Achievable logoAchievable logo
CCMA
Sign in
Sign up
Purchase
Textbook
Practice exams
Support
How it works
Resources
Exam catalog
Mountain with a flag at the peak
Textbook
Introduction
1. Medical assistant
2. Electronic records
3. Medical terminology and anatomy
4. The fundamentals of infection control
5. Introduction to vital signs
6. The patient interview and history
7. The physical examination
8. Appointment scheduling
9. Insurance billing
9.1 Health insurance basics
9.2 Government health plans: Medicare and Medicaid programs
9.3 Other government and private health plans
9.4 The medical assistant's role
9.5 HIPAA overview and the privacy rule
9.6 HIPAA authorization and security
9.7 Other private laws
9.8 Healthcare laws overview
9.9 Reporting obligations and incident management
10. Diagnostic coding and the ICD-10-CM System
11. Procedural coding
12. Medical billing and reimbursement essentials
13. Assisting with medical specialties
14. Assisting with the musculoskeletal system
15. Assisting with the cardiovascular system
16. Assisting with the respiratory system
17. Assisting with the nervous system
18. Anatomy and physiology of the urinary system
19. Assisting in obstetrics and gynecology
20. Assisting in endocrinology
21. Assisting in ophthalmology & otolaryngology
22. Assisting in gastroenterology
23. Assisting in the immune & lymphatic systems
24. Assisting in pediatrics: the developmental stages and care
25. The medical assistant’s role in caring for the older patient
26. The role of the medical assistant in physical therapy examination and assessment
27. Preparing for minor surgery: room, solutions, and supplies
28. Introduction to the clinical laboratory
29. Urinalysis
30. Blood collection
31. Analysis of blood
32. Electrocardiography and heart structure
33. The principles of pharmacology
34. Essential calculations and measurement systems
35. Solid, liquid, & solutions medication doses
36. Administering medications
37. Metabolism and core nutrient roles
38. Medical emergencies in the healthcare setting
Achievable logoAchievable logo
9.6 HIPAA authorization and security
Achievable CCMA
9. Insurance billing

HIPAA authorization and security

6 min read
Font
Discuss
Share
Feedback

Permission requiring written authorization

The only permission that requires written authorization from patients is disclosing the PHI to a third party. Examples of this type of disclosure may include when the patient wants another person to be told information or when the patient wants the records transferred to another facility. This may include a life insurance company, an employer for a pre-employment health requirement, another healthcare facility, or the patient’s lawyer. In both situations, the patient must sign a form allowing the information to be released. In some agencies, a disclosure authorization form (also called an authorization to disclose form) must be completed before information can be shared with another person. The patient must complete a record release form before the records can be transferred. The form names can differ from facility to facility. Some facilities combine these into a single document, which may be titled a release of information authorization or similar.

The forms typically require the patient to indicate the information to be released/disclosed. The form must include the patient’s name and the date of the request. The person or facility disclosing the information and receiving the information must be indicated. The form must include an expiration date. These forms also include a statement to notify patients of their right to revoke the release.

Disclosure authorization process

When patients request their information to be given to another person (e.g., family member or friend), the medical assistants can help. They can assist patients in completing the disclosure authorization form. Once completed, this form must be added to the patient’s health record.

When a person calls requesting information on a current patient, the medical assistant should first ask the caller’s name. The medical assistant must check and see if the caller is listed on the patient’s disclosure authorization form. If that caller’s name appears, then, per the facility’s policy, the medical assistant can release information about the patient. If the caller’s name is not on the form, the medical assistant has the following limitations:

  • Cannot release the patient’s information
  • Cannot even acknowledge that that person is a patient of the facility

Applying HIPAA rules is important when protecting a patient’s privacy.

In some facilities, the patient supplies a code word or number. This is documented in the patient’s health record. The patient gives this code to family members. When they call the staff and give the code, the staff member can provide an update on the patient. It is understood that the patient gives consent to anyone who received the code. This helps to settle the issue of who is really calling requesting information. The code system may be seen more in the ambulatory surgical departments.

