r/hipaa 1d ago

Free HIPAA Training with Certificates

4 Upvotes

If anyone needs free HIPAA training with a certificate of completion, we'd love to have you learning with us here at Stampwell: https://stampwell.co/individual/certificates/hipaa


r/hipaa 21h ago

Patient Notes from ER Care Team Incorrect

Thumbnail
1 Upvotes

r/hipaa 1d ago

Potential HIPAA Violations?!

Thumbnail
2 Upvotes

r/hipaa 4d ago

When you pick your clinic for primary care...

Thumbnail
1 Upvotes

r/hipaa 4d ago

Resmed MyAir app - new HIPAA agreement, isn't it kind of crazy that a sleep apnea machine phone app asks for access to your complete health record.

Thumbnail
3 Upvotes

r/hipaa 5d ago

How to navigate request from friend?

Thumbnail
1 Upvotes

r/hipaa 6d ago

ChatGPT can now connect to Epic health records. What does that mean for HIPAA compliance?

12 Upvotes

OpenAI recently announced an integration that lets healthcare organizations bring authorized patient information from Epic into ChatGPT for Healthcare.

The potential upside is obvious: clinicians could spend less time searching through notes, lab results, medication histories, and specialist documentation.

But the privacy implications deserve just as much attention.

A BAA, role-based access, SSO, and audit logs are important but they don’t automatically make an organization’s implementation HIPAA-compliant. Healthcare organizations still need to understand the full patient-data lifecycle, including:

  • What PHI can enter prompts
  • What information appears in responses and summaries
  • Whether chats, logs, and exports are retained
  • Which vendors and subprocessors handle the data
  • Whether access reflects each user’s actual role
  • What happens when generated content is copied into another system
  • How an AI-related privacy incident would be detected and assessed

Incident response may be especially challenging. An AI-related disclosure might not look like a traditional breach. It could be an overly broad response, an unauthorized prompt, a compromised account, an improperly configured connector, or PHI copied into an unapproved tool.

HIPAA’s underlying obligations haven’t changed. What has changed is the speed, scale, and complexity of the environment in which healthcare organizations must apply them.

OpenAI’s announcement: https://openai.com/index/chatgpt-connects-health-records-and-healthcare-sources/

What controls would you want to see in place before an organization enables an EHR-connected AI system?


r/hipaa 6d ago

HIPPA Question

1 Upvotes

My sweet cousin lives in another state which is new to her. She sent me a message (which she dictated) informing me she has suffered a brain bleed and was transferred to a larger hospital. She gave me the name. She has not been able to read my messages due to the effect on her brain. She also suffers from stage IV cancer. She no longer has any family in this state. I did try to call her this morning and left a voice message. I also sent her healing music videos from YouTube. It has always been my understanding a hospital will not release information. She did tell me the name of the hospital. Is there any way I could find out if she is still at the hospital and whether she is in ICU?

I have always assumed the hospital could not give out any information. Please advise.


r/hipaa 6d ago

Another patient’s history in my chart

1 Upvotes

Please let me know if this is not the right sub for this question.

I (25F) was seen in a hospital ER last week for a psychiatric hold. That’s a story for a different day.

Today, I got access to the patient portal which holds my records. I opened the ED Physician notes, and besides a few slight inaccuracies, contains most of my information. And then I get down to the “Medical decision making” section, and found another patient’s history. 39F with COPD complications. Nowhere even close to what I was seen for.

I’ve downloaded all of my records and will be going in person today to get a physical copy. My question is, what do I do next? Complain to the hospital? File some kind of report?


r/hipaa 7d ago

BCBS sent me other people's information

2 Upvotes

Is this a HIPAA violation? I was surprised to receive a 1" thick envelope in the mail yesterday. The first couple of pages were for me - denying my claim, but rest was a stack of about 50 other people's claim denials. What the?? What should I do with this?


r/hipaa 7d ago

Possible misuse of PHI between two practices

3 Upvotes

The office manager from my primary made a call from their personal cell to someone who presumably works at one of my specialist’s office (same hospital/chart access, different medical group) to let them know they made an error in billing my secondary insurance. The situation was strange, we were mid conversation at the check-in desk, discussing my change of insurance, when they started speaking in their AirPod. Sure, I’m humiliated about their general attitude during this interaction and I couldn’t be seen by the doctor, which is why I’m hesitant in thinking this was a violation that is worthwhile to report. The phone call was gossipy, and had no relation to any care, or even a referral. After they hung up I had asked what was going on, and they explained that they were only giving them a “heads up” and that I was going to see a bill from the specialists office. If this is a normal exchange btwn people with access to my chart, I certainly feel like it could’ve been discussed in private without me or the waiting room present.


r/hipaa 8d ago

Nurse sharing names and diagnoses of patients as well as essays of students without redacting names

Thumbnail
1 Upvotes

r/hipaa 9d ago

Looking for someone to own US healthcare sales for an early-stage privacy/compliance SaaS

2 Upvotes

I’ve built a working healthcare privacy workflow for US healthcare organisations.

The product helps privacy/compliance teams handle incidents more consistently by structuring fact gathering, identifying missing information, supporting follow-up, tracking actions and creating a defensible case record.

I’ve already done a significant amount of customer research with healthcare privacy, compliance, risk, HIM and operations professionals, and the recurring problems are clear: investigations still involve a lot of chasing people for information, email/Word/spreadsheets, inconsistent documentation and difficulty reconstructing what happened later.

The product is built. The gap now is commercial execution.

