# Was this a HIPAA/patient confidentiality violation?

**URL:** https://boards.straightdope.com/t/was-this-a-hipaa-patient-confidentiality-violation/331421
**Category:** In My Humble Opinion
**Created:** [November 17, 2005, 1:13am UTC](https://boards.straightdope.com/t/was-this-a-hipaa-patient-confidentiality-violation/331421 "2005-11-17T01:13:45Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![rostfrei](https://avatars.discourse-cdn.com/v4/letter/r/7bcc69/32.png) [@rostfrei](https://boards.straightdope.com/u/rostfrei)
#### Post date: [November 17, 2005, 1:13am UTC](https://boards.straightdope.com/t/was-this-a-hipaa-patient-confidentiality-violation/331421/1 "2005-11-17T01:13:45Z")

</div>

Here is the situation. I work in a hospital, a very large hospital. I went to Payroll a few weeks ago to pick up my paycheck and my co-worker asked me if I would pick up hers too. I said I would and she wrote me a note giving me permission to do this.

When I got there, I got my check and then presented the note for my co-workers check. The lady at payroll read the note and then looked on the back and began to admonish me because the note was written on the back on some type of patient form, with a patients name on it. The lady said that this was a clear HIPAA violation and broke many patient confidentiality rules. I can kind of see that, but I think she over reacted. She said she would over look this, but if it happened again, she would notify the “proper people”. LOL.

I was under the impression that the object of patient confidentiality was to prevent people from outside the institution from knowing patient details, etc…not from someone who actually works in the hospital.

Was this a breach of patient confidentiality/HIPAA?

---

<div class="post-metadata">

### Author: ![Shagnasty](https://avatars.discourse-cdn.com/v4/letter/s/9dc877/32.png) [@Shagnasty](https://boards.straightdope.com/u/Shagnasty)
#### Post date: [November 17, 2005, 1:22am UTC](https://boards.straightdope.com/t/was-this-a-hipaa-patient-confidentiality-violation/331421/2 "2005-11-17T01:22:11Z")

</div>

I work wit HIPPA data and just passes a certification exam a few weeks ago. I think it is clear that this was a HIPAA violation and a fairly serious one at that. An institution can’t let data protected by law to be used as scratch paper. There are all kinds of terms that are associated with HIPAA to tell what uses are justified. However, in the workplace, it can be summarized as a “need to know basis” and that fails here.

---

<div class="post-metadata">

### Author: ![Mr.Blue\_Sky](https://avatars.discourse-cdn.com/v4/letter/m/d26b3c/32.png) [@Mr.Blue\_Sky](https://boards.straightdope.com/u/Mr.Blue_Sky)
#### Post date: [November 17, 2005, 1:31am UTC](https://boards.straightdope.com/t/was-this-a-hipaa-patient-confidentiality-violation/331421/3 "2005-11-17T01:31:43Z")

</div>

I work in a large hospital, too, albeit in an off-campus office. When we took the HIPAA compliance classes, we were told that is was our duty to report HIPAA violations to our immediate supervisor no matter how small the violation was.

Consider yourself lucky the payroll person didn’t turn you in.

Fines for violations can be very steep. It is very unlikely that the payroll person has anything to do with the patient’s care (which includes their bill, etc) and, therefore, should not be privy to such information.

---

<div class="post-metadata">

### Author: ![Guinastasia](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/guinastasia/32/5751_2.png) [@Guinastasia](https://boards.straightdope.com/u/Guinastasia)
#### Post date: [November 17, 2005, 1:37am UTC](https://boards.straightdope.com/t/was-this-a-hipaa-patient-confidentiality-violation/331421/4 "2005-11-17T01:37:38Z")

</div>

I volunteer at a local hospital and that is INDEED a HIPAA violation. Anything involving patient names, even just a list of appointments, is to be discarded into special color-coded bins to be shredded. Even innocent discussion of patients between doctors in the halls or elevators can be considered a violation.

They take HIPAA very seriously, and no, the woman in question definitely did not overreact.

---

<div class="post-metadata">

### Author: ![lorinada](https://avatars.discourse-cdn.com/v4/letter/l/b5e925/32.png) [@lorinada](https://boards.straightdope.com/u/lorinada)
#### Post date: [November 17, 2005, 1:44am UTC](https://boards.straightdope.com/t/was-this-a-hipaa-patient-confidentiality-violation/331421/5 "2005-11-17T01:44:42Z")

</div>

I was the HIPAA officer at my last job. Yes, this was a violation. Yes, this was serious.

