decisionhealth Newsletters, Coder Pink Sheets - 2022 Issue 12 (December)
Compliance: Practice pays a high price for putting PHI in the garbage
Subscribe or sign in to view the full article.
Article Overview
This article explains a HIPAA settlement involving a dermatology practice and examines the privacy and security lessons that other covered entities and business associates can draw from it. It focuses on disposal of physical PHI, related HIPAA Privacy Rule obligations, and the kinds of policies, training, oversight, and safeguards emphasized by compliance experts.
Why This Topic Matters
Improper disposal of patient information can trigger enforcement action, financial penalties, and corrective action requirements. The article is relevant to practices that handle paper, specimen containers, labels, prescription packaging, and other physical PHI, especially smaller organizations building or strengthening HIPAA compliance programs.
Article Sections
-
Behind the breach
Summarizes the reported incident, the type of information involved, and the enforcement response from OCR. It also outlines the general compliance areas implicated by the investigation.
-
Another ‘disheartening’ finding
Presents expert commentary on the nature of the lapse and the broader implications for privacy oversight in smaller practices.
-
Is it a small entity problem?
Discusses compliance challenges that smaller provider organizations may face and the importance of assigning responsibility for privacy functions.
-
Policy and procedure woes
Reviews the role of written privacy and security policies, along with the need for practical procedures tailored to office-specific risks.
-
Beef up workforce training
Covers workforce education, documentation, and the need for routine training tied to organizational procedures.
-
Lack of security means increased risk
Explains broader disposal-related privacy and security risks and the importance of assessing and monitoring disposal practices.
-
Action steps for compliance
Outlines general categories of safeguards, oversight activities, and disposal methods that organizations may consider when building compliance programs.
What You Will Learn
- How a HIPAA disposal-related settlement can lead to a corrective action plan
- Why physical PHI disposal is a recurring privacy and security concern
- What broad categories of administrative safeguards are emphasized in OCR follow-up
- How smaller practices may organize privacy responsibility and workforce training
- Why audits, risk assessments, and vendor oversight matter for PHI disposal
Who Should Read This
- Medical practice administrators
- HIPAA privacy and security officers
- Compliance officers
- Dermatology and outpatient practice managers
- Business associates handling physical PHI
- Healthcare attorneys and consultants
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com