Q A fax containing PHI is sent to an incorrect fax number. Did the covered entity (CE) or business associate (BA) violate HIPAA? Must the patient disclosure accounting record include this incident?
Business associates (BA) may not be the target of upcoming HIPAA compliance audits, but failure to comply with the regulations could be very costly, says Tom Dumez, CHP.
Q Our authorization form for release of information requires patients to sign separate lines to authorize release of sensitive information, such as sexually transmitted diseases, substance abuse, and genetic information. We understand that very few other covered entities do this. Is this a legal requirement? And if so, may we change our form to state that all information will be released unless the patient indicates otherwise?
The May tornado that destroyed a medical center in Joplin, MO, raised an important question: How can healthcare providers protect patients' PHI when disaster strikes?