r/hipaa 16h ago

HIPAA compliance is the foundation. But in today's healthcare environment, it's no longer enough. šŸ’» 🧬 🩺

Post image
1 Upvotes

r/hipaa 1d ago

At what point does HIPAA stop giving parents access to their kid's medical records, and how does it protect young adults who don't want their parents seeing everything?

0 Upvotes

Once someone turns 18, HIPAA treats them as an adult, full stop. Parents don't automatically get access to records anymore, even if they're still on the insurance or paying the bills. The young adult has to sign a written authorization before a provider can share anything, and they can revoke it any time.

The tricky part is under 18, minors generally have some HIPAA protections around sensitive stuff (mental health, reproductive care, substance abuse) depending on state law, but parents can usually see the rest. So the sharp cutoff is really the 18th birthday.

Providers who ignore this and share records with parents anyway are the ones who end up in OCR complaints. It's one of the most common HIPAA violations we see in patient portal builds, apps that auto-link a parent account and forget to sever it when the kid becomes an adult.


r/hipaa 1d ago

Founding Head of Platform & Safety (equity) - mental health peer support startup

0 Upvotes

Looking for a Head of Platform & Safety to join Shema as a founding team member. We're building an anonymous peer support platform for people in recovery and navigating mental health challenges, currently raising our pre-seed and heading into beta.

We’re splitting this role from our Cofounder/CTO because safety and platform infrastructure are two different disciplines. Our CTO owns the technical build, but trust & safety needs its own leader focused entirely on crisis protocols, moderation frameworks, and working with clinical advisors. Mixing those under one person is how safety gets deprioritized when shipping pressure hits. We’re not doing that.

You'd own crisis escalation protocols, AI monitoring design, community moderation frameworks, and making sure everything we build is both safe and human.

What we're looking for:
- Experience in trust & safety, crisis escalation, mental health product design, or community platform moderation
- Comfortable building safety infrastructure from scratch in an early-stage environment
- Mission-aligned... this isn't just a job, it’s shaping how vulnerable people experience support
- Equity-only comp for now (we're pre-seed)

If this resonates, DM me or drop a comment. Happy to share more about what we're building and what the role looks like day-to-day.


r/hipaa 1d ago

Employee files security (WI)

1 Upvotes

I work at a large healthcare corporation that is comprised of approximately 70 nursing homes. At my location, employee personnel, medical, and FMLA files are all kept in an unlocked file cabinet in an unlocked,communal office. I act as the local HR generalist, among other things. Most admin positions in the corporation are gen Z promoted -from-within / learn-on-the job vs educated, work their way up.

I have taken this security issue to the (young) Executive Director 4 times. He has given me pacifying responses and referred me to maintenance, while secretly instructing the maintenance supervisor to ignore my requests. I escalated to the (young) corporate HR director for our location, but she simply refuted my request by stating that the last she knew, the cabinet was being locked ( it doesn't have a working lock).

Is there any regulatory body this can be reported to? I've contacted the state department of workforce, along with my state representative. I keep getting shuffled to other departments, finally being told that there may actually be no oversight to this issue. My state representative suggested that it would be necessary to obtain an attorney.

Does anyone have any idea how to handle this?


r/hipaa 2d ago

Health care admin @ Piedmont Women’s Center in Atl accessed my medical records

4 Upvotes

I found out that a medical assistant illegally accessed my medical records at Piedmont Women’s Center in Atl to obtain my contact information because she was angry that I was talking to her child’s father. Is this a HIPAA violation? What should I do?


r/hipaa 2d ago

TrimRX

3 Upvotes

Writing from Colorado.

I am prescribed medications through TrimRX, an online prescriber/ pharmacy.

I am text links daily for discounts. I am already a subscriber so I don’t open these links, but I had forwarded one of the links to my friend’s phone. When he clicked the link, it opened MY account without asking for a username/ password/ or other form of authentication. He has never logged into my account on his phone, so that’s not why a login was bypassed.

I have contacted TrimRX via phone and email without a response. I submitted a complaint with the Office of Civil Rights. I don’t want to close my account until the OCR see that they too can access my account by clicking just a link.

What else am I missing?


r/hipaa 3d ago

Help!

