Required section · Section 3 of 6
Privacy, security, records, misconduct, and billing risk
Privacy and security are related but distinct. The HIPAA Privacy Rule governs who may use or disclose PHI and for what purpose; the HIPAA Security Rule (45 CFR 164.308, 164.310, 164.312) separately requires administrative, physical, and technical safeguards for electronic PHI (ePHI). Administrative safeguards cover workforce access authorization, termination procedures, security training, and incident response. Physical safeguards cover workstation and device and media controls, including disposal. Technical safeguards cover unique user identification, audit controls, and transmission security.
Some Security Rule specifications, such as encryption, are addressable rather than flatly required: the entity must assess it, implement it if reasonable, or document an equivalent alternative; addressable is not the same as optional. A locked workstation, a screen turned away from a hallway, an approved encrypted messaging platform instead of personal text or email, and a shredded printout instead of one left at a shared printer are all ordinary applications of these same safeguard categories.
When a report needs a correction, the record is amended, never rewritten. Under 45 CFR 164.526, a patient may request an amendment to PHI, but HIPAA does not authorize deleting or rewriting the original entry; the entity adds a correction, an addendum, or the patient's statement of disagreement, while preserving the original so the record stays auditable. A covered entity may deny an amendment request if it did not create the information, the information is accurate and complete, or it falls outside the designated record set, and a denial must be in writing with appeal rights. The entity generally must act on a request within 60 days, with one 30-day extension allowed if the patient receives a written reason and an expected completion date.
Result manipulation is a separate and more serious problem than a routine correction: silently editing, suppressing, or backdating a result or flag is falsification, not documentation. The laboratory director holds ultimate responsibility under 42 CFR 493.1445 for testing quality, personnel competency, and CLIA compliance across the preanalytic, analytic, and postanalytic phases, and delegating a task does not remove that accountability; the director must run quality control and quality assessment programs and ensure remedial action, including withholding results, when performance deviates from expectation.
Proficiency testing (PT) misconduct is treated the same way: under 42 CFR 493.801, a laboratory may not send a PT sample to another lab for the same analysis, and PT-testing laboratories may not discuss PT results with another lab before the reporting deadline; narrow exceptions apply only when referral would exactly mirror a lab's own written, non-repeat patient-referral procedure, and even then CMS treats it as a sanctionable violation, with intentional PT referral grounds for CLIA certificate revocation for at least one year.
Competency assessment has its own integrity requirement: for nonwaived testing, CLIA requires six documented elements (direct observation of testing, monitoring of result recording and reporting, records review, direct observation of instrument maintenance, blind or PT-type sample performance, and problem-solving assessment), documented per test at least semiannually in the first year and at least annually after that; training records or annual reviews alone do not satisfy it.
Billing and coding sit outside the bench but rest on what the bench reports. The False Claims Act (31 U.S.C. 3729-3733) creates civil liability for knowingly submitting or causing submission of a false or fraudulent claim, including claims for medically unnecessary testing or tests never actually performed; 'knowingly' includes actual knowledge, deliberate ignorance, or reckless disregard, not only specific intent to defraud.
The Anti-Kickback Statute (42 U.S.C. 1320a-7b(b)) criminally prohibits offering, paying, soliciting, or receiving payment to induce or reward referrals of federally reimbursable testing, and a claim tainted by a kickback is treated as a false claim. CMS coverage guidance expects a test to be ordered by an authorized treating practitioner, supported by documented clinical information, and reasonable and necessary for managing the patient's condition; an order alone does not establish medical necessity.
Gifts, vendor relationships, research use of specimens, and genetic information all carry their own boundary. A vendor gift or hospitality that could be seen as influencing test selection or referral is a conflict-of-interest question, governed locally by dollar thresholds and disclosure forms that vary by institution. Research use of a specimen or its data is governed separately under the revised Common Rule (45 CFR 46, particularly 46.116(c)(8)), which requires research consent to state whether clinically relevant individual research results, including incidental findings, will be returned to participants and under what conditions.
The Genetic Information Nondiscrimination Act (GINA) restricts use of genetic information in health insurance underwriting and employment decisions, but it does not cover life, disability, or long-term care insurance, and its incidental-collection exception does not apply when collection is reasonably anticipated.
Treat every one of these boundaries the same way you treat a specimen label, correct if wrong, never altered after the fact, and escalate rather than guess when a request does not fit a category you recognize.
Illustrative drawing — this picture was drawn rather than captured.
| Category | Examples | Implementation status |
|---|---|---|
| Administrative | Workforce access authorization, termination procedures, security training, incident response | Required |
| Physical | Workstation controls, device and media disposal and reuse controls | Required |
| Technical | Unique user ID, audit controls, transmission security | Required |
| Encryption (a technical specification) | Encrypting ePHI in transit or at rest | Addressable: assess it, implement if reasonable, or document an equivalent alternative |
| Pattern | Why it draws scrutiny |
|---|---|
| Standing panel orders without individualized justification | No documented clinical reason ties the panel to this specific patient's condition |
| Fixed-frequency testing regardless of condition | Testing interval is set by a schedule rather than by clinical need |
| Tests ordered by marketers rather than treating clinicians | The order did not originate from a practitioner managing the patient's care |
Knowledge checks
Reading and checks are open. Sign in only to save.
Knowledge check 1
Knowledge check 2
Knowledge check 3
Knowledge check 4
Section status
Finish this section
Reading and checks are open. Sign in only to save.
The module finishes after every required section is marked done and every check in those sections is correct.