Compliance Program Solutions for Auto Dealers

24
Apr

The FTC responded to the American Medical Association’s stance that the Red Flags Rule should not apply to physicians and related health care providers.  That’s right - your trusty GP must have an Identity Theft Prevention Program.  In the FTC’s letter to the AMA, the FTC acknowledges that, yes, doctors take a confidentiality oath, and yes, there’s HIPAA, but that does not cover the “respond to and mitigate identity theft” provision of the Red Flags Rule.  In other words, they focus on two scenarios:

  • The doc suffers a data breach and patient data is exposed when it shouldn’t be.
  • A thief tries to someone else’s data to fool the doc, thus potentially exposing a real person to the perils of false entries in their medical records or false insurance billing.

To address these scenarios, the FTC suggests that for smaller doctors offices, which are presumably low risk, checking a drivers license and determining what to do if notified of identity theft involving the office would be sufficient.

Category : Health care / Red Flags Program / Red Flags Rule / Uncategorized

Sorry, the comment form is closed at this time.

About Us

RedFlagsMadeEasy.com is brought to you by PegaFrog, Inc., consultants to the retail automotive industry. Read more »

Subscribe

Subsribe via RSS Feed Reader

Contact Us

Red Flags Made Easy

512 - 773 - 7419

sales@redflagsmadeeasy.com