As a biller I cannot leave my desk with papers face-up. I cannot leave my computer screen with an open application. I have to lock my filing cabinet, and I have to lock my office when I am not in it. I have to have a password on all my applications, and one on my computer itself. My office is only accessible to other staff, but I still have to do this per HIPAA. HIPAA is too extenisve to quote chapter and verse, but I am required to keep my files off-limits to anyone but staff who need the information to do their job. Likewise, our charts can only be accessed by staff that need the information contained to do their job. So, no, HIPAA is not just for keeping “outsiders” away from PHI.

If the paper that contains PHI is no longer needed, it’s supposed to be shredded, or kept in a lock container until your document destruction contractor picks it up. So the fact that the piece of paper was even lying around is a couple of violations alone.

Good for your employer for making sure even none-clinical staff are instructed on HIPAA.

---

<div class="post-metadata">

### Author: ![Mr.Blue\_Sky](https://avatars.discourse-cdn.com/v4/letter/m/d26b3c/32.png) [@Mr.Blue\_Sky](https://boards.straightdope.com/u/Mr.Blue_Sky)
#### Post date: [November 17, 2005, 1:46am UTC](https://boards.straightdope.com/t/was-this-a-hipaa-patient-confidentiality-violation/331421/6 "2005-11-17T01:46:13Z")

</div>

Hell, if I get a call from an insurance company and I write just the patient’s account number on a Post-It note, the note goes in the shredder.

I don’t have $10,000 to pay a fine and I like my job.

---

<div class="post-metadata">

### Author: ![mojave66](https://avatars.discourse-cdn.com/v4/letter/m/5f9b8f/32.png) [@mojave66](https://boards.straightdope.com/u/mojave66)
#### Post date: [November 17, 2005, 2:02am UTC](https://boards.straightdope.com/t/was-this-a-hipaa-patient-confidentiality-violation/331421/7 "2005-11-17T02:02:15Z")

</div>

Yep, as another HIPPA trainee, this was pretty serious. It’s more your co-worker’s fault than yours, though. Jeez, paper is cheap. What’s wrong with grabbing a nice, clean white piece of paper for that note? Leave the recycling and reclamation to the shredding folks. That’s their job.

When I was a kid my family lived in a two-story house and my mom liked to stack the clean laundry on the stairs to take up later. One day my dad got home and said “Osha would never do a thing like that”, making OSHA sound like another woman to pique my mother’s jealousy. After my dad irritated my mother even more by laughing at her reaction, he explained what OSHA was and mentioned being “OSHA’s slave” at work. I now go around saying that I’m “HIPPA’s bitch” in homage to my father.

---

<div class="post-metadata">

### Author: ![mojave66](https://avatars.discourse-cdn.com/v4/letter/m/5f9b8f/32.png) [@mojave66](https://boards.straightdope.com/u/mojave66)
#### Post date: [November 17, 2005, 2:03am UTC](https://boards.straightdope.com/t/was-this-a-hipaa-patient-confidentiality-violation/331421/8 "2005-11-17T02:03:19Z")

</div>

Make that “HIPAA” :smack:

---

<div class="post-metadata">

### Author: ![betenoir](https://avatars.discourse-cdn.com/v4/letter/b/258eb7/32.png) [@betenoir](https://boards.straightdope.com/u/betenoir)
#### Post date: [November 17, 2005, 3:25am UTC](https://boards.straightdope.com/t/was-this-a-hipaa-patient-confidentiality-violation/331421/9 "2005-11-17T03:25:08Z")

</div>

Yeah I’d have to say violation. Beyond the fact that she didn’t “need to know” that patients information (and how much good is a privacy policy going to be in large a hospital if _anyone_ on staff can get access to anyone’s information?) there’s the matter of how it’s disposed of. Anything like that would be “sensitive trash” (band name!) and desposed of according to the guideline (shredded). But if you use it as scrap paper and she hadden’t noticed it it most likely wouldn’t have been.

---

<div class="post-metadata">

### Author: ![Shagnasty](https://avatars.discourse-cdn.com/v4/letter/s/9dc877/32.png) [@Shagnasty](https://boards.straightdope.com/u/Shagnasty)
#### Post date: [November 17, 2005, 4:19am UTC](https://boards.straightdope.com/t/was-this-a-hipaa-patient-confidentiality-violation/331421/10 "2005-11-17T04:19:35Z")

</div>

I would like to ask the OP why he/she thought this was unjustified given that the OP works in a hospital. The hospital must not run a very effective training program and that type of thing is required by federal law. HIPAA isn’t just to protect data from the “outsiders”. All of the employees have lives outside the hospital too and many have overactive tongues or malicious reasons to share what they know. If that type of thing goes on long enough, it is virtually certain that someone who has no business looking at a certain piece of information will find out something sensitive about someone he or she knows or knows of. That can be life altering for someone and it shouldn’t be taken lightly. The information could contain references to anything from abortion, to Bipolar disorder to cancer. Even seemingly innocent information like patient lists tell a whole lot when matched up by their doctor’s specialty.

