Policy · Public Health Powers, Preparedness & Biosecurity
Public Health Surveillance Authority and Its Limits
A long-form policy analysis of mandatory report, case surveillance, syndromic surveillance, laboratory report, public-health investigation, research, program evaluation, intelligence, and law enforcement, grounded in current primary authorities, operational mechanisms, measurable outcomes, and correctable governance.
- Surveillance legitimacy comes from a defined public-health purpose and authority, not from the technical ability to collect. Each data stream needs a case definition, minimum dataset, quality plan, security, role separation, use restrictions, retention schedule, public explanation, and evidence that collection supports action.
- The controlling distinctions are mandatory report, case surveillance, syndromic surveillance, laboratory report, public-health investigation, research, program evaluation, intelligence, and law enforcement.
- The operational mechanisms to test are notifiable disease law, HIPAA permissions, case definitions, laboratory and EHR feeds, identity resolution, social data, immigration and law-enforcement separation, tribal sovereignty, vendor platforms, emergencies, and research.
- Evaluation should use coverage, timeliness, completeness, positive predictive value, representativeness, reporting burden, actions taken, security incidents, secondary uses, retention, and community trust, rather than a single activity total.
- The recommended policy direction is a purpose-limited surveillance charter with statutory mapping, minimum and standardized data, quality and equity analysis, access controls, public use registers, retention rules, Tribal and community governance, and action-based evaluation.
Executive frame
A durable governance rule begins with the actual data flow or decision pathway, not with the institution's preferred shorthand. Public Health Surveillance Authority and Its Limits addresses a field in which mandatory report, case surveillance, syndromic surveillance, laboratory report, public-health investigation, research, program evaluation, intelligence, and law enforcement can be collapsed into one another. Surveillance legitimacy comes from a defined public-health purpose and authority, not from the technical ability to collect. Each data stream needs a case definition, minimum dataset, quality plan, security, role separation, use restrictions, retention schedule, public explanation, and evidence that collection supports action. The point is not to make action impossible. It is to make the reason for action visible, reviewable, and capable of being corrected when the facts, law, technology, or implementation change.
The working map for this article is health threat and authority → reporting specification → collection → identity and quality control → analysis → public-health action → sharing → retention or deletion → evaluation. That sequence identifies more than chronology. It locates the actor who can create or alter a record, the rule applicable at that stage, the people who may be affected, and the point at which an error becomes harder to reverse. Reading the chain forward prevents a later result from being projected backward onto an earlier allegation, signal, permission, technical event, or proposal.
The mechanism analysis centers on notifiable disease law, HIPAA permissions, case definitions, laboratory and EHR feeds, identity resolution, social data, immigration and law-enforcement separation, tribal sovereignty, vendor platforms, emergencies, and research. Each mechanism can produce a similar surface outcome through a different route. A delay may reflect capacity, a lawful review step, incompatible technology, missing information, strategic behavior, or an invalid barrier. A disclosure may be required, permitted, prohibited, mistakenly transmitted, or technically unavoidable in a limited emergency. Policy evaluation must identify the route before assigning responsibility or proposing a remedy.
The principal people and institutions are patients and communities; clinicians and laboratories; health departments; CDC; Tribes; schools and employers; data intermediaries; privacy and civil-rights officers; legislators; and researchers. They do not hold the same information or authority. A patient may know the consequence without seeing an internal rule; a regulator may know the governing process without observing frontline work; a vendor may know the system design without controlling how a customer configured it. The article therefore treats interviews as perspective and mechanism evidence, then uses primary records to verify legal status, dates, scope, and decisive facts.
A useful performance account includes coverage, timeliness, completeness, positive predictive value, representativeness, reporting burden, actions taken, security incidents, secondary uses, retention, and community trust. Those measures require defined units, populations, observation periods, missingness rules, and version history. A raw count cannot by itself distinguish greater underlying harm from better detection, broader jurisdiction, easier reporting, duplicate records, changed coding, or backlog clearance. Where causal evidence is unavailable, the article states the uncertainty and specifies what additional observation would help resolve it.
The guardrails are equally important: Do not say HIPAA permission creates reporting authority; do not treat absence from surveillance as absence of disease; do not repurpose data for unrelated enforcement without lawful authority. Those limits keep a valuable reform from becoming a new source of harm. The recommended direction—a purpose-limited surveillance charter with statutory mapping, minimum and standardized data, quality and equity analysis, access controls, public use registers, retention rules, Tribal and community governance, and action-based evaluation—should therefore be implemented with named owners, realistic capacity, a visible exception or review route, and measures that can reveal both benefit and burden. A policy earns confidence by surviving correction, not by avoiding it.
Definitions, authority, and scope
For Public Health Surveillance Authority and Its Limits, the most important definitions are functional. A legal rule states what an authorized source requires, permits, or prohibits; guidance explains administration without automatically carrying the same force; an operational policy tells an institution how it will act; a technical control constrains or records system behavior; and a recommendation states what this article concludes should change. One document may discuss several layers, but the resulting sentences should not merge them.
In Public Health Surveillance Authority and Its Limits, the phrase source competent to establish the claim means the current instrument closest to the proposition: statutory or regulatory text for legal authority, an operative order for a case outcome, a system or audit record for a transaction, an originating dataset and documentation for a quantitative result, and direct testimony for personal experience. Summaries are helpful navigation. They are not substitutes when definitions, exceptions, effective dates, procedural posture, or current litigation status control the answer.
A scope boundary identifies jurisdiction, actor, population, program, record type, purpose, time, and version. Here the jurisdiction is U.S. federal, state, local, territorial, and Tribal surveillance systems and health-data law. The same data or conduct may be governed differently when one of those coordinates changes. A responsible comparison preserves the coordinate that matters instead of exporting a federal rule to an uncovered actor, a state exception to another jurisdiction, or a program result to the full health system.
A governance control assigns a decision right and creates evidence that the decision was performed. Policies without an owner, data inventory, training, escalation path, review clock, audit record, and correction route can be aspirational but are not reliably operational. For Public Health Surveillance Authority and Its Limits, governance quality should be assessed by whether affected people can understand the rule, whether responsible staff can execute it under ordinary workload, and whether a reviewer can reconstruct what happened after an adverse outcome.