Records release process

Patients must complete, date, and sign a (medical) records release form for their records to be transferred to another. No records, including images and videos, can be released without the completed form. Release forms may specifically address the release of videos and images. With these forms, patients must indicate they want these to be released. If that is not done, then the videos and images are not released.

Parts of the patient record are held at a higher level of confidentiality. Many release forms require the patient to indicate if psychotherapy notes, substance abuse information, and human immunodeficiency virus (HIV) information should be released. Such information may not be automatically released with the other records due to federal and state legislation.

Release of information form used in medical records
Release of information
Achievable

Under HIPAA, psychotherapy notes are treated with higher levels of confidentiality. Psychotherapy notes include the patient-provider details from mental health treatment, either from a private, group, or family therapy. Psychotherapy notes include what the patient stated during the session and the provider’s analysis of the patient’s statements and the situation. Psychotherapy notes need to be stored separately from the patient paper health record. If the health record is electronic, the access to the psychotherapy notes is limited to those healthcare professionals who work in the mental health area. Additional information from the visit is not held at a higher level of confidentiality and includes prescriptions, session times, types and frequency of treatments, and results of clinical tests.

Drug and alcohol substance abuse and HIV content in patient records also are held at a higher level of confidentiality. There are many federal and state laws that relate to the privacy of these records. The federal statute called Confidentiality of Alcohol and Drug Abuse Patient Records, enforced by a division of HHS, is one example. This law restricts the release and use of patient records that include substance use diagnoses and services. State preemption applies to these privacy laws.

HIPAA security rule

HIPAA’s Security Rule addresses the national standards used to protect electronic protected health information (ePHI). This rule covers the records that are created, used, received, and maintained by the covered entities.

Safeguards of the security rule

Safeguards important to ensure the security of the ePHI include the following:

  • Administrative safeguards: The security officer is responsible for creating and carrying out security policies and procedures. Potential risks to the ePHI must be identified. Steps must be taken to prevent any issues. Cyber attackers pose a huge risk to network security.
  • Physical safeguards: Facility, workstation, and device security must be implemented. A security officer must create procedures for the proper use of workstations and ePHI.
  • Technical safeguards: Only authorized employees should have access to ePHI. Safeguards include audits to track the activities of users with the ePHI and encryption of data on mobile devices. They also include safeguards to prevent improper alteration, destruction, or transmission of ePHI.

It is important for the medical assistant to follow the healthcare facility’s electronic security procedures. Many facilities have policies to keep passwords confidential. Downloading personal documents puts the computer network at risk and thus is not allowed. Audit trails monitor who is looking at which patient’s chart. If the medical assistant is not working with a specific patient, then the patient record should not be accessed. Violating this rule will cause the medical assistant to breach the patient’s confidentiality and security. Many healthcare professionals, from providers to medical assistants, have breached confidentiality. They have lost their jobs and licenses or certifications. Many have also been fined. Healthcare employees cannot access their own health record or that of their family members. Most agencies require the employee to follow the patient’s review of health record policy. Violating this policy can also lead to termination.

Sign up for free to take 14 quiz questions on this topic

Previous
Next  | 9.7 Other private laws
All rights reserved ©2016 - 2026 Achievable, Inc.

HIPAA authorization and security

Permission requiring written authorization

The only permission that requires written authorization from patients is disclosing the PHI to a third party. Examples of this type of disclosure may include when the patient wants another person to be told information or when the patient wants the records transferred to another facility. This may include a life insurance company, an employer for a pre-employment health requirement, another healthcare facility, or the patient’s lawyer. In both situations, the patient must sign a form allowing the information to be released. In some agencies, a disclosure authorization form (also called an authorization to disclose form) must be completed before information can be shared with another person. The patient must complete a record release form before the records can be transferred. The form names can differ from facility to facility. Some facilities combine these into a single document, which may be titled a release of information authorization or similar.

The forms typically require the patient to indicate the information to be released/disclosed. The form must include the patient’s name and the date of the request. The person or facility disclosing the information and receiving the information must be indicated. The form must include an expiration date. These forms also include a statement to notify patients of their right to revoke the release.

