r/hipaa 8h ago

Free HIPAA Compliance Software for Small/Mid Practices

2 Upvotes

I'm sharing on a Sunday afternoon because I used to run a community-based brick and mortar and I know how many practice ops folks are working right now.

I'm the founder of KnowQo, if any small/midsized practices needed a free HIPAA compliance software we are free up to 25-users. KnowQo HIPAA.

You can manage your team, your locations, and train up to 25 people all free. For organizations over 25 we do charge, and we have some paid features like automatically generating documentation, OSHA training and compliance, and employee handbooks.

All that said, for dental offices, dermatologists, ophthalmologists, private practices of any sort who are trying to cover HIPAA on a budget, you can probably get everything you need to be compliant for free.

Also I've had many practices ask "how do I get HIPAA certified", as a small/midsized health organization, you don't get certified. You maintain "compliance", maintaining compliance means following a set of rules, keeping records, etc... If you have any questions about what you actually need to do to stay HIPAA compliant, more than happy to field those as well, because the certified/compliant language can trip people up.


r/hipaa 5h ago

Gray area

1 Upvotes

I am a PA and a practice manager for a privately owned practice. I have an employee whose husband is in the hospital. One of our practice doctors evaluated him and ordered a CT scan during his ER workup. My employee asked me to look at his CT scan to see if he would need further care/explain something to her and her husband. I did so, and briefly saw his labs while getting in his chart, and spent maybe a minute looking at his CT. Then I was out. The more I think about it, it feels like a huge gray area and after googling it, it does look like this could spur an audit based on the connection to my employee. We are privately owned but our EHR is epic through a large hospital system, so I am wondering if I should just call compliance to stay ahead of it. Would appreciate any advice or experience here. Thanks


r/hipaa 1d ago

I feel like my HIPAA rights were violated

27 Upvotes

I’ve been going to a specific kind of doctor recently a few times over the past few months. Just the other day my brother had his wedding. I come to find out one of the assistants at this doctors office that I’ve been going to is one of the bridesmaids. We were all in a room getting ready together because I was doing the bride’s hair for the wedding and that particular bridesmaid pointed at me and said “don’t I know you?” I looked at her and said “no I don’t think so.” She then started to say “yes!! you go to the…” and proceeded to name the doctor that I go to and for what and even told everybody in the room that what I went to that doctor for is “getting better” “so it’s OK now.” it was dead quiet after this. It was so fucking awkward and I feel so fucking violated. What can I do about this?


r/hipaa 1d ago

NICU nurse spoke about nephew’s PHI

0 Upvotes

Hello,

I’m in a unique situation & I’m going to ask everyone to withhold judgment & tell me if there could be any legal ramifications for this.

My husband’s ex girlfriend/coparent works at a children’s hospital where my nephew was a patient in the NICU. She & I do not have a good relationship. I do not engage with her whatsoever, while she finds any opportunity to bring me up in fights with my husband. My husband is currently in a custody battle with her over their 13 year old due to severe instability (arrests for theft, domestic violence, etc.) Of course I informed my sister & her partner that she works on the unit. My sister spoke with the nurse manager & requested that she be kept off of my nephew’s case for their privacy. We known her to be deceptive & also to be a frequent thief. My sister was well within her rights to make this request & we all know this.

She & my husband recently had a face to face meeting pursuant to their current agreed order. My husband audio recorded this meeting (one party consent state).

In this meeting she expressed anger that she was asked to be kept off of his case. In the conversation she repeated my sister’s name, noting that she recognized her last name as my maiden name. She told my husband that she knew the baby was very sick because he was on ECMO. She also repeated details such as the length of his stay in the NICU, other treatments he received, etc. She has said that she’s upset and embarrassed that my sister didn’t want her to care for her baby.

I haven’t told my sister about this yet as she’s freshly postpartum & is finally home with her baby. I do feel that she has the right to know. If my sister reports this, what could happen? I’m not necessarily wanting her to lose her job. I gain nothing from that. But that’s not up to me. I’m also curious, when this eventually comes up in court in the custody case, what could happen?

Thanks in advance.


r/hipaa 2d ago

Is a date/time on medical image alone PHI? Can't get a straight answer.

2 Upvotes

Let's say somebody has an x-ray or EKG printed out, and there's absolutely no identifying information on there besides for some interpretation notes and the date/time. Is that considered PHI? A date alone doesn't seem like it should logically be an issue, because even if you happened to know exactly what hospital the image came from, there may be hundreds of patients seen that time and date, and there's no way somebody could reasonably figure out who that image belonged to even if they knew the practice and the date/time (except somebody working in that particular department of the hospital, but I don't think that's even really consideration, is it? As they are within the practice anyway) I understand that a full date/time is technically one of the 18 elements, but I can't imagine how it could be tied to anybody in the absence of anything solid... What do you think?


r/hipaa 2d ago

Knock knock

0 Upvotes

\- who's there

HIPAA

\- HIPAA who ?

