HIPAA Q&A: You’ve got questions. We’ve got answers!
HIM-HIPAA Insider, August 3, 2015
Want to receive articles like this one in your inbox? Subscribe to HIM-HIPAA Insider!
Submit your HIPAA questions to Editor John Castelluccio at jcastelluccio@hcpro.com and we will work with our experts to provide you with the information you need.
Q: Is sending an unencrypted CD with ePHI on it via the U.S. Mail acceptable under HIPAA? I have found there is a lot of confusion on this and some misinformation too. If you choose to go this route, would it be a defensible position during an audit?
A: The HIPAA Security Rule requires covered entities to take reasonable safeguards to protect ePHI. At a minimum, PHI sent through the mail on a CD should be encrypted or password protected. Given the ease of providing this basic level of protection, it would be difficult to defend sending PHI through the mail without encrypting the CD or at least password protecting it.
Editor’s note: Mary D. Brandt, MBA, RHIA, CHE, CHPS, an editorial advisory board member, answered this question for HCPro’s Briefings on HIPAA newsletter. This information does not constitute legal advice. Consult legal counsel for answers to specific privacy and security questions.
Want to receive articles like this one in your inbox? Subscribe to HIM-HIPAA Insider!
Related Products
Most Popular
- Articles
-
- Don't forget the three checks in medication administration
- Nursing responsibilities for managing pain
- Complications from immobility by body system
- Q&A: Primary, principal, and secondary diagnoses
- The consequences of an incomplete medical record
- Note similarities and differences between HCPCS, CPT® codes
- Practice the six rights of medication administration
- Neurological checks for head injuries
- Skills of effective case managers
- Prevent dehydration with nursing interventions
- E-mailed
- Searched