Compliance Q&A: Potential breach from medical records
Compliance Monitor, January 11, 2012
Want to receive articles like this one in your inbox? Subscribe to Compliance Monitor!
Q. We found medical records about one of our patients in our parking lot. Is this a breach? What should we do?
A. With all the focus on keeping electronic records secure, there are still a lot of paper records out there. In this instance, the patient or his or her legal representative may have dropped the paperwork by accident. Or, more ominously, a staff member could have dropped them.
You should certainly do whatever you can to investigate how the records got to the parking lot and look into who might have seen them. When you have completed your investigation, you will be able to determine whether the incident is likely to cause harm to the patient. If you conclude that no harm was done, you do not have to report the incident to the patient or to HHS. That said, it is always wise to be as transparent as possible, and this would include notifying the patient.
In addition, it would be appropriate to remind your staff members that they should not take PHI out of the building. If you determine that someone removed the information for a legitimate purpose, you may want to purchase lockable bags for those who must transport PHI.
Editor’s note: Chris Simons, RHIA, originally answered this question in the January 2012 issue of the HCPro, Inc. newsletter, Medical Records Briefing. Simons is the director of utilization management and HIM, and privacy officer at Spring Harbor Hospital in Westbrook, ME.
Want to receive articles like this one in your inbox? Subscribe to Compliance Monitor!
Related Products
Most Popular
- Articles
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- HIPAA Q&A: Level of encryption needed for email
- Catch up on what's new with injections and infusions
- Identify potential Medicaid RAC target areas
- Capturing all necessary codes for IUD insertion and removal can be challenging
- Topic: CMS, OESS post new security compliance review information, checklist
- What does case-mix index mean to you?
- OB services: Coding inside and outside of the package
- Q/A: Coding infusions to correct low potassium levels
- E-mailed
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- HIPAA Q&A: Level of encryption needed for email
- CMS has reformulated payments for some bilateral procedures
- Q&A: Follow CMS' coding guidelines when using modifier -25
- Understand the spine to code back procedures correctly
- What does case-mix index mean to you?
- Catch up on what's new with injections and infusions
- New conflicts of interest create new challenges
- Q/A. One injection code or two?
- Searched