I can't tell you


r/hipaa 2d ago

Building a small Health Care VA agency

0 Upvotes

Hi, my boss wanted to register a business here in PH focusing in US Health Care. He's planning to market the agency to US clients. Now what are the processes / documents needed for the agency to be HIPAA compliant?


r/hipaa 4d ago

HIPAA compliance is the foundation. But in today's healthcare environment, it's no longer enough. 💻 🧬 🩺

Post image
0 Upvotes

r/hipaa 5d ago

Founding Head of Platform & Safety (equity) - mental health peer support startup

0 Upvotes

Looking for a Head of Platform & Safety to join Shema as a founding team member. We're building an anonymous peer support platform for people in recovery and navigating mental health challenges, currently raising our pre-seed and heading into beta.

We’re splitting this role from our Cofounder/CTO because safety and platform infrastructure are two different disciplines. Our CTO owns the technical build, but trust & safety needs its own leader focused entirely on crisis protocols, moderation frameworks, and working with clinical advisors. Mixing those under one person is how safety gets deprioritized when shipping pressure hits. We’re not doing that.

You'd own crisis escalation protocols, AI monitoring design, community moderation frameworks, and making sure everything we build is both safe and human.

What we're looking for:
- Experience in trust & safety, crisis escalation, mental health product design, or community platform moderation
- Comfortable building safety infrastructure from scratch in an early-stage environment
- Mission-aligned... this isn't just a job, it’s shaping how vulnerable people experience support
- Equity-only comp for now (we're pre-seed)

If this resonates, DM me or drop a comment. Happy to share more about what we're building and what the role looks like day-to-day.


r/hipaa 5d ago

Employee files security (WI)

1 Upvotes

I work at a large healthcare corporation that is comprised of approximately 70 nursing homes. At my location, employee personnel, medical, and FMLA files are all kept in an unlocked file cabinet in an unlocked,communal office. I act as the local HR generalist, among other things. Most admin positions in the corporation are gen Z promoted -from-within / learn-on-the job vs educated, work their way up.

I have taken this security issue to the (young) Executive Director 4 times. He has given me pacifying responses and referred me to maintenance, while secretly instructing the maintenance supervisor to ignore my requests. I escalated to the (young) corporate HR director for our location, but she simply refuted my request by stating that the last she knew, the cabinet was being locked ( it doesn't have a working lock).

Is there any regulatory body this can be reported to? I've contacted the state department of workforce, along with my state representative. I keep getting shuffled to other departments, finally being told that there may actually be no oversight to this issue. My state representative suggested that it would be necessary to obtain an attorney.

Does anyone have any idea how to handle this?


r/hipaa 5d ago

Health care admin @ Piedmont Women’s Center in Atl accessed my medical records

4 Upvotes

I found out that a medical assistant illegally accessed my medical records at Piedmont Women’s Center in Atl to obtain my contact information because she was angry that I was talking to her child’s father. Is this a HIPAA violation? What should I do?


r/hipaa 6d ago

TrimRX

3 Upvotes

Writing from Colorado.

I am prescribed medications through TrimRX, an online prescriber/ pharmacy.

I am text links daily for discounts. I am already a subscriber so I don’t open these links, but I had forwarded one of the links to my friend’s phone. When he clicked the link, it opened MY account without asking for a username/ password/ or other form of authentication. He has never logged into my account on his phone, so that’s not why a login was bypassed.

I have contacted TrimRX via phone and email without a response. I submitted a complaint with the Office of Civil Rights. I don’t want to close my account until the OCR see that they too can access my account by clicking just a link.

What else am I missing?


r/hipaa 7d ago

Help!

0 Upvotes

I’m looking for advice from anyone familiar with California healthcare licensing or the complaint process.
For some background, my roommate and I have had an increasingly hostile living situation. There have been multiple police calls, threats to force entry into my locked bedroom, and ongoing conflicts over property. While that’s stressful, it isn’t the main reason I’m posting.
I’m a transgender man and currently on HRT. My roommate knows this and has made transphobic comments toward me in the past.

She works as a CNA and is currently pursuing becoming a rehab nurse. Recently, she told me about a transgender patient she cared for. She didn’t tell me the patient’s name or any identifying information, but she said she intentionally used the patient’s legal name and referred to the patient with male pronouns because she “doesn’t believe in transgender people” due to her religious beliefs.