So OP, what was the thought process that made you think otherwise?

---

<div class="post-metadata">

### Author: ![davenportavenger](https://avatars.discourse-cdn.com/v4/letter/d/5f8ce5/32.png) [@davenportavenger](https://boards.straightdope.com/u/davenportavenger)
#### Post date: [November 17, 2005, 4:24am UTC](https://boards.straightdope.com/t/was-this-a-hipaa-patient-confidentiality-violation/331421/11 "2005-11-17T04:24:06Z")

</div>

Another hospital worker here, and yep, violation. You got off easy. Make sure to check next time!

It makes sense; if that second person wouldn’t have seen the other side, it could have been tossed out as regular trash and found by someone outside the hospital. Or, and I know this is a statistical near impossibility but that near is why we have this stuff, she could have been related to the patient on the record, or known them, and that information could have been leaked. Lots of reasons why it’s against the rules. All of them good ones, IMO.

I had to go through like a two hour seminar on this so I am pretty hardcore about my HIPAA-enforcing skillz.

---

<div class="post-metadata">

### Author: ![Smeghead](https://avatars.discourse-cdn.com/v4/letter/s/f1d935/32.png) [@Smeghead](https://boards.straightdope.com/u/Smeghead)
#### Post date: [November 17, 2005, 7:21am UTC](https://boards.straightdope.com/t/was-this-a-hipaa-patient-confidentiality-violation/331421/12 "2005-11-17T07:21:07Z")

</div>

Yep. My coworker accidentally did something quite similar and got smacked down pretty hard.

---

<div class="post-metadata">

### Author: ![Troy\_McClure\_SF](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/troy_mcclure_sf/32/4150_2.png) [@Troy\_McClure\_SF](https://boards.straightdope.com/u/Troy_McClure_SF)
#### Post date: [November 17, 2005, 4:27pm UTC](https://boards.straightdope.com/t/was-this-a-hipaa-patient-confidentiality-violation/331421/13 "2005-11-17T16:27:34Z")

</div>

Yup, violation.

---

<div class="post-metadata">

### Author: ![missbunny](https://avatars.discourse-cdn.com/v4/letter/m/76d3ee/32.png) [@missbunny](https://boards.straightdope.com/u/missbunny)
#### Post date: [November 17, 2005, 4:35pm UTC](https://boards.straightdope.com/t/was-this-a-hipaa-patient-confidentiality-violation/331421/14 "2005-11-17T16:35:43Z")

</div>

Let’s join in an say “Violation.” Very obvious violation, to me.

> [@](#):
>
> I was under the impression that the object of patient confidentiality was to prevent people from outside the institution from knowing patient details, etc…not from someone who actually works in the hospital.

It would not be logical (even without the existence of HIPAA) to assume that every hospital employee should have access to every patient’s medical information. Certainly the cooks, janitors, IT people, administrative staff, etc., do not need to know what Joe Smith is there for. Nurses and doctors in unrelated departments most likely will have no need to know either. The Payroll lady definitely doesn’t need to know.

---

<div class="post-metadata">

### Author: ![Ike\_Witt](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ike_witt/32/283_2.png) [@Ike\_Witt](https://boards.straightdope.com/u/Ike_Witt)
#### Post date: [November 17, 2005, 4:46pm UTC](https://boards.straightdope.com/t/was-this-a-hipaa-patient-confidentiality-violation/331421/15 "2005-11-17T16:46:02Z")

</div>

> [@rostfrei](#):
>
> I was under the impression that the object of patient confidentiality was to prevent people from outside the institution from knowing patient details, etc…not from someone who actually works in the hospital.
> 
> Was this a breach of patient confidentiality/HIPAA?

The fact that you don’t know these things is pretty troubling. Have you received any training on HIPAA?

---

<div class="post-metadata">

### Author: ![Sal\_Ammoniac](https://avatars.discourse-cdn.com/v4/letter/s/8dc957/32.png) [@Sal\_Ammoniac](https://boards.straightdope.com/u/Sal_Ammoniac)
#### Post date: [November 17, 2005, 5:49pm UTC](https://boards.straightdope.com/t/was-this-a-hipaa-patient-confidentiality-violation/331421/16 "2005-11-17T17:49:16Z")

</div>

But hold on here. What was the nature of the form? If it was just a boilerplate form that contained nothing more than a patient’s name, is that in and of itself a HIPAA violation? I think we need more details here.

