• Home
  • Practice Focus
    • Facial Plastic/Reconstructive
    • Head and Neck
    • Laryngology
    • Otology/Neurotology
    • Pediatric
    • Rhinology
    • Sleep Medicine
    • How I Do It
    • TRIO Best Practices
  • Business of Medicine
    • Health Policy
    • Legal Matters
    • Practice Management
    • Tech Talk
    • AI
  • Literature Reviews
    • Facial Plastic/Reconstructive
    • Head and Neck
    • Laryngology
    • Otology/Neurotology
    • Pediatric
    • Rhinology
    • Sleep Medicine
  • Career
    • Medical Education
    • Professional Development
    • Resident Focus
  • ENT Perspectives
    • ENT Expressions
    • Everyday Ethics
    • From TRIO
    • The Great Debate
    • Letter From the Editor
    • Rx: Wellness
    • The Voice
    • Viewpoint
  • TRIO Resources
    • Triological Society
    • The Laryngoscope
    • Laryngoscope Investigative Otolaryngology
    • TRIO Combined Sections Meetings
    • COSM
    • Related Otolaryngology Events
  • Search

Avoid Data Breaches, HIPAA Violations When Posting Patients’ Health Information Online

by Steven M. Harris, Esq. • October 5, 2014

  • Tweet
  • Click to email a link to a friend (Opens in new window) Email
Print-Friendly Version

Avoid Data Breaches, HIPAA Violations When Posting Patients’ Health Information OnlineFacebook, Twitter, Instagram, Snapchat, YouTube, blogs, websites, Google+, LinkedIn. What do all of these social media outlets have in common? Each of these avenues can get physicians in trouble under the Health Insurance Portability and Accountability Act (HIPAA), state privacy laws, and state medical laws, to name a few of the applicable regulations. It seems that, all too often, news outlets are reporting data breaches generated in the medical community, many of which arise out of physicians’ use of social media, and many of which could have been avoided.

You Might Also Like

  • Department of Health and Human Services’ Final Rule Expands HIPAA Obligations, Violation Penalties
  • HIPAA Expansion: Ensure your practice meets the law’s new provisions
  • How to Avoid a Healthcare Data Breach
  • Why HIPAA, Protected Health Information Cybersecurity Best Practices Are Critical in COVID-19 Era
Explore This Issue
October 2014

Physicians should be aware of the intersection of social media use—for both personal and professional use—and HIPAA and state laws. Even an inadvertent, seemingly innocuous disclosure of a patient’s protected health information (PHI) through social media can be problematic.

PHI is defined under HIPAA, in part, as health information that (i) is created or received by a physician, (ii) relates to the health or condition of an individual, (iii) identifies the individual (or with respect to which there is a reasonable basis to believe the information can be used to identify the individual), and (iv) is transmitted by or maintained in electronic media, or transmitted or maintained in another form or medium. Under HIPAA, a physician may use and disclose PHI for treatment, payment, or healthcare operations. Generally, using or disclosing PHI through social media does not qualify as treatment, payment or healthcare operations. If a physician were to use or disclose a patient’s PHI without permission, this would violate HIPAA (and likely state law).

To use or disclose a patient’s PHI without obtaining the patient’s consent, a physician must de-identify the information and ensure there is no reasonable basis to believe the information can be used to identify the patient. One option under HIPAA is to retain an expert to determine “the risk is very small that the information could be used, alone or in combination with other reasonably available information, by an anticipated recipient to identify an individual who is the subject of the information.” Alternatively (and more often the case), a physician seeking to use or disclose patient PHI can remove the following identifiers from the PHI:

  1. Name(s);
  2. Geographic information;
  3. Dates (e.g., birth date, admission date, discharge date, date of death);
  4. Telephone numbers;
  5. Fax numbers;
  6. E-mail addresses;
  7. Social Security numbers;
  8. Medical record numbers;
  9. Health plan beneficiary numbers;
  10. Account numbers;
  11. Certificate/license numbers;
  12. Vehicle identifiers and serial numbers, including license plate numbers;
  13. Device identifiers and serial numbers;
  14. URLs;
  15. IP address numbers;
  16. Biometric identifiers (e.g., finger and voice prints);
  17. Full-face photographic images and any comparable images; and
  18. Other unique identifying numbers, characteristics, or codes.

Identifier No. 18 is the most difficult to comply with in light of the significant amount of personal information available on the Internet, particularly through Google and other search engines. Inputting even a small amount of information into a search engine will generate relevant “hits” that make it increasingly more difficult to comply with the de-identification standards under HIPAA. Even if Identifier Nos. 1–17 are carefully removed, the broadness of Identifier No. 18 can turn a seemingly harmless post on social media into a patient privacy violation.

Pages: 1 2 3 | Single Page

Filed Under: Departments, Legal Matters Tagged With: HIPAA, technologyIssue: October 2014

You Might Also Like:

  • Department of Health and Human Services’ Final Rule Expands HIPAA Obligations, Violation Penalties
  • HIPAA Expansion: Ensure your practice meets the law’s new provisions
  • How to Avoid a Healthcare Data Breach
  • Why HIPAA, Protected Health Information Cybersecurity Best Practices Are Critical in COVID-19 Era

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

The Triological SocietyENTtoday is a publication of The Triological Society.

Polls

Would you choose a concierge physician as your PCP?

View Results

Loading ... Loading ...
  • Polls Archive

Top Articles for Residents

  • Applications Open for Resident Members of ENTtoday Edit Board
  • How To Provide Helpful Feedback To Residents
  • Call for Resident Bowl Questions
  • New Standardized Otolaryngology Curriculum Launching July 1 Should Be Valuable Resource For Physicians Around The World
  • Do Training Programs Give Otolaryngology Residents the Necessary Tools to Do Productive Research?
  • Popular this Week
  • Most Popular
  • Most Recent
    • A Journey Through Pay Inequity: A Physician’s Firsthand Account

    • The Dramatic Rise in Tongue Tie and Lip Tie Treatment

    • Otolaryngologists Are Still Debating the Effectiveness of Tongue Tie Treatment

    • Is Middle Ear Pressure Affected by Continuous Positive Airway Pressure Use?

    • Rating Laryngopharyngeal Reflux Severity: How Do Two Common Instruments Compare?

    • The Dramatic Rise in Tongue Tie and Lip Tie Treatment

    • Rating Laryngopharyngeal Reflux Severity: How Do Two Common Instruments Compare?

    • Is Middle Ear Pressure Affected by Continuous Positive Airway Pressure Use?

    • Otolaryngologists Are Still Debating the Effectiveness of Tongue Tie Treatment

    • Complications for When Physicians Change a Maiden Name

    • Excitement Around Gene Therapy for Hearing Restoration
    • “Small” Acts of Kindness
    • How To: Endoscopic Total Maxillectomy Without Facial Skin Incision
    • Science Communities Must Speak Out When Policies Threaten Health and Safety
    • Observation Most Cost-Effective in Addressing AECRS in Absence of Bacterial Infection

Follow Us

  • Contact Us
  • About Us
  • Advertise
  • The Triological Society
  • The Laryngoscope
  • Laryngoscope Investigative Otolaryngology
  • Privacy Policy
  • Terms of Use
  • Cookies

Wiley

Copyright © 2025 by John Wiley & Sons, Inc. All rights reserved, including rights for text and data mining and training of artificial technologies or similar technologies. ISSN 1559-4939