How will the Privacy Rule affect me as a researcher at UMass Amherst?
If you are not doing research that requires access to protected health information (PHI), HIPAA and the Privacy rule will not impact your research. UMass Amherst researchers who need access to their subject’s PHI for research purposes should understand the structure of UMass Amherst as an organization under HIPAA. Under HIPAA, UMass Amherst is a hybrid entity. University Health Services (UHS) is a covered entity i.e. covered by HIPAA; the rest of the University is not. Researchers within a covered entity may use PHI generated and stored in that entity for their research. Researchers outside a covered entity (like most UMass Amherst PIs) must request the covered entity, via a signed authorization from the subject, to “disclose” the subject’s PHI to them. This includes requests for review of medical records except where a waiver has been obtained. Once a covered entity discloses PHI to a researcher outside the covered entity, HIPAA and the Privacy rule no longer cover those records. Howe