Frequently Asked Questions About HIPAA Privacy
Please use this page as a quick reference for frequently asked questions about HIPAA privacy. We welcome the opportunity to enhance this page with reliable information.
Per CDC Public Health Law, "The Health Insurance Portability and Accountability Act (HIPAA) of 1996 establishes federal standards protecting sensitive health information from disclosure without patient's consent. The US Department of Health and Human Services issued the HIPAA Privacy Rule to implement HIPAA requirements."
Q. What does the HIPAA Privacy Rule do?
- A. The HIPAA Privacy Rule creates national standards to protect individuals’ medical records and other personal health information. This rule:
- Gives patients more control over their health information.
- Sets boundaries on the use and release of health records.
- Establishes appropriate safeguards that health care providers and others must achieve to protect the privacy of health information.
- Holds violators accountable, with civil and criminal penalties that can be imposed if they violate patients’ privacy rights.
- Strikes a balance when public responsibility supports disclosure of some forms of data – for example, to protect public health.
Q. Who may access confidential information?
- A. Only those who need access for business reasons and who have been authorized to receive it.
Q. What is meant by having access to the "minimum necessary" information to do our jobs?
- A. We have access to all information that we need to do our jobs, but we should not have access to unnecessary information.
Q. What is the difference between "consent" and "authorization" under the HIPAA Privacy Rule?
- A. The Privacy Rule permits, but does not require, a covered entity voluntarily to obtain patient consent for uses and disclosures of protected health information for treatment, payment, and health care operations. Covered entities that do so have complete discretion to design a process that best suits their needs.
- A. An “authorization” is required by the Privacy Rule for uses and disclosures of protected health information not otherwise allowed by the Rule. Where the Privacy Rule requires patient authorization, voluntary consent is not sufficient to permit a use or disclosure of protected health information unless it also satisfies the requirements of a valid authorization.
Q. Why do we need privacy and security officers?
- A. They are responsible for the overall protection of patient privacy and the security of all our information, whether on paper, electronically, or in conversation.
Q. May the hospital use or disclose a patient's entire medical record based on the patient' signed consent?
- A. Yes, as long as the Authorization describes, among other things, the information to be used or disclosed by the hospital in a "specific and meaningful fashion," and is otherwise valid under the Privacy Rule.
Q. Who is responsible for maintaining a secure environment and patient privacy?
- A. Everyone.
Q. May I discuss patients with my spouse if he/she doesn't work here and promises to keep it secret?
- A. No.
Q. Am I permitted to look up my sick father's medical record?
- A. No. You are not permitted to look at your father's record. While parents usually want family involvement in their treatment, it shouldn't be assumed. Sometimes an individual does not want family members to know the details.
Q. Does the HIPAA Privacy Rule permit a doctor to discuss a patient's health status, treatment, or payment arrangements with the patient's family and friends?
- A. Yes. The HIPAA Privacy Rule specifically permits covered entities to share information that is directly relevant to the involvement of a spouse, family members, friends, or other persons identified by a patient, in the patient’s care or payment for health care. If the patient is present, or is otherwise available prior to the disclosure, and has the capacity to make health care decisions, the covered entity may discuss this information with the family and these other persons if the patient agrees or, when given the opportunity, does not object. The covered entity may also share relevant information with the family and these other persons if it can reasonably infer, based on professional judgment that the patient does not object. Under these circumstances, for example:
- A doctor may give information about a patient’s mobility limitations to a friend driving the patient home from the hospital.
- A hospital may discuss a patient’s payment options with her adult daughter.
- A doctor may instruct a patient’s roommate about proper medicine dosage when she comes to pick up her friend from the hospital.
- A physician may discuss a patient’s treatment with the patient in the presence of a friend when the patient brings the friend to a medical appointment and asks if the friend can come into the treatment room.
Q. Is it considered a HIPAA violation to electronically access or view my own medical record?
- A. No. It is NOT a HIPAA violation to view your own medical record. Employees with Epic access may access their personal medical records in Epic. Access is limited to VIEW ONLY. Printing, making appointments, updating demographics, messaging the care team about personal matters and anything else beyond VIEW ONLY is strictly prohibited. By enrolling in MyChart, you may perform many useful functions related to my personal care such as messaging your care team. If you would like a copy of your medical records, you may contact Health Information Management (HIM) for assistance
Q. We know that diagnoses and test results are confidential. What other information about a patient is confidential? What about billing records?
- A. Essentially any information that is patient-identifiable, even the patient's address, is confidential and must be protected. Only when the patient has agreed may it be used or disclosed for specific purposes. Also, removal of the patient's name does not mean the patient's identity is protected; other information such as a medical record number, a zip code, or a date of birth could still be used for identification.
Q. What patient information can we disclose to any caller or visitor who asks?
- A. This depends on what status the patient has requested at admission to the hospital. A patient can request to have all, some or none of their information provided over the phone to callers. Patients who are listed as "confidential" do not want their information given out, and we must be careful not to let that happen. Be sure to check the status of the patient before disclosing information over the phone.
Q. What could happen to me if I talked about patients even though I no longer worked here?
- A. We are all required to keep patient information confidential "forever". A privacy breach could result in legal penalties even if you no longer work here.
Q. We know that medical records whether paper or electronic are confidential. What about handwritten notes and phone calls?
- A. All forms of information written, spoken, or electronic are confidential and must be protected.
Q. How do you know what material is confidential?
- A. Hospital guidelines describe what information is confidential, including anything that could be used to identify a patient. Computer user IDs and access codes, payroll information, confidential memos, and many other documents are also considered confidential information.
- Please refer to Carilion Clinic’s Access and Confidentiality Agreement for examples of confidential information.
Q. How should you dispose of confidential papers?
- A. Put them in the locked shredder bin in your area. Make sure you always leave your workspace free of paper PHI before you leave at the end of your shift.