Do physicians who use personal e-mail accounts to communicate with patients violate HIPAA by doing so?

Written by Reed Tinsley, CPA | April 4, 2008

From HcPro’s newsletter Briefings on HIPAA:

This is a potential violation of the HIPAA security rule. A violation has not occurred if an e-mail does not include any PHI. However, e-mails that contain PHI should be encrypted.

Encryption is an addressable implementation specification under the security rule. “Addressable” means the provider must implement the specification as stated in the rule, implement protections equivalent to the rule, or must clearly document why the implementation specification does not apply.

Cost may not be the primary reason for failure to implement the specification. It is important to remember that the security rule was finalized back in 2003 and then became effective in 2005.

Encryption technology has become much more mature and interoperable since 2003. And it is no longer cost-prohibitive-even for the smallest providers.

Physicians who elect to send PHI via unencrypted e-mail in 2008 are hard-pressed to justify this decision.

About the Author

Reed Tinsley CPA

This article is written by Reed Tinsley, a Houston, TX-based CPA with over 30 years of experience advising physicians and medical practices across Texas and the United States. Reed holds certifications as a Certified Valuation Analyst (CVA), Certified Healthcare Business Consultant (CHBC), and Certified Financial Planner (CFP), specializing exclusively in the healthcare sector. He is a published author, nationally recognized speaker, and trusted advisor to physicians on accounting & tax, practice management, and financial planning. Schedule a Free Consultation.

Have questions? I’m here to help.