HIPAA Handbooks

  • Privacy and security training for new and seasoned staff
  • 11 staff/setting focus areas
  • Education on protecting PHI
  • New HITECH Act changes
  • Discounts on bulk purchases



  • Role-based training using real-life case scenarios
  • Test-your-knowledge exercises with remediation
  • Post-course test to document staff participation


Other HIPAA Resources

  • Hot-topic audio conferences
  • Books on privacy and security
  • Newsletters
  • e-Newsletter
  • Videos



HIPAA Q&A: Accounting of disclosures

Email This Post Print This Post

Q. We are required to report information, including patient account numbers and diagnosis codes, to our state tumor registry. Must we enter each patient’s name into a database to track these as accountable disclosures?

A. Account numbers reported to the state are considered patient-identifiable information. Therefore, you must include them in an accounting of disclosures in response to patient requests. Entering each disclosure into a database is probably not worth the effort. Most healthcare organizations receive very few requests for accounting, so researching individual cases takes less time than entering every case into a database for tracking.

When patients request an accounting, simply review their records to determine whether diagnoses include those that would have been reported to the state tumor registry.

Editor’s note: Mary D. Brandt, MBA, RHIA, CHE, CHPS, a nationally recognized expert on patient privacy, information security, and regulatory compliance, answered this question. Brandt is associate executive director of HIM at Scott & White Healthcare in Temple, TX. Some of her publications were used as a basis for HIPAA privacy regulations. Advice given is general. Readers should consult professional counsel for specific legal, ethical, or clinical questions.

Leave a Reply