Back to Top Skip to main content

Privacy and Civil Liberties

Notice: As a result of increases in the Health Protection Condition (HPCON) level, our offices are limited to mission-essential personnel only and maximizing the use of telework for other personnel. This means that we are unable to handle requests sent via traditional methods such as postal mail. During this time, we  can only respond to electronic inquiries while under elevated HPCON levels and request that  when sending information to the DHA Privacy and Civil Liberties Office or the DHA Freedom of Information Act Service Center,  please use the following addresses DHA.PrivacyOfficeMail@mail.mil or DHA.FOIA@mail.mil.

Please refrain from sending personally identifiable information or health related information as these mailboxes do not allow for your encrypted submission. However, in an abundance of caution, you may use the DoD SAFE (Secure Access File Exchange) via https://safe.apps.mil/ to upload and send your personal information. Please reference the above mailbox addresses for your submission. When using SAFE, we request that any personal information being transmitted must be encrypted prior to uploading and the decryption key must then be provided to the recipient(s) by a means other than SAFE. 

Thank you for your understanding during this time. We will update our webpage when we return to normal operations.

The DHA Privacy and Civil Liberties Office is responsible for safeguarding Military Health System (MHS) individuals and information by administering compliance programs. In this section of the site, you can find information about several important programs and functions, including:

Protection of personally identifiable and protected health information (PII/PHI) serves eligible beneficiaries, human research subjects, and the DHA workforce.

You also may be interested in...

IRB Findings Document

Publication
1/29/2021

The IRB HIPAA Compliance Review Findings on Data Requests.

Recommended Content:

Privacy and Civil Liberties | Research Streamlining Initiative

Research Repository Template

Publication
1/29/2021

This template is designed to assist the Department of Defense Institutional Review Board with determining if DHA data disclosed to a research study will, in any form (de-identified or otherwise), be placed in a research repository and, if so, the type of data and whether any Health Insurance Portability and Accountability Act (HIPAA) compliance requirements are applicable.

Recommended Content:

Privacy and Civil Liberties | Research Streamlining Initiative

List of Systems Containing DHA Data

Publication
1/20/2021

Recommended Content:

Privacy and Civil Liberties

Research Repository Template

Form/Template
1/20/2021

The RRT asks researchers whether they intend to put data into a repository, and if yes, what data and under what governance terms.

Recommended Content:

Privacy and Civil Liberties

PGI 224.1-90: Personally Identifiable Information (PII), Protected Health Information (PHI), and Federal Information Requirements

Policy

This PGI provides standard language that shall be included in all purchased and non-purchased care solicitations and contracts where the contractor’s performance involves access to PII/PHI (unless those solicitations and contracts incorporate the TRICARE Manuals in their entirety, in which case this PGI does not apply).

DHA Privacy Office Standard Contract Language

Form/Template
10/27/2020

This Section addresses the Contractor’s requirements under The Privacy Act of 1974 (Privacy Act), The Freedom of Information Act (FOIA), and The Health Insurance Privacy and Accountability Act (HIPAA) as set forth in applicable statutes, implementing regulations and DoD issuances.

Recommended Content:

Privacy and Civil Liberties | DHA Privacy Contract Language

Privacy Program Plan

Publication
11/29/2019

The DHA Privacy Office has developed this PPP to present its strategic concept of operations, including descriptions of how DHA complies with federal privacy requirements and related information management subject areas. This DHA PPP formally documents the DHA’s Privacy Program, including a description of the structure of the Privacy Program, the subject programs and activities that comprise the program, the roles and responsibilities of privacy officials and staff, the strategic goals and objectives of the Privacy Program, and the controls in place or planned – such as policies and procedures and specific programs and activities for meeting applicable privacy requirements and managing privacy risks. Privacy Program Plan

Recommended Content:

Privacy and Civil Liberties

DoD Manual 6025.18-Implementation of the HIPAA Privacy Rule in DoD Health Care Programs

Policy

This issuance, in accordance with the authority in DoD Directive 5124.02, establishes policy and assigns responsibilities for; DoD compliance with federal law governing health information privacy and breach of privacy; Integrating health information privacy and breach compliance with general information privacy and security requirements in accordance with federal law and DoD issuances; Health information technology, system interoperability, and exchange of electronic health information, in relation to federal law governing health information privacy and breach; and DoD contracting and procurement activities in relation to federal law governing health information privacy and breach.

Implementation of the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule in DoD Health Care Programs

Policy

This 6025.18 DoD Manual was issued in accordance with the authority in DoD Directive 5124.02. It also implements the policy in DoD Instruction (DoDI) 6025.18, and assigns responsibilities and procedural standards for protecting personally identifiable health information in accordance with parts 160 and 164 of title 45, Code of Federal Regulations (CFR).

DHA Standard Contract Language

Policy

This Section addresses the Contractor’s requirements under The Privacy Act of 1974 (Privacy Act), The Freedom of Information Act (FOIA), and The Health Insurance Privacy and Accountability Act (HIPAA) as set forth in applicable statutes, implementing regulations and DoD issuances.

Surgical Scheduling System

Form/Template
9/16/2016

PIA summary for Surgical Scheduling System.

Recommended Content:

Privacy and Civil Liberties | Privacy Impact Assessments

Decision Tree Matrix for Contracts with PII/PHI

Fact Sheet
9/6/2016

Personally Identifiable Information (PII), Protected Health Information (PHI), and Federal Information Requirements

Recommended Content:

Privacy and Civil Liberties | DHA Privacy Contract Language

Zeiss FORUM

Form/Template
8/12/2016

Zeiss FORUM PIA summary

Recommended Content:

Privacy and Civil Liberties | Privacy Impact Assessments

Department of Defense Consolidated Cancer Registry (CCR)

Form/Template
7/21/2016

Department of Defense Consolidated Cancer Registry (CCR) System PIA summary

Recommended Content:

Privacy and Civil Liberties | Privacy Impact Assessments

Military Health System Data Repository

Form/Template
6/23/2016

Military Health System (MHS) Data Repository (MDR) PIA

Recommended Content:

Privacy and Civil Liberties | Privacy Impact Assessments
<< < 1 2 > >> 
Showing results 1 - 15 Page 1 of 2

DHA Address: 7700 Arlington Boulevard | Suite 5101 | Falls Church, VA | 22042-5101

Some documents are presented in Portable Document Format (PDF). A PDF reader is required for viewing. Download a PDF Reader or learn more about PDFs.