Answers To Your Top 5 Privacy Questions
Protecting our patients' privacy is an important part of all of our jobs at Carilion.
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a federal law that requires us to protect sensitive patient health information from being disclosed without the patient’s consent or knowledge. This sensitive health information is called protected health information (PHI). At times, PHI may be disclosed without patient consent or knowledge if the information is being shared for treatment, payment or operations purposes, and only the minimum amount of information necessary is disclosed.
Our Privacy Office responds to questions about HIPAA and investigates complaints. Here are some of the top questions the Privacy Office received during the past year:
1. What specifically is considered PHI?
There are 18 HIPAA identifiers that are considered PHI:
- Names
- Geographic information
- Dates
- Telephone numbers
- Vehicle identifiers
- Fax numbers
- Device IDs and serial numbers
- Email addresses
- Web URLs
- Social security numbers
- IP addresses
- MRNs
- Biometrics
- Health plan beneficiary numbers
- Full face or comparable photos
- Account numbers
- Certificate and license numbers
- Any other unique identifying characteristics, numbers or codes
2. How is HIPAA enforced at Carilion?
The Privacy Office is responsible for investigating all reports of potential privacy violations. If a privacy violation is suspected, the Privacy Office holds a fact-finding meeting with HR, management and the employee in question to determine the nature of the potential violation.
The Privacy Office also conducts random audits of employee access to PHI and puts safeguards in place to reduce the potential for snooping. The Break the Glass feature in Epic is an example of a safeguard.
The consequences for HIPAA violations can range anywhere from employee education all the way to separation from employment and potential board reporting. Further external consequences for violating patient privacy may include license revocation from the Virginia Department of Health and regulatory fines.
3. What is Break the Glass?
Break the Glass is a control within Epic that warns the end user that a restriction is in place and requires the user to re-enter their username and password before entering the patient’s chart. Break the Glass is meant to serve as a reminder and deterrent to prevent unauthorized users from accessing a patient’s electronic medical record. When you are accessing a patient’s medical record for business purposes, you do not need to ask for permission to break the glass before entering their chart.
4. I'm a Carilion employee, but I do not have Break the Glass on my chart. How do I get it applied to my chart?
If your primary care provider is a Carilion provider, contact their office and ask to update your chart to list your employer as Carilion. This will automatically apply Break the Glass to your chart. Another way to add Break the Glass to your chart is to email your request to privacy@carilionclinic.org. You are not allowed to apply Break the Glass to your own medical record—it must be applied by your provider's office or the Privacy Office.
5. Who can I contact when I have questions about HIPAA?
- Contact the Privacy Office by phone at 540-510-4600 (54600) or by email at privacy@carilionclinic.org.
- Ask questions or report something through the Integrity Help Line at 844-732-6232 or compliance.CarilionClinic.org.
- Find Privacy policies on PageCenterX. Note that you will need to be on the Carilion network or Apps portal to view PageCenterX.
- Visit the Privacy Office hub for additional information.
HIPAA is the law that requires us to protect our patients' sensitive health information.
There are 18 types of protected health information (PHI).
If you have questions about HIPAA, reach out to the Privacy Office.