5 Examples of HIPAA Rule Violations That You Should Know About
The Health Insurance Portability and Accountability Act (HIPAA) takes the privacy of the patients’ personal information very seriously and ensures that covered entities like hospitals and insurance companies and plans follow all the guidelines framed for such purposes, and also undertakes to penalize such entities or their employees for any breach.
These laws cover a host of different situations that encompasses all the possible aspects related to protected health information (PHI). Employers are required to provide training to employees for ensuring compliance to HIPAA rules but many times actions undertaken on the spur of the moment can lead to a violation.
The following 5 examples explore some such violations.
– Internet: The Internet is now an integral part of health care; in fact HIPAA has always encouraged the management and communication of PHI through the electronic medium. However this otherwise useful medium can be a prime cause of violations too. Such breach can happen erroneously if employees send emails to the wrong recipients or communicate through mass emails. Such breach can also take place when the communication is intercepted by unauthorized sources, which is why HIPAA recommends encryption of such information. There are also many cases of willful violations where employees publish confidential information on certain health related websites.
– Press Media: Another example of HIPAA violation is when an employee leaks PHI to the media like newspapers and magazines. Such illegal disclosures are more often seen when the information concerns celebrities and politicians for obvious reasons. Also at times nurses or doctors might end up speaking to the media when a known figure is in a hospital, however this is a breach too and such matters must be left to the concerned spokesperson.
– Expressed Permission: Very often you may spontaneously reply to a patient’s family member and give out personal information, but remember that as per the law this is a violation. The patient is required to give a written and in some cases a verbal consent and only after that any part of the PHI can be disclosed to family members, no matter how close.
– Need to Know Basis: Often a violation takes place when too many people are party to the private information which increases the chances of an accidental or deliberate disclosure. Thus it is best that only those employees must have access to the data that need it to perform their duties. Also avoid accessing the data more often than necessary because excessive views will be recorded in the maintained logs and can often incite suspicion.
– Lax Security Measures: Several past cases have shown that many violations are not caused due to a lack in security measures but because of poor implementation due to a general callousness. Common examples are when the computer is left unlocked where the information is available to anyone or storing sensitive data on machines that are not adequately protected.
As an employee working at any of the covered entities it is very important that you identify all the possible situations that are in breach of the HIPAA laws because such violations invite penalty even though done unknowingly.
For more information, please visit our HIPAA rule violations website.
For more information, please visit our HIPAA rule violations website http://www.hipaaviolations.com
Author Bio: For more information, please visit our HIPAA rule violations website.
Category: Education
Keywords: HIPAA Laws ,HIPAA Compliance,Health Insurance ,HIPAA Rule Violations