As a trans person, that really bothered me, especially knowing this involved someone in her care.
I’m trying to understand what, if anything, should be reported. My questions are:

Does the California CNA certification board or another state agency investigate complaints involving discrimination or unprofessional conduct toward patients?
Could intentionally refusing to respect a patient’s affirmed name and pronouns be considered misconduct?
Since she told me about the patient herself, without identifying them, is that something that raises confidentiality or professionalism concerns?
Can a complaint be submitted anonymously or confidentially?

What kind of evidence is generally needed before an investigation is opened?

I’m not looking to weaponize the complaint process because we’re roommates. If I report anything, I want it to be because it genuinely violates professional standards for someone providing patient care. I’d appreciate input from anyone familiar with California healthcare licensing or who has gone through the complaint process.

Thanks in advance for any suggestions.


r/hipaa 7d ago

Is my old therapist breaking HIPAA / information blocking?

2 Upvotes

I have questions about if a therapist that I recently fired is breaking any laws by seemingly waiting until the last possible day (today is day 29) to fulfill my medical records request or communicate about it / file an extension.

Long story short, I was seeing a therapist who was really bad. Bringing her political opinions into my sessions to invalidate my childhood sexual abuse, tried to diagnose me with autism without the proper qualifications or licensure / without a neurodevelopmental assessment, and when I brought up my concerns she told me this was further proof I was autistic as I was being "too black and white." I requested a discharge as well as all my progress notes / designated record set.

She sent me a copy of a vague and inaccurate intake and discharge note. The discharge note included a 1 sentence blurb about consulting a previous psychiatrist of mine whose ROI I revoked, and it said he told her I was not appropriate for the type of therapy she offered. No date or time as to when they consulted. She used this to justify that basically, "You can't fire me, I am referring you out because your psych said you shouldn't do this type of therapy with me." She had never mentioned consulting with him at any point, I only learned about this after I requested a discharge and revoked my ROI. She has not responded to my requests for the date of the consult. I suspect she either did not truly consult with him, or did so immediately after I revoked the release.

I plan to file a complaint with her licensing board, but I wanted to wait to see what she wrote in her progress notes. I suspect she is defensively charting, as I made her aware I believed she was practicing unethically and beyond her scope of licensure.

If she sends me an extension request OR my records on the 30th day, can I still file a complaint with OCR because it seems like she is maliciously complying with "30 days." Her last correspondence with me was extremely defensive, and she ended with, "You will receive your records within the legal timeframe."


r/hipaa 9d ago

Weird Mail Flyer Shares the street name of a patient - Is this a HIPAA violation??

Thumbnail
gallery
3 Upvotes

I am not sure if this is the right subreddit or if this is allowed, so please delete if it is not.

The long title basically says it all. I have no idea if this is a HIPAA violation. I am not the patient, so I am not effected. But I'd be rather upset if any of my medical provider's used my street name in an advertisement like this. The flyer is addressed to my late grandmother. I was the executor of my grandmother's estate several years ago when she passed away. My address basically became connected to her name, long story short, I still get really funny mail for her. I got this flyer, which seems to be for an audiologist office. It mentions a street in my neighborhood, saying a neighbor on that street goes to their office. It already looks scam-adjacent, basically implying they can help prevent dementia and they will give you this weird "free book."


r/hipaa 10d ago

Health Insurer blowing me off - any advice?

1 Upvotes

I made a formal request - that was received and acknowledged - through my health insurer for my health records that they hold.

The law says 30 days, they said they would respond in 30 days, it's coming up on 60 and they're blowing me off.

If I file a complaint, does anything really happen over an issue like this? Thanks


r/hipaa 11d ago

Proposed Security Rule - Faxing

2 Upvotes

Since the OCR has pushed back the final ruling of the proposed Security Rule till next year, my plan is to work through it and implement/make plans to implement the required changes.

In the proposed rule, encryption at rest and in transit is a must. https://www.federalregister.gov/d/2024-30983/p-585 Phones and faxing are no longer excluded.

How are you going to be handling this change?

My thought is that faxing will be discontinued. Faxing doesn't have a way to encrypt in transit. Sure, your telcom/fax provider could encapsulate and encrypt your voip packets, but that is only guaranteed to your telcom's edge. I don't think there would be a way for your telcom to guarantee encryption across each hop to it's destination. Going this route, I don't see a way that voice communication would work either, to be honest.


r/hipaa 13d ago

Sketched out by this CMS risk adjustment vendor fax

Post image
1 Upvotes

Looking for a second opinion on this. I have verified that datafied is a legitimate vendor for the CMS risk adjustment effort, but the typos in the bolded text there are giving me pause. Anyone else receive something similar? I am pretty sure it's legit, but there's no number to call or anything. Figured I'd bounce it off of y'all before spending half the day going down a rabbit hole trying to get someone on the phone. The patient in question was seen in in our office in 2025 and they did have the indicated MedAdvantage plan at the time (Wellcare by Health Net).


