Your patient wants records sent via unsecure email. Are you covered?

Subscribe or sign in to view the full article.

Note:  The following article synopsis was NOT provided by HCPro. It was created by Find-A-Code/innoviHealth.

Article Overview

This article addresses how HIPAA privacy and security principles apply when a patient asks for medical records to be sent by email and the provider does not use secure email. It explains the general compliance context, patient access issues, risk warnings, alternative delivery options, and related guidance from HHS, OCR, and ONC. The piece is relevant to health care providers, privacy and compliance staff, and office personnel handling record requests and patient communications.

Why This Topic Matters

Email delivery of protected health information can create privacy and security concerns, so providers need to understand when patient requests may be honored and what safeguards or alternatives may be appropriate. The article is useful for reducing compliance risk and for understanding how federal guidance affects day-to-day record release workflows.

Article Sections

  1. Question and answer on patient-requested email delivery

    Introduces the access-request scenario and frames the privacy and security issue for providers that do not have secure email capability.

  2. HIPAA privacy and security guidance

    Summarizes federal guidance on protecting patient information, reasonable safeguards, and patient-requested unsecure transmission.

  3. OCR and exception considerations

    Discusses additional federal guidance and circumstances in which a provider may need to consider whether an alternate delivery option is appropriate.

  4. Alternative delivery methods and business associate issues

    Reviews other ways to provide records and notes considerations related to messaging tools and outside vendors.

  5. Resources

    Lists the federal reference materials cited in the article for further review.

What You Will Learn

  • How federal privacy and security guidance relates to patient-requested email delivery of records
  • What general safeguards are discussed for handling access requests
  • What alternatives may be considered when secure email is not available
  • Which federal guidance documents are referenced in the discussion
  • Why compliance staff may want to review vendor and communication-tool arrangements

Who Should Read This

  • Physicians and other health care providers
  • Medical office managers
  • HIPAA compliance and privacy staff
  • Health information management professionals
  • Billing and administrative personnel who handle records requests

Code Ranges Discussed

  • CFR: 45 CFR § 164.52

Subscribe or sign in to view the full article.

Official DecisionHealth® Newsletter Archives includes:

  • Includes over 25,000 articles from:
    • Coder Pink Sheets
    • Part B News
    • Answer Books newsletters
  • Current newsletters added each quarter
  • Timely news and guidance vital for your practice
  • Fully searchable through Find-A-Code's Comprehensive Search
  • Codes mentioned in articles are linked to the Find-A-Code Code Information pages
  • Code Information pages link back to related articles
  • Save yourself tons of research time, find everything in one place!
Access to this feature is available in the following products:
  • DecisionHealth Coding, Billing and Compliance Library

Related Articles

Articles are listed in order of calculated relevance.

demo
request yours today
subscribe
start today
newsletter
free subscription

Thank you for choosing Find-A-Code, please Sign In to remove ads.

Aimee- AI -powered coding assistant - Try it now for Free Would you like Aimee - AI
to help you with this?