{"id":90,"date":"2015-03-20T20:58:08","date_gmt":"2015-03-20T20:58:08","guid":{"rendered":"http:\/\/depts.washington.edu\/compdev\/wordpress\/?page_id=90"},"modified":"2025-11-06T15:59:53","modified_gmt":"2025-11-06T23:59:53","slug":"privacy-faqs","status":"publish","type":"page","link":"https:\/\/depts.washington.edu\/comply\/privacy-faqs\/","title":{"rendered":"Patient Information Privacy FAQs"},"content":{"rendered":"<p><!---<a href=\"#email\"><span data-mce-type=\"bookmark\" style=\"display: inline-block; width: 0px; overflow: hidden; line-height: 0;\" class=\"mce_SELRES_start\"><\/span><span data-mce-type=\"bookmark\" style=\"display: inline-block; width: 0px; overflow: hidden; line-height: 0;\" class=\"mce_SELRES_start\"><\/span><span data-mce-type=\"bookmark\" style=\"display: inline-block; width: 0px; overflow: hidden; line-height: 0;\" class=\"mce_SELRES_start\"><\/span><span data-mce-type=\"bookmark\" style=\"display: inline-block; width: 0px; overflow: hidden; line-height: 0;\" class=\"mce_SELRES_start\"><\/span><span data-mce-type=\"bookmark\" style=\"display: inline-block; width: 0px; overflow: hidden; line-height: 0;\" class=\"mce_SELRES_start\"><\/span>Emailing Patient Information<\/a> | <a href=\"#text\"><span data-mce-type=\"bookmark\" style=\"display: inline-block; width: 0px; overflow: hidden; line-height: 0;\" class=\"mce_SELRES_start\"><\/span>Do You Email or Text Patients?<\/a>--><\/p>\n<p>Below are answers to commonly asked questions about\u00a0 Business Associate Agreements and emailing patient information.<\/p>\n<h3><strong>Business Associate Agreements<\/strong><\/h3>\n<div class=\"su-accordion su-u-trim\"><\/div>\n<div class=\"su-spoiler su-spoiler-style-default su-spoiler-icon-plus su-spoiler-closed\" data-scroll-offset=\"0\" data-anchor-in-url=\"no\">\n<div class=\"su-spoiler-title\" tabindex=\"0\" role=\"button\"><span class=\"su-spoiler-icon\"><\/span>May I delete the reference to Washington law in Section 1? <\/div>\n<div class=\"su-spoiler-content su-u-clearfix su-u-trim\">\n<p>No. The HIPAA privacy regulations create a minimum standard for the protection of health<br \/>\ninformation nation-wide. The regulations allow for the possibility that state law is more<br \/>\nprotective of a patient\u2019s privacy or provides a patient greater access to protected health<br \/>\ninformation. In these instances, state law may actually govern the use or disclosure of health information, not the HIPAA regulations. Thus, it is important for business associates to understand that use or disclosure of protected health information on behalf of UW Medicine must conform to both state and federal requirements.<\/p>\n<\/div>\n<\/div>\n<div class=\"su-accordion su-u-trim\"><\/div>\n<div class=\"su-spoiler su-spoiler-style-default su-spoiler-icon-plus su-spoiler-closed\" data-scroll-offset=\"0\" data-anchor-in-url=\"no\">\n<div class=\"su-spoiler-title\" tabindex=\"0\" role=\"button\"><span class=\"su-spoiler-icon\"><\/span>May I expand the requirement in Section 3 for reporting of unauthorized use or disclosure beyond five working days? <\/div>\n<div class=\"su-spoiler-content su-u-clearfix su-u-trim\">\n<p>Maybe. This is ultimately a business decision and your leadership should make this determination. Expanding the reporting period may impact UW Medicine\u2019s ability to respond quickly in the case of a breach. The maximum time UW Medicine generally accepts is twenty days.