To reply to myself, here's the related info from HHS's website
(hhs.govprivacy.html):Open ↗
PATIENT PROTECTIONS
The new privacy regulations ensure a national floor of privacy protections for patients by limiting
the ways that health plans, pharmacies, hospitals and other covered entities can use patients'
personal medical information. The regulations protect medical records and other individually
identifiable health information, whether it is on paper, in computers or communicated orally. Key
provisions of these new standards include:
Access To Medical Records. Patients generally should be able to see and obtain copies of their
medical records and request corrections if they identify errors and mistakes. Health plans, doctors,
hospitals, clinics, nursing homes and other covered entities generally should provide access these
records within 30 days and may charge patients for the cost of copying and sending the records.
Notice of Privacy Practices. Covered health plans, doctors and other health care providers must
provide a notice to their patients how they may use personal medical information and their rights
under the new privacy regulation. Doctors, hospitals and other direct-care providers generally will
provide the notice on the patient's first visit following the April 14, 2003, compliance date and
upon request. Patients generally will be asked to sign, initial or otherwise acknowledge that they
received this notice. Health plans generally must mail the notice to their enrollees by April 14 and
again if the notice changes significantly. Patients also may ask covered entities to restrict the
use or disclosure of their information beyond the practices included in the notice, but the covered
entities would not have to agree to the changes.
Limits on Use of Personal Medical Information. The privacy rule sets limits on how health plans and
covered providers may use individually identifiable health information. To promote the best quality
care for patients, the rule does not restrict the ability of doctors, nurses and other providers to
share information needed to treat their patients. In other situations, though, personal health
information generally may not be used for purposes not related to health care, and covered entities
may use or share only the minimum amount of protected information needed for a particular purpose.
In addition, patients would have to sign a specific authorization before a covered entity could
release their medical information to a life insurer, a bank, a marketing firm or another outside
business for purposes not related to their health care.
Prohibition on Marketing. The final privacy rule sets new restrictions and limits on the use of
patient information for marketing purposes. Pharmacies, health plans and other covered entities must
first obtain an individual's specific authorization before disclosing their patient information for
marketing. At the same time, the rule permits doctors and other covered entities to communicate
freely with patients about treatment options and other health-related information, including disease-
management programs.
Stronger State Laws. The new federal privacy standards do not affect state laws that provide
additional privacy protections for patients. The confidentiality protections are cumulative; the
privacy rule will set a national "floor" of privacy standards that protect all Americans, and any
state law providing additional protections would continue to apply. When a state law requires a
certain disclosure -- such as reporting an infectious disease outbreak to the public health
authorities -- the federal privacy regulations would not preempt the state law.
Confidential communications. Under the privacy rule, patients can request that their doctors, health
plans and other covered entities take reasonable steps to ensure that their communications with the
patient are confidential. For example, a patient could ask a doctor to call his or her office rather
than home, and the doctor's office should comply with that request if it can be reasonably
accommodated.
Complaints. Consumers may file a formal complaint regarding the privacy practices of a covered
health plan or provider. Such complaints can be made directly to the covered provider or health plan
or to HHS' Office for Civil Rights (OCR), which is charged with investigating complaints and
enforcing the privacy regulation. Information about filing complaints should be included in each
covered entity's notice of privacy practices. Consumers can find out more information about filing a
complaint at hhs.govhipaaOpen ↗ or by calling (866) 627-7748.
HEALTH PLANS AND PROVIDERS The privacy rule requires health plans, pharmacies, doctors and other
covered entities to establish policies and procedures to protect the confidentiality of
protected health information about their patients. These requirements are flexible and scalable
to allow different covered entities to implement them as appropriate for their businesses or
practices. Covered entities must provide all the protections for patients cited above, such as
providing a notice of their privacy practices and limiting the use and disclosure of information
as required under the rule. In addition, covered entities must take some additional steps to
protect patient privacy:
Written Privacy Procedures. The rule requires covered entities to have written privacy procedures,
including a description of staff that has access to protected information, how it will be used and
when it may be disclosed. Covered entities generally must take steps to ensure that any business
associates who have access to protected information agree to the same limitations on the use and
disclosure of that information.
Employee Training and Privacy Officer. Covered entities must train their employees in their privacy
procedures and must designate an individual to be responsible for ensuring the procedures are
followed. If covered entities learn an employee failed to follow these procedures, they must take
appropriate disciplinary action.
