Reporting doesn’t have to be a direct medical service. It can be used for studies unrelated, used by pharma, used by medical device companies and whether you have phi in the report themselves you house the underlying data in your databases. Exposing that or leaking that is an infraction covered under the protection of hipaa. If you’re in a call center and you expose it, if you’re in IT and you email it unencrypted, if it’s exposed on an open port, it all falls under that protection
Reporting doesn’t have to be a direct medical service. It can be used for studies unrelated, used by pharma, used by medical device companies and whether you have phi in the report themselves you house the underlying data in your databases. Exposing that or leaking that is an infraction covered under the protection of hipaa. If you’re in a call center and you expose it, if you’re in IT and you email it unencrypted, if it’s exposed on an open port, it all falls under that protection