Keeping You Connected

The RCMA keeps you up to date on the latest news,
policy developments, and events

News

Five Inadvertent HIPAA Violations by Physicians



Doctors do not plan ahead to violate HIPAA, but in this digital age, they may be doing it because they did not plan ahead. The recent final rule of the HITECH Act outlines that even if the physician is unaware of the violation, they may be fined a civil penalty of $100 - $50,000 per violation. It is time for even the most resistant doctors to pay attention to how they handle protected health information (PHI). Here, we will outline five common ways physicians are breaking HIPAA/HITECH privacy and security rules, and may not even know it.

1)    Texting PHI to members of your care team

It’s a simple scenario: you’ve just left the office, and your nurse texts you that Mr. Smith is having a reaction to the medication you’ve just prescribed. She has included his name and phone number in the text. You may know that texting PHI is not legal, but feel justified because it is a serious medical issue. Perhaps you even believe that deleting the text right away will protect you – and Mr. Smith

In reality, this text message with PHI has just passed from your nurse’s phone, through her phone carrier, to your phone carrier, and then to you – four vulnerable points where this unencrypted message could either be intercepted or breached. In a secure messaging app, this type of message must be encrypted as it passes through all four points of contact. Ideally, both sender and recipient should be verified and have signed a business associate agreement (BAA).

2)    Taking a photo of a patient on your mobile phone

To some this will sound silly, to others, it is as common as verifying a rash with a colleague or following the margins of a cellulitis day by day. Simple enough, but if these photos are viewed by eyes they are not intended for, you may be in violation of your patient’s privacy. It’s important to be aware of where and how patient information and images are stored. Apps that allow you to take a secure photo are just as important as sending the message securely. DocbookMD allows photos to be taken within the secure messaging app itself – never stored on your phone or within your phone’s photo album. Always use this type of feature when taking any photo of a patient or patient information.

3)    Receiving text messages from your answering service

Many physicians believe if they receive a text message from a third party, like an answering service, they are not responsible for any violation of HIPAA – this is simply not true. Many services do send a patient’s name, phone number and chief complaint via SMS text. The answering service may verify it is encrypted on their end, but if PHI pops onto the physician’s screen, it is certainly not secure on their end – and this is where the physician’s responsibility lies. Talk with your answering service today to see how they are protecting you at both ends of the communication.

4)    Allowing your child to borrow your phone that contains PHI

Many folks allow their kids to play with their phones – maybe play games on apps while in the car. If your phone has an app that can access PHI, then you may be guilty of a HIPAA breach if the information is viewed by or sent to someone it is not intended for. The simple fix is to utilize the pin-lock feature on your messaging app – and for double-protection, always password protect your phone!

5)    Not reporting a lost or stolen device that contains PHI

Losing your smartphone or tablet is a pain for many reasons, but did you know that if you have patient information on that device, you could be held responsible for a HIPAA breach If you do not report the loss right away. The ability to remotely disable an app that contains or handles PHI is an absolute must for technology that handles communications in the medical space. Be sure to ask for this feature from any company claiming to help you be HIPAA-compliant in the mobile world. Remember: Being HIPAA – compliant is an active process. A device can claim to be HIPAA secure, but it is a person who must ensure compliance.



Comments are closed.

