Health Information Technologies and Processes

HIPAA Related Work Processes...Most to Least

  • 1.  HIPAA Related Work Processes...Most to Least

    Posted 20 days ago
    A very lively discussion on a webinar on the frequency of HIPAA related requests from individuals was very informative on what people typically encounter.  Of the items discussed, the order of frequency was as follows in the list below.  Curious to hear how others experience these same requests in terms of their frequency.

    From most to least the list is:

    1. Request to use or disclose PHI (authorization for release of info)
    2. Request for access to PHI (copy or routing to a 3rd party)
    3. Request to amendment of PHI
    4. Request to restrict to use or disclosure of PHI
    5. Request to receive information by alternative means or alternative locations
    6. Request for an Accounting of Disclosure
    Thanks to those who respond with some comment on how this list from most to least is similar or not to your own "list" of requests.  Thanks!





    Posted: 6:06 AM AZ time

    ------------------------------
    Frank Ruelas
    Compliance Professional
    Arizona
    ------------------------------


  • 2.  RE: HIPAA Related Work Processes...Most to Least

    Posted 20 days ago

    Hi Frank,

     

    This sounds about right. Can you clarify what #5 entails?

     

    Thanks,
    Karla

     






  • 3.  RE: HIPAA Related Work Processes...Most to Least

    Posted 20 days ago
    Karla...glad to.

    Under the HIPAA Privacy Rule, and this one may be one that sometimes gets overlooked as well as some people treat it like #4 in that a person has a right to request but the CE doesn't have to comply, which is incorrect.

    Let me share an example.  If Patient Karla were to go to her PCP and ask that any mail which may contain PHI not be sent to her home address but to an alternative address such as a P.O. Box address, the CE must accommodate the request if the request is reasonable.  Hard for me to imagine how in this example, such a request would not be reasonable.

    In the regulations it goes along the lines that the CE must allow for the request and must accommodate if the request is reasonable.  I'll leave the cut and paste of the rules to others and simply share here that it can be found under the Right to Request Privacy Protection under the Confidential Communication Requirements (164.522)

    An example used in the OCR FAQs is a request by a patient to receive appointment reminders by email rather than postcard.

    Thanks for asking and hope this helped.




    Posted: 6:38 AM AZ time​

    ------------------------------
    Frank Ruelas
    Compliance Professional
    Arizona
    ------------------------------



  • 4.  RE: HIPAA Related Work Processes...Most to Least

    Posted 20 days ago

    Thank you, that makes sense.

     

    Karla

     






  • 5.  RE: HIPAA Related Work Processes...Most to Least

    Posted 19 days ago

    Good morning Frank et al,

     

    I would agree with this content and order of volume.

     

    Thank you,

    Nancy  

     

    Nancy Wallace, MBA, CHPS, RHIA

    Steward Health Care, LLC

    System Deputy Compliance and Privacy Officer, North Division

    30 Perwal Street

    Westwood, MA 02090

    (781) 375- 3144

     

    Compliance Admin Line: (877) 302-4378  or E-mail to: compliance@steward.org

    CONFIDENTIALITY NOTICE:   This e-mail message and any attachments are confidential, and are intended only for the individual or entity to which it is addressed. The information contained in this e-mail message, and any attachments, may be privileged and exempt from disclosure under applicable law. If you are not the intended recipient, or the employee or agent responsible for delivering the message to the intended recipient, you are notified that you may not review, disseminate, distribute, retransmit, convert to hard copy or copy this e-mail message and any attachments. If you received this e-mail message in error, you are requested to please notify the sender immediately by e-mail or telephone at 781-375-3144 and to delete this message from any hard drive, disk or other means of electronic storage.

     

     






  • 6.  RE: HIPAA Related Work Processes...Most to Least

    Posted 19 days ago
    Hi Frank-

    I agree with sequencing outlined for individual requests.

    ------------------------------
    Karen Reynolds
    Director, Health Information Management
    North Kansas City Hospital
    ------------------------------



  • 7.  RE: HIPAA Related Work Processes...Most to Least

    Posted 19 days ago
    Many thanks Karen...I know everyone's time is valuable...and I appreciate your time in sharing a response.





    Posted: 5:48 AM AZ time

    ------------------------------
    Frank Ruelas
    Compliance Professional
    Arizona
    ------------------------------