Is SHIELD Illinois SOPPA compliant?

Is SHIELD Illinois SOPPA compliant?

The privacy of our patient data and compliance with applicable laws, rules, and regulations is of the utmost importance to the SHIELD Deployment Unit of the University of Illinois system (“SHIELD Illinois”).

The legislative intent of Student Online Personal Protection Act (105 ILCS 85/), according to the legislation itself, is to address concerns raised about safeguards to protect student information that is shared specifically with educational technology companies. SHIELD Illinois is not an educational technology company. So, the terms of SOPPA are not applicable to the data provided to or by SHIELD Illinois. However, SHIELD Illinois does follow the guidelines set forth in the Privacy Rule (45 CFR Part 160 and Subparts A and E of 164) of the HHS HIPAA Standards for Privacy of Individually Identifiable Health Information which outlines data privacy not only for students, as is the case with SOPPA, but for all participants in the SHIELD Illinois COVID-19 testing program.

The Standards for Privacy of Individually Identifiable Health Information (“Privacy Rule”) establishes, a set of national standards for the protection of certain health information. The U.S. Department of Health and Human Services (“HHS”) issued the Privacy Rule to implement the requirement of the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”). The Privacy Rule standards address the use and disclosure of individuals’ health information—called “protected health information” by organizations subject to the Privacy Rule — called “covered entities,” as well as standards for individuals' privacy rights to understand and control how their health information is used.

Protected Health Information. The Privacy Rule protects all "individually identifiable health information" held or transmitted by a covered entity or its business associate, in any form or media, whether electronic, paper, or oral. The Privacy Rule calls this information "protected health information (PHI).”
“Individually identifiable health information” is information, including demographic data, that relates to:
  1. the individual’s past, present or future physical or mental health or condition,
  2. the provision of health care to the individual, or
  3. the past, present, or future payment for the provision of health care to the individual, and that identifies the individual or for which there is a reasonable basis to believe it can be used to identify the individual.
Individually identifiable health information includes many common identifiers (e.g., name, address, birth date, Social Security Number). 

PHI collected by SHIELD Illinois and affiliated vendors is stored in accordance with HIPAA security rule requirements. Point and Click Solutions, Inc., the electronic health record vendor engaged by SHIELD Illinois for the purposes of collection, storage, and management of PHI is SOC 2 Type 2 compliant for trust services criteria for security, availability, and confidentiality and undergoes annual SOC 2 and HIPAA compliance audits by an independent third party.

For more information on the HIPAA Privacy Rule and its applications, please see: https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.htmlv
    • Related Articles

    • Is SHIELD Illinois HIPAA compliant?

      The privacy of our patient data and compliance with applicable laws, rules, and regulations is of the utmost importance to the SHIELD Deployment Unit of the University of Illinois system (“SHIELD Illinois”). The Standards for Privacy of Individually ...
    • Who owns SHIELD Illinois?

      SHIELD Illinois is the SHIELD Deployment Unit of the University of Illinois System and continues the Land Grant Mission of the University of Illinois by deploying the innovative covidSHIELD saliva-based COVID-19 screening test throughout the state of ...
    • What is the University of Illinois’ role in the SHIELD program?

      SHIELD Illinois is a COVID-19screening testing program and infrastructure designed to help safely open schools, protect workplaces, and save lives. This specific test was designed by University of Illinois Urbana-Champaign researchers and was ...
    • Does SHIELD Illinois offer Binax (antigen) testing?

      The short answer is "yes." The long answer is SHIELD Illinois only provides operational support for BINAX testing for K-12 public schools which are already participating in the SHIELD Illinois covidSHIELD saliva testing program.  Overview SHIELD ...
    • Why won't SHIELD Illinois deactivate a patient account?

      Patient records are not specific to an agency but to the patient. Deactivating a patient not only prevents the patient from testing anywhere in the SHIELD Illinois network in the future but also removes the ability of the patient or their guardian to ...