News & Analysis

April 1, 2016
Briefings on HIPAA

Tips from this month's issue


April 1, 2016
Briefings on HIPAA

OCR and HIPAA audits. Give you chills, don't they? Most covered entities (CE) naturally fear getting the letter from the HIPAA privacy and security enforcers saying that they're coming?or that they want something. "Something" usually means your policies and procedures, risk analysis, and mitigation efforts if you've suffered a breach. Bottom line: CEs want to avoid OCR unless they need to go to the agency for information on the HIPAA Privacy, Security, or Breach Notification rules

April 1, 2016
Briefings on HIPAA

Subpoenas are a sometimes-unwelcome fact of life for privacy officers. They can be complicated, requesting broad amounts of information that is time-consuming to gather. They can be written in dense legal language that takes time and finesse to decipher. If a subpoena requests PHI, it can also raise privacy concerns and questions about how to honor the subpoena while releasing only the necessary information. Some subpoenas may request information that an organization considers sensitive for other reasons. It can be all too easy to put off dealing with a subpoena until the last minute, then rushing to react without taking the time to really read and understand what it says.

April 1, 2016
Briefings on HIPAA

Security Q&A

Email encryption, file sharing, and mailbox security

by Chris Apgar, CISSP

 

Q: We are in the process of building a new office. Would it be HIPAA compliant to have an outside locked mailbox for our general postal mail and therapist paperwork that is dropped off at night? If not, would a mail slot on our front door work better?

 

A: An outside locked mailbox will suffice to secure incoming mail and therapist paperwork. Ensure that the mailbox is secure and not easily broken into. If the mailbox is secured with a key, it's a good idea to implement a solid key management program so it's known who has a key. Keys should be recovered when an employee resigns or is terminated. If an employee leaves without returning his or her key, it's wise to re-key the lock on the mailbox.

 

Editor's note

Apgar is president of Apgar & Associates, LLC, in Portland, Oregon. He is also a BOH editorial advisory board member. This information does not constitute legal advice. Consult legal counsel for answers to specific privacy and security questions. Email your HIPAA questions to Associate Editor Nicole Votta at nvotta@hcpro.com.

March 1, 2016
Briefings on HIPAA

Tips from this month's issue.

March 1, 2016
Briefings on HIPAA

Q: I work in a behavioral health hospital and am looking for guidance relating to disclosures as part of the Clozapine REMS Program. In order for a patient to fill a prescription for Clozapine at an outside pharmacy (not our on-site pharmacy), the pharmacy is required to have a copy of the patient's latest blood draw (absolute neutrophil count). Is the patient required to sign a release of information for us to be able to send the latest blood draw results, or is sharing the results with the outside pharmacy considered part of the process when the patient is registered in the Clozapine program?

In addition, if the latest lab results contain more information than what is required for the Clozapine prescription to be filled, should we edit the results to only include what is specifically needed by the pharmacy?
 

A: Releasing this information is considered treatment, so the patient's authorization is not needed. Editing the results report to release only the neutrophil count would be a good practice, if it is reasonable to do that. If not, it would be acceptable to release the complete results containing the neutrophil count, since the minimum necessary requirement does not apply to treatment disclosures.

Editor's note: This question was answered by Mary Brandt. Brandt is a healthcare consultant specializing in healthcare regulatory compliance and operations improvement. She is also an advisory board member for BOH. This information does not constitute legal advice. Consult legal counsel for answers to specific privacy and security questions. Email your HIPAA questions to Associate Editor Nicole Votta at nvotta@hcpro.com.

Pages