Although the majority of the provisions of the HIPAA Omnibus Rule have become effective, many Breach Notification Rule revisions cause confusion for organizations.
Q: Some organizations consider any medical record number to be PHI. Others believe the medical record number is not a personal identifier—unless the security number is the medical record number—because anyone who would intercept that number would have no way of identifying the patient based on the number alone.