---

<div class="post-metadata">

### Author: ![davenportavenger](https://avatars.discourse-cdn.com/v4/letter/d/5f8ce5/32.png) [@davenportavenger](https://boards.straightdope.com/u/davenportavenger)
#### Post date: [November 17, 2005, 6:14pm UTC](https://boards.straightdope.com/t/was-this-a-hipaa-patient-confidentiality-violation/331421/17 "2005-11-17T18:14:19Z")

</div>

> [@Sal Ammoniac](#):
>
> But hold on here. What was the nature of the form? If it was just a boilerplate form that contained nothing more than a patient’s name, is that in and of itself a HIPAA violation?

Yes. Because it confirms a person is a patient at that particular hospital, or receiving medical care in general. Could lead to problems if that got out, especially if the person is a patient at an abortion clinic or psychiatric clinic.

---

<div class="post-metadata">

### Author: ![Sal\_Ammoniac](https://avatars.discourse-cdn.com/v4/letter/s/8dc957/32.png) [@Sal\_Ammoniac](https://boards.straightdope.com/u/Sal_Ammoniac)
#### Post date: [November 17, 2005, 6:21pm UTC](https://boards.straightdope.com/t/was-this-a-hipaa-patient-confidentiality-violation/331421/18 "2005-11-17T18:21:41Z")

</div>

> [@davenportavenger](#):
>
> Yes. Because it confirms a person is a patient at that particular hospital, or receiving medical care in general. Could lead to problems if that got out, especially if the person is a patient at an abortion clinic or psychiatric clinic.

Fair enough, though the OP says he/she works at very large hospital. Let’s suppose this is nothing more than a photocopied form acknowledging receipt of the hospital’s confidentiality policy and containing nothing more than the patient’s name. In that case, is this still a “serious” violation… or even a violation at all? And if so, has anybody ever been fined or taken to court for a violation like that?

I do feel that we need more info from the OP before we can pronounce on how serious this is.

---

<div class="post-metadata">

### Author: ![Troy\_McClure\_SF](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/troy_mcclure_sf/32/4150_2.png) [@Troy\_McClure\_SF](https://boards.straightdope.com/u/Troy_McClure_SF)
#### Post date: [November 17, 2005, 6:57pm UTC](https://boards.straightdope.com/t/was-this-a-hipaa-patient-confidentiality-violation/331421/19 "2005-11-17T18:57:43Z")

</div>

> [@Sal Ammoniac](#):
>
> In that case, is this still a “serious” violation… or even a violation at all?

As said above, yes.

From my HIPPA Training Booklet:

> [@](#):
>
> Q: You are near the emergency department and you see that a neighbor has just arrived for treatment after a car crash. You hear someone say he will be taken into surgery soon. Your neighbor’s wife works in a nother part of the hospital. Should you tell her that her husband is in the emergency department?
> 
> A: No. Instead of telling the neighbor’s wife yourself, you should tell the emergency department nursing staff that you know the member/patient and his wife and how to contact her. This answer may surprise you or make you uncomfortable, but, as a member of a health plan or health care provider, you must respect the right of your neighbor- the member/patient- to decide which of his family and friends, if any, should be told he is in the emergency room.
> 
> …
> 
> Q: A friend is worried because his girlfriend is in the hospital of after hours care. m He asks you to find out anything you can. Should you try to find information for your friend?
> 
> A: No. You should not even tell him whether his girlfriend is in the hospital or after hours care…

That’s from a very large hospital organization’s training book.

Basically, unless your contact (employee, boss, MD, janitor, friend, relative, or guy off the street) Needs To Know, they cannot be told anything about any given patient.

HIPAA is a huge pain in the ass to hosptals, but it is not only respected, but downright feared by all of them. Erring is always on the side on caution.

---

<div class="post-metadata">

### Author: ![StGermain](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/stgermain/32/2868_2.png) [@StGermain](https://boards.straightdope.com/u/StGermain)
#### Post date: [November 18, 2005, 2:58am UTC](https://boards.straightdope.com/t/was-this-a-hipaa-patient-confidentiality-violation/331421/20 "2005-11-18T02:58:08Z")

</div>

Ha! You think that’s a violation? The doctor I worked for (until Monday) recently left a foot-tall stack of charts in a window seat in a corridor of our medical office building/hospital complex. Some administrator brought them to the office, having found them there unattended. When she got back she said “I just put them there while I went to get some breakfast.” She didn’t see what the fuss was about. These were complete patient charts, containing (besides medical information) patients’ names, addresses, social security numbers and dates of birth. For probably 25 patients. An identity thief’s dream.

StG

[Next page](https://boards.straightdope.com/t/was-this-a-hipaa-patient-confidentiality-violation/331421.md?page=2)
