25% off all training courses Offer ends May 8, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 8, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Facebook Sharing of Patient Info Sees ER Doc Fired

A doctor has recently been fined $500 by the State medical board after posting personally identifiable information about a patient on Facebook, a number of months after the incident caused her to lose her employment. This is a HIPAA violation that all healthcare professionals should take note of.

The doctor, Alexandra Thran, did not post the patient’s name in her post, which would be an immediate violation of HIPAA Rules, but she did post sufficient information to enable the person to be identified. Another individual who visited Thran’s Facebook page was able to determine the identity of the patient from the information she wrote on the page, even in the absence of the patient’s name.

The disclosure of Protected Health Information, which includes references to medical treatments as well as health records, along with Personally Identifiable Information (PII) can result in civil penalties being brought against the covered entity and any individual responsible for the HIPAA breach. The penalties can involve time in jail.

This is not the first incident of its kind. Nurses and doctors have been fired by their employers in California and Wisconsin for having discussions about patients via social media.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

One problem is that users of social media are encouraged to share all manner of information with friends and relatives, yet in a work setting the potential for HIPAA violations means extreme caution should be taken. In this case the incident involved an ER doctor, and the conversation was not had with the patient. Some doctors may be choosing social media channels to interact with patients but there is considerable potential for a HIPAA violation.

With social media it is too easy to write something and regret it after it has been sent, but by that time it is too late and control of information released has been lost. To tackle the issue, it is essential that healthcare providers start to develop policies covering the use of social media, the sharing of PHI and communicating with patients through secure channels.

Social media use is only likely to grow, and with it so will the risk of causing HIPAA violations. It is better to train the staff on Privacy Rules and to set strict policies covering the use of Facebook and other platforms. Many hospitals have identified the risk and have taken action and put together policies for staff to make it clear on what is allowed and what is strictly forbidden. Children’s Hospital Boston, for example, has just developed a 6-page document detailing allowable uses of social media and do’s and don’ts, with many other hospitals now electing to do the same.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist