YOUR BUSINESS AUTHORITY

Springfield, MO

Log in Subscribe

HIPAA rule intended to protect patient privacy

Posted online

Rebecca Pruitt is an attorney with Zerrer & Pruitt, which specializes in the legal needs of seniors.

Anyone who has been to the doctor, dentist or hospital since April 14 has been given more printed forms and asked to sign more authorizations.

These new procedures are a result of the Health Insurance Portability and Accountability Act of 1996 privacy rule. Part of the privacy rule is intended to protect and enhance the rights of consumers by providing them access to their health information.

It also is intended to control the inappropriate use of that information. Although most agree the privacy rule has a good purpose, much confusion and misunderstanding exists.

Following are some common myths and truths about what the law actually says.

Myth: A hospital is prohibited from sharing information with the patient's family without the patient's express consent.

Truth: Under the privacy rule, a health care provider may "disclose to a family member, other relative or a close personal friend of the individual," the medical information directly relevant to such person's involvement with the patient's care or payment related to the patient's care. If the patient is present, the health care provider may disclose medical information to such people if the patient does not object.

If a hospital or other health care provider refuses to provide any relevant information under these circumstances, it is due to the health care provider's policy and not the regulation.

Myth: A patient cannot be listed in a hospital's directory without the patient's consent and the hospital is prohibited from sharing a patient's directory information with the public.

Truth: The privacy rule permits hospitals to continue providing directory information to the public unless the patient has specifically chosen to opt out. According to the regulation, a hospital may maintain a directory that includes the patient's name, location in the facility, condition in general terms and religious affiliation, and disclose such information to people who ask for the patient by name, unless the patient opts out of having his or her information included in the directory.

Myth: Members of the clergy can no longer find out whether members of their congregation or their religious affiliation are hospitalized unless they know the person by name.

Truth: The regulation specifically provides that hospitals may continue the practice of disclosing directory information "to members of the clergy" unless the patient has objected to such disclosure. Any requirement that the patient must list a specific church or any limitation on the practice of directly notifying clergy of admitted patients is based on hospital policy, not law.

Myth: A patient's family member can no longer pick up prescriptions for the patient.

Truth: The regulation provides that a family member or other individual may act on the patient's behalf "to pick up filled prescriptions, medical supplies, X-rays, or other similar forms of protected health information." The regulation permits the health care provider to reasonably infer that doing so is in the patient's best interest and in accordance with professional judgment and common practice.

Myth: One doctor's office cannot send medical records of a patient to another doctor's office without the patient's consent.

Truth: No consent is necessary for one doctor's office to transfer a patient's medical records to another doctor's office for treatment purposes.

A health care provider "is permitted to use or disclose protected health information (for) treatment, payment, or health care operations" without patient consent.

Myth: Patients' medical records can no longer be used for marketing.

Truth: Use or disclosure of medical information continues to be permitted for health-related marketing under the HIPAA privacy regulation.

The only disclosure of medical information for marketing that requires prior authorization by the patient under the privacy regulation is that in which the doctor or pharmacy is paid to recommend a product or service that is not related to health care.

Myth: The privacy regulation mandates new disclosures of patient information.

Truth: In most cases, the regulation does not mandate disclosure to anyone except the individual, his or her "personal representative," or the Secretary of the Department of Health and Human Services for use in oversight investigations. Disclosure is permitted, not mandated, for other uses under certain limits and standards, such as to carry out treatment, payment, or health care operations, or under applicable laws.

There are many aspects of HIPAA that are not covered by this article. A good source of information may be found on HHS's Web site at www.hhs.gov/ocr/privacysummary.pdf.

Comments

No comments on this story |
Please log in to add your comment
Editors' Pick
Fall 2026 Architects & Engineers Project Report

This installment of Springfield Business Journal’s Architects & Engineers Project Report showcases 26 endeavors by area design and engineering professionals.

Most Read
Update cookies preferences