Can healthcare providers share PHI with debt collectors? (2024)

Yes, healthcare providers can share protected health information (PHI) with debt collectors under specific circ*mstances without violating HIPAA. Debt collection isconsidered a payment activityunder HIPAA, so sharing necessary information with debt collectors is permitted.

What is the Fair Debt Collection Practices Act (FDCPA)?

HIPAA and the Fair Debt Collection Practices Act (FDCPA) intersect when medical debt collection is involved. HIPAA restricts the direct sharing of patients' health information with debt collectors. Still, the FDCPA establishesguidelines and restrictionsfor how debt collectors can communicate with debtors (including patients), such as:

  • Debt collectors are forbidden from using abusive language, threats, or harassment to collect debts.
  • Debt collectors can't contact debtors at inconvenient times, such as before 8 a.m. or after 9 p.m.
  • Debt collectors must provide debtors with information about the debt, including the amount owed, the creditor's name, and the process to dispute the debt.
  • Debt collectors cannot misrepresent the amount or legal status of the debt, make false statements, or use deceptive means to collect debts.
  • If a debtor requests in writing that a debt collector stop contacting them, the collector must cease communication except to inform the debtor of specific actions.
  • Debt collectors must provide verification or validation of the debt if the debtor disputes it in writing within 30 days of receiving the initial notice.

Related:HIPAA Compliant Email: The Definitive Guide

Can healthcare providers share PHI with debt collectors? (1)

How to ensure compliance with the FDCPA and HIPAA

  • Adherence to minimum necessary standards: Ensure that any disclosures of PHI to debt collectors are limited to the minimum necessary for debt collection purposes.
  • Ensure secure communication: Ensure that the collection agency as a business associate implements secure communication channels, such asHIPAA compliant email, so that any exchange of PHI with the healthcare provider and patients is protected.
  • Documentation and record-keeping: Maintain records of debt collection activities and communications to verify compliance with FDCPA and HIPAA, including consent for sharing PHI when necessary.
  • Business associate agreements: Establish business associate agreements with collection agencies that outline the responsibilities and expectations concerning PHI handling.
  • Clear communication and patient rights: Clearly communicate patient rights, including the right to request privacy protections and restrictions on the use or disclosure of their health information, ensuring their requests are respected during debt collection processes.

Can healthcare providers share PHI with debt collectors? (2024)
Top Articles
Latest Posts
Article information

Author: Jamar Nader

Last Updated:

Views: 6240

Rating: 4.4 / 5 (75 voted)

Reviews: 82% of readers found this page helpful

Author information

Name: Jamar Nader

Birthday: 1995-02-28

Address: Apt. 536 6162 Reichel Greens, Port Zackaryside, CT 22682-9804

Phone: +9958384818317

Job: IT Representative

Hobby: Scrapbooking, Hiking, Hunting, Kite flying, Blacksmithing, Video gaming, Foraging

Introduction: My name is Jamar Nader, I am a fine, shiny, colorful, bright, nice, perfect, curious person who loves writing and wants to share my knowledge and understanding with you.