Compromised PHI in physician office – what to do

Written by Reed Tinsley | December 17, 2013

 

In order to determine whether PHI has been compromised in a physician office, you should always consider the following:

  • The nature and extent of PHI involved, including the types of identification and the likelihood of re-identification;
  • The unauthorized person who used the PHI or to whom the disclosure was made;
  • Whether the PHI was actually acquired or viewed; and
  • The extent to which the risk to PHI has been mitigated.

This is not an exhaustive list but one to get you started. Other considerations may be applied depending on the actual circumstances surrounding the breach.

About the Author

Reed Tinsley CPA

This article is written by Reed Tinsley, a Houston, TX-based CPA with over 30 years of experience advising physicians and medical practices across Texas and the United States. Reed holds certifications as a Certified Valuation Analyst (CVA), Certified Healthcare Business Consultant (CHBC), and Certified Financial Planner (CFP), specializing exclusively in the healthcare sector. He is a published author, nationally recognized speaker, and trusted advisor to physicians on accounting & tax, practice management, and financial planning. Schedule a Free Consultation.

Have questions? I’m here to help.