Identifying the public-health purpose
Identifying the public-health purpose should be treated first as a problem of data provenance and purpose. In Public Health Surveillance Authority and Its Limits, the analyst should identify the concrete decision, the actor with authority, the affected record or service, and the consequence of a false positive, false negative, or delayed result. The relevant boundary is among mandatory report, case surveillance, syndromic surveillance, laboratory report, public-health investigation, research, program evaluation, intelligence, and law enforcement. A useful interview question asks the participant to describe the last actual case step by step, including the form, screen, queue, message, exception, and person who could change the outcome. That reconstruction often reveals where a broad policy label stopped matching work as performed.
The first primary-source anchor is CDC — What Is Case Surveillance?. It establishes a bounded proposition: CDC explains how public-health agencies collect and use information about reportable diseases to monitor and control health threats. Its limitation is just as material: Surveillance records are shaped by reporting law, case definitions, testing, access, timeliness, and missingness and are not a complete census of disease. Applied to identifying the public-health purpose, the authority should be cited for the precise proposition it can establish, with its issuer, status, date, affected entities, and operative terminology preserved. If a current regulation, statute, court order, or implementation notice differs from a general summary, the controlling or more current source should govern the sentence and the discrepancy should be recorded for editorial review.
The predictable failure mode is that a narrow permission expands into an unstated general practice. Measurement should therefore connect the issue to coverage, timeliness, completeness, positive predictive value, representativeness, reporting burden, actions taken, security incidents, secondary uses, retention, and community trust. For identifying the public-health purpose, define the unit and population before calculating a rate; distinguish intake from disposition cohorts; show median and tail performance where delay matters; and document duplicates, exclusions, suppressed small cells, missing fields, changed definitions, and revisions. Compare groups only when coverage and ascertainment are sufficiently similar. If the evidence cannot support a causal or comparative claim, report the observable process result and state the unanswered causal question rather than filling it with an impression.
Implementation should assign an owner, required evidence, decision clock, exception path, audit record, and correction trigger for identifying the public-health purpose. The design must account for notifiable disease law, HIPAA permissions, case definitions, laboratory and EHR feeds, identity resolution, social data, immigration and law-enforcement separation, tribal sovereignty, vendor platforms, emergencies, and research and should be tested with patients and communities; clinicians and laboratories; health departments; CDC; Tribes; schools and employers; data intermediaries; privacy and civil-rights officers; legislators; and researchers. The practical review asks whether a person can obtain notice where lawful, understand the basis, provide contrary information, request accommodation or urgency, receive reasons, and correct every downstream use that relied on an error. Capacity—staff, language services, accessibility, clinical expertise, security, procurement, and vendor cooperation—is part of validity in practice. The safeguard remains bounded by this article's red lines: Do not say HIPAA permission creates reporting authority; do not treat absence from surveillance as absence of disease; do not repurpose data for unrelated enforcement without lawful authority.
Federalism and reporting authority
Federalism and reporting authority should be treated first as a problem of workflow reconstruction. In Public Health Surveillance Authority and Its Limits, the analyst should identify the concrete decision, the actor with authority, the affected record or service, and the consequence of a false positive, false negative, or delayed result. The relevant boundary is among mandatory report, case surveillance, syndromic surveillance, laboratory report, public-health investigation, research, program evaluation, intelligence, and law enforcement. A useful interview question asks the participant to describe the last actual case step by step, including the form, screen, queue, message, exception, and person who could change the outcome. That reconstruction often reveals where a broad policy label stopped matching work as performed.
The first primary-source anchor is HHS OCR — Public Health Uses and Disclosures Under HIPAA. It establishes a bounded proposition: HHS explains Privacy Rule permissions for specified public-health activities and authorities. Its limitation is just as material: HIPAA permission does not itself create public-health authority, require every disclosure, or displace more protective and program-specific law. Applied to federalism and reporting authority, the authority should be cited for the precise proposition it can establish, with its issuer, status, date, affected entities, and operative terminology preserved. If a current regulation, statute, court order, or implementation notice differs from a general summary, the controlling or more current source should govern the sentence and the discrepancy should be recorded for editorial review.
The predictable failure mode is that a label outlives the evidence and context that originally supported it. Measurement should therefore connect the issue to coverage, timeliness, completeness, positive predictive value, representativeness, reporting burden, actions taken, security incidents, secondary uses, retention, and community trust. For federalism and reporting authority, define the unit and population before calculating a rate; distinguish intake from disposition cohorts; show median and tail performance where delay matters; and document duplicates, exclusions, suppressed small cells, missing fields, changed definitions, and revisions. Compare groups only when coverage and ascertainment are sufficiently similar. If the evidence cannot support a causal or comparative claim, report the observable process result and state the unanswered causal question rather than filling it with an impression.
Implementation should assign an owner, required evidence, decision clock, exception path, audit record, and correction trigger for federalism and reporting authority. The design must account for notifiable disease law, HIPAA permissions, case definitions, laboratory and EHR feeds, identity resolution, social data, immigration and law-enforcement separation, tribal sovereignty, vendor platforms, emergencies, and research and should be tested with patients and communities; clinicians and laboratories; health departments; CDC; Tribes; schools and employers; data intermediaries; privacy and civil-rights officers; legislators; and researchers. The practical review asks whether a person can obtain notice where lawful, understand the basis, provide contrary information, request accommodation or urgency, receive reasons, and correct every downstream use that relied on an error. Capacity—staff, language services, accessibility, clinical expertise, security, procurement, and vendor cooperation—is part of validity in practice. The safeguard remains bounded by this article's red lines: Do not say HIPAA permission creates reporting authority; do not treat absence from surveillance as absence of disease; do not repurpose data for unrelated enforcement without lawful authority.
Case definitions and minimum datasets
Case definitions and minimum datasets should be treated first as a problem of workflow reconstruction. In Public Health Surveillance Authority and Its Limits, the analyst should identify the concrete decision, the actor with authority, the affected record or service, and the consequence of a false positive, false negative, or delayed result. The relevant boundary is among mandatory report, case surveillance, syndromic surveillance, laboratory report, public-health investigation, research, program evaluation, intelligence, and law enforcement. A useful interview question asks the participant to describe the last actual case step by step, including the form, screen, queue, message, exception, and person who could change the outcome. That reconstruction often reveals where a broad policy label stopped matching work as performed.
The first primary-source anchor is CDC — Public Health Data Strategy. It establishes a bounded proposition: CDC describes a strategy for more timely, interoperable, secure, and action-oriented public-health data across jurisdictions. Its limitation is just as material: A strategy is not a blanket surveillance authority and does not override privacy, civil-rights, tribal, state, or program-specific law. Applied to case definitions and minimum datasets, the authority should be cited for the precise proposition it can establish, with its issuer, status, date, affected entities, and operative terminology preserved. If a current regulation, statute, court order, or implementation notice differs from a general summary, the controlling or more current source should govern the sentence and the discrepancy should be recorded for editorial review.