0 Upvotes

I’m looking for advice from anyone familiar with California healthcare licensing or the complaint process.
For some background, my roommate and I have had an increasingly hostile living situation. There have been multiple police calls, threats to force entry into my locked bedroom, and ongoing conflicts over property. While that’s stressful, it isn’t the main reason I’m posting.
I’m a transgender man and currently on HRT. My roommate knows this and has made transphobic comments toward me in the past.

She works as a CNA and is currently pursuing becoming a rehab nurse. Recently, she told me about a transgender patient she cared for. She didn’t tell me the patient’s name or any identifying information, but she said she intentionally used the patient’s legal name and referred to the patient with male pronouns because she ā€œdoesn’t believe in transgender peopleā€ due to her religious beliefs.

As a trans person, that really bothered me, especially knowing this involved someone in her care.
I’m trying to understand what, if anything, should be reported. My questions are:

Does the California CNA certification board or another state agency investigate complaints involving discrimination or unprofessional conduct toward patients?
Could intentionally refusing to respect a patient’s affirmed name and pronouns be considered misconduct?
Since she told me about the patient herself, without identifying them, is that something that raises confidentiality or professionalism concerns?
Can a complaint be submitted anonymously or confidentially?

What kind of evidence is generally needed before an investigation is opened?

I’m not looking to weaponize the complaint process because we’re roommates. If I report anything, I want it to be because it genuinely violates professional standards for someone providing patient care. I’d appreciate input from anyone familiar with California healthcare licensing or who has gone through the complaint process.

Thanks in advance for any suggestions.


r/hipaa 4d ago

Is my old therapist breaking HIPAA / information blocking?

2 Upvotes

I have questions about if a therapist that I recently fired is breaking any laws by seemingly waiting until the last possible day (today is day 29) to fulfill my medical records request or communicate about it / file an extension.

Long story short, I was seeing a therapist who was really bad. Bringing her political opinions into my sessions to invalidate my childhood sexual abuse, tried to diagnose me with autism without the proper qualifications or licensure / without a neurodevelopmental assessment, and when I brought up my concerns she told me this was further proof I was autistic as I was being "too black and white." I requested a discharge as well as all my progress notes / designated record set.

She sent me a copy of a vague and inaccurate intake and discharge note. The discharge note included a 1 sentence blurb about consulting a previous psychiatrist of mine whose ROI I revoked, and it said he told her I was not appropriate for the type of therapy she offered. No date or time as to when they consulted. She used this to justify that basically, "You can't fire me, I am referring you out because your psych said you shouldn't do this type of therapy with me." She had never mentioned consulting with him at any point, I only learned about this after I requested a discharge and revoked my ROI. She has not responded to my requests for the date of the consult. I suspect she either did not truly consult with him, or did so immediately after I revoked the release.

I plan to file a complaint with her licensing board, but I wanted to wait to see what she wrote in her progress notes. I suspect she is defensively charting, as I made her aware I believed she was practicing unethically and beyond her scope of licensure.

If she sends me an extension request OR my records on the 30th day, can I still file a complaint with OCR because it seems like she is maliciously complying with "30 days." Her last correspondence with me was extremely defensive, and she ended with, "You will receive your records within the legal timeframe."


r/hipaa 5d ago

Weird Mail Flyer Shares the street name of a patient - Is this a HIPAA violation??

Thumbnail
gallery
1 Upvotes

I am not sure if this is the right subreddit or if this is allowed, so please delete if it is not.

The long title basically says it all. I have no idea if this is a HIPAA violation. I am not the patient, so I am not effected. But I'd be rather upset if any of my medical provider's used my street name in an advertisement like this. The flyer is addressed to my late grandmother. I was the executor of my grandmother's estate several years ago when she passed away. My address basically became connected to her name, long story short, I still get really funny mail for her. I got this flyer, which seems to be for an audiologist office. It mentions a street in my neighborhood, saying a neighbor on that street goes to their office. It already looks scam-adjacent, basically implying they can help prevent dementia and they will give you this weird "free book."


r/hipaa 7d ago

Health Insurer blowing me off - any advice?

1 Upvotes

I made a formal request - that was received and acknowledged - through my health insurer for my health records that they hold.

