We have scoured the internet for real-life examples on the use of emails in medical scenarios, the better to be able to convince our readers of the points we have made in past posts about the perils and pitfalls of using unsecured emails for communications. Email is one of the oldest (some even refer to it as “legacy”) tools in our always-connected, digital world. However, its use between patients and their medical providers and amongst doctors and their business associates can be fraught with issues that may violate the provisions of the Health Insurance Portability and Accountability Act (HIPAA).
The HIPAA privacy rules require covered entities and their business associates to protect patients’ health information from unauthorized disclosure. The HIPAA security rules do not mandate specific technologies or prohibit others. In fact, HIPAA
“…allows covered health care providers to communicate electronically, such as through e-mail, with their patients, provided they apply reasonable safeguards when doing so.”
An imperfect understanding of patients’ privacy concerns, lack of proficiency in using computers or access to them, misguided policies on usage – all these play a part in HIPAA privacy breaches. The consequences of such breaches can be quite burdensome for the medical provider.
In a previous post, we provided some data on HIPAA-related complaints filed with the US Health and Human Services’ (HHS) Office of Civil Rights (OCR). There were 350 breaches of unprotected health information involving 500 or more individuals reported in the last two years to the HHS and under investigation by OCR. 75 of these had their origin in email, with half this number involved in unauthorized access or disclosure.
Medical providers often forget (or might even be unaware of) “reasonable safeguards” that can easily be implemented to prevent emails from leaking information that patients might consider as compromising their privacy. By analyzing some real life examples of how email is used (well, actually misused) in practice, we hope this post can convince you of reasonable safeguards that can make email a useful and efficient part of your workflow while conforming to HIPAA.
Read the rest of this post »