Healthcare Practice Safety Check
Fareez Mamood, RN · Engineering intelligent solutions to wellbeing
Save my contact
Fareez Mamood, RN
954-681-7308
fareez@synlearns.ai
Patient-data safety: where practices get into trouble
Three common ways patient information gets exposed. Sources are the HIPAA rules (45 CFR Part 164) and HHS Office for Civil Rights guidance.
- Patient information going to outside servers
- Pasting notes into a free or personal AI chatbot, or using an AI, transcription, cloud-storage, texting or email tool for patient information. If an outside vendor creates, receives, stores or sends patient information for you, HIPAA generally requires a signed business associate agreement (BAA) first. Cloud services that store patient information count as business associates even when the data is encrypted and they do not hold the key. Check each vendor's terms for a signed BAA before any patient information goes in. 45 CFR 164.502(e), 164.504(e); HHS OCR, Guidance on HIPAA & Cloud Computing
- Records released to the wrong place or in the wrong amount
- Sending records to the wrong fax number, email address or person, releasing without a valid patient authorization when one is needed, or sending more than the minimum necessary. Each can be an impermissible disclosure. 45 CFR 164.502(a), 164.502(b), 164.508(a)
- What happens after a mistake
- An impermissible disclosure is presumed to be a breach unless a documented risk assessment shows a low probability that the information was compromised. Affected patients must be told without unreasonable delay and no later than 60 calendar days after discovery, and HHS must be notified. HHS can impose civil money penalties for violations. 45 CFR 164.402, 164.404(b), 164.408, 160.404
Rules: ecfr.gov, Title 45 Part 164. Guidance: hhs.gov/hipaa. Education only, not legal advice; this page does not tell you whether your practice is or is not in compliance.
Practice safety check (4 minutes)
Two short parts, 21 questions. Answer for the practice as a whole. Your answers are scored in this browser only; nothing is sent or stored.
Prior auth & denials: 2026–2027 quick reference
From the CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F, 89 FR 8758, Feb 8, 2024).
- Which plans
- Medicare Advantage; Medicaid and CHIP (fee-for-service and managed care); qualified health plans on the federal Exchanges (HealthCare.gov). Commercial and employer plans are not covered. 89 FR 8759, 8760
- Decision deadlines (from 2026)
- Medicare Advantage, Medicaid and CHIP: 72 hours for expedited, 7 calendar days for standard requests. Federal-Exchange plans keep their existing deadlines. 42 CFR 422.568(b)(1), 440.230(e)(1), 438.210(d), 457.495(d)
- Denials must say why (from 2026)
- A denied prior-auth request must come with a specific reason: Medicare Advantage, Medicaid (fee-for-service and managed care), CHIP fee-for-service and federal-Exchange plans. 42 CFR 422.122(a), 431.80(a), 438.242(b)(8), 457.732(a); 45 CFR 156.223(a)
- Public metrics (from 2026)
- Payers publish prior-auth data (drugs excluded) every year by March 31. 42 CFR 422.122(c); 45 CFR 156.223(c)
- Electronic prior auth (from 2027)
- Payers must offer a Prior Authorization API (FHIR). It shows whether auth is needed and what documentation to send, and it accepts requests electronically. Start dates run from Jan 1, 2027 or from the first plan/rating year after it. 42 CFR 422.122(b), 431.80(b), 457.732(b); 45 CFR 156.223(b)
- For clinicians and hospitals (2027)
- A new yes/no "Electronic Prior Authorization" measure starts in MIPS Promoting Interoperability and the Medicare Promoting Interoperability Program. 89 FR 8758, section II.F
- Drugs are excluded
- None of the above applies to drugs of any kind, including pharmacy and medical-benefit drugs. Drug prior auth follows separate rules. 89 FR 8762; 42 CFR 422.119(b)(1)(v); 45 CFR 156.221(b)(1)(v)
Rule text: federalregister.gov, document 2024-00895; current regulations at ecfr.gov.
Want to talk it through?
Leave a note and it opens in your own email app, addressed to me. No form data is stored on this site.