To finish charts after hours, a coder emails identifiable operative reports from the hospital account to a personal Gmail address. What is the appropriate compliance conclusion?
Select an answer to reveal the explanation.
Short Explanation
Personal Gmail is not a coding inbox. Shipping identifiable operative details there for later is an unsecured PHI send—full stop. Use approved remote access instead of a private email account.
Full Explanation
Protected health information must be transmitted only through organization-approved, secured channels. Forwarding identifiable clinical documents to personal email circumvents institutional controls and constitutes an impermissible disclosure risk under HIPAA. Discharge status does not remove PHI status, and deletion after the fact does not make the initial transmission compliant.