Answers To Your Top 5 Privacy Questions

Submitted by abshaver on

Protecting our patients' privacy is an important part of all of our jobs at Carilion.

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a federal law that requires us to protect sensitive patient health information from being disclosed without the patient’s consent or knowledge. This sensitive health information is called protected health information (PHI). At times, PHI may be disclosed without patient consent or knowledge if the information is being shared for treatment, payment or operations purposes, and only the minimum amount of information necessary is disclosed.

Our Privacy Office responds to questions about HIPAA and investigates complaints. Here are some of the top questions the Privacy Office received during the past year:

1. What specifically is considered PHI?

There are 18 HIPAA identifiers that are considered PHI:

  1. Names
  2. Geographic information
  3. Dates
  4. Telephone numbers
  5. Vehicle identifiers
  6. Fax numbers
  7. Device IDs and serial numbers
  8. Email addresses
  9. Web URLs
  10. Social security numbers
  11. IP addresses
  12. MRNs
  13. Biometrics
  14. Health plan beneficiary numbers
  15. Full face or comparable photos
  16. Account numbers
  17. Certificate and license numbers
  18. Any other unique identifying characteristics, numbers or codes

2. How is HIPAA enforced at Carilion?

The Privacy Office is responsible for investigating all reports of potential privacy violations. If a privacy violation is suspected, the Privacy Office holds a fact-finding meeting with HR, management and the employee in question to determine the nature of the potential violation. 

The Privacy Office also conducts random audits of employee access to PHI and puts safeguards in place to reduce the potential for snooping. The Break the Glass feature in Epic is an example of a safeguard.

The consequences for HIPAA violations can range anywhere from employee education all the way to separation from employment and potential board reporting. Further external consequences for violating patient privacy may include license revocation from the Virginia Department of Health and regulatory fines.

3. What is Break the Glass?

Break the Glass is a control within Epic that warns the end user that a restriction is in place and requires the user to re-enter their username and password before entering the patient’s chart. Break the Glass is meant to serve as a reminder and deterrent to prevent unauthorized users from accessing a patient’s electronic medical record. When you are accessing a patient’s medical record for business purposes, you do not need to ask for permission to break the glass before entering their chart. 

4. I'm a Carilion employee, but I do not have Break the Glass on my chart. How do I get it applied to my chart?

If your primary care provider is a Carilion provider, contact their office and ask to update your chart to list your employer as Carilion. This will automatically apply Break the Glass to your chart. Another way to add Break the Glass to your chart is to email your request to privacy@carilionclinic.org. You are not allowed to apply Break the Glass to your own medical record—it must be applied by your provider's office or the Privacy Office.

5. Who can I contact when I have questions about HIPAA?

Publish date / time
News Type
Users that Liked
13764
373
112
162
4584
5104
Views
0
Thumbnail Image
blue thought bubbles with question marks and check marks
Unlisted
Off
Banner Image
colorful thought bubbles with question marks
Key Points HTML

HIPAA is the law that requires us to protect our patients' sensitive health information.

There are 18 types of protected health information (PHI).

If you have questions about HIPAA, reach out to the Privacy Office.