Thoughts on Patient-Physician Email (Part 3)
- Many patients would like to email their physicians.
- Many physicians are either unfamiliar with email or uncomfortable with giving patients the additional access that email provides.
- Email has the potential to strengthen the physician-patient relationship and improve both patient education and the quality of care.
- The HIPAA privacy law prohibits email between physicians and patients unless this communication is encrypted.
- Many commercial solutions for encrypted email between physicians and patients exist. Unfortunately, many of these solutions are either expensive, proprietary, and/or cumbersome to use. (If you would like to suggest a commercial email system that is inexpensive/free and easy to use, please comment.)
- Encrypted email systems that are cumbersome to use and/or require an elaborate login process will frustrate patients and discourage them from emailing providers.
- Many patients would prefer to use plain, unencrypted email to communicate with their physicians.
Different institutions have come up with their own solutions to this problem. This is an excerpt from Yale's Guidance on the Use of Email Containing Protected Health Information:
A provider may obtain informed consent from a patient via electronic messaging (e.g., email) by conducting the following consent exchange upon presentation of a patient query via electronic messaging (this example is for an email exchange):Columbia University also has a policy on email on their HIPAA information page:
I will be happy to respond to your query but to do so via email you must provide your consent, recognizing that email is not a secure form of communication. There is some risk that any protected health information that may be contained in such email may be disclosed to, or intercepted by, unauthorized third parties. I will use the minimum necessary amount of protected health information to respond to your query.
If you wish to conduct this discussion via email, please indicate your acceptance of this risk with your email reply. Alternatively, please call my office to arrange a phone conversation or office visit.
If a patient requests email communications containing their PHI, the individual receiving the request must obtain a completed Request for Email Communications form from the patient AND must provide the patient with the Important Information about Provider/Patient Email form prior to processing the patient’s request.(If you're interested, I've extracted the text from the forms on Kidney Notes.)
If you have other solutions to the problem of physician-patient email, please feel free to comment.



3 Comments:
At Thu Aug 09, 01:42:00 PM 2007,
Huck said…
The HIPPA issues are enlightening.
It will help me to maintain a HIPPA compliant email practice.
Thanks for the tips.
P.S. ORd3R V1@GR@ 8y e-M@il!
Just Kidding on the last part.
At Thu Aug 09, 10:38:00 PM 2007,
enoch said…
kaiser encrypts all outgoing email with PHI using Voltage Security's server based solution: without the sender knowing, it proactively encrypts outgoing email with PHI to ensure HIPPA compliance. This isn't a solution for solo practice docs, but look to the future when the technology becomes less expensive.
At Tue Aug 28, 01:56:00 PM 2007,
CC said…
There is an upcoming HIPPA secure/FREE e-mail and patient registration web site that is going in beta in a matter of weeks. Should be available to all in a matter of months.
If your readers are interested, I'll check back and post progress reports...
Post a Comment
<< Home