The predictable failure mode is that an informal shortcut becomes a durable rule without review. Measurement should therefore connect the issue to coverage, timeliness, completeness, positive predictive value, representativeness, reporting burden, actions taken, security incidents, secondary uses, retention, and community trust. For case definitions and minimum datasets, define the unit and population before calculating a rate; distinguish intake from disposition cohorts; show median and tail performance where delay matters; and document duplicates, exclusions, suppressed small cells, missing fields, changed definitions, and revisions. Compare groups only when coverage and ascertainment are sufficiently similar. If the evidence cannot support a causal or comparative claim, report the observable process result and state the unanswered causal question rather than filling it with an impression.
Implementation should assign an owner, required evidence, decision clock, exception path, audit record, and correction trigger for case definitions and minimum datasets. The design must account for notifiable disease law, HIPAA permissions, case definitions, laboratory and EHR feeds, identity resolution, social data, immigration and law-enforcement separation, tribal sovereignty, vendor platforms, emergencies, and research and should be tested with patients and communities; clinicians and laboratories; health departments; CDC; Tribes; schools and employers; data intermediaries; privacy and civil-rights officers; legislators; and researchers. The practical review asks whether a person can obtain notice where lawful, understand the basis, provide contrary information, request accommodation or urgency, receive reasons, and correct every downstream use that relied on an error. Capacity—staff, language services, accessibility, clinical expertise, security, procurement, and vendor cooperation—is part of validity in practice. The safeguard remains bounded by this article's red lines: Do not say HIPAA permission creates reporting authority; do not treat absence from surveillance as absence of disease; do not repurpose data for unrelated enforcement without lawful authority.
Clinical, laboratory, and syndromic feeds
Clinical, laboratory, and syndromic feeds should be treated first as a problem of measurement and feedback. In Public Health Surveillance Authority and Its Limits, the analyst should identify the concrete decision, the actor with authority, the affected record or service, and the consequence of a false positive, false negative, or delayed result. The relevant boundary is among mandatory report, case surveillance, syndromic surveillance, laboratory report, public-health investigation, research, program evaluation, intelligence, and law enforcement. A useful interview question asks the participant to describe the last actual case step by step, including the form, screen, queue, message, exception, and person who could change the outcome. That reconstruction often reveals where a broad policy label stopped matching work as performed.
The first primary-source anchor is HHS OCR — HIPAA Security Rule. It establishes a bounded proposition: HHS explains administrative, physical, and technical safeguards for electronic protected health information under the Security Rule. Its limitation is just as material: The rule is risk-based and entity-specific; compliance does not mean a system is invulnerable or that every cyber incident constitutes the same legal violation. Applied to clinical, laboratory, and syndromic feeds, the authority should be cited for the precise proposition it can establish, with its issuer, status, date, affected entities, and operative terminology preserved. If a current regulation, statute, court order, or implementation notice differs from a general summary, the controlling or more current source should govern the sentence and the discrepancy should be recorded for editorial review.
The predictable failure mode is that a narrow permission expands into an unstated general practice. Measurement should therefore connect the issue to coverage, timeliness, completeness, positive predictive value, representativeness, reporting burden, actions taken, security incidents, secondary uses, retention, and community trust. For clinical, laboratory, and syndromic feeds, define the unit and population before calculating a rate; distinguish intake from disposition cohorts; show median and tail performance where delay matters; and document duplicates, exclusions, suppressed small cells, missing fields, changed definitions, and revisions. Compare groups only when coverage and ascertainment are sufficiently similar. If the evidence cannot support a causal or comparative claim, report the observable process result and state the unanswered causal question rather than filling it with an impression.
Implementation should assign an owner, required evidence, decision clock, exception path, audit record, and correction trigger for clinical, laboratory, and syndromic feeds. The design must account for notifiable disease law, HIPAA permissions, case definitions, laboratory and EHR feeds, identity resolution, social data, immigration and law-enforcement separation, tribal sovereignty, vendor platforms, emergencies, and research and should be tested with patients and communities; clinicians and laboratories; health departments; CDC; Tribes; schools and employers; data intermediaries; privacy and civil-rights officers; legislators; and researchers. The practical review asks whether a person can obtain notice where lawful, understand the basis, provide contrary information, request accommodation or urgency, receive reasons, and correct every downstream use that relied on an error. Capacity—staff, language services, accessibility, clinical expertise, security, procurement, and vendor cooperation—is part of validity in practice. The safeguard remains bounded by this article's red lines: Do not say HIPAA permission creates reporting authority; do not treat absence from surveillance as absence of disease; do not repurpose data for unrelated enforcement without lawful authority.
Coverage, missingness, and representativeness
Coverage, missingness, and representativeness should be treated first as a problem of risk allocation and remedy. In Public Health Surveillance Authority and Its Limits, the analyst should identify the concrete decision, the actor with authority, the affected record or service, and the consequence of a false positive, false negative, or delayed result. The relevant boundary is among mandatory report, case surveillance, syndromic surveillance, laboratory report, public-health investigation, research, program evaluation, intelligence, and law enforcement. A useful interview question asks the participant to describe the last actual case step by step, including the form, screen, queue, message, exception, and person who could change the outcome. That reconstruction often reveals where a broad policy label stopped matching work as performed.
The first primary-source anchor is CDC Field Epidemiology Manual — Describing epidemiologic data. It establishes a bounded proposition: CDC explains that rates and proportions relate event counts to an appropriate population and time, allowing more meaningful comparisons than raw counts. Its limitation is just as material: The numerator, denominator, case definition, geography, and observation period must correspond; a rate does not repair biased ascertainment. Applied to coverage, missingness, and representativeness, the authority should be cited for the precise proposition it can establish, with its issuer, status, date, affected entities, and operative terminology preserved. If a current regulation, statute, court order, or implementation notice differs from a general summary, the controlling or more current source should govern the sentence and the discrepancy should be recorded for editorial review.
The predictable failure mode is that a technical limitation is reported as though the law required it. Measurement should therefore connect the issue to coverage, timeliness, completeness, positive predictive value, representativeness, reporting burden, actions taken, security incidents, secondary uses, retention, and community trust. For coverage, missingness, and representativeness, define the unit and population before calculating a rate; distinguish intake from disposition cohorts; show median and tail performance where delay matters; and document duplicates, exclusions, suppressed small cells, missing fields, changed definitions, and revisions. Compare groups only when coverage and ascertainment are sufficiently similar. If the evidence cannot support a causal or comparative claim, report the observable process result and state the unanswered causal question rather than filling it with an impression.
