked shred bins); and

    F. limiting attendance in meetings involving discussion of not public data to only those whose work assignment requires access to the data. 

    9. Prohibitions on disclosure

    A. The MBA and AAAs or other contracting or granting or auditing agency may not require a provider of long-term care ombudsman services to reveal any information that is protected by disclosure provisions in 45 CFR part 1324, subpart A.

    B. The MBA and AAAs shall not require a provider of legal assistance under this part to reveal any information that is protected by attorney client privilege.

    10. MBA, AAAs, and service providers must comply with all applicable Federal laws as well as guidance as the State of Minnesota determines, for the collection, use, and exchange of both Personal Identifiable Information (PII) and personal health information in the provision of Title III services under the Act.

    11. The “Procedures” section of this policy refers to PeerPlace, which is a software program currently used by Minnesota’s aging network. This policy applies both to PeerPlace or any successor program used for similar purposes.

    12. MBA, AAAs, and service providers must exercise caution to prevent data breaches.

    A. A data breach occurs when all of the following apply:

  • · i. A person
  • · ii. Views or takes private or confidential data:
  • · iii. Without permission or statutory authority, and
  • · iv. With the intent to use the private or confidential data for nongovernmental purposes
  • B. AAA and service provider employees, contractors, volunteers, external auditors, interns, and any individuals having access to MBA data and systems are required to promptly and appropriately respond to all data privacy and security incidents. This means reporting all incidents of possible unauthorized access, use, or disclosure of not public data. If a data privacy and security incident occurs, this should first be immediately reported to a supervisor, who must in turn notify the MBA Executive Director.  This process helps safeguard the security of not public data by allowing incidents to be timely investigated and mitigated, by facilitating the timely notification of individuals if an incident is determined to be a breach, and by allowing DHS to reduce the risk of future incidents. 

    C. Any entity receiving MBA funds (OAA, CMS, and/or State of Minnesota funding), including AAAs and service providers, must disclose any breach of private or confidential data to affected individuals who are the subjects of the data when they reasonably believe a qualifying breach has occurred. The required notice to individuals must:

  • · Be in writing
  • · Inform the individual that a report will be prepared about the breach investigation
  • · State that an individual may request a copy of the report by mail or email
  • · Be sent without unreasonable delay
  • Please refer to the Procedures section of this policy for a template notification letter.

    13. MBA, AAA and service provider employees, contractors, volunteers, external auditors, interns, and any individuals having access to data and systems shall not use, disclose, or access not public data, including data about themselves, for any reason except what is required to complete a work assignment or is permitted by state or federal law.  Sanctions and penalties may be imposed for willful violations of this policy or the provisions of the MGDPA, as provided for in Minnesota Statutes, section 13.09, as necessary.  Sanctions include disciplinary action, up to and including termination, and/or referring the matter to the appropriate prosecutorial authority to determine possible criminal charges. 

    Procedures

    1. AAA employees are required to take a suite of State of Minnesota trainings called “Handling MN Information Securely” that collectively relate to confidentiality and disclosure of information. This training is available on-line in an on-demand format. New employees must take this training within three business days of starting their position. All employees must take the training on an annual basis. MBA will monitor whether training has been completed.

    2. The MBA uses the State of Minnesota’s Tennessen warning to ensure clients understand the purpose of collecting data about them and for what purposes the data may be disclosed. The Tennessen warning language is included on all NAPIS forms and must be reviewed with participants as part of the NAPIS form completion process.

    3. AAAs are strongly encouraged to require service providers to directly enter or to use approved technological devices to submit client data into PeerPlace whenever possible. This reduces the number of individuals with access to or handling client data.

    4. Service provider employees who need access to PeerPlace to perform their professional responsibilities must sign and return the PeerPlace Memorandum of Understanding to MBA prior to when they first obtain access to PeerPlace and annually as long as their system access is needed. MBA will disseminate this Memorandum of Understanding form on an annual basis.

    5. Users of the PeerPlace system must not share their access credentials.

    6. MBA, AAAs, and service providers must promptly terminate access for employees whose employment relationship with the organization ends or if the employee no longer needs access to PeerPlace because such access is no longer required to perform professional responsibilities.

    7. AAAs and service providers may use this sample breach notification letter if a breach occurs.

    Report this page