decisionhealth Newsletters, Coder Pink Sheets - 2023 Issue 2 (February)
Compliance: Remind staff to stick to HIPAA guidelines when PHI is a family affair
Subscribe or sign in to view the full article.
Article Overview
This compliance-focused article explains why HIPAA privacy rules still apply when patients are related to or known by staff, and why organizations need clear policies for access, training, and monitoring. It is aimed at coding, compliance, privacy, and practice management professionals who handle protected health information and want to understand the operational risks of improper record access. The article discusses general HIPAA privacy and security themes, breach response considerations, workforce training, and examples used to illustrate common access pitfalls.
Why This Topic Matters
Improper access to PHI can create privacy breaches, reporting obligations, and organizational risk even when the employee’s intent is personal rather than malicious. Understanding the article helps practices reinforce access controls and training before an incident occurs.
Article Sections
-
Privacy rules apply to everyone
Discusses the baseline HIPAA privacy framework and why employee relationships to patients do not change the obligation to follow access and disclosure requirements. It also addresses general concerns about breach exposure and privacy reporting obligations.
-
Compliance ends when snooping begins
Explains the difference between authorized access and improper peeking at records, including the broader privacy and security risks that can arise in workplace settings. The section also references illustrative situations involving personal relationships and curiosity-driven access.
-
Train staff, encourage feedback
Covers the role of HIPAA training, policy documentation, and periodic reminders in supporting compliance efforts. It also emphasizes encouraging staff to ask questions when they are unsure how to handle access-related situations.
What You Will Learn
- How HIPAA privacy obligations apply when staff know the patient personally
- Why access controls and the minimum necessary principle matter in day-to-day operations
- How improper record access can create compliance and breach risks
- Why training and documentation are important for privacy compliance programs
- How practices can encourage staff to raise questions about access and disclosure concerns
Who Should Read This
- Medical practice staff
- Coders
- Compliance officers
- Privacy officers
- Practice managers
- Health information management professionals
Subscribe or sign in to view the full article.



Quick, Current, Complete - www.findacode.com