A newer version of the platform is available. Please refresh the page.
By: Jeffrey E. Barnett, Psy.D., ABPP
Revised April 2011
Originally published by Div. 42 of APA and was posted at https://www.division42.org/MembersArea/Nws_Views/articles/Mal_RM/Pat_Privacy.html
Overall, psychologists are a group that is very sensitive about privacy and confidentiality. We know that patients fully expect that we will take all steps possible to ensure that all they discuss with us is kept confidential. Patients frequently share with psychologists information they have not shared with their closest friends, family members, or partners and that might be embarrassing or harmful if it were disclosed.
For these reasons the informed consent process in general and an understanding of the limits to confidentiality in particular take on great importance. Clearly, patients have the right to know in advance of discussing sensitive issues any limits to confidentiality that may exist. Knowledge of these limits may have a great impact on what a patient chooses to share or discuss in treatment.
The important issues of informed consent and limits to confidentiality will be addressed in subsequent articles in this series. In this brief article, the focus is on inadvertent breeches of confidentiality which may damage the therapy relationship, create a negative view of psychology and mental health treatment in general, or possibly lead to ethics complaints or malpractice claims.
A patient’s privacy may be violated and confidentiality breeched in a variety of ways, many of which are unintentional. Areas to address and steps to take include:
Soundproofing: Soundproofing our offices is an important detail to attend to so that conversations with patients will not be overheard by those in waiting rooms or outside our office. Careful attention to soundproofing walls, doors, and ceilings will help prevent such invasions of privacy. The use of a ‘white noise’ machine outside the door of one’s office and the use of soft music in the waiting room may help as well. Additionally, there are many commercially available self-contained waterfalls that can be placed in one’s waiting room. These can make the relaxing sounds of falling water that many in the waiting room may find to be soothing, while creating a white noise effect and helping to prevent those in the waiting room from hearing conversations in treatment rooms.
Office Planning: Placing a receptionist or secretary in the same area as waiting patients creates a great threat to patient privacy. If office staff are making or receiving telephone calls in the presence of patients or others in the waiting room sensitive information may be disclosed. Telephone conversations concerning patient information, insurance and billing, and appointment scheduling should all be done in private. Placing office staff behind a movable glass partition is helpful so that patients may be greeted but also privacy may be maintained. Placing a receptionist or secretary in the waiting room along with waiting patients may seem very welcoming and make it easier for the staff member to greet patients as they arrive. But, such an arrangement places confidentiality at risk. The staff member may be typing correspondence to a patient or referral source, may need to make or return telephone calls in which confidential information is discussed, and the scheduling of appointments may take place within earshot of other waiting patients. Some professionals even have a separate entrance to their office suite and a separate exit. This enables patients to leave the office without needing to go through the waiting room again. This step seems far above minimally expected standards, but if it is possible, it provides an additional layer of protection of each patient’s privacy.
Where one has their office is relevant as well. For example, having a home office in a rural area where most residents know each other’s vehicles by sight may not be a prudent plan. Instead, it would be better to have one’s office in a multiuse professional building that has several businesses in it. Many of these buildings may have insurance agents, accountants, medical practices, and a wide range of other businesses in them. Thus, if a patient is parked at such a building it would not be possible for others to know which business they are visiting.
Access to Records: All patient records should be safeguarded so that unauthorized access to them will be prevented. Records should be stored in locked cabinets with access to the keys tightly restricted. Leaving one’s session notes on one’s desk over night may give the cleaning crew or others access to treatment information. Office staff should be instructed in the steps to take to maintain patient confidentiality.
How records are stored becomes a challenge when large amounts of paper records are kept over a number of years. A busy practice may run out of storage space in their file cabinets. Practitioners may be tempted to keep boxes of patient records in their garage or basement. Such an action is never considered appropriate. Instead, if paper records must be kept and storage space at one’s office is limited, renting a storage space at a secure facility is recommended. But, many professionals are digitizing paper records by scanning them and then storing them electronically (challenges with regard to this are addressed below) as a means of saving physical space and for increasing ease of access to them.
Discussion of Patients: The discussion of patients with others should be consistent with the APA Ethics Code (APA, 2010) and relevant state laws. Steps should be taken to protect each patient’s anonymity even when consulting with colleagues and consultation is best carried out in a private setting. Discussion of patients with family, friends, and others should be avoided. Those with a need to vent about one’s day may wish to seek out a peer support group or personal psychotherapy. While the demands of being a mental health clinician may be great it is never appropriate to share about the details of one’s day with family members or friends. The desire or need to do so may be seen as a sign for the need for better ongoing self-care, possible limit setting with regard to one’s work load, and the need for professional consultation or assistance.
Use of Technology:
Fax Machines: When using fax machines to send evaluations, reports, and other patient-related information it is important to ensure that steps are taken to prevent inadvertent disclosures of confidential information. The use of preprogrammed speed dialing will help avoid misdialing and having sensitive information being sent to the wrong individual. Because a fax may not reach the intended recipient the use of a cover sheet is recommended. Brockman and VandeCreek (1994) recommend it state who sent the fax, who is to receive it, the number of pages, a statement regarding redisclosure, a statement regarding destruction of the fax, and verification instructions. Verifying who will have access to the fax machine on the receiving end will also help to prevent unintended disclosures from occurring.
