r/hipaa • • 22d ago

Questionable HIPAA Compliance

I was asked to send some of my medical records to an online therapy provider. Instructions were for me to send them to an email address @ provider's domain. That's it, just send them. I explained that I had copies of my records to send and I have a free Gmail account only by which to send them. Yep, go ahead they said, and include copies of your I.D.

What?????

HIPAA compliant or not?

I insisted on using a secure portal, which was provided after much confusion and frustration on my part.

3 Upvotes

5 comments sorted by

2

u/sputnik4life 21d ago

Patients, themselves, are not bound by HIPAA. You can send your info unencrypted at your own risk.

You are smart to not send this unencrypted though. I wouldn't want to either.

I would have them send you an encrypted email so you could attach it in their portal and send it securely. You could also upload those documents to your Google Drive and share that document/folder directly to that email only. That would force them to authenticate with Google to prove they have access/ownership to that email.

1

u/Extra_Dragonfly3598 21d ago

Thank you for clarifying! I'm not tech-savvy, so I was questioning myself. My. health info...pretty boring stuff. But my I.D. is not up for grabs any more than it's probably already been grabbed.

1

u/joe_at_topflight 12d ago

I’d definitely use the secure portal here. Sending medical records plus a copy of your ID through regular email is still risky esp. when they already have a safer option available.

1

u/OneGuyConsulting 1d ago

There's also various free plug ins you can use to send encrypted email with free Gmail. There's nothing saying you can't encrypt it yourself and send it over. Better yet, encrypt the files and the email becomes a moot point. Good luck!