The HIPAA Journal is the leading provider of news, updates, and independent advice for HIPAA compliance

Healthcare Providers Violate HIPAA Responding to Negative Yelp Reviews

Some healthcare providers have violated patient privacy and HIPAA Rules when responding to negative comments on Yelp and similar review sites according to a recent ProPublica report.

For the report, ProPublica was provided with access to around 1.7 million Yelp reviews of healthcare providers. The researchers used a tool to sift through the reviews and isolated approximately 3,500 one-star ratings of healthcare providers – the lowest possible rating on the review site – that mentioned “Privacy” or “HIPAA”.

ProPublica researchers discovered “dozens” of instances where healthcare providers had breached HIPAA Rules when responding to comments. In some cases, the responses to the negative comments involved the disclosure of patients’ protected health Information.

ProPublica cited one example of a Californian chiropractor that replied to a negative comment from a patient and included details of the procedures he had performed and information about her medical condition. Another example involved a dentist who responded to a comment about an alleged unnecessary tooth extraction. The dentist wrote “Due to your clenching and grinding habit, this is not the first molar tooth you have lost due to a fractured root,” and explained that “This tooth is no different.”

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Disclosing any details of medical procedures performed or personal information about patients in website comments is a violation of patient privacy and a violation of the Health Insurance Portability and Accountability Act. Even when no PHI is disclosed in the comments, healthcare providers have breached HIPAA Rules simply by confirming that the commenter is one of their patients.

Even when a patient posts a comment about a physician or other healthcare provider, they have not given their permission for any information about them to be disclosed. That includes their status as a patient of a particular healthcare provider.

While hotels and restaurant owners can respond to negative Yelp comments and can provide their points of view, healthcare professionals must exercise restraint and not enter into comment discussions with patients. This does not mean that healthcare providers do not get the right to reply, only that any responses to negative comments should not refer to individuals.

ProPublica contacted Deven McGraw, Deputy Director for Health Information Privacy at the Office for Civil Rights, who explained that any responses to negative comments should be general in nature and that providers should never “take those accusations on individually by the patient.”

The Office for Civil Rights (OCR) and state attorneys general can issue heavy fines for HIPAA violations and breaches of patient privacy. In 2013, Shasta Regional Medical Center agreed to pay the OCR $275,000 after the impermissible disclosure of a patient’s protected health information to the media. Healthcare providers that disclose PHI when responding to comments on review sites may find they too will have to pay a substantial financial penalty for breaching HIPAA Rules and violating patient privacy.

Author: Steve Alder is the editor-in-chief of HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist