Note: Your progress in watching these videos WILL NOT be tracked. These training videos are the same videos you will experience when you take the full ProHIPAA for Leaders program. You may begin the training for free at any time to start officially tracking your progress toward your certificate of completion.
In this lesson, we'll cover how HIPAA applies to electronic Protected Health Information (ePHI) across modern communication channels, including social media, mobile devices, email platforms, and faxes.
HIPAA covers all electronic Protected Health Information across all social media platforms, including Facebook, X, Snapchat, and Instagram. Never disclose a patient's name, treatment, or identifiable health details on any social media network under any circumstance.
Disclosing PHI on social media platforms carries severe risks. Individuals can be held personally liable both financially and criminally for posting protected health information on social channels.
Mobile devices include smartphones, tablets, and laptops. While mobile devices can be used to share PHI, strict technical safeguards must be in place first:
Free consumer email services should never be used to send or store PHI because consumer providers generally refuse to sign a Business Associate Agreement (BAA), which is legally required to handle protected data.
Organizations must use paid enterprise email platforms (such as Google Workspace or Microsoft 365) properly configured for HIPAA compliance and supported by a signed BAA.
Pro Tip: The Cost of Insecure Email: Unsecured email communications lead to major regulatory penalties. In 2019, Solara Medical Supplies agreed to a $3 million OCR settlement following an email breach that exposed over 114,000 patient records.
Faxes remain an approved and compliant method for transmitting PHI, provided essential security protocols are followed:
So what do you do if you do receive PHI in error or no longer need access to it? Disposing of PHI is of the utmost importance, particularly in our modern digital world where deleted files and posts are rarely ever completely gone. Following these PHI disposal guidelines will help ensure you and your organization remain HIPAA compliant. Click each guideline to learn more about proper disposal protocols:
Shred all hard copies containing Protected Health Information (PHI) when the copies are no longer needed.
Place hard copies designated for recycling into locked recycle bins whenever available.
Delete all soft copy files containing PHI from your workstation computer and local server once the information is no longer required within your record retention requirements.
Physically destroy all disks, CDs, and external media drives that contained PHI prior to disposal.
Do not reuse disks, CDs, or storage drives that previously contained PHI without thoroughly sanitizing them first.
Contact your IT department before transporting or transferring hardware. IT must follow proper procedures to move equipment and sanitize hard drives and storage media.
Return PHI directly to the original sender if this requirement is stipulated in any contractual agreements.