<\/p>\n<\/div>\n<\/div>\n<div class=\"su-accordion su-u-trim\"><\/div>\n<div class=\"su-spoiler su-spoiler-style-default su-spoiler-icon-plus su-spoiler-closed\" data-scroll-offset=\"0\" data-anchor-in-url=\"no\">\n<div class=\"su-spoiler-title\" tabindex=\"0\" role=\"button\"><span class=\"su-spoiler-icon\"><\/span>May I expand the requirement in Section 5 for amending the designated record set beyond five days? <\/div>\n<div class=\"su-spoiler-content su-u-clearfix su-u-trim\">\n<p>Maybe. UW Medicine must consider state law requirements and you should consult with UW Medicine Compliance to discuss the operational implications. Upon request for amendment of a medical record, state law provides that a health care provider must correct or amend the records within ten calendars days of receiving the request (RCW 70.02.100). If unusual circumstances exist, state law provides for a maximum of twenty-one days to respond. The HIPAA privacy regulations, in contrast, allow a health care provider sixty days to respond. This provision tends to be an area in which considerable energy in negotiation is expended. The most important question to address is whether the business associate holds medical records that would be subject of the amendment request and whether they will be impacted by a short deadline.<\/p>\n<\/div>\n<\/div>\n<div class=\"su-accordion su-u-trim\"><\/div>\n<div class=\"su-spoiler su-spoiler-style-default su-spoiler-icon-plus su-spoiler-closed\" data-scroll-offset=\"0\" data-anchor-in-url=\"no\">\n<div class=\"su-spoiler-title\" tabindex=\"0\" role=\"button\"><span class=\"su-spoiler-icon\"><\/span>Can the Business Associate Agreement be multi-entity for vendors providing services to more than one entity?<\/div>\n<div class=\"su-spoiler-content su-u-clearfix su-u-trim\">\n<p>Yes, the Business Associate Agreement may include any\/all UW Medicine entities. The Business Associate Agreement must have signature lines for each entity included, be signed by an authorized person from each entity, and be maintained in accordance with entity-specific records retention rules.<\/p>\n<\/div>\n<\/div>\n<div class=\"su-accordion su-u-trim\"><\/div>\n<div class=\"su-spoiler su-spoiler-style-default su-spoiler-icon-plus su-spoiler-closed\" data-scroll-offset=\"0\" data-anchor-in-url=\"no\">\n<div class=\"su-spoiler-title\" tabindex=\"0\" role=\"button\"><span class=\"su-spoiler-icon\"><\/span>May I remove the requirement that the Business Associate provide individuals with access to their PHI?<\/div>\n<div class=\"su-spoiler-content su-u-clearfix su-u-trim\">\n<p>No, the Business Associate must make PHI available in accordance with HIPAA and state laws governing access of individuals to PHI.<\/p>\n<p>See\u00a0 <a href=\"https:\/\/depts.washington.edu\/comply\/docs\/comp_104.pdf\" target=\"_blank\" rel=\"noopener\">COMP.104 Patient Rights Related to Protected Health Information (PHI)<\/a>.<\/p>\n<\/div>\n<\/div>\n<div class=\"su-accordion su-u-trim\"><\/div>\n<div class=\"su-spoiler su-spoiler-style-default su-spoiler-icon-plus su-spoiler-closed\" data-scroll-offset=\"0\" data-anchor-in-url=\"no\">\n<div class=\"su-spoiler-title\" tabindex=\"0\" role=\"button\"><span class=\"su-spoiler-icon\"><\/span>May the Business Associate provide PHI to a subcontractor?<\/div>\n<div class=\"su-spoiler-content su-u-clearfix su-u-trim\">\n<p>Yes, but the Business Associate must enter into a contract that meets the requirements of a business associate agreement or other arrangement with the subcontractor(s) to ensure that the same restrictions and conditions, including the implementation of reasonable and appropriate safeguards to protect the information that apply to the Business Associate, also apply to the subcontractor.<\/p>\n<\/div>\n<\/div>\n<div class=\"su-accordion su-u-trim\"><\/div>\n<div class=\"su-spoiler su-spoiler-style-default su-spoiler-icon-plus su-spoiler-closed\" data-scroll-offset=\"0\" data-anchor-in-url=\"no\">\n<div class=\"su-spoiler-title\" tabindex=\"0\" role=\"button\"><span class=\"su-spoiler-icon\"><\/span>Is a Business Associate Agreement required for a data storage contract?