New York Maternal Mortality Review Privacy Laws: Requirements for Sharing Perinatal Case Abstracts Statewide
Overview of Maternal Mortality Review Board Authority
New York’s Maternal Mortality Review Board (MMRB) examines maternal deaths to identify contributing factors, preventability, and system-level improvements. Its mandate is quality improvement and public health—not discipline or fault-finding—so you can share information with confidence that its use is focused on saving lives.
Under Public Health Law Section 2509, the MMRB may obtain and analyze materials from hospitals, birthing centers, medical examiners, emergency services, and public health programs. Perinatal Case Abstracts distill those source records into standardized, decision-ready summaries that support consistent, statewide review.
Core functions you should know
- Receive, curate, and review Perinatal Case Abstracts for maternal mortality cases.
- Issue findings on preventability and recommendations for clinical and community practice.
- Coordinate with advisory bodies to advance equitable, data-informed maternal health policy.
Legal Framework for Data Collection
Public Health Law Section 2509 authorizes the collection of information necessary for maternal mortality review. It operates alongside federal Health Insurance Portability and Accountability Act (HIPAA) allowances that permit disclosures for public health and health oversight activities, enabling source facilities to transmit the minimum necessary data for review.
Data may be pulled from medical records, vital records, EMS run sheets, autopsy reports, and social determinants documentation when pertinent to circumstances of death. Health Information Privacy Compliance requires you to document your legal basis for disclosure, apply minimum-necessary standards, and maintain auditable logs for each transmission.
Permissible pathways for obtaining records
- Direct submission by covered entities to the MMRB or its designee for public health review.
- Data Use Agreements for limited datasets when direct identifiers are not needed.
- Interagency exchanges governed by statute and written protocols that specify purpose, scope, and retention limits.
Privacy and Confidentiality Protections
Confidentiality Safeguards are central to New York’s framework. Records and proceedings of the Maternal Mortality Review Board are confidential; they are protected from unauthorized disclosure and are used strictly for public health review and prevention activities. You must prevent any re-identification of patients, infants, or providers outside the permitted use.
Safeguards span administrative, technical, and physical controls. Administratively, designate custodians, train staff annually, and maintain access rosters. Technically, apply role-based access, multifactor authentication, encryption in transit and at rest, and immutable audit logs. Physically, secure storage, badge-controlled areas, and clean-desk rules reduce incidental exposure.
Key compliance expectations
- Use only De-identified Health Information whenever identifiable data are not essential.
- Publish only aggregate results with small-cell suppression to prevent re-identification.
- Prohibit secondary use (research, litigation, marketing) unless separately authorized by law and governance.
Procedures for De-identifying Case Abstracts
Perinatal Case Abstracts should be prepared to remove or obfuscate direct and quasi-identifiers before statewide sharing. When individual-level review requires identifiers, confine them to the originating entity, and share a de-identified or limited dataset externally.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Standard de-identification workflow
- Strip direct identifiers: names, exact addresses, telephone numbers, email, medical record numbers, social security numbers, full-face photos, and unique device/biometric IDs.
- Generalize dates and locations: convert exact dates to month/year or intervals; reduce full ZIP codes to three digits when population thresholds are met; replace facility names with coded values.
- Suppress small cells and rare combinations: review tables for counts below established thresholds and aggregate categories as needed.
- Minimize free text: redact narratives that could reveal identity (e.g., unique events, occupations, or locations) and standardize terminology.
- Create a re-identification key: store the linkage file securely at the originating institution; never transmit it with the abstract.
- Document methods: retain de-identification checklists and quality assurance sign-offs for Health Information Privacy Compliance audits.
Quality checks before release
- Run automated scans for residual identifiers across structured fields and notes.
- Conduct a second-person review for contextual clues to identity.
- Log all approvals, version numbers, and release dates.
Statewide Data Sharing Protocols
Statewide exchange relies on uniform Data Transmission Protocols and least-privilege access. Your goal is to move accurate, timely, de-identified abstracts to the right reviewers while maintaining end-to-end security and accountability.
Submission and transport
- Use secure channels such as SFTP or VPN with AES-256 encryption; forbid email attachments for primary transfers.
