Health Law Blog - Healthcare Legal Issues

Posts Tagged ‘OCR Settlement’

Faxing Patient Health Information to Wrong Number – Compliance Risk Area

Tuesday, March 13th, 2018

Physician Revises Faxing Procedures to Safeguard PHI After Faxing PHI to Employer  by Mistake

faxing phi wrong numberA medical office recently settled with OCR after it allegedly disclosed a patient’s HIV status when the office mistakenly faxed medical records to the patient’s place of employment instead of to the patient’s new health care provider.  The employee responsible for the disclosure received a written disciplinary warning, and both the employee and the physician apologized to the patient.  To resolve this matter, OCR also required the practice to revise the office’s fax cover page to underscore a confidential communication for the intended recipient. The office informed all its employees of the incident and counseled staff on proper faxing procedures.

Two things pop about about this instance.  First, this was clearly a privacy violation.  The patient’s protected health information, which incidentally revealed his or her HIV status, we sent to the employer.  Secondly, it was evident from the facts that this was a mistake.  We aren’t told exactly how this mistake was made.  Was the fax number written down in the wrong box on the patient’s records?  Did the employee who faxed the records put the incorrect number on the fax cover sheet?  We may never know.  But this does raise the importance of being precise at all stages of the patient encounter to assure that no inadvertent violations occur.  Care you should be taken when information about the patient is initially entered into the system.  Individuals at all levels who may be responsible for transmitting PHI must be deliberate about their actions.  How many people have called or faxed something to the wrong person before?  How many people have written down the wrong telephone or fax number before?  Everyone?

This OCR settlement just illustrates that sometimes these small errors can have big implications.  It does not appear to have been any significant fines or loss of employment in this situation.  But we cannot downplay the potential embarrassment or other negative consequences of mistakes like these.  It is one thing to text your friend Bob rather than your friend Bobbie, and weirdly from Bob’s perspective say how wonderful last night was and how you can’t wait to see him again.  Telling a patient’s employer about their health condition can have consequences that are much harder to laugh off.

Medical Alerts – HIPAA Implications of Flagging Patient Records

Tuesday, February 27th, 2018

Identification of AIDS Status Through Medical Alert System

Dentist Revises Process to Safeguard Medical Alert PHI

AIDS identification external alert HIPAAA recent OCR investigation of a dental practice’s flagging of patients records highlights a potential HIPAA violation.  The OCR investigation confirmed allegations that the dental practice flagged some of its medical records with a red sticker with the word “AIDS” on the outside cover.   Records were handled so that other patients and staff without need to know could read the sticker.  A patient complaint commenced an OCR investigation into whether the practice potentially identified the AIDS status of patients within the office.

When notified of the complaint filed with OCR, the dental practice immediately removed the red AIDS sticker from the complainant’s file. To resolve this matter, OCR also required the practice to revise its policies and operating procedures and to move medical alert stickers to the inside cover of the records. Further, the covered entity’s Privacy Officer and other representatives met with the patient and apologized, and followed the meeting with a written apology.

The lesson here is not to place special medical alerts on the outside of physical patient records.  This is a particularly bad practice in a dental office where the typical office setup can result in visual identification by other patients.  If a patient is being escorted by staff and is seen by other patients, the identification on the outside of the patient’s chart can easily be connected to the patient.  This creates a very sensitive potential violation of HIPAA and other laws protecting against disclosure of the AIDS status of individuals.

John H. Fisher

Health Care Counsel
Ruder Ware, L.L.S.C.
500 First Street, Suite 8000
P.O. Box 8050
Wausau, WI 54402-8050

Tel 715.845.4336
Fax 715.845.2718

Ruder Ware is a member of Meritas Law Firms Worldwide

The Health Care Law Blog is made available by Ruder Ware for educational purposes and to provide a general understanding of some of the legal issues relating to the health care industry. This site does not provide specific legal advice and you should not use the information contained on this site to address your specific situation without consulting with legal counsel that is well versed in health care law and regulation. By using the Health Care Law Blog site you understand that there is no attorney client relationship between you and Ruder Ware or any individual attorney. Postings on this site do not represent the views of our clients. This site links to other information resources on the Internet; these sites are not endorsed or supported by Ruder Ware, and Ruder Ware does not vouch for the accuracy or reliability of any information provided therein. For further information regarding the articles on this blog, contact Ruder Ware through our primary website.