Massachusetts Department of Public Health
Confidentiality Procedures – Procedure 3
Procedure 3 Page 18
Table 3.1: Permitted Disclosures of Confidential Information
To whom Nature of Disclosure
Authority or Documentation
Required & Whom Completed by
Referenced
Procedure
As directed
by Data
Subject
Confidential Information relating to Data Subject Valid authorization form completed by Data
Subject or his/her personal representative
submitted to data holder
4
Vital Record
Requestor
Identifiable vital record information considered
unrestricted in accordance with applicable laws in
M.G.L. c 46 and disclosed by the Registry of Vital
Records and Statistics
Request submitted to Vital Statistics by the
record requestor
Another
MDPH
Program
Confidential Information related to program
evaluation, quality improvement, payment
verification, public health investigation, surveillance
or intervention, or other health care operations
MDPH Intra-Department Data Use
Agreement executed between data
custodian and program needing data; copy
submitted to confidential data officer
Another
EOHHS
agency
pursuant to
101 CMR
16.00
Confidential client Information related to:
• Administration of agency programs;
• Eligibility determinations or benefit amounts;
• Helping clients obtain services;
• Improve coordination or management of
services;
• Quality assurance activities;
• Serving the interests of agencies’ clients;
• Other circumstances that improve the provision
of services
Appendix B submitted by data requestor to
confidential data officer
MOU for
Data-Sharing
Between and
Among
EOHHS and
its
Constituent
Agencies
Public
Health
Authority
Confidential Information necessary for preventing
or controlling disease, injury, or disability; reporting
vital records, federal grant compliance; conducting
public health surveillance, investigations, or
interventions.
The disclosure must have underlying
authority in a statute or regulation.
No documentation required
Healthcare
Oversight
Agency
Confidential Information necessary to conduct
audits; civil and criminal investigations and
proceedings; inspections; and licensure and
certification actions. The disclosure must have
underlying authority in a statute or regulation.
The disclosure must have underlying
authority in a statute or regulation.
No documentation required
MDPH
Vendor
Confidential Information pursuant to the contract
between the vendor and MDPH
Covered Components:
Business Associate Agreement
Non-Covered Components
:
Confidentiality Agreement
• Executed between MDPH and vendor
CC-2
Public
Health
Evaluator
Partially De-identified Confidential Information for
public health purposes or health care operations
Application for access to confidential data
completed by a public health evaluator and
submitted through IRBNet for review by the
confidential data officer for approval in
accordance with MGL c.111, §24A.
7
Researcher Individually identifiable data or partially de-identified
data for research or scientific studies pursuant to
MGL c. 111 §24A or other statutes authorizing
public health research as authorized by the
Commissioner of DPH
24A approval letter co-signed by the
Principal Investigator. Pledge of
Confidentiality submitted for each research
project participant with access to
Confidential Information.
6
Individual or
court
specified in
a court
order or
other legal
process
Confidential Information belonging to a Data
Subject(s) specified in a judicial order or other legal
process
Valid Authorization Form completed by
Data Subject or his/her personal
representative submitted to data holder or
court order after notice to Data Subject
5
As required
by law
Required or authorized by law or regulation
Example
: Report of elder or child abuse
None required
Return to table of contents