Skip to site content

FAQs

1. Q: How can IHS employees, students, volunteers, and contractors securely send PHI or PII by email?

A: When sending protected health information (PHI) or personally identifiable information (PII) electronically, IHS workforce members must use an approved secure transmission method. IHS-approved options include Microsoft Purview Message Encryption for encrypted email or the IHS Secure Data Transfer System (SDTS) for securely transferring sensitive information.

Do not send PHI or PII through unencrypted email.

2. Q: How do I report a suspected HIPAA Privacy violation?

A: If you become aware of a suspected or actual HIPAA Privacy violation involving protected health information (PHI), report the incident promptly in accordance with the IHS Incident Reporting Standard Operating Procedure (SOP 09-02).

Follow the reporting procedures and instructions provided in SOP 09-02, Incident Reporting to ensure the incident is reported to the appropriate IHS officials for review and response.

Reference: IHS SOP 09-02 - Incident Reporting

3. Q: What should I do if I am unsure whether I can use, access, or disclose information?

A: Contact your Area or Service Unit Privacy Official for guidance before accessing, using, or disclosing the information. When in doubt, stop and protect the information until you receive appropriate guidance.

4. Q: Can I access a patient or employee record if I have system access?

A: No. Having access to an IHS system does not authorize you to access every record in that system. Access PHI, PII, and other protected records only when necessary to perform your assigned official duties.

5. Q: What should I do if I accidentally send PHI or PII to the wrong person?

A: Report the suspected privacy incident promptly through the IHS Privacy Incident Report process. Do not wait to determine whether the unintended recipient opened or used the information, and do not investigate the incident yourself.

6. Q: Does HIPAA apply to all personal information maintained by IHS?

A: No. HIPAA applies to protected health information (PHI) maintained by IHS in its role as a HIPAA covered entity. Other personal information may be protected by the Privacy Act of 1974, 42 CFR Part 2 when applicable, other federal laws and regulations, and IHS policies.

7. Q: Do HIPAA and the Privacy Act both apply to IHS patient records?

A: They may. IHS patient records may be subject to both HIPAA, the Privacy Act and if applicable 42 CFR Part 2. When more than one privacy law applies, all applicable requirements must be considered before information is used or disclosed.

8. Q: Are all records containing substance use disorder information protected by 42 CFR Part 2?

A: They may. IHS patient records may be subject to HIPAA and the Privacy Act and, when applicable, 42 CFR Part 2. When more than one privacy law applies, all applicable requirements must be considered before the information is used or disclosed.

9. Q: Can I release patient information when law enforcement presents a badge, subpoena, warrant, or other official request?

A: Do not automatically release patient information in response to a law enforcement request, subpoena, warrant, or other legal request. Protect the information and follow IHS procedures by routing the request to the appropriate IHS official for review before disclosure.