The law says 30 days, they said they would respond in 30 days, it's coming up on 60 and they're blowing me off.

If I file a complaint, does anything really happen over an issue like this? Thanks


r/hipaa 7d ago

Proposed Security Rule - Faxing

2 Upvotes

Since the OCR has pushed back the final ruling of the proposed Security Rule till next year, my plan is to work through it and implement/make plans to implement the required changes.

In the proposed rule, encryption at rest and in transit is a must. https://www.federalregister.gov/d/2024-30983/p-585 Phones and faxing are no longer excluded.

How are you going to be handling this change?

My thought is that faxing will be discontinued. Faxing doesn't have a way to encrypt in transit. Sure, your telcom/fax provider could encapsulate and encrypt your voip packets, but that is only guaranteed to your telcom's edge. I don't think there would be a way for your telcom to guarantee encryption across each hop to it's destination. Going this route, I don't see a way that voice communication would work either, to be honest.


r/hipaa 8d ago

Anyone experience frequent violations from doctors interfamillially?

2 Upvotes

Like i'm getting say dental care with this one doctor, then a parent is, and theres a total breakdown of hipaa compliance + i got told im overly concerned? Anyone else notice this?

or the doctor messages my parents about my dental stuff(and its fine, theyre paying, idk if i filled out a form)

ect

idk if its just this one guy but, as an adult, eh..

im an adult my mom reminded my doctor to fill a prescription i didnt need too.


r/hipaa 9d ago

Sketched out by this CMS risk adjustment vendor fax

Post image
1 Upvotes

Looking for a second opinion on this. I have verified that datafied is a legitimate vendor for the CMS risk adjustment effort, but the typos in the bolded text there are giving me pause. Anyone else receive something similar? I am pretty sure it's legit, but there's no number to call or anything. Figured I'd bounce it off of y'all before spending half the day going down a rabbit hole trying to get someone on the phone. The patient in question was seen in in our office in 2025 and they did have the indicated MedAdvantage plan at the time (Wellcare by Health Net).


r/hipaa 9d ago

Ex psychiatrist reached out to sell me new experimental depression medication

0 Upvotes

Hi, so to make a short story long- I had a psychiatrist probably 2-3 years ago, who I only visited once for an anxiety/panic disorder, to which I was prescribed some low dosage anxiety/blood pressure medication, and that's it. The pills didn't end up helping me in the ways I needed, I didn't go back to her, and I actually officially ended our client-doctor relationship via email (which included her sending me documentation of her discharging me as a client of hers), and found another provider.

Today this same previous psychiatrist, has reached out to me via email, to try and sell me an experimental depression medication, because I'm a patient "resistant to other depression medications". For starters I don't recall us going deep into my history much less medical history with depression and medications. Meaning this psychiatrist has actually no earthy idea the depression medications I've had before or what I may take now, and furthermore has no idea I would be resistant to certain depression medications. Second of all, I feel like it's really skeezy of a psychiatrist to go through former patient profiles to attempt to sell medication, to those who match. I just feel like this is murky waters as far as legality or at least professional standards of practice, and I tried to look it up, and am finding conflicting answers.

And so now I’m here with questions: does this violate hipa, if not does it violate other codes of conduct, do I need to report this, who should I report it to if I do, should I do nothing, what do you think?


r/hipaa 11d ago

Has anyone ever experienced this before?

Post image
7 Upvotes

I’ve worked inpatient mental health for 4 years, and have read, signed, provided education for different facilities, as well as signing for my own health visits. I encountered something this past week I’ve never seen.

I’m 27F from Mississippi and recently had an OBGYN visit (not pregnant) and this was in the updated agreement I had to sign. As someone of reproductive age in a very red state, the laws regarding abortion and reporting to authorities has been a scary risk already. What are your thoughts on this? How is this supposed to be interpreted?


r/hipaa 12d ago

Calling all Crisis Responders!

