A new member of the PIC asks, "The OFI we're talking about will use patient data on outcomes and satisfaction to evaluate new functional protocols. Are we allowed to do that under HIPAA rules? Do we need IRB approval?" As internal consulting (IC) staff to the PIC, you answer:
Question 21 options:
1)
"That's a complex question. I'll have to check with our counsel and get back to you."
2)
"For HIPAA, we deidentify the patients. For IRB, HHS has established an explicit right for HCOs to use data for process improvement without IRB approval."
3)
"That's a great question. I'm glad you asked, because we always want to follow the letter and spirit of the law."
4)
"HIPPA is no problem, but IRB approval might be a good idea."