HIPAA-Compliant Patient Data-Use & Referral Workflow (Clinical-to-Development Firewall)
The operational rulebook specifying exactly how patient information moves from the EHR into development, what fields are permissible without authorization, and how the firewall is enforced — the artifact auditors scrutinize first.
Draft: pending review
This starter document is signed off by Health-system privacy officer (HIPAA) + hospital foundation counsel + compliance officer (Stark/AKS) + information-security lead before it ships. The guardrails below define that review.
What’s inside
- Permissible limited-data-set fields vs. data requiring authorization, in an allow/deny table
- Data-flow diagram: EHR → privacy gate → screening → development CRM, with logging at each hop
- Physician grateful-patient referral pathway that avoids improper PHI disclosure and referral-for-value
- Role-based access, minimum-necessary standard, and BAA requirements for CRM/screening/mail vendors
Legal & ethical guardrails
The sector-specific compliance points this document must honor.
- Build the allow/deny table on the §164.514(f) fundraising-permissible fields (demographics, dates & department of service, treating physician, outcome, insurance status) — NOT the separate §164.514(e) 'limited data set' (which excludes name/address). Anything richer (diagnosis, notes) requires §164.508 authorization, and the NPP must carry the fundraising statement before any data moves; importing clinical detail without authorization is a reportable violation
- Minimum-necessary and role-based access mean only named, trained staff touch the data set, and vendors require signed BAAs
- Physician referrals must avoid compensation for steering patients (Anti-Kickback/Stark) and impermissible PHI disclosure
- State laws (e.g., CA CMIA) and Part 2 substance-use records may be stricter than HIPAA and must be layered on
Held for professional review.
The native DOCX and full working text ship only after sign-off by Health-system privacy officer (HIPAA) + hospital foundation counsel + compliance officer (Stark/AKS) + information-security lead on this exact version. The summary and review requirements remain visible in the meantime.
Not legal advice. Not legal, tax, or accounting advice. The Fundraising Co. provides educational fundraising materials and is not a law firm; nothing here creates an attorney–client relationship or substitutes for advice from professionals licensed in your jurisdiction. Laws and IRS rules vary by state and change over time. Review every document with qualified counsel before use.