Public Responsibilities. In limited circumstances, the final rule permits -- but does not require
--covered entities to continue certain existing disclosures of health information for specific
public responsibilities. These permitted disclosures include: emergency circumstances;
identification of the body of a deceased person, or the cause of death; public health needs;
research that involves limited data or has been independently approved by an Institutional Review
Board or privacy board; oversight of the health care system; judicial and administrative
proceedings; limited law enforcement activities; and activities related to national defense and
security. The privacy rule generally establishes new safeguards and limits on these disclosures.
Where no other law requires disclosures in these situations, covered entities may continue to use
their professional judgment to decide whether to make such disclosures based on their own policies
and ethical principles.
Equivalent Requirements For Government. The provisions of the final rule generally apply equally to
private sector and public sector covered entities. For example, private hospitals and government-run
hospitals covered by the rule have to comply with the full range of requirements.
------------------
How many of you receive insurance disbursements or reimbursements? How many of you receive referrals
from doctors? How many have written privacy policies, and an assigned privacy officer? How many get
patient consent and have the privacy information signed off on by the patient?
I think this is where you might see some trouble:
In other situations, though, personal health information generally may not be used for purposes not
related to health care, and covered entities may use or share only the minimum amount of protected
information needed for a particular purpose. In addition, patients would have to sign a specific
authorization before a covered entity could release their medical information to a life insurer, a
bank, a marketing firm or another outside business for purposes not related to their health care.
Prohibition on Marketing. The final privacy rule sets new restrictions and limits on the use of
patient information for marketing purposes. Pharmacies, health plans and other covered entities must
first obtain an individual's specific authorization before disclosing their patient information for
marketing.
Lee
"]news:[email hidden]...
Quoted message said:I'd be really really careful about taking any private information about client's out of the office
without the client's consent. HIPAA would
frown
Quoted message said:on medical records being copied or transferred without prior written consent. You and/or your
current employer could get in a lot of hot
water.
Quoted message said:HIPAA might not apply to you - but it might as well. If you receive any insurance reimbursement it
certainly will apply to you and all your
records.
Quoted message said:IANAL.
Lee Drake
"George" <[email hidden]> wrote in message "]news:[email hidden]...
Quoted message said:Tiffany,
It sounds like it is too late for this, but the most professional
approach
Quoted message said:Quoted message said:to this situation that I've ever seen was taken by my massage therapist
(she
Quoted message said:has others working for her). She sent out letters to all the clients
who'd
Quoted message said:ever had a massage from the therapists who were leaving to let them know
and
Quoted message said:to allow the client the opportunity to choose if the exiting therapists could leave with contact
information.
From a client standpoint, I'd say the most important issues should be:
1) the break should look professional and on good terms to the client,
even
Quoted message said:if it wasn't
2) the exiting therapist should be allowed to say that he/she is leaving
and
Quoted message said:when...it isn't nice to surprise a client with a new therapist (I screen carefully and would
feel cheated)...if the client inquires about contact info you should be allowed to give it
3) the existing business shouldn't solicit any of this customer
base...after
Quoted message said:all, they are already clients and already know the business is there and what it can do
4) be aware that some clients (myself included) select two
therapists...a
Quoted message said:Quoted message said:backup therapist in case one is in pain and cannot get in to see the
favored
Quoted message said:therapist (good ones book up fast...sometimes I feel like I'm waiting
for
Quoted message said:a
Quoted message said:death to occur on her client list if I need to get in sooner)
5) the existing business should release any therapy notes to clients on request so that they may
bring the notes to you (the biggest objection
you
Quoted message said:Quoted message said:might run into in just having a copy of everyone's notes may be a
privacy
Quoted message said:Quoted message said:issue from clients themselves who choose to stay with the existing business...I know as a
client, I'd want to be in control of WHO has such information and not feel like they just made
copies of my chart for all their employees)
Good luck! George
PS--You don't practice in Michigan, do you?
"Tiffany" <[email hidden]> wrote in message "]news:[email hidden]...
Quoted message said:I am a MT.... I used to work in a private office as an independent contractor. I am leaving
there, this week is my last. I am not allowed
to
Quoted message said:Quoted message said:solicited clients except for the ones that I brought into the office.
Should
Quoted message said:I be allowed to take those client's information forms with notes with
me
Quoted message said:Quoted message said:as
Quoted message said:I continue to work on them at my new location? Should the owner of
that
Quoted message said:Quoted message said:Quoted message said:private office still be soliciting those clients? We don't really have anything in the
contract about this but I would like to take those
files
Quoted message said:Quoted message said:Quoted message said:with me. Just want an idea of if its professional to ask her for the
files
Quoted message said:Quoted message said:or not.
Thanks
Tiffany