A billing analyst emails an unencrypted spreadsheet of claim denials that includes patient names and account numbers to a personal Gmail account to finish work at home. What is the correct HIPAA security assessment?
Select an answer to reveal the explanation.
Short Explanation
Personal Gmail isn't a secure tunnel for patient-named denial files. If the spreadsheet has identifiers, it needs the practice's approved encrypted path—not a convenience send to finish work on the couch.
Full Explanation
The HIPAA Security Rule requires appropriate safeguards for electronic PHI, including transmission security. Emailing unencrypted files containing patient identifiers to a personal account exposes PHI outside approved systems and controls. Workforce members should use organization-approved secure email, VPN, or encrypted portals and avoid removing identifiable claim data to personal accounts.