General Surgery Coding Alert - 2013 Issue 27
Patient Privacy: Buckle Down for HIPAA's Regs on Patient Access
Subscribe or sign in to view the full article.
Article Overview
This article explains recent HIPAA and HITECH patient-access requirements and why covered entities need a clear process for responding to requests for copies of records. It focuses on electronic access, patient requests for unencrypted delivery, defining the designated record set, updating privacy notices, and producing access reports or accounting information. The content is aimed at compliance staff, front-desk personnel, practice managers, and others responsible for privacy operations and record release workflows.
Why This Topic Matters
Patient access obligations affect how organizations receive, evaluate, and fulfill records requests, especially when information is maintained electronically. Understanding the scope of the designated record set and related disclosure reporting requirements helps reduce compliance risk and supports timely, accurate responses to patients.
Article Sections
-
Create a Process Now
Introduces the need for an internal workflow for handling patient requests for copies of records and related access issues. The section frames the article’s focus on compliance readiness and record-release procedures.
-
Heed New Rules for Electronic Copies — But Tread Carefully
Discusses updated HIPAA and HITECH patient-access requirements for electronic information and the need to address patient preferences for electronic delivery. It also covers privacy and risk considerations associated with electronic transmission requests.
-
Define the Scope of Your DRS
Addresses how organizations should understand and define the designated record set and where relevant information may reside. The section also notes the relationship between the DRS and privacy notice updates.
-
What You Must Include in an Access Report
Explains the general scope of access reports and accounting of disclosures under the updated rules. It also highlights the need to assess system capabilities for producing the required report information.
What You Will Learn
- How patient access requests are affected by HIPAA and HITECH updates
- Why organizations need a process for furnishing copies of records
- How electronic record requests and delivery options are addressed at a high level
- What the designated record set concept means for access workflows
- Why privacy notices and reporting capabilities may need review
Who Should Read This
- Compliance officers
- Privacy officers
- Practice managers
- Front-desk staff
- Health information management professionals
- Healthcare administrators
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com