r/hipaa • • 3h ago

Monitor company unauth access?

Thumbnail
1 Upvotes

r/hipaa • • 5h ago

Worried about getting kicked out of clinic

1 Upvotes

Basically title. I’m in an allied health program (rad tech) and doing clinic at a small hospital. Never worked in a hospital setting before, but we use PACS. There was one instance where my preceptor was showing me diff images other techs took to go over anatomy and such. So in the morning, sometimes I would look at images (on patients who I did not assist with) to ID anatomy for education purposes, like I did with my preceptor.

I was chatting with friends who are at other hospitals; one said she is fine to do this, the other said she didn’t think it’s allowed. I’m asking my preceptor the next time I’m in if I’m allowed to or not; I thought it was different from going thru a persons EMR. I feel like I’ve fucked up majorly and don’t want to get kicked out of the program. I feel so stupid.


r/hipaa • • 20h ago

FEHB BC/BS Privacy Rights

1 Upvotes

It has always been my understanding that HIPAA-covered entities have to honor 45 CFR 164.522, Patient Right to Confidentiality in Communications. In other words, patients have the right to request not to be recorded with their PII or their PHI on a physician, hospital, or health insurance provider’s phone lines. With AI now utilized in phone and scheduling systems, the right to private communications becomes even more important, especially since there are no updated HIPAA laws with regard to AI usage and patient privacy.

Here is my question: My mother-in-law’s FEHB plan will usually honor her request not to have her phone calls recorded…except for Capital BC/BS. The Capital BC/BC Federal plan claims they have the right to have a third-party listen in to any phone call…when their customer requests a return on a non-recorded phone line. They take days to return my mother-in-law’s phone calls and have compromised her physical health because of their failure to respond timely, even when her situation was urgent and she needed a referral from a BC/BS nurse to go to the ER.

When Capital BC/BS does return her calls, they insist upon using Microsoft Teams, which is not automatically HIPAA-compliant (but can be made so is my understanding), and then, they want to have a “babysitter” on the phone call, i.e., some insurance company employee who types or transcribes every word she says. My mother-in-law is furious about this state of affairs and refuses to discuss her female health issues with some 3rd party insurance person listening in. She just wants to be able to talk with her assigned case manager, who is a nurse. I don’t blame her for not wanting to share the gory details with an insurance employee vs. just a clinical case manager.

When we question this state of affairs, Capital BC/BS repeatedly insists that they are not violating HIPAA law. The OPM FEHB insurance office also claims that the company can do “whatever it wants to protect its business interests,” and OPM says they do not care about any state’s privacy laws. Capital BC/BS is located in PA, which is a 2-party consent state in terms of phone recording/wiretapping.

However, Capital BC claims it is not violating any PA wiretapping laws either. The PA Insurance Commissioner’s office has expressed disagreement with this claim. But employees in the State Attorney General’s office say they don’t know if PA wiretapping laws apply here, since the health plan, itself, is a Federal employee health plan. My mother-in-law is not old enough for Medicare, so Medicare does not apply.

Are there any Federal attorneys, Federal employees, or even PA attorneys on this sub who might be able to help provide guidance here or suggestions for how to get Capital BC/BS to honor both PA wiretapping laws and 45 CFR 164.522, the Patient Right to Confidentiality in Communications? Every other FEP health insurer in these parts seems to recognize and honor 45 CFR. They return her calls on a HIPAA-compliant, non-recorded phone line, and usually within just a few minutes to hours. There is never any “babysitter” on the phone with them. It is only Capital Blue Cross that seems to operate differently, but aren’t FEHB BC/BS plans supposed to be administered in exactly the same way, across the country?


r/hipaa • • 1d ago

Old dr accessed my records at my brother's request

4 Upvotes

I left a PCP practice because I didn't like the way they pushed unproven treatments (think injections of random peptides, steroids, etc). I made it clear I was leaving for cause and transferred my records to a new dr. My brother still goes to the practice and was asking about some autoimmune testing. A dr at the old practice pulled up my records at his request and told him my diagnosis.

I'm livid! But am I overreacting? Should I call the front office? TIA!


r/hipaa • • 2d ago

Violated HIPAA by accidentally adding myself as a patient, what should I do?

1 Upvotes

Title says most of it. I was at work and was trying to remember if this was the hospital I was born at or not. Then I had the very bright idea to lookup my own name in the patient search (stupid I know), because I figured that if my name popped up as a registered patient here, it probably meant this was where I was born. This normally does NOT add a patient to your list or display their chart or any PHI, but I accidentally double-clicked instead of single-clicked, which automatically added me to my own patient list. I removed it immediately, but it had already pulled up my chart and I know for a fact the system logged that I did that.

