View Single Post
Old 6 May 2019, 04:52 AM   #12
elvey
The "e" in e-mail
 
Join Date: Jan 2002
Location: San Francisco
Posts: 2,458
Cool Regular email is NOT prohibited by HIPAA

FYI:

Please be aware that HIPAA - regulated healthcare entities ARE allowed to send PHI via regular mail:
https://www.hhs.gov/hipaa/for-profes...x.html*states:
"...*the Privacy Rule does not prohibit the use of unencrypted e-mail ...**Note that an individual has the right under the Privacy Rule to request and have a covered health care provider communicate with him or her by alternative means or at alternative locations, if reasonable. See 45 C.F.R. ยง 164.522(b).*"

So regular email is generally appropriate if a patient requests it or if, because of safeguards that have been applied, such as the ones that this thread shows have been applied, normal email between identified parties is encrypted already.

Some of those HIPAA-compliant systems are much worse than others, so this can be valuable info. So I reposted this outside the FM board, here: http://www.emaildiscussions.com/showthread.php?t=74378, along with a poll: Surprised? Y/N?

Last edited by elvey : 6 May 2019 at 05:00 AM. Reason: Mention reposting.
elvey is offline   Reply With Quote