<\/div>\n<div class=\"su-spoiler-content su-u-clearfix su-u-trim\">\n<p>Yes, if an entity maintains PHI on behalf of the University of Washington or UW Medicine, it is a business associate even if the entity does not actually view the PHI.<\/p>\n<\/div>\n<\/div>\n<div class=\"su-accordion su-u-trim\"><\/div>\n<div class=\"su-spoiler su-spoiler-style-default su-spoiler-icon-plus su-spoiler-closed\" data-scroll-offset=\"0\" data-anchor-in-url=\"no\">\n<div class=\"su-spoiler-title\" tabindex=\"0\" role=\"button\"><span class=\"su-spoiler-icon\"><\/span>What if the Business Associate is a governmental entity?<\/div>\n<div class=\"su-spoiler-content su-u-clearfix su-u-trim\">\n<p>When the Business Associate is a governmental entity, UW Medicine may enter a Memorandum of Understanding to document the Business Associate\u2019s privacy, security, and electronic exchanges assurances. The Memorandum of Understanding must contain the required elements of a Business Associate Agreement.<\/p>\n<\/div>\n<\/div>\n<div class=\"su-accordion su-u-trim\"><\/div>\n<div class=\"su-spoiler su-spoiler-style-default su-spoiler-icon-plus su-spoiler-closed\" data-scroll-offset=\"0\" data-anchor-in-url=\"no\">\n<div class=\"su-spoiler-title\" tabindex=\"0\" role=\"button\"><span class=\"su-spoiler-icon\"><\/span>What if there is a suspected or discovered violation of a Business Associate Agreement?<\/div>\n<div class=\"su-spoiler-content su-u-clearfix su-u-trim\">\n<p>If violation(s) of the Business Associate Agreement is suspected or discovered, the department manager or other individual initiating a contract is required to report the violation to UW Medicine Compliance and request investigation.<\/p>\n<\/div>\n<\/div>\n<h3><strong>Emailing Patient Information<\/strong><\/h3>\n<div class=\"su-accordion su-u-trim\"><\/div>\n<div class=\"su-spoiler su-spoiler-style-default su-spoiler-icon-plus su-spoiler-closed\" data-scroll-offset=\"0\" data-anchor-in-url=\"no\">\n<div class=\"su-spoiler-title\" tabindex=\"0\" role=\"button\"><span class=\"su-spoiler-icon\"><\/span>Do You Text or Email Patients?<\/div>\n<div class=\"su-spoiler-content su-u-clearfix su-u-trim\">\n<p>Yes. UW Medicine Compliance policies allow workforce members to communicate electronically with their patients provided they apply reasonable safeguards such as:<\/p>\n<ol>\n<li>Double checking the recipient email address to avoid unintentional disclosure; and<\/li>\n<li>Limiting the amount or type of protected health information<\/li>\n<\/ol>\n<p>Patients have a right to request communication preferences such as text message or email and, when reasonable, workforce members should accommodate such requests. Workforce members may consider using Microsoft Outlook\u2019s Encryption feature in the email\u2019s Options tab when emailing protected health information. If this is not possible then the patient should be warned about the risks of unencrypted email or text messages, which is described in the UW Medicine <a href=\"https:\/\/www.uwmedicine.org\/about\/policies-and-notices\/email-risk\" target=\"_blank\" rel=\"noopener\">Agreement for Electronic Correspondence<\/a>.<\/p>\n<\/div>\n<\/div>\n<div class=\"su-spoiler su-spoiler-style-default su-spoiler-icon-plus su-spoiler-closed\" data-scroll-offset=\"0\" data-anchor-in-url=\"no\">\n<div class=\"su-spoiler-title\" tabindex=\"0\" role=\"button\"><span class=\"su-spoiler-icon\"><\/span>Can you send Protected Health Information (PHI) to authorized third party recipients via email?