University Privacy Office
- Home
- Training
- Reporting
- What is HIPAA
- Designated Components and ACE
- FAQs
- Data Privacy IRP
- Red Flag
- FERPA
- Forms and Policies
- Resources
Contact Us
Institutional Privacy
The University of Toledo (UToledo) is committed to safeguarding the privacy and confidentiality of the sensitive information entrusted to us by our patient customers. This includes protecting Protected Health Information (PHI) and Education records and Personally Identifiable Information (PII) From Education records through appropriate administrative, technical, and physical safeguards.
UToledo complies with all applicable federal and state privacy laws and regulations. The primary federal laws governing these obligations include:
- Health Insurance Portability and Accountability Act (HIPAA) for protected health information.
- Family Educational Rights and Privacy Act (FERPA) for student education records and personally identifiable information.
The UToledo Privacy Office, in partnership with the University Privacy and Information Security Committee, is dedicated to maintaining compliance with these requirements and fostering a culture of privacy and security throughout the institution.
Protected Information
Protected information includes data that is defined as confidential, sensitive, or otherwise protected under applicable federal and state laws, regulations, and University policies. For purposes of identifying protected health and student information, UToledo adopts and incorporates by reference the classifications and identifiers established in the following policies:
- Protected Health Information (PHI): The identifiers and data elements that constitute PHI are defined in the University's De-Identifiable and Re-Identifiable Health Information, Limited Data Set and Data Use agreement, which is based on the HIPAA Privacy Rule's list of identifiers.
- Student Information: Personally identifiable information contained within education records is defined and governed by the University's Confidentiality of Student Information (FERPA) Policy, which outlines the categories of information protected under FERPA and related regulations.
Information that falls within the definitions established by these policies must be afforded appropriate administrative, technical, and physical safeguards.
Process owners may implement additional protections and designate additional categories of information as protected; however, they may not reduce the level of protection required by University policy or remove data elements identified as protected under applicable laws, regulations, or University policies.
University policy requires that all PHI and Education records and Personally Identifiable Information (PII) From Education records that is communicated electronically be encrypted, at a minimum. View the email encryption page for guidance on the required method of encryption when transmitting PHI/ Education records and Personally Identifiable Information (PII) From Education records is required. As a reminder, transmitting PHI/ Education records and Personally Identifiable Information (PII) From Education records is strongly discouraged and should only be attempted with the knowledge and consent of the leader of your unit. And under no circumstances should data containing PHI/ Education records and Personally Identifiable Information (PII) From Education records stored on an unencrypted portable device. Refer to the University Policy webpage for additional guidance for protecting all forms of UToledo data.
Please feel free to contact the University Privacy Office, the IT Help Desk, or the IT Security Office for further guidance on this subject.
What is HIPAA?
The Health Insurance Portability and Accountability Act (HIPAA) is a federal law that establishes standards for protecting the privacy and security of individuals' health information. HIPAA also sets requirements for how healthcare organizations and their business associates use, disclose, and safeguard protected health information.
Key objectives of HIPAA include:
- Improve the portability and continuity of health insurance coverage for individuals and groups
- Promote the use of medical savings accounts
- Improve access to long-term care services and coverage
- Provide established policies, procedures, and safeguards for security and privacy of patient data and patient related systems
- Simplify administrative procedures
What Are My Responsibilities?
Protecting confidential information is the responsibility of every member of the UToledo community, including faculty, staff, students, volunteers, contractors, and business associates.
Individuals who access PHI, Education records and Personally Identifiable Information (PII) from Education records or other confidential University information must:
- Complete required privacy and security training.
- Access information only as necessary to perform assigned duties.
- Protect confidential information from unauthorized access, use, disclosure, alteration, or destruction.
- Follow all applicable University policies and procedures.
- Immediately report any suspected privacy, confidentiality, or security incident to the appropriate University office.
Failure to comply with privacy and security requirements may result in disciplinary action, up to and including termination of employment or affiliation, loss of privileges, civil penalties, criminal penalties, and other sanctions as permitted by law.
The University is committed to maintaining a culture of privacy, security, and accountability, and every member of the UToledo community plays an important role in protecting the information entrusted to us.