Implementation should assign an owner, required evidence, decision clock, exception path, audit record, and correction trigger for coverage, missingness, and representativeness. The design must account for notifiable disease law, HIPAA permissions, case definitions, laboratory and EHR feeds, identity resolution, social data, immigration and law-enforcement separation, tribal sovereignty, vendor platforms, emergencies, and research and should be tested with patients and communities; clinicians and laboratories; health departments; CDC; Tribes; schools and employers; data intermediaries; privacy and civil-rights officers; legislators; and researchers. The practical review asks whether a person can obtain notice where lawful, understand the basis, provide contrary information, request accommodation or urgency, receive reasons, and correct every downstream use that relied on an error. Capacity—staff, language services, accessibility, clinical expertise, security, procurement, and vendor cooperation—is part of validity in practice. The safeguard remains bounded by this article's red lines: Do not say HIPAA permission creates reporting authority; do not treat absence from surveillance as absence of disease; do not repurpose data for unrelated enforcement without lawful authority.
Identity resolution and false matches
Identity resolution and false matches should be treated first as a problem of measurement and feedback. In Public Health Surveillance Authority and Its Limits, the analyst should identify the concrete decision, the actor with authority, the affected record or service, and the consequence of a false positive, false negative, or delayed result. The relevant boundary is among mandatory report, case surveillance, syndromic surveillance, laboratory report, public-health investigation, research, program evaluation, intelligence, and law enforcement. A useful interview question asks the participant to describe the last actual case step by step, including the form, screen, queue, message, exception, and person who could change the outcome. That reconstruction often reveals where a broad policy label stopped matching work as performed.
The first primary-source anchor is U.S. Government Accountability Office — Standards for Internal Control in the Federal Government (Green Book). It establishes a bounded proposition: GAO's 2025 Green Book revision sets federal internal-control principles concerning objectives, risks, information, monitoring, and corrective action, effective beginning in fiscal year 2026. Its limitation is just as material: The Green Book applies directly within its federal scope and is a useful benchmark elsewhere; it is not a universal state-agency statute. Applied to identity resolution and false matches, the authority should be cited for the precise proposition it can establish, with its issuer, status, date, affected entities, and operative terminology preserved. If a current regulation, statute, court order, or implementation notice differs from a general summary, the controlling or more current source should govern the sentence and the discrepancy should be recorded for editorial review.
The predictable failure mode is that a narrow permission expands into an unstated general practice. Measurement should therefore connect the issue to coverage, timeliness, completeness, positive predictive value, representativeness, reporting burden, actions taken, security incidents, secondary uses, retention, and community trust. For identity resolution and false matches, define the unit and population before calculating a rate; distinguish intake from disposition cohorts; show median and tail performance where delay matters; and document duplicates, exclusions, suppressed small cells, missing fields, changed definitions, and revisions. Compare groups only when coverage and ascertainment are sufficiently similar. If the evidence cannot support a causal or comparative claim, report the observable process result and state the unanswered causal question rather than filling it with an impression.
Implementation should assign an owner, required evidence, decision clock, exception path, audit record, and correction trigger for identity resolution and false matches. The design must account for notifiable disease law, HIPAA permissions, case definitions, laboratory and EHR feeds, identity resolution, social data, immigration and law-enforcement separation, tribal sovereignty, vendor platforms, emergencies, and research and should be tested with patients and communities; clinicians and laboratories; health departments; CDC; Tribes; schools and employers; data intermediaries; privacy and civil-rights officers; legislators; and researchers. The practical review asks whether a person can obtain notice where lawful, understand the basis, provide contrary information, request accommodation or urgency, receive reasons, and correct every downstream use that relied on an error. Capacity—staff, language services, accessibility, clinical expertise, security, procurement, and vendor cooperation—is part of validity in practice. The safeguard remains bounded by this article's red lines: Do not say HIPAA permission creates reporting authority; do not treat absence from surveillance as absence of disease; do not repurpose data for unrelated enforcement without lawful authority.
HIPAA permissions and state privacy law
HIPAA permissions and state privacy law should be treated first as a problem of risk allocation and remedy. In Public Health Surveillance Authority and Its Limits, the analyst should identify the concrete decision, the actor with authority, the affected record or service, and the consequence of a false positive, false negative, or delayed result. The relevant boundary is among mandatory report, case surveillance, syndromic surveillance, laboratory report, public-health investigation, research, program evaluation, intelligence, and law enforcement. A useful interview question asks the participant to describe the last actual case step by step, including the form, screen, queue, message, exception, and person who could change the outcome. That reconstruction often reveals where a broad policy label stopped matching work as performed.
The first primary-source anchor is CDC — What Is Case Surveillance?. It establishes a bounded proposition: CDC explains how public-health agencies collect and use information about reportable diseases to monitor and control health threats. Its limitation is just as material: Surveillance records are shaped by reporting law, case definitions, testing, access, timeliness, and missingness and are not a complete census of disease. Applied to hipaa permissions and state privacy law, the authority should be cited for the precise proposition it can establish, with its issuer, status, date, affected entities, and operative terminology preserved. If a current regulation, statute, court order, or implementation notice differs from a general summary, the controlling or more current source should govern the sentence and the discrepancy should be recorded for editorial review.
The predictable failure mode is that a missing denominator turns activity into an apparent outcome. Measurement should therefore connect the issue to coverage, timeliness, completeness, positive predictive value, representativeness, reporting burden, actions taken, security incidents, secondary uses, retention, and community trust. For hipaa permissions and state privacy law, define the unit and population before calculating a rate; distinguish intake from disposition cohorts; show median and tail performance where delay matters; and document duplicates, exclusions, suppressed small cells, missing fields, changed definitions, and revisions. Compare groups only when coverage and ascertainment are sufficiently similar. If the evidence cannot support a causal or comparative claim, report the observable process result and state the unanswered causal question rather than filling it with an impression.
