HIPAA and Confidentiality
According to the federal law, all patients have the right to have their personal privacy respected and their medical records handled with confidentiality.
No information—including test results, patient histories, and even the fact that the patient is a patient—can be told to another person without the patient’s permission. Therefore, it is important that a medical assistant adhere to the following guidelines:
- Never make any statements about your employing physician that could be interpreted as an admission of fault. On the other hand, as a medical assistant, you cannot remain silent if you are aware that your employing physician is doing something illegal. You can be held liable for remaining silent.
- Do not participate in negative or critical discussions of the physician(s) or other practitioners in your office with your patients. Do not comment on a patient’s negative criticism of a current or former physician.
- Never discuss anything about a patient outside the office or with office staff unless they have a need to know specific information.
- Make sure that a female medical assistant is present when the physician (male or female) examines a female patient.
- Treat all patients with dignity and respect.
This is not just a matter of ethics or professionalism; as already noted, it is the law. After numerous complaints from patients unable to continue to pay premiums to the same insurance company when they changed jobs, Congress passed the Health Insurance Portability and Accountability Act (HIPAA) of 1996. HIPAA, also known as Public Law 104-191, seeks to improve the efficiency and effectiveness of the health care system through insurance reform and administrative simplification. Although some of the information in this section may have been already mentioned earlier in the chapter, it is important to review it in relationship to HIPAA guidelines. Many citizens feared that certain information about their health might prevent them from getting insurance coverage, and Congress responded by legislating rigorous standards of privacy for protected health information. The U.S. Department of Health and Human Services was charged with setting privacy and security standards for health information. Covered entities include health plans, health care clearinghouses, and providers who conduct certain health care transactions electronically. Medical practices are required to notify patients about the uses, disclosures, and rights of their protected information.
These protocols, although sharing common concerns for the patient, are not standardized by the government. Each practice should have policies and procedures for handling confidential information, including privacy officers who guard the security of identifiable health information. All employees and business associates who will have access to identifiable health information must give written assurances that they will protect patient information before they may access it. Patients also must be informed about how their information might be shared with others.
HIPAA gives patients more control over their health information than they had before, sets boundaries and safeguards for release of information, and holds personnel accountable to protect the information. Patients can find out who had access to their private information, and HIPAA gives them the right to examine and copy their records. They also can request corrections to records. Penalties for the improper release of information are very expensive. There are few exceptions to this rule, such as government access, worker’s compensation laws, research, and matters relating to public health and law enforcement. Medical assistants must always be vigilant about protecting patient information and following the safeguards established in their office.
Complaints under HIPAA should be addressed to the U.S. Department of Health and Human Services. However, the medical assistant and office team should make every effort to personally address and rectify any patient complaints.
All medical office employees must undergo HIPAA training during their orientation. HIPAA is organized into three parts:
- Privacy regulations • Transaction standards • Security regulations
To adhere to HIPAA regulations, the medical office must have an appointed privacy official, draft privacy policies and procedures, and implement a program to educate and train all employees and physicians on the mandates of HIPAA. These polices should be included in the office policy and procedures manual. Acknowledgment of receiving a copy of the privacy practices of the medical office should be signed by all new patients. This policy should be clearly posted in the waiting area of the medical office. Patients must sign an authorization to release any medical information, including information released to a spouse or adult children. Without a signed consent, the medical assistant is prohibited from disclosing any medical information.
HIPAA extends its rules to making sure that computers with confidential patient information cannot be seen or accessed by unauthorized individuals. All faxes and e-mails
that contain private patient information must have a disclaimer stating that the information is confidential, and if the information is accidentally transmitted to someone without clearance to read it, the recipient must immediately notify the office and destroy the information.
Health care professionals should refrain from discussing patients’ private information where it can be overheard by others. Even when the medical assistant reaches a patient’s voice mail, it is important to leave only the minimal information that contains return-call information. The use of speakerphones should be avoided when discussing patient information.
Although HIPAA is the law that protects the patient and promotes the portability of insurance, massive amounts of health care data must be controlled to ensure not only privacy but also efficiency. To simplify data use, the HIPAA transactions standard requires unique identification numbers for health care providers, individuals, health care plans, and employers. With these numbers, it is clear (even if names are similar) who the interested parties are in a transaction.
HIPAA further seeks to protect the transmission of data relating to health care. To improve the efficiency and effectiveness of the health care system, Congress, the public, and the health care industry have mutually agreed that standards are needed for the electronic exchange of administrative and financial health care transactions. HIPAA designates the Secretary of Health and Human Services to adopt protective and secure standards. National standards for electronic health care transactions ultimately sought to simplify the processes involved in transmitting information required for quality patient care. Following these standards should promote savings resulting from the reduction in administrative burdens on health care providers and health plans. A standardized national electronic claim format replaced over 400 different formats that existed before the HIPAA transactions standard. Health plans now accept one standard format for electronic claims as well as other transactions such as remittance advices and referral authorizations to health care providers. The Secretary of Health and Human Services has adopted the standards for the following administrative and financial health care transactions:
- Health claims and equivalent encounter information
- Enrollment and disenrollment in a health plan
- Eligibility for a health plan
- Health care payment and remittance advice
- Health plan premium payments
- Health claim status
- Referral certification and authorization
The medical assistant’s treatment of and concern for the patient reflects the physician’s high standards of care. The human dignity of each patient must be preserved regardless of the patient’s socioeconomic background, race, age, nationality, sexual orientation, or gender.
Any information that is given to a physician by a patient is considered confidential, and it may not be given to an unauthorized person (Figure 3-8). The physician’s medical assistant is considered to be an authorized person with access to the patient’s file and information. This information may not be divulged to anyone without permission of the doctor or patient. The physician must be notified of any information the patient gives the medical assistant, such as if the patient is not taking prescribed medications or complying with treatment.
FIGURE 3-8 A medical assistant listening to the patient and physician discuss the patient’s care.
**PROFESSIONALISM
Telling the truth is one of the most important parts of being a medical professional. Every human makes mistakes; it is part of being human. However, the most important thing any professional can do is admit having made a mistake and seek to correct it. Do not offer extra information to the patient. You should only state that there is a correction to be made. Be sure to speak with the supervising physician, and document clearly in the chart the mistake that was made and how it was corrected. Honesty goes a very long way in preventing litigation and providing good, quality care to all patients. Be sure to notify the physician if there is a task you are not proficient to do. For example, if you did a procedure early in your training but have not done it for a long time, you need to notify the physician rather than perform the task without proficiency. Veracity, or speaking the truth at all times, is a professional quality that all medical assistants must have.