Tags

2013 2014 Ebola Outbreak 2014 Election 2016 Abuse ACA Addiction AIDS All Physicians Annual Report Appointments Assembly Business and Professions Committee Awards Ballot Initiatives Boxer Budget Burnout CA Ballot Initiatives CAFP California CMA CMA Annual Report Comments Congress Construction Controlled Substance COVID-19 Discontent Dolores Early-Career Physician EHR Election Election 2014 Exchange Financial Governance Grace Period H.R.2. Health Exchange Health Laws Healthcare Laws HIE HIT HIV Hizon HOD House House of Delegates ICD-10 IEHP Languages Lee Legislation Mahdi Meaningful Use Medical Medi-Cal Medical Office Safety Medicare MICRA Mode of Practice New No on 46 NoOn46 Opioids Outstanding Contribution Palm Springs Patients Paul Green Physicians for a Healthy California Practice Management Prop 46 Prop 56 Proposition 46 Public Health Public Health Alert Public Safety Power Outage Rajaratnam Ranch Mirage Rancho Springs Rating RCMA RCMA President Repeal Residents Risk Management Riverside Community Hospital Riverside County Schedualing Senate SGR Shooting Southwest Healthcare Stage 2 Stress Termination Trial Lawyers Uppal Vaccines White Wilson Creek Winery #GivingTuesday #Medi-CalRedetermination #MeToo #RiversideCountyPhysicians 2014 2014 Election 2014 laws 2015-2017 2016 2016 Election 2018 2019 2020 2021 2021 taxes 2022 Employment Law 2023 Year in Review 46 AB 2770 AB 3087 AB 3109 AB 5 AB 880 AB5 ABMS ABX2-15 ACA Advisory Council Advocacy Affordable Care Act AHCA AMA Anthem Blue Cross Asian Violence Assembly Assembly Bill Attestation Awards Awards Committee Behavioral Health Benefit Big Tobacco Blue Shield of California board certification board certified Bruce Holmblad Burnout Business Partner CA CA Senate Cal INDEX CalHealthCares Calhhs California California Employment Law California Laws California Legislation California Society of Plastic Surgeons Californian Physicians Call for Nominations Cameron Kaiser CCI CDC CEO certification Childcare City of Riverside Claims Clearinghouses CMA CME CMS Coalition for Patient Access and Quality Care Committee Confidential Congress Contributions to Medicine controlled substances Coronavirus Coronavirus Testing Coroner Council on Graduate Medical Education Covered CA Covered Califonria Covered California covid19 COVID-19 COVID-19 Employer Concerns COVID-19 Financial Assistance COVID-19 Resources COVID-19 Response COVID-19 Testing COVID-19 Updates COVID-19-Resources CPT modifer CSPS Cultural Diversity CURES Cuts Data Exchange data exchange framework data sharing data sharing agreement David Duffner Deadlines DEARequirements deductible Delegates Delivery Models Depression DHCS Documentation donate Donate to RCMA Donations Drugs Dual Elligibles DxF Ebola ehi EHR eligibility employee Employee Classification Employer Concerns Employer Guidance employment employment law Employment Status End-Of-Life Energy and Commerce Committee Republicans enrollment ERISA Ethnic Unity Exchange FAQ Federal Federal Legislation Feinstein Financial Assistance financial planning Free Free PPE Funding fundraiser Future Gary Honts GivingTuesday Governor Governor Newsom Grace Period Health Care Reform Health Information health information exchange Health Reform healthcare burnout Healthcare Information Technoloogy Healthcare Legislation Healthcare Rates Healthcare Reform healthcare symposium healthcare worker bonus Healthcare Workers Hernandez HIPAA HIT Holiday Giving ICD-10 IEFMC IEHIE IEHP IEPCC Imagine Plastic Surgery Increase infoblocking informationblocking informationblockingfaq informationblockingrule Installation Installation of Officers insurance investments JFK Memorial Hospital Jiangmen China Hospital Kaiser Permanente lactation accomodations Laws legal Legislation Legislative Alert Loan Assistance Loan repayment Loan Repayment Progam Loan Repayment Scholarship Program Loma Linda long term disability LTSS MA Mahdi Maintenance of Certification Managed Care Manifest MedEx marketing Meaningful Use Measles Med-CalRe-enrollment Medcare Medicaid Medi-Cal medical board Medical law medical practices Medical Record Documentation medical staff Medical Student Scholarship Fund Medical Students Medical Supply Donations Medi-CalEligibility medicare medicare cuts 2023 member benefit Mental Health Mentoring MICRA minimum wage minimum wage increase MIPS MOC Molina Molina Healthcare NAACOS National Prescription Drug Take-Back Day News Nomination Nominations Nondiscrimination Posting Non-profit Donations norcal Noridian Obamacare Insurance October 22 On-Call ONET ONET Physicians opiod opiod advocacy opiod crisis opiod enforcement opiod epidemic opiods opioid opioid abuse Outstanding Outstanding Contributions Outstanding Contributions Awards Palmetto GBA Patient Patient Care Patient Data Patient Refusal of Treatment patients pay equity Paycheck protection Payment Models Pediatric Physicians PHA PHC Physician Physician Aid-in-Dying Physician Awards Physician Burnout physician certification physician medical board physician mentoring Physician mentors Physician Recruitment Physician Wellness Physicians Physicians for a healthy California Physicians in Riverside Pietro Wellness Fund Plastic Surgery POLST Population Health Power Outage PPE PPE Provider Survey PPE Supplies practice management practice managment Practice Mangement prescribing opiods prescription drugs President Priorities privacy ProAssurance Professional Liability Project K.I.N.D. Project Kind Prop 46 Prop 56 Proposition 46 Proposition 56 PSPS Public Health Public Health Alert Public Safety QPP Quality Payment Program RCH RCMA RCMA Business Partner RCMA Business Partners RCMA Docs RCMA Medicare Update RCMA Member RCMA Physicians RCMA Scholarship Program RCMA Stands RCMA Year In Review RCPMF Real-time Patient Data Red Tape Repayment Demands Reputation Resources retention bonus retention payments Retreat Risk Management Riverside County Riverside County Medical Association riverside county physicians Riverside County Physicians Memorial Foundation Riverside County Public Health riverside physicians RiversideCountyMedicalAssociation RIVPAC RUHS RUHS-PH SB 1343 SB 491 SB 492 SB 493 SB 62 SB1343 SBA scholarship scholarship fundraiser Scholarships Scope of Practice Sequestration sexual harassment sexual harassment preventation sexual harassment training SGR Small Business Small Business Resources Small Businesses social media State Capitol Stress Survey taxes Telehealth Telemedicine Tenet Texting Safety Thakur Law Firm The Unforgettables Foundation Timothy Pietro Wellness Fund Toolkits Top Doctor Awards Transforming Your Practice UC Riverside UCR School of Medicine United Vaccines Management Vaccines Management Plan Value Based Care Vantage Virtual We Care for California Webinars Wellness WestPac Wealth Worker Classification Workers' Comp Workplace workplace compliance Year in Review Year-in-review

Current Initiatives

Medical Scholarship Programs

Scholarship Programs

Medical Student & Early-Career Physician Loan Repayment Programs

View Program
Member Benefits

Member Benefits

Resources that support our members’ practices.

Member Benefits
Physician Wellness

Physician Wellness

Supporting the health of physicians

Wellness Resources
Riverside County Medical Association Seal
California Medical Association Seal

Contact Us

Riverside County Medical Association (RCMA)
Mailing: PO Box 2425, Riverside, CA 92516
Location: 3993 Jurupa Ave., Riverside, CA 92506
Phone: (951) 686-3342
Email: membership@rcmadocs.org

As a member of the RCMA and/or its affiliated organizations (Inland Empire Foundation for Medical Care, Riverside County Foundation for Medical Care, Inland Empire Health Information Organization, Riverside County Physicians Memorial Foundation), I authorize Riverside County Medical Association, and its affiliated organizations listed above, permission to use my likeness, name and/or quote and consent to the audio and video recording of my voice, name, and image. I further consent to the distribution and broadcast of my appearance, including any information and content I provide, in audio, video, or text form for the purpose of publication, promotion, illustration, advertising, or any other related lawful purpose.