- Package files with tamper-evident hashing and standardized filenames (jurisdiction_date_casecode_version).
- Transmit only the minimum necessary fields for the receiving party’s role.
Standardized formats and metadata
- Adopt a common data dictionary for Perinatal Case Abstracts, including codes for cause of death, contributing factors, and social context.
- Embed provenance metadata (origin, abstractions performed, de-identification steps) to support audit and comparability.
- Version-control datasets to track corrections without overwriting prior analyses.
Access, governance, and retention
- Grant role-based access to the Maternal Mortality Review Board, designated abstractors, and analysts; review permissions at least quarterly.
- Execute Data Use Agreements that define purpose, allowed uses, redisclosure prohibitions, retention periods, and destruction requirements.
- Maintain breach response plans with notification timelines, containment steps, and post-incident reviews.
Roles of Healthcare Institutions
Healthcare institutions are essential partners in data quality and timeliness. Your privacy and quality teams should work together so submissions meet legal and technical standards on the first pass.
Hospitals and birthing centers
- Designate an MMRB liaison and privacy officer to coordinate case identification and abstraction.
- Assemble complete source materials (clinical notes, labs, imaging summaries, EMS reports) and convert them into standardized abstracts.
- Perform de-identification and QA checks; retain the re-identification key securely on-site.
- Respond to clarifications from reviewers within defined service levels to keep reviews on schedule.
Medical examiners, coroners, EMS, and public health programs
- Provide timely inputs (autopsy findings, toxicology summaries, scene narratives, EMS timelines) with minimum-necessary detail.
- Coordinate coding for manner and cause of death to align with the common data dictionary.
- Support cross-agency privacy reviews for complex cases while maintaining Confidentiality Safeguards.
Maternal Mortality Review Board and analysts
- Validate incoming data, manage secure repositories, and maintain role-based access controls.
- Lead case discussions, assign preventability, and translate findings into actionable recommendations.
- Publish de-identified, aggregate insights to inform statewide quality improvement and policy.
Impact on Maternal Health Outcomes
Strong privacy practices enable candid, comprehensive reviews that reveal system gaps—delays in diagnosis, care coordination failures, or barriers to postpartum follow-up. When clinicians and families trust that information will be protected, participation rises and case abstracts become more complete and useful.
Statewide sharing accelerates learning. With consistent, de-identified data, you can compare patterns across regions, evaluate the impact of hemorrhage and hypertension bundles, and target community interventions that address transportation, housing, and behavioral health needs linked to preventable deaths.
Over time, standardized analytics and rapid feedback loops help reduce disparities. De-identified Health Information supports equity analyses by race, ethnicity, preferred language, geography, and payer while protecting privacy, guiding resources to the communities with the greatest need.
Conclusion
By following Public Health Law Section 2509, applying rigorous de-identification, and using secure Data Transmission Protocols, you can share Perinatal Case Abstracts statewide without compromising privacy. The result is better data, stronger Health Information Privacy Compliance, and measurable improvements in maternal health outcomes.
FAQs.
What information is protected under New York maternal mortality review privacy laws?
Records, discussions, and work products used by the Maternal Mortality Review Board— including Perinatal Case Abstracts and underlying materials—are confidential. Identifiers of patients, infants, family members, clinicians, and facilities are protected, and information is used solely for public health review, prevention, and quality improvement purposes.
How is personal identifying information removed from case abstracts?
Abstractors follow a documented de-identification workflow: remove direct identifiers, generalize dates and locations, suppress small cells, minimize free text, and keep any re-identification key only at the originating facility. A secondary reviewer confirms that no residual identifiers remain before statewide sharing.
Who is authorized to access the perinatal case data?
Access is limited to the Maternal Mortality Review Board, designated abstractors, analysts, and authorized public health staff with a defined role and a need to know. Permissions are governed by role-based access controls and Data Use Agreements that prohibit redisclosure and require secure handling.
How do confidentiality requirements affect data sharing statewide?
Confidentiality requirements shape how data are prepared, transmitted, and used: only de-identified or limited datasets are shared beyond the originating entity; transfers use secure, encrypted channels; and recipients agree to purpose-limited use, retention limits, and destruction. These guardrails enable rapid, statewide learning while protecting privacy.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.