Pregnancy Companion
Privacy
Maternl© considers privacy a first order of priority for its users.
What we collect
Maternl© does not collect or store any user identifiers, with two exceptions: a first name in some modules, and an email address when you voluntarily provide one so we can send you information you've requested.
How your privacy is protected
- No stored identifiers. No user identifiers are collected or stored in our databases, except an email address when one is needed.
- Anonymous usernames. Used wherever a username is required.
- Encrypted passwords. Where a password is required, it is hashed before storage. In the Maternl© SSL database it appears only as a 32-character value that cannot be reversed into the original password.
- Limited use of data. Any information collected is used solely to understand and improve the program.
- You remain anonymous. You cannot be identified from this information unless you voluntarily add identifying details.
- Secure transmission. The entire program resides on a secure (SSL) server and all information is transmitted encrypted.
- No tracking cookies. No cookies are used to track users.
HIPAA and Maternl©
Maternl© is a stand-alone program, open to the public on the Internet, and is not associated, affiliated, or connected with any HIPAA "covered entity." HIPAA Privacy Rules therefore do not apply to Maternl©. Nonetheless, Maternl© was designed to preserve user anonymity: no personal identifiers are requested and no tracking cookies are used.
The reference material below is provided for informational purposes.
HIPAA Protected Health Information: the 18 identifiers
- Names
- All geographic subdivisions smaller than a state — street address, city, county, precinct, ZIP code, and equivalent geocodes — except the initial three digits of a ZIP code if, per current Census Bureau data: (a) the geographic unit formed by all ZIP codes with those three initial digits contains more than 20,000 people, and (b) the initial three digits for units of 20,000 or fewer people are changed to 000
- All elements of dates (except year) directly related to an individual, including birth date, admission date, discharge date, and date of death; and all ages over 89 and all date elements (including year) indicating such age, except that these may be aggregated into a single "age 90 or older" category
- Phone numbers
- Fax numbers
- Email addresses
- Social Security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate and license numbers
- Vehicle identifiers and serial numbers, including license plate numbers
- Device identifiers and serial numbers
- Web URLs
- IP addresses
- Biometric identifiers, including finger and voice prints
- Full-face photographic images and any comparable images
- Any other unique identifying number, characteristic, or code (this does not include a unique code assigned by the investigator to code the data)
Protection against re-identification
Additional standards apply beyond removing the 18 identifiers. Any code used to replace identifiers in a dataset cannot be derived from information related to the individual, and neither the master codes nor the method used to derive them may be disclosed. For example, a subject's initials cannot be used to code their data, because initials are derived from their name. The researcher must also have no actual knowledge that a subject could be re-identified from the remaining information. In other words, information is still considered identifiable if a way to identify the individual exists, even after all 18 identifiers have been removed.
What is PHI?
Protected health information (PHI) is any information in a medical record or designated record set that can be used to identify an individual and that was created, used, or disclosed in the course of providing a health care service such as diagnosis or treatment. HIPAA regulations allow researchers to access and use PHI when necessary to conduct research. However, HIPAA only affects research that uses, creates, or discloses PHI that will be entered into the medical record or used for health care services such as treatment, payment, or operations.
For example, PHI is used in studies involving review of existing medical records, such as retrospective chart review. Studies that create new medical information because a health care service is performed as part of the research — diagnosing a condition, or testing a new drug or device — also create PHI that will be entered into the medical record. Sponsored clinical trials that submit data to the U.S. Food and Drug Administration involve PHI and are therefore subject to HIPAA regulations.
What is not PHI?
Some research studies use person-identifiable data — including identifiers such as name and address — that is nonetheless not PHI, because the data are not associated with or derived from a health care service event (treatment, payment, operations, medical records), are not entered into the medical record, and the results are not disclosed to the subject. Research health information kept only in the researcher's records is not subject to HIPAA, though it remains regulated by other human subjects protection regulations.
Examples include the use of aggregate data, diagnostic tests that do not go into the medical record because they are part of a basic research study whose results will not be disclosed to the subject, and testing done without PHI identifiers. Some basic genetic research falls into this category, such as searches for potential genetic markers, promoter control elements, and other exploratory work. By contrast, genetic testing for a known disease as part of diagnosis, treatment, or health care does use PHI and is subject to HIPAA.
Health information by itself, without the 18 identifiers, is not PHI. A dataset of vital signs alone does not constitute protected health information. However, if that dataset includes medical record numbers, the entire dataset must be protected because it contains an identifier. PHI is anything that can be used to identify an individual — private information, facial images, fingerprints, voiceprints — whether associated with medical records, biological specimens, biometrics, datasets, or direct identifiers of research subjects in clinical trials.