HIPAA authorization and security
Permission requiring written authorization
The only permission that requires written authorization from patients is disclosing the PHI to a third party. Examples of this type of disclosure may include when the patient wants another person to be told information or when the patient wants the records transferred to another facility. This may include a life insurance company, an employer for a pre-employment health requirement, another healthcare facility, or the patient’s lawyer. In both situations, the patient must sign a form allowing the information to be released. In some agencies, a disclosure authorization form (also called an authorization to disclose form) must be completed before information can be shared with another person. The patient must complete a record release form before the records can be transferred. The form names can differ from facility to facility. Some facilities combine these into a single document, which may be titled a release of information authorization or similar.
The forms typically require the patient to indicate the information to be released/disclosed. The form must include the patient’s name and the date of the request. The person or facility disclosing the information and receiving the information must be indicated. The form must include an expiration date. These forms also include a statement to notify patients of their right to revoke the release.
Disclosure authorization process
When patients request their information to be given to another person (e.g., family member or friend), the medical assistants can help. They can assist patients in completing the disclosure authorization form. Once completed, this form must be added to the patient’s health record.
When a person calls requesting information on a current patient, the medical assistant should first ask the caller’s name. The medical assistant must check and see if the caller is listed on the patient’s disclosure authorization form. If that caller’s name appears, then, per the facility’s policy, the medical assistant can release information about the patient. If the caller’s name is not on the form, the medical assistant has the following limitations:
- Cannot release the patient’s information
- Cannot even acknowledge that that person is a patient of the facility
Applying HIPAA rules is important when protecting a patient’s privacy.
In some facilities, the patient supplies a code word or number. This is documented in the patient’s health record. The patient gives this code to family members. When they call the staff and give the code, the staff member can provide an update on the patient. It is understood that the patient gives consent to anyone who received the code. This helps to settle the issue of who is really calling requesting information. The code system may be seen more in the ambulatory surgical departments.
Records release process
Patients must complete, date, and sign a (medical) records release form for their records to be transferred to another. No records, including images and videos, can be released without the completed form. Release forms may specifically address the release of videos and images. With these forms, patients must indicate they want these to be released. If that is not done, then the videos and images are not released.
Parts of the patient record are held at a higher level of confidentiality. Many release forms require the patient to indicate if psychotherapy notes, substance abuse information, and human immunodeficiency virus (HIV) information should be released. Such information may not be automatically released with the other records due to federal and state legislation.
Under HIPAA, psychotherapy notes are treated with higher levels of confidentiality. Psychotherapy notes include the patient-provider details from mental health treatment, either from a private, group, or family therapy. Psychotherapy notes include what the patient stated during the session and the provider’s analysis of the patient’s statements and the situation. Psychotherapy notes need to be stored separately from the patient paper health record. If the health record is electronic, the access to the psychotherapy notes is limited to those healthcare professionals who work in the mental health area. Additional information from the visit is not held at a higher level of confidentiality and includes prescriptions, session times, types and frequency of treatments, and results of clinical tests.
Drug and alcohol substance abuse and HIV content in patient records also are held at a higher level of confidentiality. There are many federal and state laws that relate to the privacy of these records. The federal statute called Confidentiality of Alcohol and Drug Abuse Patient Records, enforced by a division of HHS, is one example. This law restricts the release and use of patient records that include substance use diagnoses and services. State preemption applies to these privacy laws.
HIPAA security rule
HIPAA’s Security Rule addresses the national standards used to protect electronic protected health information (ePHI). This rule covers the records that are created, used, received, and maintained by the covered entities.
Safeguards of the security rule
Safeguards important to ensure the security of the ePHI include the following:
- Administrative safeguards: The security officer is responsible for creating and carrying out security policies and procedures. Potential risks to the ePHI must be identified. Steps must be taken to prevent any issues. Cyber attackers pose a huge risk to network security.
- Physical safeguards: Facility, workstation, and device security must be implemented. A security officer must create procedures for the proper use of workstations and ePHI.
- Technical safeguards: Only authorized employees should have access to ePHI. Safeguards include audits to track the activities of users with the ePHI and encryption of data on mobile devices. They also include safeguards to prevent improper alteration, destruction, or transmission of ePHI.
It is important for the medical assistant to follow the healthcare facility’s electronic security procedures. Many facilities have policies to keep passwords confidential. Downloading personal documents puts the computer network at risk and thus is not allowed. Audit trails monitor who is looking at which patient’s chart. If the medical assistant is not working with a specific patient, then the patient record should not be accessed. Violating this rule will cause the medical assistant to breach the patient’s confidentiality and security. Many healthcare professionals, from providers to medical assistants, have breached confidentiality. They have lost their jobs and licenses or certifications. Many have also been fined. Healthcare employees cannot access their own health record or that of their family members. Most agencies require the employee to follow the patient’s review of health record policy. Violating this policy can also lead to termination.
