Wiki HIPAA violations

huguezbrian

Networker
Messages
59
Location
Culver City
Best answers
0
Yesterday a random guy emailed me for a remote Medical/Radiation Oncology coding opportunity. He seemed kind of suspicious and didn't want to provide me with any of his company information. So today he emails me (8) different patient complete medical records (mind you we have not established an employment relationship). So I do my investigation and it turns out that he is from India. Some Oncology/Hematology practice located in Florida contracted with a coding company in India and this man was trying to have me code these patient's treatment for them? Of course I called the practice and informed them, but my question is what do I have to do now? PHI was disclosed, multiple HIPAA violations were done?

Thanks!
 
In addition, I would report what information I have to the OCR of HHS. Although the requirements are that facilities should report, for low numbers of violations, I'm not sure the enforcement or compliance is strong. Although you've alerted the practice, there's no guarentee any follow-up or change in practice shall occur.
 
Top