📰 K-12 Question of the Month: What is your organization doing to manage and protect PII and PHI? | Experience Community
Skip to main content

📰 K-12 Question of the Month: What is your organization doing to manage and protect PII and PHI?

  • October 12, 2021
  • 1 reply
  • 26 views

SaraL
Qualtrics Employee
Forum|alt.badge.img

Hi K-12 colleagues! My name is Sara Laskey, a Senior Industry Advisor for Public Health and Education here at Qualtrics. I wanted to take a moment to add my thoughts and answer a few questions that I have been asked often over the past couple of months.
Since the pandemic started, institutions and school districts of all sizes have had to concern themselves with the personal health information of their employees.  Whether performing daily symptom screens, contact tracing employees who may have been exposed or now, requiring employees to share vaccination records or COVID test results, this is new and confusing territory for HR leaders, frontline managers and corporate risk.
Over the past 18 months, Qualtrics has developed and implemented multiple solutions for workplace safety and public health -  from end-to-end COVID testing systems for states to symptom checking and contact tracing used at hundreds of colleges, school districts and companies.  
In that time, a number of important questions on employee privacy and protected health information (PHI) have consistently come up.  The recent US COVID vaccination and testing requirements have only increased the volume and urgency to address this important topic.
Here are some of the most frequently asked questions to help teams navigate the complex world of employee privacy and COVID vaccination, testing and symptom attestation. 
What is the difference between PII and PHI?
PHI (protected health information) is any health information that can be tied to an individual.  This is important ONLY if your organization is in an industry that is covered by the HIPAA privacy and security rules.  
PII (personally identifiable information) is any data that could potentially identify a specific individual - regardless of whether it is used for healthcare purposes. 
Per EEOC recommendations, companies must allow for appropriate accommodations for employees with disabilities.
What is HIPAA?
HIPAA (The Health Insurance Portability and Accountability Act) requires covered entities to implement safeguards to ensure the confidentiality, integrity and availability of protected health information.
Who are covered entities under HIPAA?
Covered entities are those that provide healthcare, healthcare operations and payment for healthcare services.  In simpler terms, hospitals, providers, insurance companies, clinics, etc.
If my company collects health information from employees is this protected information?
According to HHS, if an employer asks an employee to provide proof of vaccination or test results that is not a HIPAA violation, employees may decide whether or not to provide that information to their employer. 
What if my employees receive vaccines or test results through an onsite clinic?
If you provide an onsite clinic and/or administer a self-insured health plan you are subject to ‘partial compliance’ and are required to provide certification the PHI will be safeguarded and not used for employment-related actions. https://www.hipaajournal.com/does-hipaa-apply-to-employers/
Trust and transparency are critical components to the employer-employee relationship.  Qualtrics is here to help every company in any industry help maintain those key features as we all navigate through this future of work.
Now I want to ask you: What is your organization doing to manage and protect PII and PHI?

1 reply

julia_campbell_1
Level 2 ●●
Forum|alt.badge.img+10

Thank you for distilling this info & sharing!