skip to main content

Protecting your patients’ personal information.

I have never triggered HIPAA (Health Insurance Portability and Accountability Act), and I don’t maintain compliance. However, another provider sent me electronic files containing patient information. Does that mean I am now required to be HIPAA compliant?  


No. You are not required to be HIPAA compliant just because another provider/person sent you electronic protected health information (PHI). No one can trigger HIPAA on your behalf by sending you electronic documents.    

Most psychologists trigger HIPAA by electronically transmitting or sending PHI. PHI includes any information connected to a patient’s identity, health diagnosis and treatment and health insurance claims. If someone acting on your behalf, such as a billing service, electronically transmits PHI in connection with a patient’s claim, that will trigger HIPAA as well.

If you are a cash-only practice or do not bill insurance companies, you may not have triggered HIPAA and would not need to maintain HIPAA compliance. However, APA recommends that all psychologists make their practices HIPAA compliant since many health-care transactions are increasingly being done on electronic platforms and HIPAA is viewed as setting the standard of care for privacy and security protections.

So, if someone sends you electronic files — or if you keep your own files electronically — consider implementing HIPAA-level security policies and practices:

  • Encrypt the data on your computer
    You can choose to encrypt an individual file or folder that contains sensitive information, or to encrypt all of the data stored on your computer’s hard drive. Options for HIPAA compliant encryption programs include Windows “BitLocker”, Apple’s “FileVault 2” and the freeware utility “VeraCrypt”, among others (For more tips, read "Keeping Up With the Security Rule" in Good Practice, January 2018).
  • Back up your electronic files
    You may want to consider storing your data outside of your computer. Simple options include external hard drives and USB flash drives. If you decide to utilize flash drives or external hard drives, look for one that provides extra security, such as those that offer encryption or password protection.
  • Store electronic files on a third-party cloud storage service
    Several companies, including Carbonite and MozyPro, enable you to upload and save your documents in a secure and encrypted manner. If you are not HIPAA-compliant and you decide to store information in the cloud, we recommend that you look for a service that meets HIPAA standards. It will be more secure than a service that does not.

Whether you’ve triggered HIPAA or not, remember that you are always subject to your state’s recordkeeping and patient privacy/confidentiality laws, and need to comply with their requirements. Contact your licensing board with specific questions related to your state requirements.   


Disclaimer: *Legal issues are complex and highly fact-specific and state-specific.  They require legal expertise that cannot be provided in this article.  Moreover, APA and APA Services, Inc. attorneys do not, and cannot, provide legal advice to our membership or state associations.  The information in this article does not constitute and should not be relied upon as legal advice and should not be used as a substitute for obtaining personal legal advice and consultation prior to making decisions.

Date created: 2019