You can't share these 6 numbers, often written xx/xx/xx.
What is the birthdate?
We permission from the family to bill insurance from this, our one and only insurance contract (permission is included in the intake forms).
What is Tricare?
ROI
What is release of information?
This common way of sharing information is not HIPAA compliant, which is why we use Simple Practice to share reports with caregivers.
What is email?
This PHI, often labeled in a blue folder around the office, cannot be client-facing, and should technically be kept behind a lock.
What is the first and last name?
Before sharing this protected health information that includes the @ symbol, you need an ROI.
What is the email adddress?
We don't need an ROI to share information with this state-funded agency, since we have an ongoing HIPAA agreement in place as a contracted vendor.
What is the San Diego Regional Center (SDRC)?
PHI
What is protected health information?
Since this agency has HIPAA compliant email, we can send PHI, such as reports, to them via email, rather than using Simple Practice.
What is SDRC?
When a client and/or their caregiver wanders into your office (with or without an invitation) you need to be sure this isn't visible on your computer.
What is Simple Practice?
The first one of these is sometimes PHI, but the last one always is.
What is the name?
A verbal or written agreement isn't enough to share PHI with this SGD distributor.
What is AbleNet?
HIPAA
What is the Health Insurance Portability and Accountability Act?
We send reports to Tricare using this pre-email document transmission method.
What is fax?
Discussing diagnosis, names, ages, goals, progress, or home plan in this part of the office, should be done with discretion, as it may be overheard by other clients.
What is the hall?
This location is a form of PHI.
What is the address?
If this educational entity shares their own ROI, we can use it to share PHI.
What is a school?
FERPA
What is the Family Educational Rights and Privacy Act?
Technically, when sharing reports with these individuals, we should encrypt our emails.
What are school SLPs, ABA therapists, and other providers?
If a parent asks the name, age, diagnosis, etc. of another client, it would be a violation of this if you shared it.
What is HIPAA?
Restriction of this media as PHI is not limited to images of the face, but includes any visuals that could uniquely identify the individual.
What are pictures and videos?
You actually don't need an ROI to share PHI if information must be disclosed "in the public interest", which includes this, for which SLPs are mandated reporters.
What is abuse?
BAA
What is business associates agreement?
This telephone-based communication method, that includes short message service and multimedia message service, is not, in fact, HIPAA-compliant.
What is texting?
If a parent wants the contact information for the parent of another client, you need this in order to provide the information (although it's better to get the first parent's info and pass it along to the second).
What is an ROI?