Computers: All patient records should be protected by a password and, if possible, encryption. Like all other treatment records computer disks should be stored in a locked cabinet. It is also important not to leave patient information on the computer’s monitor when leaving one’s work area. Merely erasing used disks may not prove sufficient since they may be restored and the data accessed by those with certain computer skills. The use of a program to ‘wipe’ used disks is recommended. The same is true when disposing of an old hard drive. Merely deleting files is insufficient and having the hard drive ‘wiped’, that is having every space of memory imprinted with random characters in place of the information that had previously been there, is essential.
When using computers for record keeping it is important that all documents be backed up as a precaution against computer failure and the possible loss of important records. A wide range of external back up services are available that use encryption and only allow access with the appropriate password that you set. Representative companies that provide off site electronic storage and back up of computer data include Carbonite (www.carbonite.com), Mozy (www.mozy.com), Back Blaze (www.backblaze.com), Crash Plan (www.crashplan.com), and Iron Mountain (www.ironmountain.com). No endorsement of any particular company is provided here. These companies are regulated under the American Recovery and Reinvestment Act of 2009. This requires that they have HIPAA compliant safeguards in place, that they report all breaches of security to you, that they account for all disclosures to you, and that they destroy protected health information at the end of the contract. Vendors can be disciplined by the federal government for breaches of any of these requirements.
Additionally, when it comes to passwords it is important to be aware that hackers and other potential intruders will be able to figure out simple passwords such as your name, your child or pet’s name, and the like. It is recommended that passwords include letters and numbers with some of them capitalized, as well as several random characters. Further, it is recommended that passwords be changed periodically, at least once every several month. Clearly, computer security should be taken seriously to protect each patient’s privacy and to sufficiently protect confidential information stored in computers.
Email: It is strongly recommended that email not be used as a method for discussing confidential patient information unless the patient is first made aware of the risks and then agrees to this practice. Sussman (1995) states that without encryption email is no more private than a postcard. Quittner (1995) describes it like a vault with a screen door on the back. If confidential information must be shared via email the use of encryption is recommended. At present, a number of companies offer Email encryption software that can make the use of Email a relatively secure medium. Examples of Email encryption programs include Hushmail (www.hushmail.com), TrueCrypt (www.truecrypt.org), BestCrypt Enterprise (www.jetico.com/data-protection-encryption-bestcrypt-enterprise), and PGP Whole Disk Encryption (www.symantec.com/index.jsp). Other companies exist that provide this service as well. These are representative examples and not endorsement of any of them is implied. But, for those who use Email to communicate with patients or about patients encryption software is strongly recommended.
For those mental health professionals with questions about HIPAA compliance requirements, it is important to note that HIPAA compliance is required when a health professional sends protected health information by electronic means. Yet, when using encryption what is sent is not protected health information, just scrambled characters that are unintelligible to anyone without the ability to decrypt the message (this requires use of the same encryption program and a password provided by the health care provider). Thus, one would not be required to be HIPAA compliant if all electronic submissions are sent in an encrypted form (Harris & Younggren, 2011).
Telephones and Answering Machines: Conversations on cellular and wireless telephones may easily be listened in on. There are reports of individuals hearing cellular telephone conversations over AM radios and nursery monitors. Confidential patient information should not be discussed on such phones. Answering machines should be kept in a secure location so unauthorized individuals won’t have access to them. With voice mail, the use of a restricted pass code is recommended so that access to patients’ messages will be restricted. As part of each patient’s informed consent process find out at which number they would like to be called should you need to contact them between regularly scheduled appointments and if confidential messages can be left on the voice mail system at that number. Not all patients will want others to know they are in treatment with a mental health professional. Some will want to be contacted at home, some at work, and some via their cell phone. But, it is their choice and we must find out their preferences at the beginning of the professional relationship to ensure that their privacy rights and expectations are not violated.
Disposal of Records: This should be done in accordance with the clinician’s profession’s code of ethics and relevant state laws. Each jurisdiction will have in their laws a specific period of time that all health care records must be maintained. At the end of that period of time (typically anywhere from 5 to 7 years from the date of last professional contact) the record may then be destroyed. That does not mean that the record must be destroyed, but that it may. Additionally, a method such as shredding should be used before documents are disposed of. One certainly does not want ripped trash bags and spilled garbage cans to lead to unintended invasions of privacy.
Attention to these issues is of importance to mental health professionals in our quest to attend to our patients’ welfare. The use of well thought out office policies, attention to the physical considerations of our offices, and the careful use of the many technologies available to us will help practitioners to avoid unauthorized releases of confidential information and inadvertent violations of our patients’ privacy.
References
American Psychological Association. (2010). Ethical principles of psychologists and code of conduct. Accessed at website: www.apa.org/ethics.
Brockman, R.A. and VandeCreek, L. (1994). Technology and confidentiality in the office. The Psychotherapy Bulletin, 28, 53-56.
Quittner, J. (February 27, 1995). Cracks in the internet. Time, 33-45.
Sussman, V. (January 23, 1995). Policing cyberspace. U.S. News and World Report, 55-60.
Harris, E. A., & Younggren, J. N. (2011). Adventures on the electronic frontier: Ethics and risk management in the digital era. Continuing education workshop provided by the APA Insurance Trust, Beltsville, Maryland.