Q&A: Potential PHI breach from found medical records
HIM Connection, January 10, 2012
Want to receive articles like this one in your inbox? Subscribe to HIM Connection!
Q We found medical records about one of our patients in our parking lot. Is this a breach? What should we do?
A: With all the focus on keeping electronic records secure, a lot of paper records still exist. In this instance, the patient or his or her legal representative may have dropped the paperwork by accident. Or, more ominously, a staff member could have dropped them.
You should certainly do whatever you can to investigate how the records got to the parking lot and look into who might have seen them. When you have completed your investigation, you will be able to determine whether the incident is likely to cause harm to the patient. If you conclude that no harm was done, you do not have to report the incident to the patient or to HHS. That said, it is always wise to be as transparent as possible, and this would include notifying the patient.
In addition, it would be appropriate to remind your staff members that they should not take PHI out of the building. If you determine that someone removed the information for a legitimate purpose, you may want to purchase lockable bags for those who must transport PHI.
Editor’s note: Chris Simons, RHIA, originally answered this question in the January issue of Medical Records Briefing. Simons is director of utilization management and HIM, and privacy officer at Spring Harbor Hospital in Westbrook, ME.
Want to receive articles like this one in your inbox? Subscribe to HIM Connection!
Related Products
Most Popular
- Articles
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- Catch up on what's new with injections and infusions
- Topic: CMS, OESS post new security compliance review information, checklist
- Capturing all necessary codes for IUD insertion and removal can be challenging
- What does case-mix index mean to you?
- QA:Coding multiple initial infusions
- News and briefs: Oklahoma Osteopathic Association against residency bill change
- HIPAA Q&A: Level of encryption needed for email
- OB services: Coding inside and outside of the package
- E-mailed
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- HIPAA Q&A: Level of encryption needed for email
- CMS has reformulated payments for some bilateral procedures
- Catch up on what's new with injections and infusions
- New conflicts of interest create new challenges
- Q/A. One injection code or two?
- What does case-mix index mean to you?
- Identify modifiable risk factors to prevent patient falls
- Hospitals are not bound by InterQual criteria for determining patient status
- Searched