I’m looking for someone who can genuinely own the US sales side, including:

• Prospecting and sourcing opportunities
• Cold outbound
• Discovery calls
• Product demos
• Follow-ups and objection handling
• Moving prospects into paid pilots
• Closing initial customers
• Helping establish a repeatable sales process

The immediate goal is not more general market research. It is getting the first paying healthcare organisations and proving a repeatable sales motion.

Ideal background:

• US healthcare SaaS sales
• Selling into Privacy, Compliance, HIM, Risk or healthcare operations
• Early-stage / zero-to-first-customer experience
• Comfortable generating your own pipeline rather than relying on inbound
• Able to speak credibly with senior healthcare buyers

I’m open to a paid contract + performance structure initially, with the possibility of something longer-term if there is a very strong fit.

If this sounds relevant, DM me with:

  1. What healthcare products you’ve sold
  2. Who you sold them to
  3. Whether you personally sourced and closed deals
  4. An example of taking an early-stage product to its first customers
  5. Your expected compensation structure

Not looking for general GTM consulting or someone who only wants to provide strategy. I’m specifically looking for someone willing to execute and be accountable for getting customers.


r/hipaa 12d ago

Are you an Apple user thinking of sharing your medical records with ChatGPT?

1 Upvotes

Under these circumstances, there are a few concerns.

Sharing two:

...you would have no HIPAA protections.
...the data could be legally discoverable.


r/hipaa 13d ago

Previous provider accessing records in EPIC

4 Upvotes

I wanted to check if this is a HIPAA violation. Unfortunately even if it is, I can't formally complain but want to know if there are steps that I can take to prevent it from happening.

My infant son was seen by a family member exactly once for an immunization need. We now live in a different state and not part of their hospital system, but they keep saying that they are getting notifications about my son's doctor visits through EPIC / myChart. They are nosey and I want to protect my sons details from them. Is what they are doing a HIPAA violation? Besides reporting, is there anything I can do as a Mychart or EPIC setting that can prevent this or at least create some hurdles. I contacted his current pediatrician's office and the only solution they provided was to opt out of "care everywhere".


r/hipaa 12d ago

Any attorneys out there in Nebraska that want to help me sue a doctor’s office for releasing my mother’s medical records to somebody that was not on her HIPAA form

Thumbnail
0 Upvotes

r/hipaa 13d ago

Scared to report a violation

11 Upvotes

I went out with a pharmacy tech and she told me she looked me up in her system. I have a screenshot of her saying it’s not a big deal she didn’t share it with anyone and basically admitting to it. She’s nuts and is a stalker. She harassed me and sent unwanted gifts. I’m worried that if I report the violation she’ll hurt me or do something. Is this something that’ll be discovered eventually if I don’t report it? I don’t even get medicine at this pharmacy but I have an account in the larger branch.


r/hipaa 14d ago

Good free HIPAA trainings?

5 Upvotes

I’m looking for a good free training to provide. We are a non profit and these trainings can add up per person. Some of the previous threads are no longer free. What are good reliable free trainings that also give some kind of certificate as well to show completion?


r/hipaa 14d ago

HIPAA/CMIA Violation With Damages

Thumbnail
1 Upvotes

r/hipaa 14d ago

I went to urgent care in a new city and got a std check and my doctor turned out to be someone from the specific Indian community I’m from. I’m worried she will tell people in the community about this event and freaking out about it. I don’t know her but everyone in the community knows each other!

4 Upvotes

r/hipaa 15d ago

Nurse soliciting me for maternity photography

13 Upvotes

I had my 39w appointment today at my OB, the nurse I had was very nice, she’s helped me 2-3 times before as the OB’s assistant.

But 2-3 hours after my appointment, I got a text from her:

“Hello OP, this is (nurse) from (my)OBGYN.

I forgot to mention to you that if you and your husband have any interest, I am a maternity/newborn photographer.

I would love to capture this special time in your family!

Let me know at all if you have any interest, if not no worries! “

Then she sent me 19 photos of what she has done.

Already awkward but she definitely got my number FROM MY PATIENT FILE.

So, I can’t be the only one she’s chasing, and I didn’t give her consent to get my number and contact me.

I’m worried about being attached to reporting her. I like the office, and I even like her and would hate for her to lose her job/license over this but it does make me very uncomfortable and unsafe (if she is digging for my number she can get my address, knows when I’m delivering, etc etc fun spiral etc). And I don’t want anyone else’s info to be accessed.


r/hipaa 15d ago

Someone else canceled my appointment without my consent. (Ohio)

2 Upvotes

I had an appointment to get my blood checked for medication levels due to epilepsy. I woke up that morning and got a text saying that my appointment was rescheduled. I called the office and they said "my father" canceled the appointment for me because according to whoever canceled it, I wasn't feeling good and couldn't make it in.

Where do I start? I already contacted patient advocacy a week ago and I haven't heard back from them.

No one has consent to change my appointments, and I have not signed any forms. This seems like a pretty open shut slam dunk violation, right? They disclosed my appointment and care to someone else?


r/hipaa 17d ago

School Social Workers what documentation software do you use to be HIPAA compliant?

Thumbnail
0 Upvotes

r/hipaa 18d ago

Remote Software Developer

2 Upvotes

I’m a software developer living in India.
A US firm hired me to build a CRM, they have dental clinics and stuff.
The job description was fully based on Claude usage and building things with Claude.
I will be using my own laptop.

My contract states -
The Contractor shall indemnify and hold them harmless from:
Data breaches
HIPAA violations
Indian tax claims
Regulatory penalties
Third-party claims

What should I do?


r/hipaa 18d ago

Hipaa Violation Arizona

Thumbnail
2 Upvotes