HIPAA and Confidentiality 

According to the federal law, all patients have the right to  have their personal privacy respected and their medical  records handled with confidentiality. 

No information—including test results, patient histories, and even the fact that the patient is a patient—can be  told to another person without the patient’s permission.  Therefore, it is important that a medical assistant adhere to  the following guidelines: 

  • Never make any statements about your employing physician that could be interpreted as an admission of fault. On the other hand, as a medical assistant, you  cannot remain silent if you are aware that your employing physician is doing something illegal. You can be  held liable for remaining silent. 
  • Do not participate in negative or critical discussions of the physician(s) or other practitioners in your office with your patients. Do not comment on a patient’s  negative criticism of a current or former physician. 
  • Never discuss anything about a patient outside the office or with office staff unless they have a need to know specific information. 
  • Make sure that a female medical assistant is present when the physician (male or female) examines a female patient. 
  • Treat all patients with dignity and respect.

This is not just a matter of ethics or professionalism; as  already noted, it is the law. After numerous complaints  from patients unable to continue to pay premiums to the same  insurance company when they changed jobs, Congress passed  the Health Insurance Portability and Accountability Act (HIPAA)  of 1996. HIPAA, also known as Public Law 104-191, seeks to  improve the efficiency and effectiveness of the health care system through insurance reform and administrative simplification. Although some of the information in this section may  have been already mentioned earlier in the chapter, it is important to review it in relationship to HIPAA guidelines.  Many citizens feared that certain information about their  health might prevent them from getting insurance coverage,  and Congress responded by legislating rigorous standards of  privacy for protected health information. The U.S. Department of Health and Human Services was charged with setting privacy and security standards for health information.  Covered entities include health plans, health care clearinghouses, and providers who conduct certain health care transactions electronically. Medical practices are required to  notify patients about the uses, disclosures, and rights of their  protected information.

These protocols, although sharing common concerns for  the patient, are not standardized by the government. Each  practice should have policies and procedures for handling  confidential information, including privacy officers who  guard the security of identifiable health information. All  employees and business associates who will have access to  identifiable health information must give written assurances  that they will protect patient information before they may  access it. Patients also must be informed about how their  information might be shared with others. 

HIPAA gives patients more control over their health  information than they had before, sets boundaries and safeguards for release of information, and holds personnel  accountable to protect the information. Patients can find out  who had access to their private information, and HIPAA  gives them the right to examine and copy their records.  They also can request corrections to records. Penalties for the  improper release of information are very expensive. There are  few exceptions to this rule, such as government access, worker’s compensation laws, research, and matters relating to  public health and law enforcement. Medical assistants must  always be vigilant about protecting patient information and  following the safeguards established in their office. 

Complaints under HIPAA should be addressed to the U.S.  Department of Health and Human Services. However, the  medical assistant and office team should make every effort to  personally address and rectify any patient complaints. 

All medical office employees must undergo HIPAA training during their orientation. HIPAA is organized into three  parts: 

  • Privacy regulations • Transaction standards • Security regulations 

To adhere to HIPAA regulations, the medical office must  have an appointed privacy official, draft privacy policies and  procedures, and implement a program to educate and train  all employees and physicians on the mandates of HIPAA.  These polices should be included in the office policy and  procedures manual. Acknowledgment of receiving a copy of  the privacy practices of the medical office should be signed  by all new patients. This policy should be clearly posted in  the waiting area of the medical office. Patients must sign an  authorization to release any medical information, including  information released to a spouse or adult children. Without  a signed consent, the medical assistant is prohibited from  disclosing any medical information. 

HIPAA extends its rules to making sure that computers  with confidential patient information cannot be seen or  accessed by unauthorized individuals. All faxes and e-mails

that contain private patient information must have a disclaimer stating that the information is confidential, and if  the information is accidentally transmitted to someone  without clearance to read it, the recipient must immediately  notify the office and destroy the information. 

Health care professionals should refrain from discussing  patients’ private information where it can be overheard by others. Even when the medical assistant reaches a patient’s voice  mail, it is important to leave only the minimal information that  contains return-call information. The use of speakerphones  should be avoided when discussing patient information. 

Although HIPAA is the law that protects the patient and  promotes the portability of insurance, massive amounts of  health care data must be controlled to ensure not only privacy  but also efficiency. To simplify data use, the HIPAA transactions standard requires unique identification numbers for  health care providers, individuals, health care plans, and  employers. With these numbers, it is clear (even if names are  similar) who the interested parties are in a transaction. 

HIPAA further seeks to protect the transmission of data  relating to health care. To improve the efficiency and effectiveness of the health care system, Congress, the public, and  the health care industry have mutually agreed that standards  are needed for the electronic exchange of administrative and  financial health care transactions. HIPAA designates the  Secretary of Health and Human Services to adopt protective  and secure standards.  National standards for electronic health care transactions  ultimately sought to simplify the processes involved in  transmitting information required for quality patient care.  Following these standards should promote savings resulting  from the reduction in administrative burdens on health care  providers and health plans. A standardized national electronic claim format replaced over 400 different formats that  existed before the HIPAA transactions standard. Health  plans now accept one standard format for electronic claims as  well as other transactions such as remittance advices and  referral authorizations to health care providers. The Secretary of Health and Human Services has adopted the standards for the following administrative and financial health  care transactions: 

  1. Health claims and equivalent encounter information
  2. Enrollment and disenrollment in a health plan
  3. Eligibility for a health plan
  4. Health care payment and remittance advice
  5. Health plan premium payments
  6. Health claim status
  7. Referral certification and authorization

 

The medical assistant’s treatment of and concern for the  patient reflects the physician’s high standards of care. The  human dignity of each patient must be preserved regardless  of the patient’s socioeconomic background, race, age, nationality, sexual orientation, or gender. 

Any information that is given to a physician by a patient  is considered confidential, and it may not be given to an  unauthorized person (Figure 3-8). The physician’s medical  assistant is considered to be an authorized person with access  to the patient’s file and information. This information may  not be divulged to anyone without permission of the doctor  or patient. The physician must be notified of any information the patient gives the medical assistant, such as if the  patient is not taking prescribed medications or complying  with treatment.

FIGURE 3-8 A medical assistant listening to the patient and physician  discuss the patient’s care.

**PROFESSIONALISM

Telling the truth is one of the most important parts  of being a medical professional. Every human  makes mistakes; it is part of being human. However, the most important thing any professional can do is  admit having made a mistake and seek to correct it. Do not  offer extra information to the patient. You should only state  that there is a correction to be made. Be sure to speak with  the supervising physician, and document clearly in the chart  the mistake that was made and how it was corrected. Honesty goes a very long way in preventing litigation and providing good, quality care to all patients. Be sure to notify the  physician if there is a task you are not proficient to do. For  example, if you did a procedure early in your training but  have not done it for a long time, you need to notify the physician rather than perform the task without proficiency. Veracity, or speaking the truth at all times, is a professional  quality that all medical assistants must have.