Disclosure authorization process

When patients request their information to be given to another person (e.g., family member or friend), the medical assistants can help. They can assist patients in completing the disclosure authorization form. Once completed, this form must be added to the patient’s health record.

When a person calls requesting information on a current patient, the medical assistant should first ask the caller’s name. The medical assistant must check and see if the caller is listed on the patient’s disclosure authorization form. If that caller’s name appears, then, per the facility’s policy, the medical assistant can release information about the patient. If the caller’s name is not on the form, the medical assistant has the following limitations:

  • Cannot release the patient’s information
  • Cannot even acknowledge that that person is a patient of the facility

Applying HIPAA rules is important when protecting a patient’s privacy.

In some facilities, the patient supplies a code word or number. This is documented in the patient’s health record. The patient gives this code to family members. When they call the staff and give the code, the staff member can provide an update on the patient. It is understood that the patient gives consent to anyone who received the code. This helps to settle the issue of who is really calling requesting information. The code system may be seen more in the ambulatory surgical departments.

Records release process

Patients must complete, date, and sign a (medical) records release form for their records to be transferred to another. No records, including images and videos, can be released without the completed form. Release forms may specifically address the release of videos and images. With these forms, patients must indicate they want these to be released. If that is not done, then the videos and images are not released.

Parts of the patient record are held at a higher level of confidentiality. Many release forms require the patient to indicate if psychotherapy notes, substance abuse information, and human immunodeficiency virus (HIV) information should be released. Such information may not be automatically released with the other records due to federal and state legislation.

Under HIPAA, psychotherapy notes are treated with higher levels of confidentiality. Psychotherapy notes include the patient-provider details from mental health treatment, either from a private, group, or family therapy. Psychotherapy notes include what the patient stated during the session and the provider’s analysis of the patient’s statements and the situation. Psychotherapy notes need to be stored separately from the patient paper health record. If the health record is electronic, the access to the psychotherapy notes is limited to those healthcare professionals who work in the mental health area. Additional information from the visit is not held at a higher level of confidentiality and includes prescriptions, session times, types and frequency of treatments, and results of clinical tests.

Drug and alcohol substance abuse and HIV content in patient records also are held at a higher level of confidentiality. There are many federal and state laws that relate to the privacy of these records. The federal statute called Confidentiality of Alcohol and Drug Abuse Patient Records, enforced by a division of HHS, is one example. This law restricts the release and use of patient records that include substance use diagnoses and services. State preemption applies to these privacy laws.

HIPAA security rule

HIPAA’s Security Rule addresses the national standards used to protect electronic protected health information (ePHI). This rule covers the records that are created, used, received, and maintained by the covered entities.

Safeguards of the security rule

Safeguards important to ensure the security of the ePHI include the following:

  • Administrative safeguards: The security officer is responsible for creating and carrying out security policies and procedures. Potential risks to the ePHI must be identified. Steps must be taken to prevent any issues. Cyber attackers pose a huge risk to network security.
  • Physical safeguards: Facility, workstation, and device security must be implemented. A security officer must create procedures for the proper use of workstations and ePHI.
  • Technical safeguards: Only authorized employees should have access to ePHI. Safeguards include audits to track the activities of users with the ePHI and encryption of data on mobile devices. They also include safeguards to prevent improper alteration, destruction, or transmission of ePHI.

It is important for the medical assistant to follow the healthcare facility’s electronic security procedures. Many facilities have policies to keep passwords confidential. Downloading personal documents puts the computer network at risk and thus is not allowed. Audit trails monitor who is looking at which patient’s chart. If the medical assistant is not working with a specific patient, then the patient record should not be accessed. Violating this rule will cause the medical assistant to breach the patient’s confidentiality and security. Many healthcare professionals, from providers to medical assistants, have breached confidentiality. They have lost their jobs and licenses or certifications. Many have also been fined. Healthcare employees cannot access their own health record or that of their family members. Most agencies require the employee to follow the patient’s review of health record policy. Violating this policy can also lead to termination.

More from Insurance billing

  • Health insurance basics
  • Government health plans: Medicare and Medicaid programs
  • Other government and private health plans
  • The medical assistant's role
  • HIPAA overview and the privacy rule