Compliance: Practice pays a high price for putting PHI in the garbage

Subscribe or sign in to view the full article.

Note:  The following article synopsis was NOT provided by HCPro. It was created by Find-A-Code/innoviHealth.

Article Overview

This article explains a HIPAA settlement involving a dermatology practice and examines the privacy and security lessons that other covered entities and business associates can draw from it. It focuses on disposal of physical PHI, related HIPAA Privacy Rule obligations, and the kinds of policies, training, oversight, and safeguards emphasized by compliance experts.

Why This Topic Matters

Improper disposal of patient information can trigger enforcement action, financial penalties, and corrective action requirements. The article is relevant to practices that handle paper, specimen containers, labels, prescription packaging, and other physical PHI, especially smaller organizations building or strengthening HIPAA compliance programs.

Article Sections

  1. Behind the breach

    Summarizes the reported incident, the type of information involved, and the enforcement response from OCR. It also outlines the general compliance areas implicated by the investigation.

  2. Another ‘disheartening’ finding

    Presents expert commentary on the nature of the lapse and the broader implications for privacy oversight in smaller practices.

  3. Is it a small entity problem?

    Discusses compliance challenges that smaller provider organizations may face and the importance of assigning responsibility for privacy functions.

  4. Policy and procedure woes

    Reviews the role of written privacy and security policies, along with the need for practical procedures tailored to office-specific risks.

  5. Beef up workforce training

    Covers workforce education, documentation, and the need for routine training tied to organizational procedures.

  6. Lack of security means increased risk

    Explains broader disposal-related privacy and security risks and the importance of assessing and monitoring disposal practices.

  7. Action steps for compliance

    Outlines general categories of safeguards, oversight activities, and disposal methods that organizations may consider when building compliance programs.

What You Will Learn

  • How a HIPAA disposal-related settlement can lead to a corrective action plan
  • Why physical PHI disposal is a recurring privacy and security concern
  • What broad categories of administrative safeguards are emphasized in OCR follow-up
  • How smaller practices may organize privacy responsibility and workforce training
  • Why audits, risk assessments, and vendor oversight matter for PHI disposal

Who Should Read This

  • Medical practice administrators
  • HIPAA privacy and security officers
  • Compliance officers
  • Dermatology and outpatient practice managers
  • Business associates handling physical PHI
  • Healthcare attorneys and consultants

Subscribe or sign in to view the full article.

Official DecisionHealth® Newsletter Archives includes:

  • Includes over 25,000 articles from:
    • Coder Pink Sheets
    • Part B News
    • Answer Books newsletters
  • Current newsletters added each quarter
  • Timely news and guidance vital for your practice
  • Fully searchable through Find-A-Code's Comprehensive Search
  • Codes mentioned in articles are linked to the Find-A-Code Code Information pages
  • Code Information pages link back to related articles
  • Save yourself tons of research time, find everything in one place!
Access to this feature is available in the following products:
  • DecisionHealth Coding, Billing and Compliance Library

Related Articles

Articles are listed in order of calculated relevance.

demo
request yours today
subscribe
start today
newsletter
free subscription

Thank you for choosing Find-A-Code, please Sign In to remove ads.

Aimee- AI -powered coding assistant - Try it now for Free Would you like Aimee - AI
to help you with this?