twitter




Monday, October 12, 2009

Is sending confidential personal profile data to an email address dangerous?

If someone request for a copy of their personal profile data (in the database) from the admin staff, can they send it by email?
Is sending confidential personal profile data to an email address dangerous?
I would send it in a file with password protection...
Reply:The Data Privacy Act and HIPAA (Health Information Portability and Accountability Act) allows each organization to make this determination for themselves, so long as personal identifying information remains secure within reason. The social services organization I work at, for example, would not send the entire completed government/social service form(s) to someone via e-mail. However, informal correspondence and inter-agency forms between clients and our agency is permitted.





When using e-mail, we use a client's initials in the e-mail. Or another ID number in the file.





Check with your HR administrator if your organization is accountable to the above mentioned federal laws.





Hope this helps!

No comments:

Post a Comment