Ryn Coleridge, director of enterprise systems and analytics and the agency's privacy officer, gave a board education session on HIPAA compliance and commissioners' responsibilities.
Coleridge said SFHSS is a component of a hybrid covered entity and reminded commissioners that when they receive protected health information (PHI), "it's governed by HIPAA" and that the legal test of disclosure is the "minimum necessary" standard. He outlined operational practices: avoid storing PHI on personal computers, route member inquiries through board staff (for triage and assignment), use de‑identification safe harbor when releasing aggregate data, and complete required cybersecurity training.
The presentation reviewed the 18 identifiers that must be removed under the safe‑harbor de‑identification method, examples of permissible uses for treatment, payment and operations, and possible civil penalties across four tiers and criminal penalties up to 10 years for willful neglect or intentional violations. Commissioners asked about practical steps for forwarding member emails and were directed to send inquiries to executive staff for triage.
Coleridge encouraged commissioners to contact the privacy officer before releasing any member information and said the department is providing secured laptops for commissioners to reduce risks from using personal devices.