• FreeAdvice has a new Terms of Service and Privacy Policy, effective May 25, 2018.
    By continuing to use this site, you are consenting to our Terms of Service and use of cookies.

Medical Lab is seriously violating HIPAA but refuses to change

Accident - Bankruptcy - Criminal Law / DUI - Business - Consumer - Employment - Family - Immigration - Real Estate - Tax - Traffic - Wills   Please click a topic or scroll down for more.

throwaway12453

New member
I'm in a serious situation where I discovered early on in my time at a medical research lab that my employers are storing their patient information (life events, phone numbers, names, dicoms) through unsecure means (like Dropbox, but also on a variety of other methods), which is 100% not approved by the institution and I'm positive this is not HIPAA safe. I brought this to my PI's attention and she was completely dismissive of the problem. She said it's not something to worry about even though I told her I spoke with the privacy department at our institution and they confirmed if we were doing the exact things we are doing then we are violation of HIPAA. It's not even a question of if I misunderstood something. This violation is obvious and at a massive scale. What I want to know is: What is the most likely scenario if I report them? Will I face ramifications in any way if I'm the one reporting? I'm a pretty low level staff member at the lab.

State: CA
 
Last edited:


Just Blue

Senior Member
I'm in a serious situation where I discovered early on in my time at a medical research lab that my employers are storing their patient information (life events, phone numbers, names, dicoms) through unsecure means (like Dropbox, but also on a variety of other methods), which is 100% not approved by the institution and I'm positive this is not HIPAA safe. I brought this to my PI's attention and she was completely dismissive of the problem. She said it's not something to worry about even though I told her I spoke with the privacy department at our institution and they confirmed if we were doing the exact things we are doing then we are violation of HIPAA. It's not even a question of if I misunderstood something. This violation is obvious and at a massive scale. What I want to know is: What is the most likely scenario if I report them? Will I face ramifications in any way if I'm the one reporting? I'm a pretty low level staff member at the lab.
What state?
 

FlyingRon

Senior Member
What sort of "medical research labs?" Are you even a covered entity under HIPAA? Just because you have human patients doesn't necessarily make you one, you have to be involved with electronic medical billing.
 

quincy

Senior Member
What sort of "medical research labs?" Are you even a covered entity under HIPAA? Just because you have human patients doesn't necessarily make you one, you have to be involved with electronic medical billing.
Even if not a HIPAA-covered entity (and apparently the "privacy department of the institution" believes it is), California's privacy laws are potentially violated by the medical research lab's treatment of patients' personal identifying documents.
 

Find the Right Lawyer for Your Legal Issue!

Fast, Free, and Confidential
data-ad-format="auto">
Top