Health Information Management

Do "e-signatures" conflict with HIPAA's focus on privacy and security?

HIPAA Weekly Advisor, October 4, 2002

Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!

Q: We have recently heard from several insurance companies that we should now accept "e-signatures" from them when they request a patient's medical record, for example, for life insurance applications. They are referring to a typed signature, rather than a handwritten signature, which we have always compared to the signature we have in the patient's file. We are told this new practice does not conflict with HIPAA, but how do we explain our increased attention to privacy and security while simultaneously accepting a weaker standard for this type of release?

A: That's a very valid question. An "electronic signature" has no specific meaning and no formal standard. The term is sometimes used to make a process sound more secure than it actually is. In fact, in the proposed security and electronic signature rule, HHS said that if an electronic signature were required by HIPAA (although it is not, at this time), it would have to be a more clearly defined and powerful "digital signature."

You are right to be concerned about accepting a typed name. You should require a form of authentication at least as meaningful as a photocopy of the signed form that you received in the past. Under HIPAA, the burden falls on your organization to ensure proper authorization prior to release, so you may need to review your process and take on the responsibility of obtaining a signed HIPAA-compliant authorization form from the patient before releasing the record.

Answered by Kate Borten, CISSP, president of The Marblehead Group, Inc., in Marblehead, MA, and excerpted from the October 2002 issue of Briefings on HIPAA.



Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!

  • Briefings on APCs

    Worried about the complexities of the new rules under OPPS and APCs? Briefings on APCs helps you understand the new rules...

  • Medical Records Briefing

    Guiding Health Information Management professionals through the continuously changing field of medical records and toward a...

  • Briefings on Coding Compliance Strategies

    Submitting improper Medicare documentaion can lead to denial of fees, payback, fines, and increased diligence from payers...

  • Briefings on HIPAA

    How can you minimize the impact of HIPAA? Subscribe to Briefings on HIPAA, your health information management resource for...

  • APCs Weekly Monitor

    This HTML-based e-mail newsletter provides weekly tips and advice on the new ambulatory payment classifications regulations...

Most Popular

Related Articles