<\/div>\n<div class=\"su-spoiler-content su-u-clearfix su-u-trim\">\n<p>Yes, so long as the following requirements are met:<\/p>\n<ol>\n<li>The email is encrypted:\n<ul>\n<li>The email is sent within UW Medicine (to other @uw.edu or @Valleymed.org email addresses)<\/li>\n<li>The email is sent to one of our affiliates included on the UW Medicine Information Security <a href=\"https:\/\/depts.washington.edu\/uwmedsec\/restricted\/guidance\/encryption\/approved-email-domains\/\" target=\"_blank\" rel=\"noopener\">Approved Domain List<\/a> (for example, @fhcrc.org, @med.va.gov, @psbc.org, @seattlecca.org, or @seattlechildrens.org,); or<\/li>\n<li>The email is manually encrypted using email options; and<\/li>\n<\/ul>\n<\/li>\n<li>The email contains the minimum amount of patient information necessary to meet the recipient\u2019s needs.<\/li>\n<\/ol>\n<\/div>\n<\/div>\n<div class=\"su-spoiler su-spoiler-style-default su-spoiler-icon-plus su-spoiler-closed\" data-scroll-offset=\"0\" data-anchor-in-url=\"no\">\n<div class=\"su-spoiler-title\" tabindex=\"0\" role=\"button\"><span class=\"su-spoiler-icon\"><\/span>Is there a person available to assist with email program configuration in the event problems arise?<\/div>\n<div class=\"su-spoiler-content su-u-clearfix su-u-trim\">\n<p>Yes, the IT personnel that support your department or clinical entity can assist you.<\/p>\n<\/div>\n<\/div>\n<div class=\"su-spoiler su-spoiler-style-default su-spoiler-icon-plus su-spoiler-closed\" data-scroll-offset=\"0\" data-anchor-in-url=\"no\">\n<div class=\"su-spoiler-title\" tabindex=\"0\" role=\"button\"><span class=\"su-spoiler-icon\"><\/span>Is there specific language that should be used in email sent directly to a patient?<\/div>\n<div class=\"su-spoiler-content su-u-clearfix su-u-trim\">\n<p>Yes, the following language should be included under your signature on any email sent to a patient:<\/p>\n<p>\u201cThe above email may contain patient identifiable or confidential information. Because email is not secure, please be aware of associated risks of email transmission. If you are communicating with a UW Medicine Provider or Researcher via email, your acceptance of the risk and agreement to the conditions for email communications is implied. (See\u00a0<a href=\"http:\/\/www.uwmedicine.org\/about\/compliance\/email-risk\" target=\"_blank\" rel=\"noreferrer noopener\">http:\/\/www.uwmedicine.org\/about\/compliance\/email-risk<\/a>.)<\/p>\n<p>The information is intended for the individual named above. If you are not the intended recipient, any disclosure, copying, distribution or use of the contents of this information is prohibited. Please notify the sender by reply email, and then destroy all copies of the message and any attachments. See our Notice of Privacy Practices at\u00a0<a href=\"http:\/\/www.uwmedicine.org\/about\/privacy\" target=\"_blank\" rel=\"noreferrer noopener\">http:\/\/www.uwmedicine.org\/about\/privacy<\/a>.\u201d<\/p>\n<\/div>\n<\/div>\n<div class=\"su-spoiler su-spoiler-style-default su-spoiler-icon-plus su-spoiler-closed\" data-scroll-offset=\"0\" data-anchor-in-url=\"no\">\n<div class=\"su-spoiler-title\" tabindex=\"0\" role=\"button\"><span class=\"su-spoiler-icon\"><\/span>Can you automatically forward email received by your University account to other email accounts such as Gmail or Yahoo? <\/div>\n<div class=\"su-spoiler-content su-u-clearfix su-u-trim\">No, UW Medicine staff and students may not automatically forward email received by their University account to a personal email account. This action is prohibited by the policies of the University since the transmission and storage of email data is not necessarily secure.<\/div>\n<\/div>\n<div class=\"su-spoiler su-spoiler-style-default su-spoiler-icon-plus su-spoiler-closed\" data-scroll-offset=\"0\" data-anchor-in-url=\"no\">\n<div class=\"su-spoiler-title\" tabindex=\"0\" role=\"button\"><span class=\"su-spoiler-icon\"><\/span>What steps should be taken when an email containing patient information is sent to the wrong recipient?