At this point, HIPAA-covered providers know that they are required to keep patients’ protected health information (PHI) private and secure. What they may not know is that they also are required to maintain a HIPAA-compliant breach notification policy in the office and to notify patients if a breach occurs.
In an ideal world, all PHI would be perfectly safe, sound and accessible only by appropriate parties. The writers of the HIPAA rules realized that, even with protective measures in place, PHI is managed by imperfect, albeit well-meaning, human beings. Even with the best of efforts, the privacy and security of PHI may be breached occasionally. HIPAA requires providers to implement protective procedures and to follow notification requirements when a breach occurs.
Keep reading with an ICS membership
This in-depth guidance is reserved for ICS members. Join the Illinois Chiropractic Society for full access to every article, CEU, compliance tool, and advocacy update.
