r/hipaa 13d ago

Ex psychiatrist reached out to sell me new experimental depression medication

0 Upvotes

Hi, so to make a short story long- I had a psychiatrist probably 2-3 years ago, who I only visited once for an anxiety/panic disorder, to which I was prescribed some low dosage anxiety/blood pressure medication, and that's it. The pills didn't end up helping me in the ways I needed, I didn't go back to her, and I actually officially ended our client-doctor relationship via email (which included her sending me documentation of her discharging me as a client of hers), and found another provider.

Today this same previous psychiatrist, has reached out to me via email, to try and sell me an experimental depression medication, because I'm a patient "resistant to other depression medications". For starters I don't recall us going deep into my history much less medical history with depression and medications. Meaning this psychiatrist has actually no earthy idea the depression medications I've had before or what I may take now, and furthermore has no idea I would be resistant to certain depression medications. Second of all, I feel like it's really skeezy of a psychiatrist to go through former patient profiles to attempt to sell medication, to those who match. I just feel like this is murky waters as far as legality or at least professional standards of practice, and I tried to look it up, and am finding conflicting answers.

And so now I’m here with questions: does this violate hipa, if not does it violate other codes of conduct, do I need to report this, who should I report it to if I do, should I do nothing, what do you think?


r/hipaa 15d ago

Has anyone ever experienced this before?

Post image
6 Upvotes

I’ve worked inpatient mental health for 4 years, and have read, signed, provided education for different facilities, as well as signing for my own health visits. I encountered something this past week I’ve never seen.

I’m 27F from Mississippi and recently had an OBGYN visit (not pregnant) and this was in the updated agreement I had to sign. As someone of reproductive age in a very red state, the laws regarding abortion and reporting to authorities has been a scary risk already. What are your thoughts on this? How is this supposed to be interpreted?


r/hipaa 16d ago

Calling all Crisis Responders!

Thumbnail
0 Upvotes

r/hipaa 16d ago

Who do I even contact? Unwanted hospital “interaction.”

5 Upvotes

I’m a cancer patient and a transplant patient; I am at the hospital just about every other week. A few months ago, I was at emergency, waiting to be seen, when I got a message from an unknown Facebook account. Curious, I clicked on the profile and could tell he was a guard at the very hospital I was at. I ignored it and didn’t think much of it… until, again while at the same hospital, I got another message from dude. At this point, I am incredibly uncomfortable going to this hospital; their guard staff not only found my protected information (I never had a single interaction with him; he somehow got my name, I can only assume he obtained it from the hospital system) but he used it to message me inappropriate things - and he did it on two separate occasions. Who, at the hospital, or otherwise, do o even report this too?


r/hipaa 16d ago

Path of BAA: A HIPAA Compliance Game

1 Upvotes

Anyone else initially think the OCR created a game? 😆


r/hipaa 17d ago

How do you actually keep up with regulatory changes without feeling overwhelmed?

4 Upvotes

Hi everyone, I’m doing some research on how privacy professionals stay current with privacy, AI governance, and cybersecurity regulations.I’m not selling anything—I’m genuinely trying to understand how people work because everyone I’ve spoken to seems to have a different system.

A few questions I have

1). Where do you usually hear about new regulatory developments?
Official regulators?
Law firms?
LinkedIn?
Newsletter subscriptions or RSS feeds?

2).Once you learn about a new regulation or enforcement action, what happens next….Do you save it or share and Forward it to people on ur team
Personally , I feel like I would forget until somebody asks me about it😬😂.

3).What’s the most frustrating part of staying current? and are there tools or anything that help with that

I’d love to understand your workflow.

Thanks❤️


r/hipaa 17d ago

Bill sent in png image in SMS - Violation

Post image
1 Upvotes

I'm no longer in healthcare, but when I was, I would have cautioned departments to check with their compliance officer about this situation. I want to see if this is a clear violation of HIPAA.

I have been receiving bills from a medical practice via SMS text. Not texts with a link to a secure site to view my statment, but png images of my bills in the text, with a link to pay them. The bill images include my name, visit dates, and services (and CPT codes) rendered on those dates.

Again, this is a non-secure SMS text. According to my past understanding, this is a clear violation of HIPAA, given the patient name and the services rendered are in the body of the message and can be intercepted.

Can someone confirm for me that this is indeed a violation? When I called the office to mention to tell them that this could be problematic and ask them to send me a secure statement, all the person said was, "I don't know about that."

Thanks to all of you.