Confidentiality/HIPAA
Patients have the right to request that their protected health information be amended by their healthcare provider to correct incomplete or incorrect information upon submission of a written request. Once a request is made, deadlines go into effect and must be acted upon by the provider in a timely manner. (See HIPAA Privacy Rule – Standard 164.526). However, the office may deny a patient’s request for amendment if the office determines that the protected information subject to the request:
- Was not created by the office, unless the individual provides a reasonable basis to believe that the originator of the protected health information is no longer available to act on the requested information.
- Would not be available to the patient for inspection (see HIPAA Privacy Rule 164.524 for exceptions to a patient’s right to access protected health information).
- Is accurate and complete.
Should a provider deny a patient’s request to amend his/her protected health information, the provider must provide the patient with a written explanation of the denial. The patient will have the right to file a statement of disagreement or to request that the office include the individual’s request for amendment and the denial with any future disclosures of the protected health information subject to the request.
If a doctor sees evidence of child abuse, he or she has a duty to report this to authorities under most states’ law and no release is required. If evidence of abuse is not apparent during a visit, or from the patient record itself, and a law enforcement officer simply makes a verbal or written request to see the chart, the doctor is not required to provide copies of the record. The doctor may do so under certain limited circumstances, however, primarily when the alleged victim of the crime is incapacitated.
The HIPAA Security Rule requires practices to notify a patient in the event that unsecured protected health information is disclosed to an unauthorized person. Unsecured protected health information means health information that is not protected by technology that renders it unusable or unreadable to unauthorized persons.
The patient must be notified in writing by first class mail as soon as possible, but no later than 60 days after discovery of the unauthorized disclosure by the practice. If the practice does not have current mailing information, notice may be given by telephone or email. The notification must include, to the extent possible, the following:
- A brief description of what happened, including the date of the unauthorized disclosure and the date of its discovery.
- A description of the type of health information involved in the disclosure (e.g., name, Social Security number, date of birth, diagnoses, etc.).
- The steps the patient should take to protect himself/herself from potential harm resulting from the disclosure.
- A brief description of what the practice is doing to investigate the disclosure, mitigate its impact and to protect against future unauthorized disclosures.
- Contact information for the patient to ask questions (a toll-free telephone number, email address, website or postal address).
If the practice does not have current contact information on 10 or more patients affected by the unauthorized disclosure, the practice must give notice by posting on the practice’s website for at least 90 days, or by placing a notice in a major print or broadcast media in the geographic area where the patients most likely reside.
If the breach affects 500 or more patients affected by the unauthorized disclosure, the practice must give notification through major media outlets serving the city or town in which the practice is located. In addition, notification must be given to the Department of Health and Human Services (DHHS) of the breach. If the unauthorized disclosure involved less than 500 patients, the practice must maintain a log of the incident and submit the log to the federal DHHS at the end of the calendar year. If the disclosure involves more than 500 patients, the practice must notify DHHS immediately.
The U.S. Department of Health and Human Services, Office of Civil Rights, has a HIPAA website which has a wealth of information. Additionally, the American Health Information Management (AHIMA) website has several “Practice Briefs” on various HIPAA topics.
Disclaimer: The information contained in these FAQs do not establish a standard of care, nor do they constitute legal advice. These FAQs are for general informational purposes only and are written from a risk management perspective to aid in reducing professional liability exposure. You are encouraged to consult with your personal attorney for legal advice, as specific legal requirements may vary from state to state. Links or references to organizations, websites, or other information is for reference use only and do not constitute the rendering of legal, financial, or other professional advice or recommendations.