Get certified in HIPAA for Leaders for just $49.95.
To view this video please enable JavaScript, and consider upgrading to a web browser that supports HTML5 video
HIPAA law covers PHI in electronic format. This includes all social media platforms such as Facebook, X, Snapchat, and Instagram. Never under any circumstance disclose a patient's name or treatment on any social media platform. You can personally be liable financially and criminally for disclosing PHI on social media. Mobile devices include smartphones and tablets, and also laptops. These can be used to share PHI if appropriate safeguards are in place. This means you must use an encrypted texting platform or chat, as standard messaging platforms lack sufficient encryption, are not HIPAA-compliant, and store data on unapproved servers. When it comes to email, do not use free consumer email services to send or store protected health information. Those providers generally will not sign a Business Associate Agreement (BAA), which is legally required to handle PHI. Failing to secure email communications carries severe consequences. For instance, in 2019 Solara Medical Supplies agreed to a $3 million OCR settlement following an email breach exposing over 114,000 patient records. You must use a paid enterprise email service (such as Google Workspace or Microsoft 365) configured for HIPAA and backed by a signed BAA. Faxes remain an approved and compliant method to send PHI. However, you must always use a cover sheet before sending PHI through a physical fax machine or an eFax. If you send PHI in error, notify the receiver immediately to destroy the information. Likewise, if you receive PHI in error, notify the sender and destroy the information immediately.
In this lesson, we'll cover how HIPAA applies to electronic Protected Health Information (ePHI) across modern communication channels, including social media, mobile devices, email platforms, and faxes.
HIPAA covers all electronic Protected Health Information across all social media platforms, including Facebook, X, Snapchat, and Instagram. Never disclose a patient's name, treatment, or identifiable health details on any social media network under any circumstance.
Disclosing PHI on social media platforms carries severe risks. Individuals can be held personally liable both financially and criminally for posting protected health information on social channels.
Mobile devices include smartphones, tablets, and laptops. While mobile devices can be used to share PHI, strict technical safeguards must be in place first:
Free consumer email services should never be used to send or store PHI because consumer providers generally refuse to sign a Business Associate Agreement (BAA), which is legally required to handle protected data.
Organizations must use paid enterprise email platforms (such as Google Workspace or Microsoft 365) properly configured for HIPAA compliance and supported by a signed BAA.
Pro Tip: The Cost of Insecure Email: Unsecured email communications lead to major regulatory penalties. In 2019, Solara Medical Supplies agreed to a $3 million OCR settlement following an email breach that exposed over 114,000 patient records.
Faxes remain an approved and compliant method for transmitting PHI, provided essential security protocols are followed:
So what do you do if you do receive PHI in error or no longer need access to it? Disposing of PHI is of the utmost importance, particularly in our modern digital world where deleted files and posts are rarely ever completely gone. Following these PHI disposal guidelines will help ensure you and your organization remain HIPAA compliant. Click each guideline to learn more about proper disposal protocols:
Shred all hard copies containing Protected Health Information (PHI) when the copies are no longer needed.
Place hard copies designated for recycling into locked recycle bins whenever available.
Delete all soft copy files containing PHI from your workstation computer and local server once the information is no longer required within your record retention requirements.
Physically destroy all disks, CDs, and external media drives that contained PHI prior to disposal.
Do not reuse disks, CDs, or storage drives that previously contained PHI without thoroughly sanitizing them first.
Contact your IT department before transporting or transferring hardware. IT must follow proper procedures to move equipment and sanitize hard drives and storage media.
Return PHI directly to the original sender if this requirement is stipulated in any contractual agreements.
It depends whom you ask. This is unfortunately a complicated answer, and one for which you will find differing opinions if you search the web. Apple is not willing to sign Business Associate Agreements with Covered Entities. However, if Apple's Facetime service can be considered a conduit under the Conduit Exception Rule, then a BAA is not strictly required as long as the service is used in a HIPAA compliant manner. Whether or not Facetime is considered a conduit is what is hotly debated. The US Department of Veteran Affairs has authorized Facetime for use internally for telemedicine and thereby gives its stamp of approval. Nonetheless, there are other peer-to-peer video services who are willing to sign BAAs, so our recommendation would be to use one of those services instead.
Yes, Zoom is HIPAA compliant. In order to use Zoom in a HIPAA compliant manner, the covered entity must enter into a business associate agreement with Zoom prior to using the platform. You can learn more and request a BAA on the Zoom for Healthcare website.
Please be aware that it is possible to violate HIPAA Rules while using Zoom. Users must be properly trained on their responsibilities regarding patient privacy and permitted sharing of PHI only with authorized individuals. It is the covered entity's responsibility to ensure Zoom is used in a HIPAA compliant manner and that staff are all adequately trained.