Skip to content

Confidentiality/HIPAA

May I disclose health information to a patient’s family member or friend?
The U.S. Department of Health and Human Services published a guide, which can be accessed here. This guide explains when a healthcare provider is allowed to share a patient’s health information with the patient’s family members, friends or others identified by the patient as involved in the patient’s care under HIPAA.
May I leave diagnostic test results on a patient’s voicemail?
No. The best practice is to leave a call back number with the patient. It is acceptable to leave messages on a patient’s phone voicemail; however, care should be taken to limit the amount of information disclosed in order to reasonably safeguard the patient’s privacy. Additionally, you cannot be sure the patient receives the test result if you leave a message. It is best to deliver test results directly to the patient. Be sure the conversation with the patient is documented in the patient’s record, including the date and time of the call, the exact information given, and who relayed the information.
Do patients have the right to request restrictions to the use or disclosure of their health information?
Under the initial HIPAA privacy rule, the patient had the right to request restrictions to the use or disclosure of his/her private health information (PHI), but the provider did not have to agree to the restrictions. However, the new Health Information Technology for Economic and Clinical Health Act (HITECH) increases the patient’s right to request restrictions on disclosure of the patient’s PHI. Now, providers must agree to patients’ requests to restrict disclosure of PHI to an insurance company if the patient paid cash for the service.
Do patients have the right to request an amendment to their medical records?

Patients have the right to request that their protected health information be amended by their healthcare provider to correct incomplete or incorrect information upon submission of a written request. Once a request is made, deadlines go into effect  and must be acted upon by the provider in a timely manner. (See HIPAA Privacy Rule – Standard 164.526). However, the office may deny a patient’s request for amendment if the office determines that the protected information subject to the request:

  1. Was not created by the office, unless the individual provides a reasonable basis to believe that the originator of the protected health information is no longer available to act on the requested information.
  2. Would not be available to the patient for inspection (see HIPAA Privacy Rule 164.524 for exceptions to a patient’s right to access protected health information).
  3. Is accurate and complete.

Should a provider deny a patient’s request to amend his/her protected health information, the provider must provide the patient with a written explanation of the denial. The patient will have the right to file a statement of disagreement or to request that the office include the individual’s request for amendment and the denial with any future disclosures of the protected health information subject to the request.

The state is investigating a child abuse case and has requested a copy of the child’s patient records. May I release a copy of the records to the investigator?
The law surrounding this issue varies by each state. It is highly recommended to consult with personal counsel or contact OUM. If you receive a subpoena or court order, there may be deadlines for you to respond. Under no circumstances should a subpoena go unanswered, otherwise you may waive certain rights or defenses available to you and the patient.

If a doctor sees evidence of child abuse, he or she has a duty to report this to authorities under most states’ law and no release is required. If evidence of abuse is not apparent during a visit, or from the patient record itself, and a law enforcement officer simply makes a verbal or written request to see the chart, the doctor is not required to provide copies of the record. The doctor may do so under certain limited circumstances, however, primarily when the alleged victim of the crime is incapacitated.
My patient’s prior doctor wants my patient’s test results. Am I allowed to provide him with the results without my patient’s permission?
The HIPAA Privacy Rule (45 CFR 164.506) allows healthcare providers to share protected health information for treatment purposes without the patient’s authorization. However, if a prior healthcare provider is no longer involved in the care and treatment, you should not disclose a patient’s information without the express written consent of the patient.
The hard drive containing patient information was stolen from one of my computers. What should I do?

The HIPAA Security Rule requires practices to notify a patient in the event that unsecured protected health information is disclosed to an unauthorized person. Unsecured protected health information means health information that is not protected by technology that renders it unusable or unreadable to unauthorized persons.

The patient must be notified in writing by first class mail as soon as possible, but no later than 60 days after discovery of the unauthorized disclosure by the practice. If the practice does not have current mailing information, notice may be given by telephone or email. The notification must include, to the extent possible, the following:

  • A brief description of what happened, including the date of the unauthorized disclosure and the date of its discovery.
  • A description of the type of health information involved in the disclosure (e.g., name, Social Security number, date of birth, diagnoses, etc.).
  • The steps the patient should take to protect himself/herself from potential harm resulting from the disclosure.
  • A brief description of what the practice is doing to investigate the disclosure, mitigate its impact and to protect against future unauthorized disclosures.
  • Contact information for the patient to ask questions (a toll-free telephone number, email address, website or postal address).

If the practice does not have current contact information on 10 or more patients affected by the unauthorized disclosure, the practice must give notice by posting on the practice’s website for at least 90 days, or by placing a notice in a major print or broadcast media in the geographic area where the patients most likely reside.

If the breach affects 500 or more patients affected by the unauthorized disclosure, the practice must give notification through major media outlets serving the city or town in which the practice is located. In addition, notification must be given to the Department of Health and Human Services (DHHS) of the breach. If the unauthorized disclosure involved less than 500 patients, the practice must maintain a log of the incident and submit the log to the federal DHHS at the end of the calendar year. If the disclosure involves more than 500 patients, the practice must notify DHHS immediately.

Where can I find information regarding HIPAA?

The U.S. Department of Health and Human Services, Office of Civil Rights, has a HIPAA website which has a wealth of information. Additionally, the American Health Information Management (AHIMA) website has several “Practice Briefs” on various HIPAA topics.

Disclaimer: The information contained in these FAQs do not establish a standard of care, nor do they constitute legal advice. These FAQs are for general informational purposes only and are written from a risk management perspective to aid in reducing professional liability exposure. You are encouraged to consult with your personal attorney for legal advice, as specific legal requirements may vary from state to state. Links or references to organizations, websites, or other information is for reference use only and do not constitute the rendering of legal, financial, or other professional advice or recommendations.