6.6.6904 DEIDENTIFICATION FOR GROUP POLICYHOLDER AUDITS
(1) For purposes of 33-19-306 (14) , MCA, medical record information provided to a group policyholder is deemed to be "edited to prevent the identification of the applicant, policyholder, or certificate holder" if the following identifiers of the individual are removed:
(c) all elements of dates (except year) for dates directly related to the individual, including birth date, discharge date, and date of death;
(d) telephone numbers;
(e) fax numbers;
(f) electronic mail addresses;
(g) social security number;
(h) medical record numbers;
(i) health plan beneficiary numbers;
(j) account numbers;
(k) certificate/license numbers;
(l) vehicle identifiers and serial numbers, including license plate numbers;
(m) device identifiers and serial numbers;
(n) web universal resource locators (URLs) ;
(o) internet protocol (IP) address numbers;
(p) biometric identifiers, including finger and voice prints; and
(q) full face photographic images and any comparable images.
(2) Disclosure by the licensee of personal information that the group policyholder already has in its possession is not a disclosure under 33-19-306 (14) , MCA, unless the personal information is associated with or otherwise attached to medical record information or personal financial information.
(3) The fact of death does not require deidentification if that information is publicly available, unless it is associated with or otherwise attached to other medical record information or personal financial information.
History: Sec. 33-1-313 and 33-19-106, MCA; IMP, Sec. 33-19-102 and 33-19-103, MCA; NEW, 2002 MAR p. 3390, Eff. 12/13/02.