Video: Every Case Tells a Story| Webinar: ACR/CHEST ILD Guidelines in Practice

An official publication of the ACR and the ARP serving rheumatologists and rheumatology professionals

  • Conditions
    • Axial Spondyloarthritis
    • Gout and Crystalline Arthritis
    • Myositis
    • Osteoarthritis and Bone Disorders
    • Pain Syndromes
    • Pediatric Conditions
    • Psoriatic Arthritis
    • Rheumatoid Arthritis
    • Sjögren’s Disease
    • Systemic Lupus Erythematosus
    • Systemic Sclerosis
    • Vasculitis
    • Other Rheumatic Conditions
  • FocusRheum
    • ANCA-Associated Vasculitis
    • Axial Spondyloarthritis
    • Gout
    • Psoriatic Arthritis
    • Rheumatoid Arthritis
    • Systemic Lupus Erythematosus
  • Guidance
    • Clinical Criteria/Guidelines
    • Ethics
    • Legal Updates
    • Legislation & Advocacy
    • Meeting Reports
      • ACR Convergence
      • Other ACR meetings
      • EULAR/Other
    • Research Rheum
  • Drug Updates
    • Analgesics
    • Biologics/DMARDs
  • Practice Support
    • Billing/Coding
    • EMRs
    • Facility
    • Insurance
    • QA/QI
    • Technology
    • Workforce
  • Opinion
    • Patient Perspective
    • Profiles
    • Rheuminations
      • Video
    • Speak Out Rheum
  • Career
    • ACR ExamRheum
    • Awards
    • Career Development
  • ACR
    • ACR Home
    • ACR Convergence
    • ACR Guidelines
    • Journals
      • ACR Open Rheumatology
      • Arthritis & Rheumatology
      • Arthritis Care & Research
    • From the College
    • Events/CME
    • President’s Perspective
  • Search

Physician Texting Could Violate HIPAA

Steven M. Harris, Esq.  |  Issue: August 2012  |  August 8, 2012

To a physician, a simple text message does not appear like it could possibly jeopardize these safeguards, but this perception is incorrect. For starters, it is difficult to be sure that there is no one in eyeshot of your phone screen. If a physician is at a busy restaurant and a text message comes in containing patient information, the physician may not be the only one seeing the text message. This has HIPAA implications because the physician has compromised the privacy of the patient’s healthcare information. The damage is done once an unauthorized person views the patient’s healthcare information.

Use the same physician as an example again, but this time the physician is alone at home, and there are no onlookers who could catch a glimpse of the patient’s healthcare information. This scenario appears to be safe, but a text message is stored on different servers, not just on the phones of the sender and receiver. If a hacker were to break into one of these servers and obtain those texts, this would constitute a security breach under HIPAA. It does not matter that the hacker had no intention of obtaining a patient’s health information and did not even know what he or she was getting. It is, nevertheless, a HIPAA violation.

ad goes here:advert-1
ADVERTISEMENT
SCROLL TO CONTINUE

Take that same physician again, but this time the physician leaves his or her cell phone, which contains a text message with a patient’s healthcare information, at a restaurant. Someone picks up the cell phone and, in an effort to determine the phone’s owner, sees the text message that contained a patient’s healthcare information. Even though that individual had no intention of viewing the patient’s healthcare information, it is still a HIPAA violation, because an unauthorized person viewed the patient’s personal healthcare information.

Preventing HIPAA Violations

Although there may not be a HIPAA violation until a patient’s healthcare information is actually intercepted, the threat of a violation is very real. The threat of a HIPAA violation remains with every text message regarding a patient that a physician sends or receives. It is advisable for physicians to password-protect their cell phones. It is even better if the cell phone software requires the password to be changed on a regular basis. Although passwords may help prevent some security breaches, a password may be nothing more than a minor inconvenience that can be circumvented by a hacker. There are also software programs and applications that can be downloaded that encrypt and decrypt messages. Some of these apps can send messages via a secure server. However, most physicians are not currently employing these apps, and those who do find them cumbersome to use. Even those programs that advertise that they provide a secure network to transmit protected information may not be “HIPAA proof.”

ad goes here:advert-2
ADVERTISEMENT
SCROLL TO CONTINUE

Page: 1 2 3 | Single Page
Share: 

Filed under:Legal UpdatesLegislation & AdvocacyProfessional TopicsTechnology Tagged with:communicationHarrisHIPAALegalLegislationrheumatologistTechnologytext messaging

Related Articles

    Bridge the Gap Between Goal and Attainment

    May 1, 2010

    Use motivational interviewing to facilitate behavior change for your clients

    Email & Text in the World of HIPAA

    May 17, 2019

    The world we live in necessitates infor­mation be communicated in a quick and easy manner. This remains true in the healthcare setting. The ability to text or email staff and patients has become a priority for many healthcare entities. However, maintaining patient privacy and confidentiality is essential to ensure we meet compliance standards. Although emailing…

    HIPAA Security Standards: What Rheumatologists Need to Know

    April 1, 2015

    Maintain compliance with updated federal rules governing privacy protection for patient health information

    Phase 2 of HIPAA Audit Program Launches

    May 13, 2016

    With many competing priorities facing physician practices, HIPAA compliance and security is not a topic that usually makes it to the top of the list. But this is not the case with the Department of Health and Human Services’ Office for Civil Rights (OCR), because it has initiated a new phase of audits of physician…

  • About Us
  • Meet the Editors
  • Issue Archives
  • Contribute
  • Advertise
  • Contact Us
  • Copyright © 2025 by John Wiley & Sons, Inc. All rights reserved, including rights for text and data mining and training of artificial technologies or similar technologies. ISSN 1931-3268 (print). ISSN 1931-3209 (online).
  • DEI Statement
  • Privacy Policy
  • Terms of Use
  • Cookie Preferences