COMDTINST 6000.8 governs HIPAA Privacy Rule compliance in Coast Guard health care programs and the protection of health information.
View COMDTINST 6000.8 on armypubs.army.mil
It addresses PHI uses and disclosures, authorization requirements, privacy incidents, breaches, definitions, and military command exceptions. It requires designated privacy and security officers and establishes procedures for handling protected health information.
HIPAA’s Privacy Rule protects individually identifiable health information (called Protected Health Information (PHI)) that is held or transmitted by a covered entity (CE) or its business associate(s) (BA), in any form or media, whether electronic, paper, or oral. (paragraph 5)
Under the Military Command Exception, a healthcare provider may disclose the PHI of service members for authorized activities to appropriate military command authorities.
The term encompasses both suspected and confirmed incidents involving PII, whether intentional or inadvertent, which raises a reasonable risk of harm.
Health information that does not identify an individual and there is no reasonable basis to believe that the information can be used to identify an individual is not individually identifiable health information. (paragraph 7)
A written statement submitted to a CG CE’s HIPAA privacy officer or to the HHS Office for Civil Rights alleging that the CG CE has violated an individual's health information privacy rights or committed a violation of the HIPAA Privacy or Security Rule provisions.