Healthcare Practice Safety Check

Fareez Mamood, RN · Engineering intelligent solutions to wellbeing

Do not enter patient information anywhere on this page. Nothing here needs it.

Save my contact

Fareez Mamood, RN
954-681-7308
fareez@synlearns.ai

Patient-data safety: where practices get into trouble

Three common ways patient information gets exposed. Sources are the HIPAA rules (45 CFR Part 164) and HHS Office for Civil Rights guidance.

Patient information going to outside servers
Pasting notes into a free or personal AI chatbot, or using an AI, transcription, cloud-storage, texting or email tool for patient information. If an outside vendor creates, receives, stores or sends patient information for you, HIPAA generally requires a signed business associate agreement (BAA) first. Cloud services that store patient information count as business associates even when the data is encrypted and they do not hold the key. Check each vendor's terms for a signed BAA before any patient information goes in. 45 CFR 164.502(e), 164.504(e); HHS OCR, Guidance on HIPAA & Cloud Computing
Records released to the wrong place or in the wrong amount
Sending records to the wrong fax number, email address or person, releasing without a valid patient authorization when one is needed, or sending more than the minimum necessary. Each can be an impermissible disclosure. 45 CFR 164.502(a), 164.502(b), 164.508(a)
What happens after a mistake
An impermissible disclosure is presumed to be a breach unless a documented risk assessment shows a low probability that the information was compromised. Affected patients must be told without unreasonable delay and no later than 60 calendar days after discovery, and HHS must be notified. HHS can impose civil money penalties for violations. 45 CFR 164.402, 164.404(b), 164.408, 160.404

Rules: ecfr.gov, Title 45 Part 164. Guidance: hhs.gov/hipaa. Education only, not legal advice; this page does not tell you whether your practice is or is not in compliance.

Practice safety check (4 minutes)

Two short parts, 21 questions. Answer for the practice as a whole. Your answers are scored in this browser only; nothing is sent or stored.

Part A · Patient-data safety & AI

    Part B · Revenue cycle health

      Prior auth & denials: 2026–2027 quick reference

      From the CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F, 89 FR 8758, Feb 8, 2024).

      Which plans
      Medicare Advantage; Medicaid and CHIP (fee-for-service and managed care); qualified health plans on the federal Exchanges (HealthCare.gov). Commercial and employer plans are not covered. 89 FR 8759, 8760
      Decision deadlines (from 2026)
      Medicare Advantage, Medicaid and CHIP: 72 hours for expedited, 7 calendar days for standard requests. Federal-Exchange plans keep their existing deadlines. 42 CFR 422.568(b)(1), 440.230(e)(1), 438.210(d), 457.495(d)
      Denials must say why (from 2026)
      A denied prior-auth request must come with a specific reason: Medicare Advantage, Medicaid (fee-for-service and managed care), CHIP fee-for-service and federal-Exchange plans. 42 CFR 422.122(a), 431.80(a), 438.242(b)(8), 457.732(a); 45 CFR 156.223(a)
      Public metrics (from 2026)
      Payers publish prior-auth data (drugs excluded) every year by March 31. 42 CFR 422.122(c); 45 CFR 156.223(c)
      Electronic prior auth (from 2027)
      Payers must offer a Prior Authorization API (FHIR). It shows whether auth is needed and what documentation to send, and it accepts requests electronically. Start dates run from Jan 1, 2027 or from the first plan/rating year after it. 42 CFR 422.122(b), 431.80(b), 457.732(b); 45 CFR 156.223(b)
      For clinicians and hospitals (2027)
      A new yes/no "Electronic Prior Authorization" measure starts in MIPS Promoting Interoperability and the Medicare Promoting Interoperability Program. 89 FR 8758, section II.F
      Drugs are excluded
      None of the above applies to drugs of any kind, including pharmacy and medical-benefit drugs. Drug prior auth follows separate rules. 89 FR 8762; 42 CFR 422.119(b)(1)(v); 45 CFR 156.221(b)(1)(v)

      Rule text: federalregister.gov, document 2024-00895; current regulations at ecfr.gov.

      Want to talk it through?

      Leave a note and it opens in your own email app, addressed to me. No form data is stored on this site.