Implementation should assign an owner, required evidence, decision clock, exception path, audit record, and correction trigger for hipaa permissions and state privacy law. The design must account for notifiable disease law, HIPAA permissions, case definitions, laboratory and EHR feeds, identity resolution, social data, immigration and law-enforcement separation, tribal sovereignty, vendor platforms, emergencies, and research and should be tested with patients and communities; clinicians and laboratories; health departments; CDC; Tribes; schools and employers; data intermediaries; privacy and civil-rights officers; legislators; and researchers. The practical review asks whether a person can obtain notice where lawful, understand the basis, provide contrary information, request accommodation or urgency, receive reasons, and correct every downstream use that relied on an error. Capacity—staff, language services, accessibility, clinical expertise, security, procurement, and vendor cooperation—is part of validity in practice. The safeguard remains bounded by this article's red lines: Do not say HIPAA permission creates reporting authority; do not treat absence from surveillance as absence of disease; do not repurpose data for unrelated enforcement without lawful authority.
Separation from unrelated enforcement
Separation from unrelated enforcement should be treated first as a problem of implementation ownership. In Public Health Surveillance Authority and Its Limits, the analyst should identify the concrete decision, the actor with authority, the affected record or service, and the consequence of a false positive, false negative, or delayed result. The relevant boundary is among mandatory report, case surveillance, syndromic surveillance, laboratory report, public-health investigation, research, program evaluation, intelligence, and law enforcement. A useful interview question asks the participant to describe the last actual case step by step, including the form, screen, queue, message, exception, and person who could change the outcome. That reconstruction often reveals where a broad policy label stopped matching work as performed.
The first primary-source anchor is HHS OCR — Public Health Uses and Disclosures Under HIPAA. It establishes a bounded proposition: HHS explains Privacy Rule permissions for specified public-health activities and authorities. Its limitation is just as material: HIPAA permission does not itself create public-health authority, require every disclosure, or displace more protective and program-specific law. Applied to separation from unrelated enforcement, the authority should be cited for the precise proposition it can establish, with its issuer, status, date, affected entities, and operative terminology preserved. If a current regulation, statute, court order, or implementation notice differs from a general summary, the controlling or more current source should govern the sentence and the discrepancy should be recorded for editorial review.
The predictable failure mode is that a narrow permission expands into an unstated general practice. Measurement should therefore connect the issue to coverage, timeliness, completeness, positive predictive value, representativeness, reporting burden, actions taken, security incidents, secondary uses, retention, and community trust. For separation from unrelated enforcement, define the unit and population before calculating a rate; distinguish intake from disposition cohorts; show median and tail performance where delay matters; and document duplicates, exclusions, suppressed small cells, missing fields, changed definitions, and revisions. Compare groups only when coverage and ascertainment are sufficiently similar. If the evidence cannot support a causal or comparative claim, report the observable process result and state the unanswered causal question rather than filling it with an impression.
Implementation should assign an owner, required evidence, decision clock, exception path, audit record, and correction trigger for separation from unrelated enforcement. The design must account for notifiable disease law, HIPAA permissions, case definitions, laboratory and EHR feeds, identity resolution, social data, immigration and law-enforcement separation, tribal sovereignty, vendor platforms, emergencies, and research and should be tested with patients and communities; clinicians and laboratories; health departments; CDC; Tribes; schools and employers; data intermediaries; privacy and civil-rights officers; legislators; and researchers. The practical review asks whether a person can obtain notice where lawful, understand the basis, provide contrary information, request accommodation or urgency, receive reasons, and correct every downstream use that relied on an error. Capacity—staff, language services, accessibility, clinical expertise, security, procurement, and vendor cooperation—is part of validity in practice. The safeguard remains bounded by this article's red lines: Do not say HIPAA permission creates reporting authority; do not treat absence from surveillance as absence of disease; do not repurpose data for unrelated enforcement without lawful authority.
Retention, access, and public transparency
Retention, access, and public transparency should be treated first as a problem of risk allocation and remedy. In Public Health Surveillance Authority and Its Limits, the analyst should identify the concrete decision, the actor with authority, the affected record or service, and the consequence of a false positive, false negative, or delayed result. The relevant boundary is among mandatory report, case surveillance, syndromic surveillance, laboratory report, public-health investigation, research, program evaluation, intelligence, and law enforcement. A useful interview question asks the participant to describe the last actual case step by step, including the form, screen, queue, message, exception, and person who could change the outcome. That reconstruction often reveals where a broad policy label stopped matching work as performed.
The first primary-source anchor is CDC — Public Health Data Strategy. It establishes a bounded proposition: CDC describes a strategy for more timely, interoperable, secure, and action-oriented public-health data across jurisdictions. Its limitation is just as material: A strategy is not a blanket surveillance authority and does not override privacy, civil-rights, tribal, state, or program-specific law. Applied to retention, access, and public transparency, the authority should be cited for the precise proposition it can establish, with its issuer, status, date, affected entities, and operative terminology preserved. If a current regulation, statute, court order, or implementation notice differs from a general summary, the controlling or more current source should govern the sentence and the discrepancy should be recorded for editorial review.
The predictable failure mode is that an informal shortcut becomes a durable rule without review. Measurement should therefore connect the issue to coverage, timeliness, completeness, positive predictive value, representativeness, reporting burden, actions taken, security incidents, secondary uses, retention, and community trust. For retention, access, and public transparency, define the unit and population before calculating a rate; distinguish intake from disposition cohorts; show median and tail performance where delay matters; and document duplicates, exclusions, suppressed small cells, missing fields, changed definitions, and revisions. Compare groups only when coverage and ascertainment are sufficiently similar. If the evidence cannot support a causal or comparative claim, report the observable process result and state the unanswered causal question rather than filling it with an impression.
Implementation should assign an owner, required evidence, decision clock, exception path, audit record, and correction trigger for retention, access, and public transparency. The design must account for notifiable disease law, HIPAA permissions, case definitions, laboratory and EHR feeds, identity resolution, social data, immigration and law-enforcement separation, tribal sovereignty, vendor platforms, emergencies, and research and should be tested with patients and communities; clinicians and laboratories; health departments; CDC; Tribes; schools and employers; data intermediaries; privacy and civil-rights officers; legislators; and researchers. The practical review asks whether a person can obtain notice where lawful, understand the basis, provide contrary information, request accommodation or urgency, receive reasons, and correct every downstream use that relied on an error. Capacity—staff, language services, accessibility, clinical expertise, security, procurement, and vendor cooperation—is part of validity in practice. The safeguard remains bounded by this article's red lines: Do not say HIPAA permission creates reporting authority; do not treat absence from surveillance as absence of disease; do not repurpose data for unrelated enforcement without lawful authority.
