Who we are under HIPAA
The practice is a covered entity. That means the HIPAA Privacy Rule and Security Rule apply to us directly, and to you as a member of our workforce. Vendors that handle client information on our behalf (our practice management system, our clearinghouse, Google Workspace) are business associates, and we have signed agreements with them that require them to protect it too. A note on wording: we don’t describe ourselves as “HIPAA-compliant” as if it were a badge. Compliance is a set of practices we do every day, not a status we’ve achieved. Don’t use the phrase in marketing, on the phone, or in writing.What counts as PHI
Protected health information is any information that identifies a client, or could reasonably identify them, and relates to their health, their care, or payment for their care. That includes the obvious (diagnosis, notes) and the less obvious (the fact that someone is a client at all, their appointment time, their phone number in our system, a voicemail from them). If it identifies a client and it came to us because they’re a client, treat it as PHI.The three rules, in one paragraph each
Privacy Rule. Governs when PHI can be used and disclosed. Treatment, payment, and running the practice are permitted without a separate authorization. Almost everything else needs the client’s written authorization, and every use is limited to the minimum necessary. See Privacy Rule and minimum necessary. Security Rule. Governs how electronic PHI is protected: who can access it, on what devices, with what passwords, and how we know. See Security Rule and ePHI. Breach Notification Rule. Governs what happens when PHI is exposed. Short version: you tell us immediately, and the practice handles notification. See Breach and incident reporting.What HIPAA requires of you
- Complete privacy and security training at hire and annually, and sign the completion record.
- Sign the practice’s confidentiality agreement before you get access to any client information.
- Follow the practices in this manual and the SOPs.
- Report anything that looks like a privacy problem, immediately.
- Never access a record you don’t need for your work, including your own family members’, colleagues’, or anyone you’re curious about.