Do you have any tips for maintaining a compliant private practice?
Yes, maintaining a compliant private practice protects your patients, your license, and your ability to continue delivering insurance-based care. Fay takes its compliance practices seriously and asks that providers on its platform do the same. While providers are ultimately responsible for ensuring their own compliance with applicable laws, licensure requirements, and professional standards, this course outlines certain compliance-related tips for delivering care on Fay.
Protecting patient privacy and HIPAA
HIPAA is the federal law that protects patient health information. Protected Health Information (PHI) includes information that identifies or could identify a patient and relates to their health, care, or payment for care. Examples include patient contact details, insurance information, medical history, weight, lab results, goals, messages, and visit notes.
To help safeguard patient information:
Use Fay’s platform for patient communications and documentation. Do not copy patient information into personal notes apps, unsecured files, personal email, text messages, or social media DMs.
Keep sessions private. Conduct appointments in a space where conversations cannot be overheard, and use Fay’s approved Zoom link. If Zoom is unavailable, a phone call may be used as a short-term alternative.
Check before sending or sharing. Confirm the correct patient, recipient, and attachments. During screen sharing, ensure another patient’s information is not visible.
Share information only as permitted. Patient information generally requires written authorization before it can be shared, unless HIPAA permits the disclosure, such as for treatment, payment, or certain health care operations.
Use AI responsibly. Do not enter, upload, or share Fay patient information in personal AI accounts, including ChatGPT, Gemini, or Copilot. You can use these tools for general tasks that do not involve patient information, such as brainstorming educational topics. Review AI-generated content for accuracy and use your professional judgment.
Check outside tools before using them. A vendor that handles PHI on your behalf generally requires a signed business associate agreement (BAA), which sets out its responsibilities for protecting patient data. A BAA alone is not enough; appropriate privacy and security safeguards are also required.
Unauthorized sharing of patient information may violate HIPAA and your Provider Agreement with Fay and may be a reportable breach.
