decisionhealth Newsletters, Part B News - 2021 Issue 3 (March)
As new rule looms, get ready to meet patient PHI email requests and avoid breaches
Subscribe or sign in to view the full article.
Article Overview
This article addresses how HIPAA privacy and security requirements apply when patients ask for protected health information to be sent electronically, especially by email, during the COVID-19 era. It also discusses the impact of a new ONC information-blocking rule, related federal enforcement discretion around online scheduling for vaccination, and practical compliance concerns for avoiding reportable breaches. It is aimed at health care providers, compliance staff, and administrators who handle patient access requests and electronic communications.
Why This Topic Matters
Patient-directed electronic delivery of protected health information can create privacy, security, and breach-reporting risks if handled incorrectly. The article helps readers understand the broader federal framework affecting emailed patient records and why careful documentation and secure transmission practices matter.
Article Sections
-
HIPAA and COVID-19 enforcement context
Overview of the federal pandemic-era HIPAA environment and the continuing obligation to protect patient information in electronic communications.
-
ONC information-blocking rule and patient access
Discussion of the upcoming ONC rule and how it relates to patient requests for electronic access and delivery of health information.
-
Get it on paper
General guidance on documenting patient authorization and related administrative safeguards before sending health information electronically.
-
Suppose they want it airdropped?
Discussion of patient preferences for delivery methods, the role of consent, and the use of alternative secure communication options.
-
How to handle if it goes wrong
General discussion of what may happen if electronic delivery is misdirected and how breach assessment and reporting considerations arise.
What You Will Learn
- How HIPAA privacy and security rules continue to apply to electronic patient communications
- How patient access requests intersect with the ONC information-blocking rule
- Why documentation and authorization are important when sending protected health information electronically
- What broad issues arise when a patient prefers a less secure delivery method
- How misdirected electronic communications can raise breach-related concerns
Who Should Read This
- Health care providers
- Compliance professionals
- Practice managers
- Health information staff
- Telehealth administrators
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com