<\/div>\n<div class=\"su-spoiler-content su-u-clearfix su-u-trim\">If you are the sender notify <a href=\"mailto:mailto:comply@uw.edu\">UW Medicine Compliance<\/a>. If you are the recipient, immediately reply to the sender notifying them of the error, delete the email permanently from your email account\u2019s Deleted Items folder, and notify UW Medicine Compliance.<\/div>\n<\/div>\n<h3><strong>Appointment Reminders and Other Types of Messages<\/strong><\/h3>\n<div class=\"su-accordion su-u-trim\"><\/div>\n<div class=\"su-spoiler su-spoiler-style-default su-spoiler-icon-plus su-spoiler-closed\" data-anchor=\"phi\" data-scroll-offset=\"0\" data-anchor-in-url=\"no\">\n<div class=\"su-spoiler-title\" tabindex=\"0\" role=\"button\"><span class=\"su-spoiler-icon\"><\/span>Can I include patient information when I leave a voicemail message?<\/div>\n<div class=\"su-spoiler-content su-u-clearfix su-u-trim\">\n<p>Patient Privacy laws allow health care entities to communicate with patients regarding their health care at their homes or other preferred locations. This includes leaving verbal messages for patients electronically (e.g. voice mail) or with individuals who may answer the phone (e.g. the patient\u2019s family member). However, to reasonably safeguard the patient\u2019s privacy, workforce members must take care to minimize the amount of PHI disclosed when leaving appointment reminders or other types of messages for patients. Outlined below are the best practices to use in these situations:<\/p>\n<ul>\n<li>When directed to voice messaging, provide your name, number, the UW Medicine entity from which you are calling and other information which is minimally necessary to confirm an appointment or request a return phone call.<\/li>\n<li>When you reach someone other than the patient at the patient\u2019s contact number, use professional judgment to determine the minimum necessary information to disclose and ensure that the disclosure is in the best interest of the patient.<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<p>If you have any questions,\u00a0<a href=\"mailto:comply@uw.edu\">contact us<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Below are answers to commonly asked questions about\u00a0 Business Associate Agreements and emailing patient information. Business Associate Agreements Emailing Patient Information Appointment Reminders and Other Types of Messages If you have any questions,\u00a0contact us.<\/p>\n<div><a class=\"more-link\" href=\"https:\/\/depts.washington.edu\/comply\/privacy-faqs\/\">Continue reading <span class=\"screen-reader-text\">Patient Information Privacy FAQs<\/span><\/a><\/div>\n","protected":false},"author":11,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"open","ping_status":"open","template":"","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"class_list":["post-90","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/depts.washington.edu\/comply\/wp-json\/wp\/v2\/pages\/90","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/depts.washington.edu\/comply\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/depts.washington.edu\/comply\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/depts.washington.edu\/comply\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/depts.washington.edu\/comply\/wp-json\/wp\/v2\/comments?post=90"}],"version-history":[{"count":25,"href":"https:\/\/depts.washington.edu\/comply\/wp-json\/wp\/v2\/pages\/90\/revisions"}],"predecessor-version":[{"id":8975,"href":"https:\/\/depts.washington.edu\/comply\/wp-json\/wp\/v2\/pages\/90\/revisions\/8975"}],"wp:attachment":[{"href":"https:\/\/depts.washington.edu\/comply\/wp-json\/wp\/v2\/media?parent=90"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}