The Defense Health Agency Privacy and Civil Liberties Office is responsible for providing guidance to the enterprise on managing and safeguarding personally identifiable information as well as protected health information
Our Mission
Ensure vigilance in the protection of privacy information and promote compliance across the organization.
What We Do
We enforce compliance with Federal statute and Department of Defense privacy & civil liberties related regulation and policy throughout the Military Health Service. This includes managing and evaluating potential risks and threats to the privacy and security of MHS health data by performing critical reviews and conducting:
- Evaluation of privacy and security safeguards, including conducting annual Health Insurance Portability and Accountability Act (HIPAA) of 1996 Security Risk Assessments
- Performance of Internal Privacy Office Compliance Assessments
- Establishment of organizational performance metrics to identify and measure potential compliance risks
- Consultation for leadership and the workforce on areas of DHA-level oversight
In addition, the DHA Privacy Office has specific responsibility for various DHA-level areas. We support HIPAA development to comply with Federal laws, DOD regulations, and guidelines governing the privacy and security of PII/PHI, as well as the development and revision of DHA privacy-related plans, policies, and procedures. Key elements include:
- Breach Prevention and Response
- Civil Liberties Compliance
- Data Sharing Agreements
- HIPAA and Privacy Act Training
- HIPAA Compliance within the MHS
- Privacy Act at DHA
- Privacy Board
- Privacy Impact Assessments
- Research Compliance with HIPAA Privacy Rule
- Risk Assessment
The DHA PCLO also engages DHA stakeholders, including employees and contractors, by developing and delivering education and awareness materials and ongoing workforce privacy and HIPAA security training.
You also may be interested in...
Publication
1/29/2021
This template is designed to assist the Department of Defense Institutional Review Board with determining if DHA data disclosed to a research study will, in any form (de-identified or otherwise), be placed in a research repository and, if so, the type of data and whether any Health Insurance Portability and Accountability Act (HIPAA) compliance requirements are applicable.
Publication
1/29/2021
The IRB HIPAA Compliance Review Findings on Data Requests.
Publication
11/29/2019
The DHA Privacy Office has developed this PPP to present its strategic concept of operations, including descriptions of how DHA complies with federal privacy requirements and related information management subject areas.
This DHA PPP formally documents the DHA’s Privacy Program, including a description of the structure of the Privacy Program, the subject programs and activities that comprise the program, the roles and responsibilities of privacy officials and staff, the strategic goals and objectives of the Privacy Program, and the controls in place or planned – such as policies and procedures and specific programs and activities for meeting applicable privacy requirements and managing privacy risks.
Privacy Program Plan
Page 1 of 1
, showing items 1 - 4
You are leaving Health.mil
The appearance of hyperlinks does not constitute endorsement by the Department of Defense of non-U.S. Government sites or the information, products, or services contained therein. Although the Defense Health Agency may or may not use these sites as additional distribution channels for Department of Defense information, it does not exercise editorial control over all of the information that you may find at these locations. Such links are provided consistent with the stated purpose of this website.
You are leaving Health.mil
View the external links disclaimer.
Last Updated: March 03, 2023