Q

Is it against HIPAA regulations to display client names?

Security management expert Mike Rothman discusses the terms of HIPAA, specifically if it is a violation of the act to publicly display client names.

I work in a residential group home for mentally ill adults. I have to keep telling my boss that displaying full...

client names on bulletin boards and desk tops is a violation of HIPAA. She has removed most of the posted memos that contain client names, but all the client charts, with their full names displayed, are kept on a bookshelf in the office -- visible to anyone who enters the office. Isn't this also in violation of HIPAA?

The reality of HIPAA and every other information security-oriented regulation is that violations and compliance are subjective based upon the judgment of the auditor. Without seeing the environment and the other defenses you have in place, I can't say if that is a violation of HIPAA or not.

Relative to your specific question, client names shouldn't be displayed out in the open, but the answer to the problem can be as easy as draping a curtain over the bookcase so the names are no longer visible to anyone walking by the work area in question.

My point here is not to minimize the importance of your issue, but to point out that there are usually multiple ways to solve any problem. More indicative of your environment is a general disdain for patient privacy. This seems to be more of a cultural issue (if I can make that assessment based on a one paragraph question).

The only way to change culture is by mandate and consistent enforcement of that mandate. The top executive would need to mandate that patient privacy is important. Someone will likely need to be terminated as a result of ignoring the mandate for the troops to really get the picture.

That is usually bad medicine, but until you were to get a significant fine (which is unlikely, given the current lack of HIPAA enforcement) or be sued by a client, nothing is likely to change without that mandate.

For more information:

This was last published in December 2007

Dig Deeper on HIPAA

PRO+

Content

Find more PRO+ content and other member only offers, here.

Have a question for an expert?

Please add a title for your question

Get answers from a TechTarget expert on whatever's puzzling you.

You will be able to add details on the next page.

Start the conversation

Send me notifications when other members comment.

By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Please create a username to comment.

-ADS BY GOOGLE

SearchCloudSecurity

SearchNetworking

SearchCIO

SearchConsumerization

SearchEnterpriseDesktop

SearchCloudComputing

ComputerWeekly

Close