Measuring whether surveillance led to effective action
Measuring whether surveillance led to effective action should be treated first as a problem of classification and authority. In Public Health Surveillance Authority and Its Limits, the analyst should identify the concrete decision, the actor with authority, the affected record or service, and the consequence of a false positive, false negative, or delayed result. The relevant boundary is among mandatory report, case surveillance, syndromic surveillance, laboratory report, public-health investigation, research, program evaluation, intelligence, and law enforcement. A useful interview question asks the participant to describe the last actual case step by step, including the form, screen, queue, message, exception, and person who could change the outcome. That reconstruction often reveals where a broad policy label stopped matching work as performed.
The first primary-source anchor is HHS OCR — HIPAA Security Rule. It establishes a bounded proposition: HHS explains administrative, physical, and technical safeguards for electronic protected health information under the Security Rule. Its limitation is just as material: The rule is risk-based and entity-specific; compliance does not mean a system is invulnerable or that every cyber incident constitutes the same legal violation. Applied to measuring whether surveillance led to effective action, the authority should be cited for the precise proposition it can establish, with its issuer, status, date, affected entities, and operative terminology preserved. If a current regulation, statute, court order, or implementation notice differs from a general summary, the controlling or more current source should govern the sentence and the discrepancy should be recorded for editorial review.
The predictable failure mode is that burden moves to the least-resourced participant and disappears from the institution's metric. Measurement should therefore connect the issue to coverage, timeliness, completeness, positive predictive value, representativeness, reporting burden, actions taken, security incidents, secondary uses, retention, and community trust. For measuring whether surveillance led to effective action, define the unit and population before calculating a rate; distinguish intake from disposition cohorts; show median and tail performance where delay matters; and document duplicates, exclusions, suppressed small cells, missing fields, changed definitions, and revisions. Compare groups only when coverage and ascertainment are sufficiently similar. If the evidence cannot support a causal or comparative claim, report the observable process result and state the unanswered causal question rather than filling it with an impression.
Implementation should assign an owner, required evidence, decision clock, exception path, audit record, and correction trigger for measuring whether surveillance led to effective action. The design must account for notifiable disease law, HIPAA permissions, case definitions, laboratory and EHR feeds, identity resolution, social data, immigration and law-enforcement separation, tribal sovereignty, vendor platforms, emergencies, and research and should be tested with patients and communities; clinicians and laboratories; health departments; CDC; Tribes; schools and employers; data intermediaries; privacy and civil-rights officers; legislators; and researchers. The practical review asks whether a person can obtain notice where lawful, understand the basis, provide contrary information, request accommodation or urgency, receive reasons, and correct every downstream use that relied on an error. Capacity—staff, language services, accessibility, clinical expertise, security, procurement, and vendor cooperation—is part of validity in practice. The safeguard remains bounded by this article's red lines: Do not say HIPAA permission creates reporting authority; do not treat absence from surveillance as absence of disease; do not repurpose data for unrelated enforcement without lawful authority.
Cross-cutting governance tests
Authority and status. Every material claim in Public Health Surveillance Authority and Its Limits should be tagged as controlling law, operative order, current agency position, technical standard, contractual rule, dataset, research evidence, attributed experience, inference, or proposal. That tag determines the verb. A court's vacatur, an agency's extension, a final rule's compliance date, or an unfinished rulemaking must appear next to the affected proposition rather than in a remote caveat.
Data and workflow provenance. The record path is health threat and authority → reporting specification → collection → identity and quality control → analysis → public-health action → sharing → retention or deletion → evaluation. Preserve who created each element, when, from which system or authority, for what purpose, and after what transformation. Where a derived field, dashboard, risk score, or summary drives action, retain a route to the underlying evidence. Lack of a public record should be described as an access limit, not proof that no confidential event or lawful restriction exists.
Purpose and proportionality. A rule designed for one purpose should not silently expand to another. For Public Health Surveillance Authority and Its Limits, compare the information collected and consequence imposed with the stated public objective. A preliminary signal may justify review but not a durable adverse label. An emergency exception may justify temporary access but not indefinite retention or unrelated reuse. Stronger and less reversible consequences require stronger evidence, reasons, human authority, and meaningful review.
Distribution and accessibility. For Public Health Surveillance Authority and Its Limits, average results can conceal predictable barriers associated with geography, language, disability, income, digital access, institutional size, or ability to wait. Analyze the mechanism before publishing a subgroup comparison. Determine whether the proposal changes access to information, clinical services, representation, appeals, correction, transportation, or technical support, and whether the relevant institution has authority and resources to repair the identified pathway.
Security, privacy, and continuity. Confidentiality is not a reason to omit operational planning, and transparency is not a license to disclose sensitive records. Public Health Surveillance Authority and Its Limits requires role-based access, minimum necessary information where applicable, secure exchange, reliable availability, incident response, lawful public reporting, retention control, and a method for continuing critical work when technology or a vendor fails. Each objective should be tied to a responsible owner rather than assigned to an abstract system.
Correction and learning. The Public Health Surveillance Authority and Its Limits audit trail should contain the source, status, version, actor, criteria, affected population, decision, reason, exception, reviewer, and correction history. A correction is incomplete if it changes only the originating page while a portal, report, search result, recipient database, clinical decision, or public label continues to carry the error. Recurring corrections should produce a root-cause review and a change to policy, training, technology, staffing, or oversight.
Ten-step verification and implementation protocol
- State the exact legal, factual, technical, causal, and normative claims being evaluated in Public Health Surveillance Authority and Its Limits.
- Fix the jurisdiction and coordinates: U.S. federal, state, local, territorial, and Tribal surveillance systems and health-data law.
- Identify the decision-maker, data controller, operational owner, affected population, consequence, and available remedy.
- Locate current primary authorities and record source type, status, version, effective or compliance date, litigation status, and scope.
- Reconstruct the workflow without skipping stages: health threat and authority → reporting specification → collection → identity and quality control → analysis → public-health action → sharing → retention or deletion → evaluation.
- Test the operative mechanisms, including notifiable disease law, HIPAA permissions, case definitions, laboratory and EHR feeds, identity resolution, social data, immigration and law-enforcement separation, tribal sovereignty, vendor platforms, emergencies, and research.
- Select outcome, process, balancing, and distribution measures from this set: coverage, timeliness, completeness, positive predictive value, representativeness, reporting burden, actions taken, security incidents, secondary uses, retention, and community trust.
- Seek later history, disconfirming evidence, alternative mechanisms, edge cases, and perspectives from differently situated participants.
- Draft with status-accurate verbs, nearby citations, explicit uncertainty, and a visible distinction between official source and original recommendation.
