HIPAA and social media compliance requires HIPAA Covered Entities and Business Associates to prevent the use or disclosure of protected health information in public posts, comments, images, videos, and messages unless a valid written authorization permits the disclosure.
How HIPAA Applies To Social Media
The HIPAA Privacy Rule does not contain platform specific requirements for social networks, but the HIPAA Privacy Rule standards for permitted uses and disclosures apply to any communication channel. Publishing protected health information to the public is not a permitted use or disclosure under routine HIPAA operations, so social media posts that include protected health information are prohibited unless a valid written authorization allows the disclosure.
The HIPAA Security Rule applies when electronic protected health information is created, received, maintained, or transmitted in a way that makes it subject to required administrative, physical, and technical safeguards. A workforce member who captures protected health information from a workplace system and uploads it to a social media account introduces an electronic protected health information handling pathway that typically lacks required safeguards and organizational control.
Protected Health Information Risks In Social Media Content
Protected health information can be disclosed through direct identifiers and through combinations of details that allow a person to be identified. Images and videos create added risk because backgrounds may include faces, name bands, documents, screens, room numbers, schedules, or other contextual details that connect an individual to care.
Text posts can also disclose protected health information without naming the patient. A description of a diagnosis, injury, procedure, admission, or encounter date can identify an individual when combined with location, occupation, relationship, or other contextual details.
Corporate Accounts and Personal Accounts
HIPAA exposure can occur through corporate accounts and personal accounts. A workforce member posting protected health information from a personal account can still create an impermissible disclosure and can also reflect unauthorized acquisition of protected health information from organizational systems or spaces.
Workforce members who do not have system access can still disclose protected health information through social media by referencing names, conditions, locations, or events learned through workplace conversations or observations.
Social Media Interactions with Patients and the Public
Public comments and direct messages create compliance risk when staff respond with protected health information or confirm a patient relationship. Even a response intended to address a complaint can disclose protected health information if it includes treatment details, scheduling information, billing information, or other individually identifiable health information.
Organizations often restrict staff from engaging in patient specific discussions on public social media channels and route service complaints and patient communications to approved channels with documented processes and safeguards.
Business Associate Considerations
Business Associates that manage social media activities, analytics, reputation management, or customer support functions can encounter protected health information through reviews, screenshots, ticketing systems, message forwarding, or shared files. Business Associate staff need role specific procedures that prevent the creation, use, or disclosure of protected health information through social platforms and that define escalation steps when protected health information appears in user generated content.
Business Associate Agreements and subcontractor controls need to address whether any protected health information is expected to be handled in connection with social media activities, and they need procedures for incident reporting when protected health information is exposed through social media related workflows.
Policy Controls and Workforce Training
A HIPAA and social media policy needs to define prohibited content, approval requirements for organizational posts, restrictions on photography and video recording in patient care areas, and restrictions on patient engagement through public comments and direct messages. The policy also needs a sanctions framework for impermissible uses and disclosures tied to social media activity.
Workforce training needs to address how protected health information is disclosed through images, background details, and contextual statements, and it needs to reinforce that social media rules apply to both corporate and personal accounts when protected health information is involved. Training should be provided to all staff in contact with protected health information and should include job specific scenarios for clinical staff, front desk staff, call center staff, marketing teams, and information technology personnel.
Monitoring and Incident Response
Organizations often monitor social media channels for references that indicate potential disclosures, including facility related tags and public posts that contain patient identifying details. Monitoring does not replace controls that prevent posting protected health information, but it can support earlier detection and internal reporting.
When protected health information appears on social media, internal response procedures should address containment steps where possible, documentation, risk assessment, and evaluation under the HIPAA Breach Notification Rule when unsecured protected health information may have been impermissibly disclosed.
HIPAA and Social Media FAQs
What is “non-health information”?
Non-health information is more commonly referred to as the 18 HIPAA identifiers that need to be removed from a designated record set before any health information left in the set is deidentified. These days, there are more than 18 pieces of non-health information that could be used to identify an individual, and while any are maintained with health information they are protected.
What is the connection between the FTC, HIPAA, and Social Media?
The FTC was given the authority in the HITECH Act to take enforcement action against noncompliant organizations that are not Covered Entities or Business Associates (i.e., vendors of electronic health devices). While FTC enforcement action is usually limited to violations of the Breach Notification Rule, the agency has imposed fines on organizations who have misrepresented consumer privacy.
Do all employees have to be trained on social media policies?
In theory, any member of the workforce can violate HIPAA within seconds by taking a photo of a patient and posting it on a social media channel. Alternatively, any member of the workforce could prevent a HIPAA violation by stopping a colleague from posting a patient´s photo on social media. For these reasons, all employees should be trained on the organization´s social media policies.
If an image of an injury is attached to a Tweet with no identifying information, is this still a violation of HIPAA?
This depends on whether a written authorization has been obtained from the patient to publish the image on social media and the patient understands that the authorization cannot be revoked because the organization has no control over how the image is used or disclosed once it is in the public domain. If these conditions have not been met, the Tweet is a violation of HIPAA.
Do HIPAA and social media rules apply to personal accounts or just corporate accounts?
HIPAA and social media rules apply to all types of accounts. Furthermore, if an impermissible disclosure occurs via a private social media account, questions may be raised by HHS´ Office for Civil Rights about how the account holder got unauthorized access to PHI or how the account holder was able to misuse their authorized access to PHI.
