Domain 12.3Medical Law and Ethics

Health Info Management Privacy

Last updated June 16, 2026

Overview

As a Medical Assistant, you are a custodian of your patients' most private information. The medical record is a legal document, and how you handle, maintain, and protect it is governed by strict federal laws, primarily HIPAA. This guide merges the concepts of record management (retention/ownership) with the laws of privacy and confidentiality.


1. Ownership of the Medical Record

This is a frequently tested concept with a crucial distinction.

What is it? Who legally owns it? Explanation
The Physical Record The Facility/Physician The facility owns the paper, folder, or server where the data lives.
The Health Information The Patient The patient owns the "story" and has the right to access, inspect, and copy the information.

2. HIPAA: The Law of the Land

The Health Insurance Portability and Accountability Act (HIPAA) is the primary federal law governing patient privacy. The act is divided into sections known as "Titles."

  • Title I: Focuses on Health Care Access, Portability, and Renewability (protecting insurance coverage when changing jobs).
  • Title II (Administrative Simplification): Focuses on preventing fraud and protecting privacy. This is the section that created the Privacy and Security Rules.

Memory Aid: Title II is about Information (Privacy and Security). Think: "Title II is for Me and You."

A. The Privacy Rule (Protects PHI)

  • Protected Health Information (PHI): Any info that identifies a patient (Name, DOB, SSN, Address, Photos) + Health Data.
  • Scope: Protects PHI in ALL forms (Paper, Oral, Electronic).
  • Required Document: Notice of Privacy Practices (NPP): Facilities are legally required to provide patients with a written notice explaining how their medical information will be used and disclosed. Patients must usually sign a form acknowledging they have received this notice.

B. The Security Rule (Protects e-PHI)

  • Scope: Specifically protects Electronic PHI.
  • Safeguards: Requires Administrative (training), Physical (locks), and Technical (passwords/encryption) safeguards.
  • Role-Based Access Control (RBAC): This is the most effective technical safeguard. It involves restricting access to information based on the user's job function.
    • Key Concept: "Need to Know." A billing specialist should not have access to clinical notes they do not need to do their job; a nurse should not access the billing history unless necessary. Users should only see data required for their specific role.

C. Permitted Disclosures: The "TPO" Rule

HIPAA allows providers to share PHI without patient authorization for three specific reasons:

  • T - Treatment: Sharing with specialists or labs to coordinate care.
  • P - Payment: Sharing with insurance to get paid.
  • O - Operations: Internal audits, training, and legal activities.

Memory Aid: You Treat, you bill for Payment, you run Operations. These do NOT need a signed release.

Important Note on Billing Forms (Assignment of Benefits): While HIPAA allows sharing for payment, most offices still require a specific financial form called the Assignment of Benefits. This form authorizes the insurance company to pay the provider directly. In exam scenarios asking what form is needed before discussing a specific claim with an insurer, look for Assignment of Benefits or a specific Release of Information for billing if the question implies a dispute or third-party involvement outside standard TPO.


3. Release of Information (ROI) and Consent

For nearly all disclosures outside of TPO (e.g., to an attorney, employer, or school), you must have a patient's signed Authorization or Release of Information (ROI) form.

  • The ROI must be specific: It must name the entity receiving the info and exactly what info is to be released.
  • The Patient is the Gatekeeper: A spouse or family member does not have automatic access to an adult patient's records.

The Doctrine of Professional Discretion

While patients have a right to their records, there is a key exception known as Professional Discretion.

  • Definition: A provider can legally withhold a patient's medical record if they reasonably believe that releasing the information would cause significant harm to the patient or others.
  • Example: A provider might withhold psychiatric notes if reading them could trigger a mental health crisis for the patient.

4. Health Information Exchange (HIE)

The Office of the National Coordinator for Health Information Technology (ONC) supports the electronic sharing of health data to improve care. You should know the three main HIE models:

HIE Model Description Key Feature
Directed Exchange Securely sending info directly to another professional (e.g., referrals, discharge summaries). Like secure email; Provider-to-Provider.
Query-Based Exchange Providers search/query for info on a patient from other sources (e.g., ER doctor looking up a patient's meds). Unplanned care; Provider searches for data.
Consumer-Mediated Exchange Patients aggregate and control the use of their own health information. Patient-Controlled; the patient mediates access.

Exam Tip: If the question asks about a model giving patients direct authority/control over their data, the answer is Consumer-Mediated Exchange.


5. Privacy Safeguards in the Office

Verbal & Physical Privacy

  • Private Info, Private Office: Discuss PHI in secure areas, not the waiting room.
  • Sign-In Sheets: It is okay to ask for Name and Arrival Time, but NEVER the reason for the visit.
  • Screens: Turn computer monitors away from public view.

Electronic Communication (Fax & Email)

  • Faxing: Always use a cover sheet with a confidentiality statement. Double-check the number.
  • Email: Standard email is not secure. You need written patient consent to use it. Secure Patient Portals are preferred.
  • Passwords: Every user needs a unique login. Never share passwords. Change passwords regularly (e.g., annually or quarterly).

Telehealth Privacy Safeguards

Treat a telehealth consultation just like an exam in a physical room.

  • Secure Environment: Ensure the conversation takes place in a private, secure location where others cannot overhear or view the screen.
  • Patient Verification: Always verify the patient's identity at the start of the call.
  • Awareness: Be aware of your surroundings (and the patient's) to prevent unauthorized disclosure of EKG results or other sensitive data.

6. Record Maintenance: Retention and Correction

A. Retention (How long to keep records)

Requirements vary by state, but follow the stricter rule.

  • Adults: Typically 7-10 years.
  • Minors: Age of majority + statute of limitations.
  • Immunization Records: PERMANENTLY. (High-Yield Exam Fact).

B. Correcting Errors (The SLIDE Method)

Never erase, obliterate, or use White-Out on a medical record. It looks like a cover-up.

The Legal Way to Correct a Paper Record:

  1. Single Line through the error.
  2. Initial.
  3. Date.
  4. Error (Write "Error" or "Err" and the correct data).

Note: In an EHR, you make an addendum. The system tracks the change automatically.


7. Legal Requests and Disposal

Subpoena Duces Tecum

A court order requiring a witness to appear in court and bring physical evidence (the medical records).

  • Memory Aid: "Duces Tecum" = "Bring with you" -> "Docs you take 'em."

Proper Disposal

Records must be destroyed in a way that preserves confidentiality (HIPAA).

  • Paper: Shredding, burning, pulping.
  • Electronic: Degaussing, wiping, physical destruction of drives.
  • Trash: Never throw PHI in the regular trash.

8. Final Key Takeaways

  • HIPAA Title II = The section containing the Privacy Rule (Info protection).
  • Notice of Privacy Practices (NPP) = The document patients must receive describing their rights.
  • HIPAA Privacy Rule = All forms of PHI. Security Rule = Electronic PHI.
  • Role-Based Access = Restricting EHR access based on job function (Need to Know).
  • Telehealth Privacy = Must occur in a private, secure location.
  • Consumer-Mediated Exchange = Patient controls their own health data sharing.
  • Professional Discretion = Provider can withhold records if harmful.
  • TPO (Treatment, Payment, Operations) = No authorization needed, though Assignment of Benefits is used for billing.
  • ROI = Required for attorneys, employers, etc.
  • Ownership = Facility owns the paper; Patient owns the info.
  • Immunizations = Kept Permanently.
  • Correction = Single line, Initial, Date, Error (SLIDE). No White-Out.
  • Subpoena Duces Tecum = Court order to bring records.