By Fisher, JD, CHC, CCEP
OCR Resolution Highlights HIPAA Risk From Visible AIDS Status Alerts on Patient Records
Dental Practice Required to Change How It Displays Medical Alert Information
Patient Complaint Prompts OCR Review of Red “AIDS” Stickers on Chart Covers
A recent OCR investigation of a dental practice’s flagging of patients records highlights a potential HIPAA violation. The OCR investigation confirmed allegations that the dental practice flagged some of its medical records with a red sticker with the word “AIDS” on the outside cover. Records were handled so that other patients and staff without need to know could read the sticker. A patient complaint commenced an OCR investigation into whether the practice potentially identified the AIDS status of patients within the office.
Resolution Required Policy Revisions, Relocation of Alerts, and Patient Apology
When notified of the complaint filed with OCR, the dental practice immediately removed the red AIDS sticker from the complainant’s file. To resolve this matter, OCR also required the practice to revise its policies and operating procedures and to move medical alert stickers to the inside cover of the records. Further, the covered entity’s Privacy Officer and other representatives met with the patient and apologized, and followed the meeting with a written apology.
Provider Lesson: Avoid Diagnosis-Specific Labels Visible to Patients or Unauthorized Staff
The lesson here is not to place special medical alerts on the outside of physical patient records. This is a particularly bad practice in a dental office where the typical office setup can result in visual identification by other patients. If a patient is being escorted by staff and is seen by other patients, the identification on the outside of the patient’s chart can easily be connected to the patient. This creates a sensitive potential violation of HIPAA and other laws protecting against disclosure of an individual’s HIV or AIDS status.
HIPAA Minimum Necessary Rule Applies to Paper Charts and Everyday Office Workflows
The case is a useful reminder that HIPAA compliance is not limited to electronic health records or sophisticated information systems. Paper charts, file folders, sign-in sheets, labels, and other routine office processes can disclose protected health information if they are visible to individuals who do not have a legitimate need to know. A medical alert system may be appropriate when it supports patient care or workforce safety, but the alert should be designed to disclose only the minimum necessary information and should be placed where it is not visible to other patients or unauthorized staff.
Compliance Steps for Reviewing Chart Labels, Stickers, and Other Visual Identifiers
- Review all physical chart labels, cover sheets, color-coded stickers, routing slips, and other visual identifiers used in patient care areas. For example, determine whether a patient’s condition, diagnosis, medication, infectious disease status, or other sensitive information can be inferred from a sticker, notation, color code, or abbreviation visible on the outside of a file.
- Move medical alerts to nonpublic portions of the chart or into access-controlled electronic record fields when possible. For example, place necessary paper alerts inside the chart cover or in an electronic health record field that is visible only to workforce members who need the information for treatment, payment, health care operations, or safety purposes.
- Use neutral wording or coded alerts that communicate operational needs without revealing a diagnosis or condition to unauthorized individuals. For example, replace a diagnosis-specific label such as “HIV,” “AIDS,” or “hepatitis” with a neutral instruction such as “see clinical alert” or “standard precautions,” if that wording is sufficient for the intended purpose.
- Train workforce members on the minimum necessary standard and on the risk of incidental disclosures in reception, hallway, operatory, and checkout areas. For example, staff should understand that leaving charts face-up at the front desk, discussing a patient’s condition within earshot of others, or carrying a visibly labeled chart through a waiting area can create privacy risk.
- Document corrective actions promptly if a concern is identified, including policy revisions, staff retraining, and any patient communication that may be appropriate. For example, maintain a record showing when the labeling practice was changed, which forms or workflows were updated, which staff received retraining, and whether the affected patient received an apology or other response.
Client Takeaway: Low-Tech Office Practices Can Still Create HIPAA Exposure
Health care providers, including dental practices and other small providers, should not assume that low-tech office practices are low-risk. OCR’s resolution shows that visible labels on paper records can trigger a privacy complaint and require corrective action. Providers should periodically walk through their facilities from the perspective of a patient or visitor and identify whether protected health information can be seen or overheard in the ordinary course of business.
