You are on page 1of 4

PRIVACY AND

RECORDS
MANAGEMENT

Respecting
Veterans Privacy
The Department of Veterans Affairs (VA) How VA Employees Comply with
understands and appreciates the trust you, Privacy Requirements
America’s Veterans, place in our ability to provide
à Awareness. Even if a VA employee does not
quality healthcare and benefits. We realize your
handle claims folders or patient medical
trust is based on our capacity to protect your
records or work in a VA hospital, he or she
personally identifiable information (PII). VA is
may have direct or casual access to your PII.
continuously developing ways to safeguard
Therefore, all employees and contractors
Veterans’ information by creating a culture of
must sign rules of behavior annually to ensure
accountability among its employees, contractors,
they understand their legal responsibilities to
business associates, and volunteers.
protect the confidentiality of Veterans’ and
The VA Privacy Service oversees and supports all their beneficiaries’ PII in all forms —
efforts within VA to protect the privacy of electronic, paper, and verbal.
Veterans’, beneficiaries’, and VA employees’ PII.
à Training. VA requires annual mandatory privacy
The VA Privacy Service develops and implements
awareness and information security training for
VA-wide programs, products, and policies that are
all employees and contractors. Specialized
implemented locally by Privacy Officers across the
privacy training is also available for Privacy
country. This approach ensures all privacy laws
Officers, Information Technology specialists,
and regulations are applied consistently
supervisors, and healthcare professionals.
throughout the Department.
Our employees know they must exercise care not
Laws to Keep Your Information Private to disclose information inadvertently, and that
discussing protected information in public or
There are numerous Federal laws and regulations
private with employees, family, friends, or others
that address the collection, use, and disclosure of
who do not have a need to know the information
PII; the two most important are the Privacy Act of
is a violation of federal law.
1974 and the Health Insurance Portability and
Accountability Act (HIPAA). You should understand If a VA employee or contractor violates privacy
the rights you have under these two laws. requirements, he or she could face disciplinary
action as well as criminal and monetary penalties
Privacy Act of 1974 outlines how the Federal
for each violation. Penalties may also apply to his
Government, including VA, collects, maintains,
or her supervisor and to VA as a whole.
uses, and discloses personally identifiable
information (PII) that can be retrieved by a
personal identifier such as your name, SSN,
medical record number, or other unique identifier.
The Act protects all of your information
maintained in agency systems of records — not
just health information — and covers all written
and verbal communication of such information.
The Department of Veterans Affairs (VA) HIPAA expands existing privacy protections and àà The right to request that VA not use or disclose
understands and appreciates the trust you, standardizes them for public and private your protected health information (PHI); and
America’s Veterans, place in our ability to provide healthcare providers, including the Veterans
àà Restricts the use and disclosure of your PHI
quality healthcare and benefits. We realize your Health Administration (VHA).
that is maintained by healthcare providers,
trust is based on our capacity to protect your
including VHA.
personally identifiable information (PII). VA is Your Rights to Privacy at VA
continuously developing ways to safeguard In general, VHA must have written authorization
Under both laws, you are allowed to:
Veterans’ information by creating a culture of to use and disclose PHI. However, authorization is
accountability among its employees, contractors, àà Access, review, and obtain copies of records not required in certain circumstances:
business associates, and volunteers. that the Federal Government maintains about
àà Treatment,
you, including medical records;
The VA Privacy Service oversees and supports all
àà Payment,
efforts within VA to protect the privacy of àà Request an amendment to records that are
Veterans’, beneficiaries’, and VA employees’ PII. incorrect; and àà Healthcare operations,
The VA Privacy Service develops and implements
àà Obtain an accounting or list of disclosures of àà Eligibility and enrollment for VA benefits,
VA-wide programs, products, and policies that are
information about you.
implemented locally by Privacy Officers across the àà Dealing with family members or others
country. This approach ensures all privacy laws In addition, the Privacy Act: involved with your care (with limitations); and
and regulations are applied consistently
àà Creates a code of “fair information practices” that àà Other uses as allowed by law (please review
throughout the Department.
mandates how the Federal Government, including the VA Notice of Privacy Practices for the
VA, maintains information about you; and complete list).
Laws to Keep Your Information Private
àà Restricts disclosure of PII that is maintained by Furthermore, HIPAA requires VHA to have written
There are numerous Federal laws and regulations
the Federal Government, including VA. privacy procedures, designated Privacy Officers
that address the collection, use, and disclosure of
(Information can only be disclosed under for each facility, and privacy training for all
PII; the two most important are the Privacy Act of
certain situations permitted by law. Otherwise, employees and contractors.
1974 and the Health Insurance Portability and
information cannot be disclosed without your
Accountability Act (HIPAA). You should understand
prior written authorization.) Reporting Privacy Issues
the rights you have under these two laws.
In addition, HIPAA requires that VHA provide If you have a VA privacy concern or question, or if
Privacy Act of 1974 outlines how the Federal
the following: you believe that your privacy rights have been
Government, including VA, collects, maintains,
violated, contact the Privacy Officer at your
uses, and discloses personally identifiable àà A copy of VA’s Notice of Privacy Practices
nearest VA facility, or talk to your Patient Advocate
information (PII) that can be retrieved by a (you can obtain a copy of this notice from
or Veteran Service Organization representative.
personal identifier such as your name, SSN, your local VHA health care facility, or
medical record number, or other unique identifier. download the notice at
The Act protects all of your information http://www1.va.gov/vhapublications/
maintained in agency systems of records — not viewpublication.asp?pub_id=1089;
just health information — and covers all written
and verbal communication of such information.
Connect with Us
For more information, visit
http://www.privacy.va.gov

VA Pamphlet 005-12-8

You might also like