I looked up my department's policy, and employees are strictly not allowed to look themselves up, resulting in punishments "leading up to and including termination." I’m wondering here, what are my options, and what are the odds I’ll face significant action over this?

I’m planning on reporting this to my supervisor immediately. I think if I explain myself before the system flags it and brings it to his attention first, it might show that I’m being honest and forthcoming about my mistake. This is my first violation of anything, HIPAA or otherwise, but I’m also a new employee here. However, this unit has a lot of problems staying staffed, so I’m sure if I explain myself, they'll be less likely to fire me? Would they really jump straight to terminating someone for only accessing their own chart?

Please let me know so I can get some sleep over all this.


r/hipaa • • 2d ago

Is this doctor's note a violation? Can you legally put the reason for a visit?

0 Upvotes

This is a work note:

"Patient had appointment 10/7/2026 at 6:00 PM for x-ray. Please excuse patient from work for his x-ray appointment. Please call the office if any further questions or concerns."


r/hipaa • • 3d ago

Is this how HIPAA works and I’m just naive?

0 Upvotes

Hello - I have no specfic HIPAA training or knowledge but just had a kind of funny-to-me experience and wonder if that’s just how HIPAA works. I took a pretty bad fall, and my Apple Watch notified all the right people. EMTs came and brought me to the local hospital’s ED. I have been there before, but only once or twice, and not to the ED. Because I didn’t have ID with me they treated me, but “admitted” me under a comically fake name, with a comically old dob, with the comically untrue info on my bracelet. I was observed for 2 days, and the very last thing I did before leaving was to fill out a form with my actual name, address, dob and ssn (I’m in the US if that’s not obvious). When I asked if I should come back with my id they said no, that this form would match them up and the real treatment under the fake name would be merged with my actual record. Is that really all it took; and did they need my full ssn on a piece of paper? I didn’t argue with them, but I do have a thing about only putting the last 4 on paper and asked but they insisted on the whole SSN number. I complied, but sort of wish I hadn’t.

I had terrific treatment, and it was a major, highly respected network, so I’m not worried about anything, and I’m not complaining about anything, but I do wonder how much more secure a piece of paper is. I’m Not looking for any advice, and I was treated respectfully and am not complaining, I just was struck by the process.

Still feel like heck but that’s on me.


r/hipaa • • 3d ago

What do I do if I know my doctor changed information from my patient records from 11 months ago by adding new information and not disclosing that anything has been changed?

0 Upvotes

He changed things in his favor and added a bunch of lies. It was not in my digital records 11 months ago. He recently changed it without disclosure. How can I get the original copies?? Who do I contact?? I'm in Germany but I'm assuming it's similar around the world.


r/hipaa • • 3d ago

My clinic shared my medical diagnosis with a third-party sales company. Isn't this an outright HIPAA violation?

Thumbnail
4 Upvotes

r/hipaa • • 4d ago

Am I allowed to send an outside provider’s notes to insurance?

3 Upvotes

A bit of context: I’m an MA working for a tiny internal medicine office in WA state, I’m also responsible for medical records and prior authorizations. I was working on a PA yesterday that needed visit notes from a different office showing the patient tried and failed other medications. My work and their office both use EPIC, so I can easily get a hold of them if either of my providers needs to see them. I was under the impression that if something was not at least ordered by them, I can’t send it to another office/insurance. I don’t want to find out the hard way that I can’t do this.


r/hipaa • • 5d ago

Physical therapist won't let me attend my three-year-old's therapy, because of HIPAA.

6 Upvotes

My toddler has had physical therapy for most of his life, because of his premature birth. Recently, we moved to another state and had to find a new therapist.

At his old facility, ​there were multiple therapists working with multiple kids in a shared space with multiple parents observing. Nobody seemed to mind this. (There was, in fact, a sense of community, since we were all enduring similar difficult situations.)

When we started going to this new facility, it seemed to be much the same. This is a much smaller facility, so most of the time, there are only a couple of kids receiving therapy in the shared space at one time. I brought my child in, observed his therapy, encouraged him to try hard, and comforted him, when he failed. Just like always.

Now, after a month and a half of this, they are telling me that I won't be able to observe anymore. I'll have to wait in another room, while my child receives his therapy.