- Reopen every link, recheck numbers and current status, confirm review and correction routes, and timestamp the final public version.
Failure modes that should stop publication or implementation
- Treating mandatory report, case surveillance, syndromic surveillance, laboratory report, public-health investigation, research, program evaluation, intelligence, and law enforcement as though the categories carry the same authority or consequence.
- Using a summary, press release, dashboard, or vendor statement where current controlling text or originating data are necessary.
- Converting a proposal, allegation, technical capability, voluntary framework, or selected enforcement action into a universal final rule.
- Publishing a total or ranking without the unit, relevant exposure population, time cohort, ascertainment limits, and revision history.
- Ignoring an effective date, compliance transition, injunction, vacatur, extension, state-law overlay, contract, or later correction.
- Adopting a reform without confronting its operational mechanisms: notifiable disease law, HIPAA permissions, case definitions, laboratory and EHR feeds, identity resolution, social data, immigration and law-enforcement separation, tribal sovereignty, vendor platforms, emergencies, and research.
- Failing to include or account for the relevant participants: patients and communities; clinicians and laboratories; health departments; CDC; Tribes; schools and employers; data intermediaries; privacy and civil-rights officers; legislators; and researchers.
- Crossing these substantive boundaries: Do not say HIPAA permission creates reporting authority; do not treat absence from surveillance as absence of disease; do not repurpose data for unrelated enforcement without lawful authority.
Questions for boards, agencies, health systems, and reporters
- What exact action, right, restriction, data flow, or outcome is at issue in Public Health Surveillance Authority and Its Limits?
- Which institution has legal authority, which has information, which operates the workflow, and which can repair the result?
- What is the current primary source, what is its legal or evidentiary status, and what does it leave unanswered?
- Which population, program, data class, purpose, jurisdiction, time, and technology version are inside the claim?
- Where can the workflow fail along this path: health threat and authority → reporting specification → collection → identity and quality control → analysis → public-health action → sharing → retention or deletion → evaluation?
- Which of these mechanisms is actually operating: notifiable disease law, HIPAA permissions, case definitions, laboratory and EHR feeds, identity resolution, social data, immigration and law-enforcement separation, tribal sovereignty, vendor platforms, emergencies, and research?
- What would a plausible competing explanation predict, and which record could distinguish it?
- Are the proposed measures sufficient to reveal benefit, error, delay, burden, and distribution: coverage, timeliness, completeness, positive predictive value, representativeness, reporting burden, actions taken, security incidents, secondary uses, retention, and community trust?
- Can an affected person understand the basis, obtain needed access or accommodation, present contrary information, and receive a reasoned response?
- How will an error be corrected in the source record and in every important downstream use?
- What staffing, expertise, technology, translation, accessibility, security, procurement, or interagency capacity is assumed?
- What evidence would require the institution to pause, narrow, reverse, or retire the policy?
Reform direction
The recommended direction is a purpose-limited surveillance charter with statutory mapping, minimum and standardized data, quality and equity analysis, access controls, public use registers, retention rules, Tribal and community governance, and action-based evaluation. Implementation should begin with a written objective, a current authority map, named decision and operational owners, and a specification of the population and outcome being protected. The design should identify dependencies and failure recovery rather than assigning responsibility to the final worker, the patient, or a vendor whose contract does not match its practical control.
The implementation model must address notifiable disease law, HIPAA permissions, case definitions, laboratory and EHR feeds, identity resolution, social data, immigration and law-enforcement separation, tribal sovereignty, vendor platforms, emergencies, and research. For each mechanism, leaders should define the expected control, the evidence that the control operated, an exception or escalation path, and the person who reviews failure. Pilot testing should include ordinary workload, urgent cases, uncommon data or languages, accessibility needs, small and less-resourced organizations, vendor outages, and conflicting authority. A policy that works only in a demonstration environment should not be represented as system capacity.
Evaluation should publish definitions and use coverage, timeliness, completeness, positive predictive value, representativeness, reporting burden, actions taken, security incidents, secondary uses, retention, and community trust. Results should be shown with appropriate denominators, cohorts, severity, tail delay, missingness, uncertainty, revisions, and distribution where reliable. Activity measures can explain workload but should not substitute for protection, access, accuracy, continuity, fairness, or durable correction. Independent review is most credible when its methods, access, conflicts, disagreements, and institutional response are documented.
Finally, implementation should make the boundaries enforceable: Do not say HIPAA permission creates reporting authority; do not treat absence from surveillance as absence of disease; do not repurpose data for unrelated enforcement without lawful authority. Affected people need a usable route for questions, urgency, accommodation, access, challenge, and correction. Leaders should review adverse events, appeals, overrides, disparities, workarounds, security incidents, vendor changes, and source updates on a scheduled cycle. Adoption is the beginning of evidence, not the end; failure to produce the expected outcomes should trigger revision rather than a search for a more flattering metric.
Conclusion
Surveillance legitimacy comes from a defined public-health purpose and authority, not from the technical ability to collect. Each data stream needs a case definition, minimum dataset, quality plan, security, role separation, use restrictions, retention schedule, public explanation, and evidence that collection supports action. The conclusion is intentionally narrower than a slogan because Public Health Surveillance Authority and Its Limits crosses legal, technical, clinical, administrative, and human boundaries. Each layer requires the source competent to establish it and a workflow capable of carrying the rule into ordinary practice.
The policy choice should be tested through coverage, timeliness, completeness, positive predictive value, representativeness, reporting burden, actions taken, security incidents, secondary uses, retention, and community trust. Those measures can reveal whether the reform protected people, improved access or accuracy, reduced preventable delay, and avoided transferring burden. They also create a basis for correction. When a later source, revised dataset, incident, appeal, or patient experience contradicts the expected result, governance should make revision possible before the error becomes normal practice.
A skeptical reader should be able to reconstruct every major claim in Public Health Surveillance Authority and Its Limits from current authority to operational mechanism to measured outcome. Law remains law, guidance remains guidance, technology remains a tool, evidence retains its limits, and the recommendation remains the author's analysis. That disciplined separation is how a long-form policy article can be both useful now and correctable later.
Authority-first application map
Separate modernization from legal authority. A data-modernization program asks whether agencies can receive, standardize, match, analyze, and return information reliably. An authority audit asks a different sequence of questions: who may demand or receive which field, from whom, under what legal predicate, for what public-health purpose, with which procedural protections, for how long, and with what consequence for refusal or error. New infrastructure can make an authorized workflow faster, but speed does not enlarge jurisdiction. Conversely, a fragmented or manual system does not erase a valid reporting duty. Boards should maintain an authority register alongside the system inventory so that each interface, message type, and recurring report is tied to a current statute, regulation, order, agreement, or voluntary consent pathway.
