Is QuickBooks HIPAA Compliant?
QuickBooks is not HIPAA compliant and cannot be used to create, collect, store, or transmit Protected Health Information unless the desktop version of the software is used via a third party hosting service that supports HIPAA compliance. However, due to the cost of deploying QuickBooks Desktop on a third party hosting service, it may be better for healthcare providers to use a HIPAA compliant QuickBooks alternative. QuickBooks by Intuit is a popular accounting software solution – available as an online SaaS solution or a downloadable desktop solution – that offers a range of financial management packages for small and medium sized businesses. In addition to its own capabilities, QuickBooks Online integrates with hundreds of third party apps to increase payment options, accelerate payment processing, simplify tax reporting, and better analyze data. For businesses in the healthcare industry, QuickBooks can be used for budgeting, payroll management, financial reporting, and auditing. Time-tracking add-ons exist to support compliance with the Fair Labor Standards Act (FLSA) and...
HIPAA Compliant Appointment Reminders
HIPAA compliant appointment reminders are communications with patients that must take into account any consent requirements or privacy restrictions and the channel of communication being used to remind the patient of the appointment. In addition to complying with HIPAA, appointment reminders must also comply with FCC regulations. The HIPAA Privacy Rule permits the use of Protected Health Information (PHI) to remind patients of appointments under the treatment, payment, and healthcare operations (TPO) provisions of §164.506. This is according to an FAQ published by the Department of Health and Human Services (HHS) in 2002. However, while the use of PHI is permitted, how much PHI can be disclosed may be subject to several factors, including: Who is receiving the appointment reminder? Have privacy restrictions been requested? How is the reminder being communicated? Does the reminder comply with FCC regulations? Who is Receiving the Appointment Reminder? In the context of how much PHI can be disclosed in HIPAA compliant appointment reminders, although the minimum necessary standard...
Is HoneyBook HIPAA Compliant?
HoneyBook is not HIPAA compliant and cannot be used to create, collect, store, or transmit electronic Protected Health Information if a healthcare provider qualifies as a HIPAA covered entity or provides services to or on behalf of a covered entity as a business associate. However, this does not mean HoneyBook cannot be used by healthcare providers at all. HoneyBook describes itself as a client flow management platform for small businesses. The description is accurate inasmuch as the platform is a scaled down version of an enterprise CRM that can be used by small businesses to manage enquiries, schedule appointments, and automate workflows. HoneyBook can also be used for invoicing clients and accepting payments. Businesses that want more capabilities can upgrade to an Essentials or Premium Plan – both of which also support integrations with apps such as Calendly, Gmail, Outlook, QuickBooks, and Zapier. For many individual healthcare providers and small medical practices, these capabilities are usually sufficient for managing client flow and backroom client administration. When...
HIPAA Compliance for Emergency Care
HIPAA compliance for emergency care professionals can be harder than for other healthcare professionals due to the variety of emergency events they attend and the behaviors of patients and their families during emergency events. We look at why this is the case and what covered entities can do to prevent unintentional HIPAA violations in emergencies. In 2020, a study into “emotionally evocative patients in the emergency department […] and the implications for patient safety” found that patient behaviors and issues with hostile family members left the majority of emergency care professionals angry, frustrated, or irritated. Many professionals admitted failing to provide the best possible care or act professionally following an angry encounter. The study backed up previous research suggesting that emotions can influence clinical reasoning and behavior, raised concerns that negative encounters could evoke negative emotions that could compromise patient safety in emergency situations, and concluded that emergency care professionals should receive additional training to promote awareness...
HIPAA and Canada
HIPAA can apply in Canada in several different ways, even when a company is physically located only in Canada. In practice, it comes into play whenever a Canadian organization handles Protected Health Information for U.S. HIPAA Covered Entities, signs Business Associate Agreements with U.S. healthcare clients, or uses subcontractors and services that are part of a cross border healthcare data ecosystem. Providing Services to U.S. HIPAA Covered Entities A Canadian company can fall under HIPAA when it provides services to a U.S. HIPAA Covered Entity such as a hospital, clinic, telehealth provider, or health plan. If the work involves handling, viewing, or using Protected Health Information, or PHI, on behalf of that U.S. client, then the Canadian company fits the definition of a HIPAA Business Associate. The fact that the company is physically located in Canada does not remove those obligations, because HIPAA is concerned with who is doing work for the Covered Entity and how PHI is handled, rather than limiting its reach only to vendors inside the United States. Scope Based On...



