All UNC School of Medicine fundraising activities involving Protected Health Information (PHI) must be coordinated through the UNC Health Medical Foundation as appropriate.
As outlined in UNC Health’s Uses and Disclosures of PHI for Fundraising Purposes Policy access, use or disclosure of certain PHI to a business associate or institutionally related foundation may be permitted without patient authorization for the purpose of fundraising activities. The PHI that may be disclosed to a business associate or institutionally related foundation include:
- Demographic information relating to an individual (including name, address, other contact information, age and gender)
- Date of birth;
- Dates of health care services;
- Departments of services (e.g, cardiology, oncology, pediatrics, etc.);
- Treating physician;
- Outcome information (including death or sub-optimal treatment); and
- Health insurance status
Any other PHI beyond what is listed above may be accessed, used or disclosed with the written authorization of the individual using the UNC Health Use or Disclosure of PHI for Education, Fundraising or Marketing Authorization.
All fundraising communications must include clear and conspicuous instructions, in “plain language,” on how an individual may opt-out from receiving fundraising communications from the UNC SOM. If the communication is in a language other than English, then the opt-out should also be in the other language so that it is easy to understand.
Providing a phone number or email address is permissible, but requiring a written letter to opt-out cannot be used. See UNC Health Uses and Disclosures of PHI for Fundraising Purposes Policy.
Business Associate Agreement
If a covered entity contracts with a third party to perform services (e.g., distribute fundraising materials) on behalf of the covered entity and the third-party will create, receive, transmit, access, or store PHI to perform those services, then a BAA must be obtained. See UNC Health Business Associates Policy.