HUD is the U.S. Department of Housing and Urban Development, the federal agency responsible for national housing policy and for funding the country's response to homelessness. Through homeless assistance programs such as the Continuum of Care (CoC) Program and the Emergency Solutions Grants (ESG) Program, HUD funds local agencies and requires the communities it funds to use a Homeless Management Information System (HMIS). An HMIS is a local database that records who is being served, what services they receive, and how the local system is performing. Since that database holds sensitive information about people in crisis, HUD set privacy and security rules for it in its 2004 Data and Technical Standards Final Notice. The HMIS privacy and security standards apply to any "Covered Homeless Organization" (CHO), meaning an organization that records, uses, or processes "protected personal information" (PPI) about homeless clients for an HMIS. PPI includes any information that identifies a person directly or indirectly, or can be linked with other information to do so. It is not limited to health data.
On the other hand, HIPAA, the Health Insurance Portability and Accountability Act of 1996, is a federal law whose Privacy and Security Rules are issued by the U.S. Department of Health and Human Services (HHS) and enforced by its Office for Civil Rights. HIPAA governs protected health information (PHI) held by covered entities, such as health plans, clearinghouses, and providers who bill electronically, and by their business associates. It aims to protect protected health information (PHI) while allowing it to be used for treatment, payment, and healthcare operations.
HIPAA was the blueprint
The Data and Technical Standards Final Notice says the standards "were developed after careful review of the Health Insurance Portability and Accountability Act (HIPAA) standards for securing and protecting patient information". In its response to public comments, HUD went further, "Although most homeless programs are not subject to HIPAA, HUD recognizes that the HIPAA privacy rule establishes a national baseline of privacy standards for most health information. Accordingly, the HIPAA privacy rule was used as a guide for developing the HMIS privacy standards."
The final notice also described a shared philosophy, "Like HIPAA, the HMIS final Notice strikes a balance between important and responsible uses of information and protecting the privacy of homeless persons who seek services."
Where they overlap
Notice to clients
HIPAA requires a Notice of Privacy Practices. The regulation says an individual "has a right to adequate notice of the uses and disclosures of protected health information that may be made by the covered entity, and of the individual's rights and the covered entity's legal duties with respect to protected health information.” HMIS requires a published privacy notice describing how PPI is collected, used, and disclosed, plus a sign at each intake desk explaining the reasons for collection and a sign stating that the notice is available on request.
Client access and correction
Both frameworks let individuals inspect their records and request corrections. HIPAA states that "an individual has a right of access to inspect and obtain a copy of protected health information about the individual in a designated record set". The exceptions include psychotherapy notes and "[i]nformation compiled in reasonable anticipation of, or for use in, a civil, criminal, or administrative action or proceeding", which is similar to the HMIS standards. Under HMIS, an organization may deny access on limited grounds, such as that litigation exception or information that could endanger someone's safety, and it must explain any denial.
Security safeguards
HMIS baseline security covers user authentication, virus protection, firewalls, backups, disaster recovery, access logs, and encryption of data transmitted over public networks. HIPAA's Security Rule addresses similar protocols. It starts by requiring covered entities and business associates to "conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate." The Privacy Rule adds a general duty to have "appropriate administrative, technical, and physical safeguards to protect the privacy of protected health information."
Permitted disclosures without consent
Both frameworks allow disclosures required by law, to avert a serious threat to health or safety, about victims of abuse, neglect, or domestic violence, for research under written agreements, and for law enforcement. HIPAA's list is found at 45 CFR § 164.512, which allows a covered entity to use or disclose PHI "without the written authorization of the individual. . .or the opportunity for the individual to agree or object" in the situations it covers. The serious-threat provision permits disclosure that "is necessary to prevent or lessen a serious and imminent threat to the health or safety of a person or the public" and "is to a person or persons reasonably able to prevent or lessen the threat, including the target of the threat". HUD drew from HIPAA's law enforcement provisions. It calls its oral-request provision "comparable to HIPAA," and says its written-request requirement "is more restrictive than HIPAA."
