The Oklahoma Department of Human Services (DHS) limits requests for, use of, and disclosure of protected health information (PHI) to that which is reasonably necessary to accomplish the intended purpose of the use, disclosure, or request, per Section 164.502(b) of Title 45 of the Code of Federal Regulations ( 45 C.F.R. § 164.502(b)) . This minimum necessary standard is not used to impede the essential activities of treatment, payment, or health care operations.
(1) The minimum necessary standard applies to: (A) the use of PHI within DHS. Employees who: (i) do not need PHI to perform their job duties must not access PHI; and(ii) need PHI to perform their job duties must access PHI to the least extent necessary;(B) disclosure of PHI to a third party in response to a request; and(C) the request of PHI from another covered entity.(2) The minimum necessary standard does not apply to disclosures made: (A) to or requests by a health care provider for treatment;(C) with a valid authorization, per 45 C.F.R. § 164.508(c);(D) to the United States Secretary of Health and Human Services for the purposes of compliance with the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule; or(E) for uses required by law.Okla. Admin. Code § 340:2-8-10
Added at 20 Ok Reg 2907, eff 8-21-03 (emergency); Added at 21 Ok Reg 784, eff 4-26-04Amended by Oklahoma Register, Volume 36, Issue 24, September 3, 2019, eff. 9/16/2019