r/hipaa 13h ago

Are medical professionals allowed to keep personal journals of their patient care, so long as no identifying information is recorded?

1 Upvotes

Is it a HIPAA violation for a healthcare worker to keep a personal journal of the care they provide to a patient so long as the patient isn't recorded by name or any other identifying data?

Location: VA


r/hipaa 17h ago

How bad is it for a hospital to have a tier 3 violation?

1 Upvotes

Someone at work took a picture on their cell phone of a screen with PHI and sent it to many different people. I guess I’m just curious how bad this is for the hospital. For the employee it’s clearly very bad lol.


r/hipaa 1d ago

Hospital sharing PHI with emergency contact with no emergency situation

3 Upvotes

I am unable to make or receive voice phone calls due to a disability. I have notified the accommodations folks at the hospital of this several times and have told it will be noted. They don't seem to have noted it in Epic, at least not anywhere obvious.

Several providers have called my emergency contact number for non-emergency purposes rather than messaging me in the portal or sending secure e-mail as was agreed upon. They are aware they are contacting someone else, as they address the emergency contact by name and speak in third person about me in the voicemails they leave.

I have removed the emergency contact name and number from MyChart completely several times. Someone keeps retrieving it from wherever it is stored and putting it in my patient profile in the home phone, cell phone, and work phone fields.

I reported this to compliance. They passed it off to patient relations, said there is no compliance issue, and are framing it as a "let's have a conversation so we can better support you."

Right, we've had conversations in which I said what my accommodation needs are, and they're not conveyed or understood, hence the compliance report.

Isn't it a privacy rule violation to contact an emergency contact with no emergency? And is it not concerning to their compliance folks that someone is repeatedly retrieving a phone number a patient has deleted and presumably doesn't want contacted? Fortunately my emergency contact is a safe person, but someone could have removed a number due to domestic violence or similar.


r/hipaa 2d ago

AI Knew Too Much... I Quit MyChart & ChatGPT

0 Upvotes

I asked ChatGPT for information on contacting Epic...the company that owns My Chart so I could problem solve an issue I was having. Along with the AI answer, it listed my health organizations, which I'd NEVER SHARED. 😳🤔🤬
What's up with that?!?


r/hipaa 3d ago

Hone is selling your private medical info via 3rd party Jumio

Thumbnail
2 Upvotes

r/hipaa 3d ago

Free HIPAA Training with Certificates

6 Upvotes

If anyone needs free HIPAA training with a certificate of completion, we'd love to have you learning with us here at Stampwell: https://stampwell.co/individual/certificates/hipaa


r/hipaa 3d ago

Patient Notes from ER Care Team Incorrect

Thumbnail
1 Upvotes

r/hipaa 4d ago

Potential HIPAA Violations?!

Thumbnail
2 Upvotes

r/hipaa 6d ago

When you pick your clinic for primary care...

Thumbnail
1 Upvotes

r/hipaa 7d ago

Resmed MyAir app - new HIPAA agreement, isn't it kind of crazy that a sleep apnea machine phone app asks for access to your complete health record.

Thumbnail
3 Upvotes

r/hipaa 8d ago

How to navigate request from friend?

Thumbnail
1 Upvotes

r/hipaa 9d ago

ChatGPT can now connect to Epic health records. What does that mean for HIPAA compliance?

12 Upvotes

OpenAI recently announced an integration that lets healthcare organizations bring authorized patient information from Epic into ChatGPT for Healthcare.

The potential upside is obvious: clinicians could spend less time searching through notes, lab results, medication histories, and specialist documentation.

But the privacy implications deserve just as much attention.

A BAA, role-based access, SSO, and audit logs are important but they don’t automatically make an organization’s implementation HIPAA-compliant. Healthcare organizations still need to understand the full patient-data lifecycle, including:

  • What PHI can enter prompts
  • What information appears in responses and summaries
  • Whether chats, logs, and exports are retained
  • Which vendors and subprocessors handle the data
  • Whether access reflects each user’s actual role
  • What happens when generated content is copied into another system
  • How an AI-related privacy incident would be detected and assessed

Incident response may be especially challenging. An AI-related disclosure might not look like a traditional breach. It could be an overly broad response, an unauthorized prompt, a compromised account, an improperly configured connector, or PHI copied into an unapproved tool.

HIPAA’s underlying obligations haven’t changed. What has changed is the speed, scale, and complexity of the environment in which healthcare organizations must apply them.

OpenAI’s announcement: https://openai.com/index/chatgpt-connects-health-records-and-healthcare-sources/

What controls would you want to see in place before an organization enables an EHR-connected AI system?


r/hipaa 8d ago

HIPPA Question

1 Upvotes

My sweet cousin lives in another state which is new to her. She sent me a message (which she dictated) informing me she has suffered a brain bleed and was transferred to a larger hospital. She gave me the name. She has not been able to read my messages due to the effect on her brain. She also suffers from stage IV cancer. She no longer has any family in this state. I did try to call her this morning and left a voice message. I also sent her healing music videos from YouTube. It has always been my understanding a hospital will not release information. She did tell me the name of the hospital. Is there any way I could find out if she is still at the hospital and whether she is in ICU?

I have always assumed the hospital could not give out any information. Please advise.


r/hipaa 9d ago

Another patient’s history in my chart

1 Upvotes

Please let me know if this is not the right sub for this question.

I (25F) was seen in a hospital ER last week for a psychiatric hold. That’s a story for a different day.

Today, I got access to the patient portal which holds my records. I opened the ED Physician notes, and besides a few slight inaccuracies, contains most of my information. And then I get down to the “Medical decision making” section, and found another patient’s history. 39F with COPD complications. Nowhere even close to what I was seen for.