Complaints and confidentiality
Each requires a way to accept complaints. HIPAA says a covered entity "must provide a process for individuals to make complaints concerning the covered entity's policies and procedures" or its compliance with them, and it may not "intimidate, threaten, coerce, discriminate against, or take other retaliatory action against any individual" for filing one. HMIS requires staff to sign confidentiality agreements acknowledging the privacy notice. HIPAA enforces workforce accountability through sanctions, it notes that a covered entity "must have and apply appropriate sanctions against members of its workforce who fail to comply."
Where they differ
Consent
HIPAA permits use and disclosure of PHI for treatment, payment, and operations without specific authorization. Its consent provision is optional, "A covered entity may obtain consent of the individual to use or disclose protected health information to carry out treatment, payment, or health care operations". HHS guidance confirms that a covered entity "may voluntarily choose, but is not required, to obtain the individual's consent" for those purposes. However, HMIS notes that at the collection stage, "Consent of the individual for data collection may be inferred from the circumstances of the collection". Uses and disclosures not described in the privacy notice require consent or a legal mandate. HUD acknowledged the difference, noting that "in several instances the HMIS baseline requirements exceed the requirements in the HIPAA privacy rule," while elsewhere the standards "diverge from HIPAA" where its requirements would be impractical for programs that register large numbers of clients daily.
Training and privacy officers
HIPAA requires workforce training and a designated privacy official. The regulation states that "a covered entity must designate a privacy official who is responsible for the development and implementation of the policies and procedures of the entity." It also requires a covered entity to "train all members of its workforce on the policies and procedures with respect to protected health information. . .as necessary and appropriate for the members of the workforce to carry out their functions within the covered entity", and to document that the training took place. Under the HMIS framework, the requirement is a signed confidentiality agreement. Formal privacy training and a chief privacy officer appear only as optional "additional privacy protections."
Two tiers
HUD describes their approach as providing "a uniform floor of protection for homeless clients with the possibility of additional protections for organizations with additional needs or capacities." HIPAA imposes one set of requirements on all covered entities, though it lets them scale their implementation, the regulation states that policies "must be reasonably designed, taking into account the size and the type of activities that relate to protected health information undertaken by a covered entity." The difference is that HIPAA scales how you comply, while HMIS makes some protections optional.
Scope and enforcement
HIPAA protects health information held by covered entities and is enforced by the HHS Office for Civil Rights, with civil and criminal penalties. HMIS covers any PPI, health-related or not, held by participating organizations.
HIPAA takes precedence
HUD's precedence provision, the final notice states that, "Any CHO that is covered under the HIPAA is not required to comply with the privacy or security standards in this Notice if the CHO determines that a substantial portion of its PPI about homeless clients or homeless individuals is protected health information as defined in the HIPAA rules."
HUD gave three reasons, HIPAA is "more finely attuned to the requirements of the health care system," it provides "important privacy and security protections for protected health information," and "requiring a homeless provider to comply with or reconcile two sets of rules would be an unreasonable burden." The goal was to avoid conflict, "Exempting HIPAA covered entities from the HMIS privacy and security rules avoids all possible conflicts between the two sets of rules."
Furthermore, the final notice states that, "Where a homeless service provider is not a covered entity under HIPAA, it is subject to the HMIS privacy and security standards. A provider is also subject to applicable state and local privacy laws."
FAQs
Can a shelter with an on-site clinic follow different rules for different records?
Yes, the HMIS standards expect split operations, where one part of the organization is governed by HMIS and another by HIPAA.
Is HUD's 128-bit encryption standard still enough?
No, because that specification reflects 2004 technology, so agencies should use current encryption standards in practice.
Does HMIS require me to notify clients of a data breach?
HUD does not prescribe a breach-response method or timeline, but it expects your privacy notice to describe your process, and other laws or your HMIS lead's policy may add requirements.
