HIPAA Compliance When Selling Medical Imaging Equipment... Delete Patient Data!
Anyone selling used medical imaging equipment needs to be proactive about maintaining HIPAA compliance and taking all necessary steps to protect patient data.
The Health Insurance Portability Accountability Act of 1996 (HIPAA) protects the privacy of patient data. The rule that is most applicable to the medical imaging community or radiology managers is the so called “HIPAA Privacy Rule.” The rule basically requires all “covered entities” (which includes just about anyone owning or operating medical imaging equipment) to protect all “individually identifiable health information;” this is called protected health information (PHI).
Protected Patient Information is Usually Stored in Medical Imaging Equipment
What type of information is on your piece of medical imaging equipment? You would expect (and you would almost certainly be right) that your digital era machines probably have dozens of patient images produced by the scans and studies being run in your facility. Most likely, your machine will also have dozens of patients’ data stored in companion info files too! These files may stay on your machine after images are removed.
When the Equipment Leaves Your Facility, it is Your Responsibility to Clear Patient Data
While a scanner is in your facility, the compliance-minded radiology or imaging center manager will ensure that patients’ PHI is closely guarded. However, that machine will not be in your facility forever.
When it comes time to trade in or sell your imaging equipment on the secondary market (see here for a free FMV), it is your responsibility to delete patient PHI.
How Do You Delete Patient Data?
The simple answer is that it depends on the equipment. On some machines, by simply deleting the patient images, you will also delete the associated info files. On others, there may be a separate location where patient data is stored.
One thing is for sure: you want to be careful when deleting information from your machine... The operating software for your machine is often on the same hard drives as the patient data and could be removed inadvertently and unless you plan on making your machine an expensive paperweight, that software needs to be preserved.
Since there is no one-size-fits-all solution, here are your options:
- Option A - Contact Block Imaging who has experience with hundreds of makes and models (too many to list here)
- Option B - Check with your regular engineer/service provider
- Option C - If you are selling your equipment, sell to a buyer who will agree to do it for you (and actually do it!)
Meet the author - Adam Desjardins
Browse related blog articles by category