Thumbnail
0 Upvotes

r/hipaa 12d ago

Who do I even contact? Unwanted hospital ā€œinteraction.ā€

5 Upvotes

I’m a cancer patient and a transplant patient; I am at the hospital just about every other week. A few months ago, I was at emergency, waiting to be seen, when I got a message from an unknown Facebook account. Curious, I clicked on the profile and could tell he was a guard at the very hospital I was at. I ignored it and didn’t think much of it… until, again while at the same hospital, I got another message from dude. At this point, I am incredibly uncomfortable going to this hospital; their guard staff not only found my protected information (I never had a single interaction with him; he somehow got my name, I can only assume he obtained it from the hospital system) but he used it to message me inappropriate things - and he did it on two separate occasions. Who, at the hospital, or otherwise, do o even report this too?


r/hipaa 12d ago

Path of BAA: A HIPAA Compliance Game

0 Upvotes

Anyone else initially think the OCR created a game? šŸ˜†


r/hipaa 13d ago

How do you actually keep up with regulatory changes without feeling overwhelmed?

4 Upvotes

Hi everyone, I’m doing some research on how privacy professionals stay current with privacy, AI governance, and cybersecurity regulations.I’m not selling anything—I’m genuinely trying to understand how people work because everyone I’ve spoken to seems to have a different system.

A few questions I have

1). Where do you usually hear about new regulatory developments?
Official regulators?
Law firms?
LinkedIn?
Newsletter subscriptions or RSS feeds?

2).Once you learn about a new regulation or enforcement action, what happens next….Do you save it or share and Forward it to people on ur team
Personally , I feel like I would forget until somebody asks me about itšŸ˜¬šŸ˜‚.

3).What’s the most frustrating part of staying current? and are there tools or anything that help with that

I’d love to understand your workflow.

Thanksā¤ļø


r/hipaa 13d ago

Bill sent in png image in SMS - Violation

Post image
1 Upvotes

I'm no longer in healthcare, but when I was, I would have cautioned departments to check with their compliance officer about this situation. I want to see if this is a clear violation of HIPAA.

I have been receiving bills from a medical practice via SMS text. Not texts with a link to a secure site to view my statment, but png images of my bills in the text, with a link to pay them. The bill images include my name, visit dates, and services (and CPT codes) rendered on those dates.

Again, this is a non-secure SMS text. According to my past understanding, this is a clear violation of HIPAA, given the patient name and the services rendered are in the body of the message and can be intercepted.

Can someone confirm for me that this is indeed a violation? When I called the office to mention to tell them that this could be problematic and ask them to send me a secure statement, all the person said was, "I don't know about that."

Thanks to all of you.


r/hipaa 14d ago

labcorp

3 Upvotes

question: i have to get blood work for my primary. i don't want my specialists getting access to the results. i always opt out of health information exchanges with providers. any recommendations?


r/hipaa 14d ago

Using personal devices for medical applications

Thumbnail
0 Upvotes

r/hipaa 16d ago

can providers see records in other healthcare systems?

2 Upvotes

i have had my primary for 25 years who uses athena health for the patient portal. i have also seen different specialists over the years in other healthcare systems (all used my chart).

i have always kept each portal separate and have never granted or shared access between providers.

my question is can the providers see the other records? does it matter if they are on different systems or do they have to be the same system?

the reason that i ask is because i read a post by a provider who said that he "searches epic" for all of a patient's records before the visit.


r/hipaa 16d ago

Is my voicemail script violating HIPAA?

3 Upvotes

I’ve been working in healthcare admin for 8 months as my first job. I never had any HIPAA training and my department’s HIPAA protocols are whatever my boss says to me in the moment.

I’ve been leaving voicemails to patients with this script I received from my boss and I have begun to worry it’s violating HIPAA.

It generally goes ā€œHello, this is (my name) from (clinic name) calling for (patient first name). I am calling to remind you of your appointments with us and the doctor for (time) and (time) on (date). Please call back if you want to cancel or need help finding us at (building name, floor number). Please don’t wear eye makeup to the appointment and please don’t take (medication) and (medication) for two days before the appointment. My phone number is (number). See you on (day of appointment). Goodbye.ā€

My boss is a nurse and said basically the same thing to patients over voicemail when I was training. She says it’s because patients don’t listen to the appointment letter we send. I did some research on HIPAA today for a different reason and now I’m very worried I’ve been violating it for the past 8 months.

Is this an issue? If so, what do I do at this point? šŸ˜ž


r/hipaa 19d ago

Moral misalignment

Thumbnail
1 Upvotes