Map federalism before mapping feeds. Most routine case reporting enters through state, territorial, Tribal, or local law, while federal agencies operate under separate statutory programs and interstate or international functions. The correct map therefore begins with the reporting jurisdiction, the covered disease or condition, the person or organization subject to the duty, the event that triggers reporting, the deadline, the required elements, the authorized recipient, and available enforcement or appeal. A national case definition can support comparable surveillance without itself creating a universal duty for every clinician or laboratory. Likewise, an electronic connection to a federal platform does not prove that the federal government compelled the originating disclosure. The authority chain must preserve each governmental layer rather than converting interoperability into a single national police power.
Distinguish a duty from a permission. A provider may face a state-law duty to report a condition, and the HIPAA Privacy Rule may permit the disclosure to a public-health authority without individual authorization. Those propositions answer different questions. HIPAA permission does not create the underlying state duty, identify every required field, or validate an unrelated reuse. A disclosure that is permitted may still be poorly designed, broader than the operative request, insecurely transmitted, or inconsistent with another applicable protection. The audit record should separately state the reporting mandate, the Privacy Rule pathway, the identity and legal status of the recipient, the minimum dataset specified by governing authority, the transmission method, and any stricter state, Tribal, substance-use, genetic, school, or program-specific rule.
Specify the public-health purpose at field level. “Surveillance” is too broad to justify indefinite collection. A field may support case confirmation, duplicate resolution, exposure notification, treatment linkage, geographic response, equity analysis, resource allocation, or statutory reporting, and the necessity may differ for each purpose. The data dictionary should name the purpose, legal basis, sensitivity, permissible users, source of truth, quality limitations, access tier, release rule, and retention trigger for every consequential field. Free-text clinical notes, precise location, immigration information, employer details, relationship data, and law-enforcement identifiers require special scrutiny because they can carry facts unrelated to the disease-control task. If the agency cannot explain why a field changes an authorized decision, collection should pause or move to a more restricted pathway.
Treat identity resolution as a rights issue. Surveillance systems must distinguish the same person reported by multiple laboratories from different people who share a name, address, or birth date. False merges can attach a diagnosis, exposure, isolation action, or risk label to the wrong person; false splits can inflate counts and prevent follow-up. The program should document matching rules, confidence thresholds, manual-review criteria, demographic and naming limitations, correction authority, and propagation of corrections to downstream datasets. An individual may not have a general right to inspect every internal public-health record, but that does not eliminate the agency's responsibility to investigate credible identity errors, correct operational consequences, and avoid presenting a probabilistic match as verified fact.
Keep routine and emergency powers distinct. A declared emergency can activate or support specific authorities, appropriations, waivers, contracts, and accelerated workflows, but it should not be used as a retrospective explanation for every surveillance practice. Routine communicable-disease reporting, syndromic monitoring, emergency orders, quarantine powers, laboratory networks, and research each have different predicates and termination rules. The operational register should state whether a collection continues under ordinary law after an emergency ends, whether a temporary order or agreement expires, whether retained information may still be used, and which public notice changes. Sunset review is particularly important when emergency urgency caused agencies to accept broader fields, new vendors, provisional matching, or less-tested access controls.
Separate surveillance from investigation and enforcement. Population monitoring can identify a signal that merits clinical or epidemiologic follow-up; it does not by itself establish that a named person violated a rule, caused an outbreak, or warrants an adverse employment, immigration, licensing, or criminal consequence. Agencies should document when information moves from aggregate monitoring to individual follow-up, who authorizes the transition, what corroboration is required, and which disclosures are permitted. Access for epidemiologists should not silently become general access for unrelated enforcement units. Where law authorizes a specific referral, the record should preserve the legal predicate, fields shared, recipient, purpose, date, and limitation on onward use rather than relying on a broad memorandum of understanding.
Design public reporting around both utility and restraint. A public dashboard should answer a defined community question with a denominator and time window that match the signal. Small cells, rare conditions, facility-level data, precise geography, and frequent updates can create re-identification or stigmatization risk even after direct identifiers are removed. Suppression, aggregation, statistical uncertainty, delayed release, qualitative explanation, and restricted researcher access are tools with different tradeoffs. The release review should also ask whether missing laboratories, care-seeking differences, changes in testing, revised case definitions, duplicate cleanup, or late reports could produce the observed pattern. A transparent caveat is part of the result, not a footnote that can be omitted from screenshots or downstream reuse.
Build correction and contestability into operations. Public-health action sometimes must precede complete certainty, but urgency changes timing rather than the obligation to correct. The program should identify which records can trigger outreach, exclusion, isolation, prophylaxis, clinical alerts, public counts, or resource decisions; define the evidentiary threshold for each consequence; and create a route for clinicians, laboratories, jurisdictions, and affected people to report error. Corrections should be versioned, attributed, and propagated. Where the agency cannot provide direct notice because of law, scale, or investigation needs, it should still maintain internal reason codes, supervisory review, error monitoring, and public descriptions of correction practice sufficient for oversight.
Use a stopping rule, not merely a retention schedule. A retention period answers when a record is eligible for deletion; a stopping rule asks whether collection, linkage, access, or use remains justified at all. The review should consider whether the condition is still reportable, whether the field changes a current response, whether the dataset remains sufficiently complete and accurate, whether a less intrusive source is available, whether a temporary linkage has achieved its purpose, and whether harms now exceed expected benefit. Decisions to continue should identify the accountable official and evidence. Decisions to stop should address archival law, approved research transition, vendor copies, backups, public products, and downstream systems so that an obsolete surveillance purpose does not survive through technical inertia.
Sources and Authorities
Each source below was verified against the official publisher, current through August 10, 2026. Laws, proposed rules, and agency pages change; every link is re-opened live at deployment, and time-sensitive requirements should be checked against the current official source.
CDC — What Is Case Surveillance?
HHS OCR — Public Health Uses and Disclosures Under HIPAA
CDC — Public Health Data Strategy
CDC Field Epidemiology Manual — Describing epidemiologic data
Related Articles
Educational information notice: this article provides general educational information for physicians, medical staff, and policy audiences and is not legal or medical advice. It does not create an attorney-client or physician-patient relationship. Statutes, regulations, proposed rules, and agency guidance change; individual matters require qualified counsel.