Every prescription begins its journey before the patient walks away with their medication. E-Prescribing: A Focused Review and New Approach to Addressing Safety in Pharmacies and Primary Care explains, “E-prescriptions are generated within e-prescribing systems and are electronically transmitted to pharmacies via a secure network between prescribers and pharmacies.” The obligation to protect privacy starts sooner than dispensing at the pharmacy and often extends into later correspondence and services.

HIPAA attaches to covered entities and their business associates’ use of medication information, not to the medication itself. Health care providers are covered entities, as are many pharmacies and health plans. Protected health information (PHI) is individually identifiable health information held or transmitted by one of those entities. It does not control the actions a patient takes with the bottle, but it does restrict the pharmacy’s record of those actions.

 

The protected path continues through treatment and payment

The same review states, “In primary care settings, e-prescriptions are electronically entered and sent to the pharmacy of the patient’s choice.” Covered entities may share that information among themselves, with supporting vendors, or with the patient. HIPAA treats each use differently. HIPAA’s Privacy Rule allows uses and disclosures to facilitate treatment, payment, and health care operations without separate patient authorization. Minimum necessary standards apply to payment and operations, but not to provider-to-provider treatment disclosures or disclosures to the patient. Email should be used for the same purposes. Staff should know why they are sending the message and resist the temptation to add unrelated information from the prescription history. Including only what is necessary for the next step reduces exposure while making follow-up easier.

 

Caregiver access should match the patient’s needs

Patients’ Memory for Medical Information reports, “Forty to eighty percent of medical information provided by healthcare practitioners is forgotten immediately.” A caregiver may remind patients of instructions, help them keep track of refills, or fill a similar supportive role. Those responsibilities do not automatically entitle a caregiver to unrestricted access to the patient’s medical record.

The Privacy Rule allows a pharmacy to disclose information relevant to another person’s involvement in the patient’s care or payment. For example, professionals may exercise their judgment when disclosing information to a caregiver if the patient is unavailable or unable to make that decision. Their judgment also guides pharmacy decisions about customers who are not picking up their own prescriptions. When email is part of that follow-up, document the patient’s preference and confirm that any caregiver can receive those specific details. Email only the instructions or coordination advice the person needs. Staff can use a secure follow-up to reinforce home care instructions while creating a record of what was sent.

 

Home delivery adds privacy handoffs

Trends and Contributing Factors in Medication Home Delivery Incidents in Community Pharmacies Before and After COVID-19 examined 156 reported home-delivery incidents. Privacy incidents comprised 29.2% of reported incidents before COVID-19, compared to 41.6% after the pandemic began. Remember that this data describes analyzed incidents, not the likelihood of any delivery having a privacy problem. However, it does highlight why privacy incidents should concern pharmacies.

Delivering to the wrong address exposes prescription information. Leaving an email label where someone can see it does the same. Sending a delivery photo to the wrong person bypasses protections that the pharmacy might have otherwise applied. Businesses should review their address verification procedures, limit delivery-related notifications, and define proof-of-delivery requirements to prevent mismatches.

Business associate status depends on how vendors use any information they handle. A shipping or delivery company acting only as a transportation intermediary for the pharmacy does not become a business associate by doing that work. A fulfillment vendor that handles PHI on the pharmacy’s behalf may be a business associate that requires a business associate agreement. The commentary to the HIPAA Omnibus Rule clarified that relationship, so pharmacies should evaluate the actual flow of data.

 

Refill reminders are permitted, with limits

Engagement With Text Messaging Improves Cardiovascular Medication Adherence: Secondary Analysis of a Randomized Controlled Trial found, “Any engagement was associated with shorter medication gap lengths, and higher medication adherence at 12 months.” Note that this was a secondary analysis with limits on its ability to prove causation. Engaged patients tended to adhere to their medication routines better, but the study does not prove that reminders cause better adherence. However, it does support making reminders noticeable and easy to act on.

Reminder emails that tell patients to refill their prescriptions do not qualify as marketing if compensation for the communication is reasonable and related to the covered entity’s costs to perform such communication. Reminder services that provide broader health marketing or receive compensation beyond cost-covered limitations need to be reviewed separately. Those that require payment may also require patient authorization.

Send refill reminders that explain what patients should do, where they can go for help, and avoid including clinical information in the subject line. Respect patients’ communication preferences and right to opt-out. Teams can reduce opportunities for missed refills without turning health care communication into unwanted marketing.

 

Consumer apps can mark the edge of HIPAA protection

Data Sharing Practices of Medicines Related Apps and the Mobile Ecosystem: Traffic, Content, and Network Analysis found that 19 of 24 sampled medication-related Android apps, or 79%, shared user data with third parties. Researchers studied a purposive sample in 2017, not every app available at every app store today. Nevertheless, health-related apps often run outside HIPAA simply because they are not provided by or for a covered entity.

Business associates must help covered entities comply with HIPAA. Apps that transmit information to a covered entity may be business associates themselves. A patient choosing to send prescription information to an app not offered by their pharmacy inserts another privacy boundary between the pharmacy and the app’s data practices. At that moment, HIPAA ceases to apply to the information the app receives, according to HHS. The app’s owners may have other privacy obligations, but HIPAA no longer governs.

Doctors can help patients understand that distinction before they send prescription information to unprotected apps. They could send a secure email to the patient offering general guidance about using apps. Message content can link to the app, identify who provides the service, and warn the patient that their selection may have different privacy practices. Patients can make informed decisions without assuming all medical apps have the same limitations.

 

Build the email workflow around the prescription journey

Innovations in Practice: Telepharmacy’s Time Has Arrived states, “The pharmacist and patient must be in a private area for the consultation.” For email, the organization should similarly control who can send, receive, and retrieve the information.

HHS has confirmed providers can email patients if they apply reasonable safeguards as defined in the Security Rule. Its guidance suggests verifying the email address, not including PHI in unencrypted emails, and respecting reasonable requests to communicate by other methods.

A HIPAA compliant email gateway such as Paubox builds those security and policy standards around existing email practices. Staff can send and receive prescription emails without developing a new privacy practice every time the information travels outside the pharmacy.

 

FAQs

Can pharmacies give patients their prescription records?

Yes, patients have the right to access their prescription records that are part of the pharmacy’s designated record set, with limited exceptions.

 

Should patients remove prescription labels before throwing them away?

HIPAA does not apply to patients’ disposal of their prescription bottles, but removing or covering the label can prevent accidental exposure of personal information.

 

Are prescriptions still considered PHI if they are deidentified?

No, deidentified information is not considered PHI under HIPAA.

 

What should a pharmacy do if they accidentally email a prescription to the wrong person?

Staff should cease disclosure, report the potential breach according to the organization’s procedures, and complete a risk assessment to determine if patients must be notified of the loss.