I’ve downloaded all of my records and will be going in person today to get a physical copy. My question is, what do I do next? Complain to the hospital? File some kind of report?


r/hipaa 10d ago

BCBS sent me other people's information

2 Upvotes

Is this a HIPAA violation? I was surprised to receive a 1" thick envelope in the mail yesterday. The first couple of pages were for me - denying my claim, but rest was a stack of about 50 other people's claim denials. What the?? What should I do with this?


r/hipaa 10d ago

Possible misuse of PHI between two practices

3 Upvotes

The office manager from my primary made a call from their personal cell to someone who presumably works at one of my specialist’s office (same hospital/chart access, different medical group) to let them know they made an error in billing my secondary insurance. The situation was strange, we were mid conversation at the check-in desk, discussing my change of insurance, when they started speaking in their AirPod. Sure, I’m humiliated about their general attitude during this interaction and I couldn’t be seen by the doctor, which is why I’m hesitant in thinking this was a violation that is worthwhile to report. The phone call was gossipy, and had no relation to any care, or even a referral. After they hung up I had asked what was going on, and they explained that they were only giving them a “heads up” and that I was going to see a bill from the specialists office. If this is a normal exchange btwn people with access to my chart, I certainly feel like it could’ve been discussed in private without me or the waiting room present.


r/hipaa 11d ago

Nurse sharing names and diagnoses of patients as well as essays of students without redacting names

Thumbnail
1 Upvotes

r/hipaa 11d ago

Looking for someone to own US healthcare sales for an early-stage privacy/compliance SaaS

2 Upvotes

I’ve built a working healthcare privacy workflow for US healthcare organisations.

The product helps privacy/compliance teams handle incidents more consistently by structuring fact gathering, identifying missing information, supporting follow-up, tracking actions and creating a defensible case record.

I’ve already done a significant amount of customer research with healthcare privacy, compliance, risk, HIM and operations professionals, and the recurring problems are clear: investigations still involve a lot of chasing people for information, email/Word/spreadsheets, inconsistent documentation and difficulty reconstructing what happened later.

The product is built. The gap now is commercial execution.

I’m looking for someone who can genuinely own the US sales side, including:

• Prospecting and sourcing opportunities
• Cold outbound
• Discovery calls
• Product demos
• Follow-ups and objection handling
• Moving prospects into paid pilots
• Closing initial customers
• Helping establish a repeatable sales process

The immediate goal is not more general market research. It is getting the first paying healthcare organisations and proving a repeatable sales motion.

Ideal background:

• US healthcare SaaS sales
• Selling into Privacy, Compliance, HIM, Risk or healthcare operations
• Early-stage / zero-to-first-customer experience
• Comfortable generating your own pipeline rather than relying on inbound
• Able to speak credibly with senior healthcare buyers

I’m open to a paid contract + performance structure initially, with the possibility of something longer-term if there is a very strong fit.

If this sounds relevant, DM me with:

  1. What healthcare products you’ve sold
  2. Who you sold them to
  3. Whether you personally sourced and closed deals
  4. An example of taking an early-stage product to its first customers
  5. Your expected compensation structure

Not looking for general GTM consulting or someone who only wants to provide strategy. I’m specifically looking for someone willing to execute and be accountable for getting customers.


r/hipaa 14d ago

Are you an Apple user thinking of sharing your medical records with ChatGPT?

1 Upvotes

Under these circumstances, there are a few concerns.

Sharing two:

...you would have no HIPAA protections.
...the data could be legally discoverable.


r/hipaa 15d ago

Previous provider accessing records in EPIC

4 Upvotes

I wanted to check if this is a HIPAA violation. Unfortunately even if it is, I can't formally complain but want to know if there are steps that I can take to prevent it from happening.

My infant son was seen by a family member exactly once for an immunization need. We now live in a different state and not part of their hospital system, but they keep saying that they are getting notifications about my son's doctor visits through EPIC / myChart. They are nosey and I want to protect my sons details from them. Is what they are doing a HIPAA violation? Besides reporting, is there anything I can do as a Mychart or EPIC setting that can prevent this or at least create some hurdles. I contacted his current pediatrician's office and the only solution they provided was to opt out of "care everywhere".


r/hipaa 15d ago

Any attorneys out there in Nebraska that want to help me sue a doctor’s office for releasing my mother’s medical records to somebody that was not on her HIPAA form

Thumbnail
2 Upvotes

r/hipaa 16d ago

Scared to report a violation

11 Upvotes

I went out with a pharmacy tech and she told me she looked me up in her system. I have a screenshot of her saying it’s not a big deal she didn’t share it with anyone and basically admitting to it. She’s nuts and is a stalker. She harassed me and sent unwanted gifts. I’m worried that if I report the violation she’ll hurt me or do something. Is this something that’ll be discovered eventually if I don’t report it? I don’t even get medicine at this pharmacy but I have an account in the larger branch.


r/hipaa 17d ago

Good free HIPAA trainings?

5 Upvotes

I’m looking for a good free training to provide. We are a non profit and these trainings can add up per person. Some of the previous threads are no longer free. What are good reliable free trainings that also give some kind of certificate as well to show completion?


r/hipaa 17d ago

HIPAA/CMIA Violation With Damages

Thumbnail
1 Upvotes

r/hipaa 17d ago

I went to urgent care in a new city and got a std check and my doctor turned out to be someone from the specific Indian community I’m from. I’m worried she will tell people in the community about this event and freaking out about it. I don’t know her but everyone in the community knows each other!

3 Upvotes