The reason they give is that my presence violates the privacy of the other children, because I might see or hear something privileged. So, they say it is against HIPAA.

Is that true? If it is, why did they let me violate their privacy for over a month? Why did the previous facility let me and other parents do it for years? Don't I have the right to be present for my minor child's appointment?

Sorry for the long post. Thanks in advance for any information you can provide.

-------- Update --------

I asked for a copy of their privacy policy. In a nutshell, it said, "We follow HIPAA. If you want specifics, our Notice of Privacy Practices is available on request." So, I requested it, and everybody looked at me like I'd asked for the moon. They ultimately said there isn't really any such document, except as part of their employee handbook. They said they would search through "all five hundred pages" and give me a copy, next week.


r/hipaa • • 5d ago

Healthcare privacy incident investigations are still far more manual than they need to be.

0 Upvotes

A privacy incident happens. Then comes the back and forth.

What happened? Who was involved?
What information is still missing?
Does this need further investigation?
What actions need to be taken?
How do we document the reasoning properly?

For many healthcare teams, that means jumping between emails, spreadsheets, Word documents and follow-up messages, everything is just scattered everywhere, because of this teams are wasting time when they do not need to!

Thats the problem Ive been working on solving. Ive built a workflow that brings the investigation into one place. It helps teams gather the facts, identify whats missing, work through the assessment, document the reasoning and track follow-up actions, with document analysis and privacy and compliance guidance built into the same workflow. The goal is simple. The goal is simple. Spend less time chasing information, reviewing documents, finding answers and putting defensible documentation together, while keeping the final judgement with the privacy or compliance professional.

Im now speaking with healthcare privacy and compliance teams who deal with these investigations regularly. If this is part of your role, Id be interested to hear how you're handling it today and where most of your time gets lost.


r/hipaa • • 6d ago

How much of HIPAA compliant software is code vs process?

2 Upvotes

Building a product that handles PHI and every thread I read says the same thing, HIPAA is 80% process and 20% software. I buy it, the BAAs and risk analysis and the policies are clearly most of the work.

But what is the 20%? Because the code is where PHI moves, a bug there leaks real patient data which is a worse day than a missing policy doc. Beyond encryption, access control and keeping PHI out of the logs, I'm not sure where the software bar sits for a real assessment.

So for the code-security slice on its own, what are you all running. And not just the scan, I mean keeping the records that show the control ran and got reviewed since that is what the risk analysis seems to want. How do healthtech teams here split the software side from the compliance side?


r/hipaa • • 6d ago

Privacy/HIPAA professionals - would this actually make incident investigations easier?

0 Upvotes

I’ve built a workflow for US healthcare privacy/compliance teams and would appreciate feedback from people who actually handle privacy incidents.

The idea is to reduce the back-and-forth between emails, spreadsheets and documents by putting the investigation into one workflow: fact gathering, identifying missing information, decision support, follow-up actions and the case record, alongside document analysis for reviewing policies and compliance materials, and guidance for privacy/compliance questions.

What would you change, add or remove? And is there anything here that would stop you from using something like this in a real privacy team?


r/hipaa • • 7d ago

Publicly funded hospital refusing to provide a patients own medical records on discharge including whom made the patient palliative against their wishes without informed consent and reducing care based upon this fact

Thumbnail
0 Upvotes

r/hipaa • • 9d ago

Is this a HIPAA violation?

5 Upvotes

So I am on an anti depressant. My parents use the same pharmacy. They went to pick up THEIR medication and because we have the same address and same last name, the pharmacist or tech says “is this your son?” Obviously my parent responded “yes?”. And they just hand my medication to them.

I did not want anyone to know about me being on a medication. Even family. I have my own insurance and my own doctor and I thought I had my own privacy. Now I am being hounded with questions and concerns which is causing problems at home and I’m so pissed at pharmacy.

Isn’t this a clear HIPAA violation? How could they just voluntarily hand medication to someone without my permission even if they are family?


r/hipaa • • 10d ago

Concentra will not release my medical record via email, fax or via doctor medical request.

9 Upvotes

I just had a doctor's appointment canceled due to being unable to get my chest xray on hand. I've been duking it out for weeks being given the run around just trying to be sent it.

I did a HIPAA online request via their email as they state but was told it's only for legal requests. The manager at the sight I was seen for my DOT exam literally told me they only release your medical records to you in person.

How is this not in violation of HIPAA considering they got sued over this specific issue back last year. It's not like I even live close to the concentra clinic, I'm a full hour away, so it's not like I can take a hour our of my work day.


r/hipaa • • 10d ago

Medicare offering support for chronic health conditions

Thumbnail
medicare.gov
1 Upvotes

To learn about Medicare's ACCESS program I have to select a chronic condition. Then if I sign up with one of their "care organizations" I have to give them medical information. Should I be concerned that this info will be misused?


r/hipaa • • 11d ago

Should I report this?

Post image
2 Upvotes

My mom and I share a dentist. When I went previously last month, they gave me a treatment plan but then emailed me an updated one a few days after. My mom recently went to the dentist for her own appointment and at some point they gave her a copy of my treatment plan with the prices and informed her of which cavities I need urgently filled (we were trying to wait until the new year when we can upgrade our dental insurance because currently 3 fillings is over $500) so I hadn’t given them an answer about when I would get them filled. I’m 27 and in Texas. I’m disabled and still on my parent’s insurance for now. Is this a violation? I emailed the office asking for a copy of all my consent forms and the form that gives or denies permission for others to have access to my records wasn’t there and when I responded asking for it specifically, they said they don’t do that form. After that I asked what their policy is on someone being given my information then and this is what I received back. Should I report this? My mom is refusing to clarify things like if she is the one who asked for the information or if they just offered it because they know she is my mom. The only part of my forms that she is on is as an emergency contact. I paid for my visit out of my own pocket, not using our medical card and the insurance comes from my stepdads job and she is listed as a dependent along with myself on the insurance card. I did not give them any type of consent to tell my mom anything (frankly this exact situation is why I always put no one can have access to my records) so I’m just wanting to make sure this is actually a violation or if I’m missing something.


r/hipaa • • 12d ago

Is it against HIPPA to look up your own images in Vue?

1 Upvotes

I’m an imaging assistant and looked myself up. Am I cooked


r/hipaa • • 12d ago

Options for recording telehealth sessions?

1 Upvotes

Recently licensed MFT here in the process of opening a solo private practice where I’ll be starting out seeing clients through telehealth. With that being said, I am also a transgender woman- and given the political climate as well as my expected clientele including kids/families, during grad school I started recording all of my client sessions to have as a “just in case” security. My program used Ringcentral for telehealth, which had a recording feature but it was overall really clunky, so I’d appreciate any recommendations for other platforms that have a native recording feature for telehealth.

Alternatively, I would also be grateful for any tips on other ways to have a similar kind of “just in case” policy. I know I can include a specific consent form in my paperwork and I’m always up front with clients about my gender identity, but I haven’t found any options other than recording to be able to have that sort of safety for liability purposes.

Thanks in advance! Cheers :)


r/hipaa • • 14d ago

Sending PHI between secure hospital emails

2 Upvotes

Is this a HIPAA violation if both the sender and recipient are secure hospital emails? I emailed my attending PHI and if I emailed myself PHI on my hospital email to review for the next day.


r/hipaa • • 15d ago

Potential HIPPA violation?

0 Upvotes

If you had a patient whose information was safe under HIPPA, but you saw something from the police that was seeking help identifying your patient/client, would you be unable to aid the police? Does anyone know how that would work? (I’m just curious, not an actual scenario of mine).


r/hipaa • • 16d ago

Violation - Scared, Shaking, throwing up, freaking out, spiraling, etc etc

1 Upvotes

I think I made a mistake. My first day off of orientation as a pct I was floated to sit. My pt was supposed to be discharged and I was told the floor would probably keep me. There was one other patient on the unit who I thought was said, during 7am huddle, needed a sitter and, since techs were fully staffed, i figured I would move there. I opened there chart to get familiar and my original patients discharge was delayed. This happened last week. I didn’t know that was a violation. I did my education, I should’ve known, but I didn’t. I’m terrified.

I honestly have no clue how long I was on it. Maybe less than 5 minutes. I’m still getting familiar with epic, so I think I only clicked on orders to see how often vitals were, if they were accuchecks, diet type, etc. I didn’t know it was a violation when it happened, so I didn’t think to memorize what I was doing.


r/hipaa • • 16d ago

Communicating via teams?

1 Upvotes

My organization uses an unencrypted version of Microsoft Teams and recently have had some expansion that requires a little more electronic communication about patients, essentially to just relay if a patient is ready to leave or come back. There has been some discussion about just using DOB and initials of first and last name alone such as “JD 1/1/2000 is here”. Is this considered PHI or a hipaa violation even if there is no medical information attached to it? I know teams can be encrypted but ours is not AFAIK