HIPAA Privacy

When you're at your doctor's office the last thing that's probably on your mind is your privacy.  But shouldn't it be?

What if you're dealing with a particularly embarrassing illness?  Or what if the medicine you're taking is typically used for something else that is more serious?  And that's the light stuff.

Your doctor's office keeps enough data on you to be an identity thief's dream.  The sad fact is that a majority of small clinics have computer systems that are ill-equipped to protect your data and defend themselves from a cyber attack.  This means that when you visit your doctor, your privacy and your identity could be at risk.

Compliance with HIPAA and HITECH laws is crucial because it means a clinic understands what it takes to properly protect and secure client data.

A recent HIPAA compliance survey highlighted that while adoption of a HIPAA compliance plan rose from 58 percent to 70 percent, HIPAA training actually decreased from 62 percent to 58 percent.  Further, the number of appointed Security officers decreased from 56 to 54 percent.

These survey results are shocking because a hallmark of the HIPAA/HITECH requirements center around training and accountability.  With decreasing training and accountability (lack of appointed Security officers), patient privacy is at risk and clinics don't seem to be taking it seriously.

What can you do?

It is perfectly ok to ask your physician's office manager how they are protecting your data.  It is also ok to ask to speak with their HIPAA Compliance Officer, Security Officer, or Privacy Officer.

If they don't know who that person is, they're definitely out of compliance and it's time for a new doctor.

In a time when